Intelligent question answering method and device for vulnerability repair, computer equipment and storage medium
By building a knowledge graph covering the entire life cycle of vulnerability knowledge and combining real-time online information search technology, large models are used to achieve efficient query and intelligent generation of vulnerability repair solutions, the problems of low information acquisition efficiency and high professional knowledge requirements in existing vulnerability repair methods are solved, and efficient and accurate vulnerability repair is achieved.
Patent Information
- Application Number
- CN202510162059.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing vulnerability repair methods have problems such as low information acquisition efficiency, insufficient accuracy of fixing solutions matching, and high professional knowledge requirements.
By building a knowledge graph covering the entire life cycle of vulnerability knowledge, combining real-time online information search technology and self-built vulnerability-related data sets, we use the advantages of large models in natural language processing and knowledge inference to achieve efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions.
It significantly improves the breadth and timeliness of vulnerability repair information acquisition, realizes a full-process automation service from problem analysis to the generation of repair suggestions, and reduces the requirements for user professional knowledge.
Smart Images

Figure CN120106138A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security and artificial intelligence technology, and specifically to a vulnerability repair intelligent question-answering method, device, computer equipment and storage medium. Background Art
[0002] With the rapid development of network technology and the continuous improvement of informatization, various information systems are facing increasingly complex network security threats while providing convenient services. Vulnerabilities are the main entry point for network attacks, and their identification and repair have become a key link in ensuring the safe operation of the system.
[0003] In related technologies, due to the wide range of vulnerability information sources, large quantities and various forms, traditional vulnerability repair methods are difficult to meet the actual needs of efficiency and accuracy. In addition, the professionalism and timeliness of different vulnerability repair solutions also place high demands on the skill level of security practitioners. The existing vulnerability repair process has problems such as low efficiency in information acquisition, insufficient accuracy in matching repair solutions, and high professional knowledge requirements. Summary of the invention
[0004] In view of this, the present invention provides a vulnerability repair intelligent question and answer method, device, computer equipment and storage medium to solve the problems of low information acquisition efficiency, insufficient repair solution matching accuracy and high professional knowledge requirements in the existing vulnerability repair process.
[0005] In a first aspect, the present invention provides a vulnerability repair intelligent question-answering method, the method comprising:
[0006] Obtain vulnerability intelligence datasets;
[0007] Based on the vulnerability intelligence dataset, build a vulnerability intelligence knowledge graph;
[0008] Use the vulnerability intelligence knowledge graph to build a fine-tuning dataset;
[0009] Based on the fine-tuning dataset, fine-tune the preset vulnerability repair model to obtain the target vulnerability repair model;
[0010] Utilize the target vulnerability repair large model to build an intelligent question-answering system for vulnerability repair.
[0011] In the present invention, by constructing a knowledge graph covering the entire life cycle of vulnerability knowledge, combining real-time online information search technology and self-built vulnerability-related data sets, the advantages of large models in natural language processing and knowledge reasoning are fully explored and utilized to achieve efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions. By constructing a knowledge graph in vulnerability-related fields, vulnerabilities and their repair information can be systematically stored, organized and displayed, thereby providing data support for the rapid retrieval and intelligent application of repair solutions. At the same time, combined with real-time online information search technology, dynamically changing vulnerability information can be supplemented to achieve real-time updating of information and accurate recommendation of repair solutions.
[0012] In an optional implementation, a vulnerability intelligence knowledge graph is constructed based on the vulnerability intelligence dataset, including:
[0013] According to predefined rules, identify entities and relationships in vulnerability intelligence datasets;
[0014] Capturing the context of vulnerability data in vulnerability intelligence datasets based on the distribution characteristics and feature weights of entities;
[0015] A neural network architecture based on a multi-head attention mechanism is adopted to realize the entity recognition, attribute extraction and relationship mining tasks of the vulnerability intelligence knowledge graph, and construct the vulnerability intelligence knowledge graph.
[0016] In this way, a vulnerability intelligence knowledge graph covering the entire life cycle of vulnerability knowledge is constructed. Through the efficient organization and semantic association capabilities of the knowledge graph, the subsequent use of the vulnerability intelligence knowledge graph for efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions is facilitated.
[0017] In an optional implementation, a fine-tuning dataset is constructed using a vulnerability intelligence knowledge graph, including:
[0018] Using the vulnerability intelligence knowledge graph, we combine the relationship between entities and the attribute information corresponding to the entities to construct question-answer pairs;
[0019] Based on the vulnerability intelligence knowledge graph, entities and relationships are mined, and the relationships between entities are combined to construct a fine-tuning dataset.
[0020] In this method, the above steps are used to build a vulnerability intelligence knowledge graph and the fine-tuned dataset is checked and verified by combining manual verification and machine verification to make the fine-tuned dataset more accurate and professional.
[0021] In an optional implementation, based on the fine-tuning data set, the preset vulnerability repair model is fine-tuned to obtain the target vulnerability repair model, including:
[0022] The fine-tuning dataset is input into the preset vulnerability repair model. Using the Lora fine-tuning method, additional outputs are added to the preset vulnerability repair model to obtain the target vulnerability repair model.
