Vulnerability analysis method and device, electronic equipment and computer program product

By obtaining and organizing the characteristic information of the system under test, using the vulnerability analysis model to automatically decompose and generate the task, solving the problems of high labor costs and low efficiency of the existing vulnerability analysis methods, and achieving efficient and automated vulnerability analysis.

CN120012101APending Publication Date: 2025-05-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411964790.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing vulnerability analysis methods have problems with high labor costs and low analysis efficiency, and the high false alarm rate requires a lot of manpower to review.

Method used

By obtaining the system feature information of the tested system, sorting the information based on the prompt word template, inputting the vulnerability analysis model for task decomposition, generating a list of tasks to be tested and a vulnerability analysis plan, and executing the scheme of each task to be tested in sequence to obtain the vulnerability analysis results.

Benefits of technology

It improves the efficiency of vulnerability analysis, saves labor costs, and realizes the automation and standardization of vulnerability analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012101A_ABST
    Figure CN120012101A_ABST
Patent Text Reader

Abstract

The invention discloses a vulnerability analysis method and device, electronic equipment and a computer program product, and relates to the technical field of artificial intelligence and information security. The method comprises the following steps: acquiring system feature information of a tested system, wherein the system feature information at least comprises basic system information, code feature information and business logic information; performing information arrangement on the basic system information, the code feature information and the business logic information based on the cue word template to obtain a system description text; the system description text is input into a vulnerability analysis model for task decomposition, a to-be-tested task list is obtained, and the to-be-tested task list comprises at least one to-be-tested task and a vulnerability analysis scheme corresponding to each to-be-tested task; and sequentially executing the vulnerability analysis scheme corresponding to each to-be-tested task to obtain a vulnerability analysis result of the tested system. According to the method, the vulnerability analysis efficiency can be improved, the manual analysis cost is saved, and vulnerability analysis is automatically performed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of artificial intelligence and information security technology, and in particular to a vulnerability analysis method, device, electronic device and computer program product. Background Art

[0002] With the development of network technology, network security issues have become increasingly prominent, and network security vulnerability detection has become a top priority for enterprise security protection. Existing vulnerability analysis methods generally rely on manual code audits or the use of vulnerability scanning tools to assist in analysis. On the one hand, the manual code audit method has high professional requirements for developers and a high threshold for employment; on the other hand, vulnerability scanning tools have a high false positive rate, requiring a large amount of human resources to be invested in review and confirmation in the later stage, and vulnerability analysis tools have a high learning cost. Existing vulnerability analysis methods have the problems of high labor costs and low analysis efficiency. Summary of the invention

[0003] The present application provides a vulnerability analysis method, device, electronic device and computer program product, which can improve the efficiency of vulnerability analysis and save labor costs.

[0004] In a first aspect, the present application provides a vulnerability analysis method, comprising:

[0005] Acquire system characteristic information of the system under test, wherein the system characteristic information at least includes basic system information, code characteristic information and business logic information;

[0006] Arrange the basic system information, the code feature information and the business logic information based on the prompt word template to obtain a system description text;

[0007] Input the system description text into the vulnerability analysis model to perform task decomposition, and obtain a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested;

[0008] Execute the vulnerability analysis solution corresponding to each of the tasks to be tested in turn to obtain the vulnerability analysis result of the system under test.

[0009] In a second aspect, the present application provides a vulnerability analysis device, the device comprising:

[0010] An information acquisition module is used to acquire system characteristic information of the system under test, wherein the system characteristic information at least includes basic system information, code characteristic information and business logic information;

[0011] An information sorting module, used to sort the basic system information, the code feature information and the business logic information based on a prompt word template to obtain a system description text;

[0012] A task decomposition module, used for inputting the system description text into a vulnerability analysis model to perform task decomposition, and obtaining a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested;

[0013] The vulnerability analysis module is used to execute the vulnerability analysis scheme corresponding to each of the tasks to be tested in turn to obtain the vulnerability analysis results of the system under test.

[0014] In a third aspect, the present application further provides an electronic device, the electronic device comprising:

[0015] at least one processor; and

[0016] a memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the vulnerability analysis method described in any embodiment of the present application.

[0018] In a fourth aspect, the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the vulnerability analysis method described in any embodiment of the present application when executed.

[0019] In a fifth aspect, the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the vulnerability analysis method described in any embodiment of the present application.

[0020] The vulnerability analysis scheme provided in the embodiment of the present application first organizes the basic system information, code feature information and business logic information of the system to be tested based on the prompt word template, and obtains the system description text, which helps to focus on the code area involved in the key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis; then, the vulnerability analysis model automatically decomposes the task based on the system description text to generate the task to be tested and the vulnerability analysis scheme corresponding to each task to be tested, which helps to accurately identify the vulnerability; finally, by executing the vulnerability analysis scheme corresponding to each task to be tested in turn, the vulnerability analysis result of the system to be tested is obtained, which can ensure the standardization and process of the scheme analysis process, so that the analysis of each test task can be completed efficiently. The scheme provided in this embodiment solves the problems of high labor cost and low analysis efficiency in the existing scheme, and achieves the beneficial effects of improving the efficiency of vulnerability analysis, saving the cost of manual analysis and automating vulnerability analysis.

[0021] It should be noted that the above computer instructions may be stored in whole or in part on a computer-readable storage medium, wherein the computer-readable storage medium may be packaged together with the processor of the vulnerability analysis device, or may be packaged separately from the processor of the vulnerability analysis device, which is not limited in this application.

[0022] The description of the second, third, fourth and fifth aspects of the present application can refer to the detailed description of the first aspect; and the beneficial effects of the description of the second, third, fourth and fifth aspects can refer to the beneficial effect analysis of the first aspect, which will not be repeated here.

[0023] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description.

