Business risk processing method and device, readable medium, electronic equipment and product
By setting data source capture strategies and using large language models to process vulnerability intelligence, the problem of low vulnerability intelligence processing efficiency was solved, achieving efficient and real-time vulnerability detection and processing.
Patent Information
- Application Number
- CN202510706412.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-05-28
AI Technical Summary
In existing technologies, the processing efficiency and real-time performance of vulnerability intelligence are not high, and it is impossible to proactively detect vulnerability intelligence from different data sources in a timely manner, resulting in low vulnerability processing efficiency and security risks.
By setting crawling strategies based on the type of data source, vulnerability intelligence content is crawled from the data source, and component information is matched with component libraries to generate processing tickets to promote vulnerability remediation. The Large Language Model (LLM) is used for semantic understanding and data processing, supporting data crawling from statically and dynamically loaded websites.
It improves the efficiency and real-time performance of vulnerability detection, enabling timely and proactive analysis of whether components in the component library are affected by vulnerabilities, and quickly generating processing work orders, thereby improving the efficiency and real-time performance of vulnerability handling.
Smart Images

Figure CN120455121B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of network security and large model technology, in particular, to a business risk processing method and device, readable medium, electronic equipment and product. BACKGROUND
[0002] Vulnerability intelligence is a kind of security intelligence, which focuses on discovering and analyzing vulnerabilities in systems, applications or hardware. It is an important part of the field of network security, which can help users identify, evaluate and repair potential security threats, and reduce the risk of business attacks.
[0003] Vulnerability intelligence can come from different data sources, such as vulnerability announcements and patches related to their products published by software or hardware manufacturers, vulnerability analysis reports published by teams or individuals, posts discussing vulnerabilities in open source communities, etc. When new vulnerability-related content appears, it needs to be manually collected and sorted, and it is determined whether the components in the component library are affected by the vulnerability and the repair process is promoted. The processing efficiency and real-time performance are not high, and there is a certain security risk. SUMMARY
[0004] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed technology, nor is it intended to be used to limit the scope of the claimed technology.
[0005] In a first aspect, the present disclosure provides a business risk processing method, comprising:
[0006] According to the address of the data source and the preset crawling strategy, the vulnerability intelligence content is crawled from the data source, the preset crawling strategy is determined according to the type of the data source, and the vulnerability intelligence content includes vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability includes component information of a first component affected by the first vulnerability;
[0007] The component information of the first component is matched with the component information in the component library, and in the case that there is a second component in the component library that matches the component information of the first component, it is determined that the second component has a vulnerability risk;
[0008] According to the vulnerability information of the first vulnerability and the component information of the second component, a processing work order for the vulnerability risk is generated.
[0009] In a second aspect, the present disclosure provides a business risk processing device, comprising:
[0010] The grabbing module is configured to grab vulnerability information content from the data source according to the address of the data source and a preset grabbing strategy, the preset grabbing strategy being determined according to the type of the data source, and the vulnerability information content including vulnerability information of a first vulnerability, the vulnerability information of the first vulnerability including component information of a first component affected by the first vulnerability.
[0011] The matching module is configured to match the component information of the first component with component information in a component library, and determine that a second component in the component library is at risk of a vulnerability if the component information of the first component matches the component information of the second component.
[0012] The generating module is configured to generate a processing work order for the risk of the vulnerability according to the vulnerability information of the first vulnerability and the component information of the second component.
[0013] In a third aspect, the present disclosure provides a computer readable medium having a computer program stored thereon, the program being executed by a processing device to implement the steps of the method in the first aspect.
[0014] In a fourth aspect, the present disclosure provides an electronic device, comprising:
[0015] a storage device having a computer program stored thereon;
[0016] a processing device configured to execute the computer program in the storage device to implement the steps of the method in the first aspect.
[0017] In a fifth aspect, the present disclosure provides a computer program product comprising a computer program, the computer program being executed by a processor to implement the steps of the method in the first aspect.
[0018] According to the above technical solution, the vulnerability information content can be grabbed from the data source according to the address of the data source and the preset grabbing strategy, and then the component information of the first component can be matched with the component information in the component library, and the second component in the component library can be determined to be at risk of a vulnerability if the component information of the first component matches the component information of the second component, and finally a processing work order for the risk of the vulnerability can be generated according to the vulnerability information of the first vulnerability and the component information of the second component. By using this method, different grabbing strategies can be used to automatically grab vulnerability information content for different data sources, so that the vulnerability information of different data sources can be actively perceived in a timely manner, and the efficiency and real-time performance of vulnerability perception can be improved. In addition, it can be quickly analyzed and determined whether the components in the component library are affected by the vulnerability, and the vulnerability repair can be promoted through the generation of the processing work order, so that the efficiency and real-time performance of vulnerability processing can be improved.
[0019] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF DRAWINGS
[0020] The above and other features, advantages and aspects of embodiments of the present disclosure will become more apparent by describing in detail exemplary embodiments thereof with reference to the attached drawings in which:
[0021] Figure 1 is a schematic flowchart of a business risk processing method according to an exemplary embodiment of the present disclosure;
[0022] Figure 2 is a process schematic diagram of content crawling in a subscription mode according to an exemplary embodiment of the present disclosure;
[0023] Figure 3 is a process schematic diagram of content crawling in a non-subscription mode according to an exemplary embodiment of the present disclosure;
[0024] Figure 4 is a process schematic diagram of component matching according to an exemplary embodiment of the present disclosure;
[0025] Figure 5 is a process schematic diagram of a business risk processing method according to an exemplary embodiment of the present disclosure;
[0026] Figure 6 is a structural schematic diagram of a business risk processing apparatus according to an exemplary embodiment of the present disclosure;
[0027] Figure 7 is a structural schematic diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0028] Embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all embodiments of the present disclosure are shown. Understanding that these drawings depict only some embodiments of the present disclosure and are not therefore to be considered to be limiting of its scope, the embodiments of the present disclosure will be described and explained with additional specificity and detail herein.
[0029] It should be understood that various steps in the methods of the present disclosure can be performed in a different order and / or concurrently with each other. Furthermore, various additional or alternative steps that are not shown can be included. The scope of the present disclosure is not limited in these respects.
