Heterogeneous network security information processing method and system
By periodically collecting and integrating network security intelligence data sources and using identifiers for data retrieval and matching, the problems of messy data and weak correlation in the existing technology are solved, efficient network security intelligence processing is achieved, timeliness and accuracy are improved, and vulnerability management and defense capabilities are enhanced.
Patent Information
- Application Number
- CN202510171612.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the data content in the network security intelligence data source is messy and has weak correlation, and it is impossible to directly and efficiently provide support for defense work such as network security incident discovery and risk disposal.
By periodically collecting multiple data sources, it is stored in the vulnerability information library, the network full article information library and the PoC/exp resource library. Based on cve_num, cnvd_num or cnnvd_num in the data source, the data from the data source is retrieved, inserted or updated in the vulnerability standard library, match the data in the PoC/exp resource library and the data in the vulnerability standard library, and match the articles in the network full article information library and the data in the vulnerability standard library.
It realizes efficient integration and update of data in network security intelligence data sources, improves the timeliness and accuracy of network security intelligence, enhances vulnerability management and response capabilities, promotes the correlation analysis of PoC/exp and vulnerability information, and supports network security experts to formulate precise defense strategies.
Smart Images

Figure CN120050076A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and relates to a heterogeneous network security intelligence processing method and system. Background Art
[0002] In recent years, global network security incidents have occurred frequently, and new technologies have also accelerated the evolution of attack technologies. Network attacks have shown the characteristics of diversification and complexity. Traditional security strategies mainly focused on defending vulnerabilities are difficult to detect, intercept, and analyze new, persistent, and advanced threats in a timely and effective manner. The security defense and attack requirements have gradually evolved from the traditional, vulnerability-centered passive mode to an active, intelligence-centered construction mode. The construction of a network security intelligence library is an extremely crucial basic and long-term content in information security assurance work. A large number of network information leakage cases and information security problems are closely related to network security intelligence. At present, there are already a large number of network security intelligence data sources, but in actual use, their data content is messy and the relevance is weak, and they cannot directly and efficiently provide support for defense work such as network security event discovery and risk handling. Summary of the Invention
[0003] The purpose of the present invention is to overcome the above-mentioned disadvantages of the prior art, and provide a heterogeneous network security intelligence processing method and system to solve the problems in the prior art that the data content in the network security intelligence data source is difficult to efficiently provide support for defense work such as discovering network security events and risk handling.
[0004] To achieve the above object, the present invention adopts the following technical solutions: A heterogeneous network security intelligence processing method, comprising the following steps: Periodically collect multiple data sources and store them in the corresponding vulnerability information library, network security article information library, and PoC / exp resource library; the data sources are network security intelligence; Based on the cve_num, cnvd_num, or cnnvd_num of the data source in the vulnerability information library, retrieve in the vulnerability standard library, and then insert the data source or merge and update the corresponding data of the data source in the vulnerability standard library; based on cve_num, match the pop or exp in the PoC / exp resource library with the data in the vulnerability standard library; based on cve_num, cnvd_num, or cnnvd_num, match the articles in the network security article information library with the data in the vulnerability standard library; Display the information of the data source.
[0005] A further improvement of the present invention lies in: Preferably, the forms of collecting multiple data sources include full-scale collection, incremental collection, and re-acquisition of error entries.
[0006] Preferably, during the process of periodically collecting multiple data sources, the latest collection time spectrum of each data source is recorded through a collection status information table, and the error information occurring during the data source collection process is recorded through an error information record table.
[0007] Preferably, the process of retrieving in the vulnerability standard library based on the cve_num, cnvd_num, or cnnvd_num of the data source in the vulnerability information library, and then inserting the data source or merging and updating the data corresponding to the data source in the vulnerability standard library is as follows: (1) If the data source does not have cve_num, cnvd_num, and cnnvd_num, discard the data source and set the flag bit to 1; (2) If the cve_num of the data source exists and is unique, retrieve in the vulnerability standard library according to the cve_num. If not retrieved, insert the data source into the vulnerability standard library. If the corresponding cve_num is retrieved, update the data corresponding to the cve_num in the vulnerability standard library with the data source; (3) If the cve_num of the data source does not exist and the cnvd_num exists and is unique, retrieve in the vulnerability standard library according to the cnvd_num. If not retrieved, insert the data source into the vulnerability standard library. If the corresponding cnvd_num is retrieved, update the data corresponding to the cnvd_num in the vulnerability standard library with the data source; (4) If both the cve_num and cnvd_num of the data source do not exist and the cnnvd_num exists and is unique, retrieve in the vulnerability standard library according to the cnnvd_num. If not retrieved, insert the data source into the vulnerability standard library. If the corresponding cnnvd_num is retrieved, update the data corresponding to the cnnvd_num in the vulnerability standard library with the data source.
