Method and device for predicting range of product influenced by vulnerability, electronic equipment and medium
By building frequent set and association models, predicting the range of product versions affected by target vulnerabilities, it solves the problem that security personnel have difficulty determining whether other product versions are affected by vulnerabilities, and improves the efficiency and accuracy of security assessments.
Patent Information
- Application Number
- CN202510188819.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-16
AI Technical Summary
Because security personnel have difficulty obtaining all product iteration versions, it is difficult to determine whether other product versions are affected by vulnerabilities and it is difficult to understand whether other products are affected.
By obtaining product versions affected by known vulnerabilities, building frequent sets and association models, predicting the range of product versions affected by target vulnerabilities.
This enables rapid identification of other product versions of the vulnerability, improving the efficiency and accuracy of security assessments.
Smart Images

Figure CN120012114A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, electronic device and medium for predicting the scope of products affected by vulnerabilities. Background Art
[0002] Each product (such as hardware chips, software, components, etc.) usually has multiple versions. When a vulnerability occurs in one of the versions of a product, it is difficult for security personnel to understand whether other versions of the product are also affected by the vulnerability, as it is impossible or difficult for security personnel to obtain all iterative versions of the product. It is also difficult to understand whether other products are also affected by the vulnerability. Summary of the invention
[0003] In view of this, the purpose of the present application is to provide a method, device, electronic device and medium for predicting the range of products affected by a vulnerability, so as to quickly determine the range of other product versions affected by the target vulnerability when one product version is affected by the target vulnerability.
[0004] In a first aspect, an embodiment of the present application provides a method for predicting the scope of products affected by a vulnerability, including:
[0005] For known vulnerabilities, obtain the disclosed product versions that are affected by the vulnerabilities; the product versions include product names and product version identifiers;
[0006] If the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version affected by the sample vulnerability is determined as a sample product version;
[0007] Based on the sample product versions, multiple frequent sets are constructed, and for each of the frequent sets, a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability is calculated; wherein each of the frequent sets contains at least one sample product version;
[0008] Calculating the association confidence between the sample product versions based on the first probability that all sample product versions in each of the frequent sets are affected by the same sample vulnerability;
[0009] Based on the association confidence between the sample product versions, a vulnerability impact association model is constructed so that when a target sample product version is affected by a target vulnerability, the vulnerability impact association model can be used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more of the sample product versions.
[0010] In combination with the first aspect, an embodiment of the present application provides a first possible implementation of the first aspect, wherein, based on the sample product version, multiple frequent sets are constructed, and for each of the frequent sets, a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability is calculated, including:
[0011] Based on each of the sample product versions, construct a set corresponding to each of the sample product versions; wherein the set corresponding to the sample product version includes the sample product version;
[0012] For each of the item sets, calculating a first probability that a sample product version in the item set is affected by the sample vulnerability, and determining an item set whose first probability is greater than or equal to a first preset threshold as a frequent set;
[0013] Using any two of the one-item frequent sets to construct a two-item set, so as to obtain a plurality of two-item sets; wherein each two-item set contains two sample product versions in two of the one-item frequent sets;
[0014] For each of the two-item sets, calculating a first probability that two sample product versions included in the two-item set are affected by the same sample vulnerability, and determining a two-item set whose first probability is greater than or equal to the first preset threshold as a two-item frequent set;
[0015] Construct three-item sets using the one-item frequent set and the two-item frequent set; wherein each of the three-item sets contains three sample product versions;
[0016] For each of the three-item sets, a first probability that the three sample product versions included in the three-item set are affected by the same sample vulnerability is calculated, and the three-item sets whose first probability is greater than or equal to the first preset threshold are determined as three-item frequent sets.
[0017] In combination with the first possible implementation of the first aspect, the embodiment of the present application provides a second possible implementation of the first aspect, wherein the calculation of the association confidence between the sample product versions based on the first probability that all sample product versions in each of the frequent sets are affected by the same sample vulnerability includes:
[0018] For each of the two frequent sets, based on the first probability that the two sample product versions included in the two frequent sets are affected by the same sample vulnerability and the first probability that the two sample product versions are each affected by the sample vulnerability, calculate the second probability that when one of the two sample product versions is affected by the vulnerability, the other sample product version is also affected by the vulnerability;
[0019] For each of the three frequent sets, based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that any two of the three sample product versions are affected by the same sample vulnerability, and the first probability that the other sample product version is affected by the sample vulnerability, calculate the second probability that when any two sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability;
[0020] And based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that one of the three sample product versions is affected by the sample vulnerability, and the first probability that the other two sample product versions are affected by the same sample vulnerability, a second probability that when one of the sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability is calculated.