[0030] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0031] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0032] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0033] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0034] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0035] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0036] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0037] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0038] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0039] Vulnerability intelligence can come from various data sources, such as vulnerability announcements and patches released by software or hardware vendors related to their products, vulnerability databases that centrally store and manage vulnerability information, vulnerability analysis reports released by teams or individuals, and posts by developers and users of open-source projects reporting and discussing vulnerabilities in the community.
[0040] When a new vulnerability begins to be discussed in a small circle, or when a vulnerability is exposed on a large scale, it is necessary to analyze the technical details, exploitation conditions, attack harm, and remediation methods of the vulnerability, and determine whether the vulnerability will affect the company's products, software, and services. If it will, an emergency response is required, the affected components and scope are identified, and efforts are made to remediate the affected components to reduce and avoid the impact and harm of the vulnerability on the components, thereby protecting the security of the company's products, software, and services.
[0041] If we only become aware of and begin addressing new vulnerabilities after they have spread widely, this reactive approach is prone to causing losses. In related technologies, when new vulnerability-related content emerges, it requires manual collection and organization, along with determining whether components in the component library are affected and driving remediation. This process is inefficient and lacks real-time performance, and it cannot guarantee the collection of all vulnerability intelligence, posing certain security risks. Furthermore, from the perspective of a single vulnerability, we can only analyze and determine whether a component is affected; we cannot determine from the component's perspective whether a new component is affected by a particular vulnerability.
[0042] In view of this, the present disclosure provides a business risk handling method, apparatus, readable medium, electronic device, and product to solve the above-mentioned technical problems.
[0043] The embodiments of this disclosure will be further explained below with reference to the accompanying drawings.
[0044] Figure 1 This is a flowchart illustrating a business risk handling method according to an exemplary embodiment of this disclosure, with reference to... Figure 1 The business risk management method may include the following steps:
[0045] S101: Extract vulnerability intelligence content from the data source based on the data source address and preset crawling strategy.
[0046] The preset crawling strategy is determined based on the type of data source. The vulnerability intelligence content includes the vulnerability information of the first vulnerability, which includes the component information of the first component affected by the first vulnerability.
[0047] For example, data sources may be websites where software or hardware vendors release vulnerability announcements and patches related to their products, vulnerability databases that centrally store and manage vulnerability information, platforms where teams or individuals publish vulnerability analysis reports, open-source community websites, etc., and this disclosure does not impose any restrictions on them.
[0048] For example, users can pre-configure corresponding crawling information for different data sources, including the data source address and crawling strategies determined based on the data source type. Here, the user can be an operations staff member within a company who analyzes and processes vulnerabilities; the specific configuration can be tailored to individual needs, and this disclosure does not impose any restrictions. Furthermore, scheduled crawling tasks can be set up to periodically crawl vulnerability intelligence content from the corresponding data sources based on the crawling configuration information, ensuring comprehensive collection of vulnerability intelligence content from various data sources and improving the efficiency and real-time nature of vulnerability intelligence content perception.
[0049] S102: Match the component information of the first component with the component information in the component library, and if there is a second component in the component library that matches the component information of the first component, determine that the second component has a vulnerability risk.
[0050] It should be understood that the components in the component library are used in the company's products, software, and services. If a component has vulnerabilities, it will also have a security impact on the company's assets. By matching the information of vulnerable components with the component information in the component library, it is possible to quickly determine whether there are security risks to the company's assets, improving the efficiency and real-time nature of vulnerability analysis.
[0051] S103: Based on the vulnerability information of the first vulnerability and the component information of the second component, generate a work order for handling the vulnerability risk.
[0052] For example, when it is determined that a vulnerability affects certain components, a processing work order can be automatically created for the affected components to promote vulnerability remediation. In addition, during the remediation process, special remediation can be carried out for different business lines according to the business line dimension. This disclosure does not limit this.
[0053] In some possible ways, there are multiple second components, and the business risk handling method further includes: displaying multiple first options that correspond one-to-one with the multiple second components; generating a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component, including: in response to the selection operation of the second option among the multiple first options, generating a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the component corresponding to the second option.
[0054] For example, multiple options corresponding to components affected by the vulnerability can be displayed, allowing users to manually select affected components to create corresponding processing tickets to promote vulnerability remediation. The specific settings can be configured according to needs, and this disclosure does not impose any restrictions. This enables targeted vulnerability remediation of components based on user requirements.
[0055] Using the above method, different crawling strategies can be employed to automatically capture vulnerability intelligence content for different data sources, thereby enabling timely and proactive detection of vulnerability intelligence from different data sources and improving the efficiency and real-time nature of vulnerability detection. Furthermore, it can quickly analyze and determine whether components within the component library are affected by vulnerabilities, and promote vulnerability remediation by generating processing work orders, thus improving the efficiency and real-time nature of vulnerability handling.
[0056] In order to more promptly and proactively detect changes in vulnerability intelligence, it is necessary to continuously monitor websites, forums and platforms related to vulnerability intelligence, and capture the latest vulnerability intelligence from these data sources for centralized and automated analysis, judgment and processing. However, the data formats and loading methods of different websites and platforms are usually different.
[0057] For example, some websites or platforms that provide vulnerability intelligence offer subscription methods to push vulnerability intelligence to users, such as RSS (Really Simple Syndication) subscription methods.
[0058] In one possible manner, vulnerability intelligence content is retrieved from the data source based on the data source address and a preset retrieval strategy, including: when the data source type is a preset type, vulnerability intelligence content is retrieved from the data source according to the following retrieval strategy: detecting whether there are updated vulnerability intelligence content items at the address of the pre-subscribed data source; if there are updated vulnerability intelligence content items, retrieving the vulnerability intelligence content from the address corresponding to the updated vulnerability intelligence content item; wherein, the preset type represents the type of vulnerability intelligence content displayed through subscription.
[0059] For example, such as Figure 2 As shown, taking RSS subscription as an example, websites or platforms usually provide subscription RSS links. For such websites or platforms, users can subscribe to the address through the subscription service provided by the website or platform. The page corresponding to the address is used to display vulnerability intelligence content items, such as vulnerability intelligence entries. Each entry corresponds to an address that leads to the vulnerability intelligence details page.
[0060] For example, a timed crawling task can be configured to periodically check whether there are updated vulnerability intelligence entries at the address. If a new vulnerability intelligence entry exists, the link address corresponding to the new vulnerability intelligence entry can be obtained and the vulnerability intelligence content in the vulnerability intelligence details page corresponding to the address can be crawled for subsequent processing and analysis of the vulnerability intelligence content. This disclosure does not impose any restrictions on this.