[0024] It is understandable that before using the technical solutions disclosed in the embodiments of this application, the type, scope of use, and usage scenarios of the personal information involved in this application should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0026] Figure 1 It is a flowchart of the vulnerability analysis method provided by the embodiment of the present application;

[0027] Figure 2 is another flow chart of the vulnerability analysis method provided in the embodiment of the present application;

[0028] Figure 3 It is a structural schematic diagram of a vulnerability analysis device provided in an embodiment of the present application;

[0029] Figure 4 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the present application will be clearly and completely described below in conjunction with the drawings in the present embodiment. Obviously, the described embodiment is only a part of the embodiment of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present application.

[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0032] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the present application, rather than to limit the present application. It should also be noted that, for ease of description, only the parts related to the present application, rather than all structures, are shown in the accompanying drawings.

[0033] Figure 1 A flowchart of a vulnerability analysis method provided in an embodiment of the present application is provided. This embodiment is applicable to the case of automated testing and analysis of system vulnerabilities. The method can be performed by a vulnerability analysis device, which can be implemented in the form of hardware and / or software and integrated in an electronic device that performs the method. Preferably, the electronic device in the embodiment of the present application can be a server, or a computer device, etc.

[0034] refer to Figure 1 The vulnerability analysis method of this embodiment includes but is not limited to the following steps:

[0035] S110. Obtain system characteristic information of the system under test, where the system characteristic information at least includes basic system information, code characteristic information, and business logic information.

[0036] The above-mentioned system under test is the software system that is currently to be analyzed for vulnerabilities. Among them, the current system under test can include multiple types based on different usage scenarios, such as network applications, desktop software or mobile applications. And when the usage scenarios of the system under test are different, the corresponding system feature information has certain differences.

[0037] The system feature information described in this embodiment includes at least basic system information, code feature information and business logic information. Among them, the basic system information may include the operating system type, network architecture and deployment environment, etc.; the code feature information may include the common programming language type and version, code size (such as the number of lines of code, the number of files, etc.), the common development framework type and version, the third-party library and version used by the program, the program source code and or the intermediate code generated by the code analysis tool, etc.; the business logic information may include the business functions implemented by the program (such as user registration and login, product browsing and searching, shopping cart management, order processing) and data interaction content (such as data input and output, source and destination, etc.). This information will provide a basic basis for the subsequent filling of the prompt word template.

[0038] The purpose of this embodiment of obtaining system feature information from multiple dimensions of basic system information, code feature information and business logic information is to facilitate focusing on the code areas involved in key business functions for vulnerability analysis, avoid repeated detection or invalid detection due to missing key information, and help improve the efficiency and accuracy of vulnerability analysis.

[0039] S120: sorting basic system information, code feature information and business logic information based on the prompt word template to obtain a system description text.

[0040] The prompt word template in this embodiment is a standardized information integration framework developed for the system to be tested to meet the needs of different vulnerability analysis scenarios.

[0041] According to the specific vulnerability analysis scenario that has been determined, fill in the specific content corresponding to the basic system information, code feature information and business logic information into the corresponding position of the prompt word template to obtain the completed system description text about the system to be tested. Exemplarily, the prompt word template can be: 1. Programming language: X version of XXX language; 2. Development framework: X version of XXX framework is used; 3. Calling third-party libraries: X version of XXX library is called; 4. The business functions implemented include XXXXX; 5. {Test object program source code or intermediate code}. Among them, the content in "XXX" is filled in according to the actual information corresponding to the basic system information, code feature information and business logic information in the system to be tested.

[0042] After filling the basic system information, code feature information and business logic information of the system to be tested into the prompt word template, the obtained system description text may be: "For enterprise-level applications developed based on programming language A, the development framework used is framework a, which mainly implements user registration, login and commodity online trading functions. It is necessary to generate a vulnerability mining plan, such as scanning the program, obtaining the control flow graph and call graph of the program, analyzing the source points and sink points in the program, analyzing all reachable paths from the source point to the sink in the program, and eliminating false positives in the reachable paths."

[0043] This embodiment designs a prompt word template to fill in various types of collected complex information according to the established format of the template, which can quickly organize scattered information in an orderly manner to form a complete system description text. This process not only standardizes the form of information presentation, but also facilitates the subsequent vulnerability analysis model to directly read and understand this information, reducing the time cost spent on data preprocessing and understanding due to confusing information formats, making the process from collecting information to entering model analysis smoother and more efficient, and accelerating the progress of overall vulnerability analysis.

[0044] S130: Input the system description text into the vulnerability analysis model to perform task decomposition, and obtain a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested.

[0045] After receiving the system description text, the vulnerability analysis model will make inferences based on the massive historical vulnerability-related knowledge and experience learned during the training process. After the inference is completed, the output result is the vulnerability mining plan for the scenario. The plan will perform detailed task decomposition of the vulnerability mining process as required and generate a list of tasks to be tested. In the list of tasks to be tested, the content of each task to be tested is clearly defined, and the corresponding vulnerability analysis plan is produced for each task to be tested. In the list of tasks to be tested, the task list can be updated in real time according to the actual completion status of each task in the list of tasks to be tested, so as to ensure that the entire vulnerability mining work can be flexibly and dynamically adjusted and optimized according to the progress.

[0046] The vulnerability analysis model in this embodiment is obtained by training through model fine-tuning on the basis of a general large model, so that the model has the ability to mine more vulnerabilities. Therefore, it is necessary to construct a vulnerability data set and a vulnerability mining tool data set. Among them, the vulnerability data can be obtained by using existing vulnerability data sets, crawling public vulnerability databases and vulnerability public opinion, etc.; the vulnerability mining tool data set can be constructed by crawling the official documents and usage examples of existing static and dynamic vulnerability mining tools.

