Vulnerability severity assessment method and system based on vulnerability knowledge graph

By building a vulnerability knowledge graph and using GRU classifier to predict vulnerability severity, the problems of low accuracy and poor operability in the existing technology are solved, and a more efficient vulnerability severity assessment is achieved.

CN120296738APending Publication Date: 2025-07-11YANGZHOU UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311630454.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art has problems of low accuracy and poor operability in vulnerability assessment, especially in the absence of vulnerability elements, and the relationship between vulnerabilities cannot be effectively exploited.

Method used

Build an evaluation method based on vulnerability knowledge graph, and use the GRU classifier to predict vulnerability severity, combining the code and description information in the vulnerability knowledge graph for severity evaluation.

Benefits of technology

Improve the accuracy and operability of vulnerability severity assessment, effectively exploit the relationship between vulnerabilities, and reduce training costs and time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296738A_ABST
    Figure CN120296738A_ABST
Patent Text Reader

Abstract

The invention discloses a vulnerability severity assessment method and system based on a vulnerability knowledge graph. The method comprises the following steps: S1, acquiring a vulnerability report according to a CVE-ID number, and processing to form a vulnerability element labeling set; s2, training and generating an extraction model based on the vulnerability element labeling set, and extracting target vulnerability elements; s3, constructing a vulnerability knowledge graph based on the target vulnerability element, the description text, the vulnerability code and the CVE-ID number; s4, after representing the code nodes and the vulnerability description nodes, splicing the code nodes and the vulnerability description nodes to form corresponding CVE-ID representation; taking a vulnerability evaluation result as a label, taking the CVE-ID representation as input, and training to generate a GRU classifier; and S5, obtaining a to-be-evaluated vulnerability description text, predicting the size of a vulnerability severity index based on the extraction model, the vulnerability knowledge graph and the GRU classifier, and calculating the vulnerability severity level of the to-be-evaluated vulnerability description text according to the size of the vulnerability severity index. The method has the characteristics of high correlation, high accuracy and high operability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of software security, and particularly to a method and system for evaluating the severity of software vulnerabilities based on a vulnerability knowledge graph. Background Art

[0002] Software vulnerabilities can have a negative impact on the confidentiality, integrity, and availability of software systems. The negative impacts of software vulnerabilities mainly include attackers executing arbitrary code on the host, system denial of service, obtaining sensitive user information, etc. With the continuous increase in the number of vulnerabilities, it has become increasingly important to find critical vulnerabilities that need to be prioritized for remediation among a large number of software vulnerabilities. Therefore, the assessment of software vulnerability severity is very necessary.

[0003] Most of the previous vulnerability severity assessment work directly obtained the severity level by classifying the vulnerability description text. For example, "Learning to Predict Severity of Software Vulnerability Using Only Vulnerability Description" used a CNN classification model to train the severity level classification task on the complete vulnerability description text on CVE as of 2016. In "Automated Software Vulnerability Assessment with Concept Drift", the author proposed using more than 100,000 vulnerability description text data, training separately for different indicators of vulnerability severity, and combining time-based k-fold cross-validation to mitigate the problem of concept drift in vulnerability description text, learning the character-level and word-level representations of vulnerability description text, learning the features of each vulnerability severity indicator, and finally calculating the severity level. "Automatic software vulnerability assessment by extracting vulnerability elements" predicted six severity indicators by extracting vulnerability elements from the vulnerability description and using the vulnerability elements to replace the entire vulnerability description, and finally calculated the severity level. However, such tasks require a large amount of data sets for training, consuming a large amount of time and cost, and are not very operable.

[0004] Among the 133,639 reported vulnerability descriptions disclosed by CVE in the past 20 years, the CVEs lacking the cause of generation, attack vectors, and attackers accounted for 85%, 38%, and 28% respectively. This makes these methods for severity assessment using only vulnerability descriptions less effective when facing the lack of vulnerability elements. At the same time, existing methods only process individual vulnerability descriptions, do not consider the correlation between vulnerability descriptions, and ignore the relationship between vulnerabilities, that is, vulnerabilities with the same or similar vulnerability elements are more likely to have the same severity. In addition, it is difficult to describe the vulnerabilities existing in the code based on text descriptions, and there is a serious phenomenon of missing vulnerability elements in vulnerability descriptions. In other words, it is difficult for vulnerability descriptions to accurately and completely depict all the information of a vulnerability, which leads to poor results and low accuracy in severity assessment using only descriptions. Summary of the Invention

[0005] Object of the Invention: The object of the present invention is to provide a vulnerability severity assessment method and system based on a vulnerability knowledge graph with strong correlation, high accuracy, and strong operability.

