Vulnerability protection method and device, electronic equipment, program product and storage medium

By implanting security antibodies in network devices, using target vulnerabilities to obtain system permissions, and actively defending against vulnerabilities, it solves the problem that ordinary users cannot fix network security vulnerabilities, and achieves fast and low false alarm rate vulnerability repair, improving system security.

CN120263435APending Publication Date: 2025-07-04TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410016397.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-03
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the repair of network security vulnerabilities requires manual participation, and ordinary users lack technical capabilities, resulting in reduced system security.

Method used

By obtaining the asset list information of the device to be protected, using the target vulnerabilities to obtain system permissions, and implanting pre-built security antibodies into the device to actively defend against vulnerability exploits, including agents, application runtime patches, traffic intermediate layers and vulnerability patches, etc., to achieve vulnerability protection without human participation.

Benefits of technology

It realizes fast and low false alarm rate vulnerability repair, improves system security, solves the problem that ordinary users cannot fix network security vulnerabilities, and reduces response time and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263435A_ABST
    Figure CN120263435A_ABST
Patent Text Reader

Abstract

The invention provides a vulnerability protection method and device, electronic equipment, a program product and a storage medium, which are at least applied to the field of artificial intelligence, and the method comprises the following steps: obtaining asset list information of to-be-protected equipment; in response to a received input operation for vulnerability information of the target vulnerability, determining a target asset based on the vulnerability information and the asset list information; the target assets are assets influenced by the target vulnerability in the to-be-protected equipment; acquiring a system permission of a target system of the to-be-protected equipment by utilizing the target vulnerability; implanting a pre-constructed security antibody in the to-be-protected device based on the system permission, and performing vulnerability protection on the target asset by using the security antibody; the secure antibody includes an antibody file for proactively defending the target vulnerability from being utilized. According to the method and the device, vulnerabilities can be protected without user operation, so that the system security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technologies, and in particular, to a vulnerability protection method, apparatus, electronic device, program product, and storage medium. Background Art

[0002] With the development of network technologies, various network security vulnerabilities may exist on network assets. Network security vulnerabilities can enable attackers to access or damage network assets without authorization, thereby resulting in various network attack behaviors.

[0003] In related technologies, the process of vulnerability management mainly includes first obtaining vulnerability intelligence, scanning for vulnerabilities based on the vulnerability intelligence, and performing vulnerability repair processing according to the scanning results. Common vulnerability repair solutions include: timely updating and upgrading software: keeping the latest versions of operating systems, application programs, and other software, strengthening authentication and access control: implementing multi-factor authentication to ensure that only authorized users can access the system, encryption and data protection: using encryption technologies to protect the transmission and storage of sensitive data, ensuring the use of strong passwords and secure encryption algorithms, and regularly changing keys, etc.

[0004] However, the above-mentioned related technical solutions all require manual participation to achieve vulnerability repair. Therefore, for ordinary users without technical capabilities, they cannot use the above professional solutions to repair network security vulnerabilities, resulting in a reduction in the system security of network assets. Summary of the Invention

[0005] Embodiments of the present application provide a vulnerability protection method, apparatus, electronic device, program product, and storage medium, which can be at least applied in the field of artificial intelligence, and can actively protect against vulnerabilities without the need for user participation, thereby improving system security.

[0006] The technical solution of the embodiments of the present application is implemented as follows:

[0007] Embodiments of the present application provide a vulnerability protection method, and the method includes:

[0008] Obtaining asset list information of a device to be protected; in response to receiving an input operation of vulnerability information for a target vulnerability, determining a target asset based on the vulnerability information and the asset list information; the target asset is an asset in the device to be protected that is affected by the target vulnerability; obtaining system permissions of a target system of the device to be protected by using the target vulnerability; implanting a pre-constructed security antibody in the device to be protected based on the system permissions, and using the security antibody to perform vulnerability protection on the target asset; the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

[0009] An embodiment of the present application provides a vulnerability protection device, including: an asset acquisition module for acquiring asset list information of a device to be protected; a target asset determination module for, in response to receiving an input operation of vulnerability information for a target vulnerability, determining a target asset based on the vulnerability information and the asset list information; the target asset being an asset in the device to be protected that is affected by the target vulnerability; a permission acquisition module for using the target vulnerability to acquire system permissions of a target system of the device to be protected; a vulnerability protection module for implanting a pre-constructed security antibody in the device to be protected based on the system permissions, and using the security antibody to protect the target asset against vulnerabilities; the security antibody including an antibody file for actively defending against the exploitation of the target vulnerability.

[0010] In some embodiments, the asset acquisition module is further configured to acquire asset information of the device to be protected; perform fingerprint recognition on the asset information to obtain fingerprint information corresponding to the asset information; store the asset information and the fingerprint information corresponding to the asset information in a database, where the asset information and the fingerprint information of the device to be protected stored in the database constitute the asset list information.

[0011] In some embodiments, the target asset determination module is further configured to acquire application scope information of the target vulnerability carried in the vulnerability information; based on the application scope information, screen out candidate fingerprint information from the asset list information, and determine the asset information corresponding to the candidate fingerprint information as candidate assets; use a pre-constructed vulnerability detection script to detect whether the target vulnerability affects the candidate assets to obtain a detection result of the candidate assets; based on the detection result, screen out the target assets from the candidate assets.

[0012] In some embodiments, the security antibody includes an agent, and the vulnerability protection module is further configured to collect system information of the target system under the system permissions; based on the system information, implant a pre-constructed agent on the target system; load host-side protection rules through the agent; scan for code to be cleared existing in the target system according to the host-side protection rules, and clear the code to be cleared; the code to be cleared being software installed and run on the device to be protected without permission; or, in response to an operation of performing an unauthorized behavior by exploiting the target vulnerability, intercept the operation based on the host-side protection rules.

[0013] In some embodiments, the security antibody includes an application runtime patch. The vulnerability protection module is further configured to collect system information of the target system under the system permissions; based on the system information, implant a pre-built application runtime patch on the target asset; load application layer protection rules based on the application runtime patch; scan for code to be cleared existing in the target system according to the application layer protection rules, and clear the code to be cleared; the code to be cleared is software installed and running on the device to be protected without permission; or, in response to an unauthorized operation against the target vulnerability, intercept the unauthorized operation based on the application layer protection rules.

[0014] In some embodiments, the security antibody includes a traffic intermediate layer. The vulnerability protection module is further configured to collect system information of the target system under the system permissions; based on the system information, add a pre-built traffic intermediate layer to the device to be protected; the traffic intermediate layer includes one of a kernel layer, a network interface layer, a user layer, and an application layer; load traffic layer protection rules through the traffic intermediate layer; in response to an exploit operation against the target vulnerability, intercept the exploit operation based on the traffic layer protection rules.

[0015] In some embodiments, the security antibody includes a vulnerability patch. The vulnerability protection module is further configured to collect system information of the target system under the system permissions; based on the system information, obtain the vulnerability patch corresponding to the target asset; after backing up the source code and configuration information of the target asset, implant the vulnerability patch on the target asset; in response to the vulnerability patch being run and the target asset being restarted, verify the installation status of the vulnerability patch; in the case where the vulnerability patch is successfully installed, intercept the exploit operation against the target vulnerability based on the vulnerability patch.

[0016] In some embodiments, the vulnerability protection device further includes a prohibition module, configured to prohibit protecting the target vulnerability in the case where candidate fingerprint information cannot be filtered out from the asset list information based on the application scope information.

[0017] In some embodiments, the vulnerability protection device further includes a report generation module, configured to generate a vulnerability protection report after protecting the target asset against vulnerabilities; the vulnerability protection report includes at least one of the following: version information of the target system, vulnerability information of the target vulnerability, implantation result of the security antibody, protection result of the target vulnerability, and intercepted insecure operations.

[0018] In some embodiments, the vulnerability protection device further includes a status feedback module, configured to, after establishing a connection with a specified server through the security antibody, regularly send the status information of the security antibody to the server through the security antibody; or return a verification response to a protection verification request through the security antibody, where the verification response includes the status information of the security antibody; and the protection verification request is sent by a specified server to the security antibody.

[0019] An embodiment of the present application provides an electronic device, which includes:

[0020] A memory, configured to store computer-executable instructions;

[0021] A processor, configured to implement the vulnerability protection method provided by the embodiment of the present application when executing the computer-executable instructions stored in the memory.

[0022] An embodiment of the present application provides a computer-readable storage medium, storing a computer program or computer-executable instructions, which are configured to implement the vulnerability protection method provided by the embodiment of the present application when being executed by a processor.

[0023] An embodiment of the present application provides a computer program product, including a computer program or computer-executable instructions, which are configured to implement the vulnerability protection method provided by the embodiment of the present application when being executed by a processor.

[0024] The embodiment of the present application has the following beneficial effects:

[0025] When performing vulnerability protection on a device to be protected, it is possible to first determine the target assets in the device to be protected that may be affected by the target vulnerability, obtain the system permissions of the target system of the device to be protected by using the target vulnerability, and then implant a security antibody in the device to be protected based on the system permissions, so as to implement vulnerability protection for the target assets. Among them, when determining the target assets, it is possible to first obtain the asset list information of the device to be protected, receive the vulnerability information for the target vulnerability, and determine the target assets that may be affected by the target vulnerability from the asset list information based on the vulnerability information. In the embodiment of the present application, when there are target assets that may be affected by the target vulnerability, the system permissions are obtained by using the target vulnerability, and a security antibody is implanted to quickly strengthen the target assets so that the target assets are immune to attacks, thereby significantly improving the security of the device to be protected and solving the network security hidden dangers brought by the vulnerabilities. Therefore, when ordinary users do not have the technical ability to repair network security vulnerabilities, they can use the vulnerability protection method provided by the embodiment of the present application to repair the vulnerabilities without the participation of ordinary users. By introducing a security antibody to repair the vulnerabilities, the false alarm rate is low and the response is rapid. Description of the Drawings

[0026] Figure 1It is a schematic structural diagram of the vulnerability protection system architecture provided by an embodiment of the present application;

[0027] Figure 2 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;

[0028] Figure 3 It is a schematic flow diagram of the vulnerability protection method provided by an embodiment of the present application;

[0029] Figure 4 It is a schematic flow diagram of the vulnerability protection method provided by an embodiment of the present application;

[0030] Figure 5 It is a schematic architecture diagram of the vulnerability protection system provided by an embodiment of the present application;

[0031] Figure 6 It is a schematic flow diagram of the vulnerability detection module provided by an embodiment of the present application;

[0032] Figure 7 It is a schematic flow diagram of the vulnerability repair module provided by an embodiment of the present application;

[0033] Figure 8 It is a schematic flow diagram of the vulnerability protection method provided by an embodiment of the present application;

[0034] Figure 9 It is a schematic flow diagram of the host - side vulnerability repair method provided by an embodiment of the present application;

[0035] Figure 10 It is a schematic flow diagram of the application - side vulnerability repair method provided by an embodiment of the present application;

[0036] Figure 11 It is a schematic flow diagram of the traffic - side vulnerability repair method provided by an embodiment of the present application;

[0037] Figure 12 It is a schematic flow diagram of the vulnerability repair method based on vulnerability patches provided by an embodiment of the present application;

[0038] Figure 13 It is a schematic flow diagram of the continuous verification module provided by an embodiment of the present application;

[0039] Figure 14 It is a schematic diagram of the interaction process during the vulnerability protection process provided by an embodiment of the present application. Detailed implementation manners

[0040] In order to make the purpose, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0041] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0042] Unless otherwise defined, all technical and scientific terms used in the embodiments of the present application have the same meaning as commonly understood by those skilled in the art to which the present application belongs. The terms used in the embodiments of the present application are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0043] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are described, and the nouns and terms involved in the embodiments of the present application are applicable to the following explanations.