[0061] In other words, the embodiments of this disclosure support the detection and data capture of websites or platforms that offer subscription methods, thereby enabling the acquisition of vulnerability intelligence from data sources that provide subscription methods, enriching the sources of vulnerability intelligence, and thus improving the comprehensiveness and real-time nature of vulnerability intelligence content perception.
[0062] In addition, some vulnerability intelligence sources have a security bulletin page displaying vulnerability and security-related information. Another type is forum websites where users post discussions about vulnerabilities. These websites or platforms can be categorized into statically loaded and dynamically loaded data.
[0063] Static loading refers to the website content being returned directly by the server when the page loads. Typically, the content is already contained in the HTML (HyperText Markup Language) file, and the user doesn't need to make additional requests to load the data. Dynamic loading, on the other hand, refers to the website content not being returned directly when the page loads, but rather being dynamically requested and rendered on the front end using technologies such as JavaScript.
[0064] In related technologies, the page content of statically loaded websites can be directly crawled. However, dynamically loaded websites require executing Javascript in the browser and calling other interfaces to obtain data before rendering and displaying it, so the page content cannot be directly crawled.
[0065] In one possible manner, vulnerability intelligence content is crawled from the data source based on the data source address and a preset crawling strategy, including: when the data source type is not a preset type, vulnerability intelligence content is crawled from the data source according to the following crawling strategy: crawling first initial content from the data source address; when the first initial content includes a vulnerability intelligence address that satisfies a preset matching rule, vulnerability intelligence content is crawled based on the vulnerability intelligence address; wherein, the preset type represents the type of vulnerability intelligence content displayed through a subscription method.
[0066] It's important to note that non-subscription websites tend to have more abundant data, with multiple entries per page, each linking to a specific details page. Therefore, it's necessary to analyze each entry to determine if it corresponds to a vulnerability intelligence details page. Consequently, in addition to configuring the website's links, it's also necessary to configure matching rules for the details page addresses from which vulnerability intelligence content is extracted.
[0067] For example, such as Figure 3 As shown, for websites or platforms that are statically or dynamically loaded, you can configure the link address of such websites or platforms, and then configure a timed crawling task to periodically crawl page content from that address, and perform content matching on the crawled page content based on preset matching rules. The preset matching rules are used to match the address links corresponding to the vulnerability intelligence content in the page content.
[0068] Furthermore, if a match is successful, it indicates that the website or platform uses static loading, meaning the website or platform is a static loading type. In other words, the details page address corresponding to the vulnerability intelligence content can be directly obtained from the crawled page content, and the vulnerability intelligence content can then be crawled based on that address.
[0069] In this embodiment of the disclosure, it is possible to detect and crawl data from statically loaded websites or platforms, thereby obtaining vulnerability intelligence from statically loaded data sources, enriching the sources of vulnerability intelligence, and thus improving the comprehensiveness and real-time nature of vulnerability intelligence content perception.
[0070] In some possible ways, the business risk handling method also includes: if the first initial content does not include vulnerability intelligence addresses that meet preset matching rules, scraping second initial content from the address of the data source using a content scraping tool; if the second initial content includes vulnerability intelligence addresses that meet preset matching rules, scraping vulnerability intelligence content based on the vulnerability intelligence addresses.
[0071] For example, continue to refer to Figure 3 If the crawled page content fails to match the preset matching rules, it indicates that the website or platform uses dynamic loading, meaning the website or platform is a dynamically loaded type. In other words, it's necessary to use a crawling tool to re-crawl the page content and perform a second matching based on the preset rules. If a match is successful, it means the page content includes the details page address corresponding to the vulnerability intelligence content, and the vulnerability intelligence content can then be crawled from that address.
[0072] The scraping tools can be headless, fake UA (User-Agent), etc., and this disclosure does not impose any restrictions on them.
[0073] In this embodiment of the disclosure, it is possible to detect and crawl data from dynamically loaded websites or platforms, thereby obtaining vulnerability intelligence from statically loaded data sources, enriching the sources of vulnerability intelligence, and thus improving the comprehensiveness and real-time nature of vulnerability intelligence content perception.
[0074] In possible ways, the vulnerability intelligence address that meets the preset matching rules includes at least one of the following: a first intelligence address that meets the first preset address rule; a second intelligence address marked with a first preset page tag; a third intelligence address that does not meet the preset anomaly list, wherein the preset anomaly list includes the second preset address rule and / or the second preset page tag.
[0075] For example, the default matching rule can be an address matching rule. Suppose a vulnerability intelligence page "http: / / abc.com / defg / " contains multiple vulnerability intelligence entries, and we need to parse and obtain the details of each vulnerability intelligence entry. We can configure a matching rule based on the details page of the vulnerability intelligence entry, for example, an address rule "http: / / abc\.com / defg / .+". For instance, if the crawled content page includes a link address of "http: / / abc.com / defg / hij", it means that the link address is the address of the vulnerability intelligence details page. Extracting this address allows us to crawl the vulnerability intelligence content. If the crawled content page includes a link address of "http: / / abc.com / xyz", it means that the link address is not the address of the vulnerability intelligence details page. The above rules can be set using regular expressions or other forms of rules; this disclosure does not impose any restrictions on this.
[0076] For example, the preset matching rule could be a page tag rule. If the crawled page content includes the address of the vulnerability intelligence details page, the corresponding page source code will carry preset page tags. Therefore, the page tags can be used to determine whether the crawled page content includes the address of the vulnerability intelligence details page, extract that address, and then use that address to crawl the vulnerability intelligence content.
[0077] It should be noted that the tags of the details page addresses of different data sources can be different, thereby distinguishing different data sources. For example, if the vulnerability intelligence content page references vulnerability intelligence from different data sources, different page tags can be used to distinguish the different details page addresses. This disclosure does not impose any restrictions on this.
[0078] For example, an exception list can be set up. For instance, based on the details page address that is not related to vulnerability intelligence, the exception list can be configured with the aforementioned address matching rules and / or page tag rules. Then, when an address matching the rules set in the exception list is found in the page content, the details page content corresponding to that address will not be crawled. In other words, an exception list can prevent the crawling of details page content that is not related to vulnerability intelligence.
