Method, device and equipment for identifying manufacturers and products influenced by vulnerabilities and medium
Through automated identification strategies and in-depth analysis technology, the problem of inefficient information of manufacturers and products affected by manual analysis vulnerabilities is solved, efficient and accurate identification results are achieved, and security protection capabilities are enhanced.
Patent Information
- Application Number
- CN202510193214.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, inefficiency, accuracy and integrity are affected when manually analyzing vulnerability descriptions to determine the affected manufacturers and products, especially when the number of vulnerabilities surges.
By obtaining the target vulnerability description of the vulnerability to be identified, the target recognition strategy is determined from several recognition strategies based on the description, and the manufacturer and product database, part-of-speech annotation or algorithm model are used for identification to determine the manufacturers and products affected by the vulnerability.
It realizes efficient and accurate identification of manufacturers and products affected by vulnerabilities, improves identification efficiency and accuracy and completeness of results, and reduces manual intervention and errors.
Smart Images

Figure CN120124070A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method, device, equipment and medium for identifying manufacturers and products affected by vulnerabilities. Background Art
[0002] With the rapid development of information technology, network security issues have become increasingly prominent, and software vulnerabilities have become the main target of hacker attacks. When a new software vulnerability is discovered, it is crucial to promptly identify the affected manufacturers and products for taking prompt protective measures. In the prior art, this task relies on security experts to manually analyze vulnerability descriptions and then sort out a list of affected manufacturers and products.
[0003] However, it is found in the research that the method of manually sorting out manufacturers and products affected by vulnerabilities has significant defects. First of all, manual analysis requires a large amount of time and human resources. Especially in the case of a sharp increase in the number of vulnerabilities, the efficiency of this method is particularly low. Secondly, due to factors such as human subjectivity and fatigue, the accuracy and integrity of the analysis results may be affected. In addition, with the diversification and complexity of software products, vulnerability descriptions may also become more complex and ambiguous, further increasing the difficulty of manual analysis. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a method, device, equipment and medium for identifying manufacturers and products affected by vulnerabilities, so as to realize the efficient and accurate identification of manufacturers and products affected by vulnerabilities, improve the identification efficiency, and at the same time improve the accuracy and integrity of the identification results of manufacturers and products.
[0005] In a first aspect, an embodiment of the present application provides a method for identifying manufacturers and products affected by vulnerabilities, and the method includes:
[0006] Obtain the target vulnerability description of the vulnerability to be identified;
[0007] Determine a target identification strategy for identifying the vulnerability to be identified from a number of identification strategies based on the target vulnerability description;
[0008] Identify the vulnerability to be identified based on the target identification strategy to determine the target manufacturers and products affected by the vulnerability to be identified.
[0009] Optionally, the determining a target identification strategy for identifying the vulnerability to be identified from a number of identification strategies based on the target vulnerability description includes:
[0010] Judge whether a target field appears in the target vulnerability description;
[0011] If the target field appears in the target vulnerability description, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on the manufacturer and product database; if the target field does not appear in the target vulnerability description, determine whether the target vulnerability description conforms to the target specification.
[0012] If the target vulnerability description conforms to the target specification, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging; if the target vulnerability description does not conform to the target specification, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on the algorithm model.
[0013] Optionally, identifying the vulnerability to be identified based on the target recognition strategy to determine the target manufacturers and products affected by the vulnerability to be identified includes:
[0014] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database, extract the target manufacturers and products from the manufacturer and product database according to the target field;
[0015] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on part-of-speech tagging, extract the target manufacturers and products from the target vulnerability description according to the NLTK part-of-speech;
[0016] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on the algorithm model, use the algorithm model to determine the target manufacturers and products according to the target vulnerability description.
[0017] Optionally, the method further includes:
[0018] Obtain the historical vulnerability descriptions of historical vulnerabilities;
[0019] Construct a model training set and a model test set based on the historical vulnerability descriptions;
[0020] Train and test the initial model based on the model training set and the model test set to obtain the algorithm model.