[0044] (1) Responsive to, used to indicate the conditions or states on which the executed operations depend. When the dependent conditions or states are met, one or more executed operations may be real-time or may have a set delay; without special indication, there is no limitation on the execution order of multiple executed operations.

[0045] (2) Asset, also known as network asset, refers to various devices used in a computer (or communication) network, mainly including hosts, network devices (routers, switches, etc.) and security devices (firewalls, etc.).

[0046] (3) Vulnerability, which is a defect existing in the specific implementation of hardware, software, protocol or system security policy. It may come from defects in the design of application software or operating systems or errors generated during coding, or may also come from design defects or unreasonable aspects in the logical process during business interaction processing. Vulnerabilities may be exploited intentionally or unintentionally, causing the system to be accessed or damaged without the authorization of the system administrator, thereby having an adverse impact on the assets or operations of an organization, such as the information system being attacked or controlled, important data being stolen, user data being tampered with, and the system being used as a springboard to invade other host systems.

[0047] (4) Security antibody, which is used to obtain system privileges by exploiting existing system vulnerabilities, and then use these system privileges to defend against the exploitation of the same type of vulnerabilities, and can also remove malicious software such as implanted Trojans. Specifically, the security antibody can be understood as an active defense mechanism. First, the security antibody scans and identifies the existing vulnerabilities in the system, and then uses these vulnerabilities to obtain system privileges. This step is similar to the virus infection process, but the purpose is to protect the system rather than damage it. After obtaining the system privileges, the security antibody uses the system privileges to defend against the exploitation of the same type of vulnerabilities, including fixing these vulnerabilities, or using these vulnerabilities in advance before they are exploited, so that other objects cannot use the vulnerabilities anymore. This step is similar to the antibody defense mechanism in the biological body, which identifies and defends against viruses or pathogens that have been encountered. In addition, the security antibody can also include a cleaning function, which can detect and remove the Trojans or other malicious software that have been implanted in the system, so that the security antibody can not only defend against future threats, but also handle existing security problems. Therefore, the security antibody is an active defense mechanism based on existing vulnerabilities, whose goal is to prevent the same type of vulnerabilities from being exploited again and remove the implanted malicious software, thereby improving the security of the system.

[0048] (5) Runtime application patch is a network security technology, which refers to dynamically applying security patches when the application is running without stopping or restarting the application. The runtime application patch can provide real-time and seamless security protection to reduce the potential risks and vulnerabilities of the system. Similar to Runtime Application Self-Protection (RASP), the runtime application patch is also carried out when the application is running, but it can not only detect and prevent attacks in real time, but also remove the implanted malicious software such as Trojans. Even if the application has been infected by malicious software, the runtime application patch can remove these malicious software without affecting the normal operation of the application.

[0049] (6) Asset fingerprint is used to represent the "ID card" of network assets. Each asset has its corresponding fingerprint information, and the fingerprint information of each asset is different. For example, for software, the fingerprint information of the software can include information such as the server information corresponding to the software, the installation path information, and the software version number.

[0050] (7) Vulnerability exploitation is a computer security term, which refers to using certain vulnerabilities in a program to gain control of the computer.

[0051] (8) An agent refers to a computing entity that resides in a certain environment, can continuously and autonomously play its role, and has characteristics such as residency, reactivity, sociality, and initiative. In the network security application environment, an agent can be regarded as an executable security antibody file on the operating system.

[0052] In related technologies, the common vulnerability repair solutions are as follows: timely update and upgrade software: keep the operating system, applications, and other software up-to-date to ensure that known vulnerabilities have been fixed, regularly check and apply security patches and updates provided by the vendor; use security devices: use network security devices such as firewalls, Intrusion Detection Systems (IDS), and Intrusion-prevention systems (IPS) to detect and prevent potential attacks, and configure network devices to restrict access to sensitive data and systems; strengthen authentication and access control: implement multi-factor authentication (such as using passwords and tokens) to ensure that only authorized users can access the system, and use Access Control Lists (ACL) and privilege management to restrict users' access to sensitive data and functions; security coding practices: developers should follow security coding guidelines, such as input validation, output encoding, error handling, and security configuration, and discover and fix potential vulnerabilities through code review and security testing; encryption and data protection: use encryption technology to protect the transmission and storage of sensitive data, ensure the use of strong passwords and secure encryption algorithms, and regularly change keys; regular vulnerability scanning and penetration testing: use vulnerability scanning tools and penetration testing to discover vulnerabilities in the system, conduct these tests regularly, and promptly fix the discovered vulnerabilities. These solutions can solve the threats brought by network vulnerabilities to a certain extent, but they cannot be used by ordinary users without technical capabilities, and they also lack the ability to handle security emergency events to a certain extent. When ordinary users do not have the technical ability to repair network security vulnerabilities, they may use the following solutions: hire a professional team, outsource security services, use security software, seek vendor support, etc., but these solutions all require full manual participation and are costly.

[0053] Based on the problems existing in the related art, an embodiment of the present application provides a vulnerability protection method. This vulnerability protection method is a method for protecting public services with vulnerabilities based on a vulnerability repair solution implanted with security antibodies in a scenario where a device needs to repair security vulnerabilities, but the application management party does not have the ability to independently repair vulnerabilities or there is no repair patch. After obtaining service permissions by exploiting vulnerabilities, this method implants security antibodies into the device in different ways to protect against subsequent malicious vulnerability exploitation, and solves the network security risks brought by vulnerabilities. Compared with the vulnerability repair methods in the above-mentioned related art, the vulnerability protection method provided by the embodiment of the present application repairs vulnerabilities in an active manner, without the need for user participation, and repairs vulnerabilities by introducing security antibodies, with a low false alarm rate and rapid response.

[0054] Here, an exemplary application of the vulnerability protection device provided by the embodiment of the present application will be described first. This vulnerability protection device is an electronic device for implementing the vulnerability protection method. In one implementation, the vulnerability protection device (i.e., the electronic device) provided by the embodiment of the present application can be implemented as a terminal or a server. In one implementation, the vulnerability protection device provided by the embodiment of the present application can be implemented as various types of user terminals such as a laptop computer, a tablet computer, a desktop computer, a set-top box, a mobile device (e.g., a mobile phone, a portable music player, a personal digital assistant, a dedicated messaging device, a portable gaming device), a smart phone, a smart speaker, a smart watch, a smart TV, a vehicle-mounted terminal, etc.; in another implementation, the vulnerability protection device provided by the embodiment of the present application can also be implemented as a server. Among them, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs, Content Delivery Network), and big data and artificial intelligence platforms. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, which are not limited in the embodiment of the present application. Next, an exemplary application when the vulnerability protection device is implemented as a server will be described.

[0055] See Figure 1 , Figure 1 is an optional architecture diagram of the vulnerability protection system 100 provided by the embodiment of the present application. To implement vulnerability protection for the device to be protected, a vulnerability protection application can be provided. For example, this vulnerability protection application can be an application dedicated to vulnerability protection or a functional module in other applications.

[0056] In the vulnerability protection system 100 provided by the embodiments of the present application, at least a terminal 400, a network 300, and a server 200 are included. The vulnerability protection application runs on the terminal 400. Among them, in one implementation, the terminal 400 can be the same device as the device to be protected. In another implementation, the terminal 400 and the device to be protected can be two different devices. The server 200 is the server of the vulnerability protection application. The server 200 can constitute the vulnerability protection device of the embodiments of the present application, that is, the vulnerability protection method of the embodiments of the present application is implemented through the server 200. The terminal 400 is connected to the server 200 through the network 300. The network 300 can be a wide area network, a local area network, or a combination of the two. Refer to Figure 1 , the terminal 400 and the device to be protected 500 are two different devices. When protecting the device to be protected 500 from vulnerabilities, an operator can perform interactive operations through the terminal 400 on the client of the vulnerability protection application. The interactive operation can be a click start operation, an information input operation, etc. After receiving the interactive operation of the operator, the client can send a vulnerability protection request to the server 200 through the terminal 400. When receiving the vulnerability protection request, the server 200, in response to the vulnerability protection request, obtains the asset list information of the device to be protected 500; then, the server 200, in response to receiving an input operation of vulnerability information for a target vulnerability, determines a target asset based on the vulnerability information and the asset list information; where the target asset is the asset in the device to be protected 500 affected by the target vulnerability; obtains the system privilege of the target system of the device to be protected 500 by using the target vulnerability; implants a pre-constructed security antibody in the device to be protected 500 based on the system privilege, and uses the security antibody to protect the target asset from vulnerabilities; where the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability. After implanting the security antibody, the server 200 can receive the status information of the security antibody and generate a vulnerability protection report, and send the status information of the security antibody and the vulnerability protection report to the terminal 400.

[0057] In some embodiments, the vulnerability protection method of the embodiments of the present application can also be executed by the terminal 400 itself. That is to say, when the terminal 400 receives an interactive operation input by an operator through the client, the terminal 400 obtains the asset list information of the device to be protected 500; then, the terminal 400, in response to receiving an input operation of vulnerability information for a target vulnerability, determines a target asset based on the vulnerability information and the asset list information; obtains the system privilege of the target system of the device to be protected 500 by using the target vulnerability; implants a pre-constructed security antibody in the device to be protected 500 based on the system privilege, and uses the security antibody to protect the target asset from vulnerabilities. After implanting the security antibody, the terminal 400 can receive the status information of the security antibody and generate a vulnerability protection report.

[0058] The vulnerability protection method provided by the embodiments of the present application can also be implemented based on a cloud platform and through cloud technology. For example, the above-mentioned server 200 can be a cloud server. The asset list information of the device to be protected 500 is obtained through the cloud server, or the cloud server determines the target asset based on the vulnerability information and the asset list information in response to receiving an input operation of vulnerability information for a target vulnerability, or the cloud server obtains the system permission of the target system of the device to be protected 500 by using the target vulnerability, or the cloud server implants a pre-built security antibody into the device to be protected 500 based on the system permission, and uses the security antibody to protect the target asset from vulnerabilities, etc.

