Business risk processing method and device, readable medium, electronic equipment and product
By automatically crawling and matching vulnerability intelligence content and generating work orders, the problem of insufficient efficiency and real-time vulnerability intelligence processing is solved, timely and proactive vulnerability perception and processing is achieved, and security is improved.
Patent Information
- Application Number
- CN202510706412.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-05-28
AI Technical Summary
In the prior art, the processing efficiency and real-time performance of vulnerability intelligence are not high, and it is impossible to timely and proactively perceive and process vulnerability intelligence from different data sources, which poses security risks.
By setting a crawling policy based on the type of the data source, the vulnerability intelligence content is automatically crawled from the data source and matched it with the component information in the component library, and a processing ticket is generated to promote vulnerability repair.
It improves the efficiency and real-time nature of vulnerability perception, can promptly and proactively perceive and process vulnerability intelligence, reduces security risks, and improves the efficiency and real-time nature of vulnerability processing.
Smart Images

Figure CN120455121A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of network security and large model technology, and in particular to a business risk processing method, device, readable medium, electronic device, and product. Background Art
[0002] Vulnerability intelligence is a type of security intelligence focused on discovering and analyzing vulnerabilities in systems, applications, or hardware. It is a crucial component of network security, helping users identify, assess, and remediate potential security threats, reducing the risk of business attacks.
[0003] Vulnerability intelligence can come from a variety of sources, such as vulnerability advisories and patches released by software or hardware vendors, vulnerability analysis reports published by teams or individuals, and posts discussing vulnerabilities in open source communities. When new vulnerability-related content emerges, it requires manual collection and organization to determine whether components within the component library are affected by the vulnerability and initiate remediation. This processing is inefficient and time-sensitive, posing certain security risks. Summary of the Invention
[0004] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] In a first aspect, the present disclosure provides a method for handling business risks, the method comprising: crawling vulnerability intelligence content from the data source according to an address of the data source and a preset crawling strategy, wherein the preset crawling strategy is determined according to a type of the data source, the vulnerability intelligence content including vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability; Matching the component information of the first component with component information in a component library, and determining that a vulnerability risk exists in the second component if there is a second component in the component library that matches the component information of the first component; A processing work order for the vulnerability risk is generated according to the vulnerability information of the first vulnerability and the component information of the second component.
[0006] In a second aspect, the present disclosure provides a business risk processing device, the business risk processing device comprising: a crawling module, configured to crawl vulnerability intelligence content from the data source according to an address of the data source and a preset crawling strategy, wherein the preset crawling strategy is determined according to a type of the data source, the vulnerability intelligence content including vulnerability information of a first vulnerability, the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability; a matching module, configured to match the component information of the first component with component information in a component library, and, if a second component matching the component information of the first component exists in the component library, determine that the second component has a vulnerability risk; A generation module is used to generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component.
[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in the first aspect when executed by a processing device.
[0008] In a fourth aspect, the present disclosure provides an electronic device, comprising: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method in the first aspect.
[0009] In a fifth aspect, the present disclosure provides a computer program product, comprising a computer program, which implements the steps of the method described in the first aspect when executed by a processor.
[0010] Through the above technical solution, vulnerability intelligence content can be captured from the data source according to the address of the data source and the preset crawling strategy, and then the component information of the first component can be matched with the component information in the component library. When there is a second component in the component library that matches the component information of the first component, it is determined that the second component has a vulnerability risk. Finally, based on the vulnerability information of the first vulnerability and the component information of the second component, a processing work order for the vulnerability risk is generated. Using this method, different crawling strategies can be used for different data sources to automatically capture vulnerability intelligence content, so that vulnerability intelligence from different data sources can be perceived in a timely and proactive manner, improving the efficiency and real-time performance of vulnerability perception. In addition, it is possible to quickly analyze and determine whether the components in the component library are affected by the vulnerability, and promote vulnerability repair by generating processing work orders, thereby improving the efficiency and real-time performance of vulnerability processing.
[0011] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1 is a schematic flow chart of a business risk handling method according to an exemplary embodiment of the present disclosure; Figure 2 This is a schematic diagram of a process of content crawling in a subscription manner according to an exemplary embodiment of the present disclosure; Figure 3 This is a schematic diagram showing a process of content crawling in a non-subscription manner according to an exemplary embodiment of the present disclosure; Figure 4 is a schematic diagram showing a component matching process according to an exemplary embodiment of the present disclosure; Figure 5 This is a process diagram of a method for handling business risks according to an exemplary embodiment of the present disclosure; Figure 6 is a structural diagram of a business risk processing device according to an exemplary embodiment of the present disclosure; Figure 7 The figure is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0013] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0014] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0015] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.
[0016] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0017] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0018] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0019] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0020] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the operation requested will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operations of the disclosed technical solution based on the prompt message.
[0021] As an optional but non-limiting implementation, in response to receiving a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0022] It is understandable that the above notification and user authorization process are merely illustrative and do not limit the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0023] At the same time, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0024] Vulnerability intelligence can come from different data sources, such as vulnerability announcements and patches related to their products released by software or hardware manufacturers, vulnerability databases that centrally store and manage vulnerability information, vulnerability analysis reports released by teams or individuals, and posts by developers and users of open source projects in the community to report and discuss vulnerabilities.
[0025] When a new vulnerability begins to be discussed in a small circle, or a vulnerability breaks out on a large scale, it is necessary to analyze the technical details, exploitation conditions, attack hazards, and repair methods of the vulnerability, and determine whether the vulnerability has an impact on the company's products, software, and services. If there is an impact, an emergency response is required, and the components and scope affected by the vulnerability are counted. The affected components should be repaired to reduce and avoid the impact and harm of the vulnerability on the components, and protect the security of the company's products, software, and services.
[0026] If we wait until a new vulnerability becomes widespread before detecting and addressing it, this passive response approach can easily lead to losses. In related technologies, when new vulnerability-related content emerges, manual collection and organization are required to determine whether components within the component library are affected by the vulnerability and initiate remediation. This processing is inefficient and time-sensitive, and there is no guarantee that all vulnerability intelligence can be collected, posing certain security risks. Furthermore, from the perspective of a single vulnerability, only the impact of a component can be analyzed and determined; it is impossible to determine from the component's perspective whether a new component is affected by a vulnerability.