[0047] Specifically, before training the vulnerability analysis model, the acquired vulnerability dataset needs to be preprocessed. The specific processing method can be: format the vulnerability data into vulnerability name, vulnerability number, vulnerability description, vulnerability code, exploit script, mining solution and repair solution. The vulnerability number is the number of the vulnerability in the public vulnerability library; the vulnerability description includes the application and version range to which the vulnerability belongs, the vulnerability principle explanation, and the exploitation conditions; the vulnerability code refers to the source code where the vulnerability is located or the intermediate code obtained after being processed by the code analysis tool; the exploit script refers to the concept proof that can reproduce the vulnerability or the vulnerability exploitation program that uses this vulnerability to perform malicious operations; further, in order to enable the large model to have the ability to use vulnerability mining tools and reduce the learning cost of manual use of tools, it is necessary to construct an additional vulnerability mining tool dataset. The dataset preprocessing format is tool name, tool usage scenario description, and tool manual. Among them, the tool usage scenario description describes the characteristics of the tool, the types of vulnerabilities that can be mined, and the appropriate programming language; the manual contains the tool environment deployment process, running instructions, and natural language descriptions of instruction parameters and functions; finally, the vulnerability dataset and vulnerability mining tool dataset are used to fine-tune the general large model to obtain the vulnerability analysis model. The method of fine-tuning the general large model can be implemented using existing fine-tuning methods, such as using a low-rank adaptation (LoRa) fine-tuning method.

[0048] Optionally, when the vulnerability analysis model decomposes the system description text into tasks, obtains at least one task to be tested about the system to be tested, and formulates a corresponding vulnerability analysis plan for each task to be tested, it can be obtained by association analysis based on the knowledge graph, such as matching the entities (such as programming language, business function, etc.) in the key information such as the received system information, code information and business logic with the nodes in the constructed knowledge graph. For example, after identifying the programming language node of programming language A, the common vulnerability types, security features of the development framework, and corresponding code analysis methods related to programming language A are found through the existing edges in the constructed knowledge graph. For the business logic part, business functions such as "user registration and login" are also linked to the common security risks, data processing specifications, etc. of the function in the knowledge graph, and the direction of vulnerability mining tasks that may need to be carried out is sorted out based on this; optionally, it can also be obtained based on rule matching and historical solution analysis, such as learning a large number of vulnerability mining rules and past actual cases during the training process of the vulnerability analysis model. For the input prompt word, it will match the corresponding task generation logic according to the established rules. For example, when the prompt mentions that the focus is on the "Structured Query Language (SQL injection)" vulnerability and the development framework is "framework b", the model checks whether the user input data in framework b is properly filtered and verified before being passed to the database operation function based on the learned rules, thereby generating tasks such as "check whether the user name and password fields entered by the user login module in the framework b project are protected against injection when constructing SQL query statements." The specific vulnerability analysis model performs task decomposition and formulates corresponding vulnerability analysis plans for each task to be tested.

[0049] As an example, the task list obtained by the vulnerability analysis model provided by this embodiment can be illustrated as follows: Task 1: Use a static code analysis tool to scan the code of programming language A, focus on checking the code patterns related to SQL injection vulnerabilities, and output a list of suspicious code locations; Task 2: Perform a black box test on the user registration and login module of the e-commerce system, try to enter special character combinations, detect whether there is a cross-site scripting (XSS) vulnerability, and record the test results; Task 3: Analyze the data interaction code between the shopping cart management module and the database, find possible privilege escalation vulnerabilities, and draw a data flow diagram.

[0050] In another embodiment, the task list obtained by the vulnerability analysis model provided in this embodiment can also be exemplified as follows: Task 1: Scan the program to obtain the control flow graph and call graph of the program; Task 2: Analyze the source points and sink points in the program; Task 3: Analyze all reachable paths from the source point to the sink in the program; Task 4: Eliminate false positives in the reachable paths.

[0051] In this embodiment, the vulnerability analysis model automatically decomposes tasks based on the system description text, and based on the built-in vulnerability type rule library and intelligent matching mechanism, it can quickly determine the possible vulnerability types in the system, and generate tasks to be tested corresponding to specific business modules and code areas. Compared with manual experience to infer possible vulnerabilities, the model can cover a large number of vulnerability possibilities in a short period of time and accurately refine tasks, greatly improving the efficiency of task allocation, so that subsequent vulnerability detection work can be carried out quickly and orderly according to the generated task list.

[0052] S140, executing the vulnerability analysis solution corresponding to each task to be tested in turn to obtain the vulnerability analysis result of the system under test.

[0053] By executing vulnerability tests in sequence according to the established vulnerability analysis plan corresponding to each task to be tested, the standardization and process of the analysis process can be ensured, so that the analysis of each test task can be completed efficiently.

[0054] The vulnerability analysis method provided in this embodiment first organizes the basic system information, code feature information and business logic information of the system to be tested based on the prompt word template to obtain the system description text, which helps to focus on the code area involved in the key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis; then, the vulnerability analysis model automatically decomposes the task based on the system description text to generate the task to be tested and the vulnerability analysis scheme corresponding to each task to be tested, which helps to accurately identify vulnerabilities; finally, by executing the vulnerability analysis scheme corresponding to each task to be tested in turn, the vulnerability analysis results of the system to be tested are obtained, which can ensure the standardization and process of the scheme analysis process, so that the analysis of each test task can be completed efficiently. The scheme provided in this embodiment solves the problems of high labor cost and low analysis efficiency in the existing scheme, and achieves the beneficial effects of improving vulnerability analysis efficiency, saving the cost of manual analysis and automating vulnerability analysis.

[0055] Figure 2It is another flow chart of the vulnerability analysis method provided in an embodiment of the present application. The embodiment of the present application is optimized on the basis of the above embodiments. The specific optimization is as follows: this embodiment explains in detail the implementation process of "organizing the basic system information, the code feature information and the business logic information based on the prompt word template to obtain the system description text" in the above embodiment, and the implementation process of "inputting the system description text into the vulnerability analysis model for task decomposition to obtain a list of tasks to be tested" in the above embodiment.

