Vulnerability full life cycle management method and system
By automatically importing assets and creating new scanning tasks, accurately matching vulnerabilities and assets, and assigning value repair priorities, the problem of incompatibility of vulnerability management in the existing technology is solved, and precise management of vulnerabilities and assets and network security is improved.
Patent Information
- Application Number
- CN202510054998.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-06-10
AI Technical Summary
The existing technology is difficult to effectively match vulnerabilities and assets of different types of assets in the entire life cycle management of vulnerabilities, and lacks systematic operations and intuitive data management of vulnerability repair situations.
By automatically importing assets and creating new scanning tasks, using vulnerability scanning equipment for vulnerability detection, accurately match scanned vulnerabilities and assets, assign vulnerabilities to fix priority, and manage and visualize the entire life cycle of vulnerabilities.
It realizes accurate matching and management of vulnerabilities and assets, improves the efficiency and accuracy of vulnerability repair, and enhances the transparency of network security management and the overall security of the system.
Smart Images

Figure CN120124063A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a vulnerability full life cycle management method and system. Background Art
[0002] With the rapid development of information technology, network security issues have increasingly become the focus of attention of countries, enterprises and individuals. Therefore, higher requirements have been placed on the discovery and management of vulnerabilities in evaluations such as classified protection and commercial cryptography. Vulnerability detection has become routine, and network security management has tended to be centralized. In periodic vulnerability detection, a large number of vulnerabilities need to be managed throughout their life cycles. Even though there are vulnerability management modules in vulnerability detection tools, manual operation of each vulnerability is still required, which requires a large amount of time and labor costs.
[0003] The current vulnerability full life cycle management methods can achieve the discovery and management of vulnerabilities, but insufficient attention has been paid to aspects such as the matching of vulnerabilities with asset management systems, the operation of vulnerability repair situations, and the intuitive management and analysis of vulnerability discovery and repair data. Moreover, more asset scenarios have not been scanned and managed, and there are deficiencies in the richness and comprehensiveness of vulnerability operation status. Summary of the Invention
[0004] The present invention aims to overcome at least one defect of the above-mentioned prior art, and provides a vulnerability full life cycle management method and system for solving the technical problem that vulnerabilities of different types of assets cannot be scanned, reasonably managed and operated in the prior art.
[0005] The present invention provides a vulnerability full life cycle management method, including:
[0006] S1. Import the managed assets to generate an asset list;
[0007] S2. Create a scanning task according to the asset list, select the assets to be scanned, and perform vulnerability detection on the assets to be scanned through a vulnerability scanning device;
[0008] S3. Obtain the scanned vulnerabilities obtained after the scanning by the vulnerability scanning device;
[0009] S4. Match the obtained scanned vulnerabilities with the asset list, and perform a unique ID binding with the matched assets to obtain a unique asset ID;
[0010] S5. Assign a vulnerability repair priority value to the matched vulnerabilities;
[0011] S6. After the assignment of the vulnerability repair priority value is completed, operate and manage the full life cycle of the vulnerabilities according to the vulnerability repair priority.
[0012] S7. Visualize all vulnerability data and status.
[0013] By automatically importing assets and setting up vulnerability scanning tasks, accurately match the scanned vulnerabilities with the asset list, generate a unique ID binding for each vulnerability and the matched asset, ensure the accurate correspondence between vulnerabilities and assets, facilitate the subsequent management and tracking of the vulnerability life cycle and assets, without manual operation, and improve the efficiency and accuracy of automated vulnerability identification and asset management operations.
[0014] Through the display, operation, and management of the entire vulnerability life cycle, and visualizing all vulnerability data and status, achieve closed-loop management of vulnerabilities, enabling network security managers to intuitively understand the security status of the current system, quickly locate problems, provide strong data support for decision-making, help eliminate security risks in a timely manner, and enhance the overall security of the system.
[0015] Among them, the scanning in the newly created scanning task described in S2 includes an online scanning mode and an offline scanning mode;
[0016] The online scanning mode sends vulnerability scanning tasks to the corresponding vulnerability scanning devices through API interfaces;
[0017] The offline scanning mode uses a handheld vulnerability scanning device to detect vulnerabilities and upload the detected vulnerabilities for unified management, which is used for special network environments to improve the applicability of the device in various network environments.
[0018] In the online scanning mode, after the user selects the assets to be scanned, basic information such as "task name", "task device ID", and "scanning type" needs to be set, and the vulnerability information of the corresponding task is obtained through the API and put into the corresponding scanning task.
[0019] The newly created scanning task includes a periodic scanning mode and a scheduled scanning mode;
[0020] In the periodic scanning mode, when the system detects that the IP and URL information of the scanned assets has changed, a scanning task is sent to the vulnerability scanning device again. The user can close the periodic task at any time. The scheduled scanning is used for single scanning tasks.
[0021] The obtaining of the scanned vulnerabilities obtained after the scanning by the vulnerability scanning device described in S3 also includes scanning vulnerabilities for temporary assets in the unimported asset list, which is used to supplement the scanning operation scenario of temporary assets, ensure that vulnerability scanning and asset management can be carried out for different assets, and improve the security of assets.
[0022] The specific matching of the obtained scanned vulnerabilities with the asset list in S4 includes:
[0023] When a host vulnerability is detected, the vulnerability scanning device returns the IP and port of the location where the vulnerability is located, and the IP can be directly and fully matched with the assets;
[0024] When a web vulnerability is detected, the vulnerability scanning device returns the URL of the location where the vulnerability is located, and the URL and the assets are matched at multiple levels;
[0025] When a vulnerability of unknown classification is detected, find the asset attribution of the detected vulnerability and classify the vulnerability into the correct unit;
[0026] When the same asset belongs to multiple different departments or units, the vulnerabilities obtained for this asset are split into multiple vulnerability data belonging to different departments or units.
[0027] By accurately matching vulnerabilities with assets, it is ensured that each detected vulnerability can be accurately corresponding to the specific assets in the system through specific matching strategies, the specific assets and vulnerability types that need to be repaired can be quickly located, the speed of vulnerability repair can be accelerated, the risk of the system being attacked can be effectively reduced, and for unknown classification vulnerabilities that cannot be automatically matched, a matching mechanism can also be provided to find the asset attribution of the vulnerabilities, so as to classify them into the correct units, ensure that all vulnerabilities are reasonably processed, gradually discover and identify unknown assets in the system, further improve the enterprise's asset management system, and for the vulnerabilities in the assets jointly managed by multiple departments, by splitting the vulnerability data, it is ensured that each relevant department can obtain the vulnerability information it needs, reasonably allocate security resources, contribute to optimizing the asset management strategy, and improving the overall management level.
