Asset vulnerability repairing method and device, electronic equipment and storage medium
By identifying, evaluating and optimizing asset vulnerabilities, using vulnerability detection fusion model and multi-dimensional evaluation model, a fast and effective repair plan is generated, solving the problem of long-term vulnerability defense measures in the existing technology, and achieving efficient vulnerability management and security improvement.
Patent Information
- Application Number
- CN202510421924.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-22
AI Technical Summary
The existing security vulnerability defense solutions rely on the accuracy and completeness of asset information, the integrity of vulnerability information database and vulnerability response script, which makes it time-consuming to discover vulnerabilities and take effective defense measures, and are not efficient and timely.
The vulnerability detection fusion model is used to identify potential vulnerabilities in the asset association map, combine the multi-dimensional vulnerability assessment model to evaluate vulnerability scores, and generate repair plans through the repair strategy optimization model, including fuzzy matching mechanism, version derivation mechanism and vulnerability propagation identification mechanism. The general vulnerability scoring mechanism CVSS, business impact assessment mechanism and environmental impact assessment mechanism are used to generate N repair plans to be selected and optimized through the integer planning model to finally determine the repair plan.
It realizes the accurate and rapid identification, evaluation and repair of asset vulnerabilities, expands the adaptability to emerging vulnerabilities, reduces the time-consuming discovery and repair, improves the efficiency and timeliness of asset management, and improves security and reliability.
Smart Images

Figure CN120355149A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security scanning, and particularly to a method, apparatus, electronic device, and computer-readable storage medium for repairing asset vulnerabilities. Background Art
[0002] Existing security vulnerability defense solutions usually achieve comprehensive network security protection through steps such as asset information collection, vulnerability information database query, response playbook generation, automated execution, defense strategy management, and monitoring and alarming.
[0003] However, when entering asset information, human errors may occur, such as entering incorrect asset models or version numbers; asset information is not updated in a timely manner, resulting in outdated vulnerability information that cannot reflect the true situation of the current device; there are some devices that may not have complete asset information, such as old devices or non-standard devices, resulting in the inability to query corresponding vulnerability information in the vulnerability information database. In addition, since the update of vulnerability information takes a certain amount of time, newly emerged vulnerabilities or unknown asset models and versions may not have been incorporated into the vulnerability information database yet. Therefore, newly emerged vulnerabilities or unknown asset models and versions may not be able to match the corresponding vulnerability response playbook in a timely manner; even if newly emerged vulnerabilities or unknown asset models and versions have been updated to the vulnerability information database, it may also take a certain amount of time to develop and test their corresponding vulnerability response playbooks, which may lead to the inability to take effective defense measures in a timely manner for some time after the vulnerabilities are discovered.
[0004] In summary, the existing security vulnerability defense solutions rely on the accuracy and integrity of asset information, the integrity and effectiveness of the vulnerability information database, and the vulnerability response playbook, resulting in a long time-consuming process for discovering vulnerabilities and taking effective defense measures, with low efficiency and timeliness. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method, apparatus, electronic device, and computer-readable storage medium for repairing asset vulnerabilities in view of the above deficiencies of the prior art. This method can accurately and quickly identify, evaluate, and repair asset vulnerabilities, expand the adaptability to newly emerged asset vulnerabilities, reduce the time-consuming for discovering and repairing asset vulnerabilities, improve the efficiency and timeliness of asset vulnerability management, and enhance the security and reliability of assets.
[0006] In a first aspect, the present invention provides a method for repairing asset vulnerabilities, including: identifying potential asset vulnerabilities of an asset association graph at the current moment based on a vulnerability detection fusion model; evaluating a vulnerability score of the potential asset vulnerabilities at the current moment based on a multi-dimensional vulnerability evaluation model; and determining a repair plan for the potential asset vulnerabilities at the current moment based on the vulnerability score and a repair strategy optimization model.
[0007] Preferably, before identifying potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model, the asset vulnerability repair method further includes: collecting multimodal data of all assets from the platform server, database, web application, and third-party services based on a vulnerability scanning tool; classifying and identifying the multimodal data, and inferring the topological relationship between all assets; and associating the multimodal data based on the topological relationship between all assets to form an asset association graph.
[0008] Preferably, the vulnerability detection fusion model includes a fuzzy matching mechanism, a version derivation mechanism, and a vulnerability propagation identification mechanism. Identifying potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model specifically includes: evaluating the integrity of the asset models of all assets in the asset association graph at the current moment based on the fuzzy matching mechanism, where the integrity of the asset model refers to the Levenshtein distance between the asset model information and the preset asset signal information; deriving the asset version numbers of all assets in the asset association graph at the current moment based on the version derivation mechanism; and determining the potential asset vulnerabilities in the asset association graph at the current moment based on the integrity of the asset model at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism.
[0009] Preferably, determining the potential asset vulnerabilities in the asset association graph at the current moment based on the integrity of the asset model at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism specifically includes: determining a first asset and a second asset, where the first asset refers to an asset with the integrity of the asset model less than a preset value at the current moment, and the second asset refers to an asset with the asset version number being the preset asset version number at the current moment; identifying a third asset based on the vulnerability propagation identification mechanism, where the third asset refers to an asset in the asset association graph that has a dependency relationship with the first asset or the second asset; and summarizing the first asset, the second asset, and the third asset to obtain the potential asset vulnerabilities in the asset association graph at the current moment.
[0010] Preferably, the multi-dimensional vulnerability assessment model includes a Common Vulnerability Scoring System (CVSS), a business impact assessment mechanism, and an environmental impact assessment mechanism. Evaluating the vulnerability score of the potential asset vulnerabilities at the current moment based on the multi-dimensional vulnerability assessment model specifically includes: evaluating the base score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerabilities at the current moment based on the Common Vulnerability Scoring System (CVSS), the business impact assessment mechanism, and the environmental impact assessment mechanism respectively; and calculating the vulnerability score of the potential asset vulnerabilities at the current moment based on the base score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerabilities at the current moment.
[0011] Preferably, calculating the vulnerability score of the potential asset vulnerability at the current moment based on the basic score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerability at the current moment specifically includes: calculating the vulnerability score of the potential asset vulnerability at the current moment according to formula (1):
[0012]
[0013] where CVSS represents the basic score of the potential asset vulnerability at the current moment, BI represents the business impact factor of the potential asset vulnerability at the current moment, ASF represents the environmental attack surface coefficient of the potential asset vulnerability at the current moment, W CVSS represents the weight factor of CVSS, W business represents the weight factor of BI, W ASF represents the weight factor of ASF, α represents the time decay factor, α = 0.1, and Δt represents the time interval between identifying the potential asset vulnerability in the asset association graph at the current moment and evaluating the vulnerability score of the potential asset vulnerability at the current moment.
[0014] Preferably, the repair strategy optimization model includes a repair plan aggregation model and an integer programming model. Determining the repair plan for the potential asset vulnerability at the current moment based on the vulnerability score and the repair strategy optimization model specifically includes: generating N alternative repair plans for the potential asset vulnerability at the current moment based on the repair plan aggregation model, where N represents a positive integer greater than 1; inputting the vulnerability score and the N alternative repair plans into the integer programming model, and respectively evaluating the coverage of the N alternative repair plans for the potential asset vulnerability at the current moment; determining the repair plan for the potential asset vulnerability at the current moment based on the coverage.
