Network security processing method and device, storage medium and equipment

By quantifying the contribution of security vulnerabilities in attack events and reasonably configuring the scanning frequency, the problem of unreasonable configuration of security vulnerabilities in network security is solved, and the utilization efficiency of scanning resources is improved.

CN120512293APending Publication Date: 2025-08-19CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510830089.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

How to achieve reasonable configuration of the frequency of scanning security vulnerabilities while ensuring network security.

Method used

By obtaining the attack information in the attack incident and the implementation relationship between the target security vulnerabilities, determining the weight of the security vulnerabilities based on the attack risk coefficient and implementation relationship, using the European-style distance to calculate the optimal solution and the worst solution, quantifying the contribution of the security vulnerabilities, and then reasonably configure the scanning frequency.

Benefits of technology

It has achieved quantification of the contribution of security vulnerabilities to attack incidents, rationally allocated scanning resources, improved the focus of scanning of important security vulnerabilities, and optimized the utilization of scanning resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120512293A_ABST
    Figure CN120512293A_ABST
Patent Text Reader

Abstract

The invention provides a network security processing method and device, a storage medium and equipment, and relates to the technical field of network security. The method comprises the following steps: acquiring attack information contained in an attack event and an implementation relationship between an attack and a target security vulnerability; determining a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and an implementation relationship between the attack and the target security vulnerability; based on a first weight of the target security vulnerability in the attack, determining a first distance between the first weight and a first weight boundary and a second distance between the first weight and a second weight boundary; and based on the first distance and the second distance, determining a second weight of the target security vulnerability in the attack event, thereby realizing quantification of contribution of the security vulnerability in the attack event. And determining the scanning frequency of the target security vulnerability based on the second weight of the security vulnerability in the attack event, thereby realizing reasonable distribution and utilization of scanning resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a network security processing method and apparatus, a storage medium, and a device. Background Art

[0002] Supply chain attacks are a common tactic used by Advanced Persistent Threat (APT) attacks, typically exploiting vulnerabilities in hardware, software, or software dependencies. Related technologies can detect and prevent these attacks by scanning for security vulnerabilities.

[0003] However, how to reasonably configure the frequency of security vulnerability scanning while ensuring network security is a technical problem that needs to be solved.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0005] The purpose of the present disclosure is to provide a network security processing method and apparatus, a storage medium and a device, so as to achieve reasonable configuration of scanning frequency while ensuring network security.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a network security processing method is provided, including: obtaining attack information contained in an attack event, and an implementation relationship between the attack and a target security vulnerability, the attack information including a risk coefficient of the attack, and the target security vulnerability referring to any security vulnerability used in the attack event; determining a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability; determining a first distance between the first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary, based on the first weight of the target security vulnerability in the attack, the first weight boundary and the second weight boundary respectively representing an optimal solution and an optimal split of the weight of the security vulnerability in the attack; determining a second weight of the target security vulnerability in the attack event based on the first distance between the first weight and the first weight boundary, and the second distance between the first weight and the second weight boundary; determining a scanning frequency of the target security vulnerability based on the second weight of the target security vulnerability in the attack event.

[0008] In one embodiment of the present disclosure, information about the attacks contained in an attack event and the implementation relationship between the attacks and target security vulnerabilities are obtained, including: extracting information about the attacks contained in the attack event from an analysis report of the attack event based on the ATT&CK (Adversarial Tactics Techniques and Common Knowledge) attack technology matrix.

[0009] In one embodiment of the present disclosure, based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability, the first weight of the target security vulnerability in the attack is determined, including: when the attack is implemented through the target security vulnerability, the risk coefficient of the attack is weighted by the third weight to obtain the first weight of the target security vulnerability in the attack; when the attack is not implemented through the target security vulnerability, the risk coefficient of the attack is weighted by the fourth weight to obtain the first weight of the target security vulnerability in the attack; wherein the third weight is greater than the fourth weight.

[0010] In one embodiment of the present disclosure, based on the first weight of the target security vulnerability in the attack, a first distance between the first weight and the first weight boundary, and a second distance between the first weight and the second weight boundary are determined, including: based on the first weight of the target security vulnerability in the attack, determining the first Euclidean distance between the first weight and the first weight boundary; based on the first weight of the target security vulnerability in the attack, determining the second Euclidean distance between the first weight and the second weight boundary.

[0011] In one embodiment of the present disclosure, the network security processing method may also include: obtaining the weights of one or more security vulnerabilities used in the attack event; determining the minimum value of these weights as the optimal solution for the weight of the security vulnerability in the attack; and determining the maximum value of these weights as the optimal solution for the weight of the security vulnerability in the attack.

[0012] In one embodiment of the present disclosure, based on a first distance between a first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary, a second weight of a target security vulnerability in an attack event is determined, including: determining a weight score of the target security vulnerability in the attack event based on the first distance and the second distance; determining the proportion of the weight score of the target security vulnerability in the first target value as the second weight of the target security vulnerability in the attack event; wherein the first target value refers to the sum of the weight scores of one or more security vulnerabilities used in the attack event in the attack event.

[0013] In one embodiment of the present disclosure, a weight score of a target security vulnerability in an attack event is determined based on a first distance and a second distance, including: determining a third Euclidean distance based on the first distance of the target security vulnerability in multiple attacks included in the attack event; determining a fourth Euclidean distance based on the second distance of the target security vulnerability in the multiple attacks included in the attack event; determining the proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value as the weight score of the target security vulnerability in the attack event; wherein the second target value refers to the sum of the third Euclidean distance and the fourth Euclidean distance.