[0023] In this way, the powerful semantic understanding and reasoning capabilities of the large model are used to accurately match user needs and generate highly professional repair solutions. The Lora fine-tuning method ensures the efficiency of training and efficient fine-tuning with less video memory usage.
[0024] In an optional implementation, the vulnerability repair intelligent question-answering system includes:
[0025] A code execution unit, used to obtain request parameters and key parameter information in the vulnerability intelligence knowledge graph corresponding to the input vulnerability information;
[0026] A real-time information search unit, used to search and obtain information search results corresponding to vulnerability information;
[0027] Vulnerability intelligence assistant, used to send requests to the vulnerability intelligence knowledge graph based on request parameters and key parameter information to obtain vulnerability repair background data;
[0028] A search query unit, used to obtain vulnerability related information associated with the vulnerability information according to the vulnerability repair related data;
[0029] The vulnerability repair generation unit is used to combine the information search results, vulnerability repair background data and vulnerability related information to generate a vulnerability repair plan.
[0030] In this approach, real-time online information search is combined with self-built vulnerability datasets to significantly improve the breadth and timeliness of vulnerability repair information acquisition, achieving full-process automated services from problem analysis to repair suggestion generation.
[0031] In an optional embodiment, the method further includes:
[0032] Use the vulnerability repair intelligent question-answering system to generate vulnerability repair solutions corresponding to the vulnerability information.
[0033] In this way, the use of the intelligent question-and-answer system for vulnerability repair not only improves the efficiency and accuracy of vulnerability repair, but also reduces the requirements for user professional knowledge, providing innovative support for the in-depth development of intelligent and automated technologies in the field of network security.
[0034] In a second aspect, the present invention provides a vulnerability repair intelligent question-answering device, the device comprising:
[0035] Data acquisition module, used to obtain vulnerability intelligence data sets;
[0036] The knowledge graph construction module is used to build a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset;
[0037] A fine-tuning dataset construction module is used to build a fine-tuning dataset using the vulnerability intelligence knowledge graph;
[0038] A model fine-tuning module is used to fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model;
[0039] The system building module is used to build an intelligent question-answering system for vulnerability repair using a large model of target vulnerability repair.
[0040] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the vulnerability repair intelligent question-and-answer method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0041] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the vulnerability repair intelligent question-and-answer method of the first aspect or any corresponding embodiment thereof.
[0042] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the vulnerability repair intelligent question-and-answer method of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0044] Figure 1 4 is a flow chart of an intelligent question-answering method for vulnerability repair according to an embodiment of the present invention.
[0045] Figure 2 It is a framework diagram of a vulnerability repair intelligent question-answering system based on a knowledge graph and a large model according to an embodiment of the present invention.
[0046] Figure 3 4 is a flow chart of another intelligent question-answering method for vulnerability repair according to an embodiment of the present invention.
[0047] Figure 4It is a schematic diagram of lora fine-tuning of a large vulnerability repair model according to an embodiment of the present invention.
[0048] Figure 5 It is a flowchart of another intelligent question-and-answer method for vulnerability repair according to an embodiment of the present invention.
[0049] Figure 6 4 is a structural block diagram of a smart question-answering device for vulnerability repair according to an embodiment of the present invention.
[0050] Figure 7 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0051] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0052] In related technologies, due to the wide range of vulnerability information sources, large quantities and various forms, traditional vulnerability repair methods are difficult to meet the actual needs of efficiency and accuracy. In addition, the professionalism and timeliness of different vulnerability repair solutions also place high demands on the skill level of security practitioners. The existing vulnerability repair process has problems such as low efficiency in information acquisition, insufficient accuracy in matching repair solutions, and high professional knowledge requirements.
[0053] In order to solve the above problems, an embodiment of the present invention provides a vulnerability repair intelligent question-answering method for use in a computer device. It should be noted that its execution subject can be a vulnerability repair intelligent question-answering device, which can be implemented as part or all of a computer device through software, hardware, or a combination of software and hardware. The computer device can be a terminal, a client, or a server. The server can be a single server or a server cluster composed of multiple servers. The terminal in the embodiment of the present application can be a smart phone, a personal computer, a tablet computer, or other intelligent hardware devices. In the following method embodiments, the execution subject is taken as an example of a computer device for explanation.
[0054] The computer device in this embodiment is suitable for use scenarios that provide comprehensive and intelligent vulnerability solution support for network security practitioners. The present invention provides an intelligent question-and-answer method for vulnerability repair, which builds a knowledge graph covering the entire life cycle of vulnerability knowledge, combines real-time online information search technology and self-built vulnerability-related data sets, and fully explores and utilizes the advantages of large models in natural language processing and knowledge reasoning to achieve efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions. By constructing a knowledge graph in vulnerability-related fields, vulnerabilities and their repair information can be systematically stored, organized and displayed, thereby providing data support for rapid retrieval and intelligent application of repair solutions. At the same time, combined with real-time online information search technology, it can supplement dynamically changing vulnerability information, realize real-time updating of information and accurate recommendation of repair solutions.
[0055] According to an embodiment of the present invention, an embodiment of a vulnerability repair intelligent question-and-answer method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0056] In this embodiment, a vulnerability repair intelligent question-answering method is provided, which can be used in the above-mentioned computer device. Figure 1 is a flow chart of a vulnerability repair intelligent question-answering method according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:
[0057] Step S101, obtaining a vulnerability intelligence data set.