[0015] Preferably, generating N alternative repair plans for the potential asset vulnerability at the current moment based on the repair plan aggregation model specifically includes: obtaining historical repair plans and extracting the atomic features of the historical repair plans, where the historical repair plans refer to all repair plans for the potential asset vulnerabilities in the asset association graph before the current moment, and the atomic features include affected services, required permissions, and restart requirements; clustering the historical repair plans based on the similarity calculation formula and the atomic features of the historical repair plans to obtain a historical repair item set, where the similarity calculation formula includes the Jaccard coefficient calculation formula; mining frequent repair item sets from the historical repair item set based on the frequent item set mining algorithm, and generating N alternative repair plans for the potential asset vulnerability at the current moment, where the frequent item set mining algorithm includes the frequent pattern tree FP-Growth algorithm.
[0016] In a second aspect, the present invention further provides a device for repairing asset vulnerabilities, including an identification module, an evaluation module, and a determination module. The identification module is configured to identify potential asset vulnerabilities in the asset association graph at the current moment based on a vulnerability detection fusion model. The evaluation module is connected to the identification module and is configured to evaluate the vulnerability score of the potential asset vulnerabilities at the current moment based on a multi-dimensional vulnerability evaluation model. The determination module is connected to the evaluation module and is configured to determine a repair plan for the potential asset vulnerabilities at the current moment based on the vulnerability score and a repair strategy optimization model.
[0017] In a third aspect, the present invention further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to implement the method for repairing asset vulnerabilities provided in the first aspect above.
[0018] In a fourth aspect, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for repairing asset vulnerabilities provided in the first aspect above is implemented.
[0019] A method, device, electronic device, and computer-readable storage medium for repairing asset vulnerabilities provided by the present invention identify, evaluate, and repair potential asset vulnerabilities through a vulnerability detection fusion model, a multi-dimensional vulnerability evaluation model, and a repair strategy optimization model, improving the timeliness and adaptability of potential asset vulnerability identification, potential asset vulnerability evaluation, and repair plan generation. Therefore, the present invention can accurately and quickly identify, evaluate, and repair asset vulnerabilities, expand the adaptability to newly emerging asset vulnerabilities, reduce the time consumed for discovering and repairing asset vulnerabilities, improve the efficiency and timeliness of asset vulnerability management, and enhance the security and reliability of assets. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a flowchart of a method for repairing asset vulnerabilities according to Embodiment 1 of the present invention;
[0021] Figure 2 It is a flowchart of a method for isolating potential asset vulnerabilities in Embodiment 1 of the present invention;
[0022] Figure 3 It is a flowchart of another method for isolating potential asset vulnerabilities in Embodiment 1 of the present invention;
[0023] Figure 4 It is a flowchart of a method for repairing asset vulnerabilities according to Embodiment 2 of the present invention;
[0024] Figure 5 It is a flowchart of another method for repairing asset vulnerabilities according to Embodiment 2 of the present invention;
[0025] Figure 6Schematic diagram of a structure of a repair device for asset vulnerabilities according to Embodiment 3 of the present invention. Detailed implementation manners
[0026] To enable those skilled in the art to better understand the technical solutions of the present invention, the following will further describe in detail the embodiments of the present invention with reference to the accompanying drawings.
[0027] It can be understood that the specific embodiments and accompanying drawings described herein are only used to explain the present invention, rather than limiting the present invention.
[0028] It can be understood that, without conflict, the various embodiments in the present invention and the features in the embodiments can be combined with each other.
[0029] It can be understood that, for the convenience of description, only the parts related to the present invention are shown in the accompanying drawings of the present invention, and the parts unrelated to the present invention are not shown in the accompanying drawings.
[0030] It can be understood that each unit and module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units and modules may also be integrated into one entity structure.
[0031] It can be understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the accompanying drawings.
[0032] It can be understood that in the flowcharts and block diagrams of the present invention, the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present invention are shown. Among them, each block in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified function. Moreover, each block or combination of blocks in the block diagram and flowchart can be implemented by a hardware-based system for implementing the specified function, or by a combination of hardware and computer instructions.
[0033] It can be understood that the units and modules involved in the embodiments of the present invention can be implemented in software or in hardware. For example, the units and modules can be located in the processor.
[0034] Embodiment 1:
[0035] As Figure 1 shown, this embodiment provides a method for repairing asset vulnerabilities. The method for repairing asset vulnerabilities includes:
[0036] S101, based on the vulnerability detection fusion model, identify potential asset vulnerabilities in the asset association graph at the current moment.
[0037] In this embodiment, the asset association graph refers to a visual or structured information graph used to display the relationships between assets. The asset association graph includes: various asset nodes (such as platform servers, databases, web application programs, and third-party services), attributes of various asset nodes (such as multi-modal data collected from platform servers, databases, web application programs, and third-party services respectively), and edges between various asset nodes. Potential asset vulnerabilities refer to assets that may have security weaknesses or defects. Due to different security weaknesses or defects existing in assets, potential asset vulnerabilities can be classified into different types. Among them, the types of potential asset vulnerabilities include, but are not limited to: SQL (Structured Query Language) injection vulnerabilities.
[0038] Optionally, before S101: Based on the vulnerability detection fusion model, identifying potential asset vulnerabilities in the asset association graph at the current moment, the asset vulnerability repair method further includes:
[0039] S104, collecting multi-modal data of all assets from platform servers, databases, web application programs, and third-party services based on a vulnerability scanning tool.
[0040] In this embodiment, the multi-modal data of assets refers to data of different types and formats related to assets. The multi-modal data includes, but is not limited to: numerical data, text data, image and video data, time series data, network data, and sensor data. The vulnerability scanning tool is respectively connected to platform servers, databases, web application programs, and third-party services, and through the vulnerability scanning tool, three methods of active scanning (port detection), passive listening (network traffic analysis), and configuration management database (CMDB, Configuration Management Database) synchronization audit are integrated to collect multi-modal data of all assets from platform servers, databases, web application programs, and third-party services at a preset cycle. Among them, the vulnerability scanning tool includes, but is not limited to: Qualys and Nessus. By automatically collecting the multi-modal data of assets in this embodiment, the manual workload and cost can be reduced, and with the help of multi-modal data, an asset association graph integrating multiple perspectives can be obtained, improving the accuracy of the relationships and dependencies between assets, and further improving the efficiency and accuracy of subsequent identification, assessment, and repair of potential asset vulnerabilities.
[0041] It should be noted that after collecting the multimodal data of all assets from the platform server, database, web application, and third-party services at a preset cycle, this embodiment also standardizes the multimodal data through a feature extractor, and performs multimodal biometric fusion verification on the multimodal data through a cross-device collaborative verification mechanism, an enhanced authentication mechanism based on zero-knowledge proof, and a dynamic access credential management mechanism. Among them, the dynamic access credential management mechanism includes, but is not limited to, the RBAC (Role-Based Access Control) mechanism. By implementing strict access management and multiple authentication mechanisms, this embodiment ensures that only authorized personnel can access specific storage media, effectively reducing the risks of data leakage and unauthorized access, and solving the security hidden danger of lax access management of storage media in the past.
[0042] Multimodal biometric fusion verification is achieved through a cross-device collaborative verification mechanism, which specifically includes: ① Terminal device -> Authentication server: Submit the main feature hash H1; ② Authentication server -> Terminal device APP (application) pushes an auxiliary verification request; ③ Terminal device APP -> Authentication server: Return the dynamic signature S = Sign(H1IIT); ④ Authentication server --> Terminal device: Release the access token if and only if Verify(S) = True.
[0043] Multimodal biometric fusion verification is achieved through an enhanced authentication mechanism based on zero-knowledge proof, which specifically includes: Using zk-SNARKs to construct the authentication process, that is:
[0044] Prover:
[0045] Generate the proof π = Prove(CRS, (pwd_hash, salt), access_policy)
[0046] Verifier:
[0047] Verify Check(CRS, n, access_policy) == 1. Among them, CRS (Common Reference String) represents the common reference string, pwd_hash represents the password hash based on Argon2id, and salt represents a 256-bit random salt value.