[0021] Optionally, constructing the model training set and the model test set based on the historical vulnerability descriptions includes:
[0022] Preprocess the historical vulnerability descriptions to obtain optimized vulnerability descriptions;
[0023] Convert the optimized vulnerability descriptions into vector form to form labeled corpus;
[0024] Select several labeled corpus respectively to construct the model training set and the model test set.
[0025] Optionally, training and testing the initial model based on the model training set and the model test set to obtain the algorithm model, including:
[0026] Training the initial model using the model training set to obtain a candidate model;
[0027] Testing the candidate model using the model test set, and determining the candidate model that passes the test as the algorithm model.
[0028] Optionally, the target field is the name of a mainstream manufacturer.
[0029] In a second aspect, an embodiment of the present application provides a device for identifying manufacturers and products affected by vulnerabilities, the device including:
[0030] A vulnerability description acquisition module, configured to acquire a target vulnerability description of a vulnerability to be identified;
[0031] An identification policy determination module, configured to determine a target identification policy for identifying the vulnerability to be identified from a plurality of identification policies based on the target vulnerability description;
[0032] A target manufacturer and product determination module, configured to identify the vulnerability to be identified based on the target identification policy to determine target manufacturers and products affected by the vulnerability to be identified.
[0033] Optionally, the determining a target identification policy for identifying the vulnerability to be identified from a plurality of identification policies based on the target vulnerability description includes:
[0034] Determining whether a target field appears in the target vulnerability description;
[0035] If the target field appears in the target vulnerability description, determining the target identification policy as extracting manufacturers and products affected by the vulnerability based on a manufacturer and product database; if the target field does not appear in the target vulnerability description, determining whether the target vulnerability description conforms to a target specification;
[0036] If the target vulnerability description conforms to the target specification, determining the target identification policy as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging; if the target vulnerability description does not conform to the target specification, determining the target identification policy as extracting the manufacturers and products affected by the vulnerability based on an algorithm model.
[0037] Optionally, the identifying the vulnerability to be identified based on the target identification policy to determine target manufacturers and products affected by the vulnerability to be identified includes:
[0038] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database, the target manufacturers and products are extracted from the manufacturer and product database according to the target fields;
[0039] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on part-of-speech tagging, the target manufacturers and products are extracted from the target vulnerability description according to the NLTK part-of-speech;
[0040] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on an algorithm model, the target manufacturers and products are determined using the algorithm model according to the target vulnerability description.
[0041] Optionally, the device further includes:
[0042] A historical vulnerability description acquisition module, configured to acquire the historical vulnerability descriptions of historical vulnerabilities;
[0043] A training and test set construction module, configured to construct a model training set and a model test set based on the historical vulnerability descriptions;
[0044] An algorithm model training module, configured to train and test an initial model based on the model training set and the model test set to obtain the algorithm model.
[0045] Optionally, constructing the model training set and the model test set based on the historical vulnerability descriptions includes:
[0046] Preprocessing the historical vulnerability descriptions to obtain optimized vulnerability descriptions;
[0047] Converting the optimized vulnerability descriptions into vector form to form labeled corpus;
[0048] Selecting a number of labeled corpus respectively to construct the model training set and the model test set.
[0049] Optionally, training and testing the initial model based on the model training set and the model test set to obtain the algorithm model includes:
[0050] Training the initial model using the model training set to obtain a candidate model;
[0051] Testing the candidate model using the model test set, and determining the candidate model that passes the test as the algorithm model.
[0052] Optionally, the target field is the name of mainstream manufacturers, and the target manufacturers and products are manufacturer products.
[0053] In a third aspect, an embodiment of the present application provides a computer device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the computer device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the method for identifying vendors and products affected by vulnerabilities in any optional implementation manner of the first aspect are executed.
[0054] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the method for identifying vendors and products affected by vulnerabilities in any optional implementation manner of the first aspect are executed.
