Vulnerability processing method, electronic equipment, program product and storage medium
Through differential code generation or pre-training machine learning model prediction, the timeliness and targeted problems of software vulnerability repair are solved, and fast and accurate vulnerability repair is achieved, avoiding the risk of business system compatibility.
Patent Information
- Application Number
- CN202510754640.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
In the prior art, software vulnerability repair relies on patch files, resulting in a long repair time and may affect business system compatibility, lacking timeliness and targeting.
By obtaining vulnerability information, determining the unfixed software version, and generating differential code patches when there is a repair software version, or using pre-trained machine learning models to predict the repair method, improve the pertinence and timeliness of vulnerability repair.
It effectively improves the pertinence and timeliness of vulnerability repair, ensuring that the business system can quickly and accurately repair vulnerabilities in the absence of patch files, and avoid compatibility issues.
Smart Images

Figure CN120277681A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technologies, and in particular, to a vulnerability handling method, an electronic device, a program product, and a storage medium. Background Art
[0002] To ensure the security and stability of the operation of a business system, it is very important to promptly repair software vulnerabilities in the business system. In related technologies, vulnerability repair depends on patch files provided by software manufacturers. However, on the one hand, the development of patch files takes a lot of time. In the case of the lack of patch files, the business system still operates with vulnerabilities exposed and lacks coping methods. On the other hand, software manufacturers may not provide patch files but repair vulnerabilities by updating software versions. However, the updated software versions may contain update content that has nothing to do with vulnerability repair, and this update content is likely to cause incompatibility between the software and the business system, thereby affecting the normal operation of the business system. Summary of the Invention
[0003] The present invention provides a vulnerability handling method, an electronic device, a program product, and a storage medium. When there is a repaired software version of the software with the repaired vulnerability, the target code for repairing the vulnerability can be located based on the repaired software version and the unrepaired software version of the software, and a patch file can be generated based on the target code. When there is no repaired software version of the software with the repaired vulnerability, a pre-trained machine learning model is used to predict the way to repair the vulnerability, so as to effectively improve the pertinence and timeliness of vulnerability repair.
[0004] To solve the above technical problems, the present invention provides a vulnerability handling method, including: Obtaining vulnerability information, and determining an unrepaired software version corresponding to the software affected by the vulnerability in the business system according to the vulnerability information; Searching whether there is a repaired software version of the software with the repaired vulnerability; If there is a repaired software version, determining the differential code between the software code of the repaired software version and the software code of the unrepaired software version, determining the target code for repairing the vulnerability in the differential code, and generating a patch file based on the target code to repair the vulnerability based on the patch file; If there is no repaired software version, obtaining the system environment information of the business system, inputting the vulnerability information, the unrepaired software version, and the system environment information into the pre-trained machine learning model, and obtaining the way to repair the vulnerability output by the pre-trained machine learning model to repair the vulnerability based on the way to repair the vulnerability.
[0005] The present invention also provides an electronic device, including: A memory for storing a computer program; A processor for implementing the above-mentioned vulnerability handling method when executing a computer program.
[0006] The present invention also provides a computer program product, including a computer program or instruction, which implements the above-mentioned vulnerability handling method when executed by a processor.
[0007] The present invention also provides a non-volatile computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are loaded and executed by a processor, the above-mentioned vulnerability handling method is implemented.
[0008] The beneficial effects of the present invention are as follows: When the present invention obtains vulnerability information, it can determine the unpatched software version corresponding to the software affected by the vulnerability in the business system according to the vulnerability information. Subsequently, the present invention can search whether the software has a patched software version with the vulnerability fixed. If there is a patched software version, in order to avoid the content unrelated to the vulnerability in the patched software version affecting the normal operation of the business system, the present invention can determine the differential code between the software code of the patched software version and the software code of the unpatched software version, locate the target code for fixing the vulnerability in the differential code, and generate a patch file based on the target code to improve the pertinence of the patch file. If there is no patched software version, the present invention can also obtain the system environment information of the business system, and input the vulnerability information, the unpatched software version, and the system environment information into a pre-trained machine learning model to obtain the vulnerability fixing method output by the pre-trained machine learning model, that is, use the pre-trained machine learning model to predict potential vulnerability fixing methods to attempt to fix the vulnerability in the case of lack of a patch file. In this way, the present invention can effectively improve the pertinence and timeliness of vulnerability fixing, thereby improving the vulnerability fixing effect.
[0009] The present invention also provides an electronic device, a program product, and a storage medium, which have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0011] Figure 1 It is a flowchart of a vulnerability handling method provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of another vulnerability handling process provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of a differential patch generation process provided by an embodiment of the present invention; Figure 4A schematic diagram of a model processing flow provided by an embodiment of the present invention; Figure 5 A structural block diagram of a vulnerability handling device provided by an embodiment of the present invention; Figure 6 A structural block diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0012] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0013] It should be noted that in the description of the present invention, the terms "including", "comprising" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0014] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0015] To ensure the security and stability of the operation of the business system, it is very important to repair software vulnerabilities in the business system in a timely manner. In the related art, vulnerability repair depends on the patch files provided by software vendors. However, on the one hand, the development of patch files takes a lot of time. In the case of the lack of patch files, the business system still operates with vulnerabilities exposed and lacks coping methods. On the other hand, software manufacturers may not provide patch files but repair vulnerabilities by updating the software version. However, the updated software version may contain update content unrelated to vulnerability repair, and this update content is likely to cause incompatibility between the software and the business system, thereby affecting the normal operation of the business system.
[0016] In view of this, in response to how to quickly and specifically repair software vulnerabilities, the present invention can provide a vulnerability handling method. When the software has a repaired software version with a repaired vulnerability, the target code for repairing the vulnerability can be located based on the repaired software version and the unrepaired software version of the software, and a patch file can be generated based on the target code. And when the software does not have a repaired software version with a repaired vulnerability, a pre-trained machine learning model can be used to predict the repair method of the vulnerability, thereby effectively improving the pertinence and timeliness of vulnerability repair.