[0059] In some embodiments, there may also be a cloud storage, and the obtained asset list information, vulnerability information of the target vulnerability, etc. can be stored in the cloud storage, and the pre-built security antibody can also be stored in the cloud storage. In this way, when a vulnerability protection request is received, the target asset can be directly determined from the cloud storage based on the vulnerability information and the asset list information, and the pre-built security antibody can be implanted into the device to be protected based on the system permission, thereby improving the speed of vulnerability protection and the system security.

[0060] It should be noted here that cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or a local area network to achieve data computing, storage, processing, and sharing. Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model, and can form a resource pool, which can be used on demand and is flexible and convenient. Cloud computing technology will become an important support. The background services of technical network systems require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. With the high development and application of the Internet industry, in the future, each item may have its own identification mark and needs to be transmitted to the background system for logical processing. Data at different levels will be processed separately, and various industry data requires a powerful system backup support, which can be achieved through cloud computing.

[0061] See Figure 2 , Figure 2 is a schematic structural diagram of an electronic device provided by the embodiments of the present application. Figure 2The electronic device shown may be a vulnerability protection device, and the vulnerability protection device includes: at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. Each component in the vulnerability protection device is coupled together through a bus system 440. It can be understood that the bus system 440 is used to realize the connection and communication between these components. In addition to including a data bus, the bus system 440 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 2 all kinds of buses are labeled as the bus system 440.

[0062] The processor 410 may be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or any conventional processor, etc.

[0063] The user interface 430 includes one or more output devices 431 that enable the presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432, including user interface components that facilitate user input, such as a keyboard, a mouse, a microphone, a touch screen display, a camera, other input buttons, and controls.

[0064] The memory 450 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memories, hard disk drives, optical disk drives, etc. The memory 450 optionally includes one or more storage devices that are physically located away from the processor 410.

[0065] The memory 450 includes volatile memory or non-volatile memory, and may also include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The memory 450 described in the embodiments of the present application is intended to include any suitable type of memory.

[0066] In some embodiments, the memory 450 is capable of storing data to support various operations. Examples of such data include programs, modules, and data structures, or subsets or supersets thereof, which are described below by way of example.

[0067] The operating system 451 includes system programs for processing various basic system services and performing hardware-related tasks, such as the framework layer, the core library layer, the driver layer, etc., for implementing various basic services and processing hardware-based tasks; the network communication module 452 is used to reach other electronic devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include: Bluetooth, Wi-Fi (Wireless Fidelity), and USB (Universal Serial Bus), etc.; the presentation module 453 is used to enable the presentation of information (such as a user interface for operating peripheral devices and displaying content and information) via one or more output devices 431 associated with the user interface 430 (such as a display screen, a speaker, etc.); the input processing module 454 is used to detect and translate one or more user inputs or interactions from one of one or more input devices 432.

[0068] In some embodiments, the device provided by the embodiments of the present application can be implemented in software. Figure 2 The vulnerability protection device 455 stored in the memory 450 is shown, which can be software in the form of a program and a plug-in, etc., and includes the following software modules: the asset acquisition module 4551, the target asset determination module 4552, the permission acquisition module 4553, and the vulnerability protection module 4554. These modules are logical, so they can be combined arbitrarily or further split according to the functions implemented. The functions of each module will be described below.

[0069] In other embodiments, the device provided by the embodiments of the present application can be implemented in hardware. As an example, the device provided by the embodiments of the present application can be a processor in the form of a hardware decoding processor, which is programmed to execute the vulnerability protection method provided by the embodiments of the present application. For example, a processor in the form of a hardware decoding processor can adopt one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.

[0070] The vulnerability protection methods provided by the embodiments of the present application can be executed by an electronic device. Among them, the electronic device can be a server or a terminal, that is, the vulnerability protection methods of the embodiments of the present application can be executed by a server, can be executed by a terminal, or can also be executed through the interaction between the server and the terminal.

[0071] Figure 3 is an optional process schematic diagram of the vulnerability protection method provided by the embodiments of the present application. The following will be described in combination with Figure 3 the steps shown. As Figure 3 shown, taking the execution entity of the vulnerability protection method as a server as an example for description, the method includes the following steps S101 to step S104:

[0072] Step S101, obtain the asset list information of the device to be protected.

[0073] Here, the device to be protected is a type of network asset, which may be multiple or one server device, a virtual machine, a group of specific application programs, etc. Exemplarily, the device to be protected is a computer device. The device to be protected may include multiple pieces of asset information, and the asset information is information about various services and applications in the device to be protected. The asset list information includes each piece of asset information in the device to be protected and the fingerprint information corresponding to the asset information. The asset list information of the device to be protected can be obtained by performing fingerprint recognition on the asset information.

[0074] Step S102, in response to receiving an input operation of vulnerability information for a target vulnerability, determine the target asset based on the vulnerability information and the asset list information.

[0075] Among them, the target asset is the asset in the device to be protected that is affected by the target vulnerability.

[0076] In the embodiments of the present application, the target vulnerability is a security network vulnerability such as a system vulnerability, an application vulnerability, or a service vulnerability existing in the device to be protected. The vulnerability information of the target vulnerability may include the application scope information affected by the target vulnerability, where the application scope information may include the application name, application version information, etc. The number of target vulnerabilities can be one or multiple.

[0077] Exemplarily, if target vulnerability a is a vulnerability existing in the 1.2 version of the virtual private network (VPN) application of Company A, then the operator can input the vulnerability information of target vulnerability a through the terminal: application scope information such as the virtual private network application of Company A, version 1.2, etc.

[0078] In an embodiment of the present application, in response to receiving an input operation for vulnerability information of a target vulnerability, application scope information affected by the target vulnerability carried in the vulnerability information can be obtained, and at least one target asset can be filtered out from the asset list information based on the application scope information.

[0079] Step S103, use the target vulnerability to obtain system permissions for the target system of the device to be protected.

[0080] In an embodiment of the present application, based on the target vulnerability, system permissions for the target system of the device to be protected can be obtained through vulnerability exploitation. Among them, the target system can be a narrow sense of the operating system or a broad sense of other systems, such as a Web application system. Exemplarily, taking the target system as a narrow sense of the operating system as an example, the target system can be one of Windows operating system, Linux operating system, and Mac operating system. Taking the target system as a broad sense of the Web application system as an example, the target system can include an Office Automation System (OA system), a Customer Relationship Management (CRM) system, etc. The embodiment of the present application does not limit the way of vulnerability exploitation, and different types of target vulnerabilities correspond to different ways of vulnerability exploitation. The types of target vulnerabilities can include buffer overflow, code injection, command injection, etc.

[0081] It should be noted that before exploiting the target vulnerability in the embodiment of the present application, the authorization of the owner user of the device to be protected has been obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions.

[0082] Step S104, implant a pre-constructed security antibody in the device to be protected based on the system permissions, and use the security antibody to protect the target asset from vulnerabilities.

[0083] The security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

[0084] In an embodiment of the present application, the security antibody can be pre-constructed and stored in the database, and different types of target systems can respectively correspond to different security antibodies. After obtaining the system permissions, the system information of the target system can be obtained first using the system permissions, and based on the system information and the vulnerability repair policy, the security antibody corresponding to the vulnerability repair policy and adapted to the target system can be retrieved from the database. The vulnerability repair policy can include, but is not limited to, repair policies such as the host side, application layer, traffic side, and patch repair.

[0085] After implanting a pre-built security antibody into the device to be protected, the security antibody can, with the authorization of the owner user of the device to be protected, load protection rules and perform vulnerability protection based on the protection rules. Vulnerability protection may include steps such as scanning for malicious code in the target system and removing the malicious code, or may also include steps such as intercepting malicious attacks or malicious behaviors from external devices in advance.

[0086] For the vulnerability protection method provided by the embodiments of the present application, when performing vulnerability protection on a device to be protected, it is possible to first determine the target assets in the device to be protected that may be affected by the target vulnerability, obtain the system permissions of the target system of the device to be protected using the target vulnerability, and thus implant a security antibody in the device to be protected based on the system permissions to achieve vulnerability protection for the target assets. Among them, when determining the target assets, it is possible to first obtain the asset list information of the device to be protected, receive the vulnerability information for the target vulnerability, and determine the target assets that may be affected by the target vulnerability from the asset list information based on the vulnerability information. In the embodiments of the present application, when there are target assets that may be affected by the target vulnerability, the system permissions are obtained using the target vulnerability, a security antibody is implanted, and the target assets are quickly fortified to protect them from attacks, thereby significantly improving the security of the device to be protected and solving the network security risks brought by the vulnerabilities. Therefore, when ordinary users do not have the technical ability to repair network security vulnerabilities, they can use the vulnerability protection method provided by the embodiments of the present application to actively patch the vulnerabilities without the participation of ordinary users. By introducing a security antibody to patch the vulnerabilities, the false alarm rate is low and the response is rapid.

[0087] In some embodiments, the vulnerability protection system at least includes a terminal and a server, where a vulnerability protection application runs on the terminal.

[0088] Figure 4 is another optional process schematic diagram of the vulnerability protection method provided by the embodiments of the present application. As Figure 4 shown, the method includes the following steps S201 to step S214:

[0089] Step S201, the terminal receives an interaction operation from an operator.

[0090] Here, the interaction operation may be a click start operation, an information input operation, etc. The operator can perform any kind of interaction operation on the client of the vulnerability protection application through the terminal.

[0091] Step S202, the terminal generates a vulnerability protection request in response to the interaction operation.

[0092] When the terminal receives an interactive operation from an operator, it determines that vulnerability protection needs to be performed on the device to be protected at present. Therefore, in response to the interactive operation, a vulnerability protection request is generated. The vulnerability protection request is used to request the server to implant a pre-built security antibody into the device to be protected when there are target assets in the device to be protected that may be affected by vulnerabilities, and use the security antibody to perform vulnerability protection on the target assets.

[0093] Here, the device to be protected is a type of network asset, which may be multiple or one server device, a virtual machine, a group of specific application programs, etc. The device to be protected may include multiple assets, such as services, applications, etc.

[0094] Step S203, the terminal sends the vulnerability protection request to the server.

[0095] Step S204, the server, in response to the vulnerability protection request, obtains the asset list information of the device to be protected.

[0096] Here, the asset list information includes multiple pieces of asset information and the fingerprint information corresponding to each piece of asset information. Multiple pieces of asset information of the device to be protected can be collected first, and fingerprint recognition is performed on the collected asset information to obtain the fingerprint information corresponding to each piece of asset information, thus forming the asset list information.

