Intelligent vulnerability feature recommendation method based on Transform model

Through the intelligent vulnerability feature recommendation method based on the Transformer model, the problems of insufficient vulnerability simulation information and low fraud success rate in the existing technology are solved, and more efficient vulnerability feature recommendation and fraud success rate are achieved.

CN120180449AActive Publication Date: 2025-06-20GUANGZHOU UNIVERSITY
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510580710.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-06-20
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The simulation pages of the existing vulnerability simulation service are static pages and cannot provide high-value information, resulting in a low fraud success rate for high-level attackers and insufficient system ability to fight against high-level attackers.

Method used

The intelligent vulnerability feature recommendation method based on the Transformer model is adopted, and the initial vulnerability information is obtained through multiple open source vulnerability libraries, and the BM25 algorithm and FAISS algorithm are combined to perform semantic correlation rough search and vector similarity fine search to recommend the optimal vulnerability feature.

Benefits of technology

It increases the amount of vulnerability information during vulnerability simulation, improves the success rate of vulnerability spoofing, and enhances the system's ability to fight against high-level attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180449A_ABST
    Figure CN120180449A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent vulnerability feature recommendation method based on a Transform model, and relates to the technical field of deception defense resource deployment. The method comprises the following steps: acquiring initial vulnerability information based on multiple open source vulnerability libraries, performing information arrangement and classification to acquire vulnerability numbers, and supplementing vulnerability information corresponding to the vulnerability numbers based on an automatic dynamic crawler; performing semantic relevancy coarse retrieval on the vulnerability information and version information of a target service system based on a BM25 algorithm to obtain a retrieval knowledge base, and performing vectorization on the retrieval knowledge base and the version information based on a Transform model to obtain vectorized data, and performing vector similarity fine retrieval on the vectorized data based on an FAISS algorithm to obtain an optimal vulnerability feature. According to the intelligent vulnerability feature recommendation method provided by the invention, the quantity of vulnerability information during vulnerability simulation is supplemented, and the optimal vulnerability feature is recommended in combination with the version information of the target service system, so that the success rate of vulnerability deception is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of deception defense resource deployment, and particularly to an intelligent vulnerability feature recommendation method based on a Transformer model. Background Art

[0002] Vulnerability countermeasure simulation service is a network security defense means. By simulating vulnerabilities and weaknesses in a real network environment, it lures attackers into the simulation environment, thereby realizing the monitoring, analysis, and defense of attack behaviors.

[0003] Currently, the simulation pages of simulation services are usually static pages, without targets that can provide high-value information for attackers to search for. Even if the attack is successful, the simulation page cannot provide any actual benefits or an entrance to deeper systems. Therefore, it is difficult to arouse the interest of high-level attackers, resulting in a low deception success rate for high-level attackers and insufficient ability of the system to counter high-level attackers. Therefore, there is an urgent need to provide a solution to improve the above problems. Summary of the Invention

[0004] The purpose of the present invention is to provide an intelligent vulnerability feature recommendation method based on a Transformer model, which improves the problems of insufficient number of vulnerability information and low vulnerability deception success rate in existing technology during vulnerability simulation.

[0005] An intelligent vulnerability feature recommendation method based on a Transformer model provided by the present invention adopts the following technical solutions: Obtain initial vulnerability information based on multiple open-source vulnerability libraries, classify the initial vulnerability information to obtain vulnerability numbers, and supplement the initial vulnerability information corresponding to the vulnerability numbers based on an automated dynamic crawler and save it in a local vulnerability knowledge base; Based on the BM25 algorithm, perform a rough semantic relevance retrieval on the local vulnerability knowledge base and the version information of the target service system to obtain a retrieval knowledge base. Based on the Transformer model, vectorize the retrieval knowledge base and the version information to obtain vectorized data. Based on the FAISS algorithm, perform a fine retrieval of vector similarity on the vectorized data to recommend the optimal vulnerability features.

[0006] For the intelligent vulnerability feature recommendation method based on a Transformer model as described above, in the process of obtaining initial vulnerability information based on multiple open-source vulnerability libraries, it includes: Obtain initial vulnerability information based on multiple open-source vulnerability libraries. The multiple open-source vulnerability libraries include NUCLEI, XRAY, GOBY, PUBLIC, and the initial vulnerability information includes vulnerability IDs, POC links, and vulnerability hazard descriptions.

[0007] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, in the process of classifying the initial vulnerability information to obtain the vulnerability number, it includes: classifying the initial vulnerability information into CVE and CNVD types, and obtaining the CVE and CNVD vulnerability numbers of the initial vulnerability information.

[0008] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, in the process of supplementing the initial vulnerability information corresponding to the vulnerability number based on an automated dynamic crawler, it includes: Based on the automated dynamic crawler, supplement the vulnerability information in CVE and CNVD for the vulnerability number to obtain complete vulnerability information, including the triggering conditions of the vulnerability, possible attack paths, and repair suggestions.