[0017] For easy understanding, please refer to Figure 1 , Figure 1 which is a flowchart of a vulnerability handling method provided by an embodiment of the present invention. This method may include: S101. Obtain vulnerability information, and determine the unrepaired software version corresponding to the software affected by the vulnerability in the business system according to the vulnerability information.
[0018] In this step, the vulnerability information refers to information related to software vulnerabilities, such as may include vulnerability numbers, vulnerability descriptions, affected software versions, vulnerability trigger conditions, vulnerability types, vulnerability hazard levels, etc. This information can be obtained from multiple data sources, such as can be collected from vulnerability databases, security bulletins, and vulnerability exploitation code libraries. After obtaining this vulnerability information, this embodiment can save it to the local database for subsequent processing.
[0019] Furthermore, in this step, the unrepaired software version corresponding to the software affected by the vulnerability will be determined in the business system according to the vulnerability information. The unrepaired software version refers to the software version with this vulnerability. It should be noted that this embodiment does not limit the specific business system, which can be arbitrarily set according to application requirements.
[0020] S102. Check whether the software has a repaired software version with a repaired vulnerability. If there is a repaired software version, go to step S103; if there is no repaired software version, go to step S104.
[0021] In this step, it can be checked whether the software has a repaired software version with a repaired vulnerability. This repaired software version is generally provided by the software manufacturer, and the repaired software version can be found through the download channels provided by the software manufacturer.
[0022] S103. Determine the differential code between the software code of the repaired software version and the software code of the unrepaired software version, determine the target code for repairing the vulnerability in the differential code, and generate a patch file based on the target code to repair the vulnerability based on the patch file.
[0023] It should be particularly noted that when the repaired software version is queried in this step, the repaired software version will not be immediately used to fix the software vulnerability. This is because software vendors usually integrate several update contents into a repaired software version and update them together. At this time, the repaired software version contains both the update content for fixing the vulnerability and other update contents, such as code optimization, function enhancement, etc. At this time, the additional update content is likely to cause this software to be incompatible with other software / operating systems, thus affecting the normal operation of the business system. Therefore, this step will extract the target code for fixing the vulnerability from the repaired software version and generate a patch file based on this target code, so as to improve the pertinence of the patch file.
[0024] Specifically, this step can obtain the software code of the repaired software version and the software code of the unrepaired software version, and determine the differential code between the software codes of the two versions. The differential code refers to the part of the code that has been modified in the software code of the repaired software version compared with the software code of the unrepaired software version, such as newly added code, deleted code, and adjusted code. At this time, the differential code contains both the code for fixing the vulnerability and other update codes. Therefore, this step will continue to locate the target code for fixing the vulnerability in the differential code, so as to generate a patch file based on the target code.
[0025] For the location of the target code, this embodiment can be determined by analyzing whether the code logic of the differential code is related to the vulnerability repair. Specifically, the vulnerability trigger condition can be obtained from the vulnerability information. The vulnerability trigger condition can indicate under what software environment and what software operations the vulnerability can be reproduced, and both the software environment and software operations can be used to locate the target code. Subsequently, this embodiment can determine the code logic for fixing the vulnerability in the differential code according to the vulnerability trigger condition to obtain the target code, such as executing the differential code to determine which codes are related to avoiding the occurrence of the vulnerability, so as to obtain the target code.
[0026] Based on this, determining the target code for fixing the vulnerability in the differential code may include: Step 11: Determine the vulnerability trigger condition according to the vulnerability information.
[0027] Step 12: Determine the code logic for fixing the vulnerability in the differential code according to the vulnerability trigger condition to obtain the target code.
[0028] To further improve the location accuracy of the target code, this embodiment can provide another way to locate the target code. First, the system environment information of the business system can be obtained, and this system environment information can characterize the operating system environment in the business system. Subsequently, a first test environment can be constructed according to the system environment information and the unpatched software version, and a second test environment can be constructed according to the system environment information and the patched software version. Subsequently, the vulnerability trigger condition can be used to trigger a vulnerability in the first test environment to determine the first code segment that causes the vulnerability in the unpatched software version, and the vulnerability trigger condition can be used to trigger a vulnerability in the second test environment to determine the second code segment that fixes the vulnerability in the patched software version. At this time, both the first code segment and the second code segment are the code segments most closely associated with the vulnerability. Finally, the target code can be determined based on the first code segment, the second code segment, and the differential code, so that the substantial code content truly used for vulnerability repair can be extracted from the differential code.
[0029] Based on this, determining the code logic for fixing the vulnerability in the differential code according to the vulnerability trigger condition to obtain the target code may include: Step 21: Construct a first test environment according to the system environment information and the unpatched software version.
[0030] Step 22: Construct a second test environment according to the system environment information and the patched software version.
[0031] In Step 21 and Step 22, different virtual machine environments can be constructed based on virtualization technology according to the system environment information and different software versions, so as to use different virtual machine environments as different test environments.
[0032] Step 23: Use the vulnerability trigger condition to trigger a vulnerability in the first test environment to determine the first code segment that causes the vulnerability in the unpatched software version.
[0033] Step 24: Use the vulnerability trigger condition to trigger a vulnerability in the second test environment to determine the second code segment that fixes the vulnerability in the patched software version.
[0034] In Step 23 and Step 24, the propagation path of the user input to the vulnerability trigger point can be traced based on static analysis, or dynamic analysis methods such as code instrumentation can be used to observe the stack trace and memory state when the vulnerability is triggered, so as to determine the first code segment that causes the vulnerability and the second code segment that fixes the vulnerability.
[0035] Step 25: Determine the target code based on the first code segment, the second code segment, and the differential code.
[0036] In Step 25, cross-comparison can be performed on the first code segment, the second code segment, and the differential code to more accurately determine the target code.
[0037] S104. Obtain the system environment information of the business system, input the vulnerability information, unpatched software version, and system environment information into the pre-trained machine learning model, and obtain the vulnerability repair method output by the pre-trained machine learning model, so as to repair the vulnerability based on the vulnerability repair method.