[0048] Multimodal biometric fusion verification is achieved through a dynamic access credential management mechanism, which specifically includes: Establishing a time decay factor model: Among them, t half = 8h, t halfIndicates the half-life, k = 0.2, where k represents the decay rate, BaseTrust represents the base trust value, and TrustLevel(t) represents the trust level at time t.
[0049] Before collecting the multimodal data of all assets from the platform server, database, web application, and third-party services at a preset cycle, this embodiment also sets the preset cycle by evaluating the security levels of the platform server, database, web application, and third-party services and according to the security levels and business requirements. For example, the platform server, database, web application, and third-party services with a high security level require a higher collection frequency, that is, a shorter preset cycle. By evaluating the security levels of the platform server, database, web application, and third-party services to set the preset cycle for multimodal data collection, this embodiment can detect the latest security vulnerabilities more accurately and comprehensively, improve the security of the system, solve the situation of possible missed detection or false detection in traditional vulnerability detection methods, and improve the accuracy and comprehensiveness of vulnerability detection.
[0050] Evaluating the security levels of the platform server, database, web application, and third-party services specifically includes: using a time series analysis model or machine learning algorithm to model the historical threat events of the platform server, database, web application, and third-party services to predict the threat probability of the platform server, database, web application, and third-party services at future times; evaluating the business importance of the platform server, database, web application, and third-party services, and combining the business importance of the platform server, database, web application, and third-party services and the value of key assets (such as data sensitivity, service interruption cost) to calculate the impact degree of the platform server, database, web application, and third-party services; constructing a risk matrix of the platform server, database, web application, and third-party services according to the threat probability of the platform server, database, web application, and third-party services at future times, the impact degree of the platform server, database, web application, and third-party services, and the formula: threat risk score = threat probability × impact degree; evaluating the vulnerability score of the platform server, database, web application, and third-party services according to the historical threat events of the platform server, database, web application, and third-party services; constructing a security level evaluation model according to the risk matrix, vulnerability score, and analytic hierarchy process of the platform server, database, web application, and third-party services, that is: security level = (threat risk score × weight 1) + (vulnerability score × weight 2) to evaluate the security levels of the platform server, database, web application, and third-party services.
[0051] In this embodiment, by analyzing the interruption costs, user impact scopes, and data sensitivities of the platform server, database, web application, and third-party services, the weights of the interruption costs, user impact scopes, and data sensitivities are determined, and a hierarchical structure model is constructed through the analytic hierarchy process, that is: Business Importance = Σ(Rating Index × Corresponding Weight), to evaluate the business importance of the platform server, database, web application, and third-party services. Among them, the rating indexes include, but are not limited to: interruption costs, user impact scopes, and data sensitivities.
[0052] This embodiment can also construct a comprehensive evaluation model based on the business importance, risk matrix, vulnerability score, and analytic hierarchy process of the platform server, database, web application, and third-party services. For example: Comprehensive Score = (Threat Risk Score × 0.4) + (Vulnerability Score × 0.3) + (Business Importance × 0.3). Then, according to the comprehensive score, the platform server, database, web application, and third-party services are divided into three security levels: high, medium, and low. This embodiment evaluates the security levels of the platform server, database, web application, and third-party services through business importance, risk matrix, vulnerability score, and analytic hierarchy process, improves the accuracy of security level evaluation, and then reasonably and flexibly sets the preset cycle of multi-modal data collection, improving the accuracy and comprehensiveness of vulnerability detection.
[0053] Time series analysis models include, but are not limited to: ARIMA (Autoregressive Integrated Moving Average) models, and machine learning algorithms include, but are not limited to: random forest, XGBoost (eXtreme Gradient Boosting).
[0054] S105, classify and label multi-modal data, and infer the topological relationships between all assets.
[0055] In this embodiment, based on protocol features, service fingerprints, and device fingerprints, multi-modal data is classified and labeled. Among them, protocol features include, but are not limited to: TCP / IP (Transmission Control Protocol / Internet Protocol) fingerprints, service fingerprints include, but are not limited to: HTTP (Hypertext Transfer Protocol) header features, and device fingerprints include, but are not limited to: MAC (Media Access Control) manufacturer identifiers.
[0056] Perform traffic analysis on the classified and labeled multimodal data to infer the topological relationships between all assets, specifically including: identifying the traffic patterns of all assets in the classified and labeled multimodal data, where the traffic patterns include the source, destination, traffic volume, and transmission frequency of data packets; based on the traffic patterns of all assets, identifying the topological relationships between each asset. In this embodiment, by classifying and labeling multimodal data and inferring the topological relationships between assets, the accuracy of the relationships and dependencies between assets is improved, making it easier to find potential security vulnerabilities and risks subsequently and taking targeted measures to repair them, thereby improving the overall security.
[0057] S106, based on the topological relationships between all assets, associate multimodal data to form an asset association graph.
[0058] In this embodiment, graph theory or network analysis methods are used to associate multimodal data to form an asset association graph. Through the asset association graph in this embodiment, data support can be provided for subsequent identification, evaluation, and repair of potential asset vulnerabilities, and furthermore, it can help enterprises make more informed decisions in terms of security policies, resource allocation, and risk management. In addition, the real-time asset association graph enables the security team to monitor the interactions between assets at any time, quickly respond to detected anomalies, and dispose of security incidents in a timely manner.
[0059] Specifically, the vulnerability detection fusion model includes a fuzzy matching mechanism, a version derivation mechanism, and a vulnerability propagation identification mechanism.
[0060] Specifically, S101: Based on the vulnerability detection fusion model, identify the potential asset vulnerabilities of the asset association graph at the current moment, including steps S1011 - S1013:
[0061] S1011, based on the fuzzy matching mechanism, evaluate the asset model integrity of all assets in the asset association graph at the current moment, where the asset model integrity refers to the Levenshtein distance between the asset model information and the preset asset signal information.
[0062] In this embodiment, the fuzzy matching mechanism includes, but is not limited to, the Levenshtein distance algorithm. For example, if the asset model in the asset association graph is "C3850" and its preset asset signal information is "WS-C3850-24T", this embodiment can use the Levenshtein distance algorithm to match "C3850" with "WS-C3850-24T" to evaluate the asset model integrity.
[0063] S1012, based on the version derivation mechanism, derive the asset version numbers of all assets in the asset association graph at the current moment.
[0064] In this embodiment, the version derivation mechanism includes, but is not limited to, semantic version rules. For example, based on the semantic version rules, the asset version number of the assets in the asset association graph is derived as v3.2.1.
[0065] S1013. Based on the asset model integrity at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism, determine the potential asset vulnerabilities in the asset association graph at the current moment.
[0066] In this embodiment, through the fuzzy matching mechanism, the version derivation mechanism, and the vulnerability propagation identification mechanism, potential asset vulnerabilities with similar but possibly not fully matched asset models, potential asset vulnerabilities with incorrect asset version numbers, and assets penetrated or affected by potential asset vulnerabilities can be effectively identified respectively, covering more potential risks and increasing the comprehensiveness and accuracy of vulnerability detection; by integrating the fuzzy matching mechanism, the version derivation mechanism, and the vulnerability propagation identification mechanism, the rapid identification of potential asset vulnerabilities is achieved, the speed of vulnerability response and repair is accelerated, the attack surface is reduced, and the overall security situation awareness is improved.
[0067] Specifically, S1013: Based on the asset model integrity at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism, determine the potential asset vulnerabilities in the asset association graph at the current moment, including: determining a first asset and a second asset, where the first asset refers to an asset with an asset model integrity less than a preset value at the current moment, and the second asset refers to an asset with a preset asset version number at the current moment; based on the vulnerability propagation identification mechanism, identify a third asset, where the third asset refers to an asset in the asset association graph that has a dependency relationship with the first asset or the second asset; summarize the first asset, the second asset, and the third asset to obtain the potential asset vulnerabilities in the asset association graph at the current moment.