[0028] In order to enable relevant departments to more clearly understand the harm degree of vulnerabilities and preferentially repair the vulnerabilities that have the greatest impact on themselves, the assignment of vulnerability repair priorities for the matched vulnerabilities in S5 specifically includes:
[0029] Construct an algorithm based on five index dimensions of asset location L, asset value V, risk level R, exploitation possibility E, and repair cost C, and let the vulnerability repair priority score be S. The larger the S value, the higher the priority of this vulnerability that needs to be repaired;
[0030] The asset location L ∈ {Internet and Intranet, Internet, Intranet}, and the corresponding values are: L{Internet and Intranet} = 7, L{Internet} = 5, L{Intranet} = 3, where the higher the number, the larger the influence range;
[0031] The asset value V ∈ {Equal Protection Level 1, Equal Protection Level 2, Equal Protection Level 3, Equal Protection Level 4, Equal Protection Level 5}, and the corresponding values are: V{Equal Protection Level 5} = 9, V{Equal Protection Level 4} = 7, V{Equal Protection Level 3} = 5, V{Equal Protection Level 2} = 3, V{Equal Protection Level 1} = 1, where the higher the number, the greater the value;
[0032] The risk level \(R\in\{Ultra - critical, High - risk, Medium - risk, Low - risk, Information\}\), and the corresponding values are: \(R\in\{Ultra - critical\}=9\), \(R\in\{High - risk\}=7\), \(R\in\{Medium - risk\}=5\), \(R\in\{Low - risk\}=3\), \(R\in\{Information\}=1\). The higher the number, the higher the risk level.
[0033] The possibility of exploitation \(E\in\{Very - high, Relatively - high, Medium, Relatively - low, Very - low\}\), and the corresponding values are: \(E\{Very - high\}=9\), \(E\{Relatively - high\}=7\), \(E\{Medium\}=5\), \(E\{Relatively - low\}=3\), \(E\{Very - low\}=1\). The higher the number, the higher the possibility of exploitation.
[0034] The repair cost \(C\in\{Very - high, Relatively - high, Medium, Relatively - low, Very - low\}\), and the corresponding values are: \(C\{Very - high\}=9\), \(C\{Relatively - high\}=7\), \(C\{Medium\}=5\), \(C\{Relatively - low\}=3\), \(C\{Very - low\}=1\). The higher the number, the higher the repair cost.
[0035] The calculation formula for the vulnerability repair priority score \(S\) is:
[0036] \(S = w\) 1 \(\times R+w\) 2 \(\times E+w\) 3 \(\times L+w\) 4 \(\times V - w\) 5 \(\times C\)
[0037] Where, \(w\) 1 \(\sim w\) 5 are the weight parameters of each index dimension, and \(w\) 1 \(+w\) 2 \(+w\) 3 \(+w\) 4 \(+w\) 5 \( = 1\).
[0038] When designing the weights, there are the following prerequisite conditions: The risk level and the possibility of exploitation are key factors, which have a greater impact on the priority and higher weights. The asset location and asset value are of secondary importance, but the weights may need to be adjusted in special scenarios. The repair cost is a negative indicator. The higher the score, the greater the repair difficulty, which has a certain inhibitory effect on the priority.
[0039] Therefore, according to the prerequisite conditions and the information entropy method, the weights of the 5 index dimensions are constructed and calculated. The specific weights of each index dimension include:
[0040] S51. Construct a decision matrix. Let the number of vulnerabilities be \(m\). According to the five index dimensions, form a decision matrix \(X\):
[0041]
[0042] S52. Adopt normalization processing to eliminate the differences between each index dimension:
[0043]
[0044] where p ij is the normalized value of the i-th vulnerability under the j-th metric;
[0045] S53. Calculate the entropy value of each metric dimension:
[0046]
[0047] where k is the normalization factor;
[0048] S54. Calculate the weights, and the weight of each metric is:
[0049]
[0050] Obtain the weights of each metric dimension.
[0051] The vulnerability full life cycle described in S6 includes To Be Fixed, To Be Retested, Fixed, False Positive, Accepted Risk, Closed - *, and by defining each stage of the vulnerability full life cycle, it aims to establish a standardized vulnerability management process.
[0052] When the vulnerability detection device detects a new vulnerability and uploads it, the vulnerability status is marked as To Be Fixed;
[0053] The To Be Retested is that after the status of the To Be Fixed vulnerability is selected as Fixed, the vulnerability status is marked as To Be Retested;
[0054] The Fixed is that after the To Be Retested or To Be Fixed vulnerability is confirmed to no longer exist after re - vulnerability detection, the vulnerability status is marked as Fixed;
[0055] The False Positive is that the vulnerability operator judges the To Be Fixed vulnerability and believes that the vulnerability does not exist, and marks the vulnerability status as False Positive, and the vulnerability will not be prompted for a period of time;
[0056] The Accepted Risk is that the vulnerability responsible person confirms that the vulnerability cannot be fixed in the short term, marks the vulnerability status as Accepted Risk, and the vulnerability enters the whitelist and will not be prompted for a period of time;
[0057] The Closed - * includes Closed - Fixed, Closed - False Positive, Closed - Accepted Risk;
[0058] The Closed - Fixed closes the vulnerability with the status of Fixed, and the vulnerability life cycle ends;
[0059] The Closed - False Positive closes the vulnerability with the status of False Positive, and the vulnerability life cycle ends;
[0060] The closed - accepted risk closes the vulnerabilities with the risk status of accepted risk, and the vulnerability cycle ends.
[0061] Due to process standardization and automation, by clarifying the tasks and status transition conditions at each life stage of vulnerabilities, security resources can be allocated more effectively, the speed of vulnerability repair can be accelerated, the risk time of vulnerabilities can be shortened, and the response speed and security of the system can be improved. Through continuous vulnerability detection and repair, and under the judgment and re - detection confirmation of vulnerability operators, as well as the reasonable risk decision - making of vulnerability responsible persons, the situations of false positives and false negatives can be effectively reduced, the anti - risk ability of the system can be improved, the risks such as system crashes or data leaks caused by vulnerabilities can be reduced, and the stability and reliability of the system can be improved.