[0055] The technical solutions provided by the present application include but are not limited to the following beneficial effects:
[0056] The present application automatically extracts the data of vendors and products affected by vulnerabilities in the vulnerability description through intelligent means, significantly improving the sorting speed and reducing manual intervention. Then, based on the target vulnerability description, a target identification strategy for identifying the to-be-identified vulnerability is determined from several identification strategies, and the to-be-identified vulnerability is identified based on the target identification strategy to determine the target vendors and products affected by the to-be-identified vulnerability. It can accurately match the relationship between the vulnerability description and the affected vendors and products based on the preset identification strategy and in-depth analysis technology, avoiding errors and omissions caused by human factors and enhancing accuracy. In addition, the present application can process different types of vulnerability descriptions, including complex and ambiguous descriptions, and has strong adaptability. By quickly and accurately identifying the affected vendors and products, the present application helps the security team take protective measures in a timely manner, reduces the risk of vulnerability exploitation, and improves the overall security protection ability of the enterprise.
[0057] In summary, the present invention solves the problem of low efficiency in manually sorting the information of vendors and products affected by vulnerabilities through intelligent means, realizes the efficient and accurate identification of vendors and products affected by vulnerabilities, improves the identification efficiency, and at the same time improves the accuracy and integrity of the identification results of vendors and products, providing an efficient and accurate method for automatically discovering vendor and product vulnerabilities, and having important practical value and social benefits.
[0058] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given in conjunction with the accompanying drawings and are described in detail as follows. Description of the Drawings
[0059] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present invention, and therefore should not be regarded as a limitation of the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0060] Figure 1 It shows a flowchart of a method for identifying manufacturers and products affected by vulnerabilities provided in the first embodiment of the present invention;
[0061] Figure 2 It shows a flowchart of a method for determining a target recognition strategy provided in the first embodiment of the present invention;
[0062] Figure 3 It shows a schematic diagram of an idea for extracting affected manufacturers and products provided in the first embodiment of the present invention;
[0063] Figure 4 It shows a schematic diagram of an idea for extracting a model provided in the first embodiment of the present invention;
[0064] Figure 5 It shows a flowchart of a method for constructing an algorithm model provided in the first embodiment of the present invention;
[0065] Figure 6 It shows a flowchart of a method for constructing a training set provided in the first embodiment of the present invention;
[0066] Figure 7 It shows a flowchart of a method for training and testing an algorithm model provided in the first embodiment of the present invention;
[0067] Figure 8 It shows a schematic diagram of an idea for constructing an algorithm model provided in the first embodiment of the present invention;
[0068] Figure 9 It shows a schematic diagram of the structure of a device for identifying manufacturers and products affected by vulnerabilities provided in the second embodiment of the present invention;
[0069] Figure 10 It shows a schematic diagram of the structure of a computer device provided in the third embodiment of the present invention. Detailed implementation manners
[0070] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0071] Embodiment 1
[0072] For the convenience of understanding this application, the following will describe Embodiment 1 of this application in detail with reference to the content described in the flowchart of a method for identifying manufacturers and products affected by vulnerabilities provided in Embodiment 1 of the present invention shown below. Figure 1 shown
[0073] See Figure 1 as shown Figure 1 shown is a flowchart of a method for identifying manufacturers and products affected by vulnerabilities provided in Embodiment 1 of the present invention, where the method includes steps S101 to S103:
[0074] S101: Obtain the target vulnerability description of the vulnerability to be identified.
[0075] Specifically, use web crawler technology to crawl the vulnerability descriptions of each vulnerability in each vulnerability database. Design the database table structure and construct the database of affected entities corresponding to the vulnerabilities. Process the data for invalid values and missing values, perform word segmentation, and BIO annotation.
[0076] S102: Determine the target identification strategy for identifying the vulnerability to be identified from several identification strategies based on the target vulnerability description.
[0077] Specifically, pre-configure identification strategies for vulnerabilities with different vulnerability descriptions. After obtaining the target vulnerability description of the vulnerability to be identified, match the corresponding target identification strategy from these identification strategies based on the target vulnerability description of the vulnerability to be identified to improve the pertinence of vulnerability identification.