[0027] In view of this, the present disclosure provides a business risk management method, device, readable medium, electronic device and product to solve the above technical problems.
[0028] The following further explains the embodiments of the present disclosure with reference to the accompanying drawings.
[0029] Figure 1 is a flowchart of a business risk processing method according to an exemplary embodiment of the present disclosure, referring to Figure 1 , the business risk handling method may include the following steps: S101: Capture vulnerability intelligence content from the data source according to the address of the data source and the preset capture strategy.
[0030] The preset crawling strategy is determined according to the type of data source, the vulnerability intelligence content includes vulnerability information of the first vulnerability, and the vulnerability information of the first vulnerability includes component information of the first component affected by the first vulnerability.
[0031] For example, the data source can be a website where software or hardware manufacturers publish vulnerability announcements and patches related to their products, a vulnerability database that centrally stores and manages vulnerability information, a platform where teams or individuals publish vulnerability analysis reports, an open source community website, etc., and this disclosure does not limit this.
[0032] For example, users can pre-configure corresponding crawling configuration information for different data sources, including the data source address and crawling strategies determined by the data source type. This user can be an operations staff member in a company who analyzes and processes vulnerabilities. The specific configuration can be customized based on needs, and this disclosure does not impose any restrictions on this. Furthermore, scheduled crawling tasks can be set later to periodically crawl vulnerability intelligence content from the corresponding data source based on the crawling configuration information, ensuring comprehensive collection of vulnerability intelligence content from each data source and improving the efficiency and real-time performance of vulnerability intelligence content perception.
[0033] S102: Match the component information of the first component with the component information in the component library, and if there is a second component in the component library that matches the component information of the first component, determine that the second component has a vulnerability risk.
[0034] It should be understood that components in the component library are used in company assets such as products, software, and services. If a component contains a vulnerability risk, it can also impact the security of company assets. By matching the information of vulnerable components with the component information in the component library, it is possible to quickly determine whether company assets present security risks, improving the efficiency and real-time nature of vulnerability analysis.
[0035] S103: Generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component.
[0036] For example, when it is determined that a vulnerability has an impact on certain components, a processing work order can be automatically created for the components affected by the vulnerability to promote vulnerability management. In addition, special management can be carried out for different business lines according to the dimensions of the business lines during repair. This disclosure does not impose any restrictions on this.
[0037] In a possible manner, there are multiple second components, and the business risk handling method also includes: displaying multiple first selection items corresponding one-to-one to the multiple second components; generating a processing work order for vulnerability risks based on the vulnerability information of the first vulnerability and the component information of the second component, including: in response to the selection operation of the second selection item among the multiple first selection items, generating a processing work order for vulnerability risks based on the vulnerability information of the first vulnerability and the component information of the component corresponding to the second selection item.
[0038] For example, multiple options corresponding to components affected by the vulnerability can be displayed, so that users can manually select the components affected by the vulnerability and create corresponding processing tickets to promote vulnerability management. The specific settings can be set according to needs and are not limited by this disclosure. In this way, vulnerability management can be carried out on components in a targeted manner according to user needs.
[0039] Using this method, we can automatically capture vulnerability intelligence content using different crawling strategies for different data sources. This allows us to proactively and timely detect vulnerability intelligence from different data sources, improving the efficiency and real-time nature of vulnerability detection. Furthermore, we can quickly analyze and determine whether components within the component library are affected by vulnerabilities, and generate work orders to promote vulnerability remediation, thereby improving the efficiency and real-time nature of vulnerability handling.
[0040] In order to perceive changes in vulnerability intelligence more promptly and proactively, it is necessary to continuously monitor websites, forums, and platforms related to vulnerability intelligence, and capture the latest vulnerability intelligence from these data sources for centralized and automated analysis, judgment, and processing. However, the data formats and loading methods corresponding to different websites and platforms are usually different.
[0041] For example, some websites or platforms that are sources of vulnerability intelligence may provide subscription methods to push vulnerability intelligence to users, such as the RSS (Really Simple Syndication) subscription method.
[0042] In a possible manner, vulnerability intelligence content is captured from the data source according to the address of the data source and a preset crawling strategy, including: when the type of the data source is a preset type, vulnerability intelligence content is captured from the data source according to the following crawling strategy: detecting whether there is an updated vulnerability intelligence content item at the address of the pre-subscribed data source; when there is an updated vulnerability intelligence content item, capturing the vulnerability intelligence content from the address corresponding to the updated vulnerability intelligence content item; wherein the preset type represents the type of vulnerability intelligence content displayed through subscription.
[0043] For example, Figure 2 As shown, taking the RSS subscription method as an example, a website or platform usually provides a subscription RSS link address. For such a website or platform, users can subscribe to the address through the subscription service provided by the website or platform. The page corresponding to the address is used to display vulnerability intelligence content items, such as vulnerability intelligence entries, and each entry corresponds to an address to enter the vulnerability intelligence details page.
[0044] For example, a scheduled crawling task can be configured to periodically detect whether there are updated vulnerability intelligence entries at the address. If there are new vulnerability intelligence entries, the link address corresponding to the new vulnerability intelligence entry can be obtained and the vulnerability intelligence content in the vulnerability intelligence details page corresponding to the address can be crawled so that the vulnerability intelligence content can be processed and analyzed subsequently. This disclosure does not impose any restrictions on this.
[0045] That is to say, the disclosed embodiment supports detection and data capture of subscription-based websites or platforms, thereby obtaining vulnerability intelligence on data sources that provide subscription methods, enriching the sources of vulnerability intelligence, and thereby improving the comprehensiveness and real-time perception of vulnerability intelligence content.
[0046] In addition, some vulnerability intelligence sources have a security announcement page displaying vulnerability and security-related information. Another type of information source is forums where users post messages to discuss vulnerabilities. These websites or platforms can be categorized as either static or dynamic based on data loading.