[0014] According to another aspect of the present disclosure, a network security processing device is provided, comprising:

[0015] The first acquisition module is used to acquire the attack information contained in the attack event and the implementation relationship between the attack and the target security vulnerability. The attack information includes the risk coefficient of the attack.

[0016] The first determination module is used to determine a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability.

[0017] The second determination module is used to determine a first distance between the first weight and the first weight boundary, and a second distance between the first weight and the second weight boundary based on the first weight of the target security vulnerability in the attack, the first weight boundary and the second weight boundary respectively representing the optimal solution and the most decomposition of the weight of the security vulnerability in the attack.

[0018] The third determining module is configured to determine a second weight of the target security vulnerability in the attack event based on a first distance between the first weight and the first weight boundary and a second distance between the first weight and the second weight boundary.

[0019] The fourth determining module is configured to determine a scanning frequency of the target security vulnerability based on a second weight of the target security vulnerability in the attack event.

[0020] In one embodiment of the present disclosure, the first acquisition module is used to extract attack information contained in the attack event from the analysis report of the attack event based on the ATT&CK attack technology matrix.

[0021] In one embodiment of the present disclosure, the first determining module includes:

[0022] The first processing unit is configured to, when an attack is carried out through a target security vulnerability, weight the risk coefficient of the attack with the third weight to obtain a first weight of the target security vulnerability in the attack.

[0023] The second processing unit is configured to, if the attack is not carried out through the target security vulnerability, weight the risk coefficient of the attack and the fourth weight to obtain a first weight of the target security vulnerability in the attack, wherein the third weight is greater than the fourth weight.

[0024] In one embodiment of the present disclosure, the second determining module includes:

[0025] The third processing unit is configured to determine a first Euclidean distance between the first weight and the first weight boundary based on the first weight of the target security vulnerability in the attack.

[0026] The fourth processing unit is configured to determine a second Euclidean distance between the first weight and a second weight boundary based on the first weight of the target security vulnerability in the attack.

[0027] In one embodiment of the present disclosure, the network security processing device may further include:

[0028] The second acquisition module is used to obtain the weight of one or more security vulnerabilities used in the attack event in the attack;

[0029] The fifth determination module is configured to determine the minimum value among the weights as the optimal solution for the weight of the security vulnerability in the attack.

[0030] The sixth determination module is used to determine the maximum value among the weights as the maximum value of the weight of the security vulnerability in the attack.

[0031] In one embodiment of the present disclosure, the third determining module includes:

[0032] A first determining unit, configured to determine a weight score of a target security vulnerability in an attack event based on the first distance and the second distance;

[0033] The second determining unit is configured to determine a proportion of the weight score of the target security vulnerability in the attack event in the first target value as a second weight of the target security vulnerability in the attack event.

[0034] The first target value refers to the sum of weighted scores of one or more security vulnerabilities used in the attack event.

[0035] In one embodiment of the present disclosure, the first determining unit is configured to:

[0036] Based on the first distance of the target security vulnerability in the multiple attacks included in the attack event, a third Euclidean distance is determined; based on the second distance of the target security vulnerability in the multiple attacks included in the attack event, a fourth Euclidean distance is determined; the proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value is determined as the weight score of the target security vulnerability in the attack event; wherein the second target value refers to the sum of the third Euclidean distance and the fourth Euclidean distance.

[0037] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the above-mentioned network security processing method by executing the executable instructions.

[0038] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the network security processing method described above is implemented.

[0039] The network security processing method and apparatus, storage medium and device provided by the embodiments of the present disclosure obtain the attack information contained in the attack event (the attack information includes the risk coefficient of the attack) and the implementation relationship between the attack and the target security vulnerability; based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability, determine the first weight of the target security vulnerability in the attack; based on the first weight of the target security vulnerability in the attack, determine the first distance between the first weight and the first weight boundary, and the second distance between the first weight and the second weight boundary; based on the first distance and the second distance, determine the second weight of the target security vulnerability in the attack event, thereby quantifying the contribution of the security vulnerability in the attack event. Based on the second weight of the security vulnerability in the attack event, determine the scanning frequency of the target security vulnerability, thereby achieving a reasonable configuration of the scanning frequency. For example, when the second weight of the security vulnerability is large, a high scanning frequency can be used to focus on scanning important security vulnerabilities; when the second weight of the security vulnerability is small, the security vulnerability can be scanned at a relatively low scanning frequency.

[0040] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0042] Figure 1 A flowchart of a network security processing method according to an embodiment of the present disclosure is shown;

[0043] Figure 2 A schematic diagram of a data acquisition method according to an embodiment of the present disclosure is shown;

[0044] Figure 3 A schematic diagram of a weight determination method according to an embodiment of the present disclosure is shown;

[0045] Figure 4 A schematic diagram of another weight determination method according to an embodiment of the present disclosure is shown;

[0046] Figure 5 A schematic diagram of another weight determination method according to an embodiment of the present disclosure is shown;

[0047] Figure 6 A flow chart of a method for determining an optimal solution and a most cracked solution according to an embodiment of the present disclosure is shown;

[0048] Figure 7 A flow chart of a method for determining the weight of a security vulnerability according to an embodiment of the present disclosure is shown;

[0049] Figure 8 A schematic diagram of a network security processing device according to an embodiment of the present disclosure is shown;

[0050] Figure 9 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0051] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0052] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0053] To facilitate understanding, several terms involved in this application are first explained below.

[0054] TOPSIS (Technique for Order Preference by Similarity to Ideal Solution) is a multi-objective decision analysis method. Its basic principle is to rank the evaluation object by measuring its distance from the optimal solution and the worst solution. The optimal solution is the one that is closest to the optimal solution and farthest from the worst solution.

