Security vulnerability processing method and device based on large model, equipment and medium

Through the large-model-based security vulnerability processing method, the vulnerability status and intention are determined using work order information and dialogue information, and the reply content is generated, which solves the problems of low efficiency and high cost in manual processing methods, and realizes automated management and rapid response of security vulnerabilities.

CN120528678AActive Publication Date: 2025-08-22BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510812178.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-08-22
Estimated Expiration
2045-06-17

AI Technical Summary

Technical Problem

The existing security vulnerability processing process relies on a large amount of manual processing, resulting in high cost, low efficiency, high vulnerability repair overdue rate, and lack of an effective continuous experience precipitation mechanism, making it difficult to meet the needs of rapid response and closed-loop security vulnerability processing.

Method used

The security vulnerability processing method based on the big model is adopted, and the work order information and dialogue information associated with the vulnerability are obtained, the current processing status and intent identification results of the vulnerability are determined, and the reply content is generated using the large language model to automatically manage the security vulnerability processing process.

Benefits of technology

It improves the efficiency and accuracy of security vulnerabilities, reduces costs, realizes automated management of security vulnerabilities, overcomes the shortcomings of manual processing methods, and can better meet the needs of fast response and closed-loop processing of security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528678A_ABST
    Figure CN120528678A_ABST
Patent Text Reader

Abstract

The invention discloses a security vulnerability processing method and device based on a large model, equipment, a medium and a product in the technical field of network security, and the method comprises the steps: firstly obtaining target information which comprises work order information used for describing a target vulnerability and at least one round of dialogue information generated in a session associated with the target vulnerability, the dialogue information at least can indicate the to-be-replied question associated with the target vulnerability; analyzing the target information to obtain an analysis result; performing intention recognition processing according to the target information and the analysis result to obtain an intention recognition result; and processing the target information, the analysis result and the intention recognition result based on the large model to obtain a reply content corresponding to the question, and displaying the reply content to a presenter of the question, so that the presenter can know a solution for the question through the reply content, and the security vulnerabilities can be automatically managed by means of the large model. Defects existing when security vulnerabilities are managed by means of a large amount of manual processing are overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, device, equipment, medium, and product for handling security vulnerabilities based on a large model. Background Art

[0002] A security hole refers to a defect in hardware, software, system or its usage strategy. When a security hole exists, the corresponding deployed equipment (such as a computer) will be vulnerable to attacks such as viruses. Therefore, it is very important to find and repair security holes in a timely manner.

[0003] However, the existing security vulnerability handling process involves a large amount of manual processing (such as repair, management, etc.), so there are some defects, such as high cost and high vulnerability repair overdue rate. Summary of the Invention

[0004] In order to solve the above technical problems, the present application provides a security vulnerability processing method, device, equipment, medium, and product based on a large model.

[0005] In order to achieve the above objectives, the technical solutions provided by this application are as follows:

[0006] The present application provides a method for handling security vulnerabilities based on a large model, the method comprising: obtaining target information, the target information comprising work order information and at least one round of dialogue information, the work order information describing the target vulnerability, the at least one round of dialogue information being generated in a session associated with the target vulnerability, the at least one round of dialogue information at least indicating questions to be answered associated with the target vulnerability; determining the current processing status of the target vulnerability based on the target information; performing intent recognition processing based on the target information and the current processing status of the target vulnerability to obtain an intent recognition result; processing the target information, the current processing status of the target vulnerability and the intent recognition result based on the large model to obtain a reply content corresponding to the question; and displaying the reply content.

[0007] In one possible implementation, determining the current processing status of the target vulnerability based on the target information includes: analyzing the target information to obtain an analysis result, the analysis result including at least one of a first result and a second result, the first result indicating whether the question to be answered belongs to a question that has been answered in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability when the question to be answered appears; determining the current processing status of the target vulnerability based on the analysis result.

[0008] In one possible implementation, the target information, the analysis result and the intention recognition result are processed based on the big model to obtain the answer content corresponding to the question, including: in response to the question to be answered being a complex question, the target information, the analysis result and the intention recognition result are processed based on the big model to obtain a question-and-answer knowledge graph, the question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and the answer content corresponding to each sub-question; based on the question-and-answer knowledge graph, the answer content corresponding to the question to be answered is determined.

