Intelligent automatic vulnerability verification system based on AI
Through the AI intelligent automation vulnerability verification system, the shortcomings of vulnerability verification in open source systems are solved, automated and accurate vulnerability detection and repair suggestions are realized, and system security is improved.
Patent Information
- Application Number
- CN202510334449.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, systems developed by open source frameworks or tools have multiple vulnerabilities, resulting in security problems in systems exposed to public networks and lack of effective automated vulnerability verification methods.
Design an AI-based intelligent automated vulnerability verification system, including data processing, feature extraction, model training, vulnerability detection and reporting feedback modules, and identify and verify potential vulnerabilities through data cleaning, feature selection, model training and optimization, and generate detailed reports and repair suggestions.
It realizes automated and accurate detection and verification of vulnerabilities, improves the accuracy and efficiency of vulnerability identification, provides targeted repair solutions, and enhances system security.
Smart Images

Figure CN120277673A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of AI vulnerability verification, and more specifically to an AI intelligent automated vulnerability verification system. Background Art
[0002] Artificial Intelligence (AI for short) is a technology that uses digital computers or machines controlled by digital calculations to simulate, extend, and expand human intelligence; it can perceive the environment, acquire knowledge, and effectively apply this knowledge, thus playing a role in various application scenarios;
[0003] With the development of artificial intelligence, more and more developers use open-source frameworks or open-source tools to develop applications. Artificial intelligence has brought a lot of convenience to people's lives and learning. However, due to various restrictions during the development of frameworks or tools, there are often various vulnerabilities, so there are many potential security problems in systems exposed to the public network;
[0004] Therefore, the present invention proposes an AI intelligent automated vulnerability verification system. Summary of the Invention
[0005] In view of the deficiencies of the prior art, the present invention provides an AI intelligent automated vulnerability verification system, which solves the problems raised in the above background art.
[0006] To solve the above technical problems, according to one aspect of the present invention, more specifically, an AI intelligent automated vulnerability verification system includes a data processing module, a feature extraction module, a model training module, a vulnerability detection module, and a report feedback module, and is characterized in that: the data processing module is used to collect data from the AI database and clean and preprocess the data;
[0007] The feature extraction module is used to extract features useful for vulnerability detection from the AI database and select an AI model for training according to the features;
[0008] The model training module is used to train the model through the extracted features and known vulnerability labels so that the model can identify potential vulnerabilities in the code;
[0009] The vulnerability detection module is used to detect the code through the trained AI model and identify potential vulnerabilities according to the input code and the extracted features;
[0010] The report feedback module generates a detailed detection report according to the results of the vulnerability detection, and provides suggestions and solutions for vulnerability repair to the development team according to the detection report.
[0011] Furthermore, the expression for screening expressions with vulnerability data in the AI database is:
[0012]
[0013] Wherein, AD is the attack and defense cost ratio of the data; PAV is the attack path; PAC is the attack complexity; PAU is the cost score of authentication; PI is the importance of the data asset; IL is the inherent lethality of the attack; ε is the weight of the importance of the data asset; r e is the vulnerability patch situation; op is the operation cost; de is the cost of damage repair; among them, when the attack and defense cost ratio of the data is higher than 1:3, the data is determined as secure data, and when the attack and defense cost ratio of the data is lower than 1:3, the data is determined as abnormal data, and this data is collected through the data processing module.
[0014] Furthermore, the data processing module includes data collection, data cleaning, and data preprocessing;
[0015] Data collection: used to collect public vulnerability information and exploitation codes from the CVE database, CNVD database, and GitHub, and train an AI model through the vulnerability information;
[0016] Data cleaning: clean the collected data, remove redundant, duplicate, and invalid information, and ensure the quality and accuracy of the data;
[0017] Data preprocessing: convert the cleaned data into a format suitable for processing by the AI model.
[0018] Furthermore, the feature extraction module includes feature extraction and feature selection;
[0019] Feature extraction: extract features useful for vulnerability detection from the preprocessed data;
[0020] Feature selection: select the most representative features for training according to the AI model, so as to improve the accuracy and efficiency of the model.
[0021] Furthermore, the model training module includes model selection, model training, and model optimization;
[0022] Model selection: select a suitable machine learning or deep learning model according to the task requirements of vulnerability detection;
[0023] Model training: train the model using the extracted features and known vulnerability labels;
[0024] Model optimization: optimize the model by adjusting model parameters, increasing training data, and using regularization methods to improve its generalization ability and accuracy.