[0062] Since some repaired, to - be - retested or false - positive vulnerabilities still exist after detection or judgment, in order to ensure that the status of vulnerabilities is continuously tracked and processed until the vulnerabilities are completely repaired and resolved, marking the vulnerability status as to - be - repaired also includes:
[0063] For the vulnerabilities marked with the status of repaired or to - be - retested, if the vulnerabilities still exist after vulnerability detection, mark the vulnerability status as to - be - repaired;
[0064] Or the vulnerability status is marked as a false positive by the vulnerability responsible person, and after the judgment of the vulnerability operator, it is considered that the vulnerability really exists, then mark the vulnerability status as to - be - repaired.
[0065] By adding a vulnerability status transition and fallback mechanism, it is ensured that omissions and misjudgments in the vulnerability handling process can be corrected in a timely manner, further reducing the system security risk, enhancing the management transparency and traceability of vulnerabilities, and facilitating subsequent vulnerability display and problem analysis.
[0066] In order to ensure that each discovered vulnerability data can be independently and accurately recorded and processed, after the end of the vulnerability life cycle, when the same vulnerability of the same asset is discovered again, a new vulnerability data is generated, which is not merged with the vulnerabilities in the closed - * status. Generating a new vulnerability data can flexibly arrange the processing priority, allocate resources and specify the repair strategy, without being affected by the closed vulnerability status, which helps to improve the response speed and efficiency of vulnerability handling and ensure the timely guarantee of system security. Through the operation of the full vulnerability life cycle, the whole process of vulnerability discovery, handling, repair, etc. can be clearly displayed. For some vulnerabilities that are difficult to completely repair or frequently appear, generating new vulnerability data helps to reproduce the vulnerability scenario, deeply study the causes and repair methods of vulnerabilities, so as to find more effective solutions.
[0067] To visually reflect the vulnerability status of the current system, including data such as the number, type, and repair progress of vulnerabilities, enabling security managers to quickly grasp the system security status, the vulnerability data and status in the S7 need to be visually displayed, and data analysis of the vulnerability data is required, specifically including:
[0068] Calculate the real-time vulnerability repair rate:
[0069] Real-time vulnerability repair rate = ([Closed - Fixed] + [Fixed]) / (Total number of vulnerabilities - [False positives] - [Closed - False positives] - [Accepted risks] - [Closed - Accepted risks]);
[0070] By setting custom parameters H, M, and L to represent the expected repair times for high, medium, and low-risk vulnerabilities respectively, the security team can allocate resources more reasonably, ensure that high-risk vulnerabilities are processed first, and at the same time take into account the repair work of other vulnerabilities.
[0071] When the real-time time T is set, the real-time vulnerability repair rate at any time can be obtained;
[0072] Monthly high-risk repair rate: The ratio of vulnerabilities discovered in the data statistics period of T - 2 that have been repaired as of T - 1;
[0073] Quarterly high-risk repair rate: The ratio of vulnerabilities discovered in the data statistics period from T - 4 to T - 1 that have been repaired as of T - 1.
[0074] By calculating the monthly high-risk repair rate and the quarterly high-risk repair rate, the long-term trend of system vulnerability repair can be tracked, providing data support for the formulation and optimization of security policies.
[0075] In order to be able to track and update the status of vulnerabilities in real time and improve the ability to manage vulnerabilities automatically, a vulnerability update mechanism is adopted to realize the status operation of vulnerabilities, specifically including:
[0076] The original vulnerability status is to be repaired. When the vulnerability is discovered again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability, the new task ID is added to the task ID in the list page, the vulnerability status remains unchanged, the last discovery time is updated, the operation time is updated. When the vulnerability is not discovered in the new scan task, the vulnerability status is marked as repaired and the operation time is updated;
[0077] The original vulnerability status is repaired. When the vulnerability is discovered again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability, the new task ID is added to the task ID in the list page, the vulnerability status is marked as to be repaired, the last discovery time and the operation update time are updated. When the vulnerability is not discovered in the new scan task, no additional operation is performed;
[0078] The original vulnerability status is pending retest. When it appears again in a new scanning task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page, the vulnerability status is marked as pending repair, the last discovery time and the operation update time are updated, and a record is added to the operation record of the vulnerability: retest failed, not found in the new scanning task, the vulnerability status is marked as fixed, the operation update time is updated, and a record is added to the vulnerability operation record: retest passed;
[0079] The original vulnerability status is risk accepted. When it is discovered again in a new scanning task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page, the vulnerability status remains unchanged, the last discovery time and the operation update time are updated, and no additional operation is performed if it is not found in the new scanning task;
[0080] The original vulnerability status is false positive. When it is discovered again in a new scanning task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page, the vulnerability status is false positive, the status remains unchanged, the last discovery time is updated, the operation update time is updated, and no additional operation is performed if it is not found in the new scanning task;
[0081] The original vulnerability status is closed-*. When it is discovered again in a new scanning task, a new vulnerability is added to the database;
[0082] For multiple vulnerability data of the same asset belonging to multiple different departments or units, when any one department or unit has completed the repair or marked a false positive for the vulnerability, the vulnerability belonging to other departments or units will be marked with the same status. When any one department or unit accepts the risk of the vulnerability, it does not affect other departments or units to dispose of the vulnerability;
[0083] For assets with unclosed vulnerabilities that need to be taken offline, after the operation personnel confirm the asset offline, the status of all vulnerabilities belonging to the asset will be changed to closed-fixed, and the asset name will be marked as offline.
[0084] By adopting an automated vulnerability update mechanism, it is possible to track and update the status of vulnerabilities in real time, ensure the accuracy and timeliness of vulnerability information, simplify the vulnerability management process, and ensure the accuracy of vulnerability repair. For the situation where the same asset belongs to multiple departments or units, by sharing vulnerability information, cross-departmental collaboration can be achieved. For assets that need to be taken offline, through manual confirmation and status change, it is ensured that each type of vulnerability can be processed in a timely manner, avoiding omission and delay, and further ensuring the security of the asset and the quality of vulnerability repair.
