Open source component risk control method and system and computer readable medium

Through software information acquisition probes, identify open source components, calculate vulnerability threats and software exposure values, the coverage and accuracy of risk control of open source components in the existing technology is solved, efficient risk identification and automatic disposal is achieved, and the security and reliability of the application system are improved.

CN120387168APending Publication Date: 2025-07-29太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510467986.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The existing open source component risk control methods have problems such as limited coverage and low accuracy in vulnerability detection, which leads to the difficulty of repairing high-risk vulnerabilities and affects the security of the application system.

Method used

Identify open source components through software information acquisition probes, calculate vulnerability threat values and software exposure values, calculate software risk values in combination with threat impact values and software exposure values, and automatically deal with them when the risk value exceeds the threshold.

Benefits of technology

It improves the accuracy of risk identification of open source components, can timely identify and automatically deal with high-risk vulnerabilities, reduces the difficulty of subsequent repairs, and improves the security and reliability of the application system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387168A_ABST
    Figure CN120387168A_ABST
Patent Text Reader

Abstract

The invention relates to an open source component risk control method and system and a computer readable medium, and the method comprises the steps: collecting software information of an application system through a software information collection probe, and recognizing an open source component according to the software information; calculating a vulnerability threat value of the open source component; calculating a software exposure value of the open source component; calculating a software risk value according to the threat influence value and the software exposure value; and in response to the software risk value greater than or equal to a preset software risk threshold, performing risk disposal on the open source component. According to the invention, the risk identification accuracy of the open source component can be improved, and risk disposal can be automatically carried out on the risky open source component.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application mainly relates to the field of software security technology, and specifically relates to a method, system and computer-readable medium for risk control of open-source components. Background Art

[0002] With the continuous increase in the popularity of open-source software, the proportion of open-source components used in application systems is also increasing day by day. When most open-source components are introduced into application systems, they may carry known and publicly disclosed vulnerabilities, among which there are many vulnerabilities with simple exploitation methods and high harm levels. For example, if an application system uses an open-source component containing a deserialization vulnerability, when the vulnerability is exploited, it can execute arbitrary code remotely, and then achieve remote control of the application system server, affecting the security of the application system.

[0003] Currently, for the risk control method of open-source components, software composition analysis (SCA) tools are usually integrated into the continuous integration / continuous delivery (CI / CD) pipeline. During the software project development and construction stages, the SCA tools are used to analyze the project source code to identify the open-source components introduced in the code.

[0004] The SCA tools have certain limitations. Firstly, since their analysis object is the project source code, they cannot cover all application systems, such as the application systems without source code provided by suppliers, partners, etc. Secondly, the risk assessment in the SCA tools is based on the Common Vulnerability Scoring System (CVSS), which mainly measures the impact of the exploited vulnerability on the confidentiality, integrity and availability of the application system. After using the CVSS scoring, a relatively large number of high-risk vulnerabilities are usually obtained, and the accuracy of the vulnerability detection results is not high, resulting in a large amount of manpower being required to judge and repair the vulnerabilities, increasing the difficulty of executing vulnerability repair. Summary of the Invention

[0005] The technical problem to be solved by this application is to provide a method, system and computer-readable medium for risk control of open-source components, which can improve the accuracy of risk identification of open-source components and can automatically perform risk disposal on risky open-source components.

[0006] The technical solution adopted by this application to solve the above technical problems is an open-source component risk control method, including: using a software information collection probe to collect software information of an application system, identifying open-source components according to the software information; calculating the vulnerability threat value of the open-source components; calculating the software exposure value of the open-source components; calculating the software risk value according to the threat impact value and the software exposure value; and in response to the software risk value being greater than or equal to a preset software risk threshold, performing risk disposal on the open-source components.

[0007] In an embodiment of this application, calculating the vulnerability threat value of the open-source components includes calculating the vulnerability threat value using the following formula:

[0008] Vulnerability threat value = Common Vulnerability Scoring * [1 - (1 - Existence of publicly available exploit code) * (1 - Existence of vulnerability scanning tool exploit code) * (1 - Existence of threat intelligence)]

[0009] Among them, the Common Vulnerability Scoring is obtained from the vulnerability threat dataset; if the open-source component matches the exploit code dataset, the value of the existence of publicly available exploit code is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0; if the open-source component matches the vulnerability scanning tool exploit code dataset, the value of the existence of vulnerability scanning tool exploit code is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0; if the open-source component matches the threat intelligence dataset, the value of the existence of threat intelligence is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0.