[0097] In some embodiments, obtaining the asset list information of the device to be protected in step S204 can be implemented in the following manner: First, obtain the asset information of the device to be protected. Then, perform fingerprint recognition on the asset information to obtain the fingerprint information corresponding to the asset information. Finally, store the asset information and the fingerprint information corresponding to the asset information in a database. Among them, the asset information and fingerprint information of the device to be protected stored in the database constitute the asset list information.

[0098] Here, the asset information of the device to be protected is the information of various services, software, and applications in the device to be protected. The asset information can be collected according to at least one of several methods such as actively collecting assets, passively collecting assets, and customer input of assets according to user configuration. Actively collecting assets is to obtain asset information through methods such as domain name collection, port scanning, and network (Web) scanning. Domain name collection can obtain the website information of software, port operation can obtain the information of each port, and Web scanning can obtain the version information corresponding to the software. Passively collecting assets is to obtain asset information by querying existing asset lists. Customer input of assets means that the user of the device to be protected specifies the asset information to be concerned about. Among them, the user is the owner of the device to be protected, and the user configuration is the collection method set by the user himself. For example, the user configuration can be: User B is not allowed to use the active method to collect assets. At this time, based on the user configuration, the methods of passively collecting assets and customer input of assets can be used to collect the asset information of the device to be protected by User B.

[0099] In the embodiments of the present application, for each piece of asset information, fingerprint recognition can be performed on the asset information to obtain the fingerprint information corresponding to the asset information. The fingerprint information may include application type, application name, application manufacturer, application version information, etc. The methods for fingerprint recognition of asset information include but are not limited to the following: recognition based on the Hypertext Transfer Protocol (HTTP) response header; recognition based on the HTTP response body; recognition based on the Uniform Resource Locator (URL) path and parameters; recognition based on error pages; recognition based on resource files; recognition based on third-party components.

[0100] It should be noted that the asset fingerprint recognition method provided in the embodiments of the present application includes but is not limited to the above several, as long as the acquisition of fingerprint information can be satisfied.

[0101] Exemplarily, when the asset information is an application program, its manifestation form can be a website: www.xxx.vpn.com, and the fingerprint information obtained by performing fingerprint recognition on the asset information can be: vpn software, the manufacturer is xxx, the version information is 1.4.1, etc.

[0102] In the embodiments of the present application, after obtaining the fingerprint information corresponding to the asset information, each piece of asset information and the fingerprint information corresponding to each piece of asset information can be randomly arranged and stored in a database according to the corresponding relationship between the asset information and the fingerprint information to obtain asset list information.

[0103] In some embodiments, the vulnerability protection method provided in the embodiments of the present application can be applied to a vulnerability protection system. Figure 5 It is a schematic diagram of the architecture of the vulnerability protection system provided in the embodiments of the present application. As Figure 5As shown in the figure, the vulnerability protection system includes a vulnerability detection module, a vulnerability repair module, and a continuous verification module. The vulnerability detection module is used to collect and identify the asset information of the device to be protected, and detect whether the corresponding asset is affected by a network security vulnerability (target vulnerability). Specifically, it includes several functions such as asset collection, fingerprint recognition, and vulnerability detection. The vulnerability repair module is the core module of the vulnerability protection system, which is used to implant security antibodies into the device to be protected (such as a computer device) to complete vulnerability repair. Specifically, it includes several functions such as vulnerability exploitation, repair strategy selection, and repair strategy execution. After determining that the device to be protected is affected by a network security vulnerability, the vulnerability repair module first obtains the system permissions of the target system (such as Windows operating system, Web application system, etc.), then collects the system information of the target system, selects an appropriate antibody implantation strategy and completes the implantation of security antibodies, and finally achieves the effect of defending against vulnerability attacks through security antibodies. The continuous verification module is used to continuously verify the repair effect after repairing the vulnerability, output the repair status report to the user, and if the security antibody fails due to application restart or other means, re-implant the security antibody to refresh the antibody effect. The continuous verification module specifically includes several functions such as repair report, status detection, and vulnerability retesting.

[0104] Reference may be made together to Figure 6 , Figure 6 which is a schematic flow diagram of the vulnerability detection module provided by an embodiment of the present application. As Figure 6 shown, the vulnerability detection stage can be divided into the following steps: Step S301, the vulnerability detection module collects the asset information of the device to be protected according to user configuration. According to user configuration, at least one of several methods such as actively collecting assets, passively collecting assets, and customer input of assets can be used to collect multiple asset information of the device to be protected. Step S302, the vulnerability detection module performs fingerprint recognition on the collected asset information to obtain the fingerprint information corresponding to each asset information. The corresponding relationship between the asset and the fingerprint can be stored in a database to obtain an asset-fingerprint database (asset list information).

[0105] Step S205, the terminal receives an input operation of the operator for the vulnerability information of the target vulnerability.

[0106] Here, the vulnerability information of the target vulnerability may include the application name targeted by the target vulnerability, application version information, etc. Exemplarily, if the target vulnerability a is a vulnerability existing in the 1.2 version of the virtual private network (VPN) application of Company A, the operator can input the vulnerability information of the target vulnerability a through the terminal: information such as the virtual private network application of Company A, 1.2 version, etc.

[0107] Step S206, the terminal generates a vulnerability detection request in response to the input operation.

[0108] In the embodiments of the present application, the vulnerability detection request is used to request the server to detect whether there is asset information in the asset list information of the device to be protected that may be affected by the target vulnerability based on the vulnerability information of the target vulnerability. After the terminal receives the input operation of the operator for the vulnerability information of the target vulnerability, it can encapsulate the vulnerability information of the target vulnerability into the vulnerability detection request.

[0109] Step S207, the terminal sends the vulnerability detection request to the server.

[0110] Step S208, the server responds to the vulnerability detection request and determines the target asset based on the vulnerability information and the asset list information.

[0111] Here, the target asset is the asset in the device to be protected that is affected by the target vulnerability.

[0112] In the embodiments of the present application, in response to the vulnerability detection request, the server can obtain the application scope information affected by the target vulnerability carried in the vulnerability detection request. Based on the application scope information affected by the target vulnerability and the fingerprint information in the asset list information, the server filters out the fingerprint information existing in the application scope information as the candidate fingerprint information, and determines the asset information corresponding to the candidate fingerprint information as the candidate asset. Further, the server can detect whether the candidate asset will be affected by the target vulnerability, obtain the detection result, and filter out the target asset from the candidate assets based on the detection result.

[0113] In some embodiments, determining the target asset based on the vulnerability information and the asset list information in step S208 can be implemented in the following manner: First, obtain the application scope information of the target vulnerability carried in the vulnerability information. Then, based on the application scope information, filter out the candidate fingerprint information from the asset list information, and determine the asset information corresponding to the candidate fingerprint information as the candidate asset. Then, use the pre-constructed vulnerability detection script to detect whether the target vulnerability affects the candidate asset, and obtain the detection result of the candidate asset. Finally, based on the detection result, filter out the target asset from the candidate assets.

[0114] Here, the application scope information of the target vulnerability may include multiple application name information, application version information, etc. In the embodiments of the present application, the application scope information includes the application name information and application version information, etc. that may be affected by the target vulnerability. The fingerprint information in the asset list information also includes the application name information and application version information, etc. corresponding to the asset. The fingerprint information in the asset list information that is the same as both the application name information and the application version information in the application scope information can be filtered out as the candidate fingerprint information. The asset information corresponding to the candidate fingerprint information is determined as the candidate asset.

[0115] Exemplarily, the application scope information affected by the target vulnerability a includes vpn applications, version 1.2, version 1.3; communication applications, version 2.2, etc. Then, traverse the asset list information to query whether there is fingerprint information of "vpn application, version 1.2", fingerprint information of "vpn application, version 1.3", and fingerprint information of "communication application, version 2.2". If so, use the above fingerprint information as candidate fingerprint information.

[0116] It should be noted that the embodiments of the present application do not specifically limit the vulnerability detection script. The vulnerability detection script can be constructed in advance by the operator and input into the client of the terminal together with the vulnerability information. The vulnerability detection script can be used to detect whether the target vulnerability affects the candidate assets. For each candidate asset, using the vulnerability detection script, a detection request can be sent to the candidate asset, and the candidate asset returns a detection response in response to the detection request. Based on the detection response, the detection result of the candidate asset can be obtained. Exemplarily, if the detection response returned by the candidate asset is "1", a detection result indicating that the candidate asset is affected by the target vulnerability is obtained; or, if the detection response returned by the candidate asset is "0", a detection result indicating that the candidate asset is not affected by the target vulnerability is obtained.

[0117] In the embodiments of the present application, if the detection result of the candidate asset is used to indicate that the candidate asset is affected by the target vulnerability, then the candidate asset is determined as the target asset.

[0118] In the embodiments of the present application, candidate assets are first screened through vulnerability information, and then target assets are obtained from the candidate assets using the vulnerability detection script, which can narrow the scope of vulnerability protection, achieve precise protection, and have a low false alarm rate and rapid response.

[0119] In some embodiments, reference can also be made to Figure 6 When the vulnerability protection method provided by the embodiments of the present application is specifically applied to the vulnerability detection module, the steps are as follows: Step S303, the vulnerability detection module can extract candidate assets corresponding to the target vulnerability from the asset - fingerprint database. When vulnerability information is input, the vulnerability detection module can extract the corresponding information (candidate assets) that hits the assets from the asset - fingerprint database according to the application scope affected by the vulnerability in the vulnerability information. Step S304, the vulnerability detection module can detect whether the candidate assets are affected by the target vulnerability based on the vulnerability detection script, and obtain the detection results of the candidate assets. The vulnerability detection module can use the vulnerability detection script preset in the vulnerability protection system to detect whether the information - hit assets are affected by the vulnerability, so as to judge whether the vulnerability affects the device to be protected and obtain the detection results.

[0120] Step S209, if there is no target asset, the server sends a protection termination result to the terminal.

[0121] In the embodiment of the present application, when candidate fingerprint information cannot be filtered out from the asset list information based on the application scope information, the protection of the target vulnerability is prohibited. That is, at this time, the device to be protected has no network security vulnerability risk and does not require vulnerability protection. The server can send a protection termination result to the terminal. The operator can restart the vulnerability protection process by inputting other vulnerability information through the terminal again.

[0122] Step S210, if there is a target asset, the server uses the target vulnerability to obtain the system privilege of the target system of the device to be protected.

[0123] In the embodiment of the present application, based on the target vulnerability, the system privilege of the target system of the device to be protected can be obtained through vulnerability exploitation. The target system may include the operating system, web application system, etc. of the device to be protected.

[0124] Step S211, the server implants a pre-built security antibody in the device to be protected based on the system privilege, and uses the security antibody to protect the target asset against vulnerabilities.