[0025] Furthermore, the vulnerability detection module includes code scanning, vulnerability identification, and vulnerability verification;
[0026] Code scanning: Input the abnormal data to be detected into the trained AI model for automated vulnerability scanning;
[0027] Vulnerability identification: The model identifies potential vulnerabilities based on the input code and extracted features;
[0028] Vulnerability verification: Verify the identified vulnerabilities through methods such as simulated attacks and penetration testing to confirm their authenticity and exploitable nature.
[0029] Furthermore, the report feedback module includes report generation, feedback, and opinions;
[0030] Report generation: Generate an information report on the location, type, and severity of the vulnerabilities based on the results of the vulnerability detection;
[0031] Feedback and opinions: Provide suggestions and solutions for vulnerability repair to the development team based on the detection report, and feedback new vulnerabilities and attack methods discovered during the detection process to the security community and database to update and improve the vulnerability database.
[0032] Furthermore, the calculation formula for the detection accuracy of the vulnerability verification system is:
[0033]
[0034] In the formula, R is the accuracy of the vulnerability verification system; a is the number of positive class data correctly detected as positive by the vulnerability verification system; b is the number of positive class data incorrectly detected as negative by the vulnerability verification system; c is the number of negative class data incorrectly detected as positive by the vulnerability verification system; d is the number of data correctly detected as negative by the vulnerability verification system.
[0035] A usage method of an AI intelligent automated vulnerability verification system includes the following steps:
[0036] S1. Take the abnormal data from the AI database, and use the data processing module to collect public vulnerability information and exploitation codes from the CVE database, CNVD database, and GitHub, and train the AI model with the vulnerability information;
[0037] S2. Clean the collected vulnerability information to remove redundant, duplicate, and invalid information, and convert the cleaned data into a format suitable for processing by the AI model;
[0038] S3. Extract features useful for vulnerability detection from the preprocessed data, and use the extracted features and known vulnerability labels to train the model. Then, optimize the model by adjusting model parameters, increasing training data, and using regularization methods to improve its generalization ability and accuracy.
[0039] S4. Input the abnormal data to be detected into the trained AI model for automated vulnerability scanning, and identify potential vulnerabilities based on the input code and the extracted features.
[0040] S5. Generate an information report on the location, type, and severity of the vulnerabilities based on the results of the vulnerability detection, and provide suggestions and solutions for vulnerability repair to the development team according to the detection report.
[0041] The beneficial effects of an AI intelligent automated vulnerability verification system according to the present invention are as follows:
[0042] In the present invention, the data processing module automatically extracts abnormal data. Then, the model is trained with the collected vulnerability information and code. During the training process, the model is optimized by adjusting model parameters, increasing training data, and using regularization methods. After that, the abnormal data to be detected is input into the trained AI model for automated vulnerability scanning, and potential vulnerabilities are identified based on the input code and the extracted features. An information report on the location, type, and severity of the vulnerabilities is generated based on the results of the vulnerability detection, and suggestions and solutions for vulnerability repair are provided to the development team according to the detection report. In summary, the present invention can automatically detect and verify vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The present invention will be further described in detail below with reference to the drawings and specific implementation methods.
[0044] Figure 1 It is a schematic structural diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The present invention will be described in detail below with reference to the drawings and embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.
[0046] As Figure 1 shown, according to one aspect of the present invention, an AI intelligent automated vulnerability verification system is provided, including a data processing module, a feature extraction module, a model training module, a vulnerability detection module, and a report feedback module, characterized in that: the data processing module is used to collect data from the AI database, and clean and preprocess the data.
[0047] The feature extraction module is used to extract features useful for vulnerability detection from the AI database and select an AI model for training based on the features;
[0048] The model training module is used to train the model with the extracted features and known vulnerability labels so that the model can identify potential vulnerabilities in the code;
[0049] The vulnerability detection module is used to detect the code through the trained AI model and identify potential vulnerabilities based on the input code and the extracted features;
[0050] The report feedback module generates a detailed detection report based on the results of the vulnerability detection and provides suggestions and solutions for vulnerability repair to the development team according to the detection report.
[0051] In this embodiment, the expression for screening expressions with vulnerability data in the AI database is:
[0052]
[0053] In the formula, AD is the attack-defense cost ratio of the data; PAV is the attack path; PAC is the attack complexity; PAU is the cost score of authentication; PI is the importance of the data asset; IL is the inherent lethality of the attack; ε is the weight of the importance of the data asset; r e is the vulnerability patch situation; op is the operation cost; de is the damage repair cost; among them, when the attack-defense cost ratio of the data is higher than 1:3, the data is determined to be secure data, and when the attack-defense cost ratio of the data is lower than 1:3, the data is determined to be abnormal data, and this data is collected through the data processing module.