[0021] In combination with the second possible implementation of the first aspect, the embodiment of the present application provides a third possible implementation of the first aspect, wherein the step of constructing a vulnerability impact association model based on the association confidence between the sample product versions includes:
[0022] A vulnerability impact association model is constructed based on the second probability that when one of the sample product versions is affected by the vulnerability, the second probability that another sample product version is also affected by the vulnerability, and the second probability that when any two of the three sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability, and the second probability that when one of the three sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability.
[0023] In combination with the third possible implementation of the first aspect, the embodiment of the present application provides a fourth possible implementation of the first aspect, wherein, when the target sample product version is affected by the target vulnerability, the range of the sample product version affected by the target vulnerability is predicted by the vulnerability impact association model, including:
[0024] When the target sample product version is affected by the target vulnerability, a second probability that other sample product versions have vulnerabilities when the target sample product version is used is queried from the vulnerability impact association model;
[0025] If the queried second probability is greater than the second preset threshold, the other sample product versions are determined as sample product versions affected by the target vulnerability to obtain a range of sample product versions affected by the target vulnerability.
[0026] In combination with the first aspect, the embodiment of the present application provides a fifth possible implementation of the first aspect, wherein, for a known vulnerability, obtaining each product version that has been disclosed and is affected by the vulnerability includes:
[0027] For known vulnerabilities, obtain the product versions that have been disclosed to be affected by the vulnerability;
[0028] Preprocessing the product version corresponding to each of the acquired vulnerabilities to obtain the preprocessed product version corresponding to each of the vulnerabilities; the preprocessing includes any one or more of the following: data deduplication, invalid value processing, missing value processing, and data normalization;
[0029] Each product version affected by the vulnerability is stored in a product version database, so that the product version database stores a product version corresponding to each vulnerability; wherein the product version corresponding to the vulnerability refers to the product version affected by the vulnerability.
[0030] In combination with the fifth possible implementation of the first aspect, the embodiment of the present application provides a sixth possible implementation of the first aspect, wherein if the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version affected by the sample vulnerability is determined as a sample product version, including:
[0031] Scan the product versions corresponding to each of the vulnerabilities stored in the product version database, and for each of the vulnerabilities, determine whether the number of product versions corresponding to the vulnerability is greater than or equal to 3;
[0032] If the number of product versions corresponding to the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version corresponding to the sample vulnerability is determined as a sample product version.
[0033] In a second aspect, the embodiment of the present application further provides a device for predicting the range of products affected by a vulnerability, including:
[0034] An acquisition module is used to acquire, for a known vulnerability, various product versions that have been disclosed and are affected by the vulnerability; the product version includes a product name and a product version identifier;
[0035] A determination module, configured to determine the vulnerability as a sample vulnerability and determine the product version affected by the sample vulnerability as a sample product version if the number of product versions affected by the vulnerability is greater than or equal to 3;
[0036] A first construction module is used to construct multiple frequent sets based on the sample product version, and for each of the frequent sets, calculate a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability; wherein each of the frequent sets contains at least one of the sample product versions;
[0037] A calculation module, configured to calculate the association confidence between the sample product versions based on the first probability that all the sample product versions in each of the frequent sets are affected by the same sample vulnerability;
[0038] The second construction module is used to construct a vulnerability impact association model based on the association confidence between the sample product versions, so that when the target sample product version is affected by the target vulnerability, the vulnerability impact association model can be used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more of the sample product versions.
[0039] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps in any possible implementation of the first aspect above are performed.
[0040] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in any possible implementation of the first aspect described above are executed.
[0041] The embodiments of the present application provide a method, device, electronic device and medium for predicting the range of products affected by a vulnerability, wherein the method comprises: for a known vulnerability, obtaining the disclosed product versions affected by the vulnerability; the product version includes a product name and a product version identifier; if the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined to be a sample vulnerability, and the product version affected by the sample vulnerability is determined to be a sample product version; based on the sample product version, multiple frequent sets are constructed, and for each frequent set, a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability is calculated; wherein each frequent set includes at least one sample product version; based on the first probability that all sample product versions in each frequent set are affected by the same sample vulnerability, the association confidence between the sample product versions is calculated; based on the association confidence between the sample product versions, a vulnerability impact association model is constructed, so that when a target sample product version is affected by a target vulnerability, the range of sample product versions affected by the target vulnerability is predicted through the vulnerability impact association model; the target vulnerability is a vulnerability other than the sample vulnerability; the target sample product version includes one or more sample product versions. By using this method, when a target sample product version is affected by a target vulnerability, the range of sample product versions affected by the target vulnerability can be predicted in a timely and comprehensive manner, wherein the range of sample product versions affected by the target vulnerability includes other sample product versions affected by the target vulnerability.