[0009] In one possible implementation, the reply content is determined by the large model based on part or all of the content in a pre-built knowledge base; the method also includes: in response to at least one information meeting a preset condition, updating the knowledge base based on the at least one information, the at least one information including the target information, the question, the reply content and part or all of the feedback information for the reply content, the preset condition including that the case indicated by the at least one information is different from the historical case recorded in the knowledge base, the case indicated by the at least one information has changed compared to the historical case, the scenario indicated by the at least one information is different from the scenario recorded in the knowledge base, the vulnerability type indicated by the at least one information is different from the vulnerability type recorded in the knowledge base, the vulnerability repair solution indicated by the at least one information has changed compared to the vulnerability repair solution recorded in the knowledge base, and the vulnerability security standard indicated by the at least one information has changed compared to the vulnerability security standard recorded in the knowledge base.

[0010] In one possible implementation, the method is applied to a vulnerability management system, which is used to manage the processing of multiple vulnerabilities; before displaying the reply content, the method also includes: in response to the difference between the acquisition times of the reply contents corresponding to at least two vulnerabilities among the multiple vulnerabilities being less than a preset threshold, determining the display timing of the reply contents corresponding to each of the at least two vulnerabilities based on the level information of each of the at least two vulnerabilities, the at least two vulnerabilities including the target vulnerability, and the reply contents corresponding to the target vulnerability including the reply contents corresponding to the question to be answered; displaying the reply contents includes: for any one of the at least two vulnerabilities, in response to reaching the display timing of the reply contents corresponding to the vulnerability, displaying the reply contents corresponding to the vulnerability.

[0011] In one possible implementation, the method is applied to a vulnerability management system, and the system is used to process conversation information sent by multiple clients, wherein the multiple clients include a client that displays a web page and a client that displays a conversation group, and the conversation information sent by the client that displays the web page includes the at least one round of conversation information, or the conversation information sent by the client that displays the conversation group includes the at least one round of conversation information; before displaying the reply content, the method also includes: in response to the difference between the moments when the system generates reply content based on the conversation information sent by each of the clients being less than a preset threshold, determining the reply timing corresponding to each of the clients based on the description information of each of the clients; displaying the reply content includes: for any of the at least two clients, in response to reaching the reply timing corresponding to the client, displaying the reply content generated by the system based on the conversation information sent by the client.

[0012] In one possible implementation, the method is applied to a vulnerability management system, wherein the repair process of the target vulnerability is executed through a first login account of the vulnerability management system, and the processing progress of the target vulnerability is followed up through a second login account of the vulnerability management system; the question to be answered is input through the first login account; and / or, the method further includes: in response to the inability to obtain the answer content corresponding to the question through the large model, sending a prompt message to the second login account, the prompt message instructing the second login account to answer the question, and determining the answer content corresponding to the question based on the content input by the second login account for the question.

[0013] The present application provides a security vulnerability processing device based on a large model, including: an acquisition unit, used to acquire target information, the target information including work order information and at least one round of dialogue information, the work order information describing the target vulnerability, the at least one round of dialogue information generated in a session associated with the target vulnerability, and the at least one round of dialogue information at least indicating a question to be answered associated with the target vulnerability; an analysis unit, used to analyze the target information to obtain an analysis result, the analysis result including a first result and / or a second result, the first result indicating whether the question to be answered belongs to a question that has been answered in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability at the time when the question to be answered appears; an identification unit, used to perform intent recognition processing based on the target information and the analysis result to obtain an intent recognition result; a processing unit, used to process the target information, the analysis result and the intent recognition result based on the large model to obtain a reply content corresponding to the question; and a display unit, used to display the reply content.

[0014] The present application provides an electronic device, which includes: a processor and a memory; the memory is used to store instructions or computer programs; the processor is used to execute the instructions or computer programs in the memory, so that the electronic device executes the large model-based security vulnerability processing method provided by the present application.

[0015] The present application provides a computer-readable medium having instructions or computer programs stored therein. When the instructions or computer programs are executed on a device, the device executes the large model-based security vulnerability processing method provided in the present application.

[0016] The present application provides a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the large model-based security vulnerability processing method provided by the present application.

[0017] Compared with the related art, this application has at least the following advantages:

[0018] In the technical solution provided by the present application, target information is first obtained, and the target information includes work order information for describing the target vulnerability (such as any security vulnerability), and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing of the target vulnerability), so that the at least one round of dialogue information can at least indicate the questions to be answered associated with the target vulnerability (such as the questions input in the current round), so that the at least one round of dialogue information can describe some problems encountered when being in the target vulnerability, such as errors in the vulnerability repair process; then, the current processing status of the target vulnerability is determined based on the target information, so that The current processing state can indicate the characteristics of the target vulnerability in the current round, such as the reasons why subsequent processing cannot be performed on the target vulnerability, and the current processing stage of the target vulnerability (such as vulnerability repair stage, vulnerability testing stage, etc.); then, intent recognition processing is performed based on the target information and the current processing state to obtain an intent recognition result, so that the intent recognition result can indicate the type of problem to be answered (such as defects in the vulnerability repair solution, inability to complete the vulnerability repair on time, etc.), so that the intent recognition result can represent the needs of the current round; secondly, based on a large model, such as a large language model (LLM), the target information, the current processing state and the intent recognition result are processed to obtain the corresponding answer content of the question and display it to the questioner, so that the questioner can better understand the solution to the problem through the answer content, so as to continue to execute the processing process for the target vulnerability after solving the problem. In this way, security vulnerabilities can be automatically managed with the help of a large model, thereby effectively overcoming the defects that exist when security vulnerabilities are managed with a large amount of manual processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A schematic diagram of a vulnerability management process implemented with a large amount of manual processing provided in an embodiment of the present application;

