Product correlation analysis method and device influenced by vulnerabilities, equipment and medium

The product correlation correlation table is constructed through the FP-Growth algorithm, which solves the problem of difficult-to-predict the scope of vulnerability impact and realizes early warning and prevention of the product range affected by vulnerability.

CN120012116APending Publication Date: 2025-05-16CHINA INFORMATION TECH SECURITY EVALUATION CENT
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510190322.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

During the process of loopholes or vulnerabilities, it is difficult for security personnel to understand whether other products will be affected by the same vulnerability, making it difficult to predict and prevent the affected product range.

Method used

The FP-Growth algorithm of association rules is used to build an FP tree and mine frequent item sets, and the product correlation correlation table affected by vulnerabilities is established, and the association relationship between different products and the probability of vulnerability impact are calculated.

Benefits of technology

After the vulnerability is disclosed, the product range affected by the vulnerability can be predicted, warnings and protection can be carried out in advance, and risk identification and prevention capabilities for safe operations can be improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012116A_ABST
    Figure CN120012116A_ABST
Patent Text Reader

Abstract

The invention provides a correlation analysis method and device for products influenced by vulnerabilities, equipment and a medium, and the method comprises the steps: obtaining all disclosed products influenced by the vulnerabilities, and obtaining a vulnerability-influenced product set containing all the products influenced by the vulnerabilities; establishing an FP tree according to the vulnerability influence product set corresponding to each vulnerability; traversing each branch in the FP tree, and mining a plurality of frequent item sets from the FP tree; for any two of a first target product and a second target product in the target products, according to a third support degree corresponding to the first target product and a third support degree corresponding to a frequent item set containing the first target product and the second target product, calculating the number of frequent item sets of the first target product and the second target product when the first target product is influenced by vulnerabilities; according to the probability that the second target product is influenced by the vulnerabilities, constructing a product correlation association table influenced by the vulnerabilities. According to the method, the association rule FP-Growth algorithm is used for analysis, and the association relationship between different products is obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, equipment and medium for analyzing the correlation of products affected by vulnerabilities. Background Art

[0002] Predicting the impact scope of a vulnerability is an important task in the field of network security. During the process of vulnerability discovery or mining, when one product is affected by a vulnerability, it is difficult for security personnel to know whether other products will also be affected by the vulnerability. Summary of the invention

[0003] In view of this, the purpose of the present application is to provide a method, device, equipment and medium for analyzing the correlation of products affected by vulnerabilities, so as to obtain the correlation between different products by using the association rule FP-Growth algorithm for analysis, that is, the probability that the product has a vulnerability and its associated products have a vulnerability is predicted. After the vulnerability is disclosed, the scheme can use the constructed correlation relationship to predict the range of products affected by the vulnerability, and can provide early warning when the associated products are unaware of the vulnerability, so that security operators can timely discover potential risks and take early protection against the vulnerability.

[0004] In a first aspect, an embodiment of the present application provides a method for analyzing product correlations affected by a vulnerability, including:

[0005] For known vulnerabilities, obtain each product that has been disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes each product affected by the vulnerability;

[0006] An FP tree is established according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes a plurality of branches extending from the same root node, and each branch corresponds to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, and each of the other nodes includes a target product in the vulnerability impact product set corresponding to the branch and a first support of the target product on the branch; the target product is a product among the products whose second expenditure is greater than a preset support; the second support is the number of times the product appears in each of the vulnerability impact product sets;

[0007] Traversing each branch in the FP tree, mining multiple frequent item sets from the FP tree; wherein each of the frequent item sets contains at least one product and a third support corresponding to the frequent item set; the third support is used to characterize the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability;

[0008] For any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability is calculated based on the third support corresponding to the first target product and the third support corresponding to the frequent item set containing the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

[0009] In combination with the first aspect, the embodiment of the present application provides a first possible implementation of the first aspect, wherein, after constructing a product correlation association table affected by the vulnerability, the method further includes:

[0010] When any target product is affected by the target vulnerability, the probability of other target products being affected by the vulnerability when the target product is affected by the vulnerability is queried from the product correlation association table affected by the vulnerability, and the queried probability is used as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is a vulnerability other than the known vulnerability.

[0011] In combination with the first aspect, the embodiment of the present application provides a second possible implementation of the first aspect, wherein the step of establishing a FP tree according to the set of vulnerability-affected products corresponding to each vulnerability includes:

[0012] A header table is established according to the set of vulnerability-affected products corresponding to each vulnerability; wherein the header table contains the second support corresponding to each target product; the target products are arranged in the header table in descending order according to the second support;

[0013] For each of the vulnerability-affected product sets, non-target products are removed from the vulnerability-affected product set to obtain a new vulnerability-affected product set, and in the new vulnerability-affected product set, the target products are arranged in descending order according to the second support degree of each target product; wherein the non-target product is a product among the products, the second expenditure degree of which is not greater than the preset support degree;

[0014] Build a FP tree based on each new vulnerability affecting the product set.