[0079] This disclosure provides a content crawling framework that supports automatic, periodic detection and data crawling of RSS, statically loaded, and dynamically loaded websites. Users can configure the link addresses of the websites or platforms to be crawled on the vulnerability intelligence platform and configure regular expression rules to extract content from the crawled pages. This facilitates configuration and maintenance and provides the ability to proactively crawl various types of websites, flexibly meeting users' content crawling needs for different data sources and page characteristics. For example, when crawling a forum website, the crawling rules can be configured based on the link characteristics of posts on the page. After crawling a website page, the set matching rules can be used to parse and obtain the post links on the page, and then the content of each post, i.e., vulnerability intelligence content, can be obtained through the links.
[0080] In this way, when new vulnerability information is made public, it can be discovered and captured for analysis and processing immediately, with high timeliness and automation capabilities. This avoids the situation where vulnerability information has already been widely disseminated before the vulnerability is discovered, or where the vulnerability is only realized after the business has been attacked.
[0081] It's worth noting that vulnerability intelligence data scraped from different data sources is unstructured data. The data format and content vary across different websites, containing a mix of various information, including vulnerability intelligence-related fields and information. To automate subsequent analysis and processing, it's necessary to extract vulnerability intelligence-related fields from the unstructured data and assemble them into a preset format, such as JSON. The specific format can be customized as needed, and this disclosure does not impose any restrictions.
[0082] While regular expressions or other string manipulation functions can be used, the sheer volume of vulnerability intelligence fields and the varying HTML styles across different websites make extracting vulnerability information from HTML using regular expressions or strings cumbersome. Firstly, maintaining a large and complex set of rules is inefficient and time-consuming. Secondly, some data features are not readily apparent, leading to low accuracy in rule-based extraction.
[0083] In one possible manner, the vulnerability information of the first vulnerability is obtained by: performing semantic understanding of the vulnerability intelligence content through the first major model, and extracting the content of the vulnerability intelligence content based on the vulnerability intelligence knowledge to obtain the initial vulnerability information; and formatting the initial vulnerability information through the first major model to obtain the vulnerability information of the first vulnerability in a preset format.
[0084] In this embodiment of the disclosure, a Large Language Model (LLM) can be used to extract and process vulnerability intelligence-related content from content scraped from different websites or platforms. The large model can be pre-inputted with vulnerability intelligence knowledge so that it understands what vulnerability intelligence-related content is, thereby enabling it to find vulnerability intelligence-related content from unstructured text based on semantics.
[0085] For example, vulnerability intelligence content and extracted examples can be used to construct prompts and build automated processes to invoke large models. This allows the entire process to analyze and extract vulnerability-related fields and data like a vulnerability intelligence expert, assembling them into a preset format, such as JSON. The specific format can be customized according to requirements; this disclosure does not impose any limitations on this. This not only improves the efficiency and accuracy of vulnerability information extraction but also facilitates subsequent analysis and processing.
[0086] It is worth noting that the fields and data related to the vulnerability may include basic information such as the vulnerability name, number, discovery and disclosure time, and scope of impact; technical details such as the cause of the vulnerability, technical analysis, affected components, and exploitation methods; harm assessment information such as the severity of the vulnerability and possible attack consequences; remediation suggestions such as patches, mitigation measures, or repair methods; and whether there have been attack activities targeting the vulnerability, etc. The specific settings can be configured according to needs, and this disclosure does not impose any restrictions on them.
[0087] Furthermore, based on the vulnerability intelligence-related fields and data extracted from the vulnerability intelligence content, as well as some component information, it is possible to match them with components in the component library to determine whether any components are affected by the vulnerability. The component library includes component names and version numbers, as well as information such as publishers and architectures; therefore, matching can be performed based on component names and version numbers against information in the component library.
[0088] In one possible approach, the component information of the first component is matched with the component information in the component library, including: matching the component name of the first component with the component names in the component library; if a candidate component exists in the component library that matches the component name of the first component, matching the version number range of the first component with the version number of the candidate component. If a second component exists in the component library that matches the component information of the first component, the second component is determined to have a vulnerability risk, including: if the version number of the candidate component is within the version number range of the first component, the candidate component is identified as the second component, and the second component is determined to have a vulnerability risk.
[0089] For example, such as Figure 4 As shown, the system first checks if there is a candidate component in the component library that matches the name of the first component. If a candidate component exists, it checks if the version number of the candidate component is within the range of version numbers affected by the vulnerability. If the version number of the candidate component is within the range of version numbers affected by the vulnerability, the candidate component is identified as the second component, and the second component is determined to have a vulnerability risk. This allows for efficient and accurate determination of whether any component is affected by a vulnerability, facilitating subsequent vulnerability remediation and protecting component security.
[0090] In addition, matching can also be based on other component information, such as publisher, architecture, etc., and this disclosure does not impose any restrictions on this, depending on the specific needs.
[0091] In one possible approach, matching the component name of the first component with the component names in the component library includes: inputting the component name of the first component and the component names in the component library into a second large model to determine whether there are candidate components in the component library that match the component name of the first component, wherein the second large model is used to determine whether at least two component names correspond to the same component based on the input at least two component names.
[0092] It should be noted that due to the inconsistent format of component names, such as ABC, abc, A_bc, and de, which may represent the same component, directly using character equality to determine whether they are the same component will not be entirely accurate.
[0093] Therefore, a large model can be used to determine whether a component has a matching name in the component library, thereby improving the accuracy of component name matching. Additionally, expert knowledge on different names of the same component can be pre-input to assist the large model in its judgment, further improving the accuracy of component name matching. Specific settings can be configured according to requirements, and this disclosure does not impose any limitations on this.
[0094] It should be understood that both the first and second major models can be trained according to requirements to obtain the corresponding data processing capabilities, which will not be elaborated further in this publication.
[0095] In one possible approach, if the version number of a candidate component is within the range of the version number of the first component, the candidate component is identified as the second component. This includes: converting the version number of the candidate component, the lower limit version number, and the upper limit version number of the first component into numerical values according to preset conversion rules, wherein the preset conversion rules include a first conversion rule for converting numeric version numbers into numerical values and / or a second conversion rule for converting non-numeric version numbers into numerical values; and if the numerical value corresponding to the version number of the candidate component is greater than or equal to the numerical value corresponding to the lower limit version number and less than or equal to the numerical value corresponding to the upper limit version number, the candidate component is identified as the second component.