[0038] In this step, if the patched software version cannot be queried, the vulnerability cannot be repaired by generating a patch file at this time. To prevent the business system from working in the case of exposed vulnerabilities, this embodiment can also attempt to adopt other vulnerability repair methods to repair the vulnerability. Among them, the vulnerability repair method is a process method for handling vulnerabilities. For example, it can be restricting functions, adjusting configuration parameters, upgrading software versions, installing existing patch files, etc. Specifically, to ensure the vulnerability repair effect, this embodiment can set up a pre-trained machine learning model, which has been trained using historical vulnerability repair information (including historical vulnerability information, historical unpatched software versions, historical system environment information, and historical vulnerability repair methods), and can predict the corresponding vulnerability repair method according to the input vulnerability information, unpatched software version, and system environment information, so as to improve the pertinence of the vulnerability repair method.
[0039] Specifically, this embodiment can first combine the vulnerability information, unpatched software version, and system environment information into the original input data. Subsequently, the original input data can be encoded to obtain the input data, so as to ensure that the model can recognize the input data. Furthermore, the input data can be input into the pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model and the confidence corresponding to the vulnerability repair method, and this confidence can represent the reliability degree of the vulnerability repair method. Finally, the vulnerability repair method and its confidence can be output for the operation and maintenance personnel to select.
[0040] Based on this, inputting the vulnerability information, unpatched software version, and system environment information into the pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model includes: Step 31: Combine the vulnerability information, unpatched software version, and system environment information into the original input data.
[0041] Step 32: Encode the original input data to obtain the input data.
[0042] Step 33: Input the input data into the pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model and the confidence corresponding to the vulnerability repair method.
[0043] Step 34: Output the vulnerability repair method and the confidence.
[0044] It should be noted that the specific type of the pre-trained machine learning model is not limited in this embodiment. For example, it can be a classification model or a language model (such as a large language model LLM, Large Language Model). For the convenience of implementation, a classification model can be selected as the pre-trained machine learning model in this embodiment. Specifically, a decision tree model can be trained to obtain the required pre-trained machine learning model.
[0045] Based on this, the training process of the pre-trained machine learning model can include: Step 41: Obtain historical vulnerability repair information and generate original training data using the historical vulnerability repair information; the historical vulnerability repair information includes historical vulnerability information, historical unpatched software versions, historical system environment information, and historical vulnerability repair methods.
[0046] Step 42: Encode the original training data to obtain training data.
[0047] Step 43: Train a decision tree model using the training data and use the trained decision tree model as the pre-trained machine learning model.
[0048] Finally, when a reliable patch file or vulnerability repair method is obtained, the business system can be repaired using the patch file or vulnerability repair method to prevent the business system from being exposed to vulnerability risks for a long time.
[0049] Based on this, the method further includes: S105. Repair the business system using the patch file or vulnerability repair method.
[0050] Based on the above embodiments, when the present invention obtains vulnerability information, it can determine the unpatched software version corresponding to the software affected by the vulnerability in the business system. Subsequently, the present invention can search for whether the software has a repaired software version for the patched vulnerability. If there is a repaired software version, to avoid the content unrelated to the vulnerability in the repaired software version affecting the normal operation of the business system, the difference code between the software code of the repaired software version and the software code of the unpatched software version can be determined, the target code for fixing the vulnerability can be located in the difference code, and a patch file can be generated based on the target code to improve the pertinence of the patch file. If there is no repaired software version, the present invention can also obtain the system environment information of the business system, and input the vulnerability information, unpatched software version, and system environment information into the pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model, that is, use the pre-trained machine learning model to predict potential vulnerability repair methods to attempt to repair the vulnerability in the absence of a patch file. In this way, the present invention can effectively improve the pertinence and timeliness of vulnerability repair, thereby improving the vulnerability repair effect.
[0051] Based on the above embodiments, after generating the patch file, in order to verify the effectiveness of the patch file and avoid huge losses to the business system caused by failed repairs, this embodiment can also determine the effectiveness of the patch file in the verification environment. Based on this, after generating the patch file based on the target code, it may further include: S201. Construct a verification environment according to the system environment information and the unpatched software version.
[0052] In this step, a virtual machine environment can be constructed based on virtualization technology according to the system environment information and the unpatched software version, and the virtual machine environment can be used as the verification environment.
[0053] S202. In the verification environment, use the patch file to repair the software.
[0054] S203. Determine the vulnerability trigger condition of the vulnerability according to the vulnerability information, and judge whether the patched software cannot trigger the vulnerability according to the vulnerability trigger condition; if it is determined that the patched software cannot trigger the vulnerability, go to step S204; if it is determined that the patched software can trigger the vulnerability, go to step S205.
[0055] S204. Determine that the patch file is valid.
[0056] S205. Determine that the patch file is invalid.
[0057] In steps S202 - S205, the patch file can be used to repair the software, and after the repair, the patched software can be triggered according to the vulnerability trigger condition of the vulnerability, and it can be judged whether the vulnerability reappears. If the vulnerability does not reappear, it can be determined that the patch file is valid and can be used to repair the business system. If the vulnerability reappears, it can be determined that the patch file is invalid, and at this time, the patch file cannot be used to repair the business system. It can be seen that through pre - verification, this embodiment can determine the effectiveness of the patch file and avoid using invalid patches to repair the business system.
[0058] Of course, in addition to judging whether the vulnerability disappears, this embodiment can also detect whether other failures occur in the verification environment, so as to further verify the effectiveness of the patch.
[0059] Further, after determining that the patch file is valid, supplementary training data can be generated using the vulnerability information, the unpatched software version, the system environment information, and the vulnerability repair method corresponding to the patch file, and the pre - trained machine learning model can be supplemented and trained using the supplementary training data. In this way, the understanding of such vulnerability repair methods by the model can be further improved, enabling it to give more accurate predictions.
[0060] Based on this, after determining that the patch file is valid, it may further include: Step 51: Generate a vulnerability repair method using the patch file.
[0061] Step 52: Generate supplementary training data by using vulnerability information, unpatched software versions, system environment information, and the vulnerability repair methods corresponding to the patch files.
[0062] Step 53: Use the supplementary training data to perform supplementary training on the pre-trained machine learning model.