[0010] In an embodiment of this application, calculating the software exposure value of the open-source components includes calculating the software exposure value using the following formula:

[0011] Software exposure value = n * Data value of the application system * Access permission of the application system * Host-attributed network area * Host software path

[0012] Among them, n is a constant greater than 0; the value of the data value of the application system is obtained from the host-attributed application system dataset according to the data value level of the application system corresponding to the open-source component; the value of the access permission of the application system is obtained from the host-attributed application system dataset according to the access permission type of the application system corresponding to the open-source component; the value of the host-attributed network area is obtained from the host-attributed application system dataset according to the host-attributed network area type of the application system corresponding to the open-source component; the value of the host software path is obtained from the host software asset dataset according to the file path type of the host corresponding to the open-source component.

[0013] In an embodiment of this application, calculating the software risk value according to the threat impact value and the software exposure value includes calculating the software risk value using the following formula:

[0014] Software risk value = Vulnerability threat value + Software exposure value.

[0015] In one embodiment of the present application, the risk disposal of open-source components includes: pushing the open-source components to the software risk management platform; the software risk management platform sending software risk notification information to the application system administrators according to the department to which the application system of the open-source components belongs; and opening the application system management authority for the application system administrators.

[0016] In one embodiment of the present application, the vulnerability threat data set includes: one or any combination of the first vulnerability number, vulnerability software name, vulnerability software version, and common vulnerability scoring; the vulnerability exploitation code data set includes: the second vulnerability number and / or the exploitation code URL address; the vulnerability scanning tool exploitation code data set includes: one or any combination of the third vulnerability number, scanning tool name, and scanning rule name; the threat intelligence data set includes: the fourth vulnerability number and / or the threat intelligence name.

[0017] In one embodiment of the present application, the host software asset data set includes: one or any combination of the first host IP address, host software path, host software name, and host software version; the host-attributed application system data set includes: one or any combination of the second host IP address, host-attributed network area, host-attributed application system name, application system administrator, department to which the application system belongs, application system data value, and application system access authority.

[0018] In one embodiment of the present application, identifying open-source components according to software information includes: calculating the similarity between the software information and the open-source component information library; and determining that it belongs to an open-source component in response to the similarity being greater than or equal to a preset similarity threshold.

[0019] In one embodiment of the present application, the software information includes: one or any combination of name, version, installation path, dependency relationship, digital signature, and developer information.

[0020] The present application also proposes an open-source component risk control system to solve the above technical problems, including: a memory for storing instructions executable by a processor; and a processor for executing the instructions to implement the above open-source component risk control method.

[0021] The present application also proposes a computer-readable medium storing computer program code, and the computer program code implements the above open-source component risk control method when executed by a processor.

[0022] The technical solution of this application can identify open-source components in a source-code-free application system by analyzing the software information of the host, broadening the coverage scope. It can also include source-code-free application systems provided by suppliers, etc. in the evaluation scope, no longer being limited to projects with source code. In terms of software risk assessment, based on the vulnerability scoring system (CVSS), this application calculates the vulnerability threat value and software exposure value of open-source components, which is equivalent to adding references for vulnerability exploitability and asset importance. This makes the evaluation no longer only focus on the theoretical impact of vulnerabilities, but rather more focus on the actual threats brought by open-source component vulnerabilities. This application improves the accuracy of open-source component risk assessment, can identify and automatically dispose of risky open-source components in a timely manner, effectively reduces the number of high-risk vulnerabilities, and thus greatly reduces the difficulty of subsequent vulnerability repair, improving the security and reliability of open-source component use. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] To make the above objects, features, and advantages of this application more obvious and understandable, the following provides a detailed description of the specific implementation manners of this application with reference to the accompanying drawings, where:

[0024] Figure 1 is a flowchart of the open-source component risk control method according to an embodiment of this application;

[0025] Figure 2 is a flowchart of the open-source component risk control method according to another embodiment of this application;

[0026] Figure 3 is a data relationship diagram of each data set according to an embodiment of this application;

[0027] Figure 4 is a system block diagram of the open-source component risk control system according to an embodiment of this application.