[0015] In combination with the second possible implementation of the first aspect, the embodiment of the present application provides a third possible implementation of the first aspect, wherein the step of establishing a FP tree according to each new set of vulnerability-affected products includes:

[0016] Create a root node;

[0017] Traversing each new set of products affected by vulnerabilities, for each target product in the new set of products affected by vulnerabilities that has not been inserted into the FP tree, determining whether the FP tree at the current stage has established corresponding nodes of at least some of the target products in the new set of products affected by vulnerabilities in descending order of the second support of each target product in the new set of products affected by vulnerabilities, starting from the root node; wherein the corresponding node of the target product with the largest second support among the target products in the new set of products affected by vulnerabilities is connected to the root node;

[0018] If the corresponding nodes of at least some of the target products among the target products are not established in the FP tree at the current stage, starting from the root node, new nodes and connection relationships between the nodes are constructed for each target product in descending order of the second support of each target product, and counting is performed in the newly-created nodes;

[0019] If corresponding nodes of at least some of the target products have been established in the FP tree of the current stage, then in the order of the second support from large to small and the order of the existing nodes, the existing nodes are reused, and the counting is performed incrementally in the existing nodes, and in the order of the second support from large to small, new nodes are constructed for the target products without corresponding nodes behind the reused existing nodes, and the connection relationship between the nodes is constructed, and the counting is performed in the newly created nodes;

[0020] After traversing all new vulnerability-affected product sets, the final FP tree is obtained; wherein the count of each node in the final FP tree is the first support of the target product corresponding to the node.

[0021] In combination with the second possible implementation of the first aspect, the embodiment of the present application provides a fourth possible implementation of the first aspect, wherein traversing each branch in the FP tree to mine multiple frequent item sets from the FP tree includes:

[0022] According to the order of the second support in the header table from small to large, determine the target product to be mined and determine the node corresponding to the target product as the FP subtree corresponding to the leaf node;

[0023] The count of each node in the FP subtree is set to the count of the leaf node, and the nodes whose count is lower than the preset support are deleted to determine the frequent itemsets corresponding to the target product through recursive mining;

[0024] Repeat the process of determining the current target product to be mined and subsequent steps in the order of the second support in the item header table from small to large, until all target products are mined and the frequent item sets corresponding to each target product are obtained.

[0025] In combination with the first aspect, an embodiment of the present application provides a fifth possible implementation of the first aspect, wherein, for any two first target products and second target products among the target products, according to the third support corresponding to the first target product and the third support corresponding to the frequent item set including the first target product and the second target product, calculating the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability includes:

[0026] The probability that the second target product M is affected by the vulnerability when the first target product N is affected by the vulnerability is calculated by the following formula:

[0027]

[0028] Among them, support count (N∪M) represents the sum of the third support corresponding to each frequent item set containing the first target product and the second target product, and support count (N) represents the third support of the first target product N.

[0029] In a second aspect, an embodiment of the present application further provides a device for analyzing product correlations affected by a vulnerability, including:

[0030] An acquisition module is used to acquire, for a known vulnerability, various products that have been disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes various products affected by the vulnerability;

[0031] A building module is used to build an FP tree according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes a plurality of branches extending from the same root node, each branch corresponds to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, each of the other nodes respectively includes a target product in the vulnerability impact product set corresponding to the branch and a first support of the target product on the branch; the target product is a product among the products whose second expenditure is greater than a preset support; the second support is the number of times the product appears in each of the vulnerability impact product sets;

[0032] A mining module, used to traverse each branch in the FP tree and mine multiple frequent item sets from the FP tree; wherein each of the frequent item sets contains at least one product and a third support corresponding to the frequent item set; the third support is used to characterize the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability;

[0033] A calculation module is used to calculate, for any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability based on the third support corresponding to the first target product and the third support corresponding to the frequent item set containing the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

[0034] In combination with the second aspect, the embodiment of the present application provides a first possible implementation of the second aspect, wherein the device further includes:

[0035] A query module is used to query the probability of other target products being affected by the vulnerability from the product correlation association table when any target product is affected by the target vulnerability after the calculation module constructs the product correlation association table affected by the vulnerability, and use the queried probability as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is other vulnerabilities other than the known vulnerabilities.

[0036] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps in any possible implementation of the first aspect above are performed.

[0037] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in any possible implementation of the first aspect described above are executed.

[0038] The method, device, equipment and medium for analyzing the correlation of products affected by the vulnerability provided in the embodiments of the present application use the association rule FP-Growth algorithm to analyze the historical data of products affected by the vulnerability (i.e., one vulnerability has multiple affected products), and can obtain the correlation between different products, i.e., the probability that the product has a vulnerability and its associated products have a vulnerability at the same time, thereby constructing a correlation table of products affected by the vulnerability. After the vulnerability is disclosed, the solution can use the constructed correlation table of products affected by the vulnerability to predict the range of products affected by the vulnerability, and can provide early warnings in the case that the associated products are unaware of the vulnerability, so that security operators can promptly discover potential risks and take early protection against the vulnerability.