[0058] In one example, multiple vulnerability standard data sets (such as CNNVD, CVE, CWE, etc.), manufacturer announcements, open source community vulnerability intelligence, and vulnerability analysis articles are used as data sources for constructing a vulnerability intelligence data set.
[0059] Specifically, data acquisition is achieved through automation and manual methods. For standardized data such as CVE, CWE, and CNNVD, it is obtained regularly from their official websites based on their update time using tools such as Python and requests. For vulnerability intelligence from open source communities, such as GitHub and open source communities, it is obtained using the APIs provided by relevant platforms. For vulnerability analysis articles and manufacturer announcements, it is obtained through manual downloading. After obtaining the data, further data preprocessing, such as deduplication and noise removal, is performed to construct a vulnerability intelligence dataset.
[0060] Step S102, constructing a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset.
[0061] In one example, entity recognition, attribute extraction, and relationship mining are performed on the data of the above vulnerability intelligence dataset to construct a vulnerability intelligence knowledge graph.
[0062] Step S103, using the vulnerability intelligence knowledge graph to construct a fine-tuning dataset.
[0063] In one example, the vulnerability intelligence knowledge graph is used in combination with manual verification and machine verification to fine-tune the data set for verification and validation, making it more accurate and professional.
[0064] Step S104: fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model.
[0065] In one example, the fine-tuning method selects lora fine-tuning, and the fine-tuning framework selects llama-factory.
[0066] Step S105, using the target vulnerability repair model, build a vulnerability repair intelligent question-answering system.
[0067] In one example, a vulnerability repair intelligent question-answering system is constructed in a modular way.
[0068] In one implementation scenario, Figure 2 is a schematic diagram of a framework of a vulnerability repair intelligent question-answering system based on a knowledge graph and a large model according to an embodiment of the present invention. Figure 2 As shown, the vulnerability repair intelligent question-answering system based on knowledge graph and big model can include: vulnerability information input; code execution to obtain query field information in the vulnerability knowledge graph; real-time information search, through instruction tuning and prompt word enhancement, using big model to generate vulnerability repair plan; obtaining intelligence data associated with the input through vulnerability intelligence assistant, and using big model to generate vulnerability repair plan; searching and querying other vulnerability databases, through instruction tuning, using big model to generate vulnerability repair plan; integrating and outputting vulnerability repair plan.
[0069] Exemplarily, the vulnerability repair intelligent question-answering system based on knowledge graph and large model may include: S01, construction of knowledge graph. There are three main ways to implement entity recognition tasks:
[0070] A. Identification method based on rule engine: The rule engine uses predefined rules (such as keyword matching, regular expressions) to identify specific entities and relationships in the field of power safety. This method is suitable for scenarios with clear patterns and can be deployed quickly, but it is highly dependent on rules. The application examples are as follows:
[0071] For example, use a regular expression to match the CVE number: CVE-\d{4}-\d{4,6}.
[0072] B. Statistical models identify entities by analyzing their distribution characteristics in the corpus. Typical models such as HiddenMarkov Model (HMM) can capture contextual relationships by learning feature weights through labeled samples. Application examples are as follows:
[0073] Input corpus: "This vulnerability allows remote attackers to execute arbitrary code in the affected version of Apache Log4j 2.x through improper input validation."
[0074] Annotate the corpus and extract the target entity:
[0075] Vulnerability Type: Remote Code Execution (RCE)
[0076] Affected components: Apache Log4j
[0077] Severity: High
[0078] The corpus is processed into a sequence annotation format for statistical model training. The application examples are as follows:
[0079] This O
[0080] O
[0081] allows O
[0082] remote B-VulnType
[0083] attackers I-VulnType
[0084] to O
[0085] execute O
[0086] arbitrary O
[0087] code O
[0088] in O
[0089] the O
[0090] affected
[0091] version O
[0092] of O
[0093] Apache B-Component
[0094] Log4j I-Component
[0095] 2.x O
[0096] through O
[0097] improper
[0098] input O
[0099] validation O
[0100] HMM model:
[0101] State space: B-VulnType, I-VulnType, B-Component, I-Component, O (annotation label).
[0102] Observe the sequence: ["This","vulnerability","allows",...,"validation","."]
[0103] Parameter learning:
[0104] Initial probability: such as P(B-VulnType).
[0105] Transition probability: such as P(I-VulnType|B-VulnType).
[0106] Emission probability: such as P("remote"|B-VulnType).
[0107] Decoding process: Use the relevant algorithm to infer the optimal annotation sequence and obtain the annotation results, namely: Vulnerability type: Remote Code Execution (RCE)
[0108] Affected components: Apache Log4j
[0109] Severity: High
[0110] C. Neural network-based methods: Deep learning extracts entities, relationships, and attributes jointly by building complex neural network structures. This phase uses a Transformer-based pre-trained model combined with a conditional random field (CRF) architecture. The following is an example of a fine-tuned dataset:
[0111] [“A CVE-2007-4288 vulnerability was discovered in microsoft:windows_media_player version 11. An attacker can use a specially crafted .au file to trigger a division by zero error, causing the application to crash, resulting in a denial of service attack, such as iapetus.au. The fix is to update it to the latest version that fixes the vulnerability.”, [[2,15,”CVE”],[24,54,”CPE”],[124,140,”Mitigations”]].