[0047] Static loading refers to website content being directly returned by the server when the page loads. Typically, all content is already included in the HTML (Hypertext Markup Language) file, eliminating the need for users to make additional requests to load data. Dynamic loading refers to website content not being directly returned when the page loads. Instead, data is dynamically requested and rendered on the front end using technologies like JavaScript.
[0048] In the related art, the page content of a statically loaded website can be directly captured, but dynamic loading requires executing Javascript on the browser and calling other interfaces to obtain data before rendering and displaying it, so it is impossible to directly capture the page content.
[0049] In a possible manner, vulnerability intelligence content is captured from the data source according to the address of the data source and a preset crawling strategy, including: when the type of the data source is not a preset type, the vulnerability intelligence content is captured from the data source according to the following crawling strategy: capturing the first initial content from the address of the data source; when the first initial content includes a vulnerability intelligence address that meets the preset matching rules, the vulnerability intelligence content is captured according to the vulnerability intelligence address; wherein the preset type represents the type of vulnerability intelligence content displayed through subscription.
[0050] It's important to note that non-subscription websites often have richer data, with multiple entries on a single page. Each entry links to its own specific detail page, so you need to analyze each entry to determine if it corresponds to the vulnerability intelligence detail page. Therefore, in addition to configuring the website's link address, you also need to configure matching rules for extracting the detail page address corresponding to the vulnerability intelligence content on the page.
[0051] For example, Figure 3As shown, for statically loaded or dynamically loaded websites or platforms, you can configure the link address of such websites or platforms, and then configure a scheduled crawling task to periodically crawl page content from the address, and perform content matching on the crawled page content based on preset matching rules. The preset matching rules are used to match the address link corresponding to the vulnerability intelligence content in the page content.
[0052] Furthermore, if a match is successful, it means that the data loading method of the website or platform is static loading, that is, the type of the website or platform is static loading. In other words, the address of the detail page corresponding to the vulnerability intelligence content can be directly obtained from the crawled page content, and the vulnerability intelligence content can be crawled based on this address.
[0053] In the disclosed embodiment, detection and data capture of statically loaded websites or platforms are supported, so that vulnerability intelligence on statically loaded data sources can be obtained, the sources of vulnerability intelligence acquisition can be enriched, and the comprehensiveness and real-time perception of vulnerability intelligence content can be improved.
[0054] In a possible manner, the business risk handling method also includes: when the first initial content does not include a vulnerability intelligence address that meets the preset matching rules, crawling the second initial content from the address of the data source through a content crawling tool; when the second initial content includes a vulnerability intelligence address that meets the preset matching rules, crawling the vulnerability intelligence content according to the vulnerability intelligence address.
[0055] For example, continue to refer to Figure 3 If the crawled page content fails to match the preset matching rules, it indicates that the website or platform's data loading method is dynamic loading, that is, the website or platform type is dynamic loading. In other words, it is necessary to use the crawler tool to crawl the page content again and perform a second match based on the preset matching rules. If a match is successful, the page content contains the address of the detail page corresponding to the vulnerability intelligence content, and the vulnerability intelligence content can be crawled based on this address.
[0056] The crawling tool may be a headless crawling tool, a fake UA (User-Agent) crawling tool, etc., and this disclosure does not impose any restrictions on this.
[0057] In the disclosed embodiment, detection and data capture of dynamically loaded websites or platforms are supported, so that vulnerability intelligence on statically loaded data sources can be obtained, the sources of vulnerability intelligence acquisition can be enriched, and the comprehensiveness and real-time nature of vulnerability intelligence content perception can be improved.
[0058] In a possible manner, the vulnerability intelligence address that meets the preset matching rules includes at least one of the following: a first intelligence address that meets the first preset address rule; a second intelligence address marked with a first preset page label; a third intelligence address that does not meet the preset exception list, and the preset exception list includes the second preset address rule and / or the second preset page label.
[0059] For example, the preset matching rule can be an address matching rule. Assuming that a page about vulnerability intelligence "http: / / abc.com / defg / " contains multiple vulnerability intelligences, and it is necessary to parse and obtain the details of each vulnerability intelligence, a matching rule can be configured based on the details page of the vulnerability intelligence, such as the address rule "http: / / abc\.com / defg / .+". For example, if the captured content page includes a link address of "http: / / abc.com / defg / hij", it means that the link address is the address of the details page of the vulnerability intelligence. The address is extracted, and the vulnerability intelligence content can be captured through the address. If the captured content page includes a link address of "http: / / abc.com / xyz", it means that the link address is not the address of the details page of the vulnerability intelligence. The above rules can be set through regular rules or other forms of rules, and the present disclosure does not limit this.
[0060] For example, the preset matching rule can be a page tag rule. If the captured page content includes the address of the vulnerability intelligence details page, the corresponding page source code will carry a preset page tag. Therefore, the page tag can be used to determine whether the captured page content includes the vulnerability intelligence details page address, extract the address, and then capture the vulnerability intelligence content through the address.
[0061] It should be noted that the labels of the details page addresses of different data sources can be different, so as to distinguish different data sources. For example, if the vulnerability intelligence content page references vulnerability intelligence from different data sources, different details page addresses can be distinguished by different page labels. This disclosure does not impose any restrictions on this.
[0062] For example, you can also set up an exception list. For example, you can set the address matching rules and / or page tag rules in the exception list based on the address of the detail page of non-vulnerability intelligence. Then, when an address that meets the rules set in the exception list is captured in the page content, the detail page corresponding to the address will not be further crawled based on the address. In other words, the exception list can avoid crawling the detail page content of non-vulnerability intelligence.
[0063] In the disclosed embodiment, a content crawling framework is provided, which supports automatic periodic detection and data crawling of RSS, statically loaded and dynamically loaded websites. Users can configure the link addresses of the websites or platforms that need to be crawled on the vulnerability intelligence platform, and support the configuration of regular rules to extract the content in the crawled pages. This facilitates configuration and maintenance and has the ability to actively crawl various types of websites, flexibly meeting users' content crawling needs for different data sources and different page characteristics. For example, when crawling a forum website, the crawling rules can be configured based on the link characteristics of the posts in the page, so that when a website page is crawled, the post links in the page can be parsed and obtained through the set matching rules, and then the content of each post, that is, the vulnerability intelligence content, can be obtained through the link.
