Software vulnerability intelligent detection and repair method oriented to network and information security
By performing multi-level abnormality monitoring and repair of software vulnerabilities, including request monitoring, browsing abnormality monitoring and user-side transmission monitoring, the problem of low accuracy of vulnerability identification in the existing technology is solved, and higher accuracy of vulnerability repair and system security is achieved.
Patent Information
- Application Number
- CN202510289914.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-12
AI Technical Summary
In the prior art, the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities is not high, resulting in possible false alarms or missed reports, affecting system security.
By monitoring the request volume and session frequency abnormality, browsing abnormality monitoring and user-side transmission abnormality monitoring, we can determine whether the first, second and third vulnerability repairs are carried out, and repairs are carried out through dynamic code analysis, browser plug-in interception and banning malicious scripts.
Improve the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities, ensure the security and stability of the system, and reduce the situation of false alarms and missed reports.
Smart Images

Figure CN120180446A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic digital data processing, and in particular, to an intelligent detection and repair method for software vulnerabilities for network and information security. Background Art
[0002] With the rapid development and wide popularization of information technology, various information systems, network platforms, etc. have emerged like mushrooms after rain. Inevitably, there will be various vulnerabilities and defects in the design, development, deployment, and operation and maintenance processes of these systems and platforms. Once these vulnerabilities are exploited by attackers, they may pose a serious threat to the security of the system, resulting in serious consequences such as data leakage, system crashes, and illegal control.
[0003] The prior art uses user-side protection technology (browser security plug-ins) to detect and prevent the execution of malicious scripts through browser plug-ins, and prevent XSS (Cross-Site Scripting) attacks on the user side. However, browser security plug-ins require a certain amount of system resources, including memory and bandwidth, etc. when running, which may cause the browser to run slower, the page loading time to be extended, and false positives and false negatives to occur due to untimely updates.
[0004] For example, the application software vulnerability scanning method and system announced in the invention patent announcement with the announcement number: CN117874772B includes: first, preliminarily judge the kernel function crash signal of the operating system and the crash signal of the source code when the application program crashes: if the two signals are inconsistent, it is preliminarily judged that there is no source code vulnerability; if they are consistent, sort according to the problem occurrence probability, and successively and deeply detect special problems, record the discovered special problems, and notify the user or the system to repair after all special problems are detected. If it cannot be repaired, the system will prompt that the detection is invalid and re-execute the detection process; if it can be successfully repaired, compare the kernel function crash signal of the operating system and the source code crash signal again. If the two signals are no longer consistent after repair, it is confirmed that there is no source code vulnerability; otherwise, if they are still the same, it is determined that there is a source code vulnerability, and special problems can be excluded without false positives.
[0005] For example, the vulnerability detection method and system announced in the invention patent announcement with the announcement number of CN117972714B include: Step S1, determining the detection scope; Step S2, selecting a calibration file; Step S3, determining suspected vulnerability files; Step S4, classifying vulnerabilities; Step S5, storing files; By selecting a historical execution file that matches the content of the execution file in the historical database as the calibration file, and analyzing the path source of the execution file, the execution file with an unknown source is initially determined as a suspected vulnerability file, and by performing code matching on the suspected vulnerability file, it is detected whether new code is input, and by performing vulnerability matching on the new code segment, the vulnerability level is determined, high-risk vulnerabilities are intercepted in a timely manner, and vulnerability matching is performed by screening out the execution files with new code.
[0006] However, in the process of implementing the technical solution of the present invention in the embodiments of the present application, it is found that the above technology has at least the following technical problems: In the prior art, software vulnerabilities in network and information security refer to defects or weaknesses existing in the process of software development, design or implementation, and these vulnerabilities may be exploited by attackers; Since the software may contain security vulnerabilities due to lack of timely updates, these vulnerabilities are easily exploited by attackers (for example, attackers may use XSS vulnerabilities to execute malicious scripts in the user's browser to send spam), resulting in the problem of low accuracy in identifying vulnerabilities when detecting and repairing software vulnerabilities. Summary of the Invention
[0007] The embodiments of the present application provide an intelligent detection and repair method for software vulnerabilities for network and information security, which solves the problem of low accuracy in identifying vulnerabilities when detecting and repairing software vulnerabilities in the prior art, and realizes the improvement of the accuracy in identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0008] The embodiments of the present application provide an intelligent detection and repair method for software vulnerabilities for network and information security, including the following steps: S1, monitoring abnormal request volume and session frequency, and determining whether to perform the first vulnerability repair; S2, monitoring abnormal browsing, and determining whether to perform the second vulnerability repair; S3, monitoring abnormal transmission at the user end, and determining whether to perform the third vulnerability repair.
[0009] Further, the specific process of monitoring the abnormal request volume and session frequency is as follows: Monitor the total request quantity and the average session frequency within a preset time period; When the monitored total request quantity is greater than the maximum preset request quantity obtained from the database, or the average session frequency is greater than the maximum preset session frequency obtained from the database, mark the corresponding request address as a suspicious address and perform the first vulnerability repair; The first vulnerability repair includes the first interception, the first repair, and the first update and verification; The first interception means intercepting the suspicious address through dynamic code analysis; The specific process of the first vulnerability repair is as follows: Monitor whether the repair detection parameters meet the interception qualification conditions. The repair detection parameters include the interception speed and the interception load, and the interception load represents the average load of the server during the first interception; When the repair detection parameters do not meet the interception qualification conditions, perform the first interception optimization, and the first interception optimization means sending a prompt to a preset person to set the dynamic standby bandwidth; When the repair detection parameters meet the interception qualification conditions, continue with the first repair, and the first repair means sending a prohibited access prompt to a preset person and setting the suspicious address code.
[0010] Further, the first update and verification include the first update and the first verification; The first update means updating the first vulnerability repair qualified data to obtain the first update data; The first verification means re-monitoring the total request quantity and the average session frequency within a preset time period after the first update; The first vulnerability repair qualified data represents the browsing-related data after the first repair.
[0011] Further, the specific process of the first update is as follows: Determine whether the monitored parameter to be verified meets the update qualification conditions. The parameter to be verified includes the server load and the total request quantity after the first interception; When the monitored parameter to be verified meets the update qualification conditions, continue with the browsing anomaly monitoring; When the monitored parameter to be verified does not meet the update qualification conditions, perform the verification load optimization, and the verification load optimization means sending a prompt to a preset person to set up a standby server and distributing the qualified requests to the standby server.