[0125] In the embodiment of the present application, the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

[0126] In some embodiments, reference may be made together to Figure 7 , Figure 7 which is a schematic flow diagram of the vulnerability repair module provided by the embodiment of the present application. As Figure 7As shown, after the detection result indicates that the device to be protected will be affected by vulnerabilities, the device to be protected needs to repair the vulnerabilities. The vulnerability repair stage can be divided into the following steps: Step S401, the vulnerability repair module can obtain the system privilege of the target system through vulnerability exploitation based on the vulnerabilities existing in the device to be protected. The method of obtaining the system privilege of the target system through vulnerability exploitation is determined based on the vulnerability type, which is not limited in this embodiment of the present application. The vulnerability type can include types such as buffer overflow, code injection, and command injection. Step S402, the vulnerability repair module can collect the system information of the system by using the system privilege. The repair strategy can be selected according to user configuration, security evaluation of different policies, stability evaluation, etc. The policy selection is mainly based on user configuration, and the judgment method of the default selection policy is as follows: for the case with more system security problems, the host-side solution is mainly used for repair; for the case where security problems are more concentrated and the requirement for invasiveness is small, the application-side solution is mainly used for repair; for the case with extremely high stability requirements, the traffic-side solution is mainly used for repair; for the case where the application publisher provides a suitable hotfix patch, the patch-based solution is mainly used for repair. Step S403, the vulnerability repair module can determine the repair strategy based on user configuration. Step S404, the vulnerability repair module can perform vulnerability protection on the device to be protected based on the repair strategy. The vulnerability is repaired according to the selected repair strategy. The specific repair strategies are described below.

[0127] In some embodiments, the security antibody includes an agent, see Figure 8 , Figure 8 shows that implanting the pre-built security antibody in the device to be protected based on the system privilege in step S211 and using the security antibody to perform vulnerability protection on the target asset can be achieved through the following steps S501 to step 505.

[0128] Step S501, collect the system information of the target system under the system privilege.

[0129] Here, the system information can include host information (operating system version, host name, domain information, patch installation status), hardware information (Central Processing Unit (CPU), memory, hard disk), user information (current user, system user, privilege information), application information (other applications installed in the operating system, running applications), network information (network interface, routing, Domain Name System (DNS) configuration, etc.), protection information (whether the firewall is configured, whether the antivirus software is installed, etc.), other vulnerability information (whether the current application is affected by other vulnerabilities), etc.

[0130] Step S502, implant the pre-built agent on the target system based on the system information.

[0131] Here, after obtaining the system information, the system security assessment result, stability assessment result, etc. can be obtained based on the system information. The vulnerability repair strategy can be selected for the device to be protected considering the user configuration, security, and system stability comprehensively. Among them, the user configuration is the vulnerability repair strategy set by the user of the device to be protected, and the selection of the vulnerability repair strategy is mainly based on the user configuration. In the case where the user has not made a configuration, the default judgment method for selecting the vulnerability repair strategy is as follows: for the case where the system security assessment result indicates more system security problems, the host-side solution is used for repair; for the case where the system security assessment result indicates that the system security problems are relatively concentrated and the intrusion requirement is small, the application-layer solution is used for repair; for the case where the stability assessment result indicates an extremely high requirement for stability, the traffic-side solution is used for repair; for the case where the system information indicates that the issuer of the target asset provides a suitable hot update patch, the vulnerability patch-based solution is used for repair.

[0132] In the embodiment of the present application, the host-side solution is selected to protect the target vulnerability. At this time, the security antibody is the agent, and the target system can be the operating system of the device to be protected. The agent is an executable file pre-constructed by the operator on the operating system. Different operating systems correspond to different agents. Based on the system information, the agent adaptable to the operating system can be obtained, and using the system permissions, the agent is implanted on the operating system of the device to be protected. After being implanted, the agent can, after being authorized by the user, choose to detect the operating system in the kernel mode or user mode, and detect various system operations, such as accessing a website, opening a file, etc. Exemplarily, for the Linux operating system, kernel-level detection can obtain permissions for detection through methods such as extended Berkeley Packet Filter (eBPF), kernel drivers, etc., and user-mode detection can obtain permissions for detection through methods such as system logs, Linux Security Modules (LSM), etc.; for the Windows operating system, kernel-level detection can obtain permissions for detection through methods such as kernel drivers, registry, system call hijacking, etc., and user-mode detection can obtain permissions for detection through methods such as Windows event logs, Windows Application Programming Interface (API) detection, etc.; for the Mac operating system, kernel-level detection can obtain permissions for detection through methods such as kernel extensions, system call hijacking, etc., and user-mode detection can obtain permissions for detection through methods such as system event detection API, system log detection, etc.

[0133] Step S503: Load the host - side protection rules through the agent.

[0134] In the embodiments of the present application, the host - side protection rules can be stored in the database of the server by the operator in advance. The host - side protection rules can also be the protection rules built into the local operating system of the device to be protected. The agent obtains the host - side protection rules from the server or the operating system and loads them into the agent. Exemplarily, the host - side protection rules include but are not limited to the following: malicious process detection rules, such as abnormal behaviors of a process attempting to modify system files, access sensitive resources, communicate with a Command and Control Server (C&C), etc.; malicious file detection rules, using mechanisms such as black - and - white lists to detect the hash value of a file to identify known malicious files; abnormal network communication detection rules, detecting network traffic, identifying communications with known C&C servers, and abnormal communications using non - standard ports or protocols; malicious behavior detection rules, detecting malicious behaviors such as modifications to registry startup items; abnormal system activity detection rules, detecting abnormal behaviors such as abnormal login attempts, modifications to system configurations, and security policies.

[0135] Step S504: Scan the target system for the code to be cleared according to the host - side protection rules and clear the code to be cleared.

[0136] The code to be cleared is software installed and run on the device to be protected without permission. In the embodiments of the present application, the code to be cleared can be software installed and run on the device to be protected without the permission or authorization of the owner user of the device to be protected. The code to be cleared can be malicious code, which refers to computer code deliberately compiled or set that poses a threat or potential threat to a network or system. Exemplarily, malicious code can include memory horses (webshells), backdoors, special malware (rootkits), malicious registries, malicious computer program instruction (crontab) configurations, etc. After loading the host - side protection rules, it is possible to directly scan the operating system based on the host - side protection rules to check if there is already code to be cleared. If so, clear the code to be cleared.

[0137] Step S505: In response to an operation that executes an unauthorized behavior using the target vulnerability, intercept the operation based on the host - side protection rules.

[0138] In the embodiments of the present application, the operation of the unpermitted behavior is a malicious behavior operation that is to be executed after an external device exploits a target vulnerability and is not authorized by the owner user of the device to be protected, that is, an operation performed without the user's knowledge. In response to the operation of exploiting the target vulnerability to execute the unpermitted behavior, the agent can intercept it based on the host-side protection rules. The specific interception process may include the following steps: Terminate malicious processes: The system can terminate malicious processes to prevent the exploitation of vulnerabilities; Block file operations: The system can block the creation, modification, or execution of malicious files to prevent the exploitation of vulnerabilities; Network traffic filtering: The system can intercept network communications related to the vulnerability to block the transmission of malicious data or connections to malicious servers; Threat response: The system can also trigger corresponding threat response mechanisms, such as generating alerts, notifying the security team, recording event logs, etc. This helps to detect and respond to vulnerabilities in a timely manner and take further security measures to repair the vulnerabilities or prevent the reuse of similar vulnerabilities.

[0139] In the embodiments of the present application, by implanting an agent in the operating system, the existing malicious code is cleared, and the target vulnerability is prevented from being exploited again, thereby improving the security of the system and the efficiency of vulnerability repair.

[0140] Here, reference may also be made to Figure 9 , Figure 9 which is a schematic flowchart of the host-side vulnerability repair method provided by the embodiments of the present application. As Figure 9 shown, first, an agent is implanted on the terminal, that is, a pre-built agent is implanted on the operating system. Among them, the agents corresponding to different operating systems are different. Then, rule loading is performed, that is, the agent can load the corresponding protection rules from the remote end (the server of the vulnerability protection system) or the local end (the operating system) according to the configuration. After the rule loading, the agent can scan and clear the malicious code based on the loaded protection rules. When an external malicious attack is identified, such as using a vulnerability to make the application system execute malicious behaviors, the agent can intercept it based on its own capabilities.

[0141] In some embodiments, the security antibody includes an application runtime patch. The implantation of the pre-built security antibody in the device to be protected based on the system permissions in step S211 and the use of the security antibody to protect the target assets can also be achieved in the following manner: First, the system information of the target system is collected under the system permissions; Then, based on the system information, a pre-built application runtime patch is implanted on the target assets; Then, the application layer protection rules are loaded based on the application runtime patch. Finally, the code to be cleared existing in the target system is scanned according to the application layer protection rules and the code to be cleared is cleared, or, in response to an unauthorized operation for the target vulnerability, the unauthorized operation is intercepted based on the application layer protection rules.

[0142] In the embodiments of the present application, a solution at the application layer is selected to protect the target vulnerability. At this time, the security antibody is a runtime patch for the application. Different target assets support different runtime patches for the application. The application type information, application version information, application programming language, operating system information, operating system version information, CPU architecture information, etc. of the target asset can be obtained based on the system information and asset information. Based on the above application type information, application version information, application programming language, operating system information, operating system version information, CPU architecture information, etc., determine the runtime patches for the application that the target asset can support, such as dynamic instrumentation or agent, etc. After determining the runtime patches for the application that the target asset can support, use the system permissions to implant the runtime patch for the application on the target asset.

[0143] In the embodiments of the present application, the application layer protection rules can be stored in the database of the server by the operator in advance. The application layer protection rules can also be the protection rules built into the operating system of the device to be protected locally. The application layer protection rules are obtained from the server or the operating system through the application runtime patch and loaded into the application runtime patch. The application layer protection rules can include traffic-side protection rules and behavior-side protection rules at the application layer. The traffic-side protection rules at the application layer refer to the rules for protection through network traffic, and the behavior-side protection rules refer to the rules for protection by identifying various behaviors on the operating system. Exemplarily, the application layer protection rules include but are not limited to the following: Structured Query Language (SQL) injection protection rules: Detect and prevent malicious SQL injection attacks, including checking special characters in input parameters, filtering malicious SQL statements, etc.; Cross-Site Scripting (XSS) attack protection rules: Detect and prevent cross-site scripting attacks, including filtering and escaping malicious scripts in input and output to prevent them from executing in the browser; Cross-Site Request Forgery (CSRF) attack protection rules: Detect and prevent cross-site request forgery attacks, including verifying the request source, using tokens for request verification, etc.; File inclusion vulnerability protection rules: Detect and prevent malicious file inclusion attacks, including restricting access paths, verifying the legality of file paths, etc.; Command injection protection rules: Detect and prevent malicious command injection attacks, including filtering and validating input parameters to prevent malicious command execution; Code execution protection rules: Detect and prevent malicious code execution, including restricting and validating dynamic code evaluation, deserialization, etc.; Sensitive data leakage protection rules: Detect and prevent sensitive data leakage, including access control of sensitive data, encrypted transmission, etc.; Insecure access control protection rules: Detect and prevent insecure access control, including verifying user permissions and roles, enforcing mandatory access control policies, etc.; Malicious file upload protection rules: Detect and prevent malicious file uploads, including verifying the type and content of uploaded files, restricting upload paths, etc.; Weak password protection rules: Detect and prevent authentication using weak passwords, including verifying password strength, enforcing password policies, etc.