[0063] Based on the above embodiments, after predicting the vulnerability repair method by using the pre-trained machine learning model, this embodiment can first verify the effectiveness of the vulnerability repair method in a verification environment, and when it is determined that the method is effective, use it to repair the business system, thereby avoiding huge losses to the business system caused by repair failures. Based on this, after obtaining the vulnerability repair method output by the pre-trained machine learning model, it may further include: S301. Construct a verification environment according to the system environment information and the unpatched software version.
[0064] In this step, a virtual machine environment can be constructed based on virtualization technology according to the system environment information and the unpatched software version, and the virtual machine environment can be used as the verification environment.
[0065] S302. In the verification environment, repair the software according to the vulnerability repair method.
[0066] S303. Determine the vulnerability trigger condition of the vulnerability according to the vulnerability information, and judge whether the repaired software cannot trigger the vulnerability according to the vulnerability trigger condition; if it is determined that the repaired software cannot trigger the vulnerability, go to S304; if it is determined that the repaired software can trigger the vulnerability, go to step S305.
[0067] S304. Determine that the vulnerability repair method is effective.
[0068] S305. Determine that the vulnerability repair method is invalid.
[0069] In steps S302 - S305, the vulnerability repair method predicted by the model can be used to repair the software, and after the repair, the repaired software can be triggered according to the vulnerability trigger condition of the vulnerability, and it can be judged whether the vulnerability reappears. If the vulnerability does not reappear, it can be determined that the vulnerability repair method is effective, and it can be used to repair the business system. If the vulnerability reappears, it can be determined that the vulnerability repair method is invalid, and at this time, the vulnerability repair method cannot be used to repair the business system. It can be seen that through pre-verification, this embodiment can determine the effectiveness of the vulnerability repair method and can avoid using invalid patches to repair the business system.
[0070] Of course, in addition to judging whether the vulnerability disappears, this embodiment can also detect whether other failures occur in the verification environment, so as to further verify the effectiveness of the vulnerability repair method.
[0071] Further, after determining that the vulnerability repair method is effective, supplementary training data can be generated using the vulnerability information, unpatched software version, system environment information, and the vulnerability repair method, and the supplementary training data can be used to supplement the pre-trained machine learning model. In this way, the model's understanding of such vulnerability repair methods can be further improved, enabling it to give more accurate predictions.
[0072] Based on this, after determining that the vulnerability repair method is effective, it further includes: Step 61: Generate supplementary training data using the vulnerability information, unpatched software version, system environment information, and the vulnerability repair method.
[0073] Step 62: Use the supplementary training data to supplement the pre-trained machine learning model.
[0074] Based on the above embodiments, considering that conventional vulnerability information usually does not include the repair priority of vulnerabilities, which in turn causes the repair progress of many low-priority vulnerabilities to affect the repair progress of high-priority vulnerabilities, making the system vulnerable to high-risk vulnerabilities for a longer time. For this reason, before performing vulnerability repair, this embodiment can also determine the repair priority of the vulnerability based on the vulnerability information and the business system to effectively repair high-priority vulnerabilities. Based on this, before searching for the repaired software version of the software with the repaired vulnerability, it can also include: S401: Determine the general evaluation score and threat intelligence of the vulnerability according to the vulnerability information.
[0075] The general evaluation score (CVSS score, Common Vulnerability Scoring System) is a common attribute in CVE vulnerability information (Common Vulnerabilities & Exposures), which can represent the risk level of the vulnerability itself.
[0076] The threat intelligence represents the threat situation of the vulnerability. Common threat intelligence can include vulnerability activity (such as the frequency of public discussion of the vulnerability, such as the number of CVE entry updates, the release volume of POC code (Proof of concept)), in-the-wild exploitation situation, attack complexity, etc.
[0077] By obtaining the general evaluation score and threat intelligence, this embodiment can effectively evaluate the risk of the vulnerability itself.
[0078] S402: Determine the asset information of the deployed software in the business system.
[0079] Assets in the business system include servers, databases, applications, network devices, etc. By determining the asset information of the software affected by the vulnerability, this embodiment can determine the impact scope of the vulnerability in the business system and can also determine the possible impact on the business system when repairing the vulnerability, so as to effectively evaluate the risk of the vulnerability to the business system.
[0080] S403. Determine the vulnerability score of the vulnerability using the general evaluation score, threat intelligence, and asset information, and determine the vulnerability repair level of the vulnerability according to the vulnerability score.
[0081] In this step, the vulnerability score of the vulnerability can be determined using the general evaluation score, threat intelligence, and asset information, and the vulnerability repair level of the vulnerability can be determined according to the vulnerability score, so as to determine the repair priority of the vulnerability by integrating the risk of the vulnerability itself and the risk of the vulnerability to the business system.
[0082] It should be noted that this embodiment does not limit the specific vulnerability repair level, which can be set according to actual application requirements. For example, three levels of low, medium, and high can be set. This embodiment also does not limit the corresponding relationship between the vulnerability score and the vulnerability repair level, which can also be set according to actual application requirements.
[0083] The following introduces a possible method for determining the vulnerability score. Based on this, determining the vulnerability score of the vulnerability using the general evaluation score, threat intelligence, and asset information may include: Step 71: Determine the threat intelligence scores corresponding to the threat intelligence in at least two preset threat intelligence evaluation dimensions, and use the preset weights corresponding to the respective preset threat intelligence evaluation dimensions to fuse the threat intelligence scores to obtain the total threat intelligence score.
[0084] In this step, the threat intelligence can be evaluated from multiple dimensions to obtain the threat intelligence scores corresponding to each dimension, and the total threat intelligence score can be obtained by means of weighted summation. This embodiment does not limit the specific preset threat intelligence evaluation dimensions. For example, it may include vulnerability activity (such as the number of updates of CVE entries and the release volume of POC codes according to the frequency of public discussion of the vulnerability), in-the-wild exploitation situation (the number of times the vulnerability is detected to be actually attacked), attack complexity (directly using the value of Attack Complexity in CVSS), threat intelligence credibility (authoritative source > commercial intelligence > community intelligence), etc.
[0085] It should be noted that this embodiment does not limit the weights corresponding to the respective preset threat intelligence evaluation dimensions, which can be set according to actual application requirements.