[0056] For details, please refer to Figure 2 The vulnerability analysis method of this embodiment includes but is not limited to the following steps:

[0057] S210. Obtain system characteristic information of the system under test, where the system characteristic information at least includes basic system information, code characteristic information, and business logic information.

[0058] S220, calling a corresponding prompt word template according to the system type corresponding to the system under test, one system type corresponds to one prompt word template, the prompt word template includes standard information and information to be filled in, and the amount of information to be filled in is consistent with the amount of system characteristic information.

[0059] In order to reflect the scope of application of this solution, this embodiment pre-sets different prompt word templates according to different system types. Therefore, by setting a mapping relationship between the system type corresponding to the system under test and the corresponding prompt word template, it is helpful to accurately identify and analyze the vulnerabilities of the system under test in different scenarios.

[0060] The system type corresponding to the system under test can be realized by identifying the extension name or identifying the network ports corresponding to different system types, and the specific system type identification method is not limited here.

[0061] Each prompt word template contains standard information and information to be filled in. The standard information indicates the common information content corresponding to the same system type, such as identification program code, etc.; the information to be filled in indicates the unique information content corresponding to the same system type, such as basic system information, code feature information, and business logic information, etc. In this embodiment, the number of information to be filled in is consistent with the number of system feature information, the purpose of which is to be able to fill in the system feature information of different dimensions collected into the prompt word template to generate a complete system description text.

[0062] S221. Obtain the basic system identifier, code resource identifier, and business function identifier corresponding to the basic system information, code feature information, and business logic information, respectively.

[0063] For basic system information, code feature information, and business logic information, identification rules can be pre-established to uniquely identify each of the contents. For example, the "server operating system" in the basic system information can be identified by "os_server", and the "server software" can be identified by "server_soft", etc.; the "front-end programming language" in the code feature information can be identified by "lang_frontend", and the "back-end programming language" can be identified by "lang_backend", etc.; the specific information method for defining different dimensions of system feature information is not limited here.

[0064] S222. Determine the corresponding information to be filled in from the standard information according to the basic system identifier, the code resource identifier and the business function identifier.

[0065] Traverse the standard information in the prompt word template, match it through the identifier, and find the information to be filled in that needs to be replaced.

[0066] S223. Replace the corresponding information to be filled in according to the basic system information, code feature information and business logic information to obtain a system description text.

[0067] After determining the information to be filled in, the basic system information, code feature information and business logic information actually collected will be replaced in the corresponding positions accordingly; according to needs, the final replaced information can be organized into a specific text format to facilitate subsequent storage, transmission, parsing and other operations.

[0068] The solution provided by the above steps S220 to S223 standardizes and normalizes the process from determining the system type, calling the template to information identification, replacement and other operations; by generating a system description text, it helps to focus on the code areas involved in key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis.

[0069] S230: Extract keywords from the system description text to obtain at least one system keyword.

[0070] In this embodiment, the method of extracting keywords from the system description text can be implemented based on the Natural Language Processing (NLP) library. Among them, when obtaining system keywords, the focus can be on words corresponding to key concepts closely related to vulnerability analysis, such as "operating system name", "programming language", "business function" and "database type", and words that meet these rules are extracted from the text as system keywords. In practical applications, the method based on the NLP tool and the custom rule screening method can be combined. First, a broader keyword set can be obtained using the NLP tool, and then further screened and supplemented through custom rules to ensure that the extracted system keywords are both comprehensive and highly relevant to vulnerability analysis.

[0071] S231. Input at least one system keyword into the vulnerability analysis model. The vulnerability analysis model performs rule matching on the at least one keyword based on a preset learning rule to obtain at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested.

[0072] In the scheme provided by this embodiment, the vulnerability analysis model matches rules for at least one keyword based on preset learning rules to perform task decomposition and obtain vulnerability analysis schemes corresponding to each task to be tested. Specifically, a rule base can be pre-built. For example, for the extracted "database" keyword, the rule base may contain such rules: if the system involves database operations and the programming language is [specific language], it is necessary to check whether the database query statement has SQL injection vulnerabilities, and the corresponding generated task to be tested may be "Use SQL injection detection tools to scan the database query module in the system"; for the "user login" keyword, the rule may be to check the encryption storage and transmission of the login password, and the task is "review the strength of the password encryption algorithm in the user login module and whether the encryption process is safe, and check the use of encryption protocols during network transmission of the password"; then, after the keywords are extracted, the vulnerability analysis model matches these keywords with the rules in the rule base one by one.

[0073] When generating tasks, the type and name of the tool to be called to complete the task and the specific parameter instructions required to run the tool are determined according to the rules to generate a corresponding vulnerability analysis plan for each task to be tested. For example, for the SQL injection detection task, the type of tool to be called is determined to be a professional SQL injection detection software (such as SQLMap), the name is "SQLMap", and the parameter instructions may include specifying the target address to be scanned (if it is a Web application), the depth level of detection, etc.

[0074] In a preferred implementation, in this embodiment, the above step S231 can be implemented as follows:

[0075] When the current keyword matches the preset learning rule, at least one task to be tested is generated based on the current keyword; the vulnerability type is determined according to the task content of the current task to be tested, and a vulnerability analysis plan is generated for the current task to be tested based on the vulnerability type.

[0076] When a keyword successfully matches the preset learning rules, it means that a point where a potential vulnerability has been discovered, and based on this, a task to be tested is generated. For example, if the keyword "user input" is matched according to the rules, it is found that there is a vulnerability risk in the part of the program that processes user input data, then the detection of this part of the code becomes a task to be tested. Therefore, through such a matching process, at least one task to be tested will be generated, and these tasks clarify the specific objects or code ranges that need to be analyzed and checked for vulnerabilities in the future.