[0009] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, in the process of performing a rough semantic relevance retrieval on the local vulnerability knowledge base and the version information of the target service system based on the BM25 algorithm to obtain the retrieval knowledge base, it includes: Score and rank based on the relevance between the keywords of the version information and the vulnerability information corresponding to the vulnerability number in the local vulnerability knowledge base, and select the vulnerability information based on a sorting threshold, where the relevance includes term frequency, inverse document frequency, and document length.

[0010] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, in the process of vectorizing the retrieval knowledge base and the version information of the target service system based on the Transformer model, it includes: Based on the Transformer model, pre-train and fine-tune the vulnerability information corresponding to the vulnerability number in the retrieval knowledge base and the version information, and convert the vulnerability information and the version information into multiple fixed-length numerical vectors, where the numerical vectors include the vector to be retrieved and the query vector.

[0011] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, in the process of performing pre-training and fine-tuning, it includes: Randomly mask the words of the vulnerability information and the version information based on the masked language model, and predict the words based on the Transformer model; predict whether two sentences are natural continuations based on the Transformer model.

[0012] The intelligent vulnerability feature recommendation method based on the Transformer model as described above, wherein, converting the vulnerability information and the version information into multiple fixed-length numerical vectors includes: Tokenize the vulnerability information and the version information based on the Transformer model to obtain initial word vectors; Encode the word vectors based on the multi-layer Transformer architecture of the Transformer model and convert them into numerical vectors that can be compared in the vector space.

[0013] In the intelligent vulnerability feature recommendation method based on the Transformer model as described above, during the process of accurately retrieving and recommending the optimal vulnerability features for the vectorized data based on the FAISS algorithm, it includes: Calculate the cosine similarity or inner product similarity between the query vector and the vector to be retrieved based on the FAISS algorithm, obtain the retrieval vector that is most similar to the query vector, and use the vulnerability number corresponding to the retrieval vector as the optimal vulnerability feature.

[0014] In the intelligent vulnerability feature recommendation method based on the Transformer model as described above, during the process of obtaining multiple retrieval knowledge base vectors that are most similar to the query vector, it includes: the value range of the cosine similarity degree in the direction of the query vector and the vector to be retrieved is from -1 to 1, and obtain the vector to be retrieved whose cosine similarity degree is closest to 1.

[0015] The beneficial effects of the intelligent vulnerability feature recommendation method based on the Transformer model proposed by the present invention are as follows: 1. The local vulnerability knowledge base of the present invention improves the problem of insufficient quantity of vulnerability information during vulnerability simulation in the prior art.

[0016] 2. The present invention recommends version information-related vulnerabilities for the target service system, which can improve the success rate of vulnerability deception. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flowchart of the intelligent vulnerability feature recommendation method based on the Transformer model provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art to which the present invention pertains. The words such as "including" used herein are intended to mean that the elements or items appearing before the word cover the elements or items listed after the word and their equivalents, without excluding other elements or items.

[0019] An embodiment of the present invention provides an intelligent vulnerability feature recommendation method based on a Transformer model. Refer to Figure 1 , including: S1. Obtain initial vulnerability information based on multiple open-source vulnerability libraries, organize and classify the initial vulnerability information to obtain vulnerability numbers, and supplement the initial vulnerability information corresponding to the vulnerability numbers based on an automated dynamic crawler and store it in a local vulnerability knowledge base; S2. Based on the BM25 algorithm, perform a rough semantic relevance retrieval on the local vulnerability knowledge base and the version information of the target service system to obtain a retrieval knowledge base, vectorize the retrieval knowledge base and the version information based on the Transformer model to obtain vectorized data, and perform a fine retrieval of vector similarity on the vectorized data based on the FAISS algorithm to obtain the optimal vulnerability features.

[0020] In some embodiments, during the execution of step S1, it includes: S1.1. Obtain initial vulnerability information based on multiple open-source vulnerability libraries; S1.2. Organize and classify the initial vulnerability information to obtain vulnerability numbers; S1.3. Supplement the initial vulnerability information corresponding to the vulnerability numbers based on an automated dynamic crawler and store it in a local vulnerability knowledge base.

[0021] Specifically, when performing step S1.1 to obtain initial vulnerability information based on multiple open-source vulnerability libraries, it includes: Obtain initial vulnerability information based on multiple open-source vulnerability libraries. The multiple open-source vulnerability libraries include NUCLEI, XRAY, GOBY, and PUBLIC. The initial vulnerability information includes vulnerability IDs, POC links, and vulnerability hazard descriptions.