[0096] It should be noted that the standard format for component version numbers is abc. Generally, when determining the version number, it is necessary to check each field in the version number. For example, for version numbers 1.2.1 and 1.3.1, the first digit is 1, and the second digit is 3>2, so 1.3.1>1.2.1.
[0097] In this embodiment of the disclosure, the version number of a component in the format of abc (purely numeric) can be converted into an integer according to certain encoding rules. For example, the version number can be converted into an integer according to the rule a×10^m+b×10^n+c×10^p, where a, b, c, m, n, and p are positive integers. The specific encoding can be set according to requirements, and this disclosure does not impose any restrictions on it. The version numbers of the candidate components, the lower limit version number, and the upper limit version number of the first component are converted into integers. Then, by quickly comparing the sizes of the integers, it is determined whether the version number of the candidate component is within the range of version numbers affected by the vulnerability, thereby improving the efficiency of version number comparison.
[0098] However, non-standard component version numbers also exist, such as 9.6p1-1. For these types of component version numbers, since the meanings of special characters differ across product version numbers, encoding rules can be predefined for these special characters. For example, p1 corresponds to an integer, -1 corresponds to an integer, and so on. The specific rules can be set according to requirements, and this disclosure does not impose any restrictions. Furthermore, by converting these characters into integers according to certain encoding rules, it becomes convenient to compare whether the version numbers of candidate components fall within the range of version numbers affected by the vulnerability.
[0099] It's worth noting that when a match is found between vulnerability information and components, it indicates that the vulnerability impacts certain company assets. Users can then select the affected components on the vulnerability intelligence platform and create a work order for vulnerability remediation. Work orders can also be created automatically. Furthermore, vulnerability remediation can be tailored to different business lines, and this disclosure does not impose any restrictions on this. When creating a work order, basic vulnerability information, attack methods, remediation suggestions, and affected components will be displayed on the order to facilitate vulnerability remediation by vulnerability handlers.
[0100] By creating work orders, affected components can be addressed through vulnerability remediation, business operations can be improved, and the impact of vulnerabilities on company assets can be reduced or avoided.
[0101] It should be noted that after the fix is completed, a retest will be conducted. One method is to perform attack tests on the component to determine if the vulnerability still exists. Another method is to determine, after a preset period, whether the fixed component is still within the scope of the vulnerability based on newly acquired vulnerability intelligence. If it is no longer within the scope of the vulnerability, it means that the component has been successfully fixed for that vulnerability. Specific settings can be configured according to requirements; this disclosure does not impose any restrictions.
[0102] When adding new vulnerability information, we can only determine whether a vulnerability affects components in the component library from the perspective of the vulnerability information itself. However, when adding new components, it is not possible to accurately determine whether the new components are affected by the vulnerability. Therefore, it is necessary to output and maintain a vulnerability intelligence database based on vulnerability information.
[0103] In possible approaches, there are multiple data sources, and the business risk handling method further includes: storing multiple vulnerability information obtained from multiple data sources into a first vulnerability intelligence table, where each vulnerability information includes multiple fields; cleaning the multiple vulnerability information in the first vulnerability intelligence table according to field dimensions, and labeling the multiple vulnerability information with hierarchical tags to obtain labeled vulnerability information, storing the labeled vulnerability information into a second vulnerability intelligence table, where the hierarchical tags include a first tag for the data source and / or a second tag for the fields in the vulnerability information, the level corresponding to the hierarchical tag is positively correlated with the accuracy of the vulnerability intelligence, and the same field for the same vulnerability in the second vulnerability intelligence table is associated with at least one field data from at least one data source; for different first field data associated with the same field for the same vulnerability in the second vulnerability intelligence table, extracting the first field data with the highest hierarchical tag level to obtain second field data, and storing the second field data into a third vulnerability intelligence table; summarizing the second field data for the same vulnerability in the third vulnerability intelligence table to obtain first vulnerability intelligence, and storing the first vulnerability intelligence into a vulnerability intelligence database.
[0104] It should be noted that vulnerability information can be integrated to construct a vulnerability intelligence database. Since the data sources for vulnerability information are diverse, the vulnerability information from each data source has both commonalities and differences. To create a high-quality vulnerability intelligence database, in this embodiment, multiple vulnerability information items from different data sources, in a preset format output by the first major model, can be stored in a base table, namely the first vulnerability intelligence table. Furthermore, the multiple vulnerability information items in the first vulnerability intelligence table can be cleaned from a field perspective, such as deleting unnecessary fields. Specific settings can be configured according to requirements, and this disclosure does not impose any limitations on this.
[0105] For example, each field of multiple vulnerability information is labeled with a hierarchical tag. If data source A has higher accuracy in vulnerability information compared to data source B, then the hierarchical tag for data source A's vulnerability information is of a higher level than the hierarchical tag for data source B's vulnerability information. That is, the field is labeled with hierarchical tags from the perspective of the data source. Alternatively, if data source A has higher accuracy in vulnerability information compared to data source B, but data source B has higher accuracy for a specific field, then a hierarchical tag needs to be labeled separately for that field. That is, the hierarchical tag for that field in data source A is of a lower level than the hierarchical tag for that field in data source B's vulnerability information. The labeled vulnerability information is then stored in a detailed table, i.e., the second vulnerability intelligence table.
[0106] For example, in the details table, the same field for the same vulnerability may have field data from different data sources. In this case, it is necessary to extract the field data with the highest level corresponding to the classification label and store the extracted field data in the intermediate table, i.e., the third vulnerability intelligence table.
[0107] Furthermore, based on the vulnerability dimension, the extracted field data for the same vulnerability are aggregated to obtain vulnerability intelligence for that vulnerability, which is stored in a wide table and then in the final vulnerability intelligence database. The information included in the vulnerability intelligence can be determined based on the aforementioned vulnerability-related fields and data, and this disclosure does not impose any restrictions on it.
[0108] By labeling vulnerability information with hierarchical tags and processing it in layers, the relevant data of vulnerability intelligence is cleaned and aggregated according to the processing logic of base table, detailed table, intermediate table and wide table, and then stored in the vulnerability intelligence database. This ensures that each field of the intelligence data in the vulnerability intelligence database comes from the most accurate data source, thereby guaranteeing the quality of the data in the vulnerability intelligence database.