[0112] The above sample examples show that characters with indexes 2 to 15 are a CVE entity, characters with indexes 24 to 54 are a CPE entity, and characters with indexes 124 to 140 are a Mitigations entity. The model was trained using accuracy and F1 score as evaluation indicators, and achieved good results, with an entity recognition accuracy of over 95%.
[0113] S02. Fine-tuning of the large model for bug fixes: Use the dataset constructed in the above steps to fine-tune the large model through Lora fine-tuning. The fine-tuned base large model can be selected according to the actual computing power to meet your needs, such as the chatglm4-9b model, and use llama-factory as the fine-tuning framework. The following is an example of a fine-tuning dataset during the fine-tuning process:
[0114] Data sample 1: {"instruction":"How to quickly fix the CVE-2023-25312 vulnerability?","input":"","output":"FastJson is an open source JSON processing library developed by a company. It is mainly used for serialization and deserialization of JSON objects in the Java language environment. It provides the ability to quickly read and write JSON data. It is often used for parsing network communication data and converting object data. It is one of the commonly used data processing libraries in Java development."}
[0115] Data sample 2: {"instruction":"What resources are needed to fix the CVE-2023-26358 vulnerability?","input":"","output":"rbash is a restricted bash shell, which is a restricted version of bash designed to limit the operations that users can perform. During the Linux privilege escalation process, attackers may exploit certain restrictions of rbash to bypass security mechanisms and gain higher system permissions. By bypassing the restrictions of rbash, attackers can execute commands that were originally prohibited, which may lead to the expansion of system security vulnerabilities and ultimately allow attackers to obtain root permissions."}
[0116] Fine-tuning is performed by setting the Lora matrix scaling coefficient, learning rate, rank of the Lora matrix (i.e. parameter k of matrices A and B). During the fine-tuning process, the loss curve shows an overall downward trend with the increase of training epochs, indicating that the error of the model is gradually decreasing; and when the training is nearing the end, the curve tends to be stable, indicating that the model has reached a better state, and the final loss will stabilize at around 0.7, with very good results.
[0117] S03. Construction of a vulnerability repair intelligent question-answering system: A vulnerability repair intelligent question-answering system is constructed through the aforementioned knowledge graph, vulnerability repair large model, its own vulnerability database, and implementation information search system. The following is an embodiment of this system:
[0118] The vulnerability information entered is: CVE-2023-5678. How to fix this vulnerability? Give a specific repair plan.
[0119] Fine-tuning of system prompt words for large models:
[0120] #Role: Vulnerability Fixing Assistant
[0121] ##Profile:
[0122] -Language: Chinese
[0123] -Description: Focus on the field of network security and provide users with detailed vulnerability repair solutions based on the vulnerability numbers provided.
[0124] ##Goals:
[0125] -Quickly locate vulnerability information based on the vulnerability number provided by the user.
[0126] - Provides comprehensive, actionable repair steps.
[0127] - List resources and tools that may be needed during the repair process.
[0128] - Provide relevant reference links for users to gain deeper understanding.
[0129] ##Skills:
[0130] -Be proficient in the basic knowledge of network security field.
[0131] -Can quickly search the vulnerability database to obtain vulnerability details.
[0132] -Accurately determine the required resources and provide effective repair steps.
[0133] ##Workflows:
[0134] 1. Receive the vulnerability number provided by the user.
[0135] 2. Search the vulnerability database to obtain vulnerability description, impact scope, CVSS score and other information.
[0136] 3. Design a repair plan, including specific repair steps.
[0137] 4. Identify the resources needed during the repair process (such as patches, tools, documentation, etc.).
[0138] 5. Provide relevant reference links, including official fix announcements, technical forum discussions, etc.
[0139] The output vulnerability repair solution is:
[0140] The vulnerability fix is as follows: CVE-2023-5678 refers to a security hole in OpenSSL that may cause performance issues when generating overly long X9.42 DH keys or checking overly long X9.42 DH keys or parameters, which may lead to a denial of service attack.
[0141] To fix this vulnerability, please follow these steps:
[0142] 1. Update to the latest version of OpenSSL: Make sure your OpenSSL environment is the latest version. If your environment is not the latest, please update to OpenSSL 3.0.12 or 3.1.4 or later, which have fixed the vulnerability.
[0143] 2. Apply security patches: If your environment cannot be updated to the latest version immediately, please download and apply the officially released patches.
[0144] 3. Apply interim fixes: If updating or patching is not feasible, consider taking the following interim measures to reduce the risk: 1) Do not obtain keys or parameters from untrusted sources. 2) When using the DH generate key() or DH checkpub key() functions, limit the input parameters to prevent keys or parameters that are too long.
[0145] 4. Check for security updates for the relevant operating system: If you have OpenSSL installed as part of your operating system, check whether the operating system provider has released security updates.