[0064] In this way, when new vulnerability intelligence is made public, it can be discovered and captured for analysis and processing in the first place, with high timeliness and automation capabilities, avoiding the situation where vulnerabilities are discovered only after the vulnerability intelligence has been widely disseminated, or vulnerabilities are perceived only after the business has been attacked.
[0065] It's worth noting that vulnerability intelligence captured from various data sources is unstructured data. The data format and content vary from website to website, and it contains a mix of various information, including fields and information related to vulnerability intelligence. To automate subsequent analysis and processing, it's necessary to extract the relevant fields from the unstructured data and assemble them into a pre-defined format, such as JSON. This format can be customized and is not limited in this disclosure.
[0066] While regular expressions or other string-related processing functions can be used, due to the large number of fields related to vulnerability intelligence and the varying HTML styles of different websites, extracting vulnerability intelligence-related fields individually from HTML using regular expressions or strings would require maintaining a large number of rules, be cumbersome, and inefficient. Furthermore, some data features are not readily apparent, making rule-based extraction inaccurate.
[0067] In a possible manner, the vulnerability information of the first vulnerability is extracted in the following manner: semantically understanding the vulnerability intelligence content through the first large model, and extracting the content of the vulnerability intelligence content based on the vulnerability intelligence knowledge to obtain initial vulnerability information; formatting the initial vulnerability information through the first large model to obtain vulnerability information of the first vulnerability in a preset format.
[0068] In the disclosed embodiments, an LLM (Large Language Model) model can be used to extract and process vulnerability intelligence-related content from content scraped from different websites or platforms. The LLM model can be pre-input with vulnerability intelligence knowledge so that it understands vulnerability intelligence-related content. This allows it to find vulnerability intelligence-related content from unstructured text based on semantics.
[0069] For example, prompt words can be constructed based on vulnerability intelligence content and extraction examples, and an automated process can be established to call the large model. This allows the entire processing process to analyze and extract vulnerability-related fields and data just like vulnerability intelligence experts, and assemble them into a preset format, such as JSON. The specific format can be set according to needs and is not limited by this disclosure. This not only improves the efficiency and accuracy of vulnerability information extraction, but also facilitates subsequent analysis and processing.
[0070] It is worth noting that the fields and data related to the vulnerability may include basic information such as the vulnerability name, number, discovery and disclosure time, and scope of impact, technical details such as the cause of the vulnerability, technical analysis, affected components, and utilization methods, hazard assessment information such as the severity of the vulnerability and possible attack consequences, repair suggestions such as vulnerability patches, mitigation measures or repair methods, and whether there have been any attack activities targeting the vulnerability, etc., which can be set specifically according to needs and this disclosure does not impose any restrictions on this.
[0071] Furthermore, based on the vulnerability intelligence-related fields and data extracted from the vulnerability intelligence content, as well as some component information, we can match it with components in the component library to determine whether any components are affected by the vulnerability. The component library includes component names and version numbers, as well as information such as publishers and architectures. Therefore, we can match component names and version numbers with information in the component library.
[0072] In a possible approach, matching component information of the first component with component information in a component library includes: matching the component name of the first component with the component name in the component library; and if a candidate component matching the component name of the first component exists in the component library, matching the version number range of the first component with the version number of the candidate component. If a second component matching the component information of the first component exists in the component library, determining that the second component has a vulnerability risk includes: if the version number of the candidate component is included in the version number range of the first component, determining that the candidate component is the second component, and determining that the second component has a vulnerability risk.
[0073] For example, Figure 4As shown, the system first checks whether there is a candidate component in the component library that matches the first component's name. If so, it then determines whether the candidate component's version number is within the version number range affected by the vulnerability. If so, the candidate component is identified as the second component and a vulnerability risk is determined for the second component. This allows for efficient and accurate determination of whether any component is affected by the vulnerability, facilitating subsequent vulnerability remediation and protecting component security.
[0074] In addition, matching can also be performed based on other component information, such as publisher, architecture, etc., which can be specifically determined according to needs and is not limited in this disclosure.
[0075] In a possible manner, matching is performed based on the component name of the first component and the component name in the component library, including: inputting the component name of the first component and the component name in the component library into a second large model to determine through the second large model whether there is a candidate component in the component library that matches the component name of the first component, and the second large model is used to determine whether at least two component names correspond to the same component based on the at least two component names input.
[0076] It should be noted that due to the inconsistency of component name formats, for example, ABC, abc, A_bc, and de may represent the same component. In this case, directly judging whether they are the same component by character equality will result in incomplete judgment.
[0077] Therefore, the macro model can be used to determine whether a component has a matching component name in the component library, thereby improving the accuracy of component name matching. In addition, expert knowledge of different names for the same component can be pre-input to assist the macro model in making judgments, further improving the accuracy of component name matching. The specific settings can be customized according to needs and are not limited by this disclosure.
[0078] It should be understood that both the first large model and the second large model can be trained according to demand to obtain corresponding data processing capabilities, and this disclosure will not go into details here.
[0079] In a possible manner, when the version number of the candidate component is included in the version number range of the first component, the candidate component is determined to be the second component, including: converting the version number of the candidate component, the lower limit version number and the upper limit version number of the first component into numerical values according to preset conversion rules, the preset conversion rules including a first conversion rule for converting a numerical version number into a numerical value and / or a second conversion rule for converting a non-numeric version number into a numerical value; when the numerical value corresponding to the version number of the candidate component is greater than or equal to the numerical value corresponding to the lower limit version number and less than or equal to the numerical value corresponding to the upper limit version number, the candidate component is determined to be the second component.
[0080] It should be noted that the standard format of the component version number is abc. Generally, when judging the version number, it is necessary to judge each field in the version number. For example, the first digit of the two version numbers 1.2.1 and 1.3.1 is 1, and the second digit 3 is greater than 2, so 1.3.1 is greater than 1.2.1.