[0006] Technical Solution: The vulnerability severity assessment method based on the vulnerability knowledge graph of the present invention includes the following steps:

[0007] S1. Obtain a vulnerability report according to the CVE-ID number, where the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, vulnerability description text, and vulnerability assessment result, and process the vulnerability description text to form a vulnerability element annotation set;

[0008] S2. Train and generate an extraction model based on the vulnerability element annotation set, and extract target vulnerability elements based on the extraction model;

[0009] S3. Construct a vulnerability knowledge graph based on the target vulnerability elements, vulnerability description text, vulnerability code, and CVE-ID number, where the vulnerability knowledge graph includes code nodes and vulnerability description nodes;

[0010] S4. After representing the code nodes and vulnerability description nodes and splicing them, form a corresponding CVE-ID representation; use the vulnerability assessment result as a label and the CVE-ID representation as an input to train and generate a GRU classifier;

[0011] S5. Obtain the vulnerability description text to be evaluated, and predict the size of the vulnerability severity index of the vulnerability description text to be evaluated based on the extraction model, vulnerability knowledge graph, and GRU classifier, and calculate the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity index.

[0012] Further, in step S1, the vulnerability description text includes the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario; the vulnerability element annotation set includes a number of vulnerability elements, and the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario correspond one-to-one with the vulnerability elements.

[0013] Further, in step S2, the following process is included:

[0014] S21. Perform BERT sequence annotation task training based on the vulnerability element annotation set until the model accuracy is satisfied, and output the training result;

[0015] S22. Connect the training result to the BiLSTM encoding layer and the CRF output layer to generate an extraction model;

[0016] S23. Based on the extraction model, extract target vulnerability elements from the vulnerability element annotation set multiple times.

[0017] Further, in steps S2 and S3, the target vulnerability elements include the text of the cause of the vulnerability, the text of the attacker, the text of the triggering operation, the text of the triggering result, and the text of the triggering scenario.

[0018] Further, the vulnerability knowledge graph includes several groups of nodes and the corresponding attribute type of the nodes, and several edges; the nodes include CVE-ID nodes and other nodes, and the several edges connect the CVE-ID nodes to other nodes in the several groups of nodes; the other nodes include vulnerability description nodes and vulnerability element nodes; the vulnerability element nodes include vulnerability description nodes, code nodes, triggering result nodes, attacker nodes, occurrence scenario nodes, and triggering operation nodes.

[0019] Further, in step S3, construct the vulnerability description node with the vulnerability description text, and the corresponding attribute type is vulnerability description; construct the CVE-ID node with the CVE-ID number, and the corresponding attribute type is ID number; construct the code node by slicing the vulnerability code through a program, and the corresponding type is vulnerability code.

[0020] Further, in step S5, the following steps are included:

[0021] S51. Extract all vulnerability elements from the vulnerability description text to be evaluated based on the extraction model;

[0022] S52. Use BLINK to perform entity linking between the vulnerability elements and the vulnerability knowledge graph to obtain the CVE-ID node that best matches the vulnerability description text to be evaluated, and accordingly obtain the code node that is uniquely connected to the CVE-ID node;

[0023] S53. Characterize the code nodes, characterize the vulnerability elements in text, and splice the code characterization and text characterization to form a CVE-ID node characterization;

[0024] S54. Input the CVE-ID node characterization into the GRU classifier to predict the size of the vulnerability severity indicator, and calculate and divide the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity indicator.