[0068] In this embodiment, it is determined whether the asset integrity of an asset is less than a preset value; if the asset integrity of the asset is less than the preset value, for example, the asset integrity is less than 50%, the asset is determined to be a first asset, and it is determined that the potential asset vulnerabilities include the first asset. It is determined whether the asset version number of the asset is a preset asset version number; if the asset version number of the asset is the preset asset version number, the asset is determined to be a second asset, and it is determined that the potential asset vulnerabilities include the second asset. For example, when it is known that there is a vulnerability in asset version number v3.2.1, all assets with asset version number v3.2.x are potential asset vulnerabilities. In addition, after determining the potential asset vulnerabilities based on the asset model integrity and the asset version number, this embodiment further uses a vulnerability propagation identification mechanism to determine whether the current asset has a dependency relationship with the first asset or the second asset; if the current asset has a dependency relationship with the first asset or the second asset, the current asset is determined to be a third asset, and it is determined that the potential asset vulnerabilities include the third asset, where the vulnerability propagation identification mechanism includes, but is not limited to: a CVE (Common Vulnerabilities & Exposures) dependency graph.
[0069] S102. Based on the multi-dimensional vulnerability assessment model, evaluate the vulnerability score of the potential asset vulnerabilities at the current moment.
[0070] Specifically, the multi-dimensional vulnerability assessment model includes a Common Vulnerability Scoring System (CVSS), a business impact assessment mechanism, and an environmental impact assessment mechanism.
[0071] Specifically, S102: Based on the multi-dimensional vulnerability assessment model, evaluate the vulnerability score of the potential asset vulnerabilities at the current moment, including steps S1021 - S1023:
[0072] S1021. Based on the Common Vulnerability Scoring System (CVSS), the business impact assessment mechanism, and the environmental impact assessment mechanism, respectively evaluate the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment.
[0073] In this embodiment, based on the Common Vulnerability Scoring System (CVSS), the business impact assessment mechanism, and the environmental impact assessment mechanism, the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerability at the current moment are evaluated respectively, specifically including: evaluating the basic score CVSS of the potential asset vulnerability at the current moment according to the formula CVSS = Roundup(Min[(Impact + Exploitability), 10]), where Roundup(·) represents a rounding function, Min[X, Y] represents the minimum value of X and Y, Impact represents the impact score of the potential asset vulnerability, and Exploitability represents the exploitability score of the potential asset vulnerability; constructing an impact factor matrix according to the Analytic Hierarchy Process (AHP). And according to the formula BI = ∑(W i × ImpactLevel i ), evaluating the business impact factor BI of the potential asset vulnerability at the current moment, where W i represents the impact factor of the i-th business element of the potential asset vulnerability, a ij represents the importance ratio of the i-th business element (such as data sensitivity, service continuity) of the potential asset vulnerability relative to the j-th element of the potential asset vulnerability, n represents the total number of business elements of the potential asset vulnerability, k represents the index of the business element in the impact factor matrix, represents the sum of the importance ratios of all business elements in the impact factor matrix to the j-th element, and ImpactLevel i represents the impact level of the potential asset vulnerability; according to the formula evaluating the environmental attack surface coefficient of the potential asset vulnerability at the current moment, where ExposedServices represents the number of services publicly accessible on the network for the potential asset vulnerability, VulnerabilityAge represents the time length since the potential asset vulnerability was identified, and PatchApplicability represents the patch applicability of the potential asset vulnerability.
[0074] It should be noted that Impact is calculated by evaluating the impact of potential asset vulnerabilities on information leakage, the impact on data integrity and credibility, and the impact on system availability. Exploitability is calculated by determining whether the attacker of the potential asset vulnerability requires physical contact, local network access, or Internet remote attack, whether the attacker of the potential asset vulnerability needs to authenticate in a preset manner to exploit the potential asset vulnerability, and evaluating the skill level required for the attacker of the potential asset vulnerability to exploit the potential asset vulnerability. The ImpactLevel of different potential asset vulnerabilities is evaluated through historical potential asset vulnerabilities i 。
[0075] S1022. Calculate the vulnerability score of the potential asset vulnerability at the current moment based on the basic score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerability at the current moment
[0076] Specifically, S1022: Calculate the vulnerability score of the potential asset vulnerability at the current moment based on the basic score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerability at the current moment, including: Calculate the vulnerability score of the potential asset vulnerability at the current moment according to formula (1):
[0077]
[0078] Among them, CVSS represents the basic score of the potential asset vulnerability at the current moment, BI represents the business impact factor of the potential asset vulnerability at the current moment, ASF represents the environmental attack surface coefficient of the potential asset vulnerability at the current moment, W CVSS represents the weight factor of CVSS, W business represents the weight factor of BI, W ASF represents the weight factor of ASF, α represents the time decay factor, α = 0.1, and Δt represents the time interval between identifying the potential asset vulnerability in the asset association graph at the current moment and evaluating the vulnerability score of the potential asset vulnerability at the current moment
[0079] In this embodiment, the analytic hierarchy process is used to construct the initial vulnerability assessment model (i.e., formula W CVSS ×CVSS + W business ×BI + W ASF×ASF), and then adjusts the initial vulnerability assessment model using a time decay factor to obtain Equation (1) for calculating the vulnerability score of potential asset vulnerabilities at the current moment. The vulnerability assessment models of the prior art usually only include the Common Vulnerability Scoring System (CVSS), with relatively poor accuracy of the vulnerability assessment model. The vulnerability assessment is limited to the risks brought by its own characteristics, lacking sufficient security situation awareness, thus resulting in low accuracy of the vulnerability assessment. In this embodiment, a quantitative assessment of technical vulnerabilities is provided through the basic score, reflecting the severity of the vulnerabilities; the business impact factor focuses on the impact degree of potential asset vulnerabilities on the business, ensuring the combination of security assessment and actual business needs; the environmental attack surface coefficient evaluates the attack surface of potential asset vulnerabilities in a specific environment, considering external threats and the effectiveness of security measures; by combining the basic score, the business impact factor, and the environmental attack surface coefficient, a comprehensive vulnerability score can be obtained, enabling a more accurate understanding of the threats of different potential asset vulnerabilities, making the assessment not only limited to the characteristics of the vulnerabilities themselves, but also covering the impact of the vulnerabilities on specific business processes and business goals, and being able to better reflect the actual risks of the vulnerabilities, thereby significantly improving the accuracy and practicality of the vulnerability assessment.
[0080] It should be noted that before calculating the vulnerability score of the potential asset vulnerabilities at the current moment according to Equation (1), this embodiment also performs standardization processing on the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment to obtain the composite feature vector [CVSS, BI, ASF].
[0081] As Figure 2 or Figure 3 shown, after calculating the vulnerability score of the potential asset vulnerabilities at the current moment based on the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment, this embodiment further includes: determining the impact scope of the potential asset vulnerabilities at the current moment; judging whether the vulnerability score of the potential asset vulnerabilities at the current moment is greater than a preset value (for example, 7.8 / 10); if the vulnerability score of the potential asset vulnerabilities at the current moment is less than or equal to the preset value, then take system isolation measures for the potential asset vulnerabilities at the current moment, mark the isolated potential asset vulnerabilities, and monitor the isolation effect, where the system isolation measures include disconnecting the network connection, closing relevant services and ports, migrating critical data, and implementing strict access control. By quickly determining the impact scope of the vulnerability when a vulnerability or security incident occurs, taking corresponding isolation measures, and continuously monitoring and tracking the isolated system, this embodiment avoids the further spread of threats, reduces the attack surface, prevents data loss or tampering, and reduces security risks and losses.