[0078] S103: Identify the vulnerability to be identified based on the target identification strategy to determine the target manufacturers and products affected by the vulnerability to be identified.
[0079] Specifically, the target recognition strategy adapted to the vulnerability to be recognized is used to recognize the vulnerability to be recognized, and the target manufacturers and products affected by the vulnerability to be recognized are determined, which can also be called entity assets, further improving the accuracy of recognizing affected manufacturers and products.
[0080] In an alternative embodiment, refer to Figure 2 as shown Figure 2 The flowchart of a method for determining a target recognition strategy provided in the first embodiment of the present invention is shown. Among them, determining the target recognition strategy for recognizing the vulnerability to be recognized from several recognition strategies based on the target vulnerability description includes steps S201 to S203:
[0081] S201: Determine whether a target field appears in the target vulnerability description.
[0082] Specifically, first determine whether the target vulnerability description contains a target field. The target field symbolizes the vulnerability description specification, and the manufacturers and products affected by the vulnerability can be directly extracted according to the specified format.
[0083] S202: If the target field appears in the target vulnerability description, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on the manufacturer and product database; if the target field does not appear in the target vulnerability description, determine whether the target vulnerability description conforms to the target specification.
[0084] Specifically, if the target field appears in the target vulnerability description, it indicates that the target vulnerability description is in specification, and the target recognition strategy is determined to directly extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database. If the target field does not appear in the target vulnerability description, it indicates that the target vulnerability description does not meet the specification and cannot directly extract the manufacturers and products affected by the vulnerability, then determine whether the target vulnerability description conforms to the target specification.
[0085] The target specification is to annotate the target vulnerability description based on the NLTK part of speech. First, input the target vulnerability description, perform operations of cleaning and word segmentation on the target vulnerability description, intercept the first 5 words of the vulnerability description, and determine whether these first 5 words meet any of the following 3 part-of-speech orders. If any order is met, it indicates compliance with the target specification; otherwise, it indicates non-compliance with the target specification. The 3 part-of-speech orders that meet the target specification are shown in the following table:
[0086] Part-of-speech order ['NN', 'NNP', 'VBZ', 'DT', 'NN'] ['NNP', 'NNP', 'VBZ', 'DT', 'NN'] ['NNP', 'NN', 'VBZ', 'DT', 'NN']
[0087] Among them, 'NN' is a singular noun, 'NNP' is a proper noun, 'VBZ' is the present tense, third-person singular, and 'DT' is an article.
[0088] S203: If the target vulnerability description conforms to the target specification, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging; if the target vulnerability description does not conform to the target specification, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on an algorithm model.
[0089] Specifically, if the target vulnerability description conforms to the target specification, determine the target recognition strategy as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging. If the target vulnerability description does not conform to the target specification, that is, if any order is not satisfied, use the BERT+CRF model to extract the affected manufacturers and products.
[0090] See Figure 3 shown in Figure 3 Fig. shows a schematic diagram of an idea for extracting affected manufacturers and products provided in the first embodiment of the present invention. Among them, it is judged whether the latest vulnerability description contains mainstream manufacturers. If it is a mainstream manufacturer, it means that the vulnerability description is relatively unified, and the affected manufacturers and products are directly obtained. If it is not a mainstream manufacturer, but the vulnerability description is relatively standardized, the affected manufacturers and products are extracted based on NITK part-of-speech judgment. If it is neither a mainstream manufacturer nor the vulnerability description is standardized, the BERT+CRF model is used to extract the affected manufacturers and products.
[0091] When using the BERT+CRF model to extract the affected manufacturers and products, see Figure 4 shown in Figure 4 Fig. shows a schematic diagram of an idea for model extraction provided in the first embodiment of the present invention. Among them, the CVE (vulnerability description) abstract is input for data preprocessing, including data cleaning, NLTK word segmentation processing, and BIO tagging processing. Then call the model files (ner_model.ckpt and label2id.pkl), input the preprocessed sequence with BIO tags into the BERT+CRF model, and finally output the affected manufacturers and products, that is, the predicted manufacturers and products.