[0039] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0041] Figure 1 A flowchart of a method for analyzing product correlations affected by vulnerabilities provided by an embodiment of the present application is shown;

[0042] Figure 2 A schematic diagram showing a process of establishing an FP tree provided in an embodiment of the present application is shown;

[0043] Figure 3 A schematic diagram showing a second process of establishing an FP tree provided in an embodiment of the present application is shown;

[0044] Figure 4 A schematic diagram showing a third process of establishing an FP tree provided in an embodiment of the present application is shown;

[0045] Figure 5 A schematic diagram showing a fourth process of establishing an FP tree provided in an embodiment of the present application is shown;

[0046] Figure 6 A schematic diagram of a built FP tree provided in an embodiment of the present application is shown;

[0047] Figure 7 A schematic diagram of an FP subtree provided in an embodiment of the present application is shown;

[0048] Figure 8 A schematic diagram of a second FP subtree provided in an embodiment of the present application is shown;

[0049] Fig. 9 A schematic diagram of a third FP subtree provided in an embodiment of the present application is shown;

[0050] Fig.10 A schematic diagram of the structure of a device for analyzing product correlations affected by vulnerabilities provided in an embodiment of the present application is shown;

[0051] Fig.11 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0052] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0053] Considering that in the process of vulnerability discovery or vulnerability mining, when one product is affected by a vulnerability, it is difficult for security personnel to know whether other products are also affected by the vulnerability. Based on this, the embodiments of the present application provide a method, device, equipment and medium for analyzing the correlation of products affected by the vulnerability, which are described below through embodiments.

[0054] To facilitate understanding of this embodiment, a method for analyzing product correlations affected by a vulnerability disclosed in an embodiment of this application is first described in detail. Figure 1 As shown, the following steps S101-S104 are included:

[0055] S101: For a known vulnerability, obtain each product that is disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes each product affected by the vulnerability.

[0056] In this embodiment, the known vulnerability refers to a currently existing vulnerability, which may be a software vulnerability, a hardware vulnerability, a component vulnerability, etc. The disclosed products affected by the vulnerability refer to the products currently known to be affected by the vulnerability, and the products affected by the vulnerability may refer to the products attacked by the vulnerability.

[0057] The product in this embodiment may refer to a single product or a version of a product. That is, different product versions in this embodiment may be regarded as different products.

[0058] In a possible implementation manner, when executing step S101, the following steps S1011-S1013 may be specifically performed:

[0059] S1011: For known vulnerabilities, obtain the products that have been disclosed to be affected by the vulnerability;

[0060] S1012: Preprocess the product corresponding to each acquired vulnerability to obtain the preprocessed product corresponding to each vulnerability; the preprocessing includes any one or more of the following: data deduplication, invalid value processing, missing value processing, and data normalization.

[0061] In this embodiment, since the acquired products affected by the vulnerability may contain duplicate information, invalid values, or missing values, it is necessary to deduplicate data, process invalid values, process missing values, etc. for the product corresponding to each vulnerability.

[0062] Furthermore, since the data formats of various products affected by the vulnerability may be different, it is necessary to normalize the data of the products corresponding to each vulnerability.

[0063] S1013: Store each product affected by the vulnerability into a vulnerability-affected product set corresponding to the vulnerability.

[0064] For example, as shown in Table 1 below, the vulnerability impact product sets corresponding to vulnerabilities 1 to 9 in this example are shown:

[0065] Vulnerabilities Vulnerability Affects Product Set Vulnerability 1 Product A, Product B, Product E Vulnerability 2 Product B, Product D Vulnerability 3 Product B, Product C Vulnerability 4 Product A, Product B, Product D Vulnerability 5 Product A, Product C Vulnerability 6 Product B, Product C Vulnerability 7 Product A, Product C Vulnerability 8 Product A, Product B, Product C, Product E Vulnerability 9 Product A, Product B, Product C, Product F

[0066] Table 1

[0067] It is worth noting that the "Product A, Product B, Product C, Product D, Product E, Product F" in the above example can be different product versions of the same product or different products.

[0068] S102: Establish an FP tree according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes multiple branches extending from the same root node, and each branch corresponds to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, and each other node includes a target product in the vulnerability impact product set corresponding to the branch and the first support of the target product on the branch; the target product is a product among the products, the second expenditure of which is greater than the preset support; the second support is the number of times the product appears in each vulnerability impact product set.

[0069] In a possible implementation manner, when executing step S102, the following steps S1021-S1023 may be specifically performed:

[0070] S1021: Establish an item header table according to the set of vulnerability-affected products corresponding to each vulnerability; wherein the item header table contains the second support corresponding to each target product; the target products are arranged in the item header table in descending order according to the second support.