[0055] The solution provided in the embodiments of the present application involves technologies such as quantifying the weight of security vulnerabilities in attack events and allocating scanning resources, which are described below in conjunction with exemplary embodiments:

[0056] Figure 1 The flowchart of a network security processing method in the embodiment of the present disclosure is shown. The method provided in the embodiment of the present disclosure can be executed by any electronic device with computing and processing capabilities. For example, in some embodiments, the electronic device referred to in the embodiment of the present disclosure can be a server, a laptop, a mobile phone, a tablet computer, etc., but is not limited to the devices listed here. Figure 1 As shown, in some exemplary implementations, the network security processing method provided by the embodiments of the present disclosure may include the following steps.

[0057] In step S101, the attack information contained in the attack event and the implementation relationship between the attack and the target security vulnerability are obtained. The attack information includes the risk coefficient of the attack.

[0058] The attack events referred to in the embodiments of the present disclosure can be understood as any network attack event. For ease of understanding, the embodiments of the present disclosure can be exemplarily understood as attack events targeting the supply chain.

[0059] In some exemplary embodiments, a single attack event may include one or more attacks. The implementation of different attacks may or may not be mutually dependent. The existence of a dependency relationship can be understood as one attack requiring one or more other attacks to achieve their objectives. The absence of a dependency relationship can be understood as the implementation of an attack not requiring the implementation of other attacks. Take the software development supply chain as an example. The software development supply chain may exemplarily include software supply, hardware supply, and service supply. The software supply may include one or more software components supplied by one or more software vendors. The hardware supply may include one or more hardware components supplied by one or more hardware vendors. The service supply may include one or more services supplied by one or more service vendors. The software, hardware, and services provided by the supply chain collectively support software development. An attack event targeting the supply chain may include attacks on one or more supply chains. Attacks on each supply chain may include attacks on one or more products (including software, hardware, and services) provided by that supply chain. These attacks may be carried out based on product security vulnerabilities. Attacking a particular supply chain may require first completing attacks on one or more other supply chains. Alternatively, an attack targeting a product provided by a supplier might rely on an attack on another product provided by the supplier first. For example, an attack on a piece of software provided by a software supplier might rely on an attack on the hardware that the software is running on, or on another piece of software running on the same hardware first.

[0060] The target security vulnerability referred to in the embodiments of the present disclosure can be exemplarily understood as any security vulnerability used in an attack event. One or more attacks included in the attack event can be implemented through the target security vulnerability.

[0061] In some embodiments, the attack information may include, but is not limited to, an attack risk factor. For example, in some embodiments, the attack information may also include an identifier of the attack (e.g., a name or number), the time the attack occurred, and information about the supplier of the product that caused the attack. In the disclosed embodiments, the attack risk factor quantifies the degree of danger of the attack.

[0062] The implementation relationship between the attack and the target security vulnerability is used to indicate whether the attack is implemented by exploiting the target security vulnerability. For example, in some examples, the implementation relationship between the attack and the target security vulnerability can be expressed as A i -W j -g. Among them, A i Indicates the attack flag, W jIndicates the security vulnerability identifier, the value of g indicates A i and W j For example, when the value of g is "1", it means A i The corresponding attack is through W j The corresponding security vulnerability is implemented; when the value of g is "0", it means A i The corresponding attack is not through W j Of course, this is just an example and not the only limitation.

[0063] In some implementations, the attack information contained in the attack event, as well as the implementation relationship between the attack and the target security vulnerability, can be obtained from the attack event analysis report. For example, in some examples, the attack information contained in the attack event, as well as the implementation relationship between the attack and the target implementation vulnerability, can be matched from the attack event analysis report using the ATT&CK attack technology matrix. ATT&CK is a guide for classifying and describing network attacks from the attacker's perspective.

[0064] In other embodiments, the attack information contained in the attack event, as well as the implementation relationship between the attack and the target security vulnerability, can be manually configured and stored on a pre-set storage device. The storage device can be, for example, a non-volatile readable storage medium, or a distributed storage node with data storage and data exchange capabilities. Of course, this is merely an exemplary description of the storage device and is not intended to be exclusive.

[0065] In some implementations, the attack information contained in the attack event and the implementation relationship between the attack and the target security vulnerability can be obtained from the storage device based on a preset instruction or data exchange protocol.

[0066] Figure 2 A schematic diagram of a data acquisition method according to an embodiment of the present disclosure is shown. Figure 2 In the embodiment of the present disclosure, device 21 can be understood as an electronic device for executing the network security processing method referred to in the embodiment of the present disclosure. Device 22 can be understood as the storage device referred to above, which stores data of one or more attack events, such as information about the attack contained in the attack event, the implementation relationship between the attack and the security vulnerability, etc.

[0067] like Figure 2As shown, in some examples, a user can send a request message to device 22 via device 21. The request message includes at least the user's identity information (e.g., account number, password, unique code, etc.) and an identifier indicating the type of the request message. For example, when the request message carries a preset identifier a11, the request message is used to request relevant data of the attack event, such as the time when the attack event occurred, the attack information included in the attack event, the implementation relationship between the attack and the security vulnerability, and whether the security vulnerability used in the attack event has been fixed.

[0068] After receiving the request message from device 21, device 22 verifies the user's identity based on the identity information carried in the request message. If the verification succeeds, device 22 returns data on one or more attack events to device 21. If the verification fails, device 22 returns a failure response message to device 21.

[0069] certainly, Figure 2 This is for illustrative purposes only and is not intended to be limiting.

[0070] In step S103, based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability, a first weight of the target security vulnerability in the attack is determined.

[0071] In the disclosed embodiment, the first weight of the target security vulnerability in the attack is used to represent the contribution or importance of the target security vulnerability in the attack. The first weight of the target security vulnerability in the attack can be determined using the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability.