[0021] Figure 2 A schematic diagram of a manual vulnerability management process provided in an embodiment of the present application;

[0022] Figure 3A flowchart of a method for handling security vulnerabilities based on a large model provided in an embodiment of the present application;

[0023] Figure 4 A schematic diagram of the structure of a vulnerability management system provided in an embodiment of the present application;

[0024] Figure 5 A schematic diagram of a vulnerability management system provided in an embodiment of the present application;

[0025] Figure 6 A schematic diagram of the structure of a security vulnerability processing device based on a large model provided in an embodiment of the present application;

[0026] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] It is understandable that before using the technical solutions disclosed in the various embodiments of the present disclosure, the type, scope of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to relevant users and authorization should be obtained from relevant users in an appropriate manner in accordance with relevant laws and regulations. The relevant users may include any type of right holders, such as individuals, enterprises, and groups.

[0028] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly prompt the relevant user that the operation requested to be performed will require obtaining and using the information of the relevant user, so that the relevant user can independently choose whether to provide information to the software or hardware such as the electronic device, application, server or storage medium that executes the operation of the technical solution of the present disclosure based on the prompt message.

[0029] As an optional but non-limiting implementation, in response to receiving an active request from a relevant user, a prompt message may be sent to the relevant user in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide information to the electronic device.

[0030] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0031] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.

[0032] The study found that when a large number of manual processes are used to manage security vulnerabilities, this management method (such as Figure 1 The management method shown in the figure) involves a lot of manual processing, so that this management method mainly relies on manual work, which makes this management method have at least the defects shown in the following ①-④. It should be noted that in this Figure 1 In the above, “security” is the abbreviation of the security party, which is responsible for at least formulating and distributing security vulnerability repair plans and following up on the handling process of security vulnerabilities; “business” is the abbreviation of the business party, which is responsible for implementing the security vulnerability repair plans.

[0033] ① Due to the low efficiency of manual work, the cycle of some processing processes performed manually (such as vulnerability repair processes, etc.) is relatively long, which may lead to the phenomenon of missed vulnerability repair follow-up, untimely vulnerability repair follow-up, or late intervention, thus affecting the management effect of security vulnerabilities.

[0034] ② When managing security vulnerabilities with a large amount of manual processing, manual classification, allocation, communication and coordination of repair plans are required during the relevant processing of the vulnerability, which is time-consuming and labor-intensive, and is prone to task omissions and unclear responsibilities, resulting in an increased repair rate.

[0035] ③ Due to the lack of an effective and continuous experience accumulation mechanism when following up on the security vulnerability handling process with a large amount of manual processing, it is difficult to form an efficient closed-loop vulnerability management.

[0036] ④ With the increasing complexity of attack methods and the increase in labor costs, vulnerability management solutions that rely on a large amount of manual processing not only show a significant increase in vulnerability management costs, but also find it difficult to meet the vulnerability management needs in some application scenarios, such as rapid response to security vulnerabilities and closed-loop processing of security vulnerabilities.

[0037] The study also found that in order to ensure that the repair process of security vulnerabilities can be carried out smoothly, to reduce the occurrence of overdue vulnerabilities and other phenomena and to improve the rate of vulnerability repair, relevant personnel (such as Figure 1 or Figure 2 The "security" personnel shown in the figure) answer questions about many issues that arise during the vulnerability repair process (such as Figure 1 It can be seen that the understanding of security vulnerability knowledge and problem solving is an important factor in the vulnerability management process. However, when relying on a large amount of manual processing to follow up on the security vulnerability processing process (such as the repair process, etc.), there are problems as shown in the following (1)-(4).

[0038] (1) When a large amount of manual processing is used to follow up on the progress of security vulnerability handling, there will be problems of low efficiency and high cost. The reasons for this problem are as follows: when a large amount of manual processing is used to follow up on the vulnerability handling process, on average, each vulnerability requires about 5 communications between different groups, so that more than 60% of the time of these groups is spent on progress confirmation and follow-up.