[0022] Specifically, when performing step S1.2 to sort and classify the initial vulnerability information to obtain a vulnerability number, it includes: sorting and classifying the initial vulnerability information into CVE and CNVD types, and obtaining the CVE and CNVD vulnerability numbers corresponding to the initial vulnerability information.

[0023] Actually, the CVE is an internationally recognized standard for public disclosure of information security vulnerabilities, and the CNVD is the National Information Security Vulnerability Sharing Platform. The CVE vulnerability number and the CNVD vulnerability number are unique. By sorting and classifying the vulnerability information to obtain the CVE vulnerability number or the CNVD vulnerability number of the vulnerability information, the detailed information of the vulnerability can be effectively obtained.

[0024] Specifically, when performing step S1.3 to supplement the initial vulnerability information corresponding to the vulnerability number based on an automated dynamic crawler and store it in the local vulnerability knowledge base, it includes: S1.3.1. The automated dynamic crawler supplements the initial vulnerability information corresponding to the vulnerability number; S1.3.2. Store the vulnerability information in the local vulnerability knowledge base.

[0025] Specifically, when performing step S1.3.1, when the automated dynamic crawler supplements the initial vulnerability information corresponding to the vulnerability number, it includes: Based on the automated dynamic crawler, supplement the initial vulnerability information for the vulnerability number in CVE and CNVD to obtain complete vulnerability information, including the triggering conditions of the vulnerability, possible attack paths, and repair suggestions.

[0026] Furthermore, when performing step S1.3.2 and storing the vulnerability information in the local vulnerability knowledge base, it is stored in the form of using the vulnerability number as the key and the vulnerability information as the value.

[0027] In some instances, during the execution of step S2, it includes: S2.1. Based on the BM25 algorithm, perform a rough semantic relevance retrieval on the local vulnerability knowledge base and the version information of the target service system to obtain a retrieval knowledge base; S2.2. Based on the Transformer model, vectorize the retrieval knowledge base and the version information to obtain vectorized data; S2.3. Based on the FAISS algorithm, perform a fine retrieval of vector similarity on the vectorized data to obtain the optimal vulnerability features.

[0028] Specifically, when performing step S2.1 and performing a rough semantic relevance retrieval on the local vulnerability knowledge base and the version information of the target service system based on the BM25 algorithm to obtain a retrieval knowledge base, it includes: Score and rank based on the correlation between the keywords based on the version information and the vulnerability information corresponding to the vulnerability numbers in the local vulnerability knowledge base, and select the vulnerability information based on a sorting threshold. The correlation includes word frequency, inverse document frequency, and document length.

[0029] Among them, the word frequency refers to the number of times the keyword appears in the vulnerability information. The inverse document frequency means that when the keyword appears in multiple vulnerability information, the lower the inverse document frequency value, and vice versa. The document length refers to the total number of characters in the vulnerability information.

[0030] Specifically, when performing step S2.2 to obtain vectorized data by vectorizing the retrieval knowledge base and the version information based on the Transformer model, it includes: S2.2.1. Pre-train and fine-tune the vulnerability information corresponding to the vulnerability numbers in the retrieval knowledge base and the version information based on the Transformer model; S2.2.2. Convert the vulnerability information and the version information into multiple fixed-length numerical vectors, and the numerical vectors include the vector to be retrieved and the query vector.

[0031] Specifically, when performing step S2.2.1, randomly mask the words in the vulnerability information and the version information based on the masked language model, and predict the words based on the Transformer model; predict whether two sentences are natural continuations based on the Transformer model.

[0032] Actually, randomly masking the words in the vulnerability information and the version information through the masked language model can enable the Transformer model to master the meanings of the words in different contexts. By judging whether two sentences are natural continuations, the Transformer model's ability to handle the logical relationships between different sentences can be improved.

[0033] Specifically, when performing step S2.2.2, it includes: performing word segmentation on the vulnerability information and the version information based on the Transformer model to obtain initial word vectors; Furthermore, encode the word vectors based on the multi-layer Transformer architecture of the Transformer model and convert them into numerical vectors that can be compared in the vector space.

[0034] Among them, the multi-layer Transformer architecture calculates the importance of each word vector in the sequence through the self-attention mechanism, generates an encoded representation containing context information, converts the version information into a query vector, and converts the vulnerability information into a vector to be retrieved.

[0035] Specifically, when performing step S2.3 to perform a refined retrieval of vector similarity on the vectorized data to obtain the optimal vulnerability features based on the FAISS algorithm, it includes: Calculate the cosine similarity or inner product similarity between the query vector and the vector to be retrieved based on the FAISS algorithm, obtain the retrieval vector with the highest similarity to the query vector, and use the vulnerability number corresponding to the retrieval vector as the optimal vulnerability feature.