[0086] Step 72: Determine the asset importance scores corresponding to the asset information in at least two preset asset evaluation dimensions, and fuse the asset importance scores using the preset weights corresponding to each preset asset evaluation dimension to obtain the total asset importance score.
[0087] In this step, the asset information can also be evaluated in multiple dimensions to obtain the asset importance scores corresponding to each dimension, and the total asset importance score can be obtained by weighted summation. This embodiment does not limit the specific preset asset evaluation dimensions. For example, it can include business criticality, data sensitivity, system dependence, and business continuity. Among them, the business criticality can be scored according to the impact degree of the business module affected by the vulnerability on the core business. The data sensitivity can be classified and weighted according to the data types involved in the asset (such as public data, internal data, confidential data). The system dependence can evaluate the dependence relationship of the asset in the system (such as whether it is an upstream dependence of other systems). The business continuity can be graded according to the maximum tolerable downtime (MTD) or recovery time objective (RTO) allowed by the system.
[0088] For example, the core payment system is the business system that users perceive most obviously and involves user data. Therefore, its business criticality = 10, and the data sensitivity = 10; the internal test server is a business system that users do not perceive obviously and only involves unimportant internal data. Therefore, its business criticality = 1, and the data sensitivity = 1.
[0089] It should be noted that this embodiment does not limit the weights corresponding to each preset asset evaluation dimension, which can be set according to actual application requirements. In addition, the weights corresponding to the preset asset evaluation dimensions can be dynamically adjusted. For example, the initial weights can be set according to the business scenario (such as the business criticality weight is 40%, the data sensitivity is 30%, and the service continuity is 30%). Subsequently, a real-time feedback mechanism can be introduced. If an asset is attacked or fails recently, its weight can be automatically increased. In this way, the user needs can be flexibly met.
[0090] Based on this, this method can also include: Step 81: Obtain the attack information of the asset corresponding to the asset information.
[0091] Step 82: Adjust the preset weights corresponding to each preset asset evaluation dimension according to the attack information.
[0092] Step 73: Determine the vulnerability score of the vulnerability using the general evaluation score, the total threat intelligence score, and the total asset importance score.
[0093] In this step, the vulnerability score of the vulnerability can be determined by weighting the general evaluation score, the total threat intelligence score, and the total asset importance score.
[0094] S404. For vulnerabilities with a vulnerability repair level higher than the preset level, immediately execute the step of checking whether the software has a repaired software version for the repaired vulnerabilities.
[0095] S405. For vulnerabilities with a vulnerability repair level not higher than the preset level, wait until the business system enters a low-load state, and then execute the step of checking whether the software has a repaired software version for the repaired vulnerabilities.
[0096] In steps S404 - S405, for vulnerabilities with a vulnerability repair level higher than the preset level, this embodiment will give priority to processing; while for vulnerabilities with a vulnerability repair level not higher than the preset level, it can wait until the business system enters a low-load state before processing. In this way, it is possible to give priority to processing high-priority vulnerabilities and avoid the processing of low-priority vulnerabilities interfering with the processing of high-priority vulnerabilities.
[0097] Based on the above embodiments, the above vulnerability handling method will be introduced below based on specific examples and schematic diagrams. Please refer to Figure 2 , Figure 2 which is a schematic diagram of another vulnerability handling process provided by the embodiment of the present invention. This method may include: I. The multi-dimensional scoring system is responsible for classifying the collected vulnerabilities to ensure that high-priority vulnerabilities are processed first.
[0098] It mainly includes the following dimensions: CVSS base score (Common Vulnerability Scoring System), total asset importance score, threat intelligence coefficient.
[0099] 1. CVSS base score: An attribute information of the obtained vulnerability, which can be directly obtained.
[0100] 2. Total asset importance score: Assets include servers, databases, application programs, network devices, etc. The importance of an asset is determined by factors such as its business criticality, data sensitivity, and impact on business continuity. Each dimension can be quantified on a scale of 1 - 10 points (10 points being the highest importance). The following is a possible quantitative evaluation method: Table 1 Quantitative evaluation method
[0101] For example: Core payment system: Business criticality = 10, data sensitivity = 10; Internal test server: Business criticality = 1, data sensitivity = 1.
[0102] Meanwhile, in this embodiment, a dynamic weight method is adopted to configure weights for each scenario. For example: 1) Set initial weights according to business scenarios (business criticality weight 40%, data sensitivity 30%, service continuity 30%).
[0103] 2) Introduce a real-time feedback mechanism: if an asset has been attacked or malfunctioned recently, its weight is automatically increased.
[0104] 3. Threat intelligence coefficient: The threat intelligence coefficient needs to be dynamically obtained and standardized from multiple dimensions, including vulnerability activity (such as the number of CVE entry updates and the release volume of POC codes based on the frequency of public discussions about vulnerabilities), in-the-wild exploitation (the number of times a vulnerability has been actually attacked), attack complexity (directly using the value of Attack Complexity in CVSS), and threat intelligence credibility (authoritative source > commercial intelligence > community intelligence).
[0105] Through the evaluation and calculation of the above three dimensions, the final level of the vulnerability is obtained.
[0106] Second, the differential patch generation is responsible for comparing and analyzing the software version affected by the vulnerability and the repaired software version, extracting the differential code between the two, and generating a lightweight differential patch.
[0107] The goal of this function is to generate efficient, reliable, and compatible differential patches, providing a basis for subsequent vulnerability repair. At the same time, this function will also input the patch information into the learning model for the model to learn, enhancing the accuracy of the repair solutions provided by the subsequent model. Please refer to Figure 3 , Figure 3 which is a schematic diagram of a differential patch generation process provided by an embodiment of the present invention. The following is the specific process: 1. Version acquisition and preprocessing: Input: The software version affected by the vulnerability and the repaired software version.
[0108] Process: Perform preprocessing operations such as decompressing, compiling, and symbol parsing on the code to ensure code readability and analyzability.
[0109] 2. Code comparison and analysis: Use a code comparison tool to compare the codes of the two versions, and identify all modified files, functions, and code lines.