[0039] (2) When the progress of security vulnerability handling is followed up with a large amount of manual processing, the work order system used only supports one-way notification and cannot actively initiate conversations or actively collect and summarize information related to vulnerability handling (such as information related to vulnerability repair) for promotion and guidance.

[0040] (3) When following up the progress of security vulnerabilities with a large amount of manual processing, there are the following difficulties in terms of working hours: if 24 / 7 shifts are not arranged, the relevant personnel (such as Figure 1 or Figure 2 The "security" personnel shown in the figure cannot be on duty and answer questions at any time, which affects the progress of vulnerability repair. However, if a 24 / 7 shift is implemented, a large amount of additional manpower costs will be added, resulting in a significant increase in vulnerability management costs.

[0041] (4) When a large number of manual processes are used to follow up on the handling process of security vulnerabilities, there is a dilemma of repeated responses. The reasons for this dilemma are as follows: for any security vulnerability, the vulnerability repair plan formulated for the vulnerability is relatively certain, and the operations involved in handling the vulnerability (such as repair, retest, extension, etc.) are identical, so that the relevant personnel (such as Figure 1 or Figure 2 The "security" personnel shown in the figure have to answer the same questions every day, which results in low efficiency and high labor costs.

[0042] Based on the above research, in order to overcome the above problems, the present application provides a security vulnerability processing method based on a large model, which includes: first obtaining target information, the target information including work order information for describing the target vulnerability (such as any security vulnerability), and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing period of the target vulnerability), so that the at least one round of dialogue information can at least indicate the questions to be answered associated with the target vulnerability (such as the questions input in the current round), so that the at least one round of dialogue information can describe some problems encountered when being in the target vulnerability, such as errors in the vulnerability repair process, etc.; then determine the current processing status of the target vulnerability based on the target information, so that the current processing status can indicate the characteristics of the target vulnerability in the current round, such as why subsequent processing cannot be performed on the target vulnerability, and the current status of the target vulnerability. At what processing stage (such as vulnerability repair stage, vulnerability testing stage, etc.); then, according to the target information and the current processing status, intent recognition processing is performed to obtain an intent recognition result, so that the intent recognition result can indicate what type of problem the question to be answered belongs to (such as the vulnerability repair solution has defects, the vulnerability repair cannot be completed on time, etc.), so that the intent recognition result can represent the current round of needs; secondly, based on a large model (such as LLM and other models), the target information, the analysis result and the intent recognition result are processed to obtain the corresponding answer content of the question and display it to the questioner, so that the questioner can better understand the solution to the problem through the answer content, so as to continue to execute the processing process for the target vulnerability after solving the problem. In this way, security vulnerabilities can be automatically managed with the help of a large model, thereby effectively overcoming the defects that exist when security vulnerabilities are managed with a large amount of manual processing.

[0043] In addition, this application does not limit the execution subject of the large model-based security vulnerability processing method. For example, the method can be applied to a terminal device or a server. For another example, the method can also be implemented through the data interaction process between the terminal device and the server. The terminal device can be a smartphone, a computer, a personal digital assistant (PDA), a tablet computer, etc. The server can be a standalone server, a cluster server, or a cloud server.

[0044] In order to help those skilled in the art better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0045] In order to better understand the technical solution provided by this application, the following first describes the security vulnerability processing method based on the large model provided by this application with reference to some drawings. Figure 3 As shown, the large model-based security vulnerability processing method provided in the embodiment of the present application includes the following S1-S5.

[0046] S1: Obtain target information, where the target information includes work order information and at least one round of dialogue information, where the work order information describes a target vulnerability, and the at least one round of dialogue information is generated in a session associated with the target vulnerability, and the at least one round of dialogue information at least indicates questions to be answered associated with the target vulnerability.

[0047] Among them, target information refers to the information that needs to be referred to in the current round of response process and may affect the final response result, such as Figure 4 The input data for the input layer is shown.

[0048] In addition, the target information may include at least work order information (such as Figure 4 Work order information shown) and at least one round of dialogue information (such as Figure 4 (dialogue information shown).

[0049] For the above-mentioned work order information, the work order information describes the target vulnerability so that the work order information can express the characteristics of the target vulnerability in the current round; and this application does not limit the implementation method of the work order information. For example, the work order information can at least include some fixed static information, such as the type of the target vulnerability, the danger level of the target vulnerability, the attributes of the target vulnerability, etc. For another example, the work order information can also include some dynamic information that may change, such as the repair plan for the target vulnerability, the executor of the repair process of the target vulnerability (such as Figure 1 The information includes the work order responsible person shown in the figure), the real-time processing stage of the target vulnerability (such as repair, retest, extension, exemption, etc.), the real-time repair status of the target vulnerability (such as repair in progress, repair suspended, repair resumed, repair stage reached, etc.), the problems encountered during the handling of the target vulnerability and their solutions, etc.