[0146] For example, if your system is Red Hat Enterprise Linux or CentOS, you can view Red Hat's Security Advisory or Security Errata: https: / / access.redhat.com / security / cve / CVE.2023-5678
[0147] 5. Monitor and upgrade: Keep monitoring your OpenSSL version and upgrade immediately when a new version comes out.
[0148] The vulnerability repair intelligent question-answering method provided in this embodiment, by constructing a knowledge graph covering the entire life cycle of vulnerability knowledge, combined with real-time online information search technology and self-built vulnerability-related data sets, fully explores and utilizes the advantages of large models in natural language processing and knowledge reasoning, and realizes efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions. By constructing a knowledge graph in vulnerability-related fields, vulnerabilities and their repair information can be systematically stored, organized and displayed, thereby providing data support for the rapid retrieval and intelligent application of repair solutions. At the same time, combined with real-time online information search technology, it can supplement dynamically changing vulnerability information, realize real-time updating of information and accurate recommendation of repair solutions.
[0149] In this embodiment, a vulnerability repair intelligent question-answering method is provided, which can be used in the above-mentioned computer device. Figure 3 is a flow chart of another intelligent question-answering method for vulnerability repair according to an embodiment of the present invention. Figure 3 As shown, the process includes the following steps:
[0150] Step S301, obtain vulnerability intelligence data set. For details, see Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0151] Step S302, constructing a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset.
[0152] Specifically, the above step S302 includes:
[0153] Step S3021, identifying entities and relationships in the vulnerability intelligence data set according to predefined rules.
[0154] Step S3022, capturing the context of vulnerability data of the vulnerability intelligence dataset based on the distribution characteristics and feature weights of the entities.
[0155] Step S3023, adopting a neural network architecture based on a multi-head attention mechanism to implement entity recognition, attribute extraction and relationship mining tasks of the vulnerability intelligence knowledge graph, and construct a vulnerability intelligence knowledge graph.
[0156] In one example, a knowledge graph is constructed by using vulnerability intelligence datasets for entity recognition, attribute extraction, and relationship mining. The main construction methods are as follows:
[0157] 1) Rule engine-based identification method - identifies specific entities and relationships in the field of cybersecurity vulnerability intelligence through predefined rules (such as keyword matching, regular expressions).
[0158] 2) Identification method based on statistical model - by analyzing the distribution characteristics of entities in the corpus and learning feature weights of labeled samples, the context of vulnerability data is captured, such as Hidden Markov Model (HMM) and Bayesian model, etc. The specific method is not limited in the present invention.
[0159] 3) Neural network-based method - adopts the Transformer neural network architecture based on the multi-head attention mechanism, adds the multi-head attention mechanism and position encoding in the encoding and decoding steps, and implements the entity recognition, relationship extraction and attribute recognition tasks of the vulnerability intelligence knowledge graph through the Transformer+CRF (Conditional Random Field) network structure. Based on the results of entity recognition, the Neo4j graph database is used to store vulnerability-related intelligence.
[0160] In this way, a vulnerability intelligence knowledge graph covering the entire life cycle of vulnerability knowledge is constructed. Through the efficient organization and semantic association capabilities of the knowledge graph, the subsequent use of the vulnerability intelligence knowledge graph for efficient query, intelligent generation and accurate recommendation of vulnerability repair solutions is facilitated.
[0161] Step S303, using the vulnerability intelligence knowledge graph to construct a fine-tuning dataset.
[0162] Specifically, the above step S303 includes:
[0163] Step S3031, using the vulnerability intelligence knowledge graph, combining the relationship between entities and the attribute information corresponding to the entities, constructs a question-answer pair.
[0164] Step S3032, based on the vulnerability intelligence knowledge graph, entities and relationships are mined, and a fine-tuning dataset is constructed based on the relationships between entities.
[0165] In one example, the vulnerability intelligence knowledge graph is used to verify and validate the data set by combining manual verification and machine verification to make it more accurate and professional. The construction methods may include:
[0166] A. Generate by using the relationship between entities in the vulnerability intelligence knowledge graph. For example, there is a VulnOf relationship between the CVE entity and the vuln_intelligence entity in the vulnerability intelligence knowledge graph. The following question-answer pair is constructed based on the attribute information of the two entities:
[0167] instruction1(input): How to fix the yyy vulnerability in xxx?
[0168] instruction2 (input): xxx has yyy vulnerability, what is the official fix?
[0169] instruction3 (input): The vulnerability number is xxx, and there is a vulnerability risk of yyy. How to quickly fix this risk?
[0170] output: zzz.
[0171] Among them, xxx is the vulnerability number of CVE. Some CVEs will directly map to CNNVD. The CNNVD number can also be used here. yyy is the name attribute of the vuln_intelligence entity, and zzz is the solution attribute information of the vuln_intelligence entity. When actually generating, on the one hand, you can construct a variety of question paradigms, and on the other hand, you need to filter CVE and CNNVD entities (select high-risk, popular, and vulnerability entities with clear component manufacturers, etc.).