[0012] Further, the specific process of performing browsing anomaly monitoring is as follows: By analyzing the ratio of the average request frequency to the preset request frequency, and jointly analyzing the weighting effect with the ratio degree value of the browsing traffic peak and the preset first weight of browsing traffic impact to obtain a traffic-request frequency analysis value, where the ratio degree value of the browsing traffic peak is used to reflect the ratio degree of the maximum browsing traffic relative to the preset maximum browsing traffic; By analyzing the ratio of the same request quantity to the preset same request quantity, and jointly analyzing the weighting effect with the ratio degree value of the browsing traffic peak and the preset second weight of browsing traffic impact to obtain a traffic-same request analysis value; By analyzing the ratio of the browsing bandwidth occupancy rate to the preset browsing bandwidth occupancy rate, and jointly analyzing the weighting effect with the ratio degree value of the browsing traffic peak and the preset third weight of browsing traffic impact to obtain a traffic-bandwidth occupancy analysis value; By analyzing the ratio of the maximum value of the request concurrent connection number to the preset request concurrent connection number, and jointly analyzing the weighting effect with the ratio degree value of the browsing traffic peak and the preset fourth weight of browsing traffic impact to obtain a traffic-concurrency analysis value; By jointly analyzing the obtained browsing traffic and anomaly reflection values above to obtain a browsing anomaly monitoring value; The browsing anomaly monitoring value is used to reflect the quantification of the influence degree of the browsing traffic and anomaly reflection values within a preset time period on the abnormal situation of the user's web page information browsing; The traffic and anomaly reflection values include a traffic-request frequency analysis value, a traffic-same request analysis value, a traffic-bandwidth occupancy analysis value, and a traffic-concurrency analysis value; The traffic-request frequency analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the average request frequency on the abnormal situation of the user's web page information browsing; The traffic-same request analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the same request quantity on the abnormal situation of the user's web page information browsing; The traffic-bandwidth occupancy analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the browsing bandwidth occupancy rate on the abnormal situation of the user's web page information browsing; The traffic-concurrency analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the maximum value of the request concurrent connection number on the abnormal situation of the user's web page information browsing.
[0013] Further, the specific process of determining whether to perform the second vulnerability repair is as follows: Compare whether the browsing anomaly monitoring value is less than the preset browsing anomaly monitoring value obtained from the database; if so, continue with the user - end transmission anomaly monitoring; if not, perform the second vulnerability repair; the second vulnerability repair includes a second interception, a second repair, and a second update; the second interception means intercepting through setting a browser plugin; the second repair means automatically repairing the vulnerability through the set browser plugin; the second update means updating the qualified data of the second vulnerability repair to obtain the second updated data; the qualified data of the second vulnerability repair means the data obtained after the first - time qualified vulnerability repair data is repaired for the second time.
[0014] Further, for the user - end transmission anomaly monitoring to determine whether to perform the third vulnerability repair, the specific process is as follows: Monitor the script change rate and determine whether to perform the third vulnerability repair; when the monitored script change rate is not greater than the preset script change rate obtained from the database, transmit the second updated data to the user - end; when the monitored script change rate is greater than the preset script change rate obtained from the database, perform the third vulnerability repair; the third vulnerability repair includes a third interception, a third repair, and a third update and verification.
[0015] Further, the third interception means sending a prompt to prohibit the running of malicious scripts to the preset personnel; the malicious script means the script corresponding to a script change rate greater than the preset script change rate; the third repair means sending a prompt to delete the malicious script to the preset personnel; the third update and verification includes a third update and a script change rate verification; the third update means updating the qualified data of the third vulnerability repair to obtain the third updated data; the qualified data of the third vulnerability repair means the data obtained after the second - time qualified vulnerability repair data is repaired for the third time; the script change rate verification means re - monitoring the script change rate until the number of script change rate verification times reaches the preset maximum number of script change rate verification times.
[0016] Further, the user - end transmission anomaly monitoring further includes obtaining a user - end transmission anomaly monitoring value, and the specific process is as follows: By analyzing the ratio of the number of browsing interruptions to the preset number of browsing interruptions, and jointly analyzing the weighting effect with the page - loading ratio value and the preset user - end transmission first weight value to obtain a loading - interruption analysis value, where the page - loading ratio value is used to reflect the ratio of the average page - loading duration to the preset page - loading duration; By analyzing the ratio of the number of interceptions to the preset number of interceptions, and jointly analyzing the weighting effect with the page - loading ratio value and the preset user - end transmission second weight value to obtain a loading - interception analysis value; By analyzing the ratio of the number of browser crashes to the preset number of browser crashes, and jointly analyzing the weighting effect with the page - loading ratio value and the preset user - end transmission third weight value to obtain a loading - crash analysis value; By analyzing the ratio of the maximum request - response duration to the preset request - response duration, and jointly analyzing the weighting effect with the page - loading ratio value and the preset user - end transmission fourth weight value to obtain a loading - request - response analysis value; By jointly analyzing the user - end transmission anomaly reflection values obtained above to obtain a user - end transmission anomaly monitoring value; The user - end transmission anomaly monitoring value is used to reflect the quantification of the influence degree of the user - end transmission anomaly reflection value within the preset user - end monitoring time period on the abnormal situation of web - page information transmission to the user - end; The user - end transmission anomaly reflection value includes a loading - interruption analysis value, a loading - interception analysis value, a loading - crash analysis value, and a loading - request - response analysis value; The loading - interruption analysis value is used to reflect the comprehensive influence degree of the number of browsing interruptions and the average page - loading duration on the abnormal situation of web - page information transmission to the user - end; The loading - interception analysis value is used to reflect the comprehensive influence degree of the number of interceptions and the average page - loading duration on the abnormal situation of web - page information transmission to the user - end; The loading - crash analysis value is used to reflect the comprehensive influence degree of the number of browser crashes and the average page - loading duration on the abnormal situation of web - page information transmission to the user - end; The loading - request - response analysis value is used to reflect the comprehensive influence degree of the maximum request - response duration and the average page - loading duration on the abnormal situation of web - page information transmission to the user - end.
[0017] Further, the user - end transmission anomaly monitoring also includes determining whether to perform user - end transmission optimization. The specific process is as follows: If the user - end transmission anomaly monitoring value is greater than the preset user - end transmission anomaly threshold obtained from the database, then the third - updated data is transmitted to the user - end; if the user - end transmission anomaly monitoring value is not greater than the preset user - end transmission anomaly threshold obtained from the database, then user - end transmission optimization is performed. The specific steps of the user - end transmission optimization are as follows: First step, monitor the transmission distance and set priorities, where the transmission distance represents the transmission distance between the server and the user - end; Second step, perform update frequency optimization, where the update frequency optimization means sending a prompt to a preset person to gradually increase the update frequency of the browser plugin by a preset multiple.
[0018] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. By performing request volume and session frequency anomaly monitoring and determining whether to perform the first vulnerability repair, then performing browsing anomaly monitoring and determining whether to perform the second vulnerability repair, and finally performing user - end transmission anomaly monitoring and determining whether to perform the third vulnerability repair, the reliability of identifying vulnerabilities during software vulnerability detection and repair is improved, and then the accuracy of identifying vulnerabilities during software vulnerability detection and repair is increased, effectively solving the problem of low accuracy of identifying vulnerabilities in the prior art during software vulnerability detection and repair.
[0019] 2. By jointly analyzing the browsing anomaly monitoring parameters and the preset browsing anomaly monitoring parameters to obtain the browsing traffic and the anomaly reflection value, and then jointly analyzing the browsing traffic and the anomaly reflection value to obtain the browsing anomaly monitoring value, the precise quantification of the influence degree of the browsing traffic and the anomaly reflection value on the abnormal situation of the user's web page information browsing is realized, and then the analysis accuracy of the abnormal situation of the user's web page information browsing is improved.