[0082] S103. Based on the vulnerability score and the repair strategy optimization model, determine the repair plan for the potential asset vulnerabilities at the current moment.
[0083] Specifically, the repair strategy optimization model includes a repair plan aggregation model and an integer programming model.
[0084] In this embodiment, for newly emerging potential asset vulnerabilities in the prior art, the corresponding vulnerability response scripts (i.e., repair plans) are usually developed and tested manually, which takes a certain amount of time, resulting in a long time-consuming process from vulnerability discovery to taking effective defensive measures, with low efficiency and timeliness. However, in this embodiment, through the repair plan aggregation model and the integer programming model, the rapid development and determination of repair plans are realized, the time delay between vulnerability discovery and vulnerability repair is reduced, and the timeliness of vulnerability repair is improved.
[0085] Specifically, S103: Based on the vulnerability score and the repair strategy optimization model, determine the repair plan for the potential asset vulnerability at the current moment, including steps S1031 - S1033:
[0086] S1031, based on the repair plan aggregation model, generate N alternative repair plans for the potential asset vulnerability at the current moment, where N represents a positive integer greater than 1.
[0087] Specifically, S1031: Based on the repair plan aggregation model, generate N alternative repair plans for the potential asset vulnerability at the current moment, where N represents a positive integer greater than 1, including: obtaining historical repair plans and extracting the atomic features of the historical repair plans, where the historical repair plans refer to all repair plans for potential asset vulnerabilities in the asset association graph before the current moment, and the atomic features include affected services, required permissions, and restart requirements; clustering the historical repair plans based on the similarity calculation formula and the atomic features of the historical repair plans to obtain a historical repair item set, where the similarity calculation formula includes the Jaccard coefficient calculation formula; mining frequent repair item sets from the historical repair item set based on the frequent item set mining algorithm, and generating N alternative repair plans for the potential asset vulnerability at the current moment, where the frequent item set mining algorithm includes the frequent pattern tree FP - Growth algorithm.
[0088] In this embodiment, based on the Jaccard coefficient calculation formula, clustering the atomic features of the historical repair plans to obtain a historical repair item set specifically includes: according to the formula Calculate the similarity between the historical repair plans corresponding to asset A and asset B, where F A Represents the set of atomic features of the historical repair plan corresponding to asset A, F BDenote the set of atomized features corresponding to the historical repair plan of Asset B, CompatibleAssets(A, B) represents the historical repair items where the historical repair plan corresponding to Asset A is compatible with the historical repair plan corresponding to Asset B, TotalAssets represents all the historical repair items involved in the historical repair plan corresponding to Asset A and the historical repair plan corresponding to Asset B, and log(·) represents the logarithmic function; cluster the historical repair plans according to the similarity between the historical repair plans corresponding to Asset A and Asset B to obtain a set of historical repair items.
[0089] Based on the FP-Growth algorithm, mine the frequent repair item sets from the set of historical repair items, specifically including: calculating the support degree of historical repair items based on the FP-Growth algorithm; determining whether the support degree of historical repair items is greater than a preset value, for example: determining whether the support degree of historical repair items > 0.7; if the support degree of historical repair items is greater than the preset value, then determine the historical repair items as frequent repair items. In this embodiment, by combining the clustering algorithm and the frequent item set mining algorithm, the to-be-selected repair plans are generated, making the selection and generation of repair plans more targeted, avoiding the blind generation of repair plans, combining past repair experience with the current environment, the generated repair plans are more valuable for decision-making, which can improve the security and stability of assets. The frequent item set mining algorithm provides an efficient way to identify past effective repair strategies and reduces the manual analysis time.
[0090] S1032, input the vulnerability score and N to-be-selected repair plans into the integer programming model, and respectively evaluate the coverage of the N to-be-selected repair plans for the potential asset vulnerabilities at the current moment.
[0091] In this embodiment, the to-be-selected repair plans include implementation costs. Input the vulnerability score and N to-be-selected repair plans into the formula to respectively evaluate the coverage of the N to-be-selected repair plans for the potential asset vulnerabilities at the current moment, where a ij represents the coverage of the i-th to-be-selected repair plan for the j-th potential asset vulnerability at the current moment, Minimize(·) represents the minimization function, c i represents the implementation cost of the i-th to-be-selected repair plan, x i =0 means not adopting the i-th to-be-selected repair plan, x i =1 means adopting the i-th to-be-selected repair plan, M represents the total number of potential asset vulnerabilities at the current moment, d j represents the vulnerability score of the j-th potential asset vulnerability at the current moment, y j =0 means the j-th potential asset vulnerability at the current moment is not repaired, y j= 1 indicates that the j-th potential asset vulnerability at the current moment has been repaired. In this embodiment, by evaluating and comparing the coverage of each repair plan to be selected for the current potential asset vulnerability, the repair plan that can most effectively solve the current potential asset vulnerability can be identified, making the security repair more prioritized and targeted. Moreover, it can optimize the human and time costs, prioritize handling the most critical vulnerabilities with limited resources, and reduce the enterprise risk.
[0092] It should be noted that in this embodiment, N repair plans to be selected are automatically generated based on the Jenkins Pipeline syntax; the N repair plans to be selected are pre-executed in an isolated environment to verify the feasibility of the N repair plans to be selected through a sandbox; a progressive deployment strategy (such as the canary release mode) is adopted to release the N repair plans to be selected in a gray scale.
[0093] S1033. Determine the repair plan for the potential asset vulnerability at the current moment based on the coverage.
[0094] In this embodiment, according to the constraint conditions Solve the repair plan for the potential asset vulnerability at the current moment.
[0095] It should be noted that after solving the repair plan for the potential asset vulnerability at the current moment, this embodiment further includes: monitoring the repair plan for the potential asset vulnerability at the current moment based on Prometheus metrics; determining whether the error rate of the repair plan for the potential asset vulnerability at the current moment is greater than a preset threshold (such as 5%); in response to the error rate of the repair plan for the potential asset vulnerability at the current moment being greater than the preset threshold, optimizing the repair plan for the potential asset vulnerability at the current moment based on the repair plan iteration mechanism of version control.
[0096] Monitoring the repair plan for the potential asset vulnerability at the current moment based on Prometheus metrics specifically includes: capturing and parsing network traffic monitoring data packets, extracting the key fields of the network traffic monitoring data packets, where the key fields include but are not limited to: source IP (Internet Protocol), destination IP, port number, request method, and response status code, and the request methods include but are not limited to: HTTP GET / POST; using the ELK (Elasticsearch, Logstash, Kibana) architecture for real-time collection, processing, and visualization of logs, and converting unstructured logs into a structured data format to obtain unified structured log data; performing anomaly detection on the structured log data and the key fields of the network traffic monitoring data packets respectively; giving real-time alerts for the abnormal structured log data and network traffic monitoring data packets, and generating threat intelligence.
[0097] Perform anomaly detection on the key fields of network traffic monitoring packets, specifically including: the historical mean of the number of IP requests within a preset time period, and the standard deviation of the number of IP requests; calculate the number of requests for each IP address per unit time, and determine whether the number of requests for each IP address per unit time is greater than the sum of the historical mean and three times the standard deviation; if the number of requests for each IP address per unit time is greater than the sum of the historical mean and three times the standard deviation, mark the current network traffic monitoring packet as abnormal.
[0098] Perform anomaly detection on the key fields of structured log data and network traffic monitoring packets, specifically including: modeling the normal operation mode through a machine learning algorithm (such as k-means clustering) to obtain a baseline model; standardize the structured log data to remove noise data; based on the baseline model, perform clustering analysis on the standardized structured log data, that is, group similar behavior patterns into one category to identify abnormal clusters in the structured log data.