[0144] When scanning for the code to be cleared existing in the target system according to the application layer protection rules and clearing the code to be cleared, the code to be cleared is software installed and running on the device to be protected without permission. In the embodiments of the present application, after loading the application layer protection rules, it is possible to directly scan the target system based on the application layer protection rules to check whether there is already code to be cleared. If so, the code to be cleared is cleared. The specific implementation manner of the embodiments of the present application can refer to the above step S504.

[0145] When intercepting an unauthorized operation for a target vulnerability based on application layer protection rules in response to the unauthorized operation for the target vulnerability, the unauthorized operation for the target vulnerability includes an operation of performing an unauthorized behavior by exploiting the target vulnerability and an operation of exploiting the target vulnerability. Among them, the operation of the unauthorized behavior is a malicious behavior operation that is not authorized by the owner user of the device to be protected after an external device exploits the target vulnerability. The operation of exploiting the target vulnerability is an operation of exploiting the target vulnerability that is to be performed without being authorized by the owner user of the device to be protected before the exploitation occurs.

[0146] In response to an operation of exploiting a target vulnerability, the application runtime patch can be intercepted based on the application layer protection rules of traffic characteristics. The specific interception process may include the following steps: Traffic detection: The system detects the traffic of the application program, including request and response data; Traffic detection parsing: The system parses the traffic data and extracts key information, such as request method, URL path, request parameters, request headers, response status code, etc.; Exploitation detection: The system detects the traffic data according to predefined exploitation patterns or rules to identify potential exploitation behaviors; Exploitation interception: If the system detects an exploitation behavior in the traffic, it will immediately take corresponding interception measures, including blocking the execution of the request, returning an error response, logging, etc.; Response processing: The system will decide how to process the request and response according to the intercepted exploitation behavior. It can choose to reject the request, redirect the request, modify the request parameters or response content, etc.; Alarm and logging: The system will generate alarms and log records to notify relevant personnel or system administrators of information about the intercepted exploitation behavior. This helps to respond and investigate potential security threats in a timely manner; Defense strategy update: According to the emergence of new exploitation patterns or attack techniques, the system will regularly update its rules and strategies to maintain effective defense against new threats.

[0147] After a vulnerability exploitation occurs, in response to an operation that performs an unauthorized behavior by exploiting a target vulnerability, the application runtime patch can intercept it based on the application-layer protection rules of behavioral characteristics. The specific interception process may include the following steps: Behavior detection: The system detects the runtime behavior of the application, including function calls, database accesses, file operations, etc.; Behavior analysis: The system analyzes the behavior of the application to identify normal behaviors and potential vulnerability exploitation behaviors. The system builds a behavior model to detect abnormal or malicious behaviors; Vulnerability exploitation detection: The system detects the behavior of the application according to predefined vulnerability exploitation patterns or rules. The system analyzes behavioral characteristics to identify potential vulnerability exploitation behaviors; Vulnerability exploitation interception: If the system detects a vulnerability exploitation behavior in the application, the system immediately takes corresponding interception measures. These include interrupting function calls, blocking sensitive operations, returning error responses, etc.; Alerting and logging: The system generates alerts and logs to notify relevant personnel or system administrators of information about the intercepted vulnerability exploitation behavior; Defense strategy update: According to the emergence of new vulnerability exploitation patterns or attack techniques, the system regularly updates its rules and strategies to maintain effective defense against new threats.

[0148] In the embodiment of the present application, by implanting an application runtime patch in the target asset, the removal of existing malicious code is achieved, and the target vulnerability is prevented from being exploited again, thereby improving the security of the system and the efficiency of vulnerability repair.

[0149] Here, reference may be made together to Figure 10 , Figure 10 which is a schematic flowchart of the vulnerability repair method on the application side provided by the embodiment of the present application. As Figure 10 shown, first, based on the asset information and system information obtained previously, the application runtime patch capabilities supported by the target system can be identified, such as dynamic instrumentation or agent, etc., and the corresponding method is used to add an application runtime patch to the target application. Then, rule loading is performed, that is, the application runtime patch can load protection rules. After the protection rules are loaded, the application runtime patch can scan and remove malicious code based on the protection rules. After the protection rules are loaded, the application runtime patch can also perform vulnerability interception based on the application-layer rules of traffic characteristics before a vulnerability exploitation occurs. After the protection rules are loaded, the application runtime patch can also perform interception based on the application-layer rules of behavioral characteristics after a vulnerability exploitation occurs and before actual malicious behaviors occur.

[0150] In some embodiments, the security antibody includes a traffic middle layer. In step S211, a pre-built security antibody is implanted in the device to be protected based on system permissions, and vulnerability protection of the target asset using the security antibody can also be achieved in the following way: first, the system information of the target system is collected under system permissions. Then, based on the system information, a pre-built traffic middle layer is added to the device to be protected; the traffic middle layer includes one of the kernel layer, the network interface layer, the user layer, and the application layer. Then, the traffic layer protection rules are loaded through the traffic middle layer. Finally, in response to the vulnerability exploitation operation against the target vulnerability, the vulnerability exploitation operation is intercepted based on the traffic layer protection rules.

[0151] In the embodiment of the present application, a solution on the flow side is selected to protect the target vulnerability. At this time, the security antibody includes a flow middle layer. The flow middle layer is used to transfer the network traffic from the flow middle layer and then forward it to other applications. The types of flow middle layers may include the kernel layer, the network interface layer, the user layer, and the application layer. Different types of flow middle layers have different flow forwarding solutions.

[0152] Exemplarily, the traffic forwarding scheme of the kernel layer may include the traffic forwarding scheme of kernel driver and eBPF; the forwarding scheme of the network interface layer may include the traffic forwarding scheme based on Internet Protocol (IP) packet filtering system (iptables), Linux subsystem etfilter, packet filtering (Packet Filter, pf), etc.; the traffic forwarding scheme of the user layer, when the stability requirement is extremely high, the system can have a built-in bypass scheme based on the user layer, and provide protection by actively blocking the captured traffic; the traffic forwarding scheme of the application layer, if the target asset uses middleware such as proxy server nginx, server software apache, application server tomcat, application framework spring, etc., the traffic can be forwarded to the protection side and then to the application side by temporary patch configuration (patch configuration) and hot loading.

[0153] In the embodiment of the present application, the type of the traffic intermediate layer added to the device to be protected can be determined based on the system information of the target system and the user configuration. After the traffic intermediate layer is determined, the traffic intermediate layer is added to the device to be protected using the system authority.

[0154] In the embodiment of the present application, when the flow layer protection rules are loaded through the flow intermediate layer, the flow layer protection rules can be stored in the database of the server in advance by the operator. The flow layer protection rules can also be the protection rules that come with the local target system of the device to be protected. The flow layer protection rules are obtained from the server or the target system through the flow intermediate layer and loaded into the flow intermediate layer.

[0155] Exemplarily, the traffic layer protection rules include but are not limited to the following: SQL injection defense rules: Detect and block malicious SQL queries, including filtering special characters, checking the structure of SQL statements, etc.; XSS (Cross-Site Scripting) attack defense rules: Detect and block malicious script injections, including filtering HTML tags, escaping special characters, etc.; CSRF (Cross-Site Request Forgery) attack defense rules: Verify the request source to prevent unauthorized requests from being executed; File inclusion attack defense rules: Detect and block malicious file inclusions, including restricting access paths, filtering special characters, etc.; Command injection attack defense rules: Detect and block malicious command injections, including filtering special characters, restricting command execution, etc.; HTTP response splitting attack defense rules: Detect and block malicious HTTP response splittings to prevent attackers from injecting malicious content; Directory traversal attack defense rules: Restrict access paths to prevent attackers from obtaining sensitive files through directory traversal; HTTP request method restriction rules: Restrict uncommon HTTP request methods, such as TRACE (an HTTP method used to debug web server connections), OPTIONS (an HTTP method used to debug web server connections), etc., to prevent attackers from using these methods for attacks; Malicious file upload defense rules: Detect and block malicious file uploads, including restricting file types, checking file contents, etc.

[0156] When responding to an exploit operation for a target vulnerability, the execution terminal in the traffic middle layer can intercept based on the traffic layer protection rules. Specific interception schemes can include the following: The kernel driver scheme directly discards the corresponding network request in the kernel and records it; The network interface layer scheme automatically configures firewall rules according to the source IP, target IP, port, etc. to block requests; The user space scheme uses the method of actively sending packets to block for protection; The application layer scheme blocks illegal requests through Web Application Firewall (WAF) rules, authentication, access control, etc.

[0157] In the embodiments of this application, by adding a traffic middle layer to the device to be protected, the removal of existing malicious code is achieved, and the reuse of target vulnerabilities is prevented, thereby improving the security and stability of the system and enhancing the vulnerability repair efficiency.

[0158] Here, reference can also be made to Figure 11 , Figure 11 which is the flowchart of the traffic-side vulnerability repair method provided by the embodiments of this application. As Figure 11As shown, first, the traffic intermediate layer can be added based on system permissions. The traffic intermediate layer can provide multiple different traffic forwarding solutions according to the system, including the following in the order from the kernel layer to the application layer: traffic forwarding solutions based on kernel drivers, forwarding solutions based on network interfaces, user-space-based solutions, application-layer-based solutions, etc. After adding the traffic intermediate layer, rule loading can be performed at the terminal of the traffic intermediate layer. After the protection rules are loaded, the traffic intermediate layer can identify malicious attacks and intercept them based on different traffic forwarding solutions.

[0159] In some embodiments, the security antibody includes a vulnerability patch. Implanting the pre-constructed security antibody in the device to be protected based on system permissions in step S211 and using the security antibody to perform vulnerability protection on the target asset can also be achieved in the following manner: First, collect the system information of the target system under system permissions, and based on the system information, obtain the vulnerability patch corresponding to the target asset. Then, after backing up the source code and configuration information of the target asset, implant the vulnerability patch on the target asset. Then, in response to the vulnerability patch being run and the target asset being restarted, verify the installation status of the vulnerability patch. Finally, in the case where the vulnerability patch is successfully installed, intercept the vulnerability exploitation operation targeting the target vulnerability based on the vulnerability patch.