[0025] Further, in step S5, calculate the vulnerability severity score according to the size of the vulnerability severity indicator, and divide the vulnerability severity level according to the vulnerability severity score. The formula for calculating the vulnerability severity score is as follows:

[0026] BaseScore = (0.6 * Impact + 0.4 * Expoitability - 1.5) * f(Impact)

[0027] In the formula, BaseScore is the vulnerability severity score; Impact is the impact degree of the vulnerability severity indicator; Expoitability is one of the vulnerability severity indicators; f(Impact) is the impact indicator factor, which is calculated from the vulnerability severity indicator.

[0028] Further, the formula for dividing the vulnerability severity level is as follows:

[0029]

[0030] In the formula, BaseLevel is the vulnerability severity level; BaseScore is the vulnerability severity score; Low is the low quality of the evaluation classification result; Medium is the medium quality of the evaluation classification result; High is the high quality of the evaluation classification result.

[0031] Technical solution: The vulnerability severity evaluation system based on the vulnerability knowledge graph of the present invention includes:

[0032] A vulnerability element annotation set generation module, which is used to obtain a vulnerability report according to the CVE-ID number, and the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, vulnerability description text, and vulnerability evaluation result, and processes the vulnerability description text to form a vulnerability element annotation set;

[0033] An extraction model establishment module, which is used to train and generate an extraction model based on the vulnerability element annotation set, and extract target vulnerability elements based on the extraction model;

[0034] Vulnerability knowledge graph construction module, which is used to construct a vulnerability knowledge graph based on the target vulnerability elements, vulnerability description text, vulnerability code, and CVE-ID number. The vulnerability knowledge graph includes code nodes and vulnerability description nodes;

[0035] GRU classifier generation module, which is used to splice the code nodes and vulnerability description nodes after characterization to form a corresponding CVE-ID characterization; use the vulnerability assessment result as a label and the CVE-ID characterization as an input to train and generate a GRU classifier;

[0036] Vulnerability severity level assessment and calculation module, which is used to obtain the vulnerability description text to be evaluated, and based on the extraction model, vulnerability knowledge graph, and GRU classifier, predict the size of the vulnerability severity index of the vulnerability description text to be evaluated, and calculate the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity index.

[0037] Beneficial effects: The present invention has the following remarkable effects: 1. The present invention has strong relevance: fully considering the relationship between vulnerabilities, that is, vulnerabilities with the same or similar vulnerability elements are more likely to have similar severity levels. By constructing a vulnerability knowledge graph, information such as artificially defined vulnerability elements is represented in the graph, and the association between different vulnerability descriptions is constructed through the edges of the knowledge graph to realize the associated representation of different knowledge; 2. High accuracy: While using the vulnerability elements in the vulnerability description text to be evaluated, combining the code information of similar vulnerabilities in the constructed vulnerability knowledge graph to predict the severity index can effectively improve the accuracy of severity assessment; 3. Strong operability: The present invention does not require a large amount of training, saves time and cost, and is easy to operate. Brief Description of the Drawings

[0038] Figure 1 It is a schematic diagram of the overall process of the vulnerability severity assessment method of the present invention;

[0039] Figure 2 It is a schematic diagram of the annotation of the vulnerability description text of Example CVE-2011-0716;

[0040] Figure 3 It is a schematic diagram of the vulnerability event extraction model of Example CVE-2020-4061;

[0041] Figure 4 It is a schematic diagram of the entity link of the vulnerability elements of Example CVE-2020-16293 in the knowledge graph. Detailed Embodiment

[0042] The present invention will be further clarified below in conjunction with the drawings and specific embodiments.

[0043] Please refer to Figures 1 to 4As shown in the figure, the present invention discloses a vulnerability severity assessment method and system based on a vulnerability knowledge graph.

[0044] The vulnerability severity assessment method based on the vulnerability knowledge graph includes the following steps:

[0045] S1. Obtain a vulnerability report according to the CVE-ID number, where the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, vulnerability description text, and vulnerability assessment result, and process the description text to form a vulnerability element annotation set.

[0046] S2. Train and generate an extraction model based on the vulnerability element annotation set, and extract target vulnerability elements based on the extraction model.

[0047] S3. Construct a vulnerability knowledge graph based on the target vulnerability elements, description text, vulnerability code, and CVE-ID number. The vulnerability knowledge graph includes code nodes and vulnerability description nodes.