[0020] 3. By performing user - end transmission optimization when the user - end transmission anomaly monitoring value is not greater than the preset user - end transmission anomaly threshold, then monitoring the transmission distance and setting priorities, and finally performing update frequency optimization, the reliability of performing user - end transmission anomaly monitoring is improved, and then the accuracy of performing user - end transmission anomaly monitoring is increased. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a flowchart of a software vulnerability intelligent detection and repair method for network and information security provided by an embodiment of the present application; Figure 2 It is the overall flowchart of software vulnerability intelligent detection and repair provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] Embodiments of the present application provide an intelligent detection and repair method for software vulnerabilities for network and information security, which solves the problem of low accuracy in identifying vulnerabilities when detecting and repairing software vulnerabilities in the prior art. By monitoring abnormal request volume and session frequency, when the total number of monitored requests is greater than the preset maximum request number, or the average session frequency is greater than the preset maximum session frequency, the corresponding request address is marked as a suspicious address, and the first vulnerability repair is performed. Then, browsing anomaly monitoring is performed to determine whether the second vulnerability repair is to be performed. Finally, user-side transmission anomaly monitoring is performed to determine whether the third vulnerability repair is to be performed, achieving an improvement in the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0023] The technical solution in the embodiments of the present application is to solve the problem of low accuracy in identifying vulnerabilities when detecting and repairing software vulnerabilities. The general idea is as follows: By monitoring abnormal request volume and session frequency and determining whether to perform the first vulnerability repair, then performing browsing anomaly monitoring and determining whether to perform the second vulnerability repair, and finally performing user-side transmission anomaly monitoring and determining whether to perform the third vulnerability repair, the effect of improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities is achieved.
[0024] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific implementation manners.
[0025] As Figure 1 shown, it is a flowchart of an intelligent detection and repair method for software vulnerabilities for network and information security provided by an embodiment of the present application. The method includes the following steps: S1, first anomaly monitoring: monitor abnormal request volume and session frequency, and determine whether to perform the first vulnerability repair; S2, second anomaly monitoring: perform browsing anomaly monitoring, and determine whether to perform the second vulnerability repair; S3, third anomaly monitoring: perform user-side transmission anomaly monitoring, and determine whether to perform the third vulnerability repair.
[0026] In this embodiment, as Figure 2As shown in the figure, it is the overall flowchart of intelligent detection and repair of software vulnerabilities provided by the embodiments of the present application. By monitoring the anomalies of the request volume and session frequency, when the total number of monitored requests is greater than the maximum value of the preset request number, or the average session frequency is greater than the maximum value of the preset session frequency, the first vulnerability repair is performed; by monitoring the browsing anomalies to obtain the browsing anomaly monitoring value, when the browsing anomaly monitoring value is not less than the preset browsing anomaly monitoring value, the second vulnerability repair is performed; by monitoring the anomalies of the user-side transmission, when the detected script change rate is greater than the preset script change rate, the third vulnerability repair is performed. At the same time, by monitoring the anomalies of the user-side transmission to obtain the user-side transmission anomaly monitoring value, when the user-side transmission anomaly monitoring value is not greater than the preset user-side transmission threshold, the user-side transmission is optimized.
[0027] The first anomaly monitoring, the second anomaly monitoring, and the third anomaly monitoring are progressive, and the first vulnerability repair, the second vulnerability repair, and the third vulnerability repair are interrelated. The first vulnerability repair intercepts the suspicious addresses through the dynamic code analysis method, effectively preventing malicious access and attacks; the second vulnerability repair uses browser plugins for automatic interception and repair, improving the repair efficiency and accuracy; the third vulnerability repair targets the anomalies of the user-side transmission, and ensures the security of the user side by sending prompts to prohibit running and delete malicious scripts; through the first update and verification, the second update, and the third update and verification, the security of the browsing information finally transmitted to the user side is ensured; thereby improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0028] For example, XSS vulnerabilities are easily exploited when the network traffic is large during peak periods, and malicious scripts are executed in the user's browser to send spam. Through the first anomaly monitoring, the second anomaly monitoring, and the third anomaly monitoring, the success rate of XSS attacks is reduced. Through the first vulnerability repair, the second vulnerability repair, and the third vulnerability repair, the detected malicious scripts are intercepted and repaired to ensure that the browsing information transmitted to the user side is completely secure and reliable.
[0029] Further, the specific process of monitoring the abnormal request volume and session frequency is as follows: Monitor the total number of requests and the average session frequency within a preset time period; When the monitored total number of requests is greater than the maximum value of the preset request number obtained from the database, or the average session frequency is greater than the maximum value of the preset session frequency obtained from the database, mark the corresponding request address as a suspicious address and perform the first vulnerability repair; The first vulnerability repair includes the first interception, the first repair, and the first update and verification; The first interception means intercepting the suspicious address through dynamic code analysis; The specific process of the first vulnerability repair is as follows: Monitor whether the repair detection parameters meet the interception qualification conditions. The repair detection parameters include the interception speed and the interception load. The interception load represents the average value of the server load during the first interception. The interception qualification conditions mean that the interception speed is greater than the preset interception speed obtained from the database, and at the same time the interception load is not greater than the preset repair load obtained from the database; When the repair detection parameters do not meet the interception qualification conditions, perform the first interception optimization, which means sending a prompt to the preset personnel to set the dynamic standby bandwidth; When the repair detection parameters meet the interception qualification conditions, continue with the first repair. The first repair means sending a prohibited access prompt to the preset personnel and setting the code of the suspicious address. The setting of the suspicious address code means prompting the preset personnel to encode the output code corresponding to the suspicious address before outputting it to the HTML (HyperText Markup Language) page.
[0030] It should be added that the first update and verification include the first update and the first verification; The first update means updating the first vulnerability repair qualified data to obtain the first update data; The first verification means re-monitoring the total number of requests and the average session frequency within the preset time period after the first update; The first vulnerability repair qualified data means the browsing-related data after the first repair (such as, the user's session ID, request time, cookies and cache files stored in the browser, etc.); When the number of times of re-monitoring the total number of requests and the average session frequency within the preset time period is greater than the preset first monitoring number obtained from the database, send an alarm prompt to the preset personnel.
[0031] The specific process of the first update is as follows: Determine whether the monitored parameter to be verified meets the update qualification condition. The parameter to be verified includes the server load and the total number of requests after the first interception. The update qualification condition means that both the server load and the total number of requests after the first interception are not greater than the corresponding preset repair load and the maximum value of the preset number of requests obtained from the database. When the monitored parameter to be verified meets the update qualification condition, continue with the abnormal browsing monitoring. When the monitored parameter to be verified does not meet the update qualification condition, perform verification load optimization, which means sending a prompt to the preset personnel to set up a standby server and distributing qualified requests to the standby server.
[0032] In this embodiment, the aforementioned database is a database provided by the embodiment of the present application for a software vulnerability intelligent detection and repair method for network and information security to store various setting data. The database includes, but is not limited to, preset request frequencies, preset numbers of identical requests, preset browsing bandwidth occupancy rates, etc. The various values therein are directly set by technical personnel. For example, the maximum value of the preset number of requests is represented by the maximum value of the number of requests in the historical time period, the maximum value of the preset session frequency is represented by the maximum value of the session frequency in the historical time period, the preset interception speed is represented by the average value of the interception speed in the historical time period, and the preset repair load is represented by the average value of the server load in the historical time period. The preset first monitoring times are represented by the average value of the number of times of re-monitoring the average value of the total number of requests and the session frequency within the preset time period in the historical time period, and the preset first monitoring times are set by the preset personnel.