[0092] In an optional implementation, the identifying the to-be-identified vulnerability based on the target recognition strategy to determine the target manufacturers and products affected by the to-be-identified vulnerability includes:
[0093] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability from the manufacturer and product database, extract the target manufacturers and products from the manufacturer and product database according to the target field.
[0094] Specifically, a manufacturer and product database is pre-configured, and the manufacturer and product database stores each target field and the manufacturers and products corresponding to each target field. When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database, the manufacturers and products corresponding to the target field are queried from the manufacturer and product database as the target manufacturers and products.
[0095] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on part-of-speech tagging, the target manufacturers and products are extracted from the target vulnerability description according to the NLTK part-of-speech.
[0096] Specifically, when the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on part-of-speech tagging, the first character in the first 5 words of the target vulnerability description is intercepted based on the NLTK part-of-speech tagging as the target manufacturers and products.
[0097] When the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on an algorithm model, the target manufacturers and products are determined using the algorithm model according to the target vulnerability description.
[0098] Specifically, when the target recognition strategy is determined to extract the manufacturers and products affected by the vulnerability based on an algorithm model, the target vulnerability description is input, and three operations of cleaning, word segmentation, and tagging are performed on the target vulnerability description to obtain a matrix sequence with BIO tags, and the target manufacturers and products are finally extracted using the algorithm model (including two pre-trained model files).
[0099] In an alternative embodiment, refer to Figure 5 as shown Figure 5 shows a flowchart of a method for constructing an algorithm model provided in Embodiment 1 of the present invention, wherein the method further includes steps S501 to S503:
[0100] S501: Obtain the historical vulnerability descriptions of historical vulnerabilities.
[0101] S502: Construct a model training set and a model test set based on the historical vulnerability descriptions.
[0102] S503: Train and test the initial model based on the model training set and the model test set to obtain the algorithm model.
[0103] Specifically, first preprocess the historical vulnerability descriptions, including word segmentation and BIO annotation. Use the preprocessed data as the training set and test set for the BERT+CRF algorithm model to construct an algorithm model for predicting affected manufacturers and products. Train the initial model using the model training set, and optimize the prediction performance of the model by adjusting model parameters and feature selection. Test the trained model using the model test set to evaluate its prediction accuracy and generalization ability. According to the test results, iteratively optimize the model until satisfactory prediction performance is obtained to form the final algorithm model.
[0104] In an alternative embodiment, refer to Figure 6 as shown Figure 6 The flowchart of a method for constructing a training set provided in Embodiment 1 of the present invention is shown, wherein constructing a model training set and a model test set based on the historical vulnerability descriptions includes steps S601 to S603:
[0105] S601: Preprocess the historical vulnerability descriptions to obtain optimized vulnerability descriptions.
[0106] Specifically, the preprocessing includes four steps: missing value processing, data cleaning, special data deletion, and named entity recognition. For missing value processing, if the crawled vulnerability description is a null value, it is directly deleted. For data cleaning, delete some punctuation marks (such as " / ") and extra spaces. Perform NLTK word segmentation on the obtained vulnerability description values. For special data deletion, since the maximum sequence length that BERT can handle is 512 (the [CLS], [SEP] and other delimiters are not counted), for vulnerability descriptions with a length exceeding 512, delete the following part without entity tags and retain the text with a length of 512. If the entity appears at the end of the corpus, intercept the text with a length of 512 from the entity part forward, and delete the rest. For named entity recognition and BIO annotation, the tags are divided into three categories: B tags, I tags, and O tags. "B" represents the starting part of the entity, "I" represents the remaining part of the entity, and "O" represents the non-entity part, resulting in the following five types of tags: B-VENDOR (VENDOR is the manufacturer), I-VENDOR, B-PRODUCT (PRODUCT is the product), I-PRODUCT, O.
[0107] S602: Convert the optimized vulnerability descriptions into vector form to form annotated corpus.
[0108] Specifically, after word segmentation of the vulnerability descriptions, store them in a list, and convert the list into word vectors to form an annotated corpus.