[0028] Description of the reference numerals in the specific implementation manners:

[0029] 310. Vulnerability threat data set;

[0030] 3101. Vulnerability exploitation code data set;

[0031] 3102. Vulnerability scanning tool exploitation code data set;

[0032] 3103. Threat intelligence data set;

[0033] 320. Host software asset data set;

[0034] 3201. Host-attributed application system data set;

[0035] 330. Software risk data set;

[0036] 340. Software risk management platform. Detailed implementation manners

[0037] To make the above objects, features, and advantages of the present application more obvious and understandable, the following will describe the detailed implementation manners of the present application in conjunction with the accompanying drawings.

[0038] In the following description, many specific details are set forth to facilitate a full understanding of the present application. However, the present application may also be implemented in other ways different from those described herein. Therefore, the present application is not limited by the specific embodiments disclosed below.

[0039] As shown in the present application and the claims, unless the context clearly indicates otherwise, words such as "a", "an", "one", and / or "the" are not specifically singular and may also include plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the clearly identified steps and elements, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements.

[0040] In the present application, flowcharts are used to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the operations before or below do not necessarily need to be executed precisely in order. On the contrary, they can be executed in reverse order or simultaneously. At the same time, other operations may be added to these processes, or one or several operations may be removed from these processes.

[0041] The present application proposes an open-source component risk control method, which can be applied to the software supply chain security scenario to identify and dispose of the risks of open-source components. The open-source component risk control method of the present application can run on a local computer, for example, within the controller of the computer, and can also run on a cloud platform. When the open-source component risk control method runs on the cloud platform, the data of the local computer and the cloud platform data are interacted through a wireless network. Exemplarily, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an interconnected cloud, a multi-cloud, etc. or any combination thereof. The present application does not limit the operating environment of the open-source component risk control method.

[0042] Figure 1 is a flowchart of the open-source component risk control method according to an embodiment of the present application. Refer to Figure 1 As shown, the open-source component risk control method of this embodiment includes the following steps:

[0043] Step S110: Use a software information collection probe to collect the software information of the application system, and identify the open-source components according to the software information.

[0044] Step S120: Calculate the vulnerability threat value of the open-source component.

[0045] Step S130: Calculate the software exposure value of the open-source component.

[0046] Step S140: Calculate the software risk value based on the threat impact value and the software exposure value.

[0047] Step S150: In response to the software risk value being greater than or equal to the preset software risk threshold, perform risk handling on the open-source components.

[0048] Exemplarily, the above step S110 is equivalent to the open-source component identification phase, and open-source components existing on the host can be analyzed by deploying software information collection probes on the application system host. The above steps S120 to S140 are equivalent to the open-source component risk assessment phase, where, based on CVSS, the exploitability of vulnerabilities and the assessment of asset importance are added. The above step S150 is equivalent to the open-source component risk handling phase, and through the software risk management platform, a long-term risk management mechanism can be established to continuously evaluate and monitor the software supply chain risk, realizing online closed-loop management of software risks and facilitating cross-departmental collaboration.

[0049] The above steps S110 to S150 are described in detail below:

[0050] In step S110, software information of the application system is collected by using software information collection probes, and open-source components are identified based on the software information.

[0051] Exemplarily, the software information collection probe is a software tool. When it is deployed on the application system host, it is like inserting a detector on the host, which can automatically collect various software-related detailed information in the host. After rich software information on the host is collected, these information can be compared with the known open-source component feature information through specific analysis algorithms. For example, some open-source components have unique naming rules, version identification methods, or specific file structures, function library features, etc. Based on these features, it is possible to identify which of the numerous software on the host belong to open-source components.

[0052] In this application, by using software information collection probes to collect software information of the application system and identifying open-source components accordingly, the open-source components included in the application system can be accurately located, avoiding the limitations of relying solely on source code to analyze open-source components, and can comprehensively cover various application systems, including application systems without source code.

[0053] In some embodiments, the software information includes one or any combination of: name, version, installation path, dependency relationship, digital signature, developer information. Exemplarily, through software information in multiple aspects, the accuracy and reliability of open-source component identification are improved, providing a data basis for subsequent open-source component risk control processes, such as calculating risk values and performing risk handling.