[0048] S4. Represent and splice the code nodes and vulnerability description nodes to form a corresponding CVE-ID representation; use the vulnerability assessment result as a label and the CVE-ID representation as an input to train and generate a GRU classifier.

[0049] S5. Obtain the vulnerability description text to be evaluated, and predict the size of the vulnerability severity index of the vulnerability description text to be evaluated based on the extraction model, vulnerability knowledge graph, and GRU classifier, and calculate the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity index.

[0050] The vulnerability severity assessment system based on the vulnerability knowledge graph includes:

[0051] A vulnerability element annotation set generation module for obtaining a vulnerability report according to the CVE-ID number, where the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, vulnerability description text, and vulnerability assessment result, and processes the description text to form a vulnerability element annotation set.

[0052] An extraction model establishment module for training and generating an extraction model based on the vulnerability element annotation set, and extracting target vulnerability elements based on the extraction model.

[0053] A vulnerability knowledge graph establishment module for constructing a vulnerability knowledge graph based on the target vulnerability elements, description text, vulnerability code, and CVE-ID number. The vulnerability knowledge graph includes code nodes and vulnerability description nodes.

[0054] The GRU classifier generation module is used to concatenate the representations of the code nodes and vulnerability description nodes to form the corresponding CVE-ID representation; use the vulnerability assessment result as a label and the CVE-ID representation as an input to train and generate a GRU classifier.

[0055] The vulnerability severity level assessment and calculation module is used to obtain the vulnerability description text to be evaluated, predict the size of the vulnerability severity index of the vulnerability description text to be evaluated based on the extraction model, vulnerability knowledge graph and GRU classifier, and calculate the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity index.

[0056] The method and system of the present invention will be specifically described below.

[0057] In step S1, in the vulnerability element annotation set generation module, the description text includes the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario. The vulnerability element annotation set includes several vulnerability elements, and the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario correspond to the vulnerability elements one by one. The vulnerability assessment result is used as a label for subsequent training of the GRU classifier, so that the GRU classifier can acquire knowledge and improve the accuracy of identification and classification.

[0058] Among them, vulnerability reports can be obtained from multiple different vulnerability databases. In this embodiment, vulnerability reports are crawled from two vulnerability databases (vulnerability database NVD, vulnerability database IBMX-Force) according to the CVE-ID number. Please refer to Figure 2 As shown, when processing the description text, the BIO annotation method is used to manually annotate the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario of the vulnerability to construct a vulnerability element annotation set. In the BIO annotation method, B (Begin) indicates that the word is the starting word of the vocabulary, I (Inside) indicates that the word is the middle character of the vocabulary, and O (Outside) indicates that the word does not represent any entity. For example, "when a certain Ethernet bridge configuration is used" is annotated as "B-sit I-sit I-sit I-sit I-sit I-sit I-sit I-sit". Please refer to Figure 2 As shown, it is a schematic diagram of the result after annotating the vulnerability description text of embodiment CVE-2011-0716.

[0059] In step S2, in the extraction model establishment module, the following process is included:

[0060] S21. Perform BERT sequence annotation task training based on the vulnerability element annotation set until the model accuracy is met, and output the training result.

[0061] S22. Connect the training result to the BiLSTM encoding layer and the CRF output layer to generate an extraction model, namely the BERT-BiLSTM-CRF extraction model. In the BiLSTM encoding layer, use the new BiLSTM network parameters When the score of each sentence in BiLSTM

[0062]

[0063] is the sum of the transition score and the network score, and the calculation formula is as follows: is the output matrix of BiLSTM; the element [f θ i,t is the score output by the neural network with parameter θ for the sentence and the i-th label at the t-th word; introduce a transition score [A] i,j to simulate the transition from the i-th state to the j-th state of consecutive time steps; is the transition score from the (t - 1)-th word to the t-th word; is the network score of the t-th word; is the label matrix of the sentence; T is the total number of words in the sentence; t is the position of the current word in the sentence; i is the label of the current word; θ is the neural network parameter of BiLSTM.