[0109] S603: Select several annotated corpus respectively to construct the model training set and the model test set.
[0110] Specifically, several labeled corpora are selected to construct a model training set, and several other labeled corpora are selected to construct a model test set.
[0111] In an alternative embodiment, refer to Figure 7 as shown Figure 7 FIG. shows a flowchart of an algorithm model training and testing method provided in the first embodiment of the present invention. Among them, the initial model is trained and tested based on the model training set and the model test set to obtain the algorithm model, including steps S701 to S702:
[0112] S701: Use the model training set to train the initial model to obtain a candidate model.
[0113] Specifically, the initial model is a BERT+CRF model. Each word vector in the model training set is used as the input of the BERT model. Then, two calculation methods, MLM and NSP, in the BERT model will extract deep inter-word features, syntactic features, and context semantic features, and provide high-quality word vectors. The higher-quality word vectors are input into the CRF layer, and the CRF layer learns the dependency information between BIO tags, and finally outputs two model files (ner_model.ckpt and label2id.pkl respectively). Before the model is tested, the model indicated by the obtained model file is used as the candidate model.
[0114] BERT is Bidirectional Encoder Representations from Transformers (BERT). The pre-trained model can extract deep inter-word features, syntactic features, and context semantic features from the input sequence, reduce the amount of calculation, improve the parallel efficiency, and at the same time provide high-quality word vectors, thereby improving the accuracy of entity recognition and classification.
[0115] CRF is Conditional Random Fields. It is a probability model for labeling and segmenting structured data (such as sequences, trees, and grids). CRF can impose constraints on the output of the model to reduce the weight of incorrect predictions, which is equivalent to setting some prior norms for the prediction behavior. For example, it will exclude cases where "B-VENDOR" and "I-PRODUCT" are connected together.
[0116] The BERT+CRF model first takes the labeled corpus converted into vector form as the input data of the BERT pre-trained model. The output of the hidden layer of the last layer of the BERT model is the word vector containing various semantics in the original sentence. Then, this word vector is input into the CRF model for further processing. The CRF is responsible for learning the dependencies in the labels, and finally obtains the predicted annotation sequence. By extracting and classifying the entities in the sequence, different entity labels are obtained.
[0117] See Figure 8 as shown in Figure 8 Fig. shows a schematic diagram of the construction idea of an algorithm model provided by Embodiment 1 of the present invention. Among them, vulnerability data is first obtained, and preprocessing of the vulnerability data is performed, including data cleaning, NLTK word segmentation processing, and BIO label processing. The preprocessed data is input into the BERT+CRF model for training. For the BERT model, it learns the context information of the sequence and provides high-quality word feature vectors for downstream tasks. For the CRF model, it learns the dependencies of BIO labels.
[0118] S702: Use the model test set to test the candidate model, and determine the candidate model that passes the test as the algorithm model.
[0119] Specifically, use the word vectors in the model test set to test the candidate model, and judge whether the candidate model passes the test based on the prediction accuracy. If the prediction accuracy exceeds the preset threshold, it is determined to pass the test. At this time, the candidate model is stored as the algorithm model, and two model files (ner_model.ckpt and label2id.pkl respectively) are output.
[0120] In an optional implementation, the target field is the name of the mainstream manufacturer.
[0121] Specifically, the target field can also be a preset field. When the target field is the name of the mainstream manufacturer, the names of the mainstream manufacturers can be seen in the following table:
[0122]
[0123] Embodiment 2
[0124] Embodiment 2 of the present invention provides a device for identifying manufacturers and products affected by vulnerabilities. See Figure 9 as shown in Figure 9 Fig. shows a structural schematic diagram of a device for identifying manufacturers and products affected by vulnerabilities provided by Embodiment 2 of the present invention. Among them, the device includes:
[0125] A vulnerability description acquisition module 901, configured to acquire a target vulnerability description of the vulnerability to be identified;
[0126] An identification strategy determination module 902, configured to determine a target identification strategy for identifying the vulnerability to be identified from a number of identification strategies based on the target vulnerability description;
[0127] A target manufacturer and product determination module 903, configured to identify the vulnerability to be identified based on the target identification strategy to determine the target manufacturers and products affected by the vulnerability to be identified.