[0054] In some embodiments, identifying open-source components based on software information includes:

[0055] Step S1101: Calculate the similarity between the software information and the open-source component information library;

[0056] Step S1102: In response to the similarity being greater than or equal to a preset similarity threshold, determine that it belongs to an open-source component.

[0057] Exemplarily, based on the similarity comparison method, the present application can comprehensively analyze complex and diverse software information. Even in the case of incomplete information or certain interference, it can relatively accurately identify open-source components. The present application can identify open-source components in a quantitative and relatively objective manner, providing a standardized process for the identification of open-source components, avoiding the uncertainty brought by subjective judgment, and improving the accuracy and reliability of the identification results.

[0058] Here, various data sets of the present application are introduced first for easy understanding of the subsequent technical content. These data sets will be used in the process of calculating the software risk value of the present application.

[0059] Figure 3 is a data relationship diagram of each data set in an embodiment of the present application. Refer to Figure 3 As shown, exemplarily, the vulnerability threat data set 310 includes a vulnerability exploitation code data set 3101, a vulnerability scanning tool exploitation code data set 3102, and a threat intelligence data set 3103; the host software asset data set 320 includes a host-owned application system data set 3201; data interaction can be performed between the vulnerability threat data set 310, the host software asset data set 320, and the software risk data set 330; the software risk management platform 340 can call the software risk data set 330 and the host-owned application system data set 3201. The construction process of these data sets of the present application will be introduced later.

[0060] In step S120, calculate the vulnerability threat value of the open-source component. Exemplarily, the vulnerability threat value can be used to evaluate the threat level that the vulnerabilities carried by the open-source component may bring.

[0061] Refer to Figure 3 As shown, in some embodiments, calculating the vulnerability threat value of the open-source component includes calculating the vulnerability threat value using the following formula (1):

[0062] Vulnerability threat value = Common Vulnerability Scoring * [1 - (1 - Existence of public vulnerability exploitation code) * (1 - Existence of vulnerability scanning tool exploitation code) * (1 - Existence of threat intelligence)] (1)

[0063] Among them, the common vulnerability scoring is obtained from the vulnerability threat data set 310. For example, at least one common vulnerability scoring can be preset.

[0064] If the open-source component matches the vulnerability exploitation code dataset 3101, then the value of the publicly available vulnerability exploitation code is set to a constant greater than 0 and less than or equal to 1, otherwise the value is set to 0. For example, publicly available vulnerability exploitation codes on the Internet can be collected in the vulnerability exploitation code dataset 3101, with each exploitation code valued at 0.2 and the total value not exceeding 1.

[0065] If the open-source component matches the vulnerability scanning tool exploitation code dataset 3102, then the value of the existing vulnerability scanning tool exploitation code is set to a constant greater than 0 and less than or equal to 1, otherwise the value is set to 0. For example, the vulnerability situations supported by the vulnerability scanning tools can be collected in the vulnerability scanning tool exploitation code dataset 3102, with each supported scanner valued at 0.3 and the total value not exceeding 1.

[0066] If the open-source component matches the threat intelligence dataset 3103, then the value of the existing threat intelligence is set to a constant greater than 0 and less than or equal to 1, otherwise the value is set to 0. For example, vulnerability intelligence can be searched in the threat intelligence dataset 3103. If there is vulnerability intelligence, it is valued at 0.6; if there is no vulnerability intelligence, it is valued at 0.

[0067] Exemplarily, after calculating the vulnerability threat value, it can be supplemented to the vulnerability threat dataset 310. In this application, the values of each key factor are determined by matching with the corresponding dataset, and the role of different sources in the vulnerability threat is fully considered in the process of calculating the vulnerability threat value. This calculation method can more accurately reflect the real threat faced by the open-source component and provide a more reliable basis for risk assessment. Supplementing the calculated vulnerability threat value to the vulnerability threat dataset 310 can further improve the dataset and provide data support for subsequent risk analysis, risk handling, and overall risk control of open-source components.