[0064] Please refer to Figure 3 as shown, for a specific example of the process of CVE-2020-4061 passing through the BERT+BiLSTM+CRF extraction model. The input text input with special symbols [CLS] and [SEP] inserted enters the BERT model and is converted into vectors (E[CLS], E[1], E[2], …, E[n], E[n+1], E[n+2], …), and after the BERT sequence labeling task, it is converted into vectors (C, T1, T2, T3, …, Tn, Tn+1, Tn+2, …), and after passing through the BiLSTM encoding layer and the CRF layer, the prediction result output of each word is obtained.

[0065] S23. Based on the extraction model, extract the target vulnerability elements from the vulnerability element annotation set multiple times.

[0066] In this embodiment, as shown in Table 1 below, the target vulnerability elements include the text of the cause of the vulnerability, the text of the attacker, the text of the triggering operation, the text of the triggering result, and the text of the triggering scenario.

[0067] Table 1 Explanation table of target vulnerability elements

[0068] ​

[0069]

[0070] In step S3, in the vulnerability knowledge graph building module, the vulnerability knowledge graph includes several groups of nodes and the corresponding attributes type of the nodes, and several edges. The nodes include CVE-ID nodes and other nodes, and the several edges connect the CVE-ID nodes with other nodes in the several groups of nodes. The other nodes include vulnerability description nodes and vulnerability element nodes. The vulnerability element nodes include code nodes, trigger result nodes, attacker nodes, occurrence scenario nodes, and trigger operation nodes. The several edges include "vulnerability description is" edge, "cause of generation is" edge, "trigger operation is" edge, "occurrence scenario is" edge, "attacker is" edge, and "trigger result is" edge. The specific implementation process of building the vulnerability knowledge graph is as follows: Connect the vulnerability description nodes, CVE-ID nodes, and vulnerability element nodes through several edges to form a vulnerability element relationship graph. The vulnerability code corresponding to each CVE-ID number is used as a code node and connected to the corresponding CVE-ID node after program slicing to form a vulnerability knowledge graph.

[0071] Among them, the vulnerability description node is constructed with the description text, and the corresponding attribute type is vulnerability description; the CVE-ID node is constructed with the CVE-ID number, and the corresponding attribute type is ID number; the code node is constructed by slicing the vulnerability code through the program, and the corresponding type is vulnerability code. Connect the CVE-ID node and the vulnerability description node with the "vulnerability description is" edge. Construct a cause of generation node with the cause of generation as the attribute Type and the specific cause of generation text as the value Value; connect the CVE-ID node and the cause of generation node with the "cause of generation is" edge. Construct a trigger operation node with the trigger operation as the attribute Type and the specific trigger operation text as the value Value; connect the CVE-ID node and the trigger operation node with the "trigger operation is" edge. Construct an occurrence scenario node with the occurrence scenario as the attribute Type and the specific occurrence scenario text as the value Value; connect the CVE-ID node and the occurrence scenario node with the "occurrence scenario is" edge. Construct an attacker node with the attacker as the attribute Type and the specific attacker text as the value Value; connect the CVE-ID node and the attacker node with the "attacker is" edge. Construct a trigger result node with the trigger result as the attribute Type and the specific trigger result text as the value Value; connect the CVE-ID node and the trigger result node with the "trigger result is" edge.

[0072] In step S4, in the GRU classifier generation module, use CodeBERT to represent the code node. Use Glove to represent the vulnerability description node.

[0073] Step S5. In the vulnerability severity level evaluation and calculation module, the following steps are included:

[0074] S51. Extract all vulnerability elements in the vulnerability description text to be evaluated based on the extraction model;

[0075] S52. Use BLINK to perform entity linking between the vulnerability elements and the vulnerability knowledge graph to obtain the CVE-ID node that best matches the vulnerability description text to be evaluated, and accordingly obtain the code node uniquely connected to the CVE-ID node. Among them, BLINK uses a two-stage method based on the fine-tuned BERT architecture for entity linking. In the first stage, BLINK performs retrieval in the dense space defined by the dual encoder, which independently embeds the mention context and entity description. Then a cross encoder is used to more carefully check each candidate, which concatenates the mention and entity text. Then, according to the entity linking result, the CVE-ID node that best matches the vulnerability description text to be evaluated is obtained, and the code node uniquely connected to this CVE-ID node is obtained. Please refer to Figure 4 as shown in the figure, it is a schematic diagram of the result after entity linking of the vulnerability elements of Example CVE-2020-16293 in the vulnerability knowledge graph.