[0128] In an optional implementation, the determining a target identification strategy for identifying the vulnerability to be identified from a number of identification strategies based on the target vulnerability description includes:
[0129] Determining whether a target field appears in the target vulnerability description;
[0130] If the target field appears in the target vulnerability description, determining the target identification strategy as extracting the manufacturers and products affected by the vulnerability based on the manufacturer and product database; if the target field does not appear in the target vulnerability description, determining whether the target vulnerability description conforms to a target specification;
[0131] If the target vulnerability description conforms to the target specification, determining the target identification strategy as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging; if the target vulnerability description does not conform to the target specification, determining the target identification strategy as extracting the manufacturers and products affected by the vulnerability based on an algorithm model.
[0132] In an optional implementation, the identifying the vulnerability to be identified based on the target identification strategy to determine the target manufacturers and products affected by the vulnerability to be identified includes:
[0133] When the target identification strategy is determined as extracting the manufacturers and products affected by the vulnerability based on the manufacturer and product database, extracting the target manufacturers and products from the manufacturer and product database according to the target field;
[0134] When the target identification strategy is determined as extracting the manufacturers and products affected by the vulnerability based on part-of-speech tagging, extracting the target manufacturers and products from the target vulnerability description according to the NLTK part-of-speech;
[0135] When the target identification strategy is determined as extracting the manufacturers and products affected by the vulnerability based on an algorithm model, determining the target manufacturers and products according to the target vulnerability description using the algorithm model.
[0136] In an optional implementation, the apparatus further includes:
[0137] A historical vulnerability description acquisition module, configured to acquire the historical vulnerability description of historical vulnerabilities;
[0138] A training and testing set construction module for constructing a model training set and a model testing set based on the historical vulnerability descriptions;
[0139] An algorithm model training module for training and testing an initial model based on the model training set and the model testing set to obtain the algorithm model.
[0140] In an optional implementation, constructing the model training set and the model testing set based on the historical vulnerability descriptions includes:
[0141] Preprocessing the historical vulnerability descriptions to obtain optimized vulnerability descriptions;
[0142] Converting the optimized vulnerability descriptions into vector form to form labeled corpora;
[0143] Selecting a number of labeled corpora respectively to construct the model training set and the model testing set.
[0144] In an optional implementation, training and testing the initial model based on the model training set and the model testing set to obtain the algorithm model includes:
[0145] Training the initial model using the model training set to obtain a candidate model;
[0146] Testing the candidate model using the model testing set, and determining the candidate model that passes the test as the algorithm model.
[0147] In an optional implementation, the target field is the name of a mainstream manufacturer.
[0148] Embodiment III
[0149] Based on the same application concept, as shown in Figure 10 shown, Figure 10 shows a schematic structural diagram of a computer device provided in Embodiment III of the present invention, wherein, as Figure 10 shown, a computer device 1000 provided in Embodiment III of the present application includes:
[0150] A processor 1001, a memory 1002, and a bus 1003. The memory 1002 stores machine-readable instructions executable by the processor 1001. When the computer device 1000 runs, communication is carried out between the processor 1001 and the memory 1002 through the bus 1003. When the machine-readable instructions are run by the processor 1001, the steps of the method for identifying manufacturers and products affected by vulnerabilities shown in Embodiment I above are executed.
[0151] Embodiment IV
[0152] Based on the same application concept, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the method for identifying manufacturers and products affected by vulnerabilities described in any one of the above embodiments.
[0153] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0154] The computer program product for identifying manufacturers and products affected by vulnerabilities provided by an embodiment of the present invention includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the method described in the foregoing method embodiments. For specific implementation, reference can be made to the method embodiments and will not be elaborated herein.