[0077] For each generated task to be tested, since the vulnerability risk types, code environments, business scenarios, etc. involved may be different, a corresponding dedicated vulnerability analysis plan is required. This plan will specify in detail which analysis methods to use for the task to be tested, which tools to use (such as static code analysis tools or dynamic testing tools, etc.), and what steps to follow to check whether there is a real vulnerability. For example, for a task to be tested that is suspected of having an SQL injection vulnerability, the corresponding vulnerability analysis plan may be to first use a static code analysis tool to find the part of the code that involves database queries and improperly handles user input, and then construct a specific test case for dynamic testing, simulating malicious input to verify whether it can be successfully injected, and a series of targeted analysis processes.

[0078] S232: Obtain a list of tasks to be tested according to each task to be tested and the corresponding vulnerability analysis solution.

[0079] The various tasks to be tested and their corresponding vulnerability analysis solutions generated by model matching are integrated in a certain format to construct a complete list of tasks to be tested. The list data structure in programming language A can be used for storage, and each element is a dictionary containing the description of the task to be tested and the corresponding analysis solution. Through the above implementation method, the system description text can be effectively input into the vulnerability analysis model, and a targeted list of tasks to be tested and their corresponding vulnerability analysis solutions can be obtained, providing powerful guidance for subsequent vulnerability detection and repair work.

[0080] The solution provided in the above steps S230 to S232 generates tasks to be tested by extracting system keywords and using the model for rule matching, which can quickly lock the key parts related to the vulnerability from the massive system information, helping to improve the targeted nature of vulnerability analysis; and when the vulnerability analysis model matches the system keywords, it performs rule matching based on preset learning rules, which can accurately determine the potential vulnerability type and the corresponding task to be tested, reduce the probability of missed judgment and misjudgment, and improve the efficiency of vulnerability analysis.

[0081] S240, executing the vulnerability analysis solution corresponding to each task to be tested in turn to obtain the vulnerability analysis result of the system under test.

[0082] Specifically, the vulnerability analysis scheme for each task to be tested can be reflected in the task list based on the task description, recommended method and expected result. For example, for the task to be tested with the task description of "analyzing the source points and sink points in the program", the recommended method can be "according to the current vulnerability analysis status, {detailed source list} can be used as the source, and {detailed sink list} can be used as the exploitation point"; for the task to be tested with the task description of "analyzing all reachable paths from the source point to the exploitation point in the program", the recommended method can be "according to the current analysis status, it is recommended to use the XXX tool and run the tool through {the script generated by the large model}"; the expected result can be "after the XXX tool is executed, all reachable paths from the source point to the exploitation point will be listed".

[0083] When vulnerability analysis is performed on the system to be tested, it can be implemented based on the vulnerability analysis scheme corresponding to each task to be tested. Optionally, the vulnerability analysis scheme provided in this embodiment includes a tool to be called and corresponding tool configuration parameters. Then, the test of a task to be tested in the task list can be realized by calling the corresponding analysis tool and the recommended configuration parameters. Then, after the test is completed, the test results need to be further analyzed. Therefore, the scheme provided in this embodiment, after executing the vulnerability analysis scheme corresponding to each task to be tested in turn, also includes: receiving the vulnerability information obtained after the vulnerability analysis of the current task to be tested according to the tool to be called and the corresponding tool configuration parameters based on the preset access interface; updating the preset field information of the current task to be tested in the task list to be tested according to the vulnerability information. The scheme provided in this embodiment receives vulnerability information and updates the relevant fields of the task to be tested through the preset access interface, and also provides decision-making basis for subsequent tasks, so that the execution results of the vulnerability analysis tool can be seamlessly connected with the entire task to be tested management process, realizing the automation process from tool analysis to task information update, and improving the overall efficiency of vulnerability analysis work.

[0084] Among them, the above-mentioned preset access interface is used to receive vulnerability information corresponding to each task to be tested after the execution of the vulnerability analysis plan is completed. For the preset access interface, the request method of the interface, the format of the request parameters, and the format and content of the response can be pre-defined. For the interface that receives vulnerability information, it is necessary to define which field information should be included in the transmitted vulnerability information, such as vulnerability number, vulnerability type, location (code file, function name, etc.), severity, discovery time, etc.; so that after receiving the vulnerability information, the preset field information of the current task to be tested in the task list to be tested can be updated based on the received field information.

[0085] Among them, the preset field information can be understood as information such as vulnerability number, vulnerability type, location (code file, function name, etc.), severity, discovery time, etc.; and then the corresponding preset field information is updated according to the actual received information content to achieve the purpose of vulnerability recording.

[0086] In another preferred embodiment, the scheme provided by this embodiment, the implementation method of obtaining the vulnerability analysis results of the system under test includes: after the preset field information corresponding to each task to be tested in the task list to be tested is updated, the vulnerability information corresponding to each task to be tested is parsed to obtain a vulnerability analysis report. This embodiment can quickly and clearly understand the vulnerability status existing in the system by integrating the vulnerability information corresponding to each task to be tested in the task list to be tested to generate a vulnerability analysis report, which helps the staff to have a clear understanding of the system security status, thereby providing a strong basis for subsequent decision-making and actions.

[0087] Among them, after the preset field information corresponding to each task to be tested in the task list to be tested is updated, it indicates that each task to be tested in the task list has been executed in sequence based on the vulnerability analysis solution, and then a vulnerability analysis report is obtained by integrating and analyzing the vulnerability information corresponding to each task to be tested. The vulnerability analysis report in this embodiment includes at least the vulnerability name, vulnerability type, vulnerability description, program location where the vulnerability is located, vulnerability exploitation method and repair suggestion, etc.

[0088] Another preferred embodiment is to improve the accuracy of the generated vulnerability analysis solution. The solution provided in this embodiment can also perform the following steps a) to c) after receiving the vulnerability information obtained after performing vulnerability analysis on the current task to be tested according to the tool to be called and the corresponding tool configuration parameters based on the preset access interface:

[0089] a) Determine vulnerability classification attributes based on vulnerability information, where the vulnerability classification attributes at least include vulnerability type, vulnerability level, and vulnerability location.