[0081] In an embodiment of the present disclosure, for a component version number in the pure numeric abc format, it can be converted into an integer according to certain encoding rules. For example, the version number can be converted into an integer according to the rule of a×10^m+b×10^n+c×10^p, where a, b, c, m, n, and p are positive integers. The specific setting can be based on the needs, and the present disclosure does not impose any restrictions on this. The version number of the candidate component, the lower limit version number of the first component, and the upper limit version number are converted into integers, and then the size of the integers is quickly compared to determine whether the version number of the candidate component is within the version number range affected by the vulnerability, thereby improving the efficiency of version number comparison.
[0082] However, there are also non-standard component version numbers, such as 9.6p1-1. For this type of component version number, because the meanings of special characters in different product version numbers are also different, encoding rules can be pre-defined for special characters, such as p1 corresponding to an integer, -1 corresponding to an integer, and so on. The specific setting can be based on demand and is not limited by this disclosure. Then, by continuing to convert it into an integer according to certain encoding rules, it is convenient to compare whether the version number of the candidate component is within the version number range affected by the vulnerability.
[0083] It is worth noting that when a match is made based on vulnerability information and components and there is a matching result, it means that the vulnerability has an impact on certain assets of the company. At this time, the user can select the components affected by the vulnerability on the vulnerability intelligence platform and perform vulnerability management by creating a processing work order. It can also automatically create a processing work order to manage the vulnerability. When managing vulnerabilities, special management can also be carried out for different business lines based on the latitude of business lines. This disclosure does not restrict this. When creating a processing work order, the basic information of the vulnerability, the attack method, repair suggestions, the affected components and other vulnerability information will be displayed on the work order to facilitate vulnerability handling personnel to repair the vulnerability.
[0084] Manage vulnerabilities in affected components by creating and processing work orders, drive business repairs, and reduce and avoid the impact of vulnerabilities on company assets.
[0085] It should be noted that after the repair is complete, retesting will be performed. One method is to conduct attack tests on the component to determine whether the vulnerability still exists. On the other hand, after a preset period, newly acquired vulnerability intelligence can be used to determine whether the repaired component is still within the scope of the vulnerability. If it is not within the scope of the vulnerability, it means that the component has been repaired for this vulnerability. The specific settings can be set according to needs and are not limited by this disclosure.
[0086] When new vulnerability intelligence is added, we can only determine whether the vulnerability affects the components in the component library based on the vulnerability intelligence. However, when new components are added, we cannot clearly determine whether the new components are affected by the vulnerability. Therefore, it is necessary to output and maintain a vulnerability intelligence library based on vulnerability information.
[0087] In a possible manner, there are multiple data sources, and the business risk handling method also includes: storing multiple vulnerability information obtained from multiple data sources into a first vulnerability intelligence table respectively, wherein each vulnerability information includes multiple fields; cleaning the multiple vulnerability information in the first vulnerability intelligence table according to the field dimension, and marking the multiple vulnerability information with graded labels to obtain marked vulnerability information, and storing the marked vulnerability information in a second vulnerability intelligence table, the graded label includes a first label for the data source and / or a second label for the field in the vulnerability information, the level corresponding to the graded label is positively correlated with the accuracy of the vulnerability intelligence, and the same field for the same vulnerability in the second vulnerability intelligence table is associated with at least one field data from at least one data source; for different first field data associated with the same field of the same vulnerability in the second vulnerability intelligence table, extracting the first field data with the highest level corresponding to the graded label to obtain second field data, and storing the second field data in a third vulnerability intelligence table; summarizing the second field data for the same vulnerability in the third vulnerability intelligence table to obtain first vulnerability intelligence, and storing the first vulnerability intelligence in the vulnerability intelligence library.
[0088] It should be noted that vulnerability information can be integrated to construct a vulnerability intelligence database. Since the data sources of vulnerability information are diverse, the vulnerability information corresponding to each data source has similarities and differences. In order to create a high-quality vulnerability intelligence database, in the embodiment of the present disclosure, the plurality of vulnerability information in a preset format output by the above-mentioned first large model and coming from different data sources can be stored in a base table, namely the first vulnerability intelligence table. Then, the plurality of vulnerability information in the first vulnerability intelligence table can be cleaned from the field dimension, such as deleting some unnecessary fields, etc. The specific settings can be made according to the needs, and the present disclosure does not impose any restrictions on this.
[0089] For example, a graded label is labeled for each field of multiple vulnerability information. For example, if data source A has higher vulnerability information accuracy than data source B, then the graded label corresponding to the vulnerability information of data source A is higher than the graded label corresponding to the vulnerability information of data source B. That is, the fields are labeled with graded labels from the data source dimension. Alternatively, if data source A has higher vulnerability information accuracy than data source B, but data source B has higher accuracy for a certain field information, in this case, it is necessary to separately label the field information with a graded label from the field dimension. That is, the graded label corresponding to the vulnerability information of data source A for the field information is lower than the graded label corresponding to the vulnerability information of data source B for the field information. The labeled vulnerability information is then stored in a detailed table, i.e., the second vulnerability intelligence table.
[0090] For example, in a detailed table, the same field for the same vulnerability may have field data from different data sources. In this case, it is necessary to extract the field data with the highest level corresponding to the grading label and store the extracted field data in an intermediate table, namely the third vulnerability intelligence table.
[0091] Then, according to the vulnerability dimension, the extracted field data for the same vulnerability is aggregated to obtain vulnerability intelligence for the vulnerability, which is stored in a wide table and then stored in the final vulnerability intelligence database. The information included in the vulnerability intelligence can be determined based on the above-mentioned vulnerability-related fields and data, and this disclosure does not limit this.
[0092] By labeling vulnerability information with hierarchical labels and processing it in layers, the relevant data of vulnerability intelligence is cleaned and aggregated according to the processing logic of base table, detailed table, intermediate table, and wide table, and stored in the vulnerability intelligence database. This ensures that each field of intelligence data in the vulnerability intelligence database comes from the most accurate data source, thereby ensuring the quality of the data in the vulnerability intelligence database.