[0109] In one possible approach, the vulnerability intelligence in the vulnerability intelligence database includes component information of components affected by the second vulnerability. The business risk handling method also includes: in response to the addition of a third component to the component library, matching the component information of the third component with the component information of the component in the vulnerability intelligence database; if there is matching component information in the vulnerability intelligence database that matches the component information of the third component, determining that the third component has a vulnerability risk, and determining the second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence database; and generating a processing work order for the vulnerability risk of the third component based on the second vulnerability intelligence and the component information of the third component.
[0110] For example, the second vulnerability refers to all vulnerabilities in the vulnerability intelligence database, including the first vulnerability mentioned above. When a new component is added to the component library, the vulnerability intelligence database is queried based on the component information to determine whether the new component is affected by a vulnerability in the database. If it is affected, a vulnerability remediation is carried out by creating a processing ticket. By building and maintaining a vulnerability intelligence database, it is possible to quickly determine whether a new component is affected by a vulnerability in the database, thus ensuring the security of company assets.
[0111] In addition, for scenarios requiring vulnerability intelligence data, the data can be pushed to downstream scenarios for consumption and processing through a subscription model. For example, black-box and white-box scanning tools will scan for relevant vulnerabilities based on vulnerability intelligence information, and firewall tools will also set plugins based on vulnerability intelligence information to block malicious attack traffic, etc. This disclosure does not impose any restrictions on this.
[0112] The vulnerability mitigation scheme of this disclosure embodiment, such as Figure 5 As shown, operations personnel processing vulnerability intelligence can configure the vulnerability intelligence platform with settings such as the URLs of websites or platforms to be detected and crawled, as well as matching rules. They can then periodically schedule the crawling of vulnerability intelligence content based on these settings. After parsing and extracting fields from the crawled vulnerability intelligence content using a large model, the vulnerability information can be formatted, filtered, and aggregated before being stored in the vulnerability intelligence database.
[0113] Furthermore, continue to refer to Figure 5 The system can match vulnerability intelligence information with components across the company's various business lines. If a matching component is found, it indicates that the component is affected by the vulnerability and poses a security risk. Operations personnel can be notified to create a processing ticket, or the ticket can be created automatically. Personnel responsible for vulnerability remediation can then fix the affected services until the remediation is complete.
[0114] The developed vulnerability intelligence detection and capture framework can proactively detect and capture vulnerability intelligence from various websites and platforms. When vulnerability intelligence is detected and captured, based on large-scale model technology, key information and fields can be extracted efficiently and accurately from the vulnerability intelligence. Furthermore, the large-scale model helps determine whether the vulnerability affects the company's assets. When it is determined that the company is affected by a vulnerability, a work order is created to address the affected assets, drive business remediation, and reduce or avoid the impact of the vulnerability on the company's assets.
[0115] Based on the same concept, this disclosure also provides a business risk processing device, such as... Figure 6 As shown, the business risk processing device 600 may include:
[0116] The crawling module 601 is used to crawl vulnerability intelligence content from the data source according to the address of the data source and a preset crawling strategy. The preset crawling strategy is determined according to the type of the data source. The vulnerability intelligence content includes vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability includes component information of a first component affected by the first vulnerability.
[0117] The matching module 602 is used to match the component information of the first component with the component information in the component library, and if there is a second component in the component library that matches the component information of the first component, determine that the second component has a vulnerability risk;
[0118] The generation module 603 is used to generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component.
[0119] Optionally, the grasping module 601 is used for:
[0120] If the data source is of a preset type, the vulnerability intelligence content is retrieved from the data source according to the following scraping strategy:
[0121] Check if there are updated vulnerability intelligence content items at the addresses of the pre-subscribed data sources;
[0122] If the updated vulnerability intelligence content item exists, the vulnerability intelligence content is retrieved from the address corresponding to the updated vulnerability intelligence content item.
[0123] The preset type represents the type of vulnerability intelligence content displayed through a subscription method.
[0124] Optionally, the grasping module 601 is used for:
[0125] If the data source type is not a preset type, the vulnerability intelligence content is retrieved from the data source according to the following scraping strategy:
[0126] Retrieve initial content from the address of the data source;
[0127] If the first initial content includes a vulnerability intelligence address that meets the preset matching rules, the vulnerability intelligence content is retrieved based on the vulnerability intelligence address.
[0128] The preset type represents the type of vulnerability intelligence content displayed through a subscription method.
[0129] Optionally, the business risk processing device 600 further includes a crawling submodule, which is used for:
[0130] If the first initial content does not include vulnerability intelligence addresses that meet the preset matching rules, a second initial content is crawled from the address of the data source using a content crawling tool;
[0131] If the second initial content includes a vulnerability intelligence address that satisfies the preset matching rule, the vulnerability intelligence content is retrieved based on the vulnerability intelligence address.
[0132] Optionally, the vulnerability intelligence address that satisfies the preset matching rules includes at least one of the following:
[0133] The first intelligence address that satisfies the first preset address rule;
[0134] The second information address is labeled with the first preset page tag;
[0135] The third intelligence address does not meet the preset abnormal list, which includes a second preset address rule and / or a second preset page tag.
[0136] Optionally, the vulnerability information of the first vulnerability is obtained by extracting it in the following manner:
[0137] The vulnerability intelligence content is semantically understood using the first major model, and the vulnerability intelligence content is extracted based on vulnerability intelligence knowledge to obtain initial vulnerability information.
[0138] The initial vulnerability information is formatted using the first large model to obtain vulnerability information of the first vulnerability in a preset format.
[0139] Optionally, the matching module 602 is used for:
[0140] Match the component name of the first component with the component names in the component library;
[0141] If a candidate component with a name matching the first component exists in the component library, the version number range of the first component is matched with the version number of the candidate component.
[0142] The matching module 602 is used for:
[0143] If the version number of the candidate component is within the range of the version number of the first component, the candidate component is identified as the second component, and the second component is identified as having a vulnerability risk.
[0144] Optionally, the matching module 602 is used for:
[0145] The component name of the first component and the component name in the component library are input into the second large model to determine whether there is a candidate component in the component library that matches the component name of the first component. The second large model is used to determine whether the at least two component names correspond to the same component based on the input at least two component names.