[0008] Preferably, if there are multiple numbers in the cve_num of the data source, retrieve according to the numbers in the vulnerability standard library. If not retrieved, insert the data source into the vulnerability standard library; stop processing other numbers.
[0009] Preferably, during the process of retrieving in the vulnerability standard library based on the cve_num, cnvd_num, or cnnvd_num of the data source in the vulnerability information library, if multiple pieces of data are retrieved, the data source is suspended from processing.
[0010] Preferably, the process of matching the pop or exp in the PoC / exp resource library with the data in the vulnerability standard library based on the cve_num is as follows: (1)Traverse the poc_exp table in the PoC / exp repository to find the cve_num corresponding to each poc or exp; (2)If it exists, check whether there is corresponding data in the vulnerability standard library through the cve_num. If it exists, update the data to the vulnerability standard library; if not, insert the corresponding data into the vulnerability standard library.
[0011] Preferably, based on the cve_num, cnvd_num or cnnvd_num, match the articles in the network security article information library with the data in the vulnerability standard library: (1)Search for cve_num, cnvd_num or cnnvd_num in the articles in the network security article information library in sequence; (2)If cve_num, cnvd_num or cnnvd_num is not found in the network security article information library, skip the data source; (3)If found, retrieve data in the vulnerability standard library through the corresponding cve_num, cnvd_num or cnnvd_num. If not retrieved, skip; if retrieved, determine whether the article content is relevant to the data source through the large language model. If relevant, update the id in the network security article information library to the id in the vulnerability standard library, and set the id position in the network security article information library to 1.
[0012] Preferably, the display of data source information includes displaying the data in the vulnerability standard library, displaying the detail icons of each data, and displaying the associated articles of each data.
[0013] A heterogeneous network security intelligence processing system, comprising: An acquisition unit for periodically acquiring multiple data sources and storing them in the corresponding vulnerability information library, network security article information library and PoC / exp repository; the data source is network security intelligence; A retrieval and matching unit for retrieving in the vulnerability standard library based on the cve_num, cnvd_num or cnnvd_num of the data source in the vulnerability information library, and then inserting the data source into the vulnerability standard library or merging and updating the corresponding data of the data source; based on the cve_num, matching the pop or exp in the PoC / exp repository with the data in the vulnerability standard library; based on the cve_num, cnvd_num or cnnvd_num, matching the articles in the network security article information library with the data in the vulnerability standard library; A display unit for displaying the information of the data source.
[0014] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses a method for processing heterogeneous network security intelligence. While periodically updating the vulnerability information database, network security article information database, and PoC / exp resource database, the method can timely match the data sources in the updated vulnerability information database with the articles in the network security article information database and the data in the PoC / exp resource database, enabling the data in the network security intelligence data sources to provide data support for defense work such as network security event discovery and risk handling in a timely manner. This method solves the problems of existing network security intelligence being messy and having weak relevance, and can effectively integrate heterogeneous network security intelligence on the Internet, providing think tank services for network security experts and improving work efficiency. The present invention also has the following advantages: (1) Improving the timeliness and accuracy of network security intelligence: By periodically collecting multiple data sources, the present invention can ensure the timely update of network security intelligence and reflect the latest network threat situation. At the same time, storing the data sources in the corresponding vulnerability information database, network security article information database, and PoC / exp resource database helps to classify and manage the intelligence in detail, thereby improving the accuracy and availability of the intelligence.