[0085] The present invention also provides a vulnerability full life cycle management system, which is characterized in that it includes:
[0086] Asset Management Module: It is used to import and update the managed assets, providing basic asset support for subsequent vulnerability operations;
[0087] Vulnerability Scanning Task Management Module: It is used to create and manage scanning tasks;
[0088] Vulnerability Acquisition Module: It is used to obtain the vulnerabilities scanned after the scanning tasks are completed in the vulnerability scanning devices;
[0089] Vulnerability and Asset Matching Module: It is used to match the obtained vulnerabilities with the assets in the system;
[0090] Vulnerability Repair Priority Module: It is used to assign values to the vulnerability repair priorities;
[0091] Vulnerability Status Operation Module: It is used to display, operate, and manage the entire life cycle of vulnerabilities;
[0092] Vulnerability Data Analysis Module: It is used to visually display all the vulnerability data and status in the system.
[0093] The beneficial effects of the present invention are as follows: For the method and system for managing the entire life cycle of vulnerabilities, through comprehensive automated vulnerability and asset matching rules, each vulnerability is accurately matched with the assets, and different types of assets in the system are detected and managed. The asset management system is improved, and through the standardized management of vulnerabilities in each stage of the entire life cycle of vulnerabilities, it is ensured that each vulnerability can be processed in a timely and effective manner, reducing vulnerability omissions and duplicate processing, optimizing the allocation of security resources, shortening the risk events of vulnerabilities existing, through the visual display of the entire life cycle of vulnerabilities and vulnerability data, intuitively reflecting the current vulnerability status of the system, timely adjusting the vulnerability repair strategy, setting the expected time for the risk level of vulnerabilities, ensuring that high-risk vulnerabilities can be processed first, adopting a vulnerability update mechanism to operate the vulnerability status, ensuring the integrity and accuracy of the vulnerability management process, improving the security of the system and the repair quality of vulnerabilities, and reducing manual intervention. BRIEF DESCRIPTION OF THE DRAWINGS
[0094] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0095] Figure 1 It is a schematic diagram of the steps of the method for managing the entire life cycle of vulnerabilities.
[0096] Figure 2 It is the flow chart of the vulnerability status.
[0097] Figure 3 It is the overall flowchart of the vulnerability full life cycle management method. Specific implementation manners
[0098] To make the objectives, technical solutions and advantages of the present invention clearer, the following will further describe the embodiments of the present invention in detail with reference to the accompanying drawings:
[0099] The embodiments of the present invention provide an embodiment of a vulnerability full life cycle management method and system. Although the logical order is shown in the flowchart, under certain data, the steps shown or described can be completed in an order different from that here.
[0100] Embodiment 1: Refer to Figure 1
[0101] As Figure 1 shown in the step schematic diagram of the vulnerability full life cycle management method, the present invention provides a vulnerability full life cycle management method, including:
[0102] S1. Import the managed assets to generate an asset list;
[0103] S2. Create a scanning task according to the asset list, select the assets to be scanned, and perform vulnerability detection on the assets to be scanned through a vulnerability scanning device;
[0104] S3. Obtain the scanned vulnerabilities obtained after the scanning by the vulnerability scanning device;
[0105] S4. Match the obtained scanned vulnerabilities with the asset list, and perform unique ID binding with the matched assets to obtain unique asset IDs;
[0106] S5. Assign a vulnerability repair priority to the matched vulnerabilities;
[0107] S6. After the vulnerability repair priority assignment is completed, operate and manage the full life cycle of the vulnerabilities according to the vulnerability repair priority;
[0108] S6. After the vulnerability repair priority assignment is completed, operate and manage the full life cycle of the vulnerabilities according to the vulnerability repair priority;
[0109] S7. Visually display all vulnerability data and statuses.
[0110] By automatically importing assets and setting up vulnerability scanning tasks, accurately matching the scanned vulnerabilities with the asset list, generating unique ID bindings for each vulnerability and the matched assets, ensuring the accurate correspondence between vulnerabilities and assets, facilitating subsequent management and tracking of the vulnerability life cycle and assets, without manual operation, and improving the efficiency and accuracy of automated vulnerability identification and asset management operations.
[0111] Through the display, operation, and management of the entire vulnerability life cycle, and visually presenting all vulnerability data and status, realizing the closed-loop management of vulnerabilities, enabling network security managers to intuitively understand the security status of the current system, quickly locate problems, providing strong data support for decision-making, helping to eliminate security risks in a timely manner, and enhancing the overall security of the system.
[0112] Example 2: Refer to Figure 2
[0113] Compared with Example 1, the difference is that the vulnerability full life cycle management method further includes:
[0114] Among them, the scanning in the newly created scanning task in S2 includes an online scanning mode and an offline scanning mode;
[0115] The online scanning mode sends vulnerability scanning tasks to the corresponding vulnerability scanning devices through API interfaces;
[0116] The offline scanning mode uses a handheld vulnerability scanning device to detect vulnerabilities and uploads the detected vulnerabilities for unified management, which is used for special network environments to improve the applicability of the device in various network environments.
[0117] In the online scanning mode, after the user selects the assets to be scanned, basic information such as "task name", "task device ID", and "scanning type" needs to be set, and the vulnerability information of the corresponding task is obtained through the API and put into the corresponding scanning task.
[0118] The newly created scanning task includes a periodic scanning mode and a scheduled scanning mode;
[0119] In the periodic scanning mode, when the system detects that the IP and URL information of the assets to be scanned has changed, a scanning task is sent to the vulnerability scanning device again, and the user can close the periodic task at any time. The scheduled scanning is used for single scanning tasks.
[0120] The newly created scanning task also includes a management scanning task. The user can view information such as the names, quantities, and task statuses of all issued scanning tasks on the management scanning task page, and can directly operate the task to perform scanning again, view the corresponding vulnerabilities through the task, etc., to realize the management of scanning tasks.
[0121] In step S3, the scanned vulnerabilities obtained after the scanning by the vulnerability scanning device mainly target the assets imported into the asset list. Since the vulnerability scanning tasks in the system correspond one-to-one with the scanning tasks in the vulnerability scanning device, the obtained vulnerabilities will also correspond to the vulnerability scanning tasks in the system.
[0122] It also includes that for the assets not imported into the asset list, scanning tasks can also be established in the vulnerability scanning device to supplement the scanning operation scenarios of temporary assets, ensuring that vulnerability scanning and asset management can be carried out for different assets and improving the security of assets.
[0123] In step S4, the specific process of matching the obtained scanned vulnerabilities with the asset list includes:
[0124] When host vulnerabilities are obtained, the vulnerability scanning device returns the IP and port of the location where the vulnerability is located, and directly performs a full match of the IP with the assets.
[0125] When web vulnerabilities are obtained, the vulnerability scanning device returns the URL of the location where the vulnerability is located, and performs a multi-level match of the URL and the assets.