[0071] In this embodiment, for each product, the number of occurrences of the product in each vulnerability-affected product set is counted, and the number of occurrences is used as the second support of the product. Exemplarily, following the above example, the second support of each product can be calculated, as shown in Table 2 below:

[0072] product Second support Product A 6 Product B 7 Product C 6 Product D 2 Product E 2 Product F 1

[0073] Table 2

[0074] Next, products whose second support is not greater than (ie, less than or equal to) a preset support are determined as non-target products, and products whose second support is greater than a preset support are determined as target products.

[0075] In this example, if the preset support is 1, then product A, product B, product C, product D, and product E can all be used as target products, and product F is a non-target product.

[0076] For the target products, the target products are sorted in descending order according to the second support, and a header table is obtained. For example, Table 3 shows the header table obtained in this example:

[0077] product Second support Target product B 7 Target product A 6 Target Product C 6 Target product D 2 Target Product E 2

[0078] Table 3

[0079] S1022: For each vulnerability-affected product set, remove non-target products from the vulnerability-affected product set to obtain a new vulnerability-affected product set, and arrange the target products in the new vulnerability-affected product set in descending order according to the second support of each target product; wherein the non-target product is a product whose second support is not greater than a preset support.

[0080] For example, for each vulnerability-affected product set in Table 1, remove the non-target product F from each vulnerability-affected product set to obtain a new vulnerability-affected product set. For example, remove the non-target product F from the vulnerability-affected product set corresponding to vulnerability 9.

[0081] In the new set of products affected by vulnerabilities, each target product is arranged in descending order according to the second support. Table 4 shows the new set of products affected by vulnerabilities in this example:

[0082] Vulnerabilities New vulnerabilities affect product set Vulnerability 1 Target product B, target product A, target product E Vulnerability 2 Target product B, target product D Vulnerability 3 Target product B, target product C Vulnerability 4 Target product B, target product A, target product D Vulnerability 5 Target product A, target product C Vulnerability 6 Target product B, target product C Vulnerability 7 Target product A, target product C Vulnerability 8 Target product B, target product A, target product C, target product E Vulnerability 9 Target product B, target product A, target product C

[0083] Table 4

[0084] S1023: Establish an FP tree (FP Tree algorithm) according to each new vulnerability-affected product set.

[0085] In a possible implementation manner, when executing step S1023, the following steps S10231-S10235 may be specifically performed:

[0086] S10231: Establish a root node;

[0087] S10232: traverse each new set of vulnerability-affected products, and for each target product in the new set of vulnerability-affected products that has not been inserted into the FP tree, determine whether the corresponding nodes of at least some of the target products in the new set of vulnerability-affected products have been established in the FP tree at the current stage in the order of the second support of each target product in the new set of vulnerability-affected products from large to small, starting from the root node; wherein the corresponding node of the target product with the largest second support among the target products in the new set of vulnerability-affected products is connected to the root node;

[0088] S10233: If the corresponding nodes of at least some of the target products in each target product are not established in the FP tree at the current stage, starting from the root node, in the order of the second support of each target product from large to small, construct the new node and the connection relationship between the nodes for each target product, and count in the newly created node;

[0089] S10234: If corresponding nodes for at least some of the target products have been established in the FP tree of the current stage, then in the order of the second support from large to small and the order of the existing nodes, the existing nodes are reused, and counted incrementally in the existing nodes, and in the order of the second support from large to small, new nodes are constructed for the target products without corresponding nodes after the reused existing nodes, and connection relationships between the nodes are constructed, and counted in the newly created nodes;

[0090] S10235: After traversing all new vulnerability-affected product sets, a final FP tree is obtained; wherein the count of each node in the final FP tree is the first support of the target product corresponding to the node.

[0091] Exemplarily, establish a root node null; traverse each new vulnerability-affected product set, and for each target product "target product B, target product A, target product E" in the new vulnerability-affected product set that has not been inserted into the FP tree (corresponding to vulnerability 1), determine whether the FP tree at the current stage has established corresponding nodes for at least some of the target products in "target product B, target product A, target product E" in the order of "target product B, target product A, target product E" with the root node as the starting point.

[0092] If the corresponding nodes of at least some of the target products in "target product B, target product A, target product E" are not established in the FP tree at the current stage, then Figure 2 As shown, starting from the root node, new nodes and connection relationships between nodes are constructed for target product B, target product A, and target product E in the order of the second support from large to small, and counted in the newly created nodes. At this time, the count of all newly created nodes is 1.

[0093] Then, for each target product "target product B, target product D" in the product set affected by the new vulnerability that has not been inserted into the FP tree (corresponding to vulnerability 2), determine whether the FP tree at the current stage has established corresponding nodes for at least some of the target products in "target product B, target product D" in the order of "target product B, target product D" and starting from the root node.