[0068] Reference Figure 3 As shown, in some embodiments, the vulnerability threat dataset 310 includes one or any combination of the following: the first vulnerability number, the name of the vulnerable software, the version of the vulnerable software, and the Common Vulnerability Scoring System.

[0069] The vulnerability exploitation code dataset 3101 includes the second vulnerability number and / or the URL address of the exploitation code.

[0070] The vulnerability scanning tool exploitation code dataset 3102 includes one or any combination of the following: the third vulnerability number, the name of the scanning tool, and the name of the scanning rule.

[0071] The threat intelligence dataset 3103 includes the fourth vulnerability number and / or the name of the threat intelligence.

[0072] Exemplarily, the first vulnerability number, the second vulnerability number, the third vulnerability number, and the fourth vulnerability number may be the same or different, and the present application does not impose any restrictions. Based on the common vulnerability database, the present application establishes a vulnerability threat dataset 310 by using the vulnerability number, software name, software version, and common vulnerability scoring; based on the publicly disclosed vulnerability exploitation code on the Internet, the present application establishes a publicly available vulnerability exploitation code dataset 3101 by using the vulnerability number and the URL address of the exploitation code; based on internal and open-source vulnerability scanning tools, the present application establishes a vulnerability scanning tool exploitation code dataset 3102 by using the vulnerability number, scanning tool name, and scanning rule name; and based on internal threat intelligence, the present application establishes a threat intelligence dataset 3103 by using the vulnerability number and threat intelligence name.

[0073] In step S130, the software exposure value of the open-source component is calculated. In some embodiments, the software exposure value is calculated using the following formula (2):

[0074] Software exposure value = n * application system data value * application system access privilege * host-attributed network area * host software path (2)

[0075] Where n is a constant greater than 0. For example, n = 10.

[0076] According to the data value level of the application system corresponding to the open-source component, the value of the application system data value is obtained from the host-attributed application system dataset 3201. For example, the data value level can be divided into level one, level two, level three, and level four, with the value of level one being 0.8; the value of level two being 0.6; the value of level three being 0.5; and the value of level four being 0.2.

[0077] According to the access privilege type of the application system corresponding to the open-source component, the value of the application system access privilege is obtained from the host-attributed application system dataset 3201. For example, according to the access privilege, it can be divided into Internet access and intranet access, with the value of Internet access being 0.75; and the value of intranet access being 0.45.

[0078] According to the host-attributed network area type of the application system corresponding to the open-source component, the value of the host-attributed network area is obtained from the host-attributed application system dataset 3201. For example, according to the network area, it can be divided into the production network area and the test network area, with the value of the production network area being 0.75; and the value of the test network area being 0.45.

[0079] According to the file path type of the host corresponding to the open-source component, the value of the host software path is obtained from the host software asset dataset 320. For example, according to the file path, it can be divided into the web directory inside the host, the web directory inside the container, and the non-web directory, with the value of the web directory inside the host being 0.85; the value of the web directory inside the container being 0.6; and the value of the non-web directory being 0.2.

[0080] Exemplarily, after calculating the software exposure value, it can be supplemented to the host software asset dataset 320. In the process of calculating the software exposure value in this application, the comprehensive impact of key factors such as the data value level of the open-source component in the application system, the type of access permission, the characteristics of the network area, and the type of host file path on the risk exposure is fully considered. This quantification method helps to accurately evaluate the risk of open-source components in actual application scenarios and provides a data basis for subsequent risk disposal.

[0081] Reference Figure 3 As shown, in some embodiments, the host software asset dataset 320 includes: one or any combination of the first host IP address, the host software path, the host software name, and the host software version;

[0082] The host-attributed application system dataset 3201 includes: one or any combination of the second host IP address, the host-attributed network area, the host-attributed application system name, the application system administrator, the department to which the application system belongs, the data value of the application system, and the access permission of the application system.

[0083] Exemplarily, the full name of the IP address is Internet Protocol Address, that is, the Internet protocol address. The first host IP address and the second host IP address may be the same or different, and this application does not make any restrictions. In this application, a data collector is installed on the host to collect the host IP address, software path, software name, and software version, and establish the host software asset dataset 320. Based on the internal asset data, the host-attributed application system dataset 3201 is established using the host IP address, the host-attributed network area, the host-attributed application system name, the application system administrator, the department to which the application system belongs, the data value of the application system, and the access permission of the application system.