[0126] Suppose the URL returned by the vulnerability scanning device is "https: / / www.aaa.com / bb / cc / dd". First, perform a full match with the assets of the corresponding vulnerability scanning task. If no match is found, truncate " / dd", and use "https: / / www.aaa.com / bb / cc" to perform a full match with the assets of the vulnerability's scanning task until "https: / / www.aaa.com" is intercepted. If still no match is found, at this time, considering the crawler characteristics during the scanning of the vulnerability scanning device, it may have scanned assets outside the target. Go back to "https: / / www.aaa.com / bb / cc / dd", and at this time, match this URL with all web assets in the system. If no match is found, repeat the above truncation and matching method until "https: / / www.aaa.com". If still no match is found, classify the assets and vulnerabilities as "unknown" and perform manual matching processing.
[0127] When vulnerabilities of unknown classification are obtained, find the asset attribution of the obtained vulnerabilities. After clarifying the asset attribution, the vulnerability list will dynamically update the attribution of the vulnerabilities and classify the vulnerabilities into the correct unit. It is also possible to detect and manage unknown assets through vulnerability detection.
[0128] When the same asset belongs to multiple different departments or units, the vulnerabilities obtained for this asset will be split into multiple vulnerability data belonging to different departments or units.
[0129] After the vulnerability and asset are successfully matched, the attribution of the vulnerability is bound to a unique asset ID. Even if the matching features of the asset, such as the IP or URL, change subsequently, it will not affect the original attribution of the vulnerability.
[0130] By precisely matching vulnerabilities with assets, it is ensured that each detected vulnerability can be accurately mapped to a specific asset in the system through specific matching strategies. This can quickly locate the specific assets and vulnerability types that need to be repaired, accelerate the speed of vulnerability repair, effectively reduce the risk of the system being attacked. For unknown classified vulnerabilities that cannot be automatically matched, a matching mechanism can also be provided to find the asset attribution of the vulnerabilities, so as to classify them into the correct units, ensure that all vulnerabilities are reasonably processed, gradually discover and identify unknown assets in the system, further improve the enterprise's asset management system. And for the vulnerabilities in the assets jointly managed by multiple departments, by splitting the vulnerability data, it is ensured that each relevant department can obtain the vulnerability information it needs, reasonably allocate security resources, which helps to optimize the asset management strategy and improve the overall management level.
[0131] The specific assignment of vulnerability repair priorities to the matched vulnerabilities described in S5 includes:
[0132] Construct an algorithm based on five indicator dimensions: asset location L, asset value V, risk level R, exploitation possibility E, and repair cost C. Let the vulnerability repair priority score be S. The larger the S value, the higher the priority for this vulnerability to be repaired;
[0133] The asset location L ∈ {Internet and Intranet, Internet, Intranet}, and the corresponding values are: L{Internet and Intranet} = 7, L{Internet} = 5, L{Intranet} = 3. The higher the number, the larger the impact range;
[0134] The asset value V ∈ {Level 1 of Equal Protection, Level 2 of Equal Protection, Level 3 of Equal Protection, Level 4 of Equal Protection, Level 5 of Equal Protection}, and the corresponding values are: V{Level 5 of Equal Protection} = 9, V{Level 4 of Equal Protection} = 7, V{Level 3 of Equal Protection} = 5, V{Level 2 of Equal Protection} = 3, V{Level 1 of Equal Protection} = 1. The higher the number, the greater the value;
[0135] The risk level R ∈ {Ultra-Critical, High-Risk, Medium-Risk, Low-Risk, Information}, and the corresponding values are: R ∈ {Ultra-Critical} = 9, R ∈ {High-Risk} = 7, R ∈ {Medium-Risk} = 5, R ∈ {Low-Risk} = 3, R ∈ {Information} = 1. The higher the number, the higher the danger level;
[0136] The exploitation possibility E ∈ {Very High, Relatively High, Medium, Relatively Low, Very Low}, and the corresponding values are: E{Very High} = 9, E{Relatively High} = 7, E{Medium} = 5, E{Relatively Low} = 3, E{Very Low} = 1. The higher the number, the higher the exploitation possibility;
[0137] The repair cost C ∈ {extremely high, relatively high, medium, relatively low, extremely low}, and the corresponding values are: C{extremely high} = 9, C{relatively high} = 7, C{medium} = 5, C{relatively low} = 3, C{extremely low} = 1. The higher the number, the higher the repair cost.
[0138] The calculation formula for the vulnerability repair priority score S is:
[0139] S = w 1 ×R + w 2 ×E + w 3 ×L + w 4 ×V - w 5 ×C
[0140] Where, w 1 ~w 5 are the weight parameters of each index dimension, and w 1 + w 2 + w 3 + w 4 + w 5 = 1.
[0141] When designing the weights, there are the following prior conditions: the risk level and exploitation possibility are key factors, which have a greater impact on the priority and higher weights. The asset location and asset value are of secondary importance, but the weights may need to be adjusted in special scenarios. The repair cost is a negative indicator, and the higher the score, the greater the repair difficulty, which has a certain inhibitory effect on the priority.
[0142] Therefore, according to the prior conditions and the information entropy value method, the weights of the 5 index dimensions are constructed and calculated. The specific weights of each index dimension include:
[0143] S51. Construct a decision matrix. Let the number of vulnerabilities be m, and according to the five index dimensions, form a decision matrix X:
[0144]
[0145] S52. Adopt normalization processing to eliminate the differences between each index dimension:
[0146]
[0147] Where, p ij is the normalized value of the i-th vulnerability under the j-th index;
[0148] S53. Calculate the entropy value of each index dimension:
[0149]
[0150] Where, k is the normalization factor;
[0151] S54. Calculate the weights. The weight of each indicator is as follows:
[0152]
[0153] Obtain the weights of each indicator dimension.
[0154] As Figure 2 shown, the vulnerability full life cycle described in S6 includes to be repaired, to be retested, repaired, false positive, accept risk, closed - *, etc. By defining each stage of the vulnerability full life cycle, it aims to establish a standardized vulnerability management process.