[0072] For example, in some embodiments, when an attack is carried out through a target security vulnerability, the first weight of the target security vulnerability in the attack can be determined as the risk coefficient of the attack. When the attack is not carried out through a target security vulnerability, the first weight of the target security vulnerability in the attack can be set to a preset base value, such as zero, but not limited to zero.

[0073] For example, Figure 3 FIG. 1 is a schematic diagram of a weight determination method according to an embodiment of the present disclosure. Figure 3 As shown, assume that the attack event includes attack 31 and attack 32. Attack 31 is implemented through the target security vulnerability, while attack 32 is not. The first weight of the target security vulnerability in attack 31 can be expressed as a31, and the first weight of the target security vulnerability in attack 32 can be expressed as a32. Here, a31 is the risk factor of attack 31, and a32 is a preset base value, with a31 being greater than a32.

[0074] For example, in other implementations, if the attack is carried out through a target security vulnerability, the risk coefficient of the attack can be weighted with a preset third weight, and the weighted result can be used as the first weight of the target security vulnerability in the attack. If the attack is not carried out through a target security vulnerability, the risk coefficient of the attack can be weighted with a preset fourth weight, and the weighted result can be used as the first weight of the target security vulnerability in the attack. The third weight is greater than the fourth weight.

[0075] For example, Figure 4 FIG2 shows another weight determination method according to an embodiment of the present disclosure. Figure 4 In FIG. (a), in some implementations, the weight coefficient of the target security vulnerability in the attack can be determined based on the implementation relationship between the attack and the target security vulnerability, such as Figure 4 In the example, attack 41 is implemented through the target security vulnerability, so the weight coefficient of the target security vulnerability in attack 41 is the third weight, that is, b41 in Figure (a). Attack 42 is not implemented through the target security vulnerability, so the weight coefficient of the target security vulnerability in attack 42 is the fourth weight, that is, b42 in Figure (a), and b41 is greater than b42. Figure 4 In Figure (b), once the weighted coefficient of the target security vulnerability in the attack is determined, the risk coefficient of the attack can be weighted by the weighted coefficient to obtain the first weight of the target security vulnerability in the attack. For example, if the risk coefficient of attack 41 is a41, and the risk coefficient of attack 42 is a42, then the first weight of the target security vulnerability in attack 41 is a41 multiplied by b41, and the first weight in attack 42 is a42 multiplied by b42.

[0076] In step S105, based on the first weight of the target security vulnerability in the attack, a first distance between the first weight and the first weight boundary, and a second distance between the first weight and the second weight boundary are determined. The first weight boundary and the second weight boundary respectively represent the optimal solution and the most decomposition of the weight of the security vulnerability in the attack.

[0077] In the disclosed embodiments, the optimal solution and the most fragmented weight of a security vulnerability in an attack may be a pre-set set value, or a calculated value calculated based on a preset algorithm. The optimal solution and the most fragmented weight of a security vulnerability in different attacks may be the same or different. In some exemplary embodiments, the optimal solution of the weight of different security vulnerabilities in the same attack may be the same, that is, the first weight boundaries of different security vulnerabilities in the same attack may be the same, and similarly, the second weight boundaries of different security vulnerabilities in the same attack may also be the same. For example, if an attack event contains three security vulnerabilities, then for the same attack, the first weight boundaries of the three security vulnerabilities in the attack may all be L1, and the second weight boundaries may all be L2.

[0078] In the embodiment of the present disclosure, there may be multiple methods for determining a first distance between the first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary based on the first weight of the target security vulnerability in the attack.

[0079] For example, in some examples, the absolute value of the difference between the first weight of the target security vulnerability in the attack and the first weight boundary in the attack can be determined as the first distance of the target security vulnerability in the attack. The absolute value of the difference between the first weight of the target security vulnerability in the attack and the second weight boundary in the attack can be determined as the second distance of the target security vulnerability in the attack. For example, the first weight of the target security vulnerability in attack G is Q1, and the first weight boundary of one or more security vulnerabilities used in the attack event (including the target security vulnerability) in attack G is L1, and the second weight boundary is L2. Then, the first distance of the target security vulnerability in attack G can be specifically defined as the absolute value of the difference between Q1 and L1, and the second distance of the target security vulnerability in attack G can be specifically defined as the absolute value of the difference between Q1 and L2.

[0080] For example, in some other examples, the Euclidean distance between the first weight of the target security vulnerability in the attack and the first weight boundary of the security vulnerability in the attack (hereinafter referred to as the first Euclidean distance) can be calculated, and the first Euclidean distance can be used as the first distance of the target security vulnerability in the attack. Similarly, the Euclidean distance between the first weight of the target security vulnerability in the attack and the second weight boundary of the security vulnerability in the attack (hereinafter referred to as the second Euclidean distance) can be calculated, and the second Euclidean distance can be used as the second distance of the target security vulnerability in the attack.

[0081] Still taking the above example, assuming that the first weight of the target security vulnerability in attack G is Q1, the first weight boundary of one or more security vulnerabilities used in the attack event (including the target security vulnerability) in attack G is L1, and the second weight boundary is L2, then the first distance D1 of the target security vulnerability in attack G can be expressed as follows.

[0082]

[0083] Similarly, the first distance D2 of the target security vulnerability in the attack G can be expressed as follows.

[0084]

[0085] Of course, the above two examples are merely illustrative of the method for determining the first distance and the second distance, and are not the only limitation.

[0086] It is worth noting that when an attack event includes multiple attacks, the first distance and the second distance of the target security vulnerability in at least some of the attacks included in the attack event can be determined separately. The determination method is similar and will not be repeated here.