[0042] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0044] Figure 1 A flow chart showing a method for predicting the scope of products affected by a vulnerability provided by an embodiment of the present application is shown;
[0045] Figure 2 A schematic diagram showing a set and a frequent set provided in an embodiment of the present application is shown;
[0046] Figure 3 A schematic diagram of a binomial set and a binomial frequent set provided in an embodiment of the present application is shown;
[0047] Figure 4A schematic diagram of a three-item set and a three-item frequent set provided in an embodiment of the present application is shown;
[0048] Figure 5 A schematic diagram of a vulnerability impact association model provided by an embodiment of the present application is shown;
[0049] Figure 6 A schematic diagram of the structure of a device for predicting the range of products affected by a vulnerability provided by an embodiment of the present application is shown;
[0050] Figure 7 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0051] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0052] Considering that each product (products such as hardware chips, software, components, etc.) usually has multiple versions, when a vulnerability occurs in one version of a product, it is difficult for security personnel to understand whether other versions of the product are also affected by the vulnerability, and it is also difficult to understand whether other products are also affected by the vulnerability. Based on this, the embodiments of the present application provide a method, device, electronic device and medium for predicting the range of products affected by the vulnerability, which are described below through embodiments.
[0053] To facilitate understanding of this embodiment, a method for predicting the scope of products affected by a vulnerability disclosed in the embodiment of this application is first described in detail. Figure 1 As shown, the following steps S101-S105 are included:
[0054] S101: For a known vulnerability, obtain the disclosed product versions that are affected by the vulnerability; the product version includes the product name and product version identifier.
[0055] In this embodiment, the known vulnerability refers to a currently existing vulnerability, which may be a software vulnerability, a hardware vulnerability, a component vulnerability, etc. The disclosed product versions affected by the vulnerability refer to the product versions currently known to be affected by the vulnerability. The product version affected by the vulnerability may refer to the product version that is attacked by the vulnerability.
[0056] In this embodiment, the product versions affected by the same vulnerability may be different product versions of the same product, or may be product versions of different products.
[0057] In a possible implementation manner, when executing step S101, the following steps S1011-S1013 may be specifically performed:
[0058] S1011: For known vulnerabilities, obtain the product versions that have been disclosed and are affected by the vulnerabilities;
[0059] S1012: Preprocess the product version corresponding to each acquired vulnerability to obtain the preprocessed product version corresponding to each vulnerability; the preprocessing includes any one or more of the following: data deduplication, invalid value processing, missing value processing, and data normalization.
[0060] In this embodiment, since the obtained product versions affected by the vulnerability may contain duplicate information, invalid values, or missing values, it is necessary to deduplicate data, process invalid values, process missing values, etc. for the product version corresponding to each vulnerability.
[0061] Furthermore, since the data formats of various product versions affected by the vulnerability may be different, it is necessary to normalize the data of the product version corresponding to each vulnerability.
[0062] S1013: Store each product version affected by the vulnerability in a product version database, so that the product version database stores a product version corresponding to each vulnerability; wherein the product version corresponding to the vulnerability refers to the product version affected by the vulnerability.
[0063] Exemplarily, the product version database stores various product versions affected by vulnerability A, vulnerability B, vulnerability C, ... vulnerability J:
[0064] Vulnerability A: {product version 1, product version 3, product version 5};
[0065] Vulnerability B: {product version 2, product version 4};
[0066] Vulnerability C: {product version 2, product version 3};
[0067] Vulnerability D: {product version 1, product version 2, product version 3, product version 4};
[0068] Vulnerability E: {product version 1, product version 2};
[0069] Vulnerability F: {product version 2, product version 3};
[0070] Vulnerability G: {product version 1, product version 2};
[0071] Vulnerability H: {product version 1, product version 2, product version 3, product version 5};
[0072] Vulnerability I: {product version 1, product version 2, product version 3};
[0073] Vulnerability J: {product version 1, product version 3, product version 5}.
[0074] It is worth noting that the “product version 1, product version 2, product version 3, product version 4, product version 5” in the above example can be different product versions of the same product or product versions of different products.
[0075] S102: If the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version affected by the sample vulnerability is determined as a sample product version.
[0076] Continuing with the above example, let's take vulnerability AD as an example. Among them, the number of product versions affected by vulnerability A is 3, the number of product versions affected by vulnerability B is 2, the number of product versions affected by vulnerability C is 2, and the number of product versions affected by vulnerability D is 4.
[0077] In this embodiment, if a vulnerability can only affect one or two product versions, then the prediction of the impact range of the vulnerability is not very meaningful. Therefore, a threshold of 3 is set in this embodiment.
[0078] In the above example, the number of product versions affected by vulnerability A, vulnerability D, vulnerability H, vulnerability I, and vulnerability J is greater than or equal to 3, so vulnerability A, vulnerability D, vulnerability H, vulnerability I, and vulnerability J can be determined as sample vulnerabilities. And product versions 1, product version 2, product version 3, product version 4, and product version 5 affected by vulnerability A, vulnerability D, vulnerability H, vulnerability I, and vulnerability J are determined as sample product versions.