[0110] Distinguish the modifications related to vulnerability repair from the unrelated modifications (such as code optimization, function enhancement, etc.).
[0111] 3. Differential code extraction: Extract the code differences related to vulnerability repair (added, deleted, and modified code lines).
[0112] Organize and format the extracted differential codes to generate a differential patch that is easy to apply.
[0113] 4. Patch Optimization and Verification: Optimize the patch: Compress the patch size, eliminate redundant codes, and resolve dependencies.
[0114] Verify the patch: Ensure that the patch can be correctly applied to the target version without introducing new problems.
[0115] 5. Patch File Generation: Package the optimized and verified differential patch with patch metadata to generate the final patch file.
[0116] Thirdly, the adaptive learning is responsible for using machine learning techniques to analyze and learn historical vulnerability repair data, construct a vulnerability repair model, and predict the best repair solution for new vulnerabilities according to the model.
[0117] The goal of this function is to realize the intelligentization and adaptability of vulnerability repair strategies and improve the accuracy and efficiency of repair solutions.
[0118] Model Input and Output: Input: Historical vulnerability repair data (including vulnerability information, software environment, repair solution, repair result), which can be represented as , where represents the feature vector of the i-th vulnerability (including vulnerability type, software environment, repair solution, etc.), represents the repair result.
[0119] New vulnerability information (including vulnerability type, affected software version, vulnerability severity level); Current software environment information (including operating system version, software version, configuration information).
[0120] Output: Best repair solution (including repair strategy, repair steps, expected effect); Credibility score s of the repair solution.
[0121] Model Processing Flow (please refer to Figure 4 ): 1. Data Collection and Preprocessing: Collect historical vulnerability repair data from multiple sources such as vulnerability databases, security bulletins, and repair records.
[0122] Perform preprocessing operations such as cleaning, deduplication, and formatting on the collected data to ensure data quality and obtain the preprocessed dataset 。
[0123] 2. Feature Engineering: Extract features from historical vulnerability repair data such as vulnerability type, software environment, repair solution, repair result, etc.
[0124] Encode and normalize the extracted features to make them suitable for the input of machine learning models, obtaining a feature matrix and a label vector 。
[0125] 3. Model Training and Evaluation: Use the decision tree algorithm to build a vulnerability repair model, specifically using the decision tree algorithm to and for training to obtain a model 。
[0126] Use historical vulnerability repair data to train the model and evaluate the performance of the model using methods such as cross-validation.
[0127] 4. Repair Solution Prediction: Input new vulnerability information and current software environment information into the model to obtain the predicted repair solution and a confidence score to help users judge the reliability of the repair solution.
[0128] 5. Model Update and Optimization: Regularly collect new vulnerability repair data to update and optimize the model, improving the prediction accuracy of the model.
[0129] Adjust the model parameters and algorithms according to user feedback and actual repair effects to enhance the practicality of the model.
[0130] The above process can be formulated as: 1. Data Preprocessing: ; 2. Feature Engineering: ; 3. Model Training: ; 4. Repair Solution Prediction: ; Comprehensive formula: Combining the above steps, a comprehensive formula can be obtained: 。
[0131] Suppose there is the following training data set: Table 2 Training Data Set
[0132] After training the decision tree, for a new vulnerability (such as vulnerability type = "buffer overflow", software version = "1.0", hazard level = "high"), the decision tree will predict that the repair solution is "upgrade version".
[0133] Through the description of the above implementation manners, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation manner.
[0134] The embodiments of the present invention also provide a vulnerability processing device. Please refer to Figure 5 , Figure 5 which is a structural block diagram of a vulnerability processing device provided by an embodiment of the present invention. The device may include: An acquisition module 501, configured to acquire vulnerability information and determine an unrepaired software version corresponding to the software affected by the vulnerability in the business system according to the vulnerability information; A search module 502, configured to search for a repaired software version of the software with the repaired vulnerability; A patch file generation module 503, configured to, if there is a repaired software version, determine the differential code between the software code of the repaired software version and the software code of the unrepaired software version, determine the target code for repairing the vulnerability in the differential code, and generate a patch file based on the target code to repair the vulnerability based on the patch file; A repair method prediction module 504, configured to, if there is no repaired software version, acquire the system environment information of the business system, input the vulnerability information, the unrepaired software version, and the system environment information into a pre-trained machine learning model, and obtain the vulnerability repair method output by the pre-trained machine learning model to repair the vulnerability based on the vulnerability repair method.
[0135] Optionally, the patch file generation module 503 may include: A trigger condition determination sub-module, configured to determine a vulnerability trigger condition according to the vulnerability information; A target code location sub-module, configured to determine the code logic for repairing the vulnerability in the differential code according to the vulnerability trigger condition to obtain the target code.
[0136] Optionally, the target code location sub-module may include: A first test environment construction unit, configured to construct a first test environment according to the system environment information and the unrepaired software version; A second test environment construction unit, configured to construct a second test environment according to system environment information and a repaired software version; A first vulnerability triggering unit, configured to trigger a vulnerability in the first test environment by using a vulnerability triggering condition, and determine a first code segment that causes the vulnerability in the unrepaired software version; A second vulnerability triggering unit, configured to trigger a vulnerability in the second test environment by using a vulnerability triggering condition, and determine a second code segment that repairs the vulnerability in the repaired software version; A target code location unit, configured to determine a target code based on the first code segment, the second code segment, and the differential code.
[0137] Optionally, the device may further include: A patch verification environment construction module, configured to construct a verification environment according to system environment information and an unrepaired software version; A patch verification environment repair module, configured to repair the software by using a patch file in the verification environment; A patch verification module, configured to determine a vulnerability triggering condition of a vulnerability according to vulnerability information, and determine whether the repaired software cannot trigger the vulnerability according to the vulnerability triggering condition; if it is determined that the repaired software cannot trigger the vulnerability, it is determined that the patch file is valid; if it is determined that the repaired software can trigger the vulnerability, it is determined that the patch file is invalid.