[0036] Among them, the cosine similarity measurement method is usually adopted, and the value range of the cosine similarity in the direction of the query vector and the vector to be retrieved is from -1 to 1, and the vector to be retrieved with the cosine similarity closest to 1 is obtained.

[0037] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein may have other embodiments and can be implemented or realized in various ways.

Claims

1. An intelligent vulnerability feature recommendation method based on the Transformer model, characterized in that: The following steps are involved: Obtaining initial vulnerability information based on multiple open source vulnerability libraries, sorting and classifying the initial vulnerability information to obtain vulnerability numbers, supplementing the initial vulnerability information corresponding to the vulnerability numbers based on an automated dynamic crawler and storing the information in a local vulnerability knowledge base; Based on the BM25 algorithm, a semantic relevance coarse search is performed on the local vulnerability knowledge base and the version information of the target service system to obtain a retrieval knowledge base, based on the Transformer model, the retrieval knowledge base and the version information are vectorized to obtain vectorized data, and based on the FAISS algorithm, a vector similarity fine search is performed on the vectorized data to obtain the optimal vulnerability features.

2. According to claim 1, the intelligent vulnerability feature recommendation method based on the Transformer model is characterized in that: The process of obtaining initial vulnerability information based on multiple open source vulnerability libraries includes: Initial vulnerability information is obtained based on multiple open source vulnerability libraries, where the multiple open source vulnerability libraries include NUCLEI, XRAY, GOBY, and PUBLIC. The initial vulnerability information includes vulnerability ID, POC link, and vulnerability hazard description.

3. According to claim 1, the intelligent vulnerability feature recommendation method based on the Transformer model is characterized in that: The process of sorting and classifying the initial vulnerability information to obtain vulnerability numbers includes: The initial vulnerability information is sorted and classified into CVE and CNVD types, and the CVE and CNVD vulnerability numbers corresponding to the initial vulnerability information are obtained.

4. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 1 is characterized in that: The process of supplementing the initial vulnerability information corresponding to the vulnerability number based on the automated dynamic crawler includes: Based on the automated dynamic crawler, the initial vulnerability information is supplemented in CVE and CNVD according to the vulnerability number to obtain complete vulnerability information, including the triggering conditions of the vulnerability, possible attack paths, and repair suggestions.

5. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 1 is characterized in that: The process of obtaining the retrieval knowledge base by performing a semantic relevance coarse search on the local vulnerability knowledge base and the version information of the target service system based on the BM25 algorithm includes: Scoring and sorting are performed based on the correlation between the keywords of the version information and the vulnerability information corresponding to the vulnerability number in the local vulnerability knowledge base, and the vulnerability information is selected based on a sorting threshold, wherein the correlation includes word frequency, inverse document frequency and document length.

6. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 1 is characterized in that: The process of vectorizing the version information of the retrieval knowledge base and the target service system based on the Transformer model includes: Based on the Transformer model, the vulnerability information and the version information corresponding to the vulnerability number in the retrieval knowledge base are pre-trained and fine-tuned, and the vulnerability information and the version information are converted into multiple numerical vectors of fixed length, and the numerical vectors include a vector to be retrieved and a query vector.

7. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 6 is characterized in that: The process of pre-training and fine-tuning includes: Randomly mask the words of the vulnerability information and the version information based on the masking language model, and predict the words based on the Transformer model; and predict whether the two sentences are natural continuations based on the Transformer model.

8. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 6 is characterized in that: Convert the vulnerability information and the version information into multiple fixed-length numerical vectors, including: Based on the Transformer model, the vulnerability information and the version information are segmented to obtain an initial word vector; The multi-layer Transformer architecture based on the Transformer model encodes the word vectors and converts them into numerical vectors that can be compared in the vector space.

9. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 6 is characterized in that: The process of performing vector similarity precise retrieval on the vectorized data based on the FAISS algorithm to obtain the optimal vulnerability features includes: The cosine similarity or inner product similarity between the query vector and the vector to be searched is calculated based on the FAISS algorithm, a search vector with the highest similarity to the query vector is obtained, and the vulnerability number corresponding to the search vector is used as the optimal vulnerability feature.

10. The intelligent vulnerability feature recommendation method based on the Transformer model according to claim 9 is characterized in that: The process of obtaining the search vector most similar to the query vector includes: The cosine similarity between the query vector and the vector to be searched in the direction ranges from -1 to 1, and the vector to be searched whose cosine similarity is closest to 1 is obtained.

Citation Information

Patent Citations

  • Method for perfecting security rule base based on crawler technology

    CN114238991A

  • Vulnerability verification method, device and equipment and computer readable storage medium

    CN118965375A

  • Vulnerability information recommendation method based on knowledge graph

    CN119168032A

  • Intelligent retrieval method and system for unstructured asset content based on large model

    CN119646243A

  • Dynamic component safety management method and system based on DevOps

    CN119646812A