[0079] In a possible implementation, when executing step S102, specifically: scan the product version corresponding to each vulnerability stored in the product version database, and for each vulnerability, determine whether the number of product versions corresponding to the vulnerability is greater than or equal to 3; if the number of product versions corresponding to the vulnerability is greater than or equal to 3, determine the vulnerability as a sample vulnerability, and determine the product version corresponding to the sample vulnerability as a sample product version.
[0080] S103: construct multiple frequent sets based on the sample product versions, and for each frequent set, calculate a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability; wherein each frequent set contains at least one sample product version.
[0081] In a possible implementation manner, when executing step S103, the following steps S1031-S1036 may be specifically performed:
[0082] S1031: Based on each sample product version, construct an item set corresponding to each sample product version; wherein the item set corresponding to the sample product version includes the sample product version.
[0083] Continuing with the above example, assume that the product versions affected by the sample vulnerabilities in the product version database are:
[0084] Sample vulnerability A: {sample product version 1, sample product version 3, sample product version 5};
[0085] Sample vulnerability D: {sample product version 1, sample product version 2, sample product version 3, sample product version 4};
[0086] Sample vulnerability H: {sample product version 1, sample product version 2, sample product version 3, sample product version 5};
[0087] Sample vulnerability I: {sample product version 1, sample product version 2, sample product version 3};
[0088] Sample vulnerability J: {sample product version 1, sample product version 3, sample product version 5}.
[0089] like Figure 2 As shown, in this example, there are 5 sample product versions, namely sample product version 1, sample product version 2, sample product version 3, sample product version 4, and sample product version 5. Each item set contains one sample product version, so there are 5 item sets.
[0090] S1032: For each item set, calculate a first probability that a sample product version in the item set is affected by a sample vulnerability, and determine an item set whose first probability is greater than or equal to a first preset threshold as a frequent set.
[0091] like Figure 2 As shown, taking a set {sample product version 1} as an example, the first probability (also called associated support) is calculated as follows: the sample product version 1 in the set {sample product version 1} is affected by 5 sample vulnerabilities (A, D, H, I, J), and there are 5 sample vulnerabilities in total. Therefore, the first probability that the sample product version 1 in the set is affected by the sample vulnerability is 1.
[0092] For example, assuming that the first preset threshold is 0.2, Figure 2 The first probabilities of the five item sets in are all greater than or equal to 0.2, so we can Figure 2 All five item sets in are determined to be frequent item sets. Figure 2 A schematic diagram of a frequent set is shown.
[0093] S1033: Use any two one-item frequent sets to construct a two-item set to obtain multiple two-item sets; each two-item set contains two sample product versions in two one-item frequent sets.
[0094] like Figure 3 As shown, 10 two-item sets are obtained by combining two-item sets in pairs. In this embodiment, all non-empty subsets of two-item sets are one-item sets.
[0095] S1034: For each binomial set, calculate a first probability that two sample product versions included in the binomial set are affected by the same sample vulnerability, and determine a binomial set whose first probability is greater than or equal to a first preset threshold as a binomial frequent set.
[0096] like Figure 3 As shown, taking the binomial set {sample product version 1, 2} as an example, the calculation method of the first probability corresponding to the binomial set is: the sample product version 1 and the sample product version 2 in the binomial set {sample product version 1, 2} are affected by sample vulnerabilities D, H, and I at the same time, that is, they are affected by 3 sample vulnerabilities at the same time, and there are 5 sample vulnerabilities in total. Therefore, the first probability that the two sample product versions included in the binomial set {sample product version 1, 2} are affected by the same sample vulnerability is 0.6.
[0097] After obtaining the first probability corresponding to each binomial set, such as Figure 3 As shown, the binomial sets with a first probability greater than or equal to 0.2 are determined as binomial frequent sets.
[0098] S1035: Use one frequent set and two frequent sets to construct three frequent sets, where each three frequent set contains three sample product versions.
[0099] like Figure 4 As shown in Figure 1, 10 three-item sets were obtained by combining one frequent set and two frequent sets in pairs.
[0100] S1036: For each three-item set, calculate a first probability that the three sample product versions included in the three-item set are affected by the same sample vulnerability, and determine the three-item set whose first probability is greater than or equal to a first preset threshold as a three-item frequent set.
[0101] In this embodiment, all non-empty subsets of the three-item frequent set are one-item frequent sets and two-item frequent sets.
[0102] Taking the three-item set {sample product version 1, 2, 3} as an example, sample product version 1, sample product version 2, and sample product version 3 are all affected by sample vulnerabilities D, H, and I, that is, they are all affected by three sample vulnerabilities, and there are five sample vulnerabilities in total. Therefore, the first probability that the three sample product versions included in the three-item set {sample product version 1, 2, 3} are affected by the same sample vulnerability is 0.6.
[0103] like Figure 4 As shown, after the first probability corresponding to each three-item set is obtained, the three-item set with the first probability greater than or equal to 0.2 is determined as the three-item frequent set.