[0087] In step S107 , a second weight of the target security vulnerability in the attack event is determined based on a first distance between the first weight of the target security vulnerability in the attack and a first weight boundary, and a second distance between the first weight of the target security vulnerability and a second weight boundary.

[0088] In the embodiment of the present disclosure, the second weight of the target security vulnerability in the attack event is a quantification of the contribution of the target security vulnerability in the attack event.

[0089] In some examples, the first distance and the second distance of the target security vulnerability in one or more attacks included in the attack event, as well as the risk factor of each attack, can be input into a first preset model, and the first preset model can be used to output the second weight of the target security vulnerability in the attack event. For example, Figure 5 A schematic diagram of another weight determination method in an embodiment of the present disclosure is shown. Figure 5 As shown, assume that an attack event includes attack A and attack B. The risk coefficient of attack A is a, and the risk coefficient of attack B is b. The first distance of the target security vulnerability in attack A is L11, and the first distance in attack B is L12. The second distance of the target security vulnerability in attack A is L21, and the second distance in attack B is L22. In some embodiments, the risk coefficient a of attack A, the risk coefficient b of attack B, the first distance L11 of the target security vulnerability in attack A, the first distance L12 of the target security vulnerability in attack B, the second distance 21 of the target security vulnerability in attack A, and the second distance L22 of the target security vulnerability in attack B can be input into a first preset model, and the output of the first preset model is used to obtain a second weight of the target security vulnerability in the attack event. The first preset model can be any artificial intelligence model, such as, but not limited to, a machine learning model or a neural network model. The first preset model can be trained using model training methods provided by relevant technologies. The sample data used to train the first preset model can include the first and second distances of the security vulnerability in one or more attacks included in the attack event. The sample label can include the weight of the security vulnerability in the attack event.

[0090] In step S109 , the scanning frequency of the target security vulnerability is determined based on the second weight of the target security vulnerability in the attack event.

[0091] In some implementations of the disclosed embodiments, the relationship between the scanning frequency of a target security vulnerability and the second weight of the target security vulnerability can be configured as a positive correlation. That is, the greater the second weight of the target security vulnerability, the higher the scanning frequency configured for the target security vulnerability, thereby achieving focused monitoring of security vulnerabilities with higher risks and improving security.

[0092] The above embodiment of the present disclosure obtains the attack information contained in the attack event (the attack information includes the risk coefficient of the attack) and the implementation relationship between the attack and the target security vulnerability; based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability, determines the first weight of the target security vulnerability in the attack; based on the first weight of the target security vulnerability in the attack, determines the first distance between the first weight and the first weight boundary (i.e., the optimal solution of the weight of the security vulnerability in the attack), and the second distance between the first weight and the second weight boundary (i.e., the most split solution of the weight of the security vulnerability in the attack); based on the first distance and the second distance, determines the second weight of the target security vulnerability in the attack event, thereby quantifying the contribution of the security vulnerability in the attack event. Based on the second weight of the security vulnerability in the attack event, determines the scanning frequency of the target security vulnerability, and realizes differentiated configuration of the scanning frequency. For example, when the second weight of the security vulnerability is large, a high scanning frequency can be used to focus on scanning important security vulnerabilities; when the second weight of the security vulnerability is small, the security vulnerability can be scanned at a relatively low scanning frequency, thereby realizing reasonable allocation and utilization of scanning resources.

[0093] Figure 6 A flow chart of a method for determining the optimal solution and the most cracking method in an embodiment of the present disclosure is shown. Figure 6 As shown, in some embodiments, the optimal solution and the optimal splitting of the weight of the security vulnerability in the attack may include the following steps.

[0094] In step S601, the weights of one or more security vulnerabilities used in the attack event are obtained.

[0095] The weight of the security vulnerability in the attack can be determined by using the method for determining the first weight in the aforementioned embodiment.

[0096] In step S603, the minimum value among the obtained weights is determined as the optimal solution to the security vulnerability in the attack.

[0097] In step S605, the maximum value among the obtained weights is determined as the most vulnerable security vulnerability in the attack.

[0098] The execution order of step S603 and step S605 can be arbitrary.

[0099] For example, assuming that the attack event contains n (n is a positive integer) attacks and there are m (m is a positive integer) security vulnerabilities used, the following matrix can be established:

[0100]

[0101] Each row vector in the matrix z represents a security vulnerability, and each column vector represents an attack. The element in the i-th row and j-th column of the matrix z represents the first weight of the security vulnerability corresponding to the i-th row in the attack corresponding to the j-th column.

[0102] Based on the matrix z, the optimal solution for the weight of the security vulnerabilities used in the attack event among n attacks can be expressed as:

[0103]

[0104] Among them, "min{}" means to find the minimum value operation. represents the optimal solution for the security vulnerability in the attack corresponding to the first column of the matrix, It represents the optimal solution of the security vulnerability in the attack corresponding to the second column of the matrix, and so on. Represents the optimal solution to the attack corresponding to the security vulnerability in the nth column of the matrix.

[0105] The optimal split of the weight of the security vulnerability used in the attack event among n attacks can be expressed as:

[0106]

[0107] Among them, "max{}" means to find the maximum value operation. Indicates the most cracked security vulnerability in the attack corresponding to the first column of the matrix, Indicates the most cracked security vulnerability in the attack corresponding to the second column of the matrix, and so on. Indicates the most cracked security vulnerability in the attack corresponding to the nth column of the matrix.

[0108] The optimal solution and the most split solution calculated in the above embodiments of the present disclosure are respectively used to calculate the distance between the weight of the target security vulnerability in the attack and the optimal solution, as well as the distance between the weight and the most split solution. This distance can help quantify the contribution of the target security vulnerability in the attack event.