[0090] After receiving the vulnerability information transmitted through the preset access interface, the vulnerabilities are first classified and sorted according to different attributes. The vulnerability classification attributes provided in this embodiment at least include vulnerability type, vulnerability level and vulnerability location.

[0091] Among them, vulnerability types may include SQL injection vulnerabilities, cross-site scripting attack vulnerabilities, and unauthorized access vulnerabilities; vulnerability levels may be assessed based on the harmful consequences that the vulnerabilities may cause, and may be divided into high-risk, medium-risk, and low-risk levels; the vulnerability location may be clearly identified as being at the basic system level, a specific code module, or a specific link in the business logic process.

[0092] b) Evaluate whether the current vulnerability analysis solution has any misjudgment based on vulnerability type, vulnerability level or vulnerability location.

[0093] In this embodiment, the specific method of evaluating whether the current vulnerability analysis scheme has a misjudgment according to the vulnerability type may be: checking the detection tools and rules configured in the vulnerability analysis scheme, and for the results determined as a certain vulnerability type, analyzing whether the normal function or interaction of the system is mistakenly regarded as a vulnerability of this type. If so, the current vulnerability analysis scheme is evaluated to have a misjudgment.

[0094] The specific method of evaluating whether the current vulnerability analysis scheme has misjudgment based on the vulnerability level is to check whether there are vulnerabilities with small actual impact but over-evaluated as high-risk. Conversely, it is also possible to check whether there are vulnerabilities that should have been judged as high-risk, but were classified as medium-risk or low-risk due to insufficient understanding of their potential harm. If so, it is evaluated that the current vulnerability analysis scheme has misjudgment.

[0095] The specific way to evaluate whether the current vulnerability analysis scheme has misjudgment based on the vulnerability location is to confirm whether the vulnerability location determined by the vulnerability analysis scheme is consistent with the actual situation. Sometimes, due to the limitations of the detection tool or analysis logic problems, the vulnerability of module A may be mistakenly located in module B, resulting in the inability to accurately carry out subsequent repair work. If so, the current vulnerability analysis scheme is evaluated to have misjudgment.

[0096] c) When there is a misjudgment, determine the cause of the misjudgment, update the current vulnerability analysis plan according to the cause of the misjudgment, and obtain a vulnerability update plan.

[0097] In this embodiment, the misjudgment reason includes at least the reason corresponding to the vulnerability type, vulnerability level or vulnerability location.

[0098] Specifically, the current vulnerability analysis scheme is updated according to the cause of the misjudgment, and the vulnerability update scheme can be obtained in the following ways: if the misjudgment is caused by the vulnerability type, the analysis is that the detection rules are too broad to cause false positives, that is, the detection rules are not comprehensive enough and fail to cover new or hidden forms of vulnerabilities, resulting in missed reports. Therefore, it is necessary to add reasonable scripts as accurate identification conditions, such as the legal calling range of specific functions, the legal assignment form of variables, etc., to avoid misjudging normal situations as vulnerabilities; if the misjudgment is caused by the vulnerability level, it is necessary to re-evaluate the weight of various influencing factors (such as data confidentiality, integrity, availability, etc.) in the level division, and combine the actual business scenarios of the system to calibrate the weights by simulating the actual impact of different vulnerability scenarios on the business, and determine a more reasonable level division mechanism; if the misjudgment is caused by the vulnerability location, it may be due to the technical limitations of the detection tool itself, and it may be impossible to accurately locate the vulnerability location or identify the location correlation. In this case, the relevant tools can be replaced or upgraded to replace them with more powerful tools with deep code traceability capabilities, and the configuration parameters can be adjusted to better adapt to the system code structure characteristics.

[0099] The solution provided in this embodiment updates the current vulnerability analysis solution based on the cause of the misjudgment after analyzing the cause of the misjudgment, thereby obtaining a vulnerability update solution. Further, the vulnerability analysis of the current task to be tested is performed again according to the vulnerability update solution, so as to evaluate the rationality of the vulnerability update solution through the vulnerability information transmitted by the preset access interface, so as to achieve the purpose of deeply analyzing the cause of the misjudgment, thereby improving the accuracy and effectiveness of the vulnerability analysis and obtaining a more reliable vulnerability analysis solution.

[0100] The vulnerability analysis method provided in this embodiment first organizes the basic system information, code feature information and business logic information of the system to be tested based on the prompt word template to obtain the system description text, which helps to focus on the code area involved in the key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis; then, the vulnerability analysis model automatically decomposes the task based on the system description text to generate the task to be tested and the vulnerability analysis scheme corresponding to each task to be tested, which helps to accurately identify vulnerabilities; finally, by executing the vulnerability analysis scheme corresponding to each task to be tested in turn, the vulnerability analysis results of the system to be tested are obtained, which can ensure the standardization and process of the scheme analysis process, so that the analysis of each test task can be completed efficiently. The scheme provided in this embodiment solves the problems of high labor cost and low analysis efficiency in the existing scheme, and achieves the beneficial effects of improving vulnerability analysis efficiency, saving the cost of manual analysis and automating vulnerability analysis.

[0101] Figure 3 Schematic diagram of a vulnerability analysis device provided in an embodiment of the present application, which is suitable for executing the vulnerability analysis method provided in an embodiment of the present application. Figure 3 As shown, the device may specifically include:

[0102] The information acquisition module 310 is used to acquire system characteristic information of the system under test, wherein the system characteristic information at least includes basic system information, code characteristic information and business logic information;

[0103] An information sorting module 320, configured to sort the basic system information, the code feature information and the business logic information based on a prompt word template to obtain a system description text;

[0104] A task decomposition module 330 is used to input the system description text into a vulnerability analysis model for task decomposition to obtain a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested;

[0105] The vulnerability analysis module 340 is used to sequentially execute the vulnerability analysis solution corresponding to each of the tasks to be tested to obtain the vulnerability analysis results of the system under test.