[0099] Anomaly detection algorithms include but are not limited to: time series anomaly detection algorithms, graph neural network attack detection algorithms, and streaming risk assessment models. Time series anomaly detection algorithms include but are not limited to: STL (Seasonal and Trend decomposition using Loess) decomposition algorithm, and streaming risk assessment models include but are not limited to: dynamic risk scoring formula and association rule mining model.
[0100] Based on the STL decomposition algorithm, perform anomaly detection on the key fields of structured log data and network traffic monitoring packets, specifically including: calculate the residual term Rt of the key fields of structured log data and network traffic monitoring packets according to Yt = Tt + St + Rt, where Tt represents the trend term calculated by Loess smoothing for the key fields of structured log data and network traffic monitoring packets, St represents the seasonal term extracted from the key fields of structured log data and network traffic monitoring packets through the fast Fourier transform (FFT), and Yt represents the key fields of structured log data and network traffic monitoring packets; determine whether |Rt| is greater than 3σR; if |Rt| is greater than 3σR, determine that there is an anomaly in the key fields of structured log data and network traffic monitoring packets.
[0101] Based on the graph neural network attack detection algorithm, perform anomaly detection on the key fields of structured log data and network traffic monitoring packets, specifically including:
[0102]
[0103]
[0104] Based on the dynamic risk scoring formula, perform anomaly detection on the key fields of structured log data and network traffic monitoring data packets respectively, specifically including: According to Among them, α represents the severity weight, α = 0.6, β represents the propagation speed weight, β = 0.4, k represents the time decay coefficient, k = 0.1, t0 represents the first occurrence time, Severity represents the vulnerability score, Riskt represents the dynamic risk of the key fields of structured log data and network traffic monitoring data packets, and t represents the current time.
[0105] Based on the association rule mining model, perform anomaly detection on the key fields of structured log data and network traffic monitoring data packets respectively, specifically including:
[0106] def mine_rules(events, min_support = 8.81):
[0107] # Use the FP-Growth algorithm to mine attack patterns
[0108] te = TransactionEncoder()
[0109] te_ary = te.fit_transform(events)
[0110] df = pd.DataFrame(te_ary, columns = te.columns_)
[0111] freq_items = fpgrowth(df, min_support = min_support, use_colnames = True)
[0112] return freq_items.sort_values('support', ascending = False).
[0113] After the repair plan for potential asset vulnerabilities at the current moment is monitored based on Prometheus metrics, this embodiment also stores all the data generated during the test phase (i.e., solving or optimizing the repair plan for potential asset vulnerabilities at the current moment) into the shared feature library through a data sharing pipeline, and calculates the call pattern deviation degree during the operation of the repair plan in real time. All the data generated during the test phase includes, but is not limited to: the submitted repair plan, the registered monitoring features, the feedback results of anomaly detection, and the regression report of the repair plan. The calculation formula for the call pattern deviation degree during the operation of the repair plan is: Deviation = 1 - (LCS length) / (max(test sequence length, running sequence length)), where LCS (Longest Common Subsequence) represents the longest common subsequence.
[0114] Based on the version control-based repair plan iteration mechanism, optimize the repair plan for potential asset vulnerabilities at the current moment, specifically including: using the code diff algorithm to identify the scope of influence of the repair plan changes:
[0115] def impact_analysis(old_plan, new_plan):
[0116] diff = difflib.SequenceMatcher(None, old_plan.operations, new_plan.operations)
[0117] changed_ops = [op for tag, i1, i2, j1, j2 in diff.get_opcodes() if tag!= 'equal']
[0118] return len(changed_ops) / len(old_plan.operations); Each repair plan to be selected for potential asset vulnerabilities at the current moment corresponds to a Git branch, and is managed through the PR (Pull Request) process to re-solve and optimize the repair plan for potential asset vulnerabilities at the current moment.
[0119] Implement real-time optimization of the repair plan using a streaming processing architecture, specifically including:
[0120]
[0121]
[0122] After optimizing the repair plan for potential asset vulnerabilities at the current moment in the version control-based repair plan iteration mechanism, this embodiment can also perform security testing on the optimized repair plan through a hybrid symbolic execution engine, an optimization model based on code coverage, and a vulnerability recurrence detection algorithm. Among them, the vulnerability recurrence detection algorithm includes a differential behavior analysis algorithm and a memory safety verification algorithm.
[0123] Performing security testing on the optimized repair plan through a hybrid symbolic execution engine specifically includes:
[0124]
[0125] Performing security testing on the optimized repair plan through an optimization model based on code coverage specifically includes: According to the formula Maximize∑ b∈B x b ·w b and the formula Performing security testing on the optimized repair plan, where x b ∈{0, 1}, x b indicates whether to select the repair plan b, w b represents the weight factor of the repair plan b, CVSS b represents the vulnerability score of the potential asset vulnerability corresponding to the repair plan b, and ExecCount b represents the execution count optimization repair priority of the repair plan b.
[0126] Performing security testing on the optimized repair plan through a differential behavior analysis algorithm specifically includes:
[0127]
[0128] Performing security testing on the optimized repair plan through a memory safety verification algorithm specifically includes:
[0129]
[0130] A method for repairing asset vulnerabilities provided by this embodiment identifies, evaluates, and repairs potential asset vulnerabilities through a vulnerability detection fusion model, a multi-dimensional vulnerability assessment model, and a repair strategy optimization model, improving the timeliness and adaptability of potential asset vulnerability identification, potential asset vulnerability assessment, and repair plan generation, achieving accurate and rapid identification, assessment, and repair of asset vulnerabilities, expanding the adaptability to newly emerging asset vulnerabilities, reducing the time-consuming for asset vulnerability discovery and repair, improving the efficiency and timeliness of asset vulnerability management, and enhancing the security and reliability of assets.
[0131] Embodiment 2:
[0132] AsFigure 4 and Figure 5 As shown in Figure 5 , this embodiment provides a method for repairing asset vulnerabilities. The method for repairing asset vulnerabilities includes:
[0133] S201, perform a security level assessment on the platform server, database, web application, and third-party services, and set a preset period according to the security level and business requirements.
[0134] In this embodiment, setting the preset period is the Figure 4 configuration scanning parameters in Figure 4 . Performing a security level assessment on the platform server, database, web application, and third-party services specifically includes: using a time series analysis model or machine learning algorithm to model the historical threat events of the platform server, database, web application, and third-party services, and predicting the threat probability of the platform server, database, web application, and third-party services at future moments; evaluating the business importance of the platform server, database, web application, and third-party services, and combining the business importance of the platform server, database, web application, and third-party services, the value of key assets (such as data sensitivity, service interruption cost), to calculate the impact degree of the platform server, database, web application, and third-party services; according to the threat probability of the platform server, database, web application, and third-party services at future moments, the impact degree of the platform server, database, web application, and third-party services, and the formula: threat risk score = threat probability × impact degree, constructing a risk matrix for the platform server, database, web application, and third-party services; evaluating the vulnerability score of the platform server, database, web application, and third-party services according to the historical threat events of the platform server, database, web application, and third-party services; according to the risk matrix, vulnerability score of the platform server, database, web application, and third-party services, and the analytic hierarchy process, constructing a security level assessment model, that is: security level = (threat risk score × weight 1) + (vulnerability score × weight 2), to evaluate the security level of the platform server, database, web application, and third-party services.
[0135] S202, the vulnerability scanning tool is respectively connected to the platform server, database, web application, and third-party services, and through the vulnerability scanning tool, three methods of active scanning (port detection), passive listening (network traffic analysis), and configuration management database synchronization audit are integrated to collect multi-modal data of all assets from the platform server, database, web application, and third-party services at a preset period. Among them, the vulnerability scanning tool includes but is not limited to: Qualys and Nessus.