[0104] S104: Calculate the association confidence between the sample product versions based on the first probability that all sample product versions in each frequent set are affected by the same sample vulnerability.
[0105] In a possible implementation manner, when executing step S104, the following steps may be specifically performed:
[0106] S1041: For each binomial frequent set, based on the first probability that the two sample product versions included in the binomial frequent set are affected by the same sample vulnerability and the first probability that the two sample product versions are each affected by the sample vulnerability, calculate the second probability (also referred to as association confidence) that when one of the two sample product versions is affected by the vulnerability, the other sample product version is also affected by the vulnerability.
[0107] In this embodiment, when calculating the second probability that, when one of the two sample product versions is affected by the vulnerability, the other sample product version is also affected by the vulnerability, it can be specifically calculated by the following formula:
[0108]
[0109] Among them, P(x→y) represents the second probability that when the sample product version x is affected by the vulnerability, the sample product version y is also affected by the vulnerability; P(x) represents the first probability that the sample product version x is affected by the sample vulnerability; P(x∪y) represents the first probability that the two sample product versions x and y included in the binomial frequent set are affected by the same sample vulnerability.
[0110] Taking the binomial frequent set {sample product version 1, 2} as an example, the first probability that the two sample product versions 1 and sample product version 2 contained in the binomial frequent set are affected by the same sample vulnerability is 0.6, and the first probability that the sample product version 1 is affected by the sample vulnerability is 1. Therefore, when the sample product version 1 is affected by the vulnerability, the second probability that the sample product version 2 is also affected by the vulnerability is 0.6 / 1=0.6.
[0111] S1042: For each three-item frequent set, based on the first probability that the three sample product versions included in the three-item frequent set are affected by the same sample vulnerability, the first probability that any two of the three sample product versions are affected by the same sample vulnerability, and the first probability that the other sample product version is affected by the sample vulnerability, calculate the second probability that when any two sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability.
[0112] In this embodiment, when calculating the second probability that two of the three sample product versions are affected by the vulnerability, another sample product version is also affected by the vulnerability, it can be specifically calculated by the following formula:
[0113]
[0114] Among them, P(xy→z) represents the second probability that when sample product version x and sample product version y are affected by the vulnerability, sample product version z is also affected by the vulnerability; P(xy) represents the first probability that sample product version x and sample product version y are affected by the same sample vulnerability at the same time; P(xy∪z) represents the first probability that the three sample product versions x, y, and z included in the three frequent sets are affected by the same sample vulnerability.
[0115] Taking the three-item frequent set {sample product version 1, 2, 3} as an example, the first probability that the three sample product versions 1, sample product version 2, and sample product version 3 included in the three-item frequent set are affected by the same sample vulnerability is 0.6, and the first probability that sample product version 1 and sample product version 2 are affected by the same sample vulnerability is 0.6. Therefore, when sample product version 1 and sample product version 2 are affected by the vulnerability, the second probability that sample product version 3 is also affected by the vulnerability is 0.6 / 0.6=1.
[0116] S1043: Calculate the second probability that when one of the sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that one of the three sample product versions is affected by the sample vulnerability, and the first probability that the other two sample product versions are affected by the same sample vulnerability.
[0117] In this embodiment, when calculating the second probability that one of the three sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability, it can be specifically calculated by the following formula:
[0118]
[0119] Among them, P(z→xy) represents the second probability that when the sample product version z is affected by the vulnerability, the sample product version x and the sample product version y are also affected by the vulnerability; P(z) represents the first probability that the sample product version z is affected by the sample vulnerability; P(xy∪z) represents the first probability that the three sample product versions x, y, and z included in the three frequent sets are affected by the same sample vulnerability.
[0120] Taking the three-item frequent set {sample product version 1, 2, 3} as an example, the first probability that the three sample product versions 1, sample product version 2, and sample product version 3 included in the three-item frequent set are affected by the same sample vulnerability is 0.6, and the first probability that the sample product version 3 is affected by the sample vulnerability is 1. Therefore, when the sample product version 3 is affected by the vulnerability, the second probability that the sample product version 1 and the sample product version 2 are affected by the vulnerability at the same time is 0.6 / 1=0.6.
[0121] It is worth noting that the above examples are only for illustration and cannot represent the actual application process of this case. Since the sample size in this example is small, the first probability is 1. Among them, the first probability of 1 means that all vulnerabilities have an impact on the sample product version. This may happen with small sample data, but not with large sample data. In the actual application process of this case, the sample data volume will be relatively large. Therefore, the first probability of 1 will rarely occur in the actual application process of this case.
[0122] S105: Based on the association confidence between sample product versions, a vulnerability impact association model is constructed, so that when a target sample product version is affected by a target vulnerability, the vulnerability impact association model is used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more sample product versions.
[0123] In this embodiment, a vulnerability impact association model is constructed based on the second probability that when one of the sample product versions is affected by the vulnerability, another sample product version is also affected by the vulnerability, and the second probability that when any two of the three sample product versions are affected by the vulnerability, another sample product version is also affected by the vulnerability, and the second probability that when one of the three sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability.