[0106] The vulnerability analysis device provided in this embodiment first organizes the basic system information, code feature information and business logic information of the system to be tested based on the prompt word template to obtain the system description text, which helps to focus on the code area involved in the key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis; then, the vulnerability analysis model automatically decomposes the task based on the system description text to generate the task to be tested and the vulnerability analysis scheme corresponding to each task to be tested, which helps to accurately identify the vulnerability; finally, by executing the vulnerability analysis scheme corresponding to each task to be tested in turn, the vulnerability analysis result of the system to be tested is obtained, which can ensure the standardization and process of the scheme analysis process, so that the analysis of each test task can be completed efficiently. The scheme provided in this embodiment solves the problems of high labor cost and low analysis efficiency in the existing scheme, and achieves the beneficial effects of improving the efficiency of vulnerability analysis, saving the cost of manual analysis and automating vulnerability analysis.

[0107] In one embodiment, the information sorting module 320 includes a template calling unit and an identification obtaining unit, wherein:

[0108] A template calling unit, used for calling a corresponding prompt word template according to the system type corresponding to the system under test, one system type corresponds to one prompt word template, the prompt word template includes standard information and information to be filled in, and the amount of the information to be filled in is consistent with the amount of the system characteristic information;

[0109] An identification acquisition unit, used to acquire a basic system identification, a code resource identification and a business function identification corresponding to the basic system information, the code feature information and the business logic information respectively;

[0110] An information determination unit, configured to determine corresponding information to be filled in from the standard information according to the basic system identifier, the code resource identifier and the business function identifier;

[0111] The information replacement unit is used to replace the corresponding information to be filled in according to the basic system information, the code feature information and the business logic information to obtain the system description text.

[0112] In one embodiment, the information sorting module 320 includes a keyword extraction unit, a rule matching unit, and a list acquisition unit, wherein:

[0113] A keyword extraction unit, used to extract keywords from the system description text to obtain at least one system keyword;

[0114] A rule matching unit, used to input at least one of the system keywords into the vulnerability analysis model, and the vulnerability analysis model performs rule matching on at least one of the keywords based on a preset learning rule to obtain at least one task to be tested and a vulnerability analysis solution corresponding to each of the tasks to be tested;

[0115] The list obtaining unit is used to obtain the list of tasks to be tested according to each of the tasks to be tested and the corresponding vulnerability analysis scheme.

[0116] In one embodiment, the rule matching unit is specifically used to generate at least one task to be tested based on the current keyword when the current keyword matches the preset learning rule; determine the vulnerability type according to the task content of the current task to be tested, and generate the vulnerability analysis plan for the current task to be tested based on the vulnerability type.

[0117] In one embodiment, the vulnerability analysis solution includes a tool to be called and corresponding tool configuration parameters;

[0118] The device further comprises: an information receiving module and an information updating module, wherein:

[0119] An information receiving module is used to receive vulnerability information obtained after performing vulnerability analysis on the current task to be tested according to the tool to be called and the corresponding tool configuration parameters based on a preset access interface;

[0120] The information updating module is used to update the preset field information of the current task to be tested in the task to be tested list according to the vulnerability information.

[0121] In one embodiment, the vulnerability analysis module 340 is further configured to parse the vulnerability information corresponding to each task to be tested in the task list to obtain a vulnerability analysis report after the preset field information corresponding to each task to be tested in the task list to be tested is updated.

[0122] In one embodiment, the device further includes an attribute acquisition module, a solution evaluation module and a solution update module, wherein:

[0123] An attribute acquisition module, used to determine vulnerability classification attributes according to the vulnerability information, wherein the vulnerability classification attributes at least include vulnerability type, vulnerability level and vulnerability location;

[0124] A scheme evaluation module is used to evaluate whether the current vulnerability analysis scheme has a misjudgment according to the vulnerability type, the vulnerability level or the vulnerability location;

[0125] The solution updating module is used to determine the cause of the misjudgment when the misjudgment occurs, and to update the current vulnerability analysis solution according to the cause of the misjudgment to obtain a vulnerability update solution.

[0126] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example for illustration. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the functional modules described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0127] An embodiment of the present application also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the vulnerability scoring method described in any embodiment of the present application.

[0128] An embodiment of the present application further provides a computer-readable medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the vulnerability classification method described in any embodiment of the present application when executed.

[0129] Reference below Figure 4 , Figure 4 1 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application, and shows a schematic diagram of the structure of a computer system 500 suitable for implementing the electronic device in an embodiment of the present application. Figure 4 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0130] like Figure 4 As shown, the computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage part 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the system 500 are also stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0131] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed, so that a computer program read therefrom is installed into the storage section 508 as needed.

[0132] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 509, and / or installed from the removable medium 511. When the computer program is executed by the central processing unit (CPU) 501, the above-mentioned functions defined in the system of the present application are executed.

[0133] It should be noted that the computer-readable medium shown in the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, etc., or any suitable combination of the above.

[0134] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the above-mentioned module, program segment or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0135] The modules and / or units involved in the embodiments described in the present application may be implemented by software or hardware. The modules and / or units described may also be set in a processor, for example, it may be described as: a processor includes an information acquisition module, an information sorting module, a task decomposition module and a vulnerability analysis module. The names of these modules do not, in some cases, constitute limitations on the modules themselves.

[0136] As another aspect, the present application also provides a computer-readable medium, which may be included in the device described in the above embodiment; or it may exist independently without being assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by a device, the device includes: obtaining system feature information of the system under test, the system feature information at least includes basic system information, code feature information and business logic information; sorting the basic system information, the code feature information and the business logic information based on the prompt word template to obtain a system description text; inputting the system description text into the vulnerability analysis model for task decomposition to obtain a list of tasks to be tested, the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis plan corresponding to each task to be tested; executing the vulnerability analysis plan corresponding to each task to be tested in turn to obtain the vulnerability analysis result of the system under test.