[0050] It can be seen that in one possible implementation, the above work order information can be updated based on the data generated in real time during the processing of the target vulnerability (such as vulnerability repair status, vulnerability processing stage, etc.), so that the work order information can accurately describe the characteristics of the target vulnerability in the current round. It should be noted that this application does not limit the initial value of the work order information. For example, the initial value can be distributed by relevant personnel for the target vulnerability (such as Figure 1 or Figure 2 Implementation is performed based on the work order information set when the vulnerability is distributed.

[0051] The at least one round of conversation information is generated in a session associated with the target vulnerability (e.g., a session triggered around the target vulnerability during the processing of the target vulnerability), so that the at least one round of conversation information can at least indicate the pending questions associated with the target vulnerability, such as the most recent question raised by the user regarding the target vulnerability in the current round. It should be noted that "around" refers to a discussion centered around the target vulnerability.

[0052] It can be seen that if the current round refers to the first round of dialogue triggered for the target vulnerability, then the “at least one round of dialogue information” may include the user (e.g., Figure 1 or Figure 2 However, if the current round refers to the Nth round of dialogue triggered for the target vulnerability, where N is a positive integer and N≥2, then the "at least one round of dialogue information" may include the 1st to the N-1th round of dialogue (such as some historical questions and their corresponding answers), as well as the latest question raised by the user in the Nth round of dialogue for the target vulnerability. In this way, the "at least one round of dialogue information" can accurately and completely represent the problems encountered by the user in the process of handling the target vulnerability (such as the vulnerability repair process achieved by executing the repair solution).

[0053] According to research, in some scenarios, in order to better improve the handling effect of security vulnerabilities, relevant personnel can set up standard operating procedures (SOP) documents for the vulnerabilities in advance, such as security vulnerability management documents, frequently asked questions and answers (Frequently Asked Questions and Answers, FQA) documents, Figure 5 The technical documentation shown, Figure 5 Safety regulations document shown, Figure 5The daily conversation record document shown, etc., can enable the document to accurately and comprehensively indicate the security standards that need to be followed in the process of handling the vulnerability, so that the document can express some constraints set for the vulnerability.

[0054] Based on the above research, it can be known that in a possible implementation, the target information may include not only work order information and at least one round of dialogue information, but also document information (such as SOP documents or Figure 4 ), so that the target information can more comprehensively describe the characteristics of the target vulnerability in the current round, such as vulnerability repair status, historical conversations, current issues, security standards, etc., thereby making the response content determined based on the target information more accurate.

[0055] It should be noted that the above-mentioned document information can indicate the constraints (such as security standards, etc.) that need to be followed during the processing of the target vulnerability; and this application does not limit the implementation method of the document information. For example, the document information can refer to some reference documents provided in advance by relevant personnel for the target vulnerability. For example, in some scenarios, such as scenarios where security standards may change, the document information can be updated based on the document adjustment information provided by the relevant personnel during the processing of the target vulnerability, so that the document information can accurately represent the constraints that the target vulnerability needs to meet in the current round.

[0056] S2: Determine the current processing status of the target vulnerability based on the target information.

[0057] Among them, the current processing status of the target vulnerability can indicate the characteristics of the target vulnerability in the current round, such as the problems encountered that can hinder the subsequent processing process of the target vulnerability, the processing stage of the target vulnerability (such as vulnerability repair stage, vulnerability retesting stage, etc.), etc.

[0058] In addition, the present application does not limit the implementation method of the above-mentioned S2. For example, it can be implemented by any method that can analyze the current processing status of the target vulnerability from the target information, such as a pre-built script with the aforementioned function, a pre-built rule with the aforementioned function, or a pre-built machine learning model with the aforementioned function (such as LLM).

[0059] S3: Perform intent recognition processing based on the target information and the current processing status of the target vulnerability to obtain the intent recognition result.

[0060] Among them, the intention recognition result (such as Figure 4The data output by the intent recognition module shown) can indicate what type of problem the above-mentioned questions to be answered belong to, such as defects in the vulnerability repair plan, inability to complete the vulnerability repair on schedule, etc., so that the intent recognition result can express the needs of the current round as accurately as possible, such as what kind of problems arise at which stage, etc.

[0061] In addition, the present application does not limit the implementation of the above S3. For example, it can adopt any method that can realize the intention recognition, such as a pre-built script with the above functions, a pre-built rule with the above functions, a pre-built machine learning model with the above functions, or a pre-built rule with the above functions. Figure 4 In addition, the present application does not limit the implementation method of the machine learning model. For example, it can be implemented using any natural language processing (NLP) model, such as LLM.