[0155] When the described vulnerability detection device detects a new vulnerability and uploads it, mark the vulnerability status as to be repaired;
[0156] The to be retested is that after the to be repaired vulnerability status is selected as repaired, mark the vulnerability status as to be retested;
[0157] The repaired is that after the to be retested or to be repaired vulnerability is confirmed to be non - existent after re - vulnerability detection, mark the vulnerability status as repaired;
[0158] The false positive is that the vulnerability operator judges the to be repaired vulnerability and believes that the vulnerability does not exist, mark the vulnerability status as false positive, and do not prompt this vulnerability for a period of time;
[0159] The accept risk is that the vulnerability responsible person confirms that the vulnerability cannot be repaired in the short term, mark the vulnerability status as accept risk, and this vulnerability enters the whitelist and is not prompted for a period of time;
[0160] The closed - * includes closed - repaired, closed - false positive, closed - accept risk;
[0161] The closed - repaired closes the vulnerability with the status of repaired, and the vulnerability life cycle ends;
[0162] The closed - false positive closes the vulnerability with the status of false positive, and the vulnerability life cycle ends;
[0163] The closed - accept risk closes the vulnerability with the status of accept risk, and the vulnerability cycle ends.
[0164] Due to process standardization and automation, by clarifying the tasks and status transition conditions at each life stage of vulnerabilities, security resources can be allocated more effectively, the speed of vulnerability repair can be accelerated, the risk time of vulnerabilities can be shortened, and the system's response speed and security can be improved. Through continuous vulnerability detection and repair, and under the judgment and re-detection confirmation of vulnerability operators, as well as the reasonable risk decision-making of vulnerability owners, the situations of false positives and false negatives can be effectively reduced, the system's anti-risk ability can be improved, the risks such as system crashes or data leaks caused by vulnerabilities can be reduced, and the stability and reliability of the system can be improved.
[0165] Since for some vulnerabilities that have been repaired, waiting for re-testing, or are false positives, after detection or judgment, the situation where the vulnerability still exists may occur. To ensure that the status of the vulnerability is continuously tracked and processed until the vulnerability is completely repaired and resolved, marking the vulnerability status as to be repaired also includes:
[0166] For the vulnerability whose status is marked as repaired or waiting for re-testing, if the vulnerability still exists after vulnerability detection, mark the vulnerability status as to be repaired;
[0167] Or the vulnerability status is marked as a false positive by the vulnerability owner, and after the judgment of the vulnerability operator, it is considered that the vulnerability actually exists, then mark the vulnerability status as to be repaired.
[0168] By adding a status transition and rollback mechanism for vulnerabilities, it is ensured that omissions and misjudgments in the vulnerability handling process can be corrected in a timely manner, further reducing the system security risk, enhancing the management transparency and traceability of vulnerabilities, and facilitating subsequent vulnerability display and problem analysis.
[0169] To ensure that the vulnerability data discovered each time can be independently and accurately recorded and processed, after the end of the vulnerability life cycle, when the same vulnerability of the same asset is discovered again, a new vulnerability data is generated, which is not merged with the vulnerabilities in the closed - * status. Generating a new vulnerability data can flexibly arrange the processing priority, allocate resources, and specify the repair strategy, without being affected by the closed vulnerability status, which helps to improve the response speed and efficiency of vulnerability handling and ensure the timely guarantee of system security. Through the operation of the entire vulnerability life cycle, the whole process of vulnerability discovery, handling, repair, etc. can be clearly displayed. For some vulnerabilities that are difficult to completely repair or frequently occur, generating new vulnerability data helps to reproduce the vulnerability scenario, deeply study the vulnerability cause and repair method, so as to find a more effective solution.
[0170] In order to visually reflect the current vulnerability status of the system, including data such as the number, type, and repair progress of vulnerabilities, so that security managers can quickly grasp the system security status, the data analysis of the vulnerability data is required for the visual display of all vulnerability data and status in S7, specifically including:
[0171] Calculate the real-time vulnerability repair rate:
[0172] Real-time vulnerability repair rate = (
Closed - Fixed
Fixed
False positives
Closed - False positives
Accepted risks
Closed - Accepted risks
[0173] By setting custom parameters H, M, and L, which are used to represent the expected repair times for high, medium, and low-risk vulnerabilities respectively, the security team can allocate resources more reasonably, ensure that high-risk vulnerabilities are processed first, and at the same time take into account the repair work of other vulnerabilities.
[0174] After setting the real-time time T, the real-time vulnerability repair rate at any time can be obtained. For example, when T = October 22, 2024 and H = 30, applying the above formula can calculate the repair rate of all high-risk vulnerabilities whose first discovery time was before September 22, 2024. By analogy, the vulnerability repair rates at different time points and with different expected times can be obtained;
[0175] Monthly high-risk repair rate: The ratio of vulnerabilities discovered during the data statistics period from T - 2 that have been repaired by T - 1. For example, on July 1, the repair rate of high-risk vulnerabilities discovered in May can be statistically calculated. The denominator is the number of high-risk vulnerabilities discovered in May (regardless of whether it was the first discovery of the vulnerability), and the numerator is the number of vulnerabilities in the denominator that were repaired in May and June;
[0176] Quarterly high-risk repair rate: The ratio of vulnerabilities discovered during the data statistics period from T - 4 to T - 1 that have been repaired by T - 1. For example, in July of the third quarter, the repair rate of high-risk vulnerabilities in the second quarter is statistically calculated. The denominator is the total number of high-risk vulnerabilities discovered from March to May (regardless of whether it was the first discovery of the vulnerability), and the numerator is the number of high-risk vulnerabilities in the denominator that have been repaired from March to June.
[0177] By calculating the monthly high-risk repair rate and the quarterly high-risk repair rate, the long-term trend of system vulnerability repair can be tracked, providing data support for the formulation and optimization of security policies.