[0109] Figure 7 A flow chart of a method for determining the weight of a security vulnerability in an embodiment of the present disclosure is shown. Figure 7 As shown, in some implementations, the second weight of the target security vulnerability in the attack event can be determined through the following steps.

[0110] In step S701 , a weight score of the target security vulnerability in the attack event is determined based on the first distance and the second distance of the target security vulnerability in the attack.

[0111] For example, in some implementations, the sum of the first distance and the second distance of the target security vulnerability in the attack included in the attack event may be used as the weight score of the target security vulnerability in the attack event.

[0112] For example, if an attack event contains one attack, the first distance of the target security vulnerability in the attack is L71 and the second distance is L72. The sum of L71 and L72 is determined as the weight score of the target security vulnerability in the attack event.

[0113] For another example, if an attack event includes two attacks, assume that the first distance of the target security vulnerability in attack H is L711 and the second distance is L712. For attack G, the first distance is L721 and the second distance is L722. The sum of L711, L712, L721, and L722 can be used to determine the weighted score of the target security vulnerability in the attack event. Similarly, if an attack event includes multiple attacks, the first and second distances of the target security vulnerability in each attack can be summed to determine the weighted score of the target security vulnerability in the attack event.

[0114] For example, in other embodiments, the sum of the first distances of the target security vulnerability in multiple attacks can be calculated, and the proportion of the calculated sum in the second target value can be determined as the weight score of the target security vulnerability in the attack event. Alternatively, the sum of the second distances of the target security vulnerability in multiple attacks can be calculated, and the proportion of the calculated sum in the second target value can be determined as the weight score of the target security vulnerability in the attack event. The second target value can be obtained by calculating the first distance and the second distance of the target security vulnerability in multiple attacks using a preset algorithm, wherein the preset algorithm can be set as needed and is not specifically limited in the embodiments of the present disclosure.

[0115] For example, in some examples, the sum of the first distance and second distance of the target security vulnerability in multiple attacks can be used as the second target value. For example, if an attack event includes two attacks, assuming the first distances of the security vulnerability in the two attacks are L211 and L212, and the second distances in the two attacks are L221 and L222, respectively, the sum of L211, L212, L221, and L222 can be used as the second target value.

[0116] In some further embodiments, the second target value may also be calculated using the following expression:

[0117]

[0118] It is the third Euclidean distance calculated based on the first distance of the target security vulnerability in multiple attacks. It is the fourth Euclidean distance calculated based on the second distance of the target security vulnerability in multiple attacks. and It can be calculated by TOPSIS method. The expression is as follows:

[0119]

[0120] n represents the number of attacks contained in the attack event, represents the optimal solution of the target security vulnerability in the jth attack, z ij Represents the weight of the target security vulnerability in the jth attack (i.e., the first weight). With z ij The difference can be exemplarily understood as the first distance of the target security vulnerability in the j-th attack.

[0121] The expression is as follows:

[0122]

[0123] Indicates the most cracked target security vulnerability in the j-th attack. With z ij The difference can be exemplarily understood as the second distance of the target security vulnerability in the j-th attack.

[0124] In this case, the weight score S of the target security vulnerability in the attack event i It can be calculated by the following expression.

[0125]

[0126] That is, in some embodiments, a third Euclidean distance can be determined based on the first distance of the target security vulnerability in multiple attacks, and a fourth Euclidean distance can be determined based on the second distance of the target security vulnerability in multiple attacks. The proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value can be determined as the weighted score of the target security vulnerability in the attack event. The second target value can be the sum of the third Euclidean distance and the fourth Euclidean distance.

[0127] In step S702, the proportion of the weight score of the target security vulnerability in the first target value is determined as the second weight of the target security vulnerability in the attack event.

[0128] The first target value refers to the sum of weighted scores of one or more security vulnerabilities used in the attack event.

[0129] In some embodiments, the second weight R of the target security vulnerability in the attack event i It can be calculated by the following expression.

[0130]

[0131] Among them, m represents the number of security vulnerabilities used in the attack incident, S j Represents the weight score of the j-th security vulnerability in the attack event.

[0132] The above-mentioned embodiment of the present disclosure determines the weight score of the target security vulnerability in the attack event through the first distance and the second distance of the target security vulnerability in the attack, and determines the proportion of the weight score of the target security vulnerability in the first target value as the second weight of the target security vulnerability in the attack event, thereby realizing the quantification of the risk of the target security vulnerability. Furthermore, based on the quantification result of the risk, differentiated allocation of scanning resources can be achieved, thereby improving the rationality of scanning resource allocation and utilization.

[0133] Figure 8 FIG2 shows a schematic diagram of a network security processing device in an embodiment of the present disclosure. The device can be understood as the electronic device or part of the functional modules in the electronic device in the aforementioned embodiment. Figure 8 As shown, in some embodiments, the determining device 80 includes:

[0134] The first acquisition module 81 is used to obtain the attack information contained in the attack event and the implementation relationship between the attack and the target security vulnerability. The attack information includes the risk coefficient of the attack. The target security vulnerability refers to any security vulnerability used in the attack event.

[0135] The first determining module 82 is configured to determine a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and the implementation relationship between the attack and the target security vulnerability.

[0136] The second determination module 83 is used to determine a first distance between the first weight and the first weight boundary, and a second distance between the first weight and the second weight boundary based on the first weight of the target security vulnerability in the attack, the first weight boundary and the second weight boundary respectively representing the optimal solution and the most decomposition of the weight of the security vulnerability in the attack.