[0015] (2) Enhancing vulnerability management and response capabilities: The present invention uses identifiers such as cve_num, cnvd_num, or cnnvd_num in the data sources to retrieve and match in the vulnerability standard database, realizing the standardized management and rapid update of vulnerability information. It helps the network security team to timely understand the details of vulnerabilities and take corresponding protection measures, such as patching and adjusting configurations, thereby effectively reducing the risk of vulnerabilities being exploited.
[0016] (3) Promoting the correlation analysis between PoC / exp and vulnerability information: By matching the PoC or exp in the PoC / exp resource database with the data in the vulnerability standard database based on cve_num, a direct connection can be established between vulnerabilities and attack means. It helps network security experts to deeply analyze the exploitation methods and potential hazards of vulnerabilities and formulate more accurate defense strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a framework diagram of a method for processing heterogeneous network security intelligence provided by an embodiment of the present invention; Figure 2 It is a logic flowchart of a data processing module of a method for processing heterogeneous network security intelligence provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0018] Hereinafter, the terms "first", "second", "third", and "fourth" are for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", "third", and "fourth" may explicitly or implicitly include one or more of such features.
[0019] The co - shooting method provided by the embodiments of this application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, in - vehicle devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra - mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), etc. The embodiments of this application do not impose any restrictions on the specific types of terminal devices.
[0020] It should be noted that the terms "first", "second", etc. in the specification and drawings of the present invention are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non - exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0021] The first aspect of the present invention discloses a heterogeneous network security intelligence processing method, and the method includes the following steps: S1, establish a periodic execution task for each data source, write the periodic execution task into an execution script, and write the execution script into the system task to automate data collection; the collected network security intelligence includes vulnerability information, network security article information, and PoC / exp resources, and is stored according to the belonging classification; after data collection, a vulnerability information library vul_info, a network security article information library cs_article_info, and a PoC / exp resource library poc_info are formed. There is also a vulnerability standard library, that is, the vul_std library, which defines the data standard format and is used to store the standardized data with vulnerabilities as the core formed after processing the obtained heterogeneous network security intelligence. This library stores the association information between network security article information and vulnerability information.
[0022] In some embodiments of the present invention, during the process of collecting data sources, it runs in the form of a command line and supports three forms: full quantification collection, incremental collection, and re-acquisition of error entries.
[0023] In some embodiments of the present invention, during the data collection process, the data collection module establishes a data collection status information table and an error information record table, which are used to record the time when the last collection of each data source is completed and the error information that occurs during the data collection process.
[0024] Furthermore, after each data collection is completed, the data collection status information and data collection error information are recorded in real time to update the data collection status information table and the error information record table.
[0025] S2. The data source storage process specifically includes: S21. Traverse all unprocessed vulnerability information in the vul_info table:
[0026] S22. For the vulnerability information database, for each piece of data to be inserted, perform the following processing: (1) Check its cve_num, cnvd_num, and cnnvd_num. If all three pieces of data are NULL, discard this piece of data and set its flag bit to 1.
[0027] (2) If the cve_num of the data to be inserted exists and is unique, retrieve it in the vul_std library according to the cve_num (note: x is the cve_num of the data to be inserted):
[0028] If no relevant data is retrieved, insert this piece of data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, perform data update and merge according to the data comparison and update method.
[0029] (3) If the cve_num of the data to be inserted does not exist and the cnvd_num exists and is unique, retrieve it in the vul_std library according to the cnvd_num (note: x is the cnvd_num of the data to be inserted):
[0030] If no relevant data is retrieved, insert this piece of data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, perform data update and merge according to the data comparison and update method.
[0031] (4)If neither the data to be inserted cve_num nor cnvd_num exists, and cnnvd_num exists and is unique, then retrieve in the vul_std library according to cnnvd_num (note: x is the cnnvd_num of the data to be inserted):
[0032] If no relevant data is retrieved, insert this data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, perform data update and merge according to the data comparison and update method.
[0033] (5)There are cases where the cve and other numbers of some data are more than one. For example, the cve_num of a certain vulnerability data side is "cve-001, cve-002, cve-003". Split the number (num) by the comma ",", and traverse whether each number appears in vul_std. If there is no data, create vul_std data for this cve number, and no longer process other number fields. Mark the data flag as 2 and perform manual processing later.