[0084] In step S140, the software risk value is calculated according to the threat impact value and the software exposure value. In some embodiments, the software risk value is calculated using the following formula (3):

[0085] Software risk value = vulnerability threat value + software exposure value (3)

[0086] Exemplarily, based on the vulnerability threat dataset 310 and the host software asset dataset 320, the present application establishes a software risk dataset 330. After calculating the software risk value, it can be supplemented to the software risk dataset 330. The present application can comprehensively consider the vulnerability threat level of open-source components and the risk exposure level of open-source components in the application system, so as to comprehensively and intuitively quantify the overall risk brought by open-source components. The present application makes the risk assessment of open-source components more comprehensive and accurate, helps to perform risk disposal on open-source components subsequently, and can ensure the security and stability of the application system.

[0087] In step S150, in response to the software risk value being greater than or equal to the preset software risk threshold, risk disposal is performed on the open-source component. In some embodiments, performing risk disposal on the open-source component includes:

[0088] Step S1501: Push the open-source component to the software risk management platform 340;

[0089] Step S1502: The software risk management platform 340 sends software risk notification information to the application system administrator according to the department to which the application system of the open-source component belongs;

[0090] Step S1503: Open the application system management permission for the application system administrator.

[0091] Exemplarily, the present application has preset a software risk threshold, and software risk data greater than or equal to the software risk threshold can be associated with the department to which the application system belongs and the application system administrator in the host-attributed application system dataset 3201, and pushed to the software risk management platform 340. The software risk management platform 340 sends software risk notification information according to the department and application system dimensions. Opening the application system management permission to the application system administrator on the software risk management platform 340 can expand the access permission of software risk data under the application system, facilitating cross-team collaboration in dealing with software risks. The open-source component risk control method of the present application can form a closed-loop management, effectively reducing the risks brought by open-source components to the application system, improving the security and stability of the application system, and ensuring the smooth operation of the system.

[0092] Next, an open-source component risk control method according to another embodiment of the present application is introduced.

[0093] Figure 2 It is a flowchart of an open-source component risk control method according to another embodiment of the present application. Refer to Figure 2As shown, in step S210, vulnerability data is collected, the vulnerability threat value is calculated, and a vulnerability threat data set is output; in step S220, host software asset data is collected, the software exposure value is calculated, and a host software asset data set is output; in step S230, the vulnerability threat data and the host software asset data are associated, the software risk value is calculated, and a software risk data set is output; in step S240, software risk data is screened according to the software risk threshold, and the data is pushed to the software risk management platform; in step S250, the software risk management platform sends software risk notification information, and software risk query and handling are performed on the platform.

[0094] The technical solution of the present application can identify open-source components in a source-code-free application system by analyzing the software information of the host, broadening the coverage range, and including source-code-free application systems provided by suppliers, etc. in the evaluation scope, no longer limited to projects with source code; in terms of software risk assessment, based on the vulnerability scoring system (CVSS), by calculating the vulnerability threat value and software exposure value of open-source components, it is equivalent to adding references to the exploitability of vulnerabilities and the importance of assets, making the evaluation no longer only focus on the theoretical impact of vulnerabilities, but more focus on the actual threats brought by open-source component vulnerabilities; the present application improves the accuracy of open-source component risk assessment, can identify and automatically handle risky open-source components in a timely manner, effectively reduces the number of high-risk vulnerabilities, and thus greatly reduces the difficulty of subsequent vulnerability repair, improving the security and reliability of the use of open-source components.

[0095] The present application also includes an open-source component risk control system, including a memory and a processor. Among them, the memory is used to store instructions executable by the processor; the processor is used to execute the instructions to implement the open-source component risk control method described above.