[0137] The third determining module 84 is configured to determine a second weight of the target security vulnerability in the attack event based on a first distance between the first weight and the first weight boundary and a second distance between the first weight and the second weight boundary.

[0138] The fourth determining module 85 is configured to determine a scanning frequency for the target security vulnerability based on the second weight of the target security vulnerability in the attack event.

[0139] In one embodiment of the present disclosure, the first acquisition module 81 is configured to extract attack information contained in an attack event from an analysis report of the attack event based on the ATT&CK attack technology matrix.

[0140] In one embodiment of the present disclosure, the first determining module 82 includes:

[0141] The first processing unit is configured to, when an attack is carried out through a target security vulnerability, weight the risk coefficient of the attack with the third weight to obtain a first weight of the target security vulnerability in the attack.

[0142] The second processing unit is configured to, if the attack is not carried out through the target security vulnerability, weight the risk coefficient of the attack and the fourth weight to obtain a first weight of the target security vulnerability in the attack, wherein the third weight is greater than the fourth weight.

[0143] In one embodiment of the present disclosure, the second determining module 83 includes:

[0144] The third processing unit is configured to determine a first Euclidean distance between the first weight and the first weight boundary based on the first weight of the target security vulnerability in the attack.

[0145] The fourth processing unit is configured to determine a second Euclidean distance between the first weight and a second weight boundary based on the first weight of the target security vulnerability in the attack.

[0146] In one embodiment of the present disclosure, the network security processing device 80 may further include:

[0147] The second acquisition module is used to obtain the weight of one or more security vulnerabilities used in the attack event in the attack;

[0148] The fifth determination module is configured to determine the minimum value among the weights as the optimal solution for the weight of the security vulnerability in the attack.

[0149] The sixth determination module is used to determine the maximum value among the weights as the maximum value of the weight of the security vulnerability in the attack.

[0150] In one embodiment of the present disclosure, the third determining module 84 includes:

[0151] A first determining unit, configured to determine a weight score of a target security vulnerability in an attack event based on the first distance and the second distance;

[0152] The second determining unit is configured to determine a proportion of the weight score of the target security vulnerability in the attack event in the first target value as a second weight of the target security vulnerability in the attack event.

[0153] The first target value refers to the sum of weighted scores of one or more security vulnerabilities used in the attack event.

[0154] In one embodiment of the present disclosure, the first determining unit is configured to:

[0155] Based on the first distance of the target security vulnerability in multiple attacks, a third Euclidean distance is determined; based on the second distance of the target security vulnerability in multiple attacks, a fourth Euclidean distance is determined, and the proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value is determined as the weight score of the target security vulnerability in the attack event; wherein the second target value refers to the sum of the third Euclidean distance and the fourth Euclidean distance.

[0156] The execution method and beneficial effects of the determination device 80 provided in the above embodiment of the present disclosure can be referred to any of the above method embodiments, and will not be repeated here.

[0157] For example, an embodiment of the present disclosure further provides an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the network security processing method in the above embodiment by executing the executable instructions.

[0158] Figure 9 The following is a block diagram of an electronic device according to an embodiment of the present disclosure. Figure 9 An electronic device 900 according to this embodiment of the present invention will be described. Figure 9 The electronic device 900 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present invention.

[0159] like Figure 9 As shown, electronic device 900 is implemented as a general-purpose computing device. Components of electronic device 900 may include, but are not limited to, at least one processing unit 910, at least one storage unit 920, and a bus 930 connecting various system components (including storage unit 920 and processing unit 910).

[0160] The storage unit stores program codes that can be executed by the processing unit 910, so that the processing unit 910 performs the steps according to various exemplary embodiments of the present invention described in the "Exemplary Method" section above. For example, the processing unit 910 can perform the following steps: Figure 1 The method shown in .

[0161] The storage unit 920 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 9201 and / or a cache memory unit 9202 , and may further include a read-only memory unit (ROM) 9203 .

[0162] The storage unit 920 may also include a program / utility 9204 having a set (at least one) of program modules 9205, such program modules 9205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0163] Bus 930 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0164] The electronic device 900 can also communicate with one or more external devices 700 (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 900, and / or any device that enables the electronic device 900 to communicate with one or more other computing devices (e.g., a router, a modem, etc.). Such communication can occur via an input / output (I / O) interface 950. Furthermore, the electronic device 900 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 960. As shown, the network adapter 960 communicates with other modules of the electronic device 900 via a bus 930. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 900, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0165] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0166] In exemplary embodiments of the present disclosure, a computer-readable storage medium is also provided, on which is stored a program product capable of implementing the aforementioned methods of this specification. In some possible implementations, various aspects of the present invention may also be implemented in the form of a program product comprising program code. When the program product is executed on a terminal device, the program code is configured to cause the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the "Exemplary Methods" section of this specification.

[0167] A program product for implementing the above-described method according to an embodiment of the present invention is described. The program product may be a portable compact disc read-only memory (CD-ROM) and include program code, and may be run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, a readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0168] The program product may be implemented in any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0169] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0170] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0171] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and the like, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0172] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0173] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0174] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0175] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. A network security processing method, characterized in that: include: Obtaining attack information contained in the attack event and an implementation relationship between the attack and the target security vulnerability, wherein the attack information includes a risk coefficient of the attack; Determining a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and the implementation relationship; Determining, based on a first weight of the target security vulnerability in the attack, a first distance between the first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary, wherein the first weight boundary and the second weight boundary respectively represent an optimal solution and an optimal split of the weight of the security vulnerability in the attack; Determining a second weight of the target security vulnerability in the attack event based on the first distance and the second distance; Based on the second weight, a scanning frequency of the target security vulnerability is determined.