[0034] (6)Match through the three data of cve_num, cnvd_num, and cnnvd_num. If multiple data are matched, set the data is_use to 3 and do not process this data temporarily.
[0035] S22. For the PoC / exp resource library, associate the poc_exp table with vul_std. The specific steps are as follows: (1)Traverse the poc_exp table to find the cve_num corresponding to each poc or exp; (2)Find whether the corresponding data already exists in the vul_std table through cve_num. If it exists, update the data to the vul_poc, vul_exp, vul_exp_level, and poc_content fields; if the data cannot be retrieved, create a new vulnerability number in the vul_std table and insert the data.
[0036] S23. For the network security article information library, associate the cs_article_info table with vul_std. The specific steps are as follows: (1)Successively find vulnerability numbers in the article in the formats of cve_num, cnvd_num, and cnnvd_num; (2)If the vulnerability number data cannot be found in the article content, skip this data and set the flag bit to 1; (3)If a vulnerability number can be found in the article content, data retrieval is performed in the vul_std table using the corresponding vulnerability number. If no data is retrieved, it is skipped. If relevant data is retrieved, it is determined using a large language model. If it is determined that the article content is related to this piece of vulnerability data, the id of cs_article_info is updated to the article_id of the corresponding entry in vul_std, and the flag position of the cs_article_info data is set to 1.
[0037] Perform word segmentation and statistics on vul_name and vul_description in the vul_std table, find several valid categories, and establish a tag library for fast retrieval of cybersecurity intelligence.
[0038] S3. Display the data source, specifically including: S31. Display the data in the vul_std table. The display content includes vulnerability name, vulnerability release time, danger level, standard number, CVE number, CNVD number or CNNVD number, vulnerability description, and exploitation method. S32. Include a details icon after each piece of data. Clicking on the details icon can open a nested page, which displays all the information of this piece of vulnerability data in tabular form. S33. If there are associated articles, support jumping to the corresponding associated article by clicking on article_id. S34. Support precise or fuzzy retrieval of vulnerability information by item, tag, and time range.
[0039] The second aspect of the present invention discloses a heterogeneous cybersecurity intelligence processing system, which includes a data collection module, a data storage module, and a data display module.
[0040] The data module is used to periodically collect multiple cybersecurity intelligence data sources to form a vulnerability information database, a network security article information database, and a PoC / exp resource database. The data collection module bypasses the restrictions on data collection behavior of the data source by using methods such as simulating manual operations, computer vision to achieve verification and recognition, and based on playwright to complete sliding verification and filling of relevant fields.
[0041] A data storage module, which is used to insert data sources or update the data corresponding to data sources in the vulnerability information database based on the cve_num, cnvd_num, or cnnvd_num of the collected data sources; insert data sources or update the information corresponding to data sources in the PoC / exp resource library based on the cve_num of the vulnerability information database; insert data sources or update the information corresponding to data sources in the network security article information database based on the cve_num, cnvd_num, or cnnvd_num of the vulnerability information database. A data display module, which displays the information of data sources.
[0042] The heterogeneous network security intelligence processing system of the present invention adopts a modular system architecture, and can quickly expand functions and increase data sources.
[0043] To further improve the data collection ability, this system has the ability to automatically change addresses. By configuring the proxy IP pool information, the proxy IP information is periodically switched to prevent its own real IP from being blocked by the target site and thus unable to continuously collect data.
[0044] The following is further illustrated with specific embodiments.
[0045] Embodiment 1 This embodiment discloses a data collection system for a heterogeneous network security intelligence processing method, specifically as follows: An automated network security intelligence system is designed. Due to the discreteness of network security intelligence sources, the network security intelligence system needs to adopt a modular design method, which can quickly expand functions and increase data sources. Optional data sources include but are not limited to CNVD, CNNVD, NVD, METASPLOITDB, SECURIT, typical repositories of GITHUB, Freebuf, official accounts, etc.
[0046] An automated intelligence collection system is built. To further improve the data collection ability, this system has the ability to automatically change addresses. By configuring the proxy IP pool information, the proxy IP information is periodically switched to prevent its own real IP from being blocked by the target site and thus unable to continuously collect data.