[0096] Figure 4 is the system block diagram of the open-source component risk control system according to an embodiment of the present application. Refer to Figure 4As shown, the open-source component risk control system 400 may include an internal communication bus 401, a processor 402, a read-only memory (ROM) 403, a random access memory (RAM) 404, and a communication port 405. When applied to a personal computer, the open-source component risk control system 400 may further include a hard disk 406. The internal communication bus 401 may enable data communication among the components of the open-source component risk control system 400. The processor 402 may make judgments and issue prompts. In some embodiments, the processor 402 may consist of one or more processors. The communication port 405 may enable data communication between the open-source component risk control system 400 and the outside. In some embodiments, the open-source component risk control system 400 may send and receive information and data from a network through the communication port 405. The open-source component risk control system 400 may further include different forms of program storage units and data storage units, such as the hard disk 406, the read-only memory (ROM) 403, and the random access memory (RAM) 404, which can store various data files used for computer processing and / or communication, as well as possible program instructions executed by the processor 402. The processor executes these instructions to implement the main part of the method. The results processed by the processor are transmitted to the user device through the communication port and displayed on the user interface.

[0097] The above-mentioned open-source component risk control method may be implemented as a computer program, stored in the hard disk 406, and loaded into the processor 402 for execution to implement the open-source component risk control method of this application.

[0098] This application also includes a computer-readable medium storing computer program code, which implements the open-source component risk control method described above when executed by a processor.

[0099] When the open-source component risk control method is implemented as a computer program, it may also be stored in a computer-readable storage medium as an article of manufacture. For example, the computer-readable storage medium may include, but is not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic strips), optical disks (e.g., compact discs (CDs), digital versatile discs (DVDs)), smart cards, and flash memory devices (e.g., electrically erasable programmable read-only memories (EPROMs), cards, sticks, key drives). In addition, the various storage media described herein can represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media (and / or storage media) that can store, contain, and / or carry code and / or instructions and / or data.

[0100] It should be understood that the embodiments described above are merely illustrative. The embodiments described herein can be implemented in hardware, software, firmware, middleware, microcode, or any combination thereof. For a hardware implementation, the processor can be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, and / or other electronic units designed to perform the functions described herein, or a combination thereof.

[0101] Some aspects of the present application can be executed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software can all be referred to as "data blocks", "modules", "engines", "units", "components", or "systems". The processor can be one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DAPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, or a combination thereof. In addition, aspects of the present application may be embodied as a computer product located in one or more computer-readable media, which includes computer-readable program code. For example, the computer-readable media may include, but is not limited to, magnetic storage devices (such as hard disks, floppy disks, magnetic tapes...), optical disks (such as compact disks CD, digital versatile disks DVD...), smart cards, and flash memory devices (such as cards, sticks, key drives...).

[0102] The computer-readable media may contain a propagated data signal having computer program code embodied therein, such as on a baseband or as part of a carrier wave. The propagated signal may have various manifestations, including electromagnetic form, optical form, etc., or a suitable combination thereof. The computer-readable media can be any computer-readable media other than a computer-readable storage medium, which can be connected to an instruction execution system, apparatus, or device to implement communication, propagation, or transmission for use of the program. The program code located on the computer-readable media can be propagated through any suitable medium, including radio, cable, fiber optic cable, radio frequency signal, or similar media, or any combination of the above media.

[0103] The basic concepts have been described above. Obviously, for those skilled in the art, the above application disclosure is merely an example and does not constitute a limitation to the present application. Although not explicitly stated herein, those skilled in the art may make various modifications, improvements, and corrections to the present application. Such modifications, improvements, and corrections are proposed in the present application, so such modifications, improvements, and corrections still fall within the spirit and scope of the exemplary embodiments of the present application.

[0104] Meanwhile, this application uses specific terms to describe the embodiments of this application. For example, "an embodiment", "one embodiment", and / or "some embodiments" mean a certain feature, structure, or characteristic related to at least one embodiment of this application. Therefore, it should be emphasized and noted that the "one embodiment" or "an embodiment" or "an alternative embodiment" mentioned twice or more at different positions in this specification does not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of this application can be appropriately combined.

[0105] In some embodiments, numbers are used to describe components and the quantity of attributes. It should be understood that such numbers used to describe embodiments are, in some examples, modified by the modifiers "about", "approximately", or "substantially". Unless otherwise stated, "about", "approximately", or "substantially" indicate that the stated number allows a ±20% variation. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, and these approximate values can change according to the characteristics required by individual embodiments. In some embodiments, the numerical parameters should consider the specified significant digits and adopt the method of retaining the general number of digits. Although the numerical ranges and parameters used to confirm the breadth of the scope in some embodiments of this application are approximate values, in specific embodiments, the setting of such numerical values is as precise as possible within the feasible range.