[0062] S4: Based on the large model, the target information, the current processing status of the target vulnerability and the intention recognition results are processed to obtain the response content corresponding to the question to be answered.

[0063] Among them, the big model is used to perform answer analysis on the input data of the model (such as the above-mentioned target information, the current processing status of the above-mentioned target vulnerability and the above-mentioned intention recognition results, etc.); and this application does not limit the implementation method of the big model. For example, the big model may include one or more of the following: a big language model, a big visual model, a big speech model, a multimodal big model, etc.

[0064] The answer content corresponding to the question to be answered refers to the answer determined for the question in the current round, so that the answer content can indicate how to solve the problem to continue to execute the subsequent process (such as the repair process, etc.) for the target vulnerability.

[0065] In addition, the present application does not limit the implementation method of the above-mentioned S4. For example, it can be specifically: inputting the target information, the current processing status of the target vulnerability and the intention recognition result into the large model, so that the large model can perform answer analysis based on the target information, the current processing status of the target vulnerability and the intention recognition result, and obtain and output the answer content corresponding to the above-mentioned question to be answered.

[0066] For example, in some scenarios, such as answering questions with the help of a robot, the above S4 may specifically include: firstly, the large model generates a multimodal instruction (such as Figure 4The multimodal instruction can express some multimodal data (such as images, videos, texts, etc.) required to answer questions in accordance with the instruction method; and then generate a robot dialogue based on the multimodal instruction (such as through Figure 4 The dialogue generation module shown in the figure implements the dialogue generation) to obtain the answer content corresponding to the above-mentioned question to be answered, so that the answer content can express the solution to the problem in a natural language.

[0067] It should be noted that for Figure 4 For example, the dialog generation module shown is an interactive component within the vulnerability management system. It enables automated communication and collaborative management throughout the vulnerability handling process through the natural language dialogues generated by this module. Furthermore, this module replaces repetitive conversations typically found in manual vulnerability management solutions (e.g., tracking issues, remediation metrics, system operations, etc.), delivering a more personalized yet efficient interactive experience.

[0068] S5: Display the answer content corresponding to the question to be answered.

[0069] It should be noted that this application does not limit the implementation of S5. For example, S5 can be implemented by Figure 4 The dialog shown shows this module being implemented.

[0070] For another example, if the above-mentioned "questions to be answered" are raised by the user through a conversation group, then the above-mentioned S5 may specifically be: according to the rendering and display algorithm corresponding to the conversation group, the answer content corresponding to the question to be answered is rendered and displayed to ensure that the answer content can be displayed in the conversation group, so that the user can continue to initiate other conversations through the conversation group later.

[0071] For example, if the above-mentioned "questions to be answered" are raised by the user through a web page, the above-mentioned S5 can specifically be: according to the rendering and display algorithm corresponding to the web page, the answer content corresponding to the question to be answered is rendered and displayed to ensure that the answer content can be displayed on the web page, so that the user can continue to initiate other conversations through the web page later.

[0072] Based on the relevant contents of S1 to S5 above, it can be seen that the solution for automatically managing security vulnerabilities provided by the present application includes: first obtaining target information, which includes work order information for describing the target vulnerability (such as any security vulnerability), and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing period of the target vulnerability), so that the at least one round of dialogue information can at least indicate the questions to be answered associated with the target vulnerability (such as the questions input in the current round), so that the at least one round of dialogue information can describe some problems encountered when being in the target vulnerability, such as errors in the vulnerability repair process; then determine the current processing status of the target vulnerability based on the target information, so that the current processing status can indicate the characteristics of the target vulnerability in the current round, such as why subsequent processing cannot be performed on the target vulnerability, and what state the target vulnerability is currently in. processing stage (such as vulnerability repair stage, vulnerability testing stage, etc.); then, intent recognition processing is performed based on the target information and the current processing status to obtain an intent recognition result, so that the intent recognition result can indicate what type of problem the question to be answered belongs to (such as defects in the vulnerability repair plan, inability to complete the vulnerability repair on schedule, etc.), so that the intent recognition result can represent the current round of needs; secondly, based on a large model (such as LLM and other models), the target information, the analysis result and the intent recognition result are processed to obtain the corresponding answer content of the question to show it to the questioner, so that the questioner can better understand the solution to the problem through the answer content, so as to continue the processing process for the target vulnerability after solving the problem. In this way, security vulnerabilities can be automatically managed with the help of a large model, thereby effectively overcoming the defects that exist when security vulnerabilities are managed with a large amount of manual processing.