[0137] According to the technical solution of this embodiment, firstly, the basic system information, code feature information and business logic information of the system to be tested are sorted based on the prompt word template to obtain the system description text, which helps to focus on the code area involved in the key business functions for vulnerability analysis and accelerate the progress of the overall vulnerability analysis; then, the vulnerability analysis model automatically decomposes the task based on the system description text to generate the task to be tested and the vulnerability analysis solution corresponding to each task to be tested, which helps to accurately identify the vulnerability; finally, by executing the vulnerability analysis solution corresponding to each task to be tested in turn, the vulnerability analysis result of the system to be tested is obtained, which can ensure the standardization and process of the solution analysis process, so that the analysis of each test task can be completed efficiently. The solution provided by this embodiment solves the problems of high labor cost and low analysis efficiency in the existing solution, and achieves the beneficial effects of improving the efficiency of vulnerability analysis, saving the cost of manual analysis and automating vulnerability analysis.

[0138] The above specific implementations do not constitute a limitation on the protection scope of this application. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions may occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principles of this application should be included in the protection scope of this application.

Claims

1. A vulnerability analysis method, characterized in that: include: Acquire system characteristic information of the system under test, wherein the system characteristic information at least includes basic system information, code characteristic information and business logic information; Arrange the basic system information, the code feature information and the business logic information based on the prompt word template to obtain a system description text; Input the system description text into the vulnerability analysis model to perform task decomposition, and obtain a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested; Execute the vulnerability analysis solution corresponding to each of the tasks to be tested in turn to obtain the vulnerability analysis result of the system under test.

2. The vulnerability analysis method according to claim 1, characterized in that: The step of arranging the basic system information, the code feature information and the business logic information based on the prompt word template to obtain a system description text includes: Calling a corresponding prompt word template according to the system type corresponding to the system under test, one system type corresponds to one prompt word template, the prompt word template includes standard information and information to be filled in, and the amount of the information to be filled in is consistent with the amount of the system characteristic information; Obtaining a basic system identifier, a code resource identifier, and a business function identifier corresponding to the basic system information, the code feature information, and the business logic information, respectively; Determine the corresponding information to be filled in from the standard information according to the basic system identifier, the code resource identifier and the business function identifier; The corresponding information to be filled in is replaced according to the basic system information, the code feature information and the business logic information to obtain the system description text.

3. The vulnerability analysis method according to claim 1, characterized in that: The step of inputting the system description text into the vulnerability analysis model for task decomposition to obtain a list of tasks to be tested includes: Extracting keywords from the system description text to obtain at least one system keyword; Inputting at least one of the system keywords into the vulnerability analysis model, wherein the vulnerability analysis model performs rule matching on the at least one keyword based on a preset learning rule to obtain at least one task to be tested and a vulnerability analysis solution corresponding to each of the tasks to be tested; The list of tasks to be tested is obtained according to each of the tasks to be tested and the corresponding vulnerability analysis solutions.

4. The vulnerability analysis method according to claim 3, characterized in that: The vulnerability analysis model performs rule matching on at least one of the keywords based on a preset learning rule to obtain at least one task to be tested and a vulnerability analysis solution corresponding to each of the tasks to be tested, including: When the current keyword matches the preset learning rule, generating at least one task to be tested based on the current keyword; The vulnerability type is determined according to the task content of the current task to be tested, and the vulnerability analysis solution is generated for the current task to be tested based on the vulnerability type.

5. The vulnerability analysis method according to claim 1, characterized in that: The vulnerability analysis scheme includes a tool to be called and corresponding tool configuration parameters; After executing the vulnerability analysis scheme corresponding to each of the tasks to be tested in sequence, the method further includes: Receiving vulnerability information obtained after performing vulnerability analysis on the current task to be tested according to the tool to be called and the corresponding tool configuration parameters based on a preset access interface; The preset field information of the current task to be tested in the list of tasks to be tested is updated according to the vulnerability information.

6. The vulnerability analysis method according to claim 5, characterized in that: The obtaining of the vulnerability analysis result of the system under test includes: After the preset field information corresponding to each of the tasks to be tested in the task list to be tested is updated, the vulnerability information corresponding to each of the tasks to be tested is parsed to obtain a vulnerability analysis report.

7. The vulnerability analysis method according to claim 5, characterized in that: After receiving vulnerability information obtained by performing vulnerability analysis on the current task to be tested according to the tool to be called and the corresponding tool configuration parameters based on the preset access interface, the method further includes: Determine vulnerability classification attributes according to the vulnerability information, wherein the vulnerability classification attributes include at least vulnerability type, vulnerability level and vulnerability location; Evaluate whether the current vulnerability analysis scheme has a misjudgment according to the vulnerability type, the vulnerability level or the vulnerability location; When the misjudgment situation occurs, the cause of the misjudgment is determined, and the current vulnerability analysis solution is updated according to the cause of the misjudgment to obtain a vulnerability update solution.

8. A vulnerability analysis device, characterized in that: include: An information acquisition module is used to acquire system characteristic information of the system under test, wherein the system characteristic information at least includes basic system information, code characteristic information and business logic information; An information sorting module, used to sort the basic system information, the code feature information and the business logic information based on a prompt word template to obtain a system description text; A task decomposition module, used for inputting the system description text into a vulnerability analysis model to perform task decomposition, and obtaining a list of tasks to be tested, wherein the list of tasks to be tested includes at least one task to be tested and a vulnerability analysis solution corresponding to each task to be tested; The vulnerability analysis module is used to execute the vulnerability analysis scheme corresponding to each of the tasks to be tested in turn to obtain the vulnerability analysis results of the system under test.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the vulnerability analysis method according to any one of claims 1 to 7.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the vulnerability analysis method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Vulnerability data retrieval method and device

    CN121456888A