[0172] B. Further in-depth mining can be performed through the entity and relationship information in the vulnerability intelligence knowledge graph, and data in json format can be generated through the above relationship. For example, for the vuln_intelligence entity, the input data can be its description information, and the output data is its related attribute information. For example, for the extracted question and answer pairs of the vuln_intelligence entity in the above figure, the input is the description information of the vulnerability (that is, the content of the description field), and the output is all the field information of this entity, and the output is a json data. As shown below:
[0173] instruction(input): There is a PHP remote file inclusion vulnerability in fc_functions / fc_example.php in FishCart 3.2RC2 and earlier versions, allowing remote attackers to execute arbitrary PHP code through the URL in the docroot parameter.
[0174]
[0175] In this method, the above steps are used to build a vulnerability intelligence knowledge graph and the fine-tuned dataset is checked and verified by combining manual verification and machine verification to make the fine-tuned dataset more accurate and professional.
[0176] Step S304: fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model.
[0177] Specifically, the above step S304 includes:
[0178] Step S3041, input the fine-tuning data set into the preset vulnerability repair large model, use the lora fine-tuning method to add additional outputs on the basis of the preset vulnerability repair large model, and obtain the target vulnerability repair large model.
[0179] In one example, the fine-tuning is implemented based on Lora: the fine-tuning method selects Lora fine-tuning, and the fine-tuning framework selects llama-factory. Figure 4 is a schematic diagram of lora fine-tuning of a large vulnerability repair model according to an embodiment of the present invention, such as Figure 4 As shown in the fine-tuning process framework Figure 4 In the example, A is a reduced-dimensional matrix and B is a raised-dimensional matrix; the dimension of the original model parameter W matrix is d*d, while the dimension k of the Lora module is much smaller than d. In this way, the training parameters are actually the sum of the parameters of A and B, that is, 2*k*d, which is much smaller than d*d, ensuring the training efficiency and efficient fine-tuning with less memory usage. The essence of Lora is to use fewer training parameters to approximate the parameters obtained by fine-tuning the full parameters of LLM. When the Lora model training is initialized, A is initialized with a Gaussian distribution and B is initialized to all 0s. This ensures that the fine-tuning process starts from the original state of the pre-trained model. The output h of the newly generated model is just a BAx (i.e., the fine-tuned parameter) added to the original output Wx. The parameter structure of W remains unchanged, which also ensures that Lora will not change the behavior of the original model. The specific formula is as follows:
[0180]
[0181] In the formula, h is the output data of the large model or hidden layer, W is the original parameter matrix of the large model, A is the dimension reduction matrix, and B is the dimension increase matrix. This formula means adding a BAx to the original output Wx.
[0182] In the training process, the fine-tuning framework selects llama_factory, the base model selects chatglm4-9b, and the loss curve is set to about 0.8, which can be considered to have achieved a relatively good effect. At this point, a large model required by the subsequent system is obtained.
[0183] In this way, the powerful semantic understanding and reasoning capabilities of the large model are used to accurately match user needs and generate highly professional repair solutions. The Lora fine-tuning method ensures the efficiency of training and efficient fine-tuning with less video memory usage.
[0184] Step S305: Use the target vulnerability repair model to build a vulnerability repair intelligent question-answering system. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.
[0185] The intelligent question-and-answer method for vulnerability repair provided in this embodiment constructs a vulnerability intelligence knowledge graph covering the entire life cycle of vulnerability knowledge. Through the efficient organization and semantic association capabilities of the knowledge graph, it is convenient for the subsequent use of the vulnerability intelligence knowledge graph to efficiently query, intelligently generate and accurately recommend vulnerability repair solutions. The above steps are used to construct a vulnerability intelligence knowledge graph and verify and validate the fine-tuning data set by combining manual verification and machine verification to make the fine-tuning data set more accurate and professional. Utilizing the powerful semantic understanding and reasoning capabilities of the large model, user needs are accurately matched and highly professional repair solutions are generated. The lora fine-tuning method ensures the efficiency of training and efficient fine-tuning with less video memory usage.
[0186] In this embodiment, a vulnerability repair intelligent question-answering method is provided, which can be used in the above-mentioned computer device. Figure 5 is a flow chart of another intelligent question-answering method for vulnerability repair according to an embodiment of the present invention. Figure 5 As shown, the process includes the following steps:
[0187] Step S501: Obtain vulnerability intelligence data set. Figure 3 Step S301 of the illustrated embodiment will not be described in detail here.
[0188] Step S502: construct a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset. Figure 3 Step S302 of the illustrated embodiment will not be described in detail here.
[0189] Step S503: Use the vulnerability intelligence knowledge graph to construct a fine-tuning dataset. Figure 3 Step S303 of the illustrated embodiment will not be described in detail here.
[0190] Step S504: fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model. Figure 3 Step S304 of the illustrated embodiment will not be described in detail here.
[0191] Step S505, using the target vulnerability repair model, build a vulnerability repair intelligent question-answering system.
[0192] Specifically, in the above step S505, the vulnerability repair intelligent question and answer system includes: a code execution unit, which is used to obtain request parameters and key parameter information in the vulnerability intelligence knowledge graph corresponding to the input vulnerability information; a real-time information search unit, which is used to search for information search results corresponding to the vulnerability information; a vulnerability intelligence assistant, which is used to send a request to the vulnerability intelligence knowledge graph based on the request parameters and key parameter information to obtain vulnerability repair background data; a search query unit, which is used to obtain vulnerability association information associated with the vulnerability information based on vulnerability repair related data; a vulnerability repair generation unit, which is used to combine the information search results, vulnerability repair background data and vulnerability association information to generate a vulnerability repair solution.