Claims

1. An open-source component risk control method, characterized in that, Including: Collecting software information of an application system using a software information collection probe, and identifying open-source components based on the software information; Calculating the vulnerability threat value of the open-source components; Calculating the software exposure value of the open-source components; Calculating the software risk value based on the threat impact value and the software exposure value; In response to the software risk value being greater than or equal to a preset software risk threshold, performing risk handling on the open-source components.

2. The open-source component risk control method according to claim 1, wherein Calculating the vulnerability threat value of the open-source components includes calculating the vulnerability threat value using the following formula: Vulnerability threat value = Common Vulnerability Scoring * [1 - (1 - Existence of publicly available exploit code) * (1 - Existence of exploit code for vulnerability scanning tools) * (1 - Existence of threat intelligence)] Wherein, the common vulnerability scoring is obtained from a vulnerability threat dataset; If the open-source component matches the exploit code dataset, the value of the existence of publicly available exploit code is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0; If the open-source component matches the exploit code dataset for vulnerability scanning tools, the value of the existence of exploit code for vulnerability scanning tools is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0; If the open-source component matches the threat intelligence dataset, the value of the existence of threat intelligence is taken as a constant greater than 0 and less than or equal to 1, otherwise the value is 0.

3. The open-source component risk control method according to claim 1, characterized in that, Calculating the software exposure value of the open-source components includes calculating the software exposure value using the following formula: Software exposure value = n * Data value of the application system * Access rights of the application system * Host-attributed network area * Host software path Wherein, n is a constant greater than 0; Obtaining the value of the data value of the application system from the host-attributed application system dataset according to the data value level of the application system corresponding to the open-source component; Obtaining the value of the access rights of the application system from the host-attributed application system dataset according to the access right type of the application system corresponding to the open-source component; Obtaining the value of the host-attributed network area from the host-attributed application system dataset according to the host-attributed network area type of the application system corresponding to the open-source component; Obtaining the value of the host software path from the host software asset dataset according to the file path type of the host corresponding to the open-source component.

4. The open-source component risk control method according to any one of claims 1-3, characterized in that, Calculating the software risk value based on the threat impact value and the software exposure value includes calculating the software risk value using the following formula: Software risk value = Vulnerability threat value + Software exposure value.

5. The open-source component risk control method according to claim 1, wherein Performing risk handling on the open-source components includes: Pushing the open-source components to a software risk management platform; The software risk management platform sends software risk notification information to application system managers according to the department to which the application system corresponding to the open-source component belongs; Opening application system management permissions for the application system managers.

6. The open-source component risk control method according to claim 2, characterized in that The vulnerability threat dataset includes one or any combination of: First vulnerability number, Vulnerable software name, Vulnerable software version, Common Vulnerability Scoring. The exploit code dataset includes: a second vulnerability number and / or an exploit code URL address; The vulnerability scanning tool exploit code dataset includes: a third vulnerability number, a scanning tool name, a scanning rule name, or any combination thereof; The threat intelligence dataset includes: a fourth vulnerability number and / or a threat intelligence name.

7. The open-source component risk control method according to claim 3, wherein The host software asset dataset includes: a first host IP address, a host software path, a host software name, a host software version, or any combination thereof; The host-attributed application system dataset includes: a second host IP address, a host-attributed network area, a host-attributed application system name, an application system administrator, an application system department, an application system data value, an application system access right, or any combination thereof.

8. The open-source component risk control method according to claim 1, characterized in that, Identifying an open-source component according to the software information includes: Calculating the similarity between the software information and the open-source component information library; In response to the similarity being greater than or equal to a preset similarity threshold, it is determined to belong to the open-source component.

9. The open-source component risk control method according to claim 8, wherein, The software information includes: a name, a version, an installation path, a dependency relationship, a digital signature, developer information, or any combination thereof.

10. An open-source component risk control system, characterized in that, Including: A memory for storing instructions executable by a processor; A processor for executing the instructions to implement the open-source component risk control method according to any one of claims 1-9.

11. A computer-readable medium storing computer program code, characterized in that, The computer program code implements the open-source component risk control method according to any one of claims 1-9 when executed by a processor.