[0136] S203, classify and identify multi-modal data, and infer the topological relationships among all assets; based on the topological relationships among all assets, associate the multi-modal data to form an asset association graph.
[0137] S204, based on a fuzzy matching mechanism, evaluate the asset model integrity of all assets in the asset association graph at the current moment, where the asset model integrity refers to the Levenshtein distance between the asset model information and the preset asset signal information; based on a version derivation mechanism, derive the asset version numbers of all assets in the asset association graph at the current moment; determine a first asset and a second asset, where the first asset refers to an asset whose asset model integrity at the current moment is less than a preset value, and the second asset refers to an asset whose asset version number at the current moment is the preset asset version number; based on a vulnerability propagation identification mechanism, identify a third asset, where the third asset refers to an asset in the asset association graph that has a dependency relationship with the first asset or the second asset; aggregate the first asset, the second asset, and the third asset to obtain the potential asset vulnerabilities of the asset association graph at the current moment.
[0138] S205, based on the Common Vulnerability Scoring System (CVSS), business impact assessment mechanism, and environmental impact assessment mechanism, evaluate the base score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerabilities at the current moment respectively; based on the base score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerabilities at the current moment, calculate the vulnerability score of the potential asset vulnerabilities at the current moment.
[0139] S206, obtain historical repair plans, and extract the atomic features of the historical repair plans, where the historical repair plans refer to all repair plans for the potential asset vulnerabilities of the asset association graph before the current moment, and the atomic features include affected services, required permissions, and restart requirements; based on the similarity calculation formula and the atomic features of the historical repair plans, cluster the historical repair plans to obtain a historical repair item set, where the similarity calculation formula includes the Jaccard coefficient calculation formula; based on the frequent item set mining algorithm, mine the frequent repair item set from the historical repair item set, and generate N alternative repair plans for the potential asset vulnerabilities at the current moment, where the frequent item set mining algorithm includes the Frequent Pattern Tree (FP-Growth) algorithm.
[0140] S207, input the vulnerability score and N alternative repair plans into an integer programming model, and evaluate the coverage of the N alternative repair plans for the potential asset vulnerabilities at the current moment respectively; based on the coverage, determine the repair plan for the potential asset vulnerabilities at the current moment.
[0141] S208, based on Prometheus metrics, monitor the repair plan for potential asset vulnerabilities at the current moment; determine whether the error rate of the repair plan for potential asset vulnerabilities at the current moment is greater than a preset threshold; in response to the error rate of the repair plan for potential asset vulnerabilities at the current moment being greater than the preset threshold, optimize the repair plan for potential asset vulnerabilities at the current moment based on the repair plan iteration mechanism of version control; perform security testing on the optimized repair plan through a hybrid symbolic execution engine, an optimization model based on code coverage, and a vulnerability recurrence detection algorithm, where the vulnerability recurrence detection algorithm includes a differential behavior analysis algorithm and a memory security verification algorithm.
[0142] A method for repairing asset vulnerabilities provided in this embodiment, through a vulnerability detection fusion model, a multi-dimensional vulnerability assessment model, and a repair strategy optimization model, identifies, evaluates, and repairs potential asset vulnerabilities, improves the timeliness and adaptability of potential asset vulnerability identification, potential asset vulnerability assessment, and repair plan generation, realizes accurate and rapid identification, evaluation, and repair of asset vulnerabilities, expands the adaptability to newly emerging asset vulnerabilities, reduces the time-consuming for asset vulnerability discovery and repair, improves the efficiency and timeliness of asset vulnerability management, and improves the security and reliability of assets.
[0143] Embodiment 3:
[0144] As Figure 6 shown, this embodiment provides a device for repairing asset vulnerabilities, including an identification module 31, an evaluation module 32, and a determination module 33. The identification module 31 is used to identify potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model. The evaluation module 32 is connected to the identification module 31 and is used to evaluate the vulnerability score of the potential asset vulnerabilities at the current moment based on the multi-dimensional vulnerability assessment model. The determination module 33 is connected to the evaluation module 32 and is used to determine the repair plan for the potential asset vulnerabilities at the current moment based on the vulnerability score and the repair strategy optimization model.
[0145] Optionally, the device for repairing asset vulnerabilities further includes: a collection module 34, a classification module 35, and an association module 36. The collection module 34 is used to collect multi-modal data of all assets from platform servers, databases, web application programs, and third-party services based on a vulnerability scanning tool. The classification module 35 is used to classify and identify the multi-modal data and infer the topological relationship between all assets. The association module 36 is used to associate the multi-modal data based on the topological relationship between all assets to form an asset association graph.
[0146] Specifically, the identification module 31 includes: a first evaluation unit 311, a derivation unit 312, and a first determination unit 313. The first evaluation unit 311 is configured to evaluate the integrity of the asset models of all assets in the asset association graph at the current moment based on a fuzzy matching mechanism, where the integrity of the asset model refers to the Levenshtein distance between the asset model information and the preset asset signal information. The derivation unit 312 is configured to derive the asset version numbers of all assets in the asset association graph at the current moment based on a version derivation mechanism. The first determination unit 313 is configured to determine the potential asset vulnerabilities in the asset association graph at the current moment based on the integrity of the asset model at the current moment, the asset version number at the current moment, and a vulnerability propagation identification mechanism.
[0147] Specifically, the first determination unit 313 includes: a determination subunit, an identification subunit, and a summarization subunit. The determination subunit is configured to determine a first asset and a second asset, where the first asset refers to an asset whose integrity of the asset model at the current moment is less than a preset value, and the second asset refers to an asset whose asset version number at the current moment is the preset asset version number. The identification subunit is configured to identify a third asset based on a vulnerability propagation identification mechanism, where the third asset refers to an asset in the asset association graph that has a dependency relationship with the first asset or the second asset. The summarization subunit is configured to summarize the first asset, the second asset, and the third asset to obtain the potential asset vulnerabilities in the asset association graph at the current moment.
[0148] Specifically, the evaluation module 32 includes: a second evaluation unit 321 and a calculation unit 322. The second evaluation unit 321 is configured to evaluate the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment based on the Common Vulnerability Scoring System (CVSS), a business impact evaluation mechanism, and an environmental impact evaluation mechanism. The calculation unit 322 is configured to calculate the vulnerability score of the potential asset vulnerabilities at the current moment based on the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment.
[0149] Specifically, the calculation unit 322 includes: a calculation subunit configured to calculate the vulnerability score of the potential asset vulnerabilities at the current moment according to formula (1):
[0150]
[0151] where CVSS represents the basic score of the potential asset vulnerabilities at the current moment, BI represents the business impact factor of the potential asset vulnerabilities at the current moment, ASF represents the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment, W CVSS represents the weight factor of CVSS, W business represents the weight factor of BI, W ASFThe weight factor representing ASF, α represents the time decay factor, α = 0.1, and Δt represents the time interval between the potential asset vulnerabilities in the asset association graph at the current moment and the vulnerability scores for evaluating the potential asset vulnerabilities at the current moment.
[0152] Specifically, the determination module 33 includes: a generation unit 331, a third evaluation unit 332, and a second determination unit 333. The generation unit 331 is configured to generate N to-be-selected repair plans for the potential asset vulnerabilities at the current moment based on the repair plan aggregation model, where N represents a positive integer greater than 1. The third evaluation unit 332 is configured to input the vulnerability scores and the N to-be-selected repair plans into an integer programming model, and respectively evaluate the coverage of the N to-be-selected repair plans for the potential asset vulnerabilities at the current moment. The second determination unit 333 is configured to determine the repair plan for the potential asset vulnerabilities at the current moment based on the coverage.