[0193] In one example, a vulnerability repair intelligent question-answering system is constructed in a modular way. The functions of each module of the system are as follows:
[0194] Code execution: Code execution obtains query field information in the vulnerability knowledge graph, and uses code to parse the input vulnerability information to obtain request parameters and key parameter information in the knowledge graph, such as vulnerability year, danger level, and other information.
[0195] Real-time information search: Obtain real-time information search data through information search APIs such as Bing's search API, and inject the searched knowledge into the big model in the form of prompt words through instruction tuning, so that the big model can use the big model to perform vulnerability repair solutions based on the search results and the data obtained from the knowledge graph.
[0196] Vulnerability Intelligence Assistant: Gets intelligence data associated with the input, executes the obtained parameters through the aforementioned code, and sends a request to the vulnerability repair knowledge graph to obtain vulnerability repair related data.
[0197] Search and query other vulnerability databases: Based on the vulnerability data built by the user, by parsing the input data and sending requests to the self-built data set, the vulnerability information associated with the input data can be obtained to provide more background knowledge for vulnerability repair.
[0198] The big model generates vulnerability repair solutions: by utilizing input data, background knowledge obtained from the knowledge graph, data obtained from online real-time searches, and data obtained from searching and querying other vulnerability databases, new instructions are composed (the obtained data is injected into the instructions as background knowledge), and the target vulnerability repair big model is used to generate vulnerability repair solutions.
[0199] In this approach, real-time online information search is combined with self-built vulnerability datasets to significantly improve the breadth and timeliness of vulnerability repair information acquisition, achieving full-process automated services from problem analysis to repair suggestion generation.
[0200] Step S506: Generate a vulnerability repair solution corresponding to the vulnerability information using the vulnerability repair intelligent question-answering system.
[0201] In this way, the use of the intelligent question-and-answer system for vulnerability repair not only improves the efficiency and accuracy of vulnerability repair, but also reduces the requirements for user professional knowledge, providing innovative support for the in-depth development of intelligent and automated technologies in the field of network security.
[0202] The vulnerability repair intelligent question-and-answer method provided in this embodiment combines real-time online information search with a self-built vulnerability data set, significantly improving the breadth and timeliness of vulnerability repair information acquisition, and realizing full-process automated services from problem analysis to repair suggestion generation. The use of the vulnerability repair intelligent question-and-answer system not only improves the efficiency and accuracy of vulnerability repair, but also reduces the requirements for user professional knowledge, providing innovative support for the in-depth development of intelligent and automated technologies in the field of network security.
[0203] In this embodiment, a vulnerability repair intelligent question-answering device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0204] This embodiment provides a vulnerability repair intelligent question-answering device, such as Figure 6 As shown, including:
[0205] The data acquisition module 601 is used to acquire vulnerability intelligence data sets. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0206] The knowledge graph construction module 602 is used to construct a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset. Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.
[0207] The fine-tuning dataset construction module 603 is used to construct a fine-tuning dataset using the vulnerability intelligence knowledge graph. Figure 1 Step S103 of the illustrated embodiment will not be described in detail here.
[0208] The model fine-tuning module 604 is used to fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model. Figure 1 Step S104 of the illustrated embodiment will not be described in detail here.
[0209] System construction module 605 is used to build a vulnerability repair intelligent question-answering system using the target vulnerability repair model. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.
[0210] In some optional implementations, the knowledge graph construction module 602 includes:
[0211] The recognition unit based on the rule engine is used to identify entities and relationships in the vulnerability intelligence data set according to predefined rules.
[0212] A statistical model-based recognition unit is used to capture the context of vulnerability data of vulnerability intelligence datasets based on the distribution characteristics and feature weights of entities.
[0213] Based on the neural network unit, it is used to adopt a neural network architecture based on a multi-head attention mechanism to realize the entity recognition, attribute extraction and relationship mining tasks of the vulnerability intelligence knowledge graph, and construct a vulnerability intelligence knowledge graph.
[0214] In some optional implementations, the fine-tuning data set construction module 603 includes:
[0215] The entity relationship generation unit is used to construct question-answer pairs by utilizing the vulnerability intelligence knowledge graph and combining the relationship between entities with the attribute information corresponding to the entities.
[0216] The deep mining unit is used to mine entities and relationships based on the vulnerability intelligence knowledge graph, and to build a fine-tuning dataset based on the relationships between entities.
[0217] In some optional implementations, the model fine-tuning module 604 includes:
[0218] The model fine-tuning unit is used to input the fine-tuning data set into the preset vulnerability repair model, and use the lora fine-tuning method to add additional outputs on the basis of the preset vulnerability repair model to obtain the target vulnerability repair model.