[0124] like Figure 5 As shown, a schematic diagram of a partial vulnerability impact association model is shown.
[0125] In a possible implementation, after the vulnerability impact association model is constructed, when the target sample product version is affected by the target vulnerability, the scope of the sample product version affected by the target vulnerability is predicted by the vulnerability impact association model, specifically:
[0126] When the target sample product version is affected by the target vulnerability, the second probability of vulnerabilities occurring in other sample product versions when the target sample product version is used is queried from the vulnerability impact association model;
[0127] If the queried second probability is greater than the second preset threshold, the other sample product versions are determined as sample product versions affected by the target vulnerability to obtain a range of sample product versions affected by the target vulnerability.
[0128] For example, Figure 5As shown, if the target sample product version is sample product version 1, it can be queried from the vulnerability impact association model that when sample product version 1 is affected by the target vulnerability, the second probability that sample product version 2 is also affected by the target vulnerability is 0.6. In addition, it can also be queried that when sample product version 1 is affected by the target vulnerability, the second probability that sample product version 3 is also affected by the target vulnerability is 1.
[0129] If the target sample product versions are sample product version 1 and sample product version 2, it can be queried from the vulnerability impact association model that when sample product version 1 and sample product version 2 are both affected by the target vulnerability, the second probability that sample product version 3 is also affected by the target vulnerability is 1.
[0130] If the target sample product version is sample product version 3, it can be queried from the vulnerability impact association model that when sample product version 3 is affected by the target vulnerability, the second probability that sample product version 1 and sample product version 2 are simultaneously affected by the target vulnerability is 0.6.
[0131] Based on the same technical concept, the embodiment of the present application also provides a device for predicting the range of products affected by the vulnerability, such as Figure 6 As shown, the device comprises:
[0132] The acquisition module 601 is used to acquire, for a known vulnerability, various product versions that have been disclosed and are affected by the vulnerability; the product version includes a product name and a product version identifier;
[0133] A determination module 602 is configured to determine the vulnerability as a sample vulnerability and the product version affected by the sample vulnerability as a sample product version if the number of product versions affected by the vulnerability is greater than or equal to 3;
[0134] A first construction module 603 is used to construct multiple frequent sets based on the sample product versions, and for each of the frequent sets, calculate a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability; wherein each of the frequent sets contains at least one sample product version;
[0135] A calculation module 604, configured to calculate the association confidence between the sample product versions based on the first probability that all the sample product versions in each of the frequent sets are affected by the same sample vulnerability;
[0136] The second construction module 605 is used to construct a vulnerability impact association model based on the association confidence between the sample product versions, so that when the target sample product version is affected by the target vulnerability, the vulnerability impact association model can be used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more of the sample product versions.
[0137] Optionally, when the first construction module 603 is used to construct multiple frequent sets based on the sample product versions, and for each of the frequent sets, calculate the first probability that all sample product versions in the frequent set are affected by the same sample vulnerability, it is specifically used to:
[0138] Based on each of the sample product versions, construct a set corresponding to each of the sample product versions; wherein the set corresponding to the sample product version includes the sample product version;
[0139] For each of the item sets, calculating a first probability that a sample product version in the item set is affected by the sample vulnerability, and determining an item set whose first probability is greater than or equal to a first preset threshold as a frequent set;
[0140] Using any two of the one-item frequent sets to construct a two-item set, so as to obtain a plurality of two-item sets; wherein each two-item set contains two sample product versions in two of the one-item frequent sets;
[0141] For each of the two-item sets, calculating a first probability that two sample product versions included in the two-item set are affected by the same sample vulnerability, and determining a two-item set whose first probability is greater than or equal to the first preset threshold as a two-item frequent set;
[0142] Construct three-item sets using the one-item frequent set and the two-item frequent set; wherein each of the three-item sets contains three sample product versions;
[0143] For each of the three-item sets, a first probability that the three sample product versions included in the three-item set are affected by the same sample vulnerability is calculated, and the three-item sets whose first probability is greater than or equal to the first preset threshold are determined as three-item frequent sets.
[0144] Optionally, when the calculation module 604 is used to calculate the association confidence between the sample product versions based on the first probability that all sample product versions in each of the frequent sets are affected by the same sample vulnerability, it is specifically used to:
[0145] For each of the two frequent sets, based on the first probability that the two sample product versions included in the two frequent sets are affected by the same sample vulnerability and the first probability that the two sample product versions are each affected by the sample vulnerability, calculate the second probability that when one of the two sample product versions is affected by the vulnerability, the other sample product version is also affected by the vulnerability;
[0146] For each of the three frequent sets, based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that any two of the three sample product versions are affected by the same sample vulnerability, and the first probability that the other sample product version is affected by the sample vulnerability, calculate the second probability that when any two sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability;
[0147] And based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that one of the three sample product versions is affected by the sample vulnerability, and the first probability that the other two sample product versions are affected by the same sample vulnerability, a second probability that when one of the sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability is calculated.
[0148] Optionally, when the second construction module 605 is used to construct the vulnerability impact association model based on the association confidence between the sample product versions, it is specifically used to:
[0149] A vulnerability impact association model is constructed based on the second probability that when one of the sample product versions is affected by the vulnerability, the second probability that another sample product version is also affected by the vulnerability, and the second probability that when any two of the three sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability, and the second probability that when one of the three sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability.
[0150] Optionally, when the target sample product version is affected by the target vulnerability, the second construction module 605 is used to predict the range of sample product versions affected by the target vulnerability through the vulnerability impact association model, specifically for:
[0151] When a target vulnerability occurs in a target sample product version, a second probability that vulnerabilities occur in other sample product versions when the target sample product version occurs is queried from the vulnerability impact association model;
[0152] If the queried second probability is greater than the second preset threshold, the other sample product versions are determined as sample product versions affected by the target vulnerability to obtain a range of sample product versions affected by the target vulnerability.
[0153] Optionally, when the acquisition module 601 is used to acquire various product versions that have been disclosed and are affected by a known vulnerability, it is specifically used to:
[0154] For known vulnerabilities, obtain the product versions that have been disclosed to be affected by the vulnerability;
[0155] Preprocessing the product version corresponding to each of the acquired vulnerabilities to obtain the preprocessed product version corresponding to each of the vulnerabilities; the preprocessing includes any one or more of the following: data deduplication, invalid value processing, missing value processing, and data normalization;
[0156] Each product version affected by the vulnerability is stored in a product version database, so that the product version database stores a product version corresponding to each vulnerability; wherein the product version corresponding to the vulnerability refers to the product version affected by the vulnerability.
[0157] Optionally, when the determination module 602 is used to determine the vulnerability as a sample vulnerability if the number of product versions affected by the vulnerability is greater than or equal to 3, and to determine the product version affected by the sample vulnerability as a sample product version, it is specifically used to:
[0158] Scan the product versions corresponding to each of the vulnerabilities stored in the product version database, and for each of the vulnerabilities, determine whether the number of product versions corresponding to the vulnerability is greater than or equal to 3;
[0159] If the number of product versions corresponding to the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version corresponding to the sample vulnerability is determined as a sample product version.
[0160] Figure 7 A structural diagram of an electronic device provided for an embodiment of the present application includes: a processor 701, a memory 702 and a bus 703, wherein the memory 702 stores machine-readable instructions executable by the processor 701. When the electronic device runs the above-mentioned information processing method, the processor 701 communicates with the memory 702 through the bus 703, and the processor 701 executes the machine-readable instructions to execute the method steps described in Example 1.
[0161] The embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method steps described in the first embodiment are executed.
[0162] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, electronic devices, and computer-readable storage media can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0163] In the several embodiments provided in the present application, it should be understood that the disclosed methods, devices, electronic devices and computer-readable storage media can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or modules can be electrical, mechanical or other forms.
[0164] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0165] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0166] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0167] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
Claims
1. A method for predicting the scope of products affected by a vulnerability, characterized in that: include: For known vulnerabilities, obtain the product versions that have been disclosed and are affected by the vulnerabilities; the product versions include the product name and product version identifier; If the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version affected by the sample vulnerability is determined as a sample product version; Based on the sample product versions, multiple frequent sets are constructed, and for each of the frequent sets, a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability is calculated; wherein each of the frequent sets contains at least one sample product version; Calculating the association confidence between the sample product versions based on the first probability that all sample product versions in each of the frequent sets are affected by the same sample vulnerability; Based on the association confidence between the sample product versions, a vulnerability impact association model is constructed so that when a target sample product version is affected by a target vulnerability, the vulnerability impact association model can be used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more of the sample product versions.
2. The method according to claim 1, characterized in that: The step of constructing a plurality of frequent sets based on the sample product versions, and calculating, for each of the frequent sets, a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability, includes: Based on each of the sample product versions, construct a set corresponding to each of the sample product versions; wherein the set corresponding to the sample product version includes the sample product version; For each of the item sets, calculating a first probability that a sample product version in the item set is affected by the sample vulnerability, and determining an item set whose first probability is greater than or equal to a first preset threshold as a frequent set; Using any two of the one-item frequent sets to construct a two-item set, so as to obtain a plurality of two-item sets; wherein each two-item set contains two sample product versions in two of the one-item frequent sets; For each of the two-item sets, calculating a first probability that two sample product versions included in the two-item set are affected by the same sample vulnerability, and determining a two-item set whose first probability is greater than or equal to the first preset threshold as a two-item frequent set; Construct three-item sets using the one-item frequent set and the two-item frequent set; wherein each of the three-item sets contains three sample product versions; For each of the three-item sets, a first probability that the three sample product versions included in the three-item set are affected by the same sample vulnerability is calculated, and the three-item sets whose first probability is greater than or equal to the first preset threshold are determined as three-item frequent sets.
3. The method according to claim 2, characterized in that: The calculating the association confidence between the sample product versions based on the first probability that all the sample product versions in each of the frequent sets are affected by the same sample vulnerability includes: For each of the two frequent sets, based on the first probability that the two sample product versions included in the two frequent sets are affected by the same sample vulnerability and the first probability that the two sample product versions are each affected by the sample vulnerability, calculate the second probability that when one of the two sample product versions is affected by the vulnerability, the other sample product version is also affected by the vulnerability; For each of the three frequent sets, based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that any two of the three sample product versions are affected by the same sample vulnerability, and the first probability that the other sample product version is affected by the sample vulnerability, calculate the second probability that when any two sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability; And based on the first probability that the three sample product versions included in the three frequent sets are affected by the same sample vulnerability, the first probability that one of the three sample product versions is affected by the sample vulnerability, and the first probability that the other two sample product versions are affected by the same sample vulnerability, a second probability that when one of the sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability is calculated.
4. The method according to claim 3, characterized in that: The step of constructing a vulnerability impact association model based on the association confidence between the sample product versions includes: A vulnerability impact association model is constructed based on the second probability that when one of the sample product versions is affected by the vulnerability, the second probability that another sample product version is also affected by the vulnerability, and the second probability that when any two of the three sample product versions are affected by the vulnerability, the other sample product version is also affected by the vulnerability, and the second probability that when one of the three sample product versions is affected by the vulnerability, the other two sample product versions are also affected by the vulnerability.
5. The method according to claim 4, characterized in that: When the target sample product version is affected by the target vulnerability, the scope of the sample product version affected by the target vulnerability is predicted by the vulnerability impact association model, including: When the target sample product version is affected by the target vulnerability, a second probability that other sample product versions have vulnerabilities when the target sample product version is used is queried from the vulnerability impact association model; If the queried second probability is greater than the second preset threshold, the other sample product versions are determined as sample product versions affected by the target vulnerability to obtain a range of sample product versions affected by the target vulnerability.
6. The method according to claim 1, characterized in that: For known vulnerabilities, obtain the product versions that have been disclosed to be affected by the vulnerability, including: For known vulnerabilities, obtain the product versions that have been disclosed to be affected by the vulnerability; Preprocessing the product version corresponding to each of the acquired vulnerabilities to obtain the preprocessed product version corresponding to each of the vulnerabilities; the preprocessing includes any one or more of the following: data deduplication, invalid value processing, missing value processing, and data normalization; Each product version affected by the vulnerability is stored in a product version database, so that the product version database stores a product version corresponding to each vulnerability; wherein the product version corresponding to the vulnerability refers to the product version affected by the vulnerability.
7. The method according to claim 6, characterized in that: If the number of product versions affected by the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version affected by the sample vulnerability is determined as a sample product version, including: Scan the product versions corresponding to each of the vulnerabilities stored in the product version database, and for each of the vulnerabilities, determine whether the number of product versions corresponding to the vulnerability is greater than or equal to 3; If the number of product versions corresponding to the vulnerability is greater than or equal to 3, the vulnerability is determined as a sample vulnerability, and the product version corresponding to the sample vulnerability is determined as a sample product version.
8. A device for predicting the range of products affected by a vulnerability, characterized in that: include: An acquisition module is used to acquire, for a known vulnerability, various product versions that have been disclosed and are affected by the vulnerability; the product version includes a product name and a product version identifier; A determination module, configured to determine the vulnerability as a sample vulnerability and determine the product version affected by the sample vulnerability as a sample product version if the number of product versions affected by the vulnerability is greater than or equal to 3; A first construction module is used to construct multiple frequent sets based on the sample product version, and for each of the frequent sets, calculate a first probability that all sample product versions in the frequent set are affected by the same sample vulnerability; wherein each of the frequent sets contains at least one of the sample product versions; A calculation module, configured to calculate the association confidence between the sample product versions based on the first probability that all the sample product versions in each of the frequent sets are affected by the same sample vulnerability; The second construction module is used to construct a vulnerability impact association model based on the association confidence between the sample product versions, so that when the target sample product version is affected by the target vulnerability, the vulnerability impact association model can be used to predict the range of sample product versions affected by the target vulnerability; the target vulnerability is a vulnerability other than the sample vulnerability; and the target sample product version contains one or more of the sample product versions.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the method as described in any one of claims 1 to 7 are performed.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are executed.
Citation Information
Patent Citations
Method for efficiently excavating frequent item sets in association rules
CN106294617A
Software vulnerability detection method and device, and storage medium
CN111797402A
Method and device for predicting products influenced by vulnerabilities
CN116821915A