[0076] S53. Characterize the code node, characterize the vulnerability elements in text, and splice the code characterization and text characterization to form a CVE-ID node characterization. Specifically, use CodeBERT to characterize the code information in the code node, and use Glove to characterize the extracted vulnerability elements in text.

[0077] S54. Input the CVE-ID node characterization into the GRU classifier to predict the size of the vulnerability severity index, and calculate and divide the vulnerability severity level of the vulnerability description text to be evaluated according to the size of the vulnerability severity index. Complete the vulnerability severity evaluation of the vulnerability description text to be evaluated. Specifically, calculate the vulnerability severity score according to the size of the vulnerability severity index, and divide the vulnerability severity level according to the vulnerability severity score. The formula for calculating the vulnerability severity score is as follows:

[0078] BaseScore = (0.6 * Impact + 0.4 * Expoitability - 1.5) * f(Impact)

[0079] In the formula, BaseScore is the vulnerability severity score; Impact is the impact degree of the vulnerability severity index; Expoitability is one of the vulnerability severity indexes; f(Impact) is the impact index factor, which is calculated from the vulnerability severity index.

[0080] The formula for dividing the vulnerability severity level is as follows:

[0081]

[0082] In the formula, BaseLevel is the vulnerability severity level; BaseScore is the vulnerability severity score; Low is the low quality of the evaluation classification result; Medium is the medium quality of the evaluation classification result; Higj is the high quality of the evaluation classification result.

[0083] In this embodiment, six vulnerability severity indicators are selected, please refer to Table 2, namely access complexity AccessComplexity, attack vector AccessVector, authentication Authentication, confidentiality impact ConfImpact, integrity impact IntegImpact, and availability impact AvailImpact. Among them, access complexity AccessComplexity indicates the complexity of the operations that the vulnerability attacker needs to perform to trigger a certain vulnerability. Attack vector AccessVector indicates the way in which the vulnerability attacker attacks. Authentication indicates how many times the vulnerability attacker needs to authenticate the attack. ConfImpact indicates the extent of file leakage caused to the user after the vulnerability attacker triggers the vulnerability. IntegImpact indicates the extent of file modification caused by the vulnerability attacker after triggering the vulnerability. AvailImpact indicates the extent of resource interruption caused by the vulnerability attacker after triggering the vulnerability.

[0084] Table 2 Vulnerability severity index table

[0085]

[0086]

[0087] Each of the above vulnerability severity indicators corresponds to a GRU classifier. Specifically, CodeBERT represents the code of the code nodes connected to each CVE-ID node with the "code is" edge, and uses Glove to represent the description text of the vulnerability description nodes connected to each CVE-ID node with the "vulnerability description is" edge. The representation dimensions are 300 dimensions. The two representation results are concatenated as the representation of the CVE-ID node. Taking the representation of the CVE-ID node as input and the six severity indicators corresponding to the CVE-ID as labels, six corresponding GRU classifiers are trained respectively.

[0088] In this embodiment, the classification results of the GRU classifier corresponding to the complexity AccessComplexity include low, medium, and high. The weight assigned to low is 0.350, the weight assigned to medium is 0.610, and the weight assigned to high is 0.710. The classification results of the three GRU classifiers corresponding to the confidentiality impact ConfImpact, integrity impact IntegImpact, and availability impact AvailImpact all include none, partial, and complete. The weight assigned to none is 0.000, the weight assigned to partial is 0.275, and the weight assigned to complete is 0.660. The classification results of the GRU classifier corresponding to the attack vector AccessVector include local, network, and adjacent network. The weight assigned to local is 0.395, the weight assigned to network is 0.646, and the weight assigned to adjacent network is 1.000. The classification results of the GRU classifier corresponding to the authentication Authentication include none, single, and multiple. The weight assigned to none is 0.704, the weight assigned to single is 0.560, and the weight assigned to multiple is 0.450.