[0146] Optionally, the matching module 602 is used for:
[0147] The version numbers of the candidate components, the lower limit version number and the upper limit version number of the first component are converted into numerical values according to the preset conversion rules. The preset conversion rules include a first conversion rule for converting numerical version numbers into numerical values and / or a second conversion rule for converting non-numerical version numbers into numerical values.
[0148] If the value corresponding to the version number of the candidate component is greater than or equal to the value corresponding to the lower limit version number and less than or equal to the value corresponding to the upper limit version number, the candidate component is determined as the second component.
[0149] Optionally, the number of data sources is multiple, and the business risk processing device 600 further includes a aggregation module, which is used for:
[0150] Multiple vulnerability information obtained from multiple data sources are stored in a first vulnerability intelligence table, wherein each vulnerability information includes multiple fields;
[0151] Multiple vulnerability information in the first vulnerability intelligence table are cleaned according to field dimensions, and the multiple vulnerability information is labeled with hierarchical tags to obtain labeled vulnerability information. The labeled vulnerability information is stored in the second vulnerability intelligence table. The hierarchical tags include a first tag for the data source and / or a second tag for the field in the vulnerability information. The level corresponding to the hierarchical tag is positively correlated with the accuracy of the vulnerability intelligence. The second vulnerability intelligence table is associated with at least one field data from at least one data source for the same field of the same vulnerability.
[0152] For different first field data associated with the same field of the same vulnerability in the second vulnerability intelligence table, extract the first field data with the highest level corresponding to the hierarchical label to obtain the second field data, and store the second field data in the third vulnerability intelligence table;
[0153] The second field data for the same vulnerability in the third vulnerability intelligence table are summarized to obtain the first vulnerability intelligence, and the first vulnerability intelligence is stored in the vulnerability intelligence database.
[0154] Optionally, the vulnerability intelligence in the vulnerability intelligence database includes component information of components affected by the second vulnerability, and the business risk processing device 600 further includes a generation submodule, which is used for:
[0155] In response to the addition of a third component to the component library, the component information of the third component is matched with the component information of the components in the vulnerability intelligence database;
[0156] If there is matching component information in the vulnerability intelligence database that matches the component information of the third component, it is determined that the third component has a vulnerability risk, and the second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence database is determined.
[0157] Based on the second vulnerability intelligence and the component information of the third component, a processing work order for the vulnerability risk of the third component is generated.
[0158] Optionally, the number of the second components is multiple, and the business risk processing device 600 further includes a display module, which is used for:
[0159] Displays a plurality of first selection options corresponding one-to-one with a plurality of the second components;
[0160] The generation module 603 is used for:
[0161] In response to the selection operation of the second option among the plurality of first options, a processing work order for the vulnerability risk is generated based on the vulnerability information of the first vulnerability and the component information of the component corresponding to the second option.
[0162] Based on the same concept, embodiments of this disclosure also provide a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of any of the above-described business risk handling methods.
[0163] Based on the same concept, this disclosure also provides an electronic device that may include:
[0164] A storage device on which computer programs are stored;
[0165] A processing device for executing a computer program stored in a storage device to implement the steps of any of the above-described business risk processing methods.
[0166] Based on the same concept, this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above-described business risk handling methods.
[0167] The following is for reference. Figure 7 The diagram illustrates a structural schematic of an electronic device 700 suitable for implementing embodiments of the present disclosure. Terminal devices in embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0168] like Figure 7 As shown, the electronic device 700 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device 700. The processing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0169] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic device 700 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 7 An electronic device 700 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0170] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 709, or installed from storage device 708, or installed from ROM 702. When the computer program is executed by processing device 701, it performs the functions defined in the methods of embodiments of this disclosure.
[0171] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0172] In some implementations, communication can be conducted using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol), and can be interconnected with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0173] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0174] The aforementioned computer-readable medium carries one or more programs. When the aforementioned one or more programs are executed by the electronic device, the electronic device causes the following to occur: Based on the address of the data source and a preset fetching strategy, the electronic device fetches vulnerability intelligence content from the data source. The preset fetching strategy is determined based on the type of the data source. The vulnerability intelligence content includes vulnerability information of a first vulnerability, which includes component information of a first component affected by the first vulnerability. The electronic device then matches the component information of the first component with component information in a component library. If a second component exists in the component library that matches the component information of the first component, the electronic device determines that the second component has a vulnerability risk. Based on the vulnerability information of the first vulnerability and the component information of the second component, the electronic device generates a processing work order for the vulnerability risk.
[0175] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0176] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0177] The modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules are not, in some cases, intended to limit the functionality of the module itself.
[0178] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0179] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0180] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0181] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0182] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which the various modules perform their operations has been described in detail in the embodiments relating to the method, and will not be elaborated upon here.
Claims
1. A business risk management method, characterized in that, The business risk handling methods include: Based on the address of the data source and a preset crawling strategy, vulnerability intelligence content is crawled from the data source. The preset crawling strategy is determined according to the type of the data source. The vulnerability intelligence content includes vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability includes component information of a first component affected by the first vulnerability. The component information of the first component is matched with the component information in the component library. If a second component exists in the component library that matches the component information of the first component, it is determined that the second component has a vulnerability risk. Based on the vulnerability information of the first vulnerability and the component information of the second component, a processing work order for the vulnerability risk is generated; The step of retrieving vulnerability intelligence content from the data source based on the data source address and a preset retrieval strategy includes: when the data source type is not a preset type, retrieving the vulnerability intelligence content from the data source according to the following retrieval strategy: First initial content is retrieved from the address of the data source; if the first initial content includes a vulnerability intelligence address that satisfies a preset matching rule, the vulnerability intelligence content is retrieved according to the vulnerability intelligence address; wherein, the preset type represents the type of vulnerability intelligence content displayed through a subscription method; The step of matching the component information of the first component with the component information in the component library, and determining that the second component has a vulnerability risk if a second component exists in the component library that matches the component information of the first component, includes: matching the component name of the first component with the component names in the component library; if a candidate component exists in the component library that matches the component name of the first component, matching the version number range of the first component with the version number of the candidate component; if the version number of the candidate component is included in the version number range of the first component, identifying the candidate component as the second component, and determining that the second component has a vulnerability risk.