[0138] Optionally, the device may further include: A repair method generation module, configured to generate a vulnerability repair method by using a patch file; A supplementary training data generation module, configured to generate supplementary training data by using vulnerability information, an unrepaired software version, system environment information, and a vulnerability repair method corresponding to the patch file; A supplementary training module, configured to perform supplementary training on a pre-trained machine learning model by using the supplementary training data.
[0139] Optionally, the repair method prediction module 504 may include: An input module, configured to combine vulnerability information, an unrepaired software version, and system environment information into original input data; An encoding module, configured to encode the original input data to obtain input data; A prediction module, configured to input the input data into a pre-trained machine learning model to obtain a vulnerability repair method output by the pre-trained machine learning model and a confidence level corresponding to the vulnerability repair method; An output module, configured to output the vulnerability repair method and the confidence level.
[0140] Optionally, the device may further include: A training data generation module, which is used to obtain historical vulnerability repair information and generate original training data by using the historical vulnerability repair information; the historical vulnerability repair information includes historical vulnerability information, historical unpatched software versions, historical system environment information, and historical vulnerability repair methods. A training data encoding module, which is used to encode the original training data to obtain training data. A training module, which is used to train a decision tree model by using the training data and use the trained decision tree model as a pre-trained machine learning model.
[0141] Optionally, the device may further include: A repair method verification environment construction module, which is used to construct a verification environment according to the system environment information and the unpatched software version. A repair method verification environment repair module, which is used to repair the software according to the vulnerability repair method in the verification environment. A repair method verification module, which is used to determine the vulnerability trigger condition of the vulnerability according to the vulnerability information and judge whether the patched software can no longer trigger the vulnerability according to the vulnerability trigger condition; if it is determined that the patched software cannot trigger the vulnerability, it is determined that the vulnerability repair method is effective; if it is determined that the patched software can trigger the vulnerability, it is determined that the vulnerability repair method is ineffective.
[0142] Optionally, after determining that the vulnerability repair method is effective, it may further include: A supplementary training data generation module, which is used to generate supplementary training data by using the vulnerability information, the unpatched software version, the system environment information, and the vulnerability repair method. A supplementary training module, which is used to perform supplementary training on the pre-trained machine learning model by using the supplementary training data.
[0143] Optionally, the device may further include: A repair module, which is used to repair the business system by using a patch file or a vulnerability repair method.
[0144] Optionally, the device may further include: A first information collection module, which is used to determine the general evaluation score and threat intelligence of the vulnerability according to the vulnerability information. A second information collection module, which is used to determine the asset information of the deployed software in the business system. A vulnerability level determination module, which is used to determine the vulnerability score of the vulnerability by using the general evaluation score, threat intelligence, and asset information, and determine the vulnerability repair level of the vulnerability according to the vulnerability score. A first vulnerability repair module, which is used to immediately perform the step of finding a repaired software version of the software with the repaired vulnerability for vulnerabilities whose vulnerability repair level is higher than the preset level. The second vulnerability repair module is used to, for vulnerabilities with a vulnerability repair level not higher than a preset level, wait for the business system to enter a low-load state and then execute the step of finding the repaired software version of the software with the repaired vulnerabilities.
[0145] Optionally, the vulnerability level determination module may include: A threat assessment module, which is used to determine the threat intelligence scores corresponding to the threat intelligence in at least two preset threat intelligence evaluation dimensions, and fuse the threat intelligence scores using the preset weights corresponding to the respective preset threat intelligence evaluation dimensions to obtain the total threat intelligence score; An asset evaluation module, which is used to determine the asset importance scores corresponding to the asset information in at least two preset asset evaluation dimensions, and fuse the asset importance scores using the preset weights corresponding to the respective preset asset evaluation dimensions to obtain the total asset importance score; A scoring module, which is used to determine the vulnerability score of the vulnerability using the general evaluation score, the total threat intelligence score, and the total asset importance score.
[0146] Optionally, the device may further include: An attack information acquisition module, which is used to acquire the attack information of the asset corresponding to the asset information; A weight adjustment module, which is used to adjust the preset weights corresponding to the respective preset asset evaluation dimensions according to the attack information.
[0147] For the descriptions of the features in the corresponding embodiments of the vulnerability handling device, reference may be made to the relevant descriptions in the corresponding embodiments of the vulnerability handling method, which will not be elaborated here one by one.
[0148] Please refer to Figure 6 , Figure 6 FIG. is a structural block diagram of an electronic device provided by an embodiment of the present invention. An embodiment of the present invention provides an electronic device 10, including a processor 11 and a memory 12; wherein, the memory 12 is used to store a computer program; the processor 11 is used to execute the vulnerability handling method provided in the foregoing embodiment when executing the computer program.
[0149] For the specific process of the foregoing vulnerability handling method, reference may be made to the corresponding content provided in the foregoing embodiments, and details will not be repeated here.
[0150] Moreover, as a carrier for resource storage, the memory 12 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the storage method may be temporary storage or permanent storage.
[0151] In addition, the electronic device 10 further includes a power supply 13, a communication interface 14, an input / output interface 15, and a communication bus 16. Among them, the power supply 13 is used to provide operating voltage for each hardware device on the electronic device 10. The communication interface 14 can create a data transmission channel between the electronic device 10 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present invention, and no specific limitation is imposed on it here. The input / output interface 15 is used to obtain external input data or output data to the outside, and the specific interface type can be selected according to specific application needs, and no specific limitation is made here.
[0152] An embodiment of the present invention further provides a non-volatile computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any of the above-mentioned embodiments of the vulnerability handling method when running.
[0153] In an exemplary embodiment, the above-mentioned computer-readable storage medium may include, but is not limited to: USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical disks, etc., various media that can store computer programs.
[0154] An embodiment of the present invention further provides a computer program product. The above-mentioned computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-mentioned embodiments of the vulnerability handling method.
[0155] An embodiment of the present invention further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-mentioned embodiments of the vulnerability handling method.