[0160] In the embodiments of the present application, for cases with higher stability requirements and when the issuer of the target asset provides a hot patch, select the vulnerability patch solution to protect the target vulnerability. At this time, the security antibody includes the vulnerability patch. The system information of the target system and the asset information of the target asset can be used to obtain information such as the target system version, application version, vulnerability patch version, vulnerability patch preconditions, system status, etc. And based on this information, determine the vulnerability patch corresponding to the target asset.

[0161] In the embodiments of the present application, after determining the vulnerability patch, first back up the source code and configuration information of the target asset and store it in the local or remote server of the target system. After the backup, the vulnerability patch can be implanted on the target asset using system permissions.

[0162] In the embodiments of the present application, after implanting the vulnerability patch, the target system can verify the information of the vulnerability patch. If the information is correct, run the vulnerability patch to the target system. In response to the vulnerability patch being run, restart or reload the target asset according to the requirements of the vulnerability patch. After restarting or reloading the target asset, the installation status of the vulnerability patch can be verified. Or, if the target system verifies that the information of the vulnerability patch is incorrect, alert the operator and terminate the subsequent steps.

[0163] In the embodiments of the present application, when the installation status of the vulnerability patch indicates that the vulnerability patch is successfully installed, the vulnerability exploitation operation targeting the target vulnerability can be intercepted based on the vulnerability patch before the target vulnerability is exploited.

[0164] In the embodiments of the present application, by implanting vulnerability patches in the target assets, it is possible to prevent the target vulnerability from being exploited again, thereby improving the security of the system and the efficiency of vulnerability repair.

[0165] Here, reference can also be made to Figure 12 , Figure 12 which is a schematic flow diagram of the vulnerability repair method based on vulnerability patches provided by the embodiments of the present application. As Figure 12 shown, the vulnerability patch can be a hot patch. First, information collection is performed: information such as the system version, application version, patch version, patch preconditions, and system status is obtained. Then, patch pulling: the vulnerability patch is pulled according to the information obtained in the previous step. System backup: the source code, configuration, etc. of the target asset are backed up. After verifying the information of the vulnerability patch, the vulnerability patch is hot updated to the application system, and the target asset is restarted or reloaded according to the requirements of the vulnerability patch. Patch verification: the installation status of the vulnerability patch is verified. Finally, malicious vulnerability exploitation can be intercepted based on the patch to make the malicious vulnerability exploitation fail.

[0166] Step S212, the server generates a vulnerability protection report.

[0167] In the embodiments of the present application, the vulnerability repair report may include: the version information of the target system of the device to be protected, the vulnerability information affected by the target system of the device to be protected, the vulnerability repair strategy selected by the device to be protected, the execution status of the vulnerability repair strategy, the status of intercepting vulnerability exploitation, and the security threats identified and intercepted, etc. Among them, the execution status of the vulnerability repair strategy is used to indicate whether the security antibody is successfully implanted, that is, whether the target vulnerability is successfully repaired.

[0168] In some embodiments, reference can also be made to Figure 13 , Figure 13It is a schematic flowchart of the continuous verification module provided by the embodiments of this application. After vulnerability repair, the continuous verification stage can be divided into the following steps: Step S601, the continuous verification module can generate a vulnerability protection report based on the vulnerability repair result. Step S602, the continuous verification module can periodically detect the status of the implanted security antibody. The status of the implanted security antibody can be periodically detected, and the detection methods include two methods: active detection and passive callback. Active detection: For the device to be protected that can actively connect to the Internet, the security antibody can actively callback to the specified server and periodically send the current status information, including whether the antibody continues to take effect and the vulnerability interception situation, etc. Passive callback: For the device to be protected that cannot actively connect to the Internet, the server can periodically send a specific request to the security antibody, so that the security antibody returns a specific response to the specific request to display the current status, including whether the antibody continues to take effect and the vulnerability interception situation, etc. Step S603, the continuous verification module can update the security antibody based on the status of the security antibody (that is, recheck the vulnerability). Before the user closes the detection task, the vulnerability protection system will periodically conduct a recheck, obtain the status of the security antibody obtained in Step 2. If the status of the security antibody indicates that the security antibody is offline, corresponding updates will be made.

[0169] Step S213, the server sends a vulnerability protection report to the terminal.

[0170] Step S214, the terminal displays the vulnerability protection report on the current interface.

[0171] In some embodiments, after establishing a connection with the specified server through the security antibody, the security antibody periodically sends the status information of the security antibody to the server; or, the security antibody returns a verification response to the protection verification request, and the verification response includes the status information of the security antibody; the protection verification request is sent by the specified server to the security antibody.

[0172] In the embodiments of this application, the devices to be protected can be divided into two situations: those that can actively connect to the Internet and those that cannot actively connect to the Internet. For the devices to be protected that can actively connect to the Internet, the security antibody can actively callback to the specified server and periodically send the current status information, including whether the antibody continues to take effect and the vulnerability interception situation, etc. For the devices to be protected that cannot actively connect to the Internet, the server can periodically send a specific request to the security antibody, so that the security antibody returns a specific response to the specific request to display the current status, including whether the antibody continues to take effect and the vulnerability interception situation, etc.

[0173] The vulnerability protection method provided by the embodiments of the present application, when performing vulnerability protection on a device to be protected, can first determine the target assets in the device to be protected that may be affected by the target vulnerability, obtain the system permissions of the target system of the device to be protected by using the target vulnerability, and then implant security antibodies in the device to be protected based on the system permissions to achieve vulnerability protection for the target assets. Among them, when determining the target assets, the asset list information of the device to be protected can be obtained first, the vulnerability information for the target vulnerability can be received, and the target assets that may be affected by the target vulnerability can be determined from the asset list information based on the vulnerability information. In the embodiments of the present application, when there are target assets that may be affected by the target vulnerability, the system permissions are obtained by using the target vulnerability, security antibodies are implanted, and the target assets are quickly fortified to protect the target assets from attacks, thereby significantly improving the security of the device to be protected and solving the network security risks brought by vulnerabilities. Therefore, when ordinary users do not have the technical ability to repair network security vulnerabilities, they can use the vulnerability protection method provided by the embodiments of the present application to proactively repair the vulnerabilities without the participation of ordinary users. By introducing security antibodies to repair the vulnerabilities, the false positive rate is low and the response is rapid.

[0174] The vulnerability protection method proposed by the embodiments of the present application is a vulnerability protection method based on antibody implantation, which can provide security protection for public services with vulnerabilities. In typical application scenarios such as attack surface management and security vulnerability emergency response, the embodiments of the present application can be used to quickly fortify applications to protect the applications from attacks, thereby significantly improving the security of the applications. Solve potential risks such as system paralysis, application control, and data leakage. After the embodiments of the present application obtain the service permissions through vulnerabilities, security antibodies are implanted in the device to be protected in different ways to protect against subsequent malicious vulnerability exploitation, and solve the network security risks brought by vulnerabilities.

[0175] Figure 14 It is a schematic diagram of the interaction process in the vulnerability protection process provided by the embodiments of the present application, as Figure 14 shown, in the vulnerability protection process, the following interaction steps S701 to step S704 are included:

[0176] Step S701, the vulnerability protection system obtains the system permissions of the target system of the device to be protected by using the target vulnerability.

[0177] Step S702, the vulnerability protection system implants the pre-constructed security antibodies in the device to be protected by using the system permissions.

[0178] Step S703, the device to be protected uses the security antibodies for vulnerability protection and returns the vulnerability protection result to the vulnerability protection system.

[0179] Step S704, the vulnerability protection system generates a vulnerability protection report.

[0180] It should be noted that Figure 14 The vulnerability protection system in Figure 14 can also be an abstract system, which can be a server cluster. The device to be protected can be one or more network assets such as servers. The vulnerability protection method provided by the embodiments of the present application can improve system security: The proactive vulnerability repair solution can help identify and repair vulnerabilities in the system, thereby improving the overall security of the system. By promptly repairing vulnerabilities, the risk of hacker intrusion can be reduced, sensitive data and user privacy can be protected; Prevent data leakage: Vulnerability repair can prevent potential data leakage. By repairing vulnerabilities in the system, the possibility of hackers using these vulnerabilities to obtain sensitive information can be blocked, thereby protecting the data security of users and organizations; Comply with regulations and compliance requirements: Many industries have specific regulations and compliance requirements that require organizations to take necessary security measures to protect user data. By proactively repairing vulnerabilities, organizations can ensure compliance with these requirements and avoid potential legal and compliance risks; Reduce potential losses: Unpatched vulnerabilities may lead to serious consequences, including data loss, system paralysis, damaged reputation, etc. By proactively repairing vulnerabilities, the risk of these potential losses can be reduced, and the interests and reputation of the organization can be protected.

[0181] It should be noted that the embodiments of the present application provide a variety of different solutions to complete vulnerability protection. In fact, other solutions can also be used for protection. In addition to the host side, application side, traffic side, and patch repair, other vulnerability solutions can also implement the vulnerability protection method provided by the embodiments of the present application. For the host side, in addition to eBPF, drivers, and user space, other host side protection solutions can also be used; For application side protection, in addition to application runtime patches such as RASP and memory WAF, other application side protection solutions can also be used; For the traffic side, in addition to iptables, modifying middleware configurations, and bypass blocking, other traffic side solutions can also be used.

[0182] It can be understood that in the embodiments of the present application, data related to the system permissions, system information, vulnerability information, asset information, etc. of the target system is involved. When the embodiments of the present application are applied to specific products or technologies, user permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0183] Next, continue to describe the exemplary structure of the vulnerability protection device 455 provided by the embodiments of the present application as a software module. In some embodiments, as Figure 2 shown, the software module stored in the vulnerability protection device 455 in the memory 450 may include:

[0184] An asset acquisition module 4551, configured to acquire asset list information of a device to be protected; a target asset determination module 4552, configured to, in response to receiving an input operation of vulnerability information for a target vulnerability, determine a target asset based on the vulnerability information and the asset list information; the target asset being an asset in the device to be protected that is affected by the target vulnerability; a permission acquisition module 4553, configured to use the target vulnerability to acquire system permissions of a target system of the device to be protected; a vulnerability protection module 4554, configured to implant a pre-built security antibody in the device to be protected based on the system permissions, and use the security antibody to protect the target asset against the vulnerability; the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

[0185] In some embodiments, the asset acquisition module 4551 is further configured to acquire asset information of the device to be protected; perform fingerprint recognition on the asset information to obtain fingerprint information corresponding to the asset information; store the asset information and the fingerprint information corresponding to the asset information in a database, wherein the asset information and the fingerprint information of the device to be protected stored in the database constitute the asset list information.