[0073] In addition, in some scenarios, the security vulnerability processing method based on the large model provided by this application can be applied to vulnerability management systems, such as Figure 4 or Figure 5 The vulnerability management system shown can be used to implement intelligent management of security vulnerabilities with the help of some artificial intelligence (AI) means, such as LLM.

[0074] It can be seen that in a possible implementation mode, when the security vulnerability processing method based on the large model provided by the present application is applied to the vulnerability management system (such as Figure 4 or Figure 5When the target vulnerability is repaired by a first login account of the vulnerability management system (such as the account used by the business party when logging into the system), and the progress of the target vulnerability is followed up by a second login account of the vulnerability management system (such as the account used by the security party when logging into the system), the questions to be answered can be input through the first login account, so that the questions to be answered can indicate the problems encountered in the repair process, so that the solutions to the problems can be learned with the help of the system in the future, thereby improving the vulnerability repair effect.

[0075] In addition, in order to better improve the response effect, the present application also provides a possible implementation method of the above-mentioned S2. In this method, the S2 may specifically include the following steps 11 and 12.

[0076] Step 11: Analyze the target information to obtain an analysis result, which includes at least one of a first result and a second result. The first result indicates whether the question to be answered belongs to a question that has been answered in the above-mentioned at least one round of dialogue information, and the second result indicates the processing stage of the target vulnerability when the question to be answered appears.

[0077] The analysis result can show the tracking result of the conversation related information (such as conversation status, conversation scene, etc.) presented in the conversation initiated for the target vulnerability up to the current round, so that the analysis result (such as the one generated by Figure 4 The data output by the status tracking module shown in the figure can describe what kind of problem has occurred at what vulnerability processing stage at the current moment, so that the analysis result can not only indicate the occurrence scenario of the problem that needs to be solved currently (such as vulnerability repair scenario, vulnerability retest scenario, etc.), but also indicate whether the problem that needs to be solved currently is related to the problem that has been answered in the past.

[0078] In addition, for the above analysis results, the analysis results may include a first result (such as a conversation state) and / or a second result (such as a conversation scene). The first result refers to the tracking result for the conversation state, so that the first result can indicate whether the question to be answered belongs to the questions that have been answered in at least one round of conversation information (such as the questions raised by the user in the 1st round of conversation to the N-1th round of conversation), so that the first result can indicate whether the question to be answered belongs to the questions that have not been solved after multiple replies, and thus the first result can indicate to a certain extent the impact of the answers to these answered questions on the current problem to be solved (such as the problem to be answered). The second result refers to the tracking result for the conversation scene, so that the second result can indicate the processing stage of the target vulnerability when the problem to be answered appears (such as the moment when the problem to be answered appears in the conversation group), such as the vulnerability repair stage, vulnerability retesting stage, extension application stage, etc., so that the second result can clearly indicate at which stage the problem to be solved appears.

[0079] In addition, the present application does not limit the implementation of the above step 11. For example, it can adopt any method that can analyze the target information, such as a pre-built script with the analysis function, a pre-built rule with the analysis function, a pre-built machine learning model (such as LLM) with the analysis function, or a pre-built rule with the analysis function. Figure 4 The state tracking module shown is implemented.

[0080] Step 12: Based on the above analysis results, determine the current processing status of the target vulnerability.

[0081] It should be noted that this application does not limit the implementation method of the above step 12. For example, it can be specifically as follows: determining the above analysis results as the current processing status of the target vulnerability. For example, in some scenarios, the specific implementation of step 12 can be as follows: determining the current processing status of the target vulnerability based on the above analysis results and the above target information (such as information related to the target vulnerability recorded in the work order information), so that the current processing status can more comprehensively describe the characteristics of the target vulnerability in the current round, such as whether the problem encountered in the current round is a problem that has been solved by trying multiple solutions, what processing stage the target vulnerability is in the current round (such as vulnerability repair stage, vulnerability retest stage, etc.), and the security standards that the target vulnerability needs to follow in the current round.

[0082] Based on the relevant contents of steps 11 to 12 above, it can be known that in some scenarios, for a vulnerability management system, the system determines the current processing status of the target vulnerability by analyzing the target information input in the current round, so that the current processing status can more comprehensively describe the characteristics of the target vulnerability in the current round, thereby making the reply content determined based on the current processing status more accurate, which is conducive to improving the reply effect.

[0083] Research has found that in some scenarios, the questions raised by users may be complex questions, such as "Why can't the webpage be opened? Can I apply for an extension to fix the vulnerability? How to apply for an extension?", making it difficult to answer this question.