[0033] Perform the first interception optimization by setting the dynamic standby bandwidth by the preset personnel. In this embodiment, when the monitored preset interception speed is greater than the interception speed or the interception load is greater than the preset repair load, set the standby bandwidth equal to the preset bandwidth threshold, which is specified by the preset personnel. When the preset interception speed is greater than 2 times the interception speed or the interception load is greater than 2 times the preset repair load, set the standby bandwidth equal to 2 times the preset bandwidth threshold, and so on.
[0034] Verify whether the first repair is effective through the first update and verification to ensure the security and stability of the first interception. The preset personnel encode the output code corresponding to the suspicious address before outputting it to the HTML page, which helps prevent attacks such as cross-site scripting (XSS). The dynamic code analysis method (such as fuzz testing) can monitor and analyze the code behavior in real time, can quickly make an interception decision on the suspicious address, effectively prevent it from continuing to send requests, thereby improving the accuracy of the interception, and further improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0035] Further, the specific process of browsing anomaly monitoring is as follows: By analyzing the ratio of the average request frequency to the preset request frequency, and jointly analyzing the weighting effect with the ratio value of the browsing traffic peak and the first preset browsing traffic influence weight to obtain the traffic-request frequency analysis value. The ratio value of the browsing traffic peak is used to reflect the ratio of the maximum browsing traffic to the preset maximum browsing traffic; the ratio value of the browsing traffic peak is represented by the ratio result of the maximum browsing traffic and the preset maximum browsing traffic; By analyzing the ratio of the same request quantity to the preset same request quantity, and jointly analyzing the weighting effect with the ratio value of the browsing traffic peak and the second preset browsing traffic influence weight to obtain the traffic-same request analysis value; By analyzing the ratio of the browsing bandwidth occupancy rate to the preset browsing bandwidth occupancy rate, and jointly analyzing the weighting effect with the ratio value of the browsing traffic peak and the third preset browsing traffic influence weight to obtain the traffic-bandwidth occupancy analysis value; By analyzing the ratio of the maximum value of the request concurrent connection number to the preset request concurrent connection number, and jointly analyzing the weighting effect with the ratio value of the browsing traffic peak and the fourth preset browsing traffic influence weight to obtain the traffic-concurrency analysis value; By jointly analyzing the obtained browsing traffic and the anomaly reflection value to obtain the browsing anomaly monitoring value; The browsing anomaly monitoring value is used to reflect the quantification of the influence degree of the browsing traffic and the anomaly reflection value on the abnormal situation of the user's web page information browsing within the preset time period; The traffic and the anomaly reflection value include the traffic-request frequency analysis value, the traffic-same request analysis value, the traffic-bandwidth occupancy analysis value, and the traffic-concurrency analysis value; The traffic-request frequency analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the average request frequency on the abnormal situation of the user's web page information browsing. The traffic-request frequency analysis value is obtained by performing a product operation on the first preset browsing traffic influence weight, the ratio result of the average request frequency and the preset request frequency, and the ratio value of the browsing traffic peak; The traffic-same request analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the same request quantity on the abnormal situation of the user's web page information browsing. The traffic-same request analysis value is obtained by performing a product operation on the second preset browsing traffic influence weight, the ratio result of the same request quantity and the preset same request quantity, and the ratio value of the browsing traffic peak; The traffic-bandwidth occupancy analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the browsing bandwidth occupancy rate on the abnormal situation of the user's web page information browsing. The traffic-bandwidth occupancy analysis value is obtained by performing a product operation on the third preset browsing traffic influence weight, the ratio result of the browsing bandwidth occupancy rate and the preset browsing bandwidth occupancy rate, and the ratio value of the browsing traffic peak;The traffic-concurrency analysis value is used to reflect the comprehensive influence degree of the maximum browsing traffic and the maximum number of concurrent request connections on the abnormal situation of users' web page information browsing. The traffic-concurrency analysis value is obtained by performing a product operation on the fourth weight of the preset browsing traffic influence, the ratio result of the maximum number of concurrent request connections and the preset number of concurrent request connections, and the peak ratio degree value of the browsing traffic.
[0036] Among them, the browsing anomaly monitoring value is obtained by the following method: ; ; In the formula, represents the browsing anomaly monitoring value in the Y-th preset time period, , Y represents the number of the preset time period, T represents the total number of the preset time periods, represents the peak ratio degree value of the browsing traffic in the Y-th preset time period, represents the average request frequency in the Y-th preset time period, represents the number of the same requests in the Y-th preset time period, represents the browsing bandwidth occupancy rate in the Y-th preset time period, represents the maximum number of concurrent request connections in the Y-th preset time period, represents the maximum browsing traffic in the Y-th preset time period, represents the preset request frequency, represents the preset number of the same requests, represents the preset browsing bandwidth occupancy rate, represents the preset number of concurrent request connections, represents the preset maximum browsing traffic, represents the first weight of the preset browsing traffic influence, represents the second weight of the preset browsing traffic influence, represents the third weight of the preset browsing traffic influence, represents the fourth weight of the preset browsing traffic influence, and e represents the natural constant.
[0037] In this embodiment, the traffic and the abnormal reflection value are obtained by analyzing the browsing abnormal monitoring parameters and the preset browsing abnormal monitoring parameters. By monitoring the browsing abnormal monitoring parameters and the preset browsing abnormal monitoring parameters, it is helpful to analyze the comprehensive influence degree of the maximum browsing traffic and the average request frequency on the abnormal situation of the user's web page information browsing, the comprehensive influence degree of the maximum browsing traffic and the same number of requests on the abnormal situation of the user's web page information browsing, the comprehensive influence degree of the maximum browsing traffic and the browsing bandwidth occupancy rate on the abnormal situation of the user's web page information browsing, and the comprehensive influence degree of the maximum browsing traffic and the maximum number of concurrent request connections on the abnormal situation of the user's web page information browsing.
[0038] It should be understood that among them, the browsing abnormal monitoring parameters include the average request frequency, the same number of requests, the browsing bandwidth occupancy rate, the maximum number of concurrent request connections, and the maximum browsing traffic; the preset browsing abnormal monitoring parameters include the preset request frequency, the preset same number of requests, the preset browsing bandwidth occupancy rate, the preset number of concurrent requests, the preset maximum browsing traffic, and the preset browsing traffic influence weight group; the preset browsing traffic influence weight group is used to reflect the influence degree of the traffic and the abnormal reflection value within the preset time period on the browsing abnormal monitoring value, and specifically includes the preset browsing traffic influence first weight, the preset browsing traffic influence second weight, the preset browsing traffic influence third weight, and the preset browsing traffic influence fourth weight.
[0039] The preset request frequency is represented by the average value of the request frequencies in the historical time period, the preset same number of requests is represented by the average value of the same number of requests in the historical time period, the preset browsing bandwidth occupancy rate is represented by the average value of the browsing bandwidth occupancy rates in the historical time period, the preset number of concurrent requests is represented by the maximum value of the number of concurrent request connections in the historical time period, and the preset maximum browsing traffic is represented by the maximum value of the browsing traffic in the historical time period.
[0040] The number of requests per unit time within the preset time period is monitored through a network monitoring tool (such as SolarWinds Network Performance Monitor), and its average value is statistically obtained as the average request frequency; the number of the same requests within the preset time period is monitored through the server log as the same number of requests; the bandwidth ratio occupied by the browsing activity within the preset time period is monitored through a network monitoring tool as the browsing bandwidth occupancy rate; the number of concurrent connections within the preset time period is monitored through a server performance monitoring tool (such as NewRelic, Datadog), and its maximum value is statistically obtained as the maximum number of concurrent request connections; the network traffic generated by the browsing activity within the preset time period is monitored through a network monitoring tool, and its maximum value is statistically obtained as the maximum browsing traffic.
[0041] This embodiment provides a mapping set for reflecting the mapping relationship between traffic and abnormal corresponding parameters and the corresponding preset browsing traffic influence weight group. The mapping relationship in the mapping set can be a one-to-one or many-to-one relationship. The mapping set is obtained from the mapping group, and the mapping group is obtained from the database; by inputting the real-time traffic and abnormal corresponding parameters into the mapping group, the preset browsing traffic influence weight group can be obtained; for example, in this embodiment, the value range of the weight is 0-1. The traffic and abnormal corresponding parameters include the average request frequency, the number of identical requests, the browsing bandwidth occupancy rate, and the maximum number of concurrent request connections.
[0042] The algorithm of this embodiment combines the traffic and abnormal reflection values to analyze and obtain the browsing anomaly monitoring value. In this embodiment, the logarithmic function is used to process the traffic and abnormal reflection values to reflect that the traffic and abnormal reflection values are directly proportional to the browsing anomaly monitoring value, and the corresponding change trend is that as the traffic and abnormal reflection values increase, the browsing anomaly monitoring value gradually increases; the larger the traffic-request frequency analysis value, the greater the comprehensive influence degree of the maximum browsing traffic and the average request frequency on the abnormal situation of the user's web page information browsing, resulting in a larger browsing anomaly monitoring value; the larger the traffic-identical request analysis value, the greater the comprehensive influence degree of the maximum browsing traffic and the number of identical requests on the abnormal situation of the user's web page information browsing, resulting in a larger browsing anomaly monitoring value; the larger the traffic-bandwidth occupancy analysis value, the greater the comprehensive influence degree of the maximum browsing traffic and the browsing bandwidth occupancy rate on the abnormal situation of the user's web page information browsing, resulting in a larger browsing anomaly monitoring value; the larger the traffic-concurrency analysis value, the greater the comprehensive influence degree of the maximum browsing traffic and the maximum number of concurrent request connections on the abnormal situation of the user's web page information browsing. In summary, the traffic and abnormal reflection values are directly proportional to the traffic and abnormal reflection values.
[0043] In the algorithm of this embodiment, the browsing anomaly monitoring parameters do not exist independently, and there is a mutual correlation between the independent variables, which requires comprehensive analysis. The larger the number of identical requests, the more likely it indicates that there is a malicious script repeating requests for the same information, which may lead to an increase in the browsing bandwidth occupancy rate and the average value of the request frequency. The larger the number of identical requests, the more likely it means abnormal network traffic and an increased possibility of the existence of malicious scripts. When multiple requests are the same and interact simultaneously, an increase in the number of identical requests may be accompanied by an increase in the number of concurrent connections, which in turn leads to an increase in the maximum value of the request concurrent connection number. The larger the maximum value of the request concurrent connection number, the more likely it is to cause network bandwidth resource tension and occupy network bandwidth resources at the same time, which in turn leads to an increase in the browsing bandwidth occupancy rate. The larger the maximum value of the request concurrent connection number, the more likely it is to cause network congestion or server overload, which in turn leads to an increase in the maximum value of the browsing traffic. By analyzing the comprehensive influence between the parameters, the accurate evaluation of the abnormal situation of the user's web page information browsing within a preset time period is realized, and the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities is improved accordingly.
[0044] Further, the specific process of determining whether to perform the second vulnerability repair is as follows: Compare whether the browsing anomaly monitoring value is less than the preset browsing anomaly monitoring value obtained from the database. If so, it indicates that there is no anomaly in the user's web page information browsing, and the user-side transmission anomaly monitoring continues. If not, it indicates that there is an anomaly in the user's web page information browsing, and the second vulnerability repair is performed. The second vulnerability repair includes the second interception, the second repair, and the second update. The second interception means intercepting through setting browser plugins. The second repair means automatically repairing vulnerabilities through the set browser plugins. The second update means updating the qualified data of the second vulnerability repair to obtain the second updated data. The qualified data of the second vulnerability repair means the data after the first qualified data of the vulnerability repair is repaired for the second time.
[0045] In this embodiment, the preset browsing anomaly monitoring value is represented by the average value of the browsing anomaly monitoring values in the historical time period. Real-time monitoring of requests within a preset time period is achieved through browser plugins (such as AdBlock, uBlock Origin). When the browsing anomaly monitoring value is not less than the preset browsing anomaly monitoring value, the browser plugin will immediately intercept and block. When the browsing anomaly monitoring value is less than the preset browsing anomaly monitoring value, the second update is performed to ensure the accuracy of the browsing data. By performing the second vulnerability repair, the download and installation of malicious scripts are effectively prevented, protecting the user's system and data security. By the second interception, the tampering and destruction of the browser and system by malicious scripts are prevented, improving the stability and reliability when the user browses the web page, and thus improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0046] Further, perform user - side transmission anomaly monitoring to determine whether to perform the third vulnerability repair. The specific process is as follows: Monitor the script change rate to determine whether to perform the third vulnerability repair; when the monitored script change rate is not greater than the preset script change rate obtained from the database, transmit the second update data to the user - side; when the monitored script change rate is greater than the preset script change rate obtained from the database, perform the third vulnerability repair; the third vulnerability repair includes the third interception, the third repair, and the third update and verification.
[0047] It should be added that the third interception means sending a prompt to prohibit the execution of malicious scripts to the preset personnel; malicious scripts refer to the scripts corresponding to the script change rate greater than the preset script change rate; the third repair means sending a prompt to delete malicious scripts to the preset personnel; the third update and verification includes the third update and script change rate verification; the third update means updating the qualified data of the third vulnerability repair to obtain the third update data; the qualified data of the third vulnerability repair refers to the data after the qualified data of the second vulnerability repair has undergone the third repair; the script change rate verification means re - monitoring the script change rate until the number of times of script change rate verification reaches the preset maximum number of script change rate verification times; when the number of times of script change rate verification is greater than the preset maximum number of script change rate verification times, send an alarm prompt to the preset personnel.
[0048] In this embodiment, the preset script change rate is represented by the average value of the script change rate in the historical time period, and the preset maximum number of script change rate verification times is set by the preset personnel; by monitoring the script change rate, malicious scripts can be detected in a timely manner, effectively preventing the execution of malicious software or attack codes, thereby enhancing the security of users when browsing the web. When the script change rate is monitored to be abnormal, that is, when the script change rate is greater than the preset script change rate, the third vulnerability repair is performed, improving the response speed to security events; by sending a prompt to delete malicious scripts to the preset personnel, it helps to shorten the vulnerability repair time and reduce the potential damage caused by malicious scripts; by updating the qualified data of the third vulnerability repair, security problems caused by data errors or omissions are avoided; through the script change rate verification, the stability of the user when browsing the web after the third repair is ensured; thus achieving the effect of improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0049] Further, for user - end transmission anomaly monitoring, it also includes obtaining the user - end transmission anomaly monitoring value, and the specific process is as follows: By analyzing the proportion degree of the number of browsing interruptions and the preset number of browsing interruptions, and jointly analyzing the weighting effect with the page loading proportion degree value and the preset user - end transmission first weight value to obtain the loading - interruption analysis value. The page loading proportion degree value is used to reflect the proportion degree of the average page loading duration relative to the preset page loading duration; the page loading proportion degree value is obtained by the result of the ratio operation of the average page loading duration and the preset page loading duration; By analyzing the proportion degree of the number of interceptions and the preset number of interceptions, and jointly analyzing the weighting effect with the page loading proportion degree value and the preset user - end transmission second weight value to obtain the loading - interception analysis value; By analyzing the proportion degree of the number of browser crashes and the preset number of browser crashes, and jointly analyzing the weighting effect with the page loading proportion degree value and the preset user - end transmission third weight value to obtain the loading - crash analysis value; By analyzing the proportion degree of the maximum request - response duration and the preset request - response duration, and jointly analyzing the weighting effect with the page loading proportion degree value and the preset user - end transmission fourth weight value to obtain the loading - request - response analysis value; By jointly analyzing the above - obtained user - end transmission anomaly reflection values to obtain the user - end transmission anomaly monitoring value; The user - end transmission anomaly monitoring value is used to reflect the quantification of the influence degree of the user - end transmission anomaly reflection values within the preset user - end monitoring time period on the abnormal situation of web page information transmission to the user - end; The user - end transmission anomaly reflection values include the loading - interruption analysis value, the loading - interception analysis value, the loading - crash analysis value, and the loading - request - response analysis value; The preset user - end monitoring time period represents the preset time period after the second vulnerability repair; The loading - interruption analysis value is obtained by performing a product operation on the ratio result of the number of browsing interruptions and the preset number of browsing interruptions, the page loading proportion degree value, and the preset user - end transmission first weight value, and is used to reflect the comprehensive influence degree of the number of browsing interruptions and the average page loading duration on the abnormal situation of web page information transmission to the user - end; The loading - interception analysis value is obtained by performing a product operation on the ratio result of the number of interceptions and the preset number of interceptions, the page loading proportion degree value, and the preset user - end transmission second weight value, and is used to reflect the comprehensive influence degree of the number of interceptions and the average page loading duration on the abnormal situation of web page information transmission to the user - end; The loading - crash analysis value is obtained by performing a product operation on the ratio result of the number of browser crashes and the preset number of browser crashes, the page loading proportion degree value, and the preset user - end transmission third weight value, and is used to reflect the comprehensive influence degree of the number of browser crashes and the average page loading duration on the abnormal situation of web page information transmission to the user - end;The load - request response analysis value is obtained by multiplying the ratio of the maximum request - response duration to the preset request - response duration, the page load proportion value, and the preset fourth weight value of the client - side transmission, and is used to reflect the comprehensive influence degree of the maximum request - response duration and the average page load duration on the abnormal situation of web information transmission to the client - side.
[0050] Among them, the client - side transmission anomaly monitoring value is obtained by the following method: ; ; In the formula, represents the client - side transmission anomaly monitoring value of the D - th preset client - side monitoring time period, , D represents the number of the preset client - side monitoring time period, K represents the total number of the preset client - side monitoring time periods, represents the page load proportion value of the D - th preset client - side monitoring time period, represents the number of interceptions in the D - th preset client - side monitoring time period, represents the number of browsing interruptions in the D - th preset client - side monitoring time period, represents the number of browser crashes in the D - th preset client - side monitoring time period, represents the maximum request - response duration of the D - th preset client - side monitoring time period, represents the average page load duration of the D - th preset client - side monitoring time period, represents the preset number of browsing interruptions, represents the preset number of interceptions, represents the preset number of browser crashes, represents the preset request - response duration, represents the preset page load duration, represents the preset first weight value of the client - side transmission, represents the preset second weight value of the client - side transmission, represents the preset third weight value of the client - side transmission, represents the preset fourth weight value of the client - side transmission.
[0051] In this embodiment, the client transmission anomaly reflection value is obtained through joint analysis based on the client transmission anomaly monitoring parameters and the preset client transmission anomaly monitoring parameters. By monitoring the client transmission anomaly monitoring parameters and the preset client transmission anomaly monitoring parameters, it helps to analyze the comprehensive influence degree of the number of browsing interruptions and the average page loading duration on the anomaly situation of web page information transmission to the client, the comprehensive influence degree of the number of interceptions and the average page loading duration on the anomaly situation of web page information transmission to the client, the comprehensive influence degree of the number of browser crashes and the average page loading duration on the anomaly situation of web page information transmission to the client, and the comprehensive influence degree of the maximum request response duration and the average page loading duration on the anomaly situation of web page information transmission to the client.
[0052] It should be understood that among them, the client transmission anomaly monitoring parameters include the number of interceptions, the number of browsing interruptions, the number of browser crashes, the maximum request response duration, and the average page loading duration; the preset client transmission anomaly monitoring parameters include the preset number of browsing interruptions, the preset number of interceptions, the preset number of browser crashes, the preset request response duration, the preset page loading duration, and the preset loading influence weight group; the preset loading influence weight group is used to reflect the influence degree of the client transmission anomaly reflection value on the client transmission anomaly monitoring value during the preset client monitoring time period, and specifically includes the preset client transmission first weight value, the preset client transmission second weight value, the preset client transmission third weight value, and the preset client transmission fourth weight value.
[0053] The preset number of browsing interruptions is represented by the average value of the number of browsing interruptions in the historical time period, the preset number of interceptions is represented by the average value of the number of interceptions in the historical time period, the preset number of browser crashes is represented by the average value of the number of browser crashes in the historical time period, the preset request response duration is represented by the average value of the request response duration in the historical time period, and the preset page loading duration is represented by the average value of the page loading duration in the historical time period.
[0054] The number of times that browser plugins (such as AdBlock, uBlock Origin) intercept malicious content (malicious scripts) during the preset client monitoring time period monitored by a network monitoring tool is the interception number; the number of times of page loading interruption events during the preset client monitoring time period monitored by JavaScript is the browsing interruption number; the number of times of browser crashes during the preset client monitoring time period monitored by a browser (with a crash reporting function) is the browser crash number; the response duration of API (Application Programming Interface) requests during the preset client monitoring time period is monitored by a network monitoring tool, and the maximum value thereof is statistically obtained to get the maximum request response duration; the page loading duration during the preset client monitoring time period is monitored by a Web analysis tool (such as Google Analytics, Pingdom), and the average value thereof is statistically obtained to get the average page loading duration.
[0055] By inputting the real-time client transmission abnormal corresponding parameters into a set of mapping groups obtained from a database to obtain a preset loading influence weight group, the mapping group provides a mapping set reflecting the mapping relationship between the client transmission abnormal corresponding parameters and the corresponding preset loading influence weight group, and the mapping relationship in the mapping set can be a one-to-one or many-to-one relationship; for example, in this embodiment, the value range of the weight is 0-1. The client transmission abnormal corresponding parameters include the browsing interruption number, the interception number, the browser crash number, and the maximum request response duration.
[0056] The algorithm of this embodiment combines the abnormal reflection value of the client transmission to analyze and obtain the abnormal monitoring value of the client transmission. In this embodiment, the exponential function is used to process the abnormal reflection value of the client transmission to reflect the proportional change trend between the abnormal reflection value of the client transmission and the abnormal monitoring value of the client transmission. And the corresponding change trend is that as the abnormal reflection value of the client transmission increases, the abnormal monitoring value of the client transmission gradually increases; the larger the load-interruption analysis value, it means that the combined influence degree of the number of browsing interruptions and the average page load duration on the abnormal situation of the web page information transmission to the client is greater, resulting in a larger abnormal monitoring value of the client transmission; the larger the load-interception analysis value, it means that the combined influence degree of the number of interceptions and the average page load duration on the abnormal situation of the web page information transmission to the client is greater, resulting in a larger abnormal monitoring value of the client transmission; the larger the load-crash analysis value, it means that the combined influence degree of the number of browser crashes and the average page load duration on the abnormal situation of the web page information transmission to the client is greater, resulting in a larger abnormal monitoring value of the client transmission; the larger the load-request response analysis value, it means that the combined influence degree of the maximum value of the request response duration and the average page load duration on the abnormal situation of the web page information transmission to the client is greater, resulting in a larger abnormal monitoring value of the client transmission. In summary, there is a proportional relationship between the abnormal reflection value of the client transmission and the abnormal monitoring value of the client transmission.
[0057] In the algorithm of this embodiment, the abnormal monitoring parameters of the client transmission do not exist independently, and there is a mutual correlation between the independent variables, which requires comprehensive analysis. The more the number of interceptions, it may mean that the web page content accessed by the user is interfered by malicious scripts, which may cause frequent loading interruptions during the browsing process, and then lead to an increase in the number of browsing interruptions; an increase in the number of interceptions may cause requests to be delayed or redirected, thus increasing the maximum value of the request response duration; an increase in the number of browsing interruptions may lead to an increased possibility of forcibly closing the page or the browser, and then lead to an increase in the number of browser crashes; an increase in the number of browsing interruptions usually means an increased possibility of being interfered by malicious scripts during the page loading process, and reloading the page, which then leads to an increase in the average page load duration; the more the number of browser crashes, it may cause the user to need to reopen the browser and resend the request, which may lead to an increase in the maximum value of the request response duration, and the larger the maximum value of the request response duration, it may be accompanied by an increase in the average page load duration; by analyzing the comprehensive influence between the parameters, the accurate evaluation of the abnormal situation of the web page information transmission to the client within the preset client monitoring time period is realized, and then the effect of improving the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities is achieved.
[0058] Further, for user - end transmission anomaly monitoring, it also includes determining whether to perform user - end transmission optimization. The specific process is as follows: If the user - end transmission anomaly monitoring value is greater than the preset user - end transmission anomaly threshold obtained from the database, then transmit the third update data to the user - end; if the user - end transmission anomaly monitoring value is not greater than the preset user - end transmission anomaly threshold obtained from the database, then perform user - end transmission optimization. The specific steps of user - end transmission optimization are as follows: First, monitor the transmission distance and set priorities, where the transmission distance represents the transmission distance between the server and the user - end; Second, perform update frequency optimization, which means sending a prompt to a preset person to gradually increase the update frequency of the browser plugin by a preset multiple.
[0059] In this embodiment, the preset user - end transmission anomaly threshold is represented by the average value of the user - end transmission anomaly monitoring values in the historical time period; By real - time monitoring the user - end transmission anomaly value, it helps to promptly detect transmission anomalies and take corresponding measures (user - end transmission optimization); When the user - end transmission anomaly monitoring value is greater than the preset user - end transmission anomaly threshold, transmitting the third update data to the user - end helps to ensure the accuracy of the user - end to obtain browsing information, and improves the stability and reliability of the transmission; Monitoring the transmission distance and setting priorities, and preferentially selecting the server with the shortest transmission distance for browsing information distribution helps to optimize user - end transmission according to the dynamic change of the transmission distance, and improves the transmission efficiency; By gradually increasing the update frequency of the browser plugin by a preset multiple, it helps to reduce the user waiting time and the situation of transmission interruption, ensures the timely update of the browser plugin, and thus improves the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities.
[0060] In summary, by performing request volume and session frequency anomaly monitoring and determining whether to perform the first vulnerability repair, then performing browsing anomaly monitoring and determining whether to perform the second vulnerability repair, and finally performing user - end transmission anomaly monitoring and determining whether to perform the third vulnerability repair, the reliability of identifying vulnerabilities when detecting and repairing software vulnerabilities is improved, and further the accuracy of identifying vulnerabilities when detecting and repairing software vulnerabilities is improved, effectively solving the problem of low accuracy of identifying vulnerabilities in the prior art when detecting and repairing software vulnerabilities.
[0061] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer - usable storage media (including but not limited to disk storage, CD - ROM, optical storage, etc.) that contain computer - usable program code.
[0062] The present invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowchart illustrations and / or block diagrams, and combinations of flows and / or blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing apparatus create means for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0063] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0064] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0065] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.
[0066] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A software vulnerability intelligent detection and repair method for network and information security, characterized in that: The following steps are involved: S1, monitor the request volume and session frequency anomalies to determine whether to perform the first vulnerability repair; S2, monitor browsing anomalies and determine whether to perform a second vulnerability repair; S3, monitor the transmission anomalies on the user side and determine whether to perform the third vulnerability repair.
2. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 1, characterized in that: The specific process of monitoring the abnormality of request volume and session frequency is as follows: Monitor the total number of requests and average session frequency within a preset time period; When the total number of monitored requests is greater than the preset maximum number of requests obtained from the database, or the average value of the session frequency is greater than the preset maximum value of the session frequency obtained from the database, the corresponding request address is marked as a suspicious address, and the first vulnerability repair is performed; The first vulnerability repair includes the first interception, the first repair and the first update and verification; The first interception means intercepting the suspicious address by a dynamic code analysis method; The specific process of the first vulnerability repair is as follows: Monitoring whether the repair detection parameters meet the interception qualification conditions, the repair detection parameters include interception speed and interception load, the interception load represents the average value of the server load during the first interception process; When the repair detection parameter does not meet the interception qualification condition, the first interception optimization is performed, and the first interception optimization means sending a prompt to a preset person to set a dynamic standby bandwidth; When the repair detection parameters meet the interception qualification conditions, the first repair is continued, and the first repair means sending a prohibited access prompt to a preset person and setting a suspicious address code.
3. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 2, characterized in that: The first update and verification include the first update and the first verification; The first update means updating the first vulnerability repair qualified data to obtain the first update data; The first verification means re-monitoring the total number of requests and the average value of session frequency within a preset time period after the first update; The first vulnerability repair qualified data represents browsing related data after the first repair is performed.
4. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 3, characterized in that: The specific process of the first update is as follows: Determine whether the monitored parameters to be verified meet the update qualification conditions, wherein the parameters to be verified include the server load and the total number of requests after the first interception; When the monitored parameters to be verified meet the update qualification conditions, continue to monitor browsing anomalies; When the monitored parameters to be verified do not meet the update qualification conditions, verification load optimization is performed, and the verification load optimization means sending a prompt to a preset person to set up a backup server and distribute the qualified requests to the backup server.
5. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 1, characterized in that: The specific process of performing browsing anomaly monitoring is as follows: The traffic-request frequency analysis value is obtained by analyzing the proportion of the average request frequency and the preset request frequency, and jointly analyzing the weighted effect with the browsing traffic peak proportion value and the preset browsing traffic impact first weight. The browsing traffic peak proportion value is used to reflect the proportion of the maximum browsing traffic value relative to the preset maximum browsing traffic. The traffic-same request analysis value is obtained by analyzing the proportion of the same request number and the preset same request number, and jointly analyzing the weighted effect with the browsing traffic peak proportion value and the preset browsing traffic impact second weight; The traffic-bandwidth occupancy analysis value is obtained by analyzing the browsing bandwidth occupancy rate and the preset browsing bandwidth occupancy rate, and jointly analyzing the weighted effect with the browsing traffic peak occupancy rate value and the preset browsing traffic impact third weight; The flow-concurrency analysis value is obtained by analyzing the proportion of the maximum value of the concurrent request connection number and the preset concurrent request connection number, and jointly analyzing the weighted effect with the browsing traffic peak proportion value and the preset browsing traffic impact fourth weight; The browsing anomaly monitoring value is obtained by jointly analyzing the browsing traffic and the anomaly reflection value obtained above; The browsing anomaly monitoring value is used to reflect the quantification of the influence of the browsing flow and the anomaly reflection value on the abnormality of the user's web page information browsing in a preset time period; The traffic and abnormal reflection values include traffic-request frequency analysis value, traffic-same request analysis value, traffic-bandwidth occupancy analysis value and traffic-concurrency analysis value; The traffic-request frequency analysis value is used to reflect the comprehensive impact of the maximum browsing traffic and the average request frequency on the abnormal situation of the user's web page information browsing; The flow-same request analysis value is used to reflect the comprehensive impact of the maximum browsing flow and the number of same requests on the abnormality of the user's web page information browsing; The traffic-bandwidth occupancy analysis value is used to reflect the comprehensive impact of the maximum browsing traffic and the browsing bandwidth occupancy rate on the abnormality of the user's web page information browsing; The flow-concurrency analysis value is used to reflect the comprehensive impact of the maximum browsing flow and the maximum number of concurrent request connections on the abnormal situation of the user's web page information browsing.
6. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 5, characterized in that: The specific process of determining whether to perform a second vulnerability repair is as follows: Compare whether the browsing anomaly monitoring value is less than the preset browsing anomaly monitoring value obtained from the database; If yes, continue to monitor the abnormality of user-side transmission; If not, perform a second vulnerability repair; The second vulnerability repair includes a second interception, a second repair and a second update; The second interception means interception by setting a browser plug-in; The second repair means automatically repairing the vulnerability through a set browser plug-in; The second update means updating the second vulnerability repair qualified data to obtain the second update data; The second vulnerability repair qualified data refers to the data of the first vulnerability repair qualified data after the second repair.
7. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 1, characterized in that: The user-side transmission anomaly monitoring is performed to determine whether to perform the third vulnerability repair. The specific process is as follows: Monitor the script change rate to determine whether to perform a third vulnerability repair; When the monitored script change rate is not greater than the preset script change rate obtained from the database, the second update data is transmitted to the user end; When the monitored script change rate is greater than the preset script change rate obtained from the database, the third vulnerability repair is performed; The third vulnerability repair includes the third interception, the third repair and the third update and verification.
8. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 7, characterized in that: The third interception means sending a prompt prohibiting the running of malicious scripts to a preset person; The malicious script indicates a script whose script change rate is greater than the script corresponding to the preset script change rate; The third repair means sending a reminder to delete the malicious script to a preset person; The third update and verification includes the third update and script change rate verification; The third update means updating the third vulnerability repair qualified data to obtain the third update data; The third vulnerability repair qualified data refers to the data of the second vulnerability repair qualified data after the third repair; The script change rate verification means re-monitoring the script change rate until the number of script change rate verifications reaches a preset maximum number of script change rate verifications.
9. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 7, characterized in that: The user terminal transmission abnormality monitoring also includes obtaining the user terminal transmission abnormality monitoring value, and the specific process is as follows; The loading-interruption analysis value is obtained by analyzing the proportion of the number of browsing interruptions and the preset number of browsing interruptions, and performing a joint analysis of the weighted effect with the page loading proportion value and the preset user terminal transmission first weight value, wherein the page loading proportion value is used to reflect the proportion of the average page loading time relative to the preset page loading time; The loading-interception analysis value is obtained by analyzing the proportion of the number of interceptions and the preset number of interceptions, and jointly analyzing the weighted effect with the page loading proportion value and the preset second weight value of the user terminal transmission; The load-crash analysis value is obtained by analyzing the proportion of the number of browser crashes and the preset number of browser crashes, and performing a weighted joint analysis with the page load proportion value and the preset user terminal transmission third weight value; The load-request-response analysis value is obtained by analyzing the proportion of the maximum request-response duration and the preset request-response duration, and jointly analyzing the weighted effect with the page load proportion value and the preset user-side transmission fourth weight value; The user terminal transmission anomaly monitoring value is obtained by jointly analyzing the user terminal transmission anomaly reflection value obtained above; The user terminal transmission abnormality monitoring value is used to reflect the quantitative situation of the influence of the user terminal transmission abnormality reflection value within the preset user terminal monitoring time period on the abnormal situation of web page information transmission to the user terminal; The user-side transmission abnormality reflection value includes a loading-interruption analysis value, a loading-interception analysis value, a loading-crash analysis value and a loading-request response analysis value; The loading-interruption analysis value is used to reflect the comprehensive impact of the number of browsing interruptions and the average page loading time on the abnormal situation of web page information transmission to the user end; The loading-interception analysis value is used to reflect the comprehensive impact of the number of interception times and the average page loading time on the abnormal situation of web page information transmission to the user end; The load-crash analysis value is used to reflect the comprehensive impact of the number of browser crashes and the average page loading time on the abnormal situation of web page information transmission to the user end; The loading-request response analysis value is used to reflect the comprehensive impact of the maximum request response duration and the average page loading duration on the abnormal situation of web page information transmission to the user end.
10. A method for intelligent detection and repair of software vulnerabilities for network and information security as claimed in claim 9, characterized in that: The monitoring of abnormal transmission at the user end also includes determining whether to optimize the transmission at the user end. The specific process is as follows: If the user terminal transmission anomaly monitoring value is greater than the preset user terminal transmission anomaly threshold obtained from the database, the third update data is transmitted to the user terminal; If the user-side transmission anomaly monitoring value is not greater than the preset user-side transmission anomaly threshold obtained from the database, user-side transmission optimization is performed; The specific steps of the user-side transmission optimization are as follows: The first step is to monitor the transmission distance and set the priority, wherein the transmission distance represents the transmission distance between the server and the user end; The second step is to optimize the update frequency, wherein the update frequency optimization means sending a prompt to a preset person to gradually increase the update frequency of the browser plug-in by a preset multiple.
Citation Information
Patent Citations
Application software vulnerability scanning method and system
CN117874772B
Vulnerability detection method and system
CN117972714B
Method for patching bugs and device thereof
CN101526984A
Data security risk assessment system based on artificial intelligence
CN119203200A
Network attack defense method and system for distributed new energy grid-connected system
CN119341807A