[0178] In order to be able to track and update the status of vulnerabilities in real time and improve the ability to manage vulnerabilities automatically, a vulnerability update mechanism is adopted to achieve the status operation of vulnerabilities, specifically including:
[0179] The original vulnerability status is to be repaired. When the same vulnerability is discovered again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability, the new task ID is added to the task ID in the list page, the vulnerability status remains unchanged, the last discovery time is updated, and the operation time is updated. If the vulnerability is not discovered in the new scan task, the vulnerability status is marked as repaired and the operation time is updated;
[0180] The original vulnerability status was fixed. When it is found again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page. The vulnerability status is marked as to be fixed, and the last discovery time and operation update time are updated. If it is not found in the new scan task, no additional operation is performed;
[0181] The original vulnerability status was to be retested. When it appears again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page. The vulnerability status is marked as to be fixed, and the last discovery time and operation update time are updated. A record is added to the operation record of the vulnerability: retest failed. If it is not found in the new scan task, the vulnerability status is marked as fixed, the operation update time is updated, and a record is added to the vulnerability operation record: retest passed;
[0182] The original vulnerability status was to accept the risk. When it is found again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page. The vulnerability status remains unchanged, and the last discovery time and operation update time are updated. If it is not found in the new scan task, no additional operation is performed;
[0183] The original vulnerability status was a false positive. When it is found again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID in the list page. The vulnerability status is a false positive and the status remains unchanged. The last discovery time is updated, and the operation update time is updated. If it is not found in the new scan task, no additional operation is performed;
[0184] The original vulnerability status was closed - *. When it is found again in a new scan task, a new vulnerability is added to the database;
[0185] For multiple vulnerability data of the same asset belonging to multiple different departments or units, when any one department or unit has completed the repair or marked a false positive for the vulnerability, the vulnerability belonging to other departments or units will be marked with the same status. When any one department or unit accepts the risk of the vulnerability, it does not affect the handling of the vulnerability by other departments or units;
[0186] For assets with unclosed vulnerabilities that need to be taken offline, after the operation personnel confirm the asset offline, the status of all vulnerabilities belonging to the asset is changed to closed - fixed, and the asset name is marked as offline.
[0187] By adopting an automated vulnerability update mechanism, it is possible to track and update the status of vulnerabilities in real time, ensure the accuracy and timeliness of vulnerability information, simplify the vulnerability management process, and ensure the accuracy of vulnerability repair. For the situation where the same asset belongs to multiple departments or units, cross-departmental collaboration can be achieved through sharing vulnerability information. For assets that need to be taken offline, through manual confirmation and status change, it is ensured that each type of vulnerability can be processed in a timely manner, avoiding omission and delay, and further ensuring the security of assets and the quality of vulnerability repair.
[0188] Example 3: Refer to Figure 3
[0189] Compared with the above embodiments, the difference is that the present invention also provides a full-life-cycle management system for vulnerabilities, including:
[0190] Asset management module: used to import and update and maintain the managed assets, providing basic asset support for subsequent vulnerability operations;
[0191] Vulnerability scanning task management module: used to create and manage scanning tasks;
[0192] Vulnerability acquisition module: used to acquire the vulnerabilities scanned after the scanning tasks in the vulnerability scanning devices are completed;
[0193] Vulnerability and asset matching module: used to match the acquired vulnerabilities with the assets in the system;
[0194] Vulnerability repair priority module: used to assign values to the vulnerability repair priorities;
[0195] Vulnerability status operation module: used to display, operate, and manage the full life cycle of vulnerabilities;
[0196] Vulnerability data analysis module: used to visually display all the vulnerability data and status in the system.
[0197] As Figure 3 shown, the asset management module includes asset entry and the update and maintenance of assets. A scanning task is created through the vulnerability scanning task management module to determine whether the asset to be scanned is already in the system. If the asset to be scanned is already in the system, the scanning task is sent to the vulnerability scanning device through the API interface. Otherwise, the asset is entered through the asset management module, and the vulnerabilities are obtained through the API interface. Then, it enters the vulnerability and asset matching module to determine whether the vulnerabilities and assets can be matched. If the vulnerabilities and assets can be matched, it enters the vulnerability status operation to update the vulnerability status. Otherwise, the assets are updated and maintained through the asset management module. Finally, it enters the vulnerability data analysis module for the analysis and display of vulnerability data.
Claims
1. A vulnerability full life cycle operation management method, characterized in that: include: S1. Import the managed assets and generate an asset list; S2. Create a new scanning task according to the asset list, select the assets to be scanned, and perform vulnerability detection on the assets to be scanned through the missed scanning device; S3, obtaining the scanned vulnerability obtained after the scan of the leaky scanning device is completed; S4, matching the acquired scanned vulnerability with the asset list, and binding the unique ID with the matched assets to obtain a unique asset ID; S5. Assign vulnerability repair priorities to the matched vulnerabilities; S6. After the vulnerability repair priority is assigned, the entire life cycle of the vulnerability is operated and managed according to the vulnerability repair priority; S7. Visualize all vulnerability data and status.
2. A vulnerability full life cycle management method according to claim 1, characterized in that: S2 The scanning in the newly created scanning task includes an online scanning mode and an offline scanning mode; The online scanning mode sends the missed scanning task to the corresponding missed scanning device through the API interface; The offline scanning mode uses a handheld vulnerability scanning device to detect vulnerabilities and upload the detected vulnerabilities for unified management; The newly created scanning task includes a periodic scanning mode and a timed scanning mode; In the periodic scanning mode, when the system detects changes in the IP and URL information of the scanned asset, it resends the scanning task to the missed device; The timed scan is used for a single scan task.
3. A vulnerability full life cycle management method according to claim 1, characterized in that: S3 said obtaining the scanning vulnerability obtained after the scanning of the missed scanning device also includes scanning the vulnerability of temporary assets that are not imported into the asset list, and establishing a scanning task in the missed scanning device to supplement the scanning operation scenario of the temporary assets.
4. A vulnerability full life cycle management method according to claim 1, characterized in that: Matching the acquired scan vulnerability with the asset list in S4 specifically includes: When a host vulnerability is obtained, the vulnerability scanning device returns the IP and port where the vulnerability is located, and the IP can be directly matched with the asset; When a web vulnerability is obtained, the vulnerability scanning device returns the URL where the vulnerability is located, and performs multi-level matching between the URL and the asset; When a vulnerability of unknown classification is obtained, the asset attribution of the obtained vulnerability is found and the vulnerability is classified into the correct unit; When the same asset belongs to multiple different departments or units, the acquired vulnerabilities of the asset are split into multiple vulnerability data belonging to different departments or units.
5. A vulnerability full life cycle management method according to claim 1, characterized in that: The vulnerability repair priority assignment for the matched vulnerabilities described in S5 specifically includes: The algorithm is constructed based on the five indicator dimensions of asset location L, asset value V, risk level R, exploit possibility E, and repair cost C. The vulnerability repair priority score is S. The larger the S score, the higher the priority of the vulnerability to be repaired. The asset location L∈{Internet and intranet, Internet, intranet}; The asset value V∈{Level 1, Level 2, Level 3, Level 4, Level 5}; The risk level R∈{very high risk, high risk, medium risk, low risk, information}; The probability of utilization E∈{very high, relatively high, medium, relatively low, very low}; Repair cost C∈{very high, relatively high, medium, relatively low, very low}; The calculation formula of the vulnerability repair priority score S is: S=w1×R+w2×E+w3×L+w4×V-w5×C Among them, w1~w5 are the weight parameters of each indicator dimension, w1+w2+w3+w4+w5=1.