[0084] Based on the above research, in order to solve the above problems, the present application provides a possible implementation method of the above S4. In this method, the step 13 can be specifically as follows: in response to the above question to be answered being a compound question, the above target information, the current processing status of the above target vulnerability and the above intention recognition result are processed based on the large model to obtain a question-and-answer knowledge graph. The question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered (such as the sub-question of "Why can't the webpage be opened?", the sub-question of "Can I apply for an extension to fix the vulnerability when the webpage cannot be opened?", the sub-question of "How to apply for an extension?", etc.) and the answer content corresponding to each sub-question, so that the question-and-answer knowledge graph can accurately and completely indicate how to answer the compound question; based on the question-and-answer knowledge graph, the answer content corresponding to the question to be answered is determined, so that the defects caused by the compound question can be overcome to improve the answer effect.

[0085] It should be noted that this application does not limit the implementation method of the above-mentioned question-answer knowledge graph. For example, in some scenarios, the question-answer knowledge graph may include the above-mentioned at least one sub-question and the corresponding answer content of each sub-question. For example, in some scenarios, the question-answer knowledge graph may include the above-mentioned at least one sub-question and the multimodal instructions generated for each sub-question, so that the answer content corresponding to each sub-question can be generated based on the multimodal instructions generated for each sub-question.

[0086] Through research, it is found that in some scenarios, different users encounter similar problems in the process of fixing the same vulnerability. Therefore, in order to improve the response effect, a knowledge base can be built in advance (such as Figure 4The knowledge base shown in the figure) is used to enable the historical cases recorded in the knowledge base (such as examples that can describe the process of solving a problem, etc.) to represent solutions to some problems. Based on this, it can be seen that under one possible implementation method, the answer content corresponding to the above-mentioned questions to be answered can be determined by the large model based on part or all of the content in the pre-built knowledge base (such as historical cases that match the questions to be answered, security standards that match the questions to be answered, etc.). In this way, the solution to the problem can be better determined under the guidance of the historical cases (and / or other content) recorded in the knowledge base.

[0087] It can be seen that in some scenarios, for a vulnerability management system, the system can first parse the intention of the current round based on the historical cases recorded by the knowledge base and the real-time data stream generated during the processing of the target vulnerability, so that the intention can express the needs of the current round; then the system constructs a question-and-answer knowledge graph under the guidance of the historical cases and the intention, so that the question-and-answer knowledge graph can express the sub-problems decomposed from the current problem to be solved and the corresponding answer content of each sub-problem, so that the system can subsequently use the question-and-answer knowledge graph to answer the current problem to be solved through multiple rounds of dialogue. This is conducive to improving the professionalism and feasibility of responses to problems encountered in the vulnerability processing process, thereby helping to improve the response effect.

[0088] Research has found that in some scenarios, the vulnerability handling system may need to answer multiple questions from different sources at the same time. Therefore, in order to better improve the answer effect, the system can automatically schedule according to certain rules (such as Figure 4 Smart Scheduling (as shown) can be used to rationally arrange the response process for these issues, which helps improve resource utilization and vulnerability handling efficiency. For ease of understanding, the following two scenarios are explained.

[0089] Case 1. In some scenarios, such as a scenario where the same system manages multiple vulnerabilities, if the large model-based security vulnerability processing method provided in this application is applied to a vulnerability management system, and the system is used to manage the processing process of multiple vulnerabilities, then the large model-based security vulnerability processing method may at least include the following steps: in response to the difference between the acquisition times of the reply contents corresponding to at least two of the multiple vulnerabilities being less than a preset threshold, it can be determined that the system may need to respond to problems arising in the processing of the at least two vulnerabilities at the same time, so the display timing of the reply contents corresponding to each of the at least two vulnerabilities can be determined based on the level information of each of the at least two vulnerabilities (such as priority information, etc.), the at least two vulnerabilities include the above-mentioned target vulnerability, and the reply contents corresponding to the target vulnerability include the reply contents corresponding to the above-mentioned questions to be answered; for any of the at least two vulnerabilities, in response to the display timing of the reply contents corresponding to the vulnerability, the reply contents corresponding to the vulnerability are displayed, so that automatic scheduling of question replies can be achieved in the scenario of unified management of multiple vulnerabilities, thereby helping to better improve efficiency.

[0090] It should be noted that, for any of the at least two vulnerabilities mentioned above, the response content corresponding to the vulnerability is used to indicate how to solve the latest question raised by the user regarding the vulnerability in the current round; and the response content is determined by the vulnerability management system.

[0091] Scenario 2: In some scenarios, such as when a system simultaneously provides services to multiple clients (e.g., a conversation group and a webpage), if the large-model-based security vulnerability handling method provided in this application is applied to a vulnerability management system, the system is configured to process conversation information (e.g., information such as multiple rounds of conversