Vulnerability elimination and control method and device, electronic equipment and storage medium

By analyzing historical vulnerability attack events, determining the target feature dimensions, training predictive models and handling vulnerabilities according to hazard scores, the problem of untimely vulnerability handling in the existing technology is solved, and more efficient vulnerability prevention and control is achieved.

CN120012115APending Publication Date: 2025-05-16CHINA INFORMATION TECH SECURITY EVALUATION CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510190321.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When handling vulnerabilities, the existing technology only relies on CVSS scores to guide the repair sequence, and does not consider whether the vulnerability is really exploited and the attacker's attack ease, resulting in many vulnerabilities to be deleted, and high-risk vulnerabilities cannot be eliminated in time.

Method used

By analyzing the situation where attack events have occurred in historical vulnerabilities, we determine the target feature dimensions that affect the vulnerabilities being exploited and generate actual attack probability, train the prediction model to predict the current vulnerability, obtain a hazard score, and eliminate control in order according to the scores.

Benefits of technology

Prioritizing the handling of vulnerabilities with higher risks reduces the risk of vulnerability handling and improves the efficiency and effectiveness of vulnerability prevention and control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012115A_ABST
    Figure CN120012115A_ABST
Patent Text Reader

Abstract

The invention provides a vulnerability elimination and control method and device, electronic equipment and a storage medium, and the method comprises the steps: analyzing the condition that a historical vulnerability generates an attack event, and determining a target feature dimension which influences the probability that the vulnerability is utilized to generate an actual attack in the attack event; taking the feature values of the sample data in the training set under each target feature dimension as the input of a basic model, training the basic model, and obtaining a prediction model when a preset cut-off condition is satisfied; predicting each current vulnerability by using a prediction model to obtain a harmfulness score of each current vulnerability; and according to the harmfulness score of each current vulnerability, performing elimination and control processing on each current vulnerability in sequence. According to the method, the prediction model is obtained by selecting multi-dimensional target feature dimension training, and the prediction model is used for predicting the current vulnerability to obtain the harmfulness score of the current vulnerability, so that the vulnerability with relatively high risk can be processed preferentially, and the risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a vulnerability control method, device, electronic device, and storage medium. Background Art

[0002] A vulnerability is a flaw in the specific implementation of hardware, software, a protocol, or a system security policy that could allow an attacker to access or damage the system without authorization.

[0003] In the prior art, when dealing with vulnerabilities, especially when there are a large number of vulnerabilities, they are eliminated and controlled in the order in which the vulnerabilities are generated or in the order in which the vulnerabilities are handled as determined by CVSS (Common Vulnerability Scoring System). This elimination and control method only reflects the degree of harm from the technical perspective of the vulnerability, without considering whether the vulnerability actually exists and can be exploited, whether it is easy for an attacker to launch an attack, whether the input-output ratio of the attack is efficient, etc. Only using CVSS scores to guide the vulnerability repair order is prone to problems such as a large number of vulnerabilities to be eliminated and not being able to be completely eliminated, and higher-risk vulnerabilities cannot be eliminated and controlled in a timely manner. Summary of the invention

[0004] In view of this, the purpose of the present application is to provide a method, device, electronic device and storage medium for vulnerability control to overcome the problems in the prior art.

[0005] In a first aspect, an embodiment of the present application provides a method for vulnerability elimination and control, the method comprising:

[0006] Analyze the historical vulnerabilities that have caused attack events, and determine the target feature dimensions that affect the probability of the vulnerability being exploited to cause an actual attack in the attack events;

[0007] The characteristic values ​​of the sample data in the training set under each target characteristic dimension are used as inputs of the basic model, the basic model is trained, and when a preset cutoff condition is met, a prediction model is obtained;

[0008] When a current vulnerability of the system is detected, the prediction model is used to predict each current vulnerability to obtain a criticality score of each current vulnerability;

[0009] According to the criticality score of each current vulnerability, each current vulnerability is eliminated and controlled in sequence.

[0010] In some technical solutions of the present application, the above analysis of the historical vulnerabilities that have generated attack events determines the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events, including:

[0011] Analyze the historical vulnerability attack events using the first analysis method to determine the first characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack;

[0012] Using the second analysis method, analyzing the historical vulnerability-generated attack events, and determining the second characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack;

[0013] The target feature dimension is obtained according to the first feature dimension and the second feature dimension.

[0014] In some technical solutions of the present application, the first analysis method is used to analyze the situation where historical vulnerabilities have generated attack events, and the first characteristic dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event is determined, including:

[0015] Performing statistical analysis on the target vulnerabilities in the attack incidents and the features contained in the target vulnerabilities;

[0016] The feature whose occurrence frequency in the target vulnerability is greater than or equal to a preset frequency threshold is used as the first feature dimension.

[0017] In some technical solutions of the present application, the second analysis method is used to analyze the historical vulnerability attack events, and determine the second feature dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event, including:

[0018] Displaying the target vulnerability in the attack event through a graphical user interface;

[0019] In response to a vulnerability selection operation, a feature included in a target vulnerability corresponding to the vulnerability selection is used as the second feature dimension.

[0020] In some technical solutions of the present application, the above analysis of the historical vulnerabilities that have generated attack events determines the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events, including:

[0021] Analyze the historical vulnerabilities that have caused attack events, and determine the manufacturer characteristics, vulnerability exploit code characteristics, vulnerability type characteristics and scoring system indicator characteristics that affect the probability of the vulnerability being exploited and causing actual attacks in the attack events.

[0022] In some technical solutions of the present application, the above method constructs the basic model in the following manner:

[0023] Constructing basic items of model parameters according to the occurrence probability of the sample data and the characteristic values ​​of each target characteristic dimension of the sample data;

[0024] constructing regularization terms for the model parameters;

[0025] The basic model is constructed according to the model parameters, the basic terms and the regularization terms.

[0026] In some technical solutions of the present application, the above-mentioned elimination and control processing of each current vulnerability is carried out in sequence according to the harmfulness score of each current vulnerability, including:

[0027] If the criticality score of the current vulnerability is greater than or equal to the preset score threshold, the vulnerability elimination and control processing are performed in sequence according to the priority order of the current vulnerability;

[0028] If the criticality score of the current vulnerability is less than a preset score threshold, the current vulnerability will not be processed.

[0029] In a second aspect, an embodiment of the present application provides a device for vulnerability elimination and control, the device comprising:

[0030] An analysis module is used to analyze the historical vulnerability attack events and determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate an actual attack in the attack event;

[0031] A training module is used to use the characteristic values ​​of the sample data in the training set under each target characteristic dimension as the input of the basic model, train the basic model, and obtain a prediction model when a preset cutoff condition is met;

[0032] A prediction module, used to predict each current vulnerability using the prediction model when a current vulnerability of the system is detected, and obtain a criticality score of each current vulnerability;

[0033] The elimination control module is used to perform elimination control processing on each of the current vulnerabilities in sequence according to the harmfulness score of each of the current vulnerabilities.

[0034] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned vulnerability mitigation method when executing the computer program.

[0035] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned vulnerability mitigation method are executed.

[0036] The technical solution provided by the embodiments of the present application may have the following beneficial effects:

[0037] The method of the present application includes analyzing the situations in which historical vulnerabilities have generated attack events, determining the target feature dimensions in the attack events that affect the probability of the vulnerability being exploited to generate actual attacks; using the feature values ​​of the sample data in the training set under each target feature dimension as the input of the basic model, training the basic model, and obtaining a prediction model when a preset cutoff condition is met; when the current vulnerability of the system is detected, using the prediction model to predict each of the current vulnerabilities to obtain a criticality score of each of the current vulnerabilities; and performing elimination and control processing on each of the current vulnerabilities in sequence according to the criticality score of each of the current vulnerabilities.

[0038] The present application obtains a prediction model by selecting a multi-dimensional target feature dimension for training, and uses the prediction model to predict the current vulnerability to obtain a criticality score of the current vulnerability, thereby giving priority to processing vulnerabilities with higher risks and reducing the risk.

[0039] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0041] Figure 1 A schematic diagram of a process flow of a vulnerability elimination method provided by an embodiment of the present application is shown;

[0042] Figure 2 A flow chart of a logistic regression algorithm provided in an embodiment of the present application is shown;

[0043] Figure 3 A schematic diagram of a vulnerability elimination and control device provided in an embodiment of the present application is shown;

[0044] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.

[0046] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0047] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0048] A vulnerability is a flaw in the specific implementation of hardware, software, a protocol, or a system security policy that could allow an attacker to access or damage the system without authorization.

[0049] In the prior art, when dealing with vulnerabilities, especially when there are a large number of vulnerabilities, they are eliminated and controlled in the order in which the vulnerabilities are generated or in the order in which the vulnerabilities are handled as determined by CVSS (Common Vulnerability Scoring System). This elimination and control method only reflects the degree of harm from the technical perspective of the vulnerability, without considering whether the vulnerability actually exists and can be exploited, whether it is easy for an attacker to launch an attack, whether the input-output ratio of the attack is efficient, etc. Only using CVSS scores to guide the vulnerability repair order is prone to problems such as a large number of vulnerabilities to be eliminated and not being able to be completely eliminated, and higher-risk vulnerabilities cannot be eliminated and controlled in a timely manner.

[0050] Based on this, the embodiments of the present application provide a method, device, electronic device and storage medium for vulnerability control, which are described below through embodiments.

[0051] Figure 1A schematic flow chart of a vulnerability elimination method provided in an embodiment of the present application is shown, wherein the method includes steps S101-S104; specifically:

[0052] S101, analyzing the historical attack events caused by the vulnerability, and determining the target feature dimensions in the attack events that affect the probability of the vulnerability being exploited to generate an actual attack;

[0053] S102, taking the characteristic values ​​of the sample data in the training set under each target characteristic dimension as the input of the basic model, training the basic model, and obtaining the prediction model when the preset cutoff condition is met;

[0054] S103, when a current vulnerability of the system is detected, using the prediction model to predict each current vulnerability to obtain a criticality score of each current vulnerability;

[0055] S104: performing control and elimination processing on each of the current vulnerabilities in order according to the severity score of each of the current vulnerabilities.

[0056] The present application obtains a prediction model by selecting a multi-dimensional target feature dimension for training, and uses the prediction model to predict the current vulnerability to obtain a criticality score of the current vulnerability, thereby giving priority to processing vulnerabilities with higher risks and reducing the risk.

[0057] Some embodiments of the present application are described in detail below. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0058] The embodiment of the present application provides a method for vulnerability control. In order to ensure the accuracy of the data, the vulnerability data in the attack event here is collected using the following method: crawling the relevant vulnerability data using crawler technology. Data storage: designing the database table structure and building the corresponding vulnerability database. Data cleaning: de-duplicating and merging the data, and processing invalid values ​​and missing values.

[0059] After acquiring the attack events of the system, it is necessary to analyze the attack events and determine the target feature dimensions in the attack events. When determining the target feature dimensions, it mainly includes: using a first analysis method to analyze the historical vulnerabilities that have generated attack events, and determining the first feature dimension in the attack events that affects the probability of the vulnerability being exploited to generate an actual attack; using a second analysis method to analyze the historical vulnerabilities that have generated attack events, and determining the second feature dimension in the attack events that affects the probability of the vulnerability being exploited to generate an actual attack; according to the first feature dimension and the second feature dimension, the target feature dimension is obtained.

[0060] When analyzing attack events, the embodiment of the present application mainly adopts two analysis methods: the first analysis method is a statistical analysis method, and the second analysis method is a manual analysis method. Regarding the statistical analysis method: the embodiment of the present application performs a statistical analysis on the target vulnerability in the attack event and the impact of the target vulnerability after use, and uses the feature of the target vulnerability whose frequency is greater than or equal to the preset frequency threshold as the first feature dimension.

[0061] For example, a test target is built. The software installed on the target covers products from large and small manufacturers, widely used products, and specialized products. These software have three types of vulnerabilities: A, B, and C. A-type vulnerabilities are vulnerabilities whose vulnerability information is public but whose attack codes such as PoC and EXP have not been leaked; B-type vulnerabilities are vulnerabilities whose vulnerability information is not only public but also spread on the Internet; and C-type vulnerabilities are vulnerabilities whose vulnerability information is not only public but also easily found by using tools such as EXP. These types of vulnerabilities cover various types given in the national standard "GB-T 30279-2020 Information Security Technology Network Security Vulnerability Classification and Grading Guide". Within a given period of time, let several security attackers and defenders launch penetration attacks on the target. The number of times each vulnerability is attacked is recorded. Assuming that the threshold of the number of attacks is a0, the features contained in the three categories A, B, and C are counted. The frequency of large manufacturer type features is a1, and the frequency of small vulnerability manufacturer type features is a2; the frequency of PoC exploit code features with vulnerabilities is b1, and the frequency of PoC exploit code features without vulnerabilities is b2; the frequency of EXP exploit code features with vulnerabilities is c1, and the frequency of EXP exploit code features without vulnerabilities is c2; statistics show that a1 is greater than a2, b2 is greater than b1, and c2 is greater than c1, so the manufacturer type features and vulnerability exploit code features are used as the first feature dimension.

[0062] For manual analysis: using the same test data as before, security personnel analyze and evaluate the losses caused by the attack and find that the vulnerability types that cause the most serious consequences such as data leakage, system unavailability, and data tampering are often concentrated in some vulnerability types such as code execution, remote exploitation, and denial of service. Therefore, the embodiment of the present application uses the vulnerability type features selected by security personnel after evaluation and analysis as the second feature dimension.

[0063] After obtaining the first feature dimension and the second feature dimension, the embodiment of the present application obtains the target feature dimension according to the first feature dimension and the second feature dimension. For example, the overlapping dimension of the first feature dimension and the second feature dimension is used as the target feature dimension, or the first feature dimension and the second feature dimension are merged together as the target, etc.

[0064] For example, the target feature dimensions are as follows: vendor features (Microsoft, Adobe, HP, etc.), exploit code features (whether the exploit code has been released, and whether the vulnerability has been weaponized (set as a plug-in for easy operation)), vulnerability type features (code execution, remote, denial of service, etc.), reference counts (REF) in published CVEs, and CVSS indicator features (baseScore, exploitabilityScore, etc.).

[0065] After determining the target feature dimension, a training set is constructed for basic model training. After obtaining the training set, the feature values ​​of the sample data in the training set under each target feature dimension are used as inputs of the basic model, and the basic model is trained. When the preset cutoff condition is met, a prediction model is obtained.

[0066] The basic model in the embodiment of the present application includes a basic term and a regular term. Specifically, the basic model is constructed in the following manner: constructing the basic term of the model parameter according to the occurrence probability of the sample data and the characteristic value of each target characteristic dimension of the sample data; constructing the regular term of the model parameter; constructing the basic model according to the model parameters, the basic term and the regular term.

[0067] In the specific implementation, the basic model in the embodiment of the present application is a logistic regression model. The basic idea of ​​logistic regression is to use the Sigmoid function to convert the predicted value into a probability. The general linear regression expression is as follows:

[0068] z=θ0+θ1x1+θ2x2+θ3x3...+θ n x n =θ T x (1)

[0069] Among them, x1,x2,...x n is the independent variable, representing each feature input; θ1,θ2,...θ n is the coefficient of each variable, representing the weight of each feature; z is the probability.

[0070] For Logistic Regression, its idea is also based on linear regression. Logistic Regression belongs to the generalized linear regression model. The expression of Logistic Regression is as follows:

[0071]

[0072] in, It is called the sigmoid function.

[0073] The loss function defined by formula (2) is:

[0074]

[0075] The method without regularization term often selects a model with higher complexity than the required model to improve the prediction ability of the training data, thereby achieving better regression analysis results. However, in actual testing, due to the lack of good generalization ability, it is easy to cause "overfitting", which is not conducive to establishing a vulnerability exploitation score prediction logistic regression model. To address this problem, the embodiment of the present application adopts the L2 regularization method and introduces a regularization term in formula (3), as shown in formula (4):

[0076]

[0077] Among them, α is a hyperparameter used to control the penalty intensity of the regular term. The larger it is, the smaller the final weight will be; m is the number of samples.

[0078] After the basic model is built, the training set is used to train the basic model. The training results are verified using the validation set. When verifying, the embodiment of the present application mainly uses the area AUC enclosed by the coordinate axis under the ROC curve (Receiver Operating Characteristic curve) as an evaluation indicator. It comprehensively considers sensitivity and specificity, and is the standard method for model evaluation at present. In the evaluation process, the larger the AUC value, the more ideal the effect of the model.

[0079] After obtaining the prediction model, the system is monitored. When the system is detected to have a current vulnerability, the prediction model is used to predict the current vulnerability and obtain the severity score of the current vulnerability output by the prediction model. For the specific training process and prediction process, please refer to Figure 2 The process shown is carried out.

[0080] After obtaining the criticality score of the current vulnerability, each current vulnerability is eliminated and controlled in order according to the criticality score of each current vulnerability. Different methods can be used when performing specific elimination and control. For example, the first elimination and control method: according to the level of criticality score, vulnerabilities with high criticality are prioritized. The second elimination and control method: vulnerabilities greater than or equal to the preset score threshold are prioritized. The third elimination and control method: For vulnerabilities less than the preset score threshold, no processing is performed, and for vulnerabilities greater than or equal to the preset score threshold, they are processed according to the level of criticality score.

[0081] In an optional implementation, Table 1 below lists some randomly selected vulnerabilities from 2020 to 2022 and their specific examples of criticality scores, for example: the vulnerability numbered CVE-2022-28605, CVSS score 10.0, is classified as a high-risk vulnerability. If the vulnerability is repaired according to the CVSS score, it is ranked first and repaired first. The collected features of the vulnerability are used as the input of the L2 logistic regression model, and the criticality score of the vulnerability is 1.06. The repair level is classified as low, and the repair order is later and can be temporarily not repaired.

[0082] Table 1 Examples of characteristics of some vulnerabilities and their severity scores

[0083]

[0084] Comparing the CVSSv3 scores of the above 20 vulnerabilities and the scores of the method of this application, the priority repair score threshold is 7.0. Using the CVSSv3 score, 15 vulnerabilities are prioritized for repair, while using the method of this application, 5 are prioritized for repair. The method of this application greatly reduces the number of vulnerabilities that need to be repaired first, allowing security operators to deal with vulnerabilities that can cause huge risks in a limited time.

[0085] This application uses an L2 regularized logistic regression model to model and analyze the various features of vulnerability data and the vulnerability's severity score. When the various features of vulnerability data are known, the severity score of the vulnerability can be predicted, so that the vulnerability treatment priority can be sorted according to the vulnerability's severity score. This solution can take into account the vulnerability severity score when determining the vulnerability treatment priority, and also consider whether the vulnerability is known to be actively exploited, which allows security operations personnel to prioritize the vulnerabilities that pose the greatest risk to themselves.

[0086] Figure 3 A schematic diagram of the structure of a vulnerability elimination device provided in an embodiment of the present application is shown, and the device includes:

[0087] An analysis module is used to analyze the historical vulnerability attack events and determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate an actual attack in the attack event;

[0088] A training module is used to use the characteristic values ​​of the sample data in the training set under each target characteristic dimension as the input of the basic model, train the basic model, and obtain a prediction model when a preset cutoff condition is met;

[0089] A prediction module, used to predict each current vulnerability using the prediction model when a current vulnerability of the system is detected, and obtain a criticality score of each current vulnerability;

[0090] The elimination control module is used to perform elimination control processing on each of the current vulnerabilities in sequence according to the harmfulness score of each of the current vulnerabilities.

[0091] The analysis of historical vulnerabilities that have generated attack events to determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events includes:

[0092] Analyze the historical vulnerability attack events using the first analysis method to determine the first characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack;

[0093] Using the second analysis method, analyzing the historical vulnerability-generated attack events, and determining the second characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack;

[0094] The target feature dimension is obtained according to the first feature dimension and the second feature dimension.

[0095] The first analysis method is used to analyze the historical vulnerability attack events to determine the first characteristic dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event, including:

[0096] Performing statistical analysis on the target vulnerabilities in the attack incidents and the features contained in the target vulnerabilities;

[0097] The feature whose occurrence frequency in the target vulnerability is greater than or equal to a preset frequency threshold is used as the first feature dimension.

[0098] The second analysis method is used to analyze the historical vulnerability attack events to determine the second characteristic dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event, including:

[0099] Displaying the target vulnerability in the attack event through a graphical user interface;

[0100] In response to a vulnerability selection operation, a feature included in a target vulnerability corresponding to the vulnerability selection is used as the second feature dimension.

[0101] The analysis of historical vulnerabilities that have generated attack events to determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events includes:

[0102] Analyze the historical vulnerabilities that have caused attack events, and determine the manufacturer characteristics, vulnerability exploit code characteristics, vulnerability type characteristics and scoring system indicator characteristics that affect the probability of the vulnerability being exploited and causing actual attacks in the attack events.

[0103] The base model is constructed in the following way:

[0104] Constructing basic items of model parameters according to the occurrence probability of the sample data and the characteristic values ​​of each target characteristic dimension of the sample data;

[0105] constructing regularization terms for the model parameters;

[0106] The basic model is constructed according to the model parameters, the basic terms and the regularization terms.

[0107] The process of performing control and elimination processing on each of the current vulnerabilities in order according to the severity score of each of the current vulnerabilities includes:

[0108] If the criticality score of the current vulnerability is greater than or equal to the preset score threshold, the vulnerability elimination and control processing are performed in sequence according to the priority order of the current vulnerability;

[0109] If the criticality score of the current vulnerability is less than a preset score threshold, the current vulnerability will not be processed.

[0110] like Figure 4 As shown, an embodiment of the present application provides an electronic device for executing the vulnerability elimination method in the present application, the device includes a memory, a processor, a bus, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the vulnerability elimination method when executing the computer program.

[0111] Specifically, the above-mentioned memory and processor may be general-purpose memory and processor, which are not specifically limited here. When the processor runs the computer program stored in the memory, the above-mentioned vulnerability elimination method can be executed.

[0112] Corresponding to the vulnerability control method in the present application, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned vulnerability control method are executed.

[0113] Specifically, the storage medium can be a general storage medium, such as a mobile disk, a hard disk, etc. When the computer program on the storage medium is run, the above-mentioned vulnerability elimination method can be executed.

[0114] In the embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. The system embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of systems or units, which can be electrical, mechanical or other forms.

[0115] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, and may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0116] In addition, each functional unit in the embodiments provided in the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0117] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0118] It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance.