[0047] In the embodiment of the present invention, data collection is performed in the form of command lines. The command line parameter "1" represents full quantitative collection, the parameter "2" represents incremental collection, and the parameter "3" represents re - crawling of error - crawled entries.
[0048] During data collection, set the data collection interval and the number of single - time data collections according to each data source, establish a periodic execution task, write the periodic execution task into an execution script, and write the execution script into the system task to automatically perform data collection.
[0049] Full - quantify the collection of publicly released cybersecurity intelligence resources. The collected cybersecurity intelligence includes vulnerability information, cybersecurity article information, and PoC / exp resources; Separate vulnerability information tables, article information tables, and PoC information tables are established in the database, and the obtained vulnerability intelligence is stored according to its respective classifications; A data collection status information table and an error information record table are established in the database. The data collection status information table records the time when the most recent collection of each data source is completed, and the error information record table includes the data source with data collection errors, the page URL, and the data collection error information; After each data collection is completed, the data collection status information and data collection error information are recorded in real - time to update the data collection status information table and the error information record table; When performing incremental data collection, the system obtains the data collection time nodes of each data source in the data collection status information table, and automatically detects and re - crawls and dynamically updates the latest released cybersecurity intelligence information from the previous state to the current time for incremental data collection and storage.
[0050] In particular, for relevant means such as machine detection, sliding verification, and verification codes included in some data sources, the embodiments of the present invention adopt methods such as simulating manual operations, implementing verification and recognition through computer vision, and completing sliding verification and filling of relevant fields based on playwright to bypass data collection restrictions; Through data collection, a vulnerability information database vul_info, a cybersecurity article information database cs_article_info, and a PoC / exp resource database poc_info are formed.
[0051] A flag field is added to the vul_info, cs_article_info, and poc_info tables for subsequent data processing, with a default value of 0, indicating that the data has not been processed; if the data has been processed, the field is set to 1; if there are subsequent update operations on this data later, it is set to 0 again; Figure 2 The following is the logical flowchart of the data processing module for a heterogeneous cybersecurity intelligence processing method provided by the embodiments of the present invention: Define vulnerability metadata, that is, the standardized fields of vulnerability information. In the embodiments of the present invention, the standardized fields of vulnerabilities include id, creation time create_time, update time update_time, standard number std_num, CVE vulnerability number cve_num, CNVD vulnerability number cnvd_num, CNNVD vulnerability number cnnvd_num, EXP table id exp_i, article table id articles_id, vulnerability name vul_name, vulnerability level vul_level, vulnerability score rank, vulnerability type type, vulnerability attack type attck_type, vulnerability source source, vulnerability description description, vulnerability references references, solutions solutions, affected manufacturers company, affected products and versions product_version, patch information patches, whether there is a POC poc_status, CVSS sub-item information (CVSS_version, Base_Score, AV, AC, AU, PR, UI, C, I, A); it should be noted that std_num is a custom number, and in the embodiments of the present invention, the format is the organization abbreviation + 8-digit number, for example, "ABCD-00000001"; Create a vul_std table according to the standardized fields of vulnerability information; The specific steps for inserting the data in the vulnerability information library vul_info into vul_std are as follows: (1) For the fields that exist in both, such as cve_num that exists in both vul_info and vul_std, perform field filling; (2) For the fields that exist in vul_std but not in vul_info, some can be obtained by parsing the fields in vul_info. Among them, parsing the vul_cpe information can obtain the product_version information, and parsing the CVSS can obtain information such as AV, AC, AU, PR, UI, C, I, A; (3) For the fields that exist in vul_std but not in vul_info, if the fields cannot be directly obtained or parsed from vul_info, the fields are first set to NULL.
[0052] (4) Set the flag field of the data in vul_info to 1 The comparison and update steps for the data A in the vulnerability information library vul_info and the vul_std data B are as follows: (1) There is at least one field data in the cve_num, cnvd_num, and cnnvd_num fields of data A and the data B to be compared that is the same and not NULL; (2) Convert A to the data format of vul_std, and the converted data is C; (3) Compare data C with data B. If the content of the same field is the same, skip it; if the content is different, combine with manual judgment, perform information merging, and update the corresponding field in B to the merged information; (4) Set the flag field of data A to 1.