[0094] like Figure 2 As shown in , the corresponding node of the target product B has been established in the FP tree at the current stage. Therefore, at this time, according to the order of the second support from large to small and the order of the existing nodes, as shown in Figure 3 As shown, the corresponding node of the target product B is reused, and the count is incremented in the existing nodes. At this time, the count of the existing nodes (the nodes corresponding to the target product B) is 2. And in the order of the second support from large to small, a new node is constructed for the target product D that has no corresponding node after the reused existing node (the node corresponding to the target product B), and the connection relationship between the node of the target product B and the node of the target product D is constructed, and the count is performed in the newly created node (the node corresponding to the target product D). At this time, the count of the newly created node is 1.

[0095] For each target product "target product B, target product C" in the product set affected by the new vulnerability that has not been inserted into the FP tree (corresponding to vulnerability 3), determine whether the FP tree at the current stage has established corresponding nodes for at least some of the target products in "target product B, target product C" in the order of "target product B, target product C" and starting from the root node.

[0096] like Figure 3 As shown, the corresponding node of the target product B has been established in the FP tree of the current stage. Figure 4As shown, in the order of the second support from large to small and the order of the existing nodes, the corresponding nodes of the target product B are reused, and the count is incremented in the existing nodes. At this time, the count of the existing nodes (the nodes corresponding to the target product B) is 3. And in the order of the second support from large to small, a new node is constructed for the target product C that has no corresponding node after the reused existing node (the node corresponding to the target product B), and the connection relationship between the node of the target product B and the product of the target product C is constructed, and the count is performed in the newly created node (the node corresponding to the target product C). At this time, the count of the newly created node is 1.

[0097] For each target product "target product B, target product A, target product D" in the product set affected by the new vulnerability that has not been inserted into the FP tree (corresponding to vulnerability 4), determine whether the FP tree at the current stage has established corresponding nodes for at least some of the target products in "target product B, target product A, target product D" in the order of "target product B, target product A, target product D" with the root node as the starting point.

[0098] like Figure 4 As shown, in the current stage of the FP tree, the corresponding nodes of target product B and target product A have been established. At this time, Figure 5 As shown, in the order of the second support from large to small and the order of the existing nodes (the corresponding nodes of the target product B and the target product A), the corresponding nodes of the target product B and the target product A are reused, and the count is incremented in the existing nodes. At this time, the node count corresponding to the target product B is 4, and the node count corresponding to the target product A is 2. And in the order of the second support from large to small, a new node is constructed for the target product D that has no corresponding node after the reused existing nodes (target product B and target product A), and a connection relationship is established between the node of the target product A and the node of the target product D, and counting is performed in the newly created node (the node corresponding to the target product D), and the newly created node count is 1 at this time.

[0099] By analogy, after traversing all new vulnerability-affected product sets, we can get the following example: Figure 6 The final FP tree shown in FIG. 1 is a tree in which the count of each node is the first support of the target product corresponding to the node. For example, if the count of the node of target product A is 4, then the first support of target product A is 4.

[0100] S103: traverse each branch in the FP tree and mine multiple frequent item sets from the FP tree; each frequent item set contains at least one product and the third support corresponding to the frequent item set; the third support is used to characterize the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability.

[0101] In a possible implementation manner, when executing step S103, the following steps S1031-S1033 may be performed:

[0102] S1031: Determine the target product to be mined and the node corresponding to the target product as the FP subtree corresponding to the leaf node according to the order of the second support in the header table from small to large;

[0103] S1032: setting the count of each node in the FP subtree to the count of the leaf node, and deleting the nodes whose counts are lower than the preset support, so as to determine the frequent itemsets corresponding to the target product through recursive mining;

[0104] S1033: Repeat steps S1031-S1032 until all target products are mined and the frequent item sets corresponding to each target product are obtained.

[0105] For example, as shown in Table 3, the second support of target product E is the smallest and it is located at the end of the header table. Therefore, the target product to be mined is target product E. Since there are two leaf nodes corresponding to target product E, the FP subtree corresponding to the node corresponding to target product E as a leaf node is as follows: Figure 7 As shown in the figure on the left.

[0106] like Figure 7 As shown in the figure on the right, the count of each node in the FP subtree is set to the count of the leaf node. In this example, if the preset support is 1, then there is no node that needs to be deleted in the FP subtree. At this time, through recursive mining, it can be determined that the frequent item sets corresponding to the target product E include: {E:2}, {B:2, E:2}, {A:2, E:2}, {C:1, E:1}, {B:2, A:2, E:2}, {B:1, C:1, E:1}, {B:1, A:1, C:1, E:1}.

[0107] After mining the target product E, we start mining the target product D. Since there are two leaf nodes corresponding to the target product D, the FP subtree corresponding to the node corresponding to the target product D as a leaf node is as follows: Figure 8 As shown in the figure on the left.

[0108] like Figure 8 As shown in the figure on the right, the count of each node in the FP subtree is set to the count of the leaf node. In this example, if the preset support is 1, then there is no node that needs to be deleted in the FP subtree. At this time, through recursive mining, it can be determined that the frequent item sets corresponding to the target product D include: {D:2}, {B:2, D:2}, {A:1, D:1}, {B:1, A:1, D:1}.

[0109] Next, we start mining the target product C. The node corresponding to the target product C is the FP subtree corresponding to the leaf node. Fig. 9 Shown on the left.

[0110] like Fig. 9 As shown in the figure on the right, the count of each node in the FP subtree is set to the count of the leaf node. Through recursive mining, it can be determined that the frequent item sets corresponding to the target product D include: {C:6}, {B:2, C:2}, {A:2, C:2}.

[0111] In this embodiment, since the node of target product A and the node of target product B are not leaf nodes, the frequent item set of target product A includes {A:6}, and the frequent item set of target product B includes {B:7}.

[0112] S104: For any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability is calculated according to the third support corresponding to the first target product and the third support corresponding to the frequent item set including the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

[0113] In a possible implementation, the probability that the second target product M is affected by the vulnerability when the first target product N is affected by the vulnerability can be calculated by the following formula:

[0114]

[0115] Among them, support count (N∪M) represents the sum of the third support corresponding to each frequent item set containing the first target product and the second target product, and support count (N) represents the third support of the first target product N.

[0116] Exemplarily, the first target product A and the second target product B are taken as an example for description, wherein the third support degree of the first target product A is 6.

[0117] Since the frequent item set {B:2, A:2, E:2} includes the first target product A and the second target product B, the frequent item set {B:1, A:1, C:1, E:1} includes the first target product A and the second target product B, and the frequent item set {B:1, A:1, D:1} includes the first target product A and the second target product B. Therefore, the sum of the third supports corresponding to the frequent item sets including the first target product and the second target product is: 2+1+1=4.

[0118] At this point, the probability that the second target product B is affected by the vulnerability when the first target product A is affected by the vulnerability can be calculated using the following formula:

[0119]

[0120] For example, as shown in Table 5, a correlation table of some products affected by the vulnerability is shown:

[0121] Target products known to be affected by the vulnerability Predict target products affected by vulnerabilities Relevance A B 66.7% A C 66.7% A E 33.3% ... ... ...

[0122] Table 5

[0123] In a possible implementation, after constructing the product correlation association table affected by the vulnerability, the following steps may be performed:

[0124] When any target product is affected by the target vulnerability, the probability of other target products being affected by the vulnerability when the target product is affected by the vulnerability is queried from the product correlation association table affected by the vulnerability, and the queried probability is used as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is a vulnerability other than the known vulnerability.

[0125] For example, when target product A is affected by the target vulnerability, the probability (66.7%) that target product B will also be affected by the target vulnerability when target product A is affected by the vulnerability can be queried from the product correlation association table affected by the vulnerability. The probability (66.7%) that target product C will also be affected by the target vulnerability when target product A is affected by the vulnerability can also be queried. The probability (33.3%) that target product E will be affected by the target vulnerability when target product A is affected by the vulnerability can also be queried.

[0126] Based on the same technical concept, the embodiment of the present application also provides a device for analyzing the correlation of products affected by vulnerabilities, such as Fig.10 As shown, including:

[0127] The acquisition module 1001 is used to acquire, for a known vulnerability, various products that have been disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes various products affected by the vulnerability;

[0128] Establishing module 1002, for establishing an FP tree according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes a plurality of branches extending from the same root node, each branch corresponding to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, each of the other nodes includes a target product in the vulnerability impact product set corresponding to the branch and a first support of the target product on the branch; the target product is a product among the products whose second expenditure is greater than a preset support; the second support is the number of times the product appears in each of the vulnerability impact product sets;

[0129] The mining module 1003 is used to traverse each branch in the FP tree and mine multiple frequent item sets from the FP tree; each of the frequent item sets contains at least one product and a third support corresponding to the frequent item set; the third support is used to represent the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability;

[0130] The calculation module 1004 is used to calculate, for any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability based on the third support corresponding to the first target product and the third support corresponding to the frequent item set containing the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

[0131] Optionally, the device further comprises:

[0132] A query module is used to query the probability of other target products being affected by the vulnerability from the product correlation association table when any target product is affected by the target vulnerability after the calculation module 1004 constructs the product correlation association table affected by the vulnerability, and use the queried probability as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is a vulnerability other than the known vulnerability.

[0133] Optionally, when the establishing module 1002 is used to establish the FP tree according to the vulnerability impact product set corresponding to each vulnerability, it is specifically used to:

[0134] A header table is established according to the set of vulnerability-affected products corresponding to each vulnerability; wherein the header table contains the second support corresponding to each target product; the target products are arranged in the header table in descending order according to the second support;

[0135] For each of the vulnerability-affected product sets, non-target products are removed from the vulnerability-affected product set to obtain a new vulnerability-affected product set, and in the new vulnerability-affected product set, the target products are arranged in descending order according to the second support degree of each target product; wherein the non-target product is a product among the products, the second expenditure degree of which is not greater than the preset support degree;

[0136] Build a FP tree based on each new vulnerability affecting the product set.

[0137] Optionally, when the establishing module 1002 is used to establish the FP tree according to each new set of vulnerability-affected products, it is specifically used to:

[0138] Create a root node;

[0139] Traversing each new set of products affected by vulnerabilities, for each target product in the new set of products affected by vulnerabilities that has not been inserted into the FP tree, determining whether the FP tree at the current stage has established corresponding nodes of at least some of the target products in the new set of products affected by vulnerabilities in descending order of the second support of each target product in the new set of products affected by vulnerabilities, starting from the root node; wherein the corresponding node of the target product with the largest second support among the target products in the new set of products affected by vulnerabilities is connected to the root node;

[0140] If the corresponding nodes of at least some of the target products among the target products are not established in the FP tree at the current stage, starting from the root node, new nodes and connection relationships between the nodes are constructed for each target product in descending order of the second support of each target product, and counting is performed in the newly-created nodes;

[0141] If corresponding nodes of at least some of the target products have been established in the FP tree of the current stage, then in the order of the second support from large to small and the order of the existing nodes, the existing nodes are reused, and the counting is performed incrementally in the existing nodes, and in the order of the second support from large to small, new nodes are constructed for the target products without corresponding nodes behind the reused existing nodes, and the connection relationship between the nodes is constructed, and the counting is performed in the newly created nodes;

[0142] After traversing all new vulnerability-affected product sets, the final FP tree is obtained; wherein the count of each node in the final FP tree is the first support of the target product corresponding to the node.

[0143] Optionally, when the mining module 1003 is used to traverse each branch in the FP tree and mine multiple frequent item sets from the FP tree, it is specifically used to:

[0144] According to the order of the second support in the header table from small to large, determine the target product to be mined and determine the node corresponding to the target product as the FP subtree corresponding to the leaf node;

[0145] The count of each node in the FP subtree is set to the count of the leaf node, and the nodes whose count is lower than the preset support are deleted to determine the frequent itemsets corresponding to the target product through recursive mining;

[0146] Repeat the process of determining the current target product to be mined and subsequent steps in the order of the second support in the item header table from small to large, until all target products are mined and the frequent item sets corresponding to each target product are obtained.

[0147] Optionally, when the calculation module 1004 is used to calculate, for any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability according to the third support corresponding to the first target product and the third support corresponding to the frequent item set including the first target product and the second target product, the probability is specifically used to:

[0148] The probability that the second target product M is affected by the vulnerability when the first target product N is affected by the vulnerability is calculated by the following formula:

[0149]

[0150] Among them, support count (N∪M) represents the sum of the third support corresponding to each frequent item set containing the first target product and the second target product, and support count (N) represents the third support of the first target product N.

[0151] Fig.11 A structural diagram of an electronic device provided for an embodiment of the present application includes: a processor 1101, a memory 1102 and a bus 1103, wherein the memory 1102 stores machine-readable instructions executable by the processor 1101. When the electronic device runs the above-mentioned information processing method, the processor 1101 communicates with the memory 1102 through the bus 1103, and the processor 1101 executes the machine-readable instructions to perform the method steps described in Example 1.

[0152] The embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method steps described in the first embodiment are executed.

[0153] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, electronic devices, and computer-readable storage media can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0154] In the several embodiments provided in the present application, it should be understood that the disclosed methods, devices, electronic devices and computer-readable storage media can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or modules can be electrical, mechanical or other forms.

[0155] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0156] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0157] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0158] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.

Claims

1. A method for analyzing the correlation of products affected by vulnerabilities, characterized in that: include: For known vulnerabilities, obtain each product that has been disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes each product affected by the vulnerability; An FP tree is established according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes a plurality of branches extending from the same root node, and each branch corresponds to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, and each of the other nodes includes a target product in the vulnerability impact product set corresponding to the branch and a first support of the target product on the branch; the target product is a product among the products whose second expenditure is greater than a preset support; the second support is the number of times the product appears in each of the vulnerability impact product sets; Traversing each branch in the FP tree, mining multiple frequent item sets from the FP tree; wherein each of the frequent item sets contains at least one product and a third support corresponding to the frequent item set; the third support is used to characterize the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability; For any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability is calculated based on the third support corresponding to the first target product and the third support corresponding to the frequent item set containing the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

2. The method according to claim 1, characterized in that: After constructing the product correlation association table affected by the vulnerability, the method further includes: When any target product is affected by the target vulnerability, the probability of other target products being affected by the vulnerability when the target product is affected by the vulnerability is queried from the product correlation association table affected by the vulnerability, and the queried probability is used as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is a vulnerability other than the known vulnerability.