2. The business risk handling method according to claim 1, characterized in that, The step of retrieving vulnerability intelligence content from the data source based on the data source address and a preset crawling strategy includes: If the data source is of a preset type, the vulnerability intelligence content will be retrieved from the data source according to the following scraping strategy: Check if there are updated vulnerability intelligence content items at the addresses of the pre-subscribed data sources; If the updated vulnerability intelligence content item exists, the vulnerability intelligence content is retrieved from the address corresponding to the updated vulnerability intelligence content item. The preset type represents the type of vulnerability intelligence content displayed through a subscription method.
3. The business risk handling method according to claim 1, characterized in that, The business risk handling methods also include: If the first initial content does not include vulnerability intelligence addresses that meet the preset matching rules, a second initial content is crawled from the address of the data source using a content crawling tool; If the second initial content includes a vulnerability intelligence address that satisfies the preset matching rule, the vulnerability intelligence content is retrieved based on the vulnerability intelligence address.
4. The business risk handling method according to claim 1 or 3, characterized in that, The vulnerability intelligence addresses that satisfy the preset matching rules include at least one of the following: The first intelligence address that satisfies the first preset address rule; The second information address is labeled with the first preset page tag; The third intelligence address does not meet the preset blacklist, which includes a second preset address rule and / or a second preset page tag.
5. The business risk handling method according to any one of claims 1-3, characterized in that, The vulnerability information for the first vulnerability was obtained through the following method: The vulnerability intelligence content is semantically understood using the first major model, and the vulnerability intelligence content is extracted based on vulnerability intelligence knowledge to obtain initial vulnerability information. The initial vulnerability information is formatted using the first large model to obtain vulnerability information of the first vulnerability in a preset format.
6. The business risk handling method according to any one of claims 1-3, characterized in that, The step of matching the component name of the first component with the component names in the component library includes: The component name of the first component and the component name in the component library are input into the second large model to determine whether there is a candidate component in the component library that matches the component name of the first component. The second large model is used to determine whether the at least two component names correspond to the same component based on the input at least two component names.
7. The business risk handling method according to any one of claims 1-3, characterized in that, The step of determining the candidate component as the second component when the version number of the candidate component is within the range of the version number of the first component includes: The version numbers of the candidate components, the lower limit version number and the upper limit version number of the first component are converted into numerical values according to the preset conversion rules. The preset conversion rules include a first conversion rule for converting numerical version numbers into numerical values and / or a second conversion rule for converting non-numerical version numbers into numerical values. If the value corresponding to the version number of the candidate component is greater than or equal to the value corresponding to the lower limit version number and less than or equal to the value corresponding to the upper limit version number, the candidate component is determined as the second component.
8. The business risk handling method according to any one of claims 1-3, characterized in that, The number of data sources is multiple, and the business risk handling method further includes: Multiple vulnerability information obtained from multiple data sources are stored in a first vulnerability intelligence table, wherein each vulnerability information includes multiple fields; Multiple vulnerability information in the first vulnerability intelligence table are cleaned according to field dimensions, and the multiple vulnerability information is labeled with hierarchical tags to obtain labeled vulnerability information. The labeled vulnerability information is stored in the second vulnerability intelligence table. The hierarchical tags include a first tag for the data source and / or a second tag for the field in the vulnerability information. The level corresponding to the hierarchical tag is positively correlated with the accuracy of the vulnerability intelligence. The same field of the same vulnerability in the second vulnerability intelligence table is associated with at least one first field data from at least one data source. For different first field data associated with the same field of the same vulnerability in the second vulnerability intelligence table, extract the first field data with the highest level corresponding to the hierarchical label to obtain the second field data, and store the second field data in the third vulnerability intelligence table; The second field data for the same vulnerability in the third vulnerability intelligence table are summarized to obtain the first vulnerability intelligence, and the first vulnerability intelligence is stored in the vulnerability intelligence database.
9. The business risk handling method according to claim 8, characterized in that, The vulnerability intelligence database includes component information of components affected by the second vulnerability, and the business risk handling method further includes: In response to the addition of a third component to the component library, the component information of the third component is matched with the component information of the components in the vulnerability intelligence database; If there is matching component information in the vulnerability intelligence database that matches the component information of the third component, it is determined that the third component has a vulnerability risk, and the second vulnerability intelligence corresponding to the matching component information in the vulnerability intelligence database is determined. Based on the second vulnerability intelligence and the component information of the third component, a processing work order for the vulnerability risk of the third component is generated.
10. The business risk handling method according to any one of claims 1-3, characterized in that, The number of the second components is multiple, and the business risk handling method further includes: Displays a plurality of first selection options corresponding one-to-one with a plurality of the second components; The step of generating a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component includes: In response to the selection operation of the second option among the plurality of first options, a processing work order for the vulnerability risk is generated based on the vulnerability information of the first vulnerability and the component information of the component corresponding to the second option.
11. A business risk processing device, characterized in that, The business risk handling device includes: The crawling module is used to crawl vulnerability intelligence content from the data source according to the address of the data source and a preset crawling strategy. The preset crawling strategy is determined according to the type of the data source. The vulnerability intelligence content includes vulnerability information of a first vulnerability, and the vulnerability information of the first vulnerability includes component information of a first component affected by the first vulnerability. The matching module is used to match the component information of the first component with the component information in the component library, and if there is a second component in the component library that matches the component information of the first component, determine that the second component has a vulnerability risk; The generation module is used to generate a processing work order for the vulnerability risk based on the vulnerability information of the first vulnerability and the component information of the second component. The crawling module is used to crawl the vulnerability intelligence content from the data source according to the following crawling strategy when the data source type is not a preset type: First initial content is retrieved from the address of the data source; if the first initial content includes a vulnerability intelligence address that satisfies a preset matching rule, the vulnerability intelligence content is retrieved according to the vulnerability intelligence address; wherein, the preset type represents the type of vulnerability intelligence content displayed through a subscription method; The matching module is used to match the component name of the first component with the component names in the component library; if there is a candidate component in the component library that matches the component name of the first component, the module matches the version number range of the first component with the version number of the candidate component; if the version number of the candidate component is included in the version number range of the first component, the module determines the candidate component as the second component and determines that the second component has a vulnerability risk.
12. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processing device, the computer program performs the steps of the method described in any one of claims 1-10.
13. An electronic device, characterized in that, include: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-10.
14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-10.
Citation Information
Patent Citations
Method and device for bug repairing
CN107480533A
Network vulnerability monitoring management method and device, medium and electronic equipment
CN114938283A