2. The method according to claim 1, characterized in that The obtaining of attack information contained in the attack event and the implementation relationship between the attack and the target security vulnerability includes: Based on the intruder tactics, techniques and the shared knowledge base ATT&CK attack technology matrix, the attack information contained in the attack event is extracted from the analysis report of the attack event.

3. The method according to claim 1 or 2, characterized in that The determining, based on the risk coefficient of the attack and the implementation relationship, a first weight of the target security vulnerability in the attack includes: In the case where the attack is carried out through the target security vulnerability, weighting the risk coefficient of the attack with the third weight to obtain a first weight of the target security vulnerability in the attack; If the attack is not carried out through the target security vulnerability, weighting the risk coefficient of the attack by the fourth weight to obtain a first weight of the target security vulnerability in the attack; The third weight is greater than the fourth weight.

4. The method according to claim 1, wherein The determining, based on the first weight of the target security vulnerability in the attack, a first distance between the first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary, comprises: Determining, based on a first weight of the target security vulnerability in the attack, a first Euclidean distance between the first weight and the first weight boundary; Based on a first weight of the target security vulnerability in the attack, a second Euclidean distance between the first weight and the second weight boundary is determined.

5. The method according to claim 1 or 4, characterized in that The method further comprises: Obtaining weights of one or more security vulnerabilities used in the attack event in the attack; Determining a minimum value among the weights of the one or more security vulnerabilities as the optimal solution; The maximum value among the weights of the one or more security vulnerabilities is determined as the most vulnerable.

6. The method according to claim 1, characterized in that The determining, based on the first distance and the second distance, a second weight of the target security vulnerability in the attack event includes: Determining a weight score of the target security vulnerability in the attack event based on the first distance and the second distance; Determine the proportion of the weight score of the target security vulnerability in the first target value as the second weight of the target security vulnerability in the attack event; The first target value refers to the sum of weighted scores of one or more security vulnerabilities used in the attack event.

7. The method according to claim 6, characterized in that Determining a weight score of the target security vulnerability in the attack event based on the first distance and the second distance includes: Determining a third Euclidean distance based on the first distance of the target security vulnerability in the multiple attacks included in the attack event; determining a fourth Euclidean distance based on a second distance of the target security vulnerability in the multiple attacks included in the attack event; determining a proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value as a weight score of the target security vulnerability in the attack event; The second target value refers to the sum of the third Euclidean distance and the fourth Euclidean distance.

8. A network security processing device, characterized in that: include: A first acquisition module is configured to acquire attack information contained in an attack event and an implementation relationship between the attack and a target security vulnerability, wherein the attack information includes a risk coefficient of the attack; A first determining module, configured to determine a first weight of the target security vulnerability in the attack based on the risk coefficient of the attack and the implementation relationship; a second determining module, configured to determine, based on a first weight of the target security vulnerability in the attack, a first distance between the first weight and a first weight boundary, and a second distance between the first weight and a second weight boundary, wherein the first weight boundary and the second weight boundary respectively represent an optimal solution and an optimal split of the weight of the security vulnerability in the attack; a third determining module, configured to determine a second weight of the target security vulnerability in the attack event based on the first distance and the second distance; A fourth determining module is configured to determine a scanning frequency for the target security vulnerability based on the second weight.

9. The device according to claim 8, characterized in that The first acquisition module is configured to: Based on the intruder tactics, techniques and the shared knowledge base ATT&CK attack technology matrix, the attack information contained in the attack event is extracted from the analysis report of the attack event.

10. The device according to claim 8 or 9, characterized in that The first determining module includes: a first processing unit configured to, when an attack is carried out through the target security vulnerability, weight the risk coefficient of the attack by a third weight to obtain a first weight of the target security vulnerability in the attack; a second processing unit, configured to, if the attack is not carried out through the target security vulnerability, weight the risk coefficient of the attack by a fourth weight to obtain a first weight of the target security vulnerability in the attack; The third weight is greater than the fourth weight.

11. The device according to claim 8, characterized in that The second determining module includes: a third processing unit, configured to determine, based on the first weight of the target security vulnerability in the attack, a first Euclidean distance between the first weight and the first weight boundary; The fourth processing unit is configured to determine a second Euclidean distance between a boundary of the first weight and a boundary of the second weight based on the first weight of the target security vulnerability in the attack.

12. The device according to claim 8 or 11, characterized in that The device further comprises: A second acquisition module is used to obtain the weights of one or more security vulnerabilities used in the attack event in the attack; a fifth determining module, configured to determine a minimum value among the weights of the one or more security vulnerabilities as the optimal solution; The sixth determining module is configured to determine the maximum value among the weights of the one or more security vulnerabilities as the most vulnerable one.

13. The device according to claim 8, characterized in that The third determining module includes: A first determining unit is configured to determine a weight score of the target security vulnerability in the attack event based on the first distance and the second distance; a second determining unit, configured to determine a proportion of the weight score of the target security vulnerability in the first target value as a second weight of the target security vulnerability in the attack event; The first target value refers to the sum of weighted scores of one or more security vulnerabilities used in the attack event.

14. The device according to claim 13, characterized in that The first determining unit is configured to: Determining a third Euclidean distance based on the first distance of the target security vulnerability in the multiple attacks included in the attack event; determining a fourth Euclidean distance based on a second distance of the target security vulnerability in the multiple attacks included in the attack event; determining a proportion of the third Euclidean distance or the fourth Euclidean distance in the second target value as a weight score of the target security vulnerability in the attack event; The second target value refers to the sum of the third Euclidean distance and the fourth Euclidean distance.

15. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to perform the method according to any one of claims 1 to 7 by executing the executable instructions.

16. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.