[0155] The device for identifying manufacturers and products affected by vulnerabilities provided by an embodiment of the present invention can be specific hardware on a device or software or firmware installed on the device, etc. For the device provided by an embodiment of the present invention, the implementation principle and the technical effects produced are the same as those of the foregoing method embodiments. For a brief description, for the parts not mentioned in the device embodiment, reference can be made to the corresponding content in the foregoing method embodiments. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can all refer to the corresponding processes in the above method embodiments, and will not be elaborated herein.
[0156] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0157] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0158] In addition, each functional unit in the embodiments provided by the present invention may be integrated into a processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit.
[0159] If the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0160] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0161] Finally, it should be noted that the above-mentioned embodiments are only specific implementation manners of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting it. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the technical field of the present invention can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. All should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for identifying manufacturers and products affected by a vulnerability, characterized in that: The method comprises: Obtain target vulnerability description of the vulnerability to be identified; Determining a target identification strategy for identifying the vulnerability to be identified from a plurality of identification strategies based on the target vulnerability description; The vulnerability to be identified is identified based on the target identification strategy to determine the target manufacturers and products affected by the vulnerability to be identified.
2. The method according to claim 1, characterized in that: The step of determining a target identification strategy for identifying the vulnerability to be identified from a plurality of identification strategies based on the target vulnerability description includes: Determine whether a target field appears in the target vulnerability description; If the target field appears in the target vulnerability description, the target identification strategy is determined to extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database; if the target field does not appear in the target vulnerability description, it is determined whether the target vulnerability description meets the target specification; If the target vulnerability description meets the target specification, the target identification strategy is determined to extract the manufacturers and products affected by the vulnerability based on part-of-speech tagging; if the target vulnerability description does not meet the target specification, the target identification strategy is determined to extract the manufacturers and products affected by the vulnerability based on an algorithm model.
3. The method according to claim 2, characterized in that The identifying the vulnerability to be identified based on the target identification strategy to determine the target manufacturer and product affected by the vulnerability to be identified includes: When the target identification strategy is determined to extract the manufacturers and products affected by the vulnerability based on the manufacturer and product database, the target manufacturers and products are extracted from the manufacturer and product database according to the target field; When the target identification strategy is determined to extract the vendors and products affected by the vulnerability based on part-of-speech tagging, the target vendors and products are extracted from the target vulnerability description according to NLTK part-of-speech; When the target identification strategy is determined to extract the manufacturers and products affected by the vulnerability based on an algorithm model, the target manufacturers and products are determined using the algorithm model according to the target vulnerability description.
4. The method according to claim 2, characterized in that: The method further comprises: Get historical vulnerability descriptions of historical vulnerabilities; Building a model training set and a model test set based on the historical vulnerability description; The algorithm model is obtained by training and testing the initial model based on the model training set and the model test set.
5. The method according to claim 4, characterized in that The constructing of a model training set and a model testing set based on the historical vulnerability description includes: Preprocessing the historical vulnerability description to obtain an optimized vulnerability description; Convert the optimization vulnerability description into a vector form to form annotated corpus; A number of annotated corpora are selected to construct the model training set and the model test set respectively.
6. The method according to claim 4, characterized in that The algorithm model is obtained by training and testing the initial model based on the model training set and the model test set, including: Using the model training set to train the initial model to obtain a candidate model; The candidate model is tested using the model test set, and the candidate model that passes the test is determined as the algorithm model.
7. The method according to claim 2, characterized in that: The target field is the name of a mainstream manufacturer.
8. A device for identifying manufacturers and products affected by vulnerabilities, characterized in that: The device comprises: A vulnerability description acquisition module is used to obtain a target vulnerability description of the vulnerability to be identified; An identification strategy determination module, used to determine a target identification strategy for identifying the vulnerability to be identified from a plurality of identification strategies based on the target vulnerability description; The target manufacturer and product determination module is used to identify the vulnerability to be identified based on the target identification strategy to determine the target manufacturer and product affected by the vulnerability to be identified.
9. A computer device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the computer device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the method for identifying manufacturers and products affected by the vulnerability as described in any one of claims 1 to 7 are performed.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the method for identifying manufacturers and products affected by vulnerabilities as described in any one of claims 1 to 7.