[0119] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-mentioned embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-mentioned embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application. They should all be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A method for vulnerability elimination and control, characterized in that: The method comprises: Analyze the historical vulnerabilities that have caused attack events, and determine the target feature dimensions that affect the probability of the vulnerability being exploited to cause an actual attack in the attack events; Taking the characteristic values ​​of the sample data in the training set under each target characteristic dimension as the input of the basic model, training the basic model, and obtaining the prediction model when the preset cutoff condition is met; When a current vulnerability of the system is detected, the prediction model is used to predict each current vulnerability to obtain a criticality score of each current vulnerability; According to the criticality score of each current vulnerability, each current vulnerability is eliminated and controlled in sequence.

2. The method according to claim 1, characterized in that The analysis of historical vulnerabilities that have generated attack events to determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events includes: Analyze the historical vulnerability-generated attack events using the first analysis method to determine the first characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack; Using the second analysis method, analyzing the historical vulnerability-generated attack events, and determining the second characteristic dimension in the attack event that affects the probability of the vulnerability being exploited to generate an actual attack; The target feature dimension is obtained according to the first feature dimension and the second feature dimension.

3. The method according to claim 2, characterized in that The first analysis method is used to analyze the historical vulnerability attack events to determine the first characteristic dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event, including: Performing statistical analysis on the target vulnerabilities in the attack incidents and the features contained in the target vulnerabilities; The feature whose occurrence frequency in the target vulnerability is greater than or equal to a preset frequency threshold is used as the first feature dimension.

4. The method according to claim 1, characterized in that: The second analysis method is used to analyze the historical vulnerability attack events to determine the second characteristic dimension that affects the probability of the vulnerability being exploited to generate an actual attack in the attack event, including: Displaying the target vulnerability in the attack event through a graphical user interface; In response to a vulnerability selection operation, a feature included in a target vulnerability corresponding to the vulnerability selection is used as the second feature dimension.

5. The method according to claim 1, characterized in that The analysis of historical vulnerabilities that have generated attack events to determine the target feature dimensions that affect the probability of the vulnerability being exploited to generate actual attacks in the attack events includes: Analyze the historical vulnerabilities that have caused attack events, and determine the manufacturer characteristics, vulnerability exploit code characteristics, vulnerability type characteristics and scoring system indicator characteristics that affect the probability of the vulnerability being exploited and causing actual attacks in the attack events.

6. The method according to claim 1, characterized in that The method constructs the basic model in the following way: Constructing basic items of model parameters according to the occurrence probability of the sample data and the characteristic values ​​of each target characteristic dimension of the sample data; constructing regularization terms for the model parameters; The basic model is constructed according to the model parameters, the basic terms and the regularization terms.

7. The method according to claim 1, characterized in that The process of performing control and elimination processing on each of the current vulnerabilities in order according to the severity score of each of the current vulnerabilities includes: If the criticality score of the current vulnerability is greater than or equal to a preset score threshold, the vulnerability is eliminated and controlled in sequence according to the priority order of the current vulnerability; If the criticality score of the current vulnerability is less than a preset score threshold, the current vulnerability will not be processed.

8. A device for eliminating loopholes, characterized in that: The device comprises: An analysis module is used to analyze the historical vulnerability-generated attack events and determine the target feature dimensions in the attack events that affect the probability of the vulnerability being exploited to generate an actual attack; A training module is used to use the characteristic values ​​of the sample data in the training set under each target characteristic dimension as the input of the basic model, train the basic model, and obtain a prediction model when a preset cutoff condition is met; A prediction module, for predicting each current vulnerability using the prediction model when a current vulnerability of the system is detected, and obtaining a criticality score of each current vulnerability; The elimination control module is used to perform elimination control processing on each of the current vulnerabilities in sequence according to the harmfulness score of each of the current vulnerabilities.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the vulnerability mitigation method as described in any one of claims 1 to 7 are performed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the vulnerability mitigation method as described in any one of claims 1 to 7.