[0093] In a possible manner, the vulnerability intelligence in the vulnerability intelligence library includes component information of the component affected by the second vulnerability, and the business risk handling method also includes: in response to the addition of a third component to the component library, matching the component information of the third component with the component information of the component in the vulnerability intelligence library; when there is matching component information in the vulnerability intelligence library that matches the component information of the third component, determining that there is a vulnerability risk in the third component, and determining the second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence library; generating a processing work order for the vulnerability risk of the third component based on the second vulnerability intelligence and the component information of the third component.
[0094] For example, the second vulnerability refers to all vulnerabilities in the vulnerability intelligence library, including the first vulnerability mentioned above. When a new component is added to the component library, a query is performed in the vulnerability intelligence library based on the component information to determine whether the new component is affected by a vulnerability in the vulnerability intelligence library. If so, a work order is created to address the vulnerability. By building and maintaining a vulnerability intelligence library, it is possible to quickly determine whether a new component is affected by a vulnerability in the vulnerability library, thus ensuring the security of company assets.
[0095] Furthermore, for scenarios requiring vulnerability intelligence data, this data can be pushed to downstream scenarios for consumption and processing via subscription. For example, black-and-white box scanning tools can scan for related vulnerabilities based on vulnerability intelligence information, and firewall tools can also set up plug-ins based on vulnerability intelligence information to block malicious access attack traffic. This disclosure does not limit this.
[0096] The vulnerability management solution of the embodiment of the present disclosure is as follows: Figure 5 As shown, operators processing vulnerability intelligence can configure the vulnerability intelligence platform with information such as the URLs of websites or platforms to be detected and crawled, as well as matching rules. This information is then periodically scheduled for crawling based on the configuration. The captured vulnerability intelligence content is parsed and fields extracted using a large model. Once the vulnerability information is obtained, it can be formatted, filtered, aggregated, and stored in the vulnerability intelligence database.
[0097] Furthermore, continue to refer to Figure 5 Based on vulnerability intelligence, the affected components can be matched against the components of assets across the company's business lines. If a matching component exists, it indicates that the component is affected by the vulnerability and poses a security risk. Operations personnel can be notified to create a work order, or the work order can be automatically created, allowing vulnerability remediation personnel to repair the affected business until the fix is complete.
[0098] The developed vulnerability intelligence detection and capture framework can proactively detect and capture vulnerability intelligence from various websites or platforms. Once vulnerability intelligence is detected and captured, the big model technology can be used to efficiently and accurately extract key information and fields from the vulnerability intelligence. The big model can also assist in determining whether the vulnerability impacts the company's assets. If a vulnerability is identified, a work order is created to manage the affected assets, drive business remediation, and minimize or avoid the impact of the vulnerability on company assets.
[0099] Based on the same concept, the embodiment of the present disclosure also provides a business risk processing device, such as Figure 6 As shown, the business risk processing device 600 may include: A capture module 601 is configured to capture vulnerability intelligence content from a data source according to an address of the data source and a preset capture strategy, wherein the preset capture strategy is determined based on the type of the data source, the vulnerability intelligence content including vulnerability information of a first vulnerability, the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability; a matching module 602 configured to match the component information of the first component with component information in a component library, and determine that a vulnerability risk exists in the second component if a second component matching the component information of the first component exists in the component library; The generating module 603 is configured to generate a processing work order for the vulnerability risk according to the vulnerability information of the first vulnerability and the component information of the second component.
[0100] Optionally, the capture module 601 is used to: When the data source is of a preset type, the vulnerability intelligence content is captured from the data source according to the following capture strategy: Detecting whether there is an updated vulnerability intelligence content item at the address of the pre-subscribed data source; If the updated vulnerability intelligence content item exists, capturing the vulnerability intelligence content from the address corresponding to the updated vulnerability intelligence content item; The preset type represents the type of vulnerability intelligence content displayed through subscription.
[0101] Optionally, the capture module 601 is used to: When the type of the data source is not a preset type, the vulnerability intelligence content is captured from the data source according to the following capture strategy: Fetching first initial content from the address of the data source; In a case where the first initial content includes a vulnerability intelligence address that meets a preset matching rule, crawling the vulnerability intelligence content according to the vulnerability intelligence address; The preset type represents the type of vulnerability intelligence content displayed through subscription.
[0102] Optionally, the business risk processing device 600 further includes a capture submodule, which is configured to: In a case where the first initial content does not include a vulnerability intelligence address that satisfies the preset matching rule, crawling the second initial content from the address of the data source using a content crawling tool; In a case where the second initial content includes a vulnerability intelligence address that meets the preset matching rule, the vulnerability intelligence content is captured according to the vulnerability intelligence address.
[0103] Optionally, the vulnerability intelligence address that meets the preset matching rule includes at least one of the following: A first information address that satisfies a first preset address rule; A second information address marked with a first preset page label; A third intelligence address that does not satisfy a preset exception list, wherein the preset exception list includes a second preset address rule and / or a second preset page tag.
[0104] Optionally, the vulnerability information of the first vulnerability is extracted in the following manner: Perform semantic understanding of the vulnerability intelligence content through the first model, and extract content from the vulnerability intelligence content based on vulnerability intelligence knowledge to obtain initial vulnerability information; The initial vulnerability information is formatted using the first large model to obtain vulnerability information of the first vulnerability in a preset format.
[0105] Optionally, the matching module 602 is configured to: matching the component name of the first component with the component names in the component library; If there is a candidate component in the component library that matches the component name of the first component, matching the version number range of the first component with the version number of the candidate component; The matching module 602 is used to: In a case where the version number of the candidate component is included in the version number range of the first component, the candidate component is determined to be the second component, and it is determined that the second component has a vulnerability risk.
[0106] Optionally, the matching module 602 is configured to: The component name of the first component and the component name in the component library are input into the second large model to determine whether there is a candidate component in the component library that matches the component name of the first component through the second large model. The second large model is used to determine whether the at least two component names correspond to the same component based on the at least two component names input.