[0156] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0157] The above has introduced in detail a vulnerability handling method, an electronic device, a program product, and a storage medium provided by the present invention. Specific examples are used herein to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
Claims
1. A vulnerability handling method, characterized in that, Including: Obtain vulnerability information, and determine the unpatched software version corresponding to the software affected by the vulnerability in the business system according to the vulnerability information; Search whether the software has a patched software version that has fixed the vulnerability; If there is the patched software version, determine the difference code between the software code of the patched software version and the software code of the unpatched software version, determine the target code for fixing the vulnerability in the difference code, and generate a patch file based on the target code to fix the vulnerability based on the patch file; If there is no such patched software version, obtain the system environment information of the business system, input the vulnerability information, the unpatched software version, and the system environment information into a pre-trained machine learning model, and obtain the vulnerability repair method output by the pre-trained machine learning model to repair the vulnerability based on the vulnerability repair method.
2. The vulnerability handling method according to claim 1, wherein Determining the target code for fixing the vulnerability in the difference code includes: Determine the vulnerability trigger condition according to the vulnerability information; Determine the code logic for fixing the vulnerability in the difference code according to the vulnerability trigger condition to obtain the target code.
3. The vulnerability handling method according to claim 1, wherein After generating the patch file based on the target code, it further includes: Construct a verification environment according to the system environment information and the unpatched software version; In the verification environment, use the patch file to repair the software; Determine the vulnerability trigger condition of the vulnerability according to the vulnerability information, and judge whether the patched software can no longer trigger the vulnerability according to the vulnerability trigger condition; If it is determined that the patched software cannot trigger the vulnerability, determine that the patch file is valid; If it is determined that the patched software can trigger the vulnerability, determine that the patch file is invalid.
4. The vulnerability handling method according to claim 3, characterized in that, After determining that the patch file is valid, it further includes: Generate a vulnerability repair method using the patch file; Generate supplementary training data using the vulnerability information, the unpatched software version, the system environment information, and the vulnerability repair method corresponding to the patch file; Use the supplementary training data to perform supplementary training on the pre-trained machine learning model.
5. The vulnerability handling method according to claim 1, characterized in that, Inputting the vulnerability information, the unpatched software version, and the system environment information into a pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model includes: Combine the vulnerability information, the unpatched software version, and the system environment information into original input data; Encode the original input data to obtain input data; Input the input data into the pre-trained machine learning model to obtain the vulnerability repair method output by the pre-trained machine learning model and the confidence corresponding to the vulnerability repair method; Output the vulnerability repair method and the confidence.
6. The vulnerability handling method according to claim 5, wherein The training process of the pre-trained machine learning model includes: Obtain historical vulnerability repair information, and generate original training data using the historical vulnerability repair information; the historical vulnerability repair information includes historical vulnerability information, historical unpatched software version, historical system environment information, and historical vulnerability repair method; Encode the original training data to obtain training data; Train a decision tree model using the training data, and use the trained decision tree model as the pre-trained machine learning model.
7. The vulnerability handling method according to claim 1, wherein After obtaining the vulnerability repair method output by the pre-trained machine learning model, it further includes: Construct a verification environment according to the system environment information and the unpatched software version; In the verification environment, repair the software according to the vulnerability repair method; Determine the vulnerability trigger condition of the vulnerability according to the vulnerability information, and determine whether the repaired software can trigger the vulnerability according to the vulnerability trigger condition; If it is determined that the repaired software cannot trigger the vulnerability, it is determined that the vulnerability repair method is effective; If it is determined that the repaired software can trigger the vulnerability, it is determined that the vulnerability repair method is invalid.
8. The vulnerability handling method according to claim 7, wherein After determining that the vulnerability repair method is effective, it further includes: Generate supplementary training data using the vulnerability information, the unpatched software version, the system environment information, and the vulnerability repair method; Use the supplementary training data to perform supplementary training on the pre-trained machine learning model.
9. The vulnerability handling method according to claim 1, characterized in that It further includes: Repair the business system using the patch file or the vulnerability repair method.
10. The vulnerability handling method according to any one of claims 1 to 9, characterized in that, Before looking for a repaired software version that has fixed the vulnerability in the software, it further includes: Determine the general evaluation score and threat intelligence of the vulnerability according to the vulnerability information; Determine the asset information for deploying the software in the business system; Determine the vulnerability score of the vulnerability using the general evaluation score, the threat intelligence, and the asset information, and determine the vulnerability repair level of the vulnerability according to the vulnerability score; For vulnerabilities with a vulnerability repair level higher than the preset level, immediately perform the step of looking for a repaired software version that has fixed the vulnerability in the software; For vulnerabilities with a vulnerability repair level not higher than the preset level, wait until the business system enters a low-load state and then perform the step of looking for a repaired software version that has fixed the vulnerability in the software.
11. The vulnerability handling method according to claim 10, wherein Determining the vulnerability score of the vulnerability using the general evaluation score, the threat intelligence, and the asset information includes: Determine the threat intelligence scores corresponding to the threat intelligence in at least two preset threat intelligence evaluation dimensions, and use the preset weights corresponding to the preset threat intelligence evaluation dimensions to fuse the threat intelligence scores to obtain the total threat intelligence score; Determine the asset importance scores corresponding to the asset information in at least two preset asset evaluation dimensions, and use the preset weights corresponding to the preset asset evaluation dimensions to fuse the asset importance scores to obtain the total asset importance score; Determine the vulnerability score of the vulnerability using the general evaluation score, the total threat intelligence score, and the total asset importance score.
12. The vulnerability handling method according to claim 11, wherein It further includes: Obtain the attack information of the asset corresponding to the asset information; Adjust the preset weights corresponding to the preset asset evaluation dimensions according to the attack information.
13. An electronic device, characterized in that, It includes: A memory for storing a computer program; A processor for implementing the vulnerability handling method according to any one of claims 1 to 12 when executing the computer program.
14. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by a processor, it implements the vulnerability handling method according to any one of claims 1 to 12.
15. A non-volatile computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are loaded and executed by a processor, it implements the vulnerability handling method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Vulnerability code repairing method and system based on pre-training large model
CN118092998A
Vulnerability fixing method based on large model and related device
CN118445812A
Network threat analysis method and device, equipment and storage medium
CN119109704A
Network attack risk mapping assessment method and system
CN119583198A
Method for determining influenced function of system based on change code and related device
CN120045440A