[0153] Specifically, the generation unit 331 includes: an acquisition subunit, a clustering subunit, and a mining subunit. The acquisition subunit is configured to acquire historical repair plans and extract the atomic features of the historical repair plans, where the historical repair plans refer to all repair plans for the potential asset vulnerabilities in the asset association graph before the current moment, and the atomic features include affected services, required permissions, and restart requirements. The clustering subunit is configured to cluster the historical repair plans based on the similarity calculation formula and the atomic features of the historical repair plans to obtain a historical repair item set, where the similarity calculation formula includes the Jaccard coefficient calculation formula. The mining subunit is configured to mine frequent repair item sets from the historical repair item set based on the frequent item set mining algorithm and generate N to-be-selected repair plans for the potential asset vulnerabilities at the current moment, where the frequent item set mining algorithm includes the frequent pattern tree FP-Growth algorithm.
[0154] It can be understood that the above-provided repair device for asset vulnerabilities executes the repair method for asset vulnerabilities corresponding to Embodiment 1 provided above. Therefore, the beneficial effects it can achieve can refer to the beneficial effects of the solution corresponding to the repair method for asset vulnerabilities in Embodiment 1 above, and will not be elaborated here.
[0155] Embodiment 4:
[0156] This embodiment provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to implement the repair method for asset vulnerabilities in Embodiment 1 or Embodiment 2 above.
[0157] Embodiment 5:
[0158] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for repairing asset vulnerabilities in the above-mentioned Embodiment 1 or Embodiment 2 is implemented.
[0159] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present invention. However, the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.
Claims
1. A method for repairing asset vulnerabilities, characterized in that, Including: Based on the vulnerability detection fusion model, identify potential asset vulnerabilities in the asset association graph at the current moment; Based on the multi-dimensional vulnerability assessment model, evaluate the vulnerability scores of the potential asset vulnerabilities at the current moment; Based on the vulnerability score and the repair strategy optimization model, determine the repair plan for the potential asset vulnerabilities at the current moment.
2. The method for repairing asset vulnerabilities according to claim 1, wherein Before identifying potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model, it further includes: Collect multi-modal data of all assets from platform servers, databases, web applications, and third-party services based on vulnerability scanning tools; Classify and identify the multi-modal data, and infer the topological relationships among all assets; Based on the topological relationships among all assets, associate the multi-modal data to form an asset association graph.
3. The method for repairing asset vulnerabilities according to claim 1, wherein, The vulnerability detection fusion model includes a fuzzy matching mechanism, a version derivation mechanism, and a vulnerability propagation identification mechanism. Identifying potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model specifically includes: Based on the fuzzy matching mechanism, evaluate the integrity of the asset models of all assets in the asset association graph at the current moment, where the integrity of the asset model refers to the Levenshtein distance between the asset model information and the preset asset signal information; Based on the version derivation mechanism, derive the asset version numbers of all assets in the asset association graph at the current moment; Based on the integrity of the asset model at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism, determine the potential asset vulnerabilities in the asset association graph at the current moment.
4. The method for repairing asset vulnerabilities according to claim 3, characterized in that, Determining the potential asset vulnerabilities in the asset association graph at the current moment based on the integrity of the asset model at the current moment, the asset version number at the current moment, and the vulnerability propagation identification mechanism specifically includes: Determine the first asset and the second asset, where the first asset refers to the asset with the integrity of the asset model less than the preset value at the current moment, and the second asset refers to the asset with the asset version number being the preset asset version number at the current moment; Based on the vulnerability propagation identification mechanism, identify the third asset, where the third asset refers to the asset in the asset association graph that has a dependency relationship with the first asset or the second asset; Summarize the first asset, the second asset, and the third asset to obtain the potential asset vulnerabilities in the asset association graph at the current moment.
5. The method for repairing asset vulnerabilities according to claim 1, characterized in that, The multi-dimensional vulnerability assessment model includes the Common Vulnerability Scoring System (CVSS), a business impact assessment mechanism, and an environmental impact assessment mechanism. Evaluating the vulnerability scores of the potential asset vulnerabilities at the current moment based on the multi-dimensional vulnerability assessment model specifically includes: Based on the Common Vulnerability Scoring System (CVSS), the business impact assessment mechanism, and the environmental impact assessment mechanism, respectively evaluate the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment; Based on the basic score, the business impact factor, and the environmental attack surface coefficient of the potential asset vulnerabilities at the current moment, calculate the vulnerability scores of the potential asset vulnerabilities at the current moment.
6. The method for repairing asset vulnerabilities according to claim 5, characterized in that Calculating the vulnerability score of the potential asset vulnerability at the current moment based on the basic score, business impact factor, and environmental attack surface coefficient of the potential asset vulnerability at the current moment, specifically including: Calculating the vulnerability score of the potential asset vulnerability at the current moment according to formula (1): Among them, CVSS represents the basic score of the potential asset vulnerability at the current moment, BI represents the business impact factor of the potential asset vulnerability at the current moment, ASF represents the environmental attack surface coefficient of the potential asset vulnerability at the current moment, W CVSS represents the weight factor of CVSS, W business represents the weight factor of BI, W ASF represents the weight factor of ASF, α represents the time decay factor, α = 0.1, and Δt represents the time interval between identifying the potential asset vulnerability in the asset association graph at the current moment and evaluating the vulnerability score of the potential asset vulnerability at the current moment.
7. The method for repairing asset vulnerabilities according to claim 1, wherein The repair strategy optimization model includes a repair plan aggregation model and an integer programming model. Determining the repair plan for the potential asset vulnerability at the current moment based on the vulnerability score and the repair strategy optimization model, specifically including: Generating N alternative repair plans for the potential asset vulnerability at the current moment based on the repair plan aggregation model, where N represents a positive integer greater than 1; Inputting the vulnerability score and the N alternative repair plans into the integer programming model, and respectively evaluating the coverage of the N alternative repair plans for the potential asset vulnerability at the current moment; Determining the repair plan for the potential asset vulnerability at the current moment based on the coverage.
8. The method for repairing asset vulnerabilities according to claim 7, characterized in that, Generating N alternative repair plans for the potential asset vulnerability at the current moment based on the repair plan aggregation model, specifically including: Obtaining historical repair plans and extracting the atomic features of the historical repair plans, where the historical repair plans refer to all repair plans for the potential asset vulnerabilities in the asset association graph before the current moment, and the atomic features include affected services, required permissions, and restart requirements; Clustering the historical repair plans based on the similarity calculation formula and the atomic features of the historical repair plans to obtain a historical repair item set, where the similarity calculation formula includes the Jaccard coefficient calculation formula; Mining frequent repair item sets from the historical repair item set based on the frequent item set mining algorithm, and generating N alternative repair plans for the potential asset vulnerability at the current moment, where the frequent item set mining algorithm includes the frequent pattern tree FP-Growth algorithm.
9. A repair device for asset vulnerabilities, characterized in that, Including an identification module, an evaluation module, and a determination module. The identification module is used to identify the potential asset vulnerabilities in the asset association graph at the current moment based on the vulnerability detection fusion model. The evaluation module is connected to the identification module and is used to evaluate the vulnerability score of the potential asset vulnerability at the current moment based on the multi-dimensional vulnerability evaluation model. The determination module is connected to the evaluation module and is used to determine the repair plan for the potential asset vulnerability at the current moment based on the vulnerability score and the repair strategy optimization model.
10. An electronic device, characterized in that, Including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to run the computer program to implement a method for repairing asset vulnerabilities according to any one of claims 1 to 8.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements a method for repairing asset vulnerabilities according to any one of claims 1 to 8.
Citation Information
Cited By
Asset vulnerability detection method and device, electronic equipment and storage medium
CN121193547A