[0053] Traverse all vulnerability information in the vul_info table that has not been associated yet:
[0054] For each piece of data to be inserted, perform the following processing: (1) Check its cve_num, cnvd_num, and cnnvd_num. If all three pieces of data are NULL, discard this piece of data and set its flag bit to 1.
[0055] (2) If the cve_num of the data to be inserted exists and is unique, retrieve it in the vul_std library according to the cve_num (note: is the cve_num of the data to be inserted):
[0056] If no relevant data is retrieved, insert this piece of data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, update the data according to the data comparison and update method.
[0057] (3) If the cve_num of the data to be inserted does not exist, the cnvd_num exists and is unique, retrieve it in the vul_std library according to the cnvd_num (note: is the cnvd_num of the data to be inserted):
[0058] If no relevant data is retrieved, insert this piece of data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, update the data according to the data comparison and update method.
[0059] (4) If the cve_num and cnvd_num of the data to be inserted do not exist, the cnnvd_num exists and is unique, retrieve it in the vul_std library according to the cnnvd_num (note: For the cnnvd_num of the data to be inserted:
[0060] If no relevant data is retrieved, insert this data into the vul_std table according to the data insertion method and set the flag bit to 1; if relevant data is retrieved, update the data according to the data comparison and update method.
[0061] (5) There are cases where there is more than one CVE number or the like for some source data. For example, for a certain vulnerability data, the cve_num is "cve-001, cve-002, cve-003". Split the numbers by ",", and traverse whether each number appears in vul_std. If there is no data, create vul_std data for this CVE number, and do not process other fields. Mark the data flag as 2 for later manual processing.
[0062] (6) Match through the three data of cve_num, cnvd_num, and cnnvd_num. If multiple data are matched, set the data is_use to 3 for later manual processing.
[0063] Associate the poc_exp table with vul_std. The specific steps are as follows: (1) Traverse the poc_exp table to find the cve_num corresponding to each poc or exp; (2) Check whether the corresponding data already exists in the vul_std table through cve_num. If it exists, update the data to the vul_poc, vul_exp, vul_exp_level, and poc_content fields; if the data cannot be retrieved, create a new vulnerability number in the vul_std table and insert the data.
[0064] Associate the cs_article_info table with vul_std. The specific steps are as follows: (1) Search for vulnerability number data in the format of cve_num, cnvd_num, and cnnvd_num in the article; (2) If the vulnerability number data cannot be found in the article content, skip this data and set the flag bit to 1; (3)If the vulnerability number data can be found in the article content, retrieve the data in the vul_std table through the corresponding vulnerability number. If no data is retrieved, skip it. If relevant data is retrieved, make a judgment through the large language model. If it is determined that the article content is related to the vulnerability data, update the id of cs_article_info to the article_id of the corresponding entry in vul_std, and set the flag position of the cs_article_info data to 1.
[0065] Use jieba word segmentation to perform word segmentation statistics on all vul_name and vul_description, find several effective categories, establish a label library, and use the name for query when querying.
[0066] The data display module is used to display the data in the vul_std table. The display content includes vulnerability name, vulnerability release time, danger level, standard number, CVE number, CNVD number, CNNVD number, vulnerability description, exploitation method. Up to 20 pieces of data can be displayed on each page; a detail icon is included after each piece of data. Clicking on the detail icon can open a nested page, and all information of the vulnerability data of this item is displayed in the form of a table on the page. If there is an associated article, it supports jumping to the corresponding associated article by clicking on article_id; it supports precise or fuzzy retrieval of vulnerability information by item, label, and time range.
[0067] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for processing heterogeneous network security intelligence, characterized in that: The following steps are involved: Periodically collect multiple data sources and store them in the corresponding vulnerability information library, network complete article information library and PoC / exp resource library; The data source is network security intelligence; Based on the cve_num, cnvd_num or cnnvd_num of the data source in the vulnerability information library, search in the vulnerability standard library, and then insert the data source into the vulnerability standard library or merge and update the data corresponding to the data source; based on cve_num, match the pop or exp in the PoC / exp resource library with the data in the vulnerability standard library; based on cve_num, cnvd_num or cnnvd_num, match the articles in the network complete article information library with the data in the vulnerability standard library; Displays information about the data source.
2. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: The forms of collecting multiple data sources include full quantitative collection, incremental collection and re-acquisition of error entries.
3. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: In the process of periodically collecting multiple data sources, the latest collected time spectrum of each data source is recorded through the collection status information table, and the error information occurring during the data source collection process is recorded through the error information recording table.
4. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: The process of searching in the vulnerability standard library based on the cve_num, cnvd_num or cnnvd_num of the data source in the vulnerability information library, and then inserting the data source in the vulnerability standard library or merging and updating the data corresponding to the data source is as follows: (1) If the data source does not have cve_num, cnvd_num, and cnnvd_num, the data source is discarded and the flag position is set to 1; (2) If the cve_num of the data source exists and is unique, search the vulnerability standard library based on cve_num. If not found, insert the data source into the vulnerability standard library. If the corresponding cve_num is found, update the data corresponding to cve_num in the vulnerability standard library as the data source. (3) If the cve_num of the data source does not exist, but cnvd_num exists and is unique, search the vulnerability standard library based on cnvd_num. If the data source is not found, insert the data source into the vulnerability standard library. If the corresponding cnvd_num is found, update the data corresponding to cnvd_num in the vulnerability standard library as the data source. (4) If both cve_num and cnvd_num of the data source do not exist, and cnnvd_num exists and is unique, search the vulnerability standard library based on cnnvd_num. If not found, insert the data source into the vulnerability standard library. If the corresponding cnnvd_num is found, update the data corresponding to cnnvd_num in the vulnerability standard library as the data source.
5. A heterogeneous network security intelligence processing method according to claim 4, characterized in that: If there are multiple numbers in the cve_num of the data source, search in the vulnerability standard library according to the number. If not found, insert the data source into the vulnerability standard library; stop processing for other numbers.
6. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: Based on the cve_num, cnvd_num or cnnvd_num of the data source in the vulnerability information library, if multiple data are retrieved during the search in the vulnerability standard library, the data source suspends processing.
7. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: The process of matching pop or exp in the PoC / exp resource library with the data in the vulnerability standard library based on cve_num is as follows: (1) Traverse the poc_exp table in the PoC / exp resource library and find the cve_num corresponding to each poc or exp; (2) If it exists, use cve_num to find out whether there is corresponding data in the vulnerability standard library. If it exists, update the data to the vulnerability standard library; if it does not exist, insert the corresponding data into the vulnerability standard library.
8. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: Based on cve_num, cnvd_num or cnnvd_num, the articles in the complete network article information library and the data in the vulnerability standard library are matched: (1) Search for cve_num, cnvd_num or cnnvd_num in the articles in the complete online article database; (2) If cve_num, cnvd_num or cnnvd_num is not found in the network complete article information database, skip the data source; (3) If found, search for data in the vulnerability standard library through the corresponding cve_num, cnvd_num or cnnvd_num. If not found, skip it. If found, determine whether the article content is related to the data source through the large language model. If so, update the id in the network complete article information library to the id in the vulnerability standard library, and set the id position in the network complete article information library to 1.
9. A heterogeneous network security intelligence processing method according to claim 1, characterized in that: The display of data source information includes displaying data in a vulnerability standard library, displaying a detail icon for each data, and displaying related articles for each data.
10. A heterogeneous network security intelligence processing system, characterized in that: include: The collection unit is used to periodically collect multiple data sources and store them in the corresponding vulnerability information library, network complete article information library and PoC / exp resource library; The data source is network security intelligence; The retrieval matching unit is used to search in the vulnerability standard library based on the cve_num, cnvd_num or cnnvd_num of the data source in the vulnerability information library, and then insert the data source into the vulnerability standard library or merge and update the data corresponding to the data source; based on cve_num, match the pop or exp in the PoC / exp resource library with the data in the vulnerability standard library; based on cve_num, cnvd_num or cnnvd_num, match the articles in the network complete article information library with the data in the vulnerability standard library; Display unit, used to display the information of data source.