6. A vulnerability full life cycle management method according to claim 5, characterized in that: The weights of each indicator dimension include: S51, construct a decision matrix, set the number of vulnerabilities to m, and form a decision matrix X according to the five indicator dimensions: S52. Use normalization to eliminate the differences between each indicator dimension: Among them, is the normalized value of the i-th vulnerability under the j-th indicator; S53. Calculate the entropy value of each indicator dimension: Where k is the normalization factor; S54. Calculate the weight. The weight of each indicator is: Get the weight of each indicator dimension.
7. A vulnerability full life cycle management method according to claim 1, characterized in that: The vulnerability life cycle described in S6 includes: to be fixed, to be retested, fixed, false positive, receiving risk, closed -*; When the vulnerability detection device detects a new vulnerability and uploads it, it marks the vulnerability status as to be repaired; The waiting for retest is to mark the vulnerability status as waiting for retest after the status of the vulnerability to be repaired is selected as repair completed; The "fixed" means that after the vulnerability to be retested or repaired is confirmed to not exist after another vulnerability detection, the vulnerability status is marked as fixed; The false alarm is to determine that the vulnerability to be repaired does not exist, mark the vulnerability status as a false alarm, and no longer prompt the vulnerability for a period of time; The repairs to be made also include: The vulnerability status is marked as a fixed or to-be-retested vulnerability. If the vulnerability still exists after vulnerability detection, the vulnerability status is marked as to-be-fixed; or the vulnerability status is a false positive. After research and judgment, it is believed that the vulnerability really exists, and the vulnerability status is marked as to-be-fixed; Accepting the risk means confirming that the vulnerability cannot be fixed in the short term, marking the vulnerability status as accepting the risk, and the vulnerability is added to the whitelist, and the vulnerability will not be prompted for a period of time; The closed-* includes closed-fixed, closed-false positive, and closed-accepted risks; The Closed-Fixed vulnerability is closed for the vulnerability whose status is Fixed, and the vulnerability lifecycle ends; The Closed-False Alarm closes the vulnerability whose vulnerability status is a false alarm, and the vulnerability life cycle ends; The Closed-Accepted Risk section closes the vulnerability whose status is Accepted Risk, and the vulnerability lifecycle ends; After the vulnerability lifecycle ends, when the same vulnerability of the same asset is discovered again, a new vulnerability data is generated and is not merged with the closed-* status vulnerability.
8. A vulnerability full life cycle management method according to claim 1, characterized in that: The visual display of all vulnerability data and status in S7 requires data analysis of the vulnerability data, specifically including: Calculate real-time vulnerability repair rate: Real-time vulnerability repair rate = ([Closed - Repaired] + [Fixed]) / (Total number of vulnerabilities - [False positives] - [Closed - False positives] - [Accepted risk] - [Closed - Accepted risk]); By setting custom parameters H, M, and L, they are used to represent the expected time to fix vulnerabilities of high, medium, and low risk levels respectively; When the real-time time T is set, the real-time vulnerability repair rate at any time can be obtained; Monthly high-risk repair rate: The ratio of vulnerabilities discovered during the statistical period T-2 to those repaired by T-1; Quarterly high-risk repair rate: The data statistics period is the ratio of vulnerabilities discovered from T-4 to T-1 to the ratio of vulnerabilities that have been repaired by T-1.
9. A vulnerability full life cycle management method according to claim 5, characterized in that: It also includes a vulnerability update mechanism to implement vulnerability status operations, including: The original vulnerability status is to be repaired. When the vulnerability is found again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability, and a new task ID is added to the task ID on the list page. The vulnerability status remains unchanged, and the last discovery time and operation time are updated. If the vulnerability is not found in the new scan task, the vulnerability status is marked as fixed, and the operation time is updated. The original vulnerability status is fixed. When it is found again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability, a new task ID is added to the task ID list page, the vulnerability status is marked as pending repair, the last discovery time and operation update time are updated, and if it is not found in the new scan task, no additional operation is performed; The original vulnerability status is pending retest. When it appears again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. A new task ID is added to the task ID on the list page. The vulnerability status is marked as pending repair, the last discovery time and operation update time are updated, and a record is added to the operation record of the vulnerability: retest failed. It was not found in the new scan task. The vulnerability status is marked as repaired, the operation update time is updated, and a record is added to the vulnerability operation record: retest passed. The original vulnerability status is accept risk. When it is discovered again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. The new task ID is added to the task ID on the list page. The vulnerability status remains unchanged, and the last discovery time and operation update time are updated. If it is not discovered in the new scan task, no additional operation is performed. The original vulnerability status is a false positive. When it is discovered again in a new scan task, a vulnerability discovery record and task ID are added to the original vulnerability. A new task ID is added to the task ID list page. The vulnerability status is a false positive, the status is not changed, the last discovery time is updated, the operation update time is updated, and it is not discovered in the new scan task, and no additional operations are performed; The original vulnerability status is closed-*. When it is found again in a new scanning task, a new vulnerability is added to the database; For multiple vulnerability data belonging to different departments or units of the same asset, when any department or unit has completed the repair or marked the false positive for the vulnerability, the vulnerability belonging to other departments or units will be marked as the same status. When any department or unit accepts the risk of the vulnerability, it will not affect the handling of the vulnerability by other departments or units. For assets that currently have unclosed loop vulnerabilities but need to be taken offline, after the operations staff confirms that the asset is offline, the status of all vulnerabilities belonging to the asset will be changed to Closed-Fixed, and the asset name will be marked as offline.
10. A vulnerability full life cycle management system, characterized in that: include: Asset management module: used to import, update and maintain managed assets, providing basic asset support for subsequent vulnerability operations; Vulnerability scanning task management module: used to create and manage scanning tasks; Vulnerability acquisition module: used to obtain the vulnerabilities scanned in the missed devices after the scanning task is completed; Vulnerability and asset matching module: used to match the acquired vulnerabilities with the assets in the system; Vulnerability repair priority module: used to assign priority to vulnerability repairs; Vulnerability status operation module: used to display, operate and manage the entire life cycle of vulnerabilities; Vulnerability data analysis module: used to visualize all vulnerability data and status of the system.