[0219] In some optional implementations, the vulnerability repair intelligent question-answering system includes:
[0220] A code execution unit is used to obtain request parameters and key parameter information in the vulnerability intelligence knowledge graph corresponding to the input vulnerability information; a real-time information search unit is used to search for information search results corresponding to the vulnerability information; a vulnerability intelligence assistant is used to send a request to the vulnerability intelligence knowledge graph based on the request parameters and key parameter information to obtain vulnerability repair background data; a search query unit is used to obtain vulnerability association information associated with the vulnerability information based on vulnerability repair related data; a vulnerability repair generation unit is used to combine the information search results, vulnerability repair background data and vulnerability association information to generate a vulnerability repair plan.
[0221] In some optional implementations, the vulnerability repair intelligent question-answering device includes:
[0222] The vulnerability repair solution generation unit is used to generate a vulnerability repair solution corresponding to the vulnerability information by using the vulnerability repair intelligent question and answer system.
[0223] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0224] The vulnerability repair intelligent question-and-answer device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0225] The embodiment of the present invention also provides a computer device having the above Figure 6 The bug-fixing smart question-answering device shown.
[0226] See also Figure 7 , Figure 7 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 7 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 7 A processor 10 is taken as an example.
[0227] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0228] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0229] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0230] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0231] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 7 The example of connecting through bus is taken in the following.
[0232] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator bar, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0233] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0234] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0235] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A vulnerability repair intelligent question-answering method, characterized in that: The method comprises: Obtain vulnerability intelligence datasets; Based on the vulnerability intelligence dataset, construct a vulnerability intelligence knowledge graph; Using the vulnerability intelligence knowledge graph, a fine-tuning dataset is constructed; Based on the fine-tuning data set, fine-tune the preset vulnerability repair model to obtain the target vulnerability repair model; Using the target vulnerability repair model, an intelligent question-answering system for vulnerability repair is constructed.
2. The method according to claim 1, characterized in that The step of constructing a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset includes: According to predefined rules, entities and relationships in the vulnerability intelligence dataset are identified; capturing context of vulnerability data of the vulnerability intelligence dataset based on distribution characteristics and feature weights of the entities; A neural network architecture based on a multi-head attention mechanism is adopted to realize the entity recognition, attribute extraction and relationship mining tasks of the vulnerability intelligence knowledge graph, and construct the vulnerability intelligence knowledge graph.
3. The method according to claim 2, characterized in that The method of using the vulnerability intelligence knowledge graph to construct a fine-tuning dataset includes: Using the vulnerability intelligence knowledge graph, combining the relationship between the entities and the attribute information corresponding to the entities, constructing a question-answer pair; Based on the vulnerability intelligence knowledge graph, the entities and relationships are mined, and the fine-tuning dataset is constructed by combining the relationships between the entities.
4. The method according to claim 1, characterized in that The method of fine-tuning the preset vulnerability repair model based on the fine-tuning data set to obtain the target vulnerability repair model includes: The fine-tuning data set is input into the preset vulnerability repair large model, and the lora fine-tuning method is used to add additional outputs on the basis of the preset vulnerability repair large model to obtain the target vulnerability repair large model.
5. The method according to claim 1, characterized in that The vulnerability repair intelligent question-answering system includes: A code execution unit, used to obtain request parameters and key parameter information in the vulnerability intelligence knowledge graph corresponding to the input vulnerability information; A real-time information search unit, used to search and obtain information search results corresponding to the vulnerability information; A vulnerability intelligence assistant, used to send a request to the vulnerability intelligence knowledge graph based on the request parameters and key parameter information to obtain vulnerability repair background data; A search query unit, configured to obtain vulnerability related information associated with the vulnerability information according to the vulnerability repair related data; The vulnerability repair generating unit is used to combine the information search results, the vulnerability repair background data and the vulnerability association information to generate a vulnerability repair solution.
6. The method according to claim 1, characterized in that The method further comprises: The vulnerability repair intelligent question-answering system is used to generate a vulnerability repair solution corresponding to the vulnerability information.
7. A vulnerability repair intelligent question-answering device, characterized in that: The device comprises: Data acquisition module, used to obtain vulnerability intelligence data sets; A knowledge graph construction module, used to construct a vulnerability intelligence knowledge graph based on the vulnerability intelligence dataset; A fine-tuning dataset construction module, used to construct a fine-tuning dataset using the vulnerability intelligence knowledge graph; A model fine-tuning module, used to fine-tune the preset vulnerability repair model based on the fine-tuning data set to obtain a target vulnerability repair model; The system building module is used to build a vulnerability repair intelligent question-answering system using the target vulnerability repair large model.
8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the vulnerability repair intelligent question-answering method according to any one of claims 1 to 6 by executing the computer instructions.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the vulnerability repair intelligent question-answering method according to any one of claims 1 to 6.
10. A computer program product, characterized in that It includes computer instructions, and the computer instructions are used to enable a computer to execute the vulnerability repair intelligent question-answering method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Vulnerability knowledge graph processing method and device, equipment and medium
CN115827895A
Question and answer model training method and intelligent question and answer method and device in network security field
CN116933075A
Network attack data processing method and device, equipment and medium
CN117240575A
Vulnerability relationship mining method and device based on large model, equipment and medium
CN117390634A
Vulnerability information query method and device based on large model technology, equipment and medium
CN117493522A
Cited By
Security vulnerability processing method and device based on large model, equipment and medium
CN120528678A
Security vulnerability handling methods, devices, equipment, and media based on large models
CN120528678B