[0107] Optionally, the matching module 602 is configured to: Converting the version number of the candidate component, the lower limit version number, and the upper limit version number of the first component into numerical values according to preset conversion rules, wherein the preset conversion rules include a first conversion rule for converting a numerical version number into a numerical value and / or a second conversion rule for converting a non-numerical version number into a numerical value; When the value corresponding to the version number of the candidate component is greater than or equal to the value corresponding to the lower limit version number and less than or equal to the value corresponding to the upper limit version number, the candidate component is determined as the second component.
[0108] Optionally, there are multiple data sources, and the business risk processing device 600 further includes a summary module, which is configured to: storing the plurality of vulnerability information obtained from the plurality of data sources into a first vulnerability intelligence table, wherein each vulnerability information includes a plurality of fields; Cleaning multiple vulnerability information in the first vulnerability intelligence table according to field dimensions, labeling the multiple vulnerability information with graded labels to obtain labeled vulnerability information, and storing the labeled vulnerability information in a second vulnerability intelligence table, wherein the graded labels include a first label for the data source and / or a second label for a field in the vulnerability information, and the level corresponding to the graded label is positively correlated with the accuracy of the vulnerability intelligence. In the second vulnerability intelligence table, the same field for the same vulnerability is associated with at least one field data from at least one data source; For different first field data associated with the same field of the same vulnerability in the second vulnerability intelligence table, extract the first field data with the highest level corresponding to the grading label to obtain second field data, and store the second field data in the third vulnerability intelligence table; The second field data for the same vulnerability in the third vulnerability intelligence table are aggregated to obtain first vulnerability intelligence, and the first vulnerability intelligence is stored in a vulnerability intelligence database.
[0109] Optionally, the vulnerability intelligence in the vulnerability intelligence database includes component information of a component affected by the second vulnerability, and the business risk processing device 600 further includes a generation submodule, the generation submodule being configured to: In response to a third component being newly added to the component library, matching component information of the third component with component information of components in the vulnerability intelligence library; If matching component information matching the component information of the third component exists in the vulnerability intelligence library, determining that the third component has a vulnerability risk, and determining second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence library; A work order for handling the vulnerability risk of the third component is generated based on the second vulnerability intelligence and the component information of the third component.
[0110] Optionally, there are multiple second components, and the business risk processing device 600 further includes a display module, which is configured to: Displaying a plurality of first selection items corresponding one-to-one to a plurality of the second components; The generating module 603 is used to: In response to a selection operation on a second option among the plurality of first options, a processing work order for the vulnerability risk is generated according to vulnerability information of the first vulnerability and component information of a component corresponding to the second option.
[0111] Based on the same concept, an embodiment of the present disclosure further provides a computer-readable medium on which a computer program is stored. When the program is executed by a processing device, the steps of any of the above-mentioned business risk handling methods are implemented.
[0112] Based on the same concept, an embodiment of the present disclosure further provides an electronic device, which may include: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of any of the above-mentioned business risk processing methods.
[0113] Based on the same concept, an embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the steps of any of the above-mentioned business risk handling methods when executed by a processor.
[0114] Reference below Figure 7 , which shows a schematic structural diagram of an electronic device 700 suitable for implementing an embodiment of the present disclosure. The terminal device in the embodiment of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0115] like Figure 7 As shown, electronic device 700 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 702 or programs loaded from a storage device 708 into a random access memory (RAM) 703. Various programs and data required for the operation of electronic device 700 are also stored in RAM 703. Processing device 701, ROM 702, and RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to bus 704.
[0116] Typically, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or by wire to exchange data. Figure 7 The electronic device 700 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.
[0117] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0118] It should be noted that the computer-readable medium described above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.
[0119] In some embodiments, communications may be conducted using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0120] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0121] The above-mentioned computer-readable medium carries one or more programs. When the above-mentioned one or more programs are executed by the electronic device, the electronic device is caused to: crawl vulnerability intelligence content from the data source according to the address of the data source and a preset crawling strategy, the preset crawling strategy is determined according to the type of the data source, and the vulnerability intelligence content includes vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability includes component information of a first component affected by the first vulnerability; match the component information of the first component with the component information in the component library, and if there is a second component in the component library that matches the component information of the first component, determine that the second component has a vulnerability risk; generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component.
[0122] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0124] The modules described in the embodiments of the present disclosure may be implemented in software or hardware, wherein the name of a module does not necessarily limit the module itself.
[0125] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0126] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0127] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the present disclosure is not limited to technical solutions formed by specific combinations of the aforementioned technical features. It also encompasses other technical solutions formed by any combination of the aforementioned technical features or their equivalents, without departing from the scope of the above disclosure. For example, a technical solution formed by replacing the aforementioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0128] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0129] Although the subject matter has been described using language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above-described embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated upon here.
Claims
1. A business risk management method, characterized in that: The business risk handling method includes: crawling vulnerability intelligence content from the data source according to an address of the data source and a preset crawling strategy, wherein the preset crawling strategy is determined according to a type of the data source, the vulnerability intelligence content including vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability; Matching the component information of the first component with component information in a component library, and determining that a vulnerability risk exists in the second component if there is a second component in the component library that matches the component information of the first component; A processing work order for the vulnerability risk is generated according to the vulnerability information of the first vulnerability and the component information of the second component.
2. The business risk management method according to claim 1, characterized in that: The step of capturing vulnerability intelligence content from the data source according to the address of the data source and the preset capture strategy includes: When the data source is of a preset type, the vulnerability intelligence content is captured from the data source according to the following capture strategy: Detecting whether there is an updated vulnerability intelligence content item at the address of the pre-subscribed data source; If the updated vulnerability intelligence content item exists, capturing the vulnerability intelligence content from the address corresponding to the updated vulnerability intelligence content item; The preset type represents the type of vulnerability intelligence content displayed through subscription.