[0054] In this embodiment, the data processing module includes data collection, data cleaning, and data preprocessing;
[0055] Data collection: Used to collect public vulnerability information and exploitation code from the CVE database, CNVD database, and GitHub, and train the AI model through the vulnerability information;
[0056] Data cleaning: Clean the collected data, remove redundant, duplicate, and invalid information to ensure the quality and accuracy of the data;
[0057] Data preprocessing: Convert the cleaned data into a format suitable for processing by the AI model.
[0058] In this embodiment, the feature extraction module includes feature extraction and feature selection;
[0059] Feature extraction: Extract features useful for vulnerability detection from the preprocessed data;
[0060] Feature Selection: Select the most representative features for training according to the AI model to improve the accuracy and efficiency of the model.
[0061] In this embodiment, the model training module includes model selection, model training, and model optimization.
[0062] Model Selection: Select a suitable machine learning or deep learning model according to the task requirements of vulnerability detection.
[0063] Model Training: Train the model using the extracted features and known vulnerability labels.
[0064] Model Optimization: Optimize the model by adjusting model parameters, increasing training data, and using regularization methods to improve its generalization ability and accuracy.
[0065] In this embodiment, the vulnerability detection module includes code scanning, vulnerability identification, and vulnerability verification.
[0066] Code Scanning: Input the abnormal data to be detected into the trained AI model for automated vulnerability scanning.
[0067] Vulnerability Identification: The model identifies potential vulnerabilities based on the input code and extracted features.
[0068] Vulnerability Verification: Verify the identified vulnerabilities through simulation attacks and penetration testing to confirm their authenticity and exploitability.
[0069] In this embodiment, the report feedback module includes report generation, feedback, and suggestions.
[0070] Report Generation: Generate an information report on the location, type, and severity of the vulnerabilities based on the results of vulnerability detection.
[0071] Feedback and Suggestions: Provide suggestions and solutions for vulnerability repair to the development team based on the detection report, and feedback new vulnerabilities and attack methods discovered during the detection process to the security community and database to update and improve the vulnerability database.
[0072] In this embodiment, the formula for calculating the detection accuracy of the vulnerability verification system is:
[0073]
[0074] Where R is the accuracy of the vulnerability verification system; a is the number of positive class data correctly detected as positive by the vulnerability verification system; b is the number of positive class data incorrectly detected as negative by the vulnerability verification system; c is the number of negative class data incorrectly detected as positive by the vulnerability verification system; d is the number of data correctly detected as negative by the vulnerability verification system.
[0075] A method of using an AI intelligent automated vulnerability verification system, comprising the following steps:
[0076] S1. Take the abnormal data in the AI database, and use the data processing module to collect public vulnerability information and exploitation codes from the CVE database, CNVD database, and GitHub, and train the AI model through the vulnerability information.
[0077] S2. Clean the collected vulnerability information, remove redundant, repeated, and invalid information, and convert the cleaned data into a format suitable for processing by the AI model.
[0078] S3. Extract the features useful for vulnerability detection from the preprocessed data, and use the extracted features and known vulnerability labels to train the model. Then, optimize the model by adjusting the model parameters, increasing the training data, and using regularization methods to improve its generalization ability and accuracy.
[0079] S4. Input the abnormal data to be detected into the trained AI model for automated vulnerability scanning, and identify potential vulnerabilities based on the input code and the extracted features.
[0080] S5. Generate an information report on the location, type, and severity of the vulnerabilities according to the results of the vulnerability detection, and provide suggestions and solutions for vulnerability repair to the development team based on the detection report.
[0081] Of course, the above description is not a limitation of the present invention, and the present invention is not limited to the above examples. Changes, modifications, additions, or substitutions made by those of ordinary skill in the art within the scope of the essence of the present invention also belong to the protection scope of the present invention.
Claims
1. An AI intelligent automated vulnerability verification system, comprising a data processing module, a feature extraction module, a model training module, a vulnerability detection module, and a report feedback module, characterized in that: The data processing module is used to collect data from the AI database and clean and preprocess the data; The feature extraction module is used to extract features useful for vulnerability detection from the AI database and select an AI model for training based on the features; The model training module is used to train the model with the extracted features and known vulnerability labels so that the model can identify potential vulnerabilities in the code; The vulnerability detection module is used to detect the code through the trained AI model and identify potential vulnerabilities based on the input code and the extracted features; The report feedback module generates a detailed detection report based on the results of the vulnerability detection and provides suggestions and solutions for vulnerability repair to the development team according to the detection report.