3. The method according to claim 1, characterized in that: The FP tree is established according to the set of vulnerability-affected products corresponding to each vulnerability, including: A header table is established according to the set of vulnerability-affected products corresponding to each vulnerability; wherein the header table contains the second support corresponding to each target product; the target products are arranged in the header table in descending order according to the second support; For each of the vulnerability-affected product sets, non-target products are removed from the vulnerability-affected product set to obtain a new vulnerability-affected product set, and in the new vulnerability-affected product set, the target products are arranged in descending order according to the second support degree of each target product; wherein the non-target product is a product among the products, the second expenditure degree of which is not greater than the preset support degree; Build a FP tree based on each new vulnerability affecting the product set.

4. The method according to claim 3, characterized in that: The FP tree is established according to each new vulnerability affecting the product set, including: Create a root node; Traversing each new set of products affected by vulnerabilities, for each target product in the new set of products affected by vulnerabilities that has not been inserted into the FP tree, determining whether the FP tree at the current stage has established corresponding nodes of at least some of the target products in the new set of products affected by vulnerabilities in descending order of the second support of each target product in the new set of products affected by vulnerabilities, starting from the root node; wherein the corresponding node of the target product with the largest second support among the target products in the new set of products affected by vulnerabilities is connected to the root node; If the corresponding nodes of at least some of the target products among the target products are not established in the FP tree at the current stage, starting from the root node, new nodes and connection relationships between the nodes are constructed for each target product in descending order of the second support of each target product, and counting is performed in the newly-created nodes; If corresponding nodes of at least some of the target products have been established in the FP tree of the current stage, then in the order of the second support from large to small and the order of the existing nodes, the existing nodes are reused, and the counting is performed incrementally in the existing nodes, and in the order of the second support from large to small, new nodes are constructed for the target products without corresponding nodes behind the reused existing nodes, and the connection relationship between the nodes is constructed, and the counting is performed in the newly created nodes; After traversing all new vulnerability-affected product sets, the final FP tree is obtained; wherein the count of each node in the final FP tree is the first support of the target product corresponding to the node.

5. The method according to claim 3, characterized in that: The traversing each branch in the FP tree and mining multiple frequent item sets from the FP tree includes: According to the order of the second support in the header table from small to large, determine the target product to be mined and determine the node corresponding to the target product as the FP subtree corresponding to the leaf node; The count of each node in the FP subtree is set to the count of the leaf node, and the nodes whose count is lower than the preset support are deleted to determine the frequent itemsets corresponding to the target product through recursive mining; Repeat the process of determining the current target product to be mined and subsequent steps in the order of the second support in the item header table from small to large, until all target products are mined and the frequent item sets corresponding to each target product are obtained.

6. The method according to claim 1, characterized in that: The calculating, for any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability according to the third support corresponding to the first target product and the third support corresponding to the frequent item set including the first target product and the second target product, includes: The probability that the second target product M is affected by the vulnerability when the first target product N is affected by the vulnerability is calculated by the following formula: Among them, support count (N∪M) represents the sum of the third support corresponding to each frequent item set containing the first target product and the second target product, and support count (N) represents the third support of the first target product N.

7. A device for analyzing the correlation of products affected by vulnerabilities, characterized in that: include: An acquisition module is used to acquire, for a known vulnerability, various products that have been disclosed to be affected by the vulnerability, and obtain a vulnerability-affected product set that includes various products affected by the vulnerability; A building module is used to build an FP tree according to the vulnerability impact product set corresponding to each vulnerability; wherein the FP tree includes a plurality of branches extending from the same root node, each branch corresponds to a vulnerability impact product set; for each branch, the branch includes a root node and other nodes except the root node, each of the other nodes respectively includes a target product in the vulnerability impact product set corresponding to the branch and a first support of the target product on the branch; the target product is a product among the products whose second expenditure is greater than a preset support; the second support is the number of times the product appears in each of the vulnerability impact product sets; A mining module, used to traverse each branch in the FP tree and mine multiple frequent item sets from the FP tree; wherein each of the frequent item sets contains at least one product and a third support corresponding to the frequent item set; the third support is used to characterize the probability that each product contained in the corresponding frequent item set is affected by the same vulnerability; A calculation module is used to calculate, for any two first target products and second target products among the target products, the probability that the second target product is affected by the vulnerability when the first target product is affected by the vulnerability based on the third support corresponding to the first target product and the third support corresponding to the frequent item set containing the first target product and the second target product, so as to construct a correlation association table of products affected by the vulnerability.

8. The device according to claim 7, characterized in that: The device also includes: A query module is used to query the probability of other target products being affected by the vulnerability from the product correlation association table when any target product is affected by the target vulnerability after the calculation module constructs the product correlation association table affected by the vulnerability, and use the queried probability as the probability of other target products being affected by the target vulnerability when the target product is affected by the target vulnerability; the target vulnerability is other vulnerabilities other than the known vulnerabilities.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the method as described in any one of claims 1 to 6 are performed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are executed.

Citation Information

Patent Citations

  • Industrial equipment fault diagnosis method based on association rule mining improved algorithm

    CN115510099A

  • Method and device for predicting products influenced by vulnerabilities

    CN116821915A

  • Correlation analysis method based on industrial control system intrusion detection

    CN117807589A