3. The business risk management method according to claim 1, characterized in that: The step of capturing vulnerability intelligence content from the data source according to the address of the data source and the preset capture strategy includes: When the type of the data source is not a preset type, the vulnerability intelligence content is captured from the data source according to the following capture strategy: Fetching first initial content from the address of the data source; In a case where the first initial content includes a vulnerability intelligence address that meets a preset matching rule, crawling the vulnerability intelligence content according to the vulnerability intelligence address; The preset type represents the type of vulnerability intelligence content displayed through subscription.
4. The business risk handling method according to claim 3, characterized in that: The business risk handling method further includes: In a case where the first initial content does not include a vulnerability intelligence address that satisfies the preset matching rule, crawling the second initial content from the address of the data source using a content crawling tool; In a case where the second initial content includes a vulnerability intelligence address that meets the preset matching rule, the vulnerability intelligence content is captured according to the vulnerability intelligence address.
5. The business risk handling method according to claim 3 or 4, characterized in that: The vulnerability intelligence address that meets the preset matching rules includes at least one of the following: A first information address that satisfies a first preset address rule; A second information address marked with a first preset page label; A third intelligence address that does not satisfy a preset exception list, wherein the preset exception list includes a second preset address rule and / or a second preset page tag.
6. The business risk handling method according to any one of claims 1 to 4, characterized in that: The vulnerability information of the first vulnerability is extracted in the following way: Perform semantic understanding of the vulnerability intelligence content through the first model, and extract content from the vulnerability intelligence content based on vulnerability intelligence knowledge to obtain initial vulnerability information; The initial vulnerability information is formatted using the first large model to obtain vulnerability information of the first vulnerability in a preset format.
7. The business risk handling method according to any one of claims 1 to 4, characterized in that: The matching of the component information of the first component with the component information in the component library includes: matching the component name of the first component with the component names in the component library; If there is a candidate component in the component library that matches the component name of the first component, matching the version number range of the first component with the version number of the candidate component; When a second component matching the component information of the first component exists in the component library, determining that the second component has a vulnerability risk includes: In a case where the version number of the candidate component is included in the version number range of the first component, the candidate component is determined to be the second component, and it is determined that the second component has a vulnerability risk.
8. The business risk handling method according to claim 7, characterized in that: The matching of the component name of the first component with the component name in the component library includes: The component name of the first component and the component name in the component library are input into the second large model to determine whether there is a candidate component in the component library that matches the component name of the first component through the second large model. The second large model is used to determine whether the at least two component names correspond to the same component based on the at least two component names input.
9. The business risk handling method according to claim 7, characterized in that: The step of determining the candidate component as the second component when the version number of the candidate component is included in the version number range of the first component includes: Converting the version number of the candidate component, the lower limit version number, and the upper limit version number of the first component into numerical values according to preset conversion rules, wherein the preset conversion rules include a first conversion rule for converting a numerical version number into a numerical value and / or a second conversion rule for converting a non-numerical version number into a numerical value; When the value corresponding to the version number of the candidate component is greater than or equal to the value corresponding to the lower limit version number and less than or equal to the value corresponding to the upper limit version number, the candidate component is determined as the second component.
10. The business risk handling method according to any one of claims 1 to 4, characterized in that: There are multiple data sources, and the business risk processing method further includes: storing the plurality of vulnerability information obtained from the plurality of data sources into a first vulnerability intelligence table, wherein each vulnerability information includes a plurality of fields; Cleaning multiple vulnerability information in the first vulnerability intelligence table according to field dimensions, labeling the multiple vulnerability information with graded labels to obtain labeled vulnerability information, and storing the labeled vulnerability information in a second vulnerability intelligence table, wherein the graded labels include first labels for the data source and / or second labels for fields in the vulnerability information, and the grades corresponding to the graded labels are positively correlated with the accuracy of the vulnerability intelligence. In the second vulnerability intelligence table, the same field for the same vulnerability is associated with at least one first field data from at least one data source; For different first field data associated with the same field of the same vulnerability in the second vulnerability intelligence table, extract the first field data with the highest level corresponding to the grading label to obtain second field data, and store the second field data in the third vulnerability intelligence table; The second field data for the same vulnerability in the third vulnerability intelligence table are aggregated to obtain first vulnerability intelligence, and the first vulnerability intelligence is stored in a vulnerability intelligence database.
11. The business risk handling method according to claim 10, characterized in that: The vulnerability intelligence in the vulnerability intelligence library includes component information of components affected by the second vulnerability, and the business risk processing method further includes: In response to a third component being newly added to the component library, matching component information of the third component with component information of components in the vulnerability intelligence library; If matching component information matching the component information of the third component exists in the vulnerability intelligence library, determining that the third component has a vulnerability risk, and determining second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence library; A work order for handling the vulnerability risk of the third component is generated based on the second vulnerability intelligence and the component information of the third component.
12. The business risk handling method according to any one of claims 1 to 4, characterized in that: There are multiple second components, and the business risk handling method further includes: Displaying a plurality of first selection items corresponding one-to-one to a plurality of the second components; Generating a processing work order for the vulnerability risk according to the vulnerability information of the first vulnerability and the component information of the second component includes: In response to a selection operation on a second option among the plurality of first options, a processing work order for the vulnerability risk is generated according to vulnerability information of the first vulnerability and component information of a component corresponding to the second option.
13. A business risk processing device, characterized in that: The business risk processing device includes: a crawling module, configured to crawl vulnerability intelligence content from the data source according to an address of the data source and a preset crawling strategy, wherein the preset crawling strategy is determined according to a type of the data source, the vulnerability intelligence content including vulnerability information of a first vulnerability, the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability; a matching module, configured to match the component information of the first component with component information in a component library, and, if a second component matching the component information of the first component exists in the component library, determine that the second component has a vulnerability risk; A generation module is used to generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component.
14. A computer-readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 12 are implemented.
15. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 12.
16. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Method and device for bug repairing
CN107480533A
Network vulnerability monitoring management method and device, medium and electronic equipment
CN114938283A
Data threat discovery method and device, electronic equipment and storage medium
CN118573432A
Vulnerability processing method and device, equipment and storage medium
CN119670098A
Methods and apparatus for analyzing and scoring digital risks
US11757916B1