[0089] Based on the weights of all the above classification results, calculate the vulnerability severity score BaseScore, and calculate the vulnerability severity level BaseLevel based on this. Among them, first calculate the impact Impact according to the confidentiality impact ConfImpact, integrity impact IntegImpact, and availability impact AvailImpact according to vulnerability formula (3) and judge f(Impact) according to formula (5). Secondly, calculate the exploitability Expoitability according to the access complexity AccessComplexity, attack vector AccessVector, and authentication Authentication according to formula (4), calculate the vulnerability severity score BaseScore according to formula (2), and substitute it into formula (6) to obtain the vulnerability severity level BaseLevel. When the value of the vulnerability severity score BaseScore is greater than or equal to 0 but less than or equal to 3.9, the vulnerability severity level BaseLevel is determined to be low. When the value of the vulnerability severity score BaseScore is greater than or equal to 4.0 but less than or equal to 6.9, the vulnerability severity level BaseLevel is determined to be medium. When the value of the vulnerability severity score BaseScore is greater than or equal to 7.0 but less than or equal to 10.0, the vulnerability severity level BaseLevel is determined to be high. The above-mentioned calculation formulas are as follows:

[0090] BaseScore = (0.6 * Impact + 0.4 * Expoitability - 1.5) * f(Impact) (2)

[0091] Impact = 10.41 * (1 - (1 - ConfImpact) * (1 - IntegImpact) * (1 - AvailImpact)) (3)

[0092] Expoitability = 20 * AccessComplexity * Authentication * AccessVector (4)

[0093]

[0094]

[0095] In the formula, f(Impact) is the impact index factor, which is calculated from the three indicators of ConfImpact, IntegImpact, and AvailImpact; * represents the multiplication operation; BaseLevel is the vulnerability severity level; BaseScore is the vulnerability severity score; Low is the low quality of the evaluation classification result; Medium is the medium quality of the evaluation classification result; High is the high quality of the evaluation classification result.

Claims

1. A vulnerability severity assessment method based on a vulnerability knowledge graph, characterized in that The method includes the following steps: S1. Obtain a vulnerability report according to the CVE-ID number, where the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, vulnerability description text, and vulnerability assessment result, and process the vulnerability description text to form a set of labeled vulnerability elements; S2. Train and generate an extraction model based on the set of labeled vulnerability elements, and extract target vulnerability elements based on the extraction model; S3. Construct a vulnerability knowledge graph based on the target vulnerability elements, vulnerability description text, vulnerability code, and CVE-ID number, where the vulnerability knowledge graph includes code nodes and vulnerability description nodes; S4. Represent and splice the code nodes and vulnerability description nodes to form a corresponding CVE-ID representation; use the vulnerability assessment result as a label and the CVE-ID representation as an input to train and generate a GRU classifier; S5. Obtain the text of the vulnerability description to be evaluated, and predict the size of the vulnerability severity index of the text of the vulnerability description to be evaluated based on the extraction model, vulnerability knowledge graph, and GRU classifier, and calculate the vulnerability severity level of the text of the vulnerability description to be evaluated according to the size of the vulnerability severity index.

2. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 1, wherein In step S1, the vulnerability description text includes the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario; the set of labeled vulnerability elements includes several vulnerability elements, and the cause of the vulnerability, the attacker, the triggering operation, the triggering result, and the triggering scenario correspond to the vulnerability elements one by one.

3. The vulnerability severity assessment method based on the vulnerability knowledge graph according to claim 1, wherein In step S2, it includes the following process: S21. Perform BERT sequence labeling task training based on the set of labeled vulnerability elements until the model accuracy is met, and output the training result; S22. Connect the training result to a BiLSTM encoding layer and a CRF output layer to generate an extraction model; S23. Extract target vulnerability elements from the set of labeled vulnerability elements multiple times based on the extraction model.

4. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 1, wherein In steps S2 and S3, the target vulnerability elements include the text of the cause of the vulnerability, the text of the attacker, the text of the triggering operation, the text of the triggering result, and the text of the triggering scenario.

5. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 4, characterized in that The vulnerability knowledge graph includes several groups of nodes and the corresponding attribute type of the nodes, and several edges; the nodes include CVE-ID nodes and other nodes, and the several edges connect the CVE-ID nodes to other nodes in the several groups of nodes; the other nodes include vulnerability description nodes and vulnerability element nodes; the vulnerability element nodes include vulnerability description nodes, code nodes, triggering result nodes, attacker nodes, occurrence scenario nodes, and triggering operation nodes.

6. The vulnerability severity assessment method based on the vulnerability knowledge graph according to claim 5, characterized in that In step S3, construct the vulnerability description node with the vulnerability description text, and the corresponding attribute type is vulnerability description; construct the CVE-ID node with the CVE-ID number, and the corresponding attribute type is ID number; construct the code node after slicing the vulnerability code through a program, and the corresponding type is vulnerability code.

7. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 1, wherein In step S5, it includes the following steps: S51. Extract all vulnerability elements in the text of the vulnerability description to be evaluated based on the extraction model; S52. Use BLINK to perform entity linking on the vulnerability elements and the vulnerability knowledge graph to obtain the CVE-ID node that best matches the text description of the vulnerability to be evaluated, and accordingly obtain the code node uniquely connected to the CVE-ID node; S53. Perform code representation on the code node, perform text representation on the vulnerability elements, and splice the code representation and the text representation to form a CVE-ID node representation; S54. Input the CVE-ID node representation into the GRU classifier to predict the magnitude of the vulnerability severity indicator, and calculate and divide the vulnerability severity level of the text description of the vulnerability to be evaluated according to the magnitude of the vulnerability severity indicator.

8. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 1, wherein In step S5, calculate the vulnerability severity score according to the magnitude of the vulnerability severity indicator, and divide the vulnerability severity level according to the vulnerability severity score; the formula for calculating the vulnerability severity score is as follows: BaseScore = (0.6 * Impact + 0.4 * Expoitability^1.5) * f(Impact) In the formula, BaseScore is the vulnerability severity score; Impact is the degree of impact of the vulnerability severity indicator; Expoitability is one of the vulnerability severity indicators; f(Impact) is the impact indicator factor, which is obtained by calculating the vulnerability severity indicator.

9. The vulnerability severity assessment method based on a vulnerability knowledge graph according to claim 8, characterized in that, The formula for dividing the vulnerability severity level is as follows: In the formula, BaseLevel is the vulnerability severity level; BaseScore is the vulnerability severity score; Low is the low quality of the evaluation classification result; Medium is the medium quality of the evaluation classification result; High is the high quality of the evaluation classification result.

10. A vulnerability severity assessment system based on a vulnerability knowledge graph, characterized in that, The system includes: A vulnerability element annotation set generation module, which is used to obtain a vulnerability report according to the CVE-ID number, where the CVE-ID number corresponds to the vulnerability report one by one; the vulnerability report includes vulnerability code, text description of the vulnerability, and vulnerability evaluation result, and processes the text description of the vulnerability to form a vulnerability element annotation set; An extraction model establishment module, which is used to train and generate an extraction model based on the vulnerability element annotation set, and extract target vulnerability elements based on the extraction model; A vulnerability knowledge graph establishment module, which is used to construct a vulnerability knowledge graph based on the target vulnerability elements, text description of the vulnerability, vulnerability code, and CVE-ID number, and the vulnerability knowledge graph includes a code node and a vulnerability description node; A GRU classifier generation module, which is used to splice the representations of the code node and the vulnerability description node to form a corresponding CVE-ID representation; use the vulnerability evaluation result as a label and the CVE-ID representation as an input to train and generate a GRU classifier; A vulnerability severity level evaluation and calculation module, which is used to obtain the text description of the vulnerability to be evaluated, and based on the extraction model, vulnerability knowledge graph, and GRU classifier, predict the magnitude of the vulnerability severity indicator of the text description of the vulnerability to be evaluated, and calculate the vulnerability severity level of the text description of the vulnerability to be evaluated according to the magnitude of the vulnerability severity indicator.

Citation Information

Cited By

  • Cloud platform vulnerability real-time quantitative analysis system based on dynamic knowledge graph

    CN121125242A

  • Cloud platform vulnerability real-time quantitative analysis system based on dynamic knowledge graph

    CN121125242B