[0186] In some embodiments, the target asset determination module 4552 is further configured to acquire application scope information of the target vulnerability carried in the vulnerability information; based on the application scope information, screen out candidate fingerprint information from the asset list information, and determine the asset information corresponding to the candidate fingerprint information as candidate assets; use a pre-built vulnerability detection script to detect whether the target vulnerability affects the candidate assets to obtain a detection result of the candidate assets; based on the detection result, screen out the target assets from the candidate assets.

[0187] In some embodiments, the security antibody includes an agent, and the vulnerability protection module 4554 is further configured to collect system information of the target system under the system permissions; implant a pre-built agent on the target system based on the system information; load host-side protection rules through the agent; scan for code to be cleared existing in the target system according to the host-side protection rules, and clear the code to be cleared; the code to be cleared is software installed and run on the device to be protected without permission; or, in response to an operation of performing an unauthorized behavior by exploiting the target vulnerability, intercept the operation based on the host-side protection rules.

[0188] In some embodiments, the security antibody includes an application runtime patch, and the vulnerability protection module 4554 is further configured to collect system information of the target system under system permissions; based on the system information, implant a pre-built application runtime patch on the target asset; load application layer protection rules based on the application runtime patch; scan the target system for code to be cleared based on the application layer protection rules, and clear the code to be cleared; the code to be cleared is software installed and run on the device to be protected without permission; or, in response to an unauthorized operation for a target vulnerability, intercept the unauthorized operation based on the application layer protection rules.

[0189] In some embodiments, the security antibody includes a traffic intermediate layer, and the vulnerability protection module 4554 is further configured to collect system information of the target system under system permissions; based on the system information, add a pre-built traffic intermediate layer to the device to be protected; the traffic intermediate layer includes one of a kernel layer, a network interface layer, a user layer, and an application layer; load traffic layer protection rules through the traffic intermediate layer; in response to an exploit operation for a target vulnerability, intercept the exploit operation based on the traffic layer protection rules.

[0190] In some embodiments, the security antibody includes a vulnerability patch, and the vulnerability protection module 4554 is further configured to obtain system information of the target system under system permissions; based on the system information, obtain a vulnerability patch corresponding to the target asset; after backing up the source code and configuration information of the target asset, implant the vulnerability patch on the target asset; in response to the vulnerability patch being run and the target asset being restarted, verify the installation status of the vulnerability patch; in the case where the vulnerability patch is successfully installed, intercept the exploit operation for the target vulnerability based on the vulnerability patch.

[0191] In some embodiments, the vulnerability protection device further includes a prohibition module, configured to prohibit protecting the target vulnerability in the case where candidate fingerprint information cannot be filtered out from the asset list information based on the application scope information.

[0192] In some embodiments, the vulnerability protection device further includes a report generation module, configured to generate a vulnerability protection report after protecting the target asset; the vulnerability protection report includes at least one of the following: version information of the target system, vulnerability information of the target vulnerability, implantation result of the security antibody, protection result of the target vulnerability, and intercepted insecure operations.

[0193] In some embodiments, the vulnerability protection device further includes a status feedback module, configured to regularly send status information of the security antibody to the server through the security antibody after establishing a connection with a specified server through the security antibody; or, return a verification response to a protection verification request through the security antibody, and the verification response includes status information of the security antibody; the protection verification request is sent by the specified server to the security antibody.

[0194] An embodiment of the present application provides a computer program product, which includes a computer program or computer-executable instructions, and the computer program or computer-executable instructions are stored in a computer-readable storage medium. A processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium, and the processor executes the computer-executable instructions, so that the electronic device executes the vulnerability protection method described above in the embodiment of the present application.

[0195] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, where computer-executable instructions or a computer program are stored, and when the computer-executable instructions or the computer program are executed by a processor, the processor will be caused to execute the vulnerability protection method provided by the embodiment of the present application. For example, as Figure 3 the vulnerability protection method shown.

[0196] In some embodiments, the computer-readable storage medium may be a memory such as RAM, ROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; or may be various devices including one or any combination of the above memories.

[0197] In some embodiments, the computer-executable instructions may be in the form of a program, software, software module, script, or code, and may be written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including being deployed as an independent program or being deployed as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0198] As an example, the computer-executable instructions may or may not correspond to a file in the file system, and may be stored as a part of a file storing other programs or data. For example, they may be stored in one or more scripts in a Hyper Text Markup Language (HTML) document, stored in a single file dedicated to the program under discussion, or stored in multiple cooperating files (for example, files storing one or more modules, subroutines, or code portions).

[0199] As an example, the computer-executable instructions may be deployed to be executed on one electronic device, or on multiple electronic devices located at one location, or on multiple electronic devices distributed at multiple locations and interconnected by a communication network.

[0200] In summary, through the embodiments of the present application, in typical application scenarios such as attack surface management and security vulnerability emergency response, applications can be quickly fortified to protect them from attacks, thereby significantly improving the security of the applications and addressing potential risks such as system paralysis, application control, and data leakage.

[0201] The above description is only for the embodiments of the present application and is not intended to limit the protection scope of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are all included in the protection scope of the present application.

Claims

1. A vulnerability protection method, characterized in that, The method includes: Obtaining asset list information of the device to be protected; In response to receiving an input operation of vulnerability information for a target vulnerability, determining a target asset based on the vulnerability information and the asset list information; the target asset is an asset in the device to be protected that is affected by the target vulnerability; Obtaining system permissions for the target system of the device to be protected by using the target vulnerability; Based on the system permissions, implanting a pre-built security antibody in the device to be protected, and using the security antibody to protect the target asset against the vulnerability; the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

2. The method according to claim 1, wherein The obtaining of the asset list information of the device to be protected includes: Obtaining the asset information of the device to be protected; Performing fingerprint recognition on the asset information to obtain fingerprint information corresponding to the asset information; Storing the asset information and the fingerprint information corresponding to the asset information in a database, where the asset information and the fingerprint information of the device to be protected stored in the database constitute the asset list information.

3. The method according to claim 2, wherein The determining of the target asset based on the vulnerability information and the asset list information includes: Obtaining the application scope information of the target vulnerability carried in the vulnerability information; Based on the application scope information, screening out candidate fingerprint information from the asset list information, and determining the asset information corresponding to the candidate fingerprint information as candidate assets; Using a pre-built vulnerability detection script to detect whether the target vulnerability affects the candidate assets, and obtaining a detection result of the candidate assets; Based on the detection result, screening out the target asset from the candidate assets.

4. The method according to claim 1, wherein The security antibody includes an agent. The implanting of the pre-built security antibody in the device to be protected based on the system permissions and using the security antibody to protect the target asset against the vulnerability includes: Collecting system information of the target system under the system permissions; Based on the system information, implanting a pre-built agent on the target system; Loading host-side protection rules through the agent; Scanning for code to be cleared existing in the target system according to the host-side protection rules, and clearing the code to be cleared; the code to be cleared is software installed and run on the device to be protected without permission; Or, in response to an operation of performing an unauthorized behavior by using the target vulnerability, intercepting the operation based on the host-side protection rules.

5. The method according to claim 1, wherein The security antibody includes an application runtime patch. The implanting of the pre-built security antibody in the device to be protected based on the system permissions and using the security antibody to protect the target asset against the vulnerability includes: Collecting system information of the target system under the system permissions; Based on the system information, implanting a pre-built application runtime patch on the target asset; Loading application layer protection rules based on the application runtime patch; Scan the target system for code to be cleared according to the application layer protection rules, and clear the code to be cleared; the code to be cleared is software installed and run on the device to be protected without permission. Alternatively, in response to an unauthorized operation on the target vulnerability, intercept the unauthorized operation based on the application layer protection rules.

6. The method according to claim 1, characterized in that The security antibody includes a traffic intermediate layer. Implant a pre-built security antibody in the device to be protected based on the system permissions, and use the security antibody to protect against vulnerabilities in the target asset, including: Collect system information of the target system under the system permissions. Based on the system information, add a pre-built traffic intermediate layer to the device to be protected; the traffic intermediate layer includes one of the kernel layer, network interface layer, user layer, and application layer. Load traffic layer protection rules through the traffic intermediate layer. In response to an exploit operation on the target vulnerability, intercept the exploit operation based on the traffic layer protection rules.

7. The method according to claim 1, wherein The security antibody includes a vulnerability patch. Implant a pre-built security antibody in the device to be protected based on the system permissions, and use the security antibody to protect against vulnerabilities in the target asset, including: The system information of the target system under the system permissions. Based on the system information, obtain the vulnerability patch corresponding to the target asset. After backing up the source code and configuration information of the target asset, implant the vulnerability patch on the target asset. In response to the vulnerability patch being run and the target asset being restarted, verify the installation status of the vulnerability patch. In the case where the vulnerability patch is successfully installed, intercept the exploit operation on the target vulnerability based on the vulnerability patch.

8. The method according to claim 3, wherein The method further includes: In the case where candidate fingerprint information cannot be screened out from the asset list information based on the application scope information, prohibit protection against the target vulnerability.

9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Generate a vulnerability protection report after protecting the target asset against vulnerabilities. The vulnerability protection report includes at least one of the following: the version information of the target system, the vulnerability information of the target vulnerability, the implantation result of the security antibody, the protection result of the target vulnerability, and the intercepted insecure operations.

10. The method according to any one of claims 1 to 8, characterized in that The method further includes: After establishing a connection with a specified server through the security antibody, regularly send the status information of the security antibody to the server through the security antibody. Alternatively, return a verification response to a protection verification request through the security antibody, where the verification response includes the status information of the security antibody; the protection verification request is sent by a specified server to the security antibody.

11. A vulnerability protection device, characterized in that, The device includes: An asset acquisition module, configured to acquire the asset list information of the device to be protected. A target asset determination module, configured to, in response to receiving an input operation for the vulnerability information of a target vulnerability, determine a target asset based on the vulnerability information and the asset list information; the target asset is the asset in the device to be protected that is affected by the target vulnerability. A privilege acquisition module, configured to acquire the system privilege of the target system of the device to be protected by using the target vulnerability; A vulnerability protection module, configured to implant a pre-built security antibody in the device to be protected based on the system privilege, and use the security antibody to protect the target assets against vulnerabilities; the security antibody includes an antibody file for actively defending against the exploitation of the target vulnerability.

12. An electronic device, characterized in that, The electronic device includes: A memory, configured to store computer-executable instructions; A processor, configured to implement the vulnerability protection method according to any one of claims 1 to 10 when executing the computer-executable instructions stored in the memory.

13. A computer-readable storage medium stores computer-executable instructions or a computer program, characterized in that, The computer-executable instructions or the computer program, when executed by the processor, implement the vulnerability protection method according to any one of claims 1 to 10.

14. A computer program product, comprising computer-executable instructions or a computer program, characterized in that, The computer-executable instructions or the computer program, when executed by the processor, implement the vulnerability protection method according to any one of claims 1 to 10.