2. The AI intelligent automated vulnerability verification system according to claim 1, wherein: The expression for screening expressions with vulnerability data in the AI database is: Where, AD is the attack and defense cost ratio of the data; PAV is the attack path; PAC is the attack complexity; PAU is the cost score of authentication; PI is the importance of the data asset; IL is the inherent lethality of the attack; ε is the weight of the importance of the data asset; r e is the vulnerability patch situation; op is the operation cost; de is the destruction and repair cost; among them, when the attack and defense cost ratio of the data is higher than 1:3, the data is determined as secure data, and when the attack and defense cost ratio of the data is lower than 1:3, the data is determined as abnormal data, and this data is collected through the data processing module.
3. An AI intelligent automated vulnerability verification system according to claim 1, characterized in that: The data processing module includes data collection, data cleaning, and data preprocessing; Data collection: used to collect public vulnerability information and exploitation codes from the CVE database, CNVD database, and GitHub, and train the AI model with the vulnerability information; Data cleaning: clean the collected data to remove redundant, duplicate, and invalid information to ensure the quality and accuracy of the data; Data preprocessing: convert the cleaned data into a format suitable for processing by the AI model.
4. The AI intelligent automated vulnerability verification system according to claim 1, characterized in that: The feature extraction module includes feature extraction and feature selection; Feature extraction: extract features useful for vulnerability detection from the preprocessed data; Feature selection: select the most representative features for training according to the AI model to improve the accuracy and efficiency of the model.
5. The AI intelligent automation vulnerability verification system according to claim 1, characterized in that: The model training module includes model selection, model training, and model optimization; Model selection: select a suitable machine learning or deep learning model according to the task requirements of vulnerability detection; Model training: train the model with the extracted features and known vulnerability labels; Model optimization: optimize the model by adjusting model parameters, increasing training data, and using regularization methods to improve its generalization ability and accuracy.
6. The AI intelligent automation vulnerability verification system according to claim 1, wherein: The vulnerability detection module includes code scanning, vulnerability identification, and vulnerability verification; Code scanning: input the abnormal data to be detected into the trained AI model for automated vulnerability scanning; Vulnerability identification: the model identifies potential vulnerabilities based on the input code and the extracted features; Vulnerability verification: verify the identified vulnerabilities by means of simulated attacks and penetration testing to confirm their authenticity and exploitable nature.
7. An AI intelligent automated vulnerability verification system according to claim 1, characterized in that: The report feedback module includes report generation and feedback and opinions; Report generation: generate an information report on the location, type, and severity of the vulnerability based on the results of the vulnerability detection; Feedback and opinions: provide suggestions and solutions for vulnerability repair to the development team according to the detection report, and feedback new vulnerabilities and attack methods found during the detection process to the security community and database to update and improve the vulnerability database.
8. An AI intelligent automated vulnerability verification system according to claim 1, characterized in that: The calculation formula for the detection accuracy of the vulnerability verification system is: Wherein, R is the accuracy rate of the vulnerability verification system; a is the number of positive-class data correctly detected as positive by the vulnerability verification system; b is the number of positive-class data incorrectly detected as negative by the vulnerability verification system; c is the number of negative-class data incorrectly detected as positive by the vulnerability verification system; d is the number of data correctly detected as negative by the vulnerability verification system.
9. An AI-based intelligent automated vulnerability verification system, including the method of using an AI-based intelligent automated vulnerability verification system according to any one of claims 1-8, characterized in that, It includes the following steps: S1. Take the abnormal data in the AI database, and use the data processing module to collect public vulnerability information and exploitation codes from the CVE database, CNVD database, and GitHub, and train the AI model with the vulnerability information. S2. Clean the collected vulnerability information, remove redundant, duplicate, and invalid information, and convert the cleaned data into a format suitable for processing by the AI model. S3. Extract features useful for vulnerability detection from the preprocessed data, train the model using the extracted features and known vulnerability labels, and then optimize the model by adjusting model parameters, increasing training data, and using regularization methods to improve its generalization ability and accuracy. S4. Input the abnormal data to be detected into the trained AI model for automated vulnerability scanning, and identify potential vulnerabilities based on the input code and extracted features. S5. Generate an information report on the location, type, and severity of the vulnerabilities based on the results of the vulnerability detection, and provide suggestions and solutions for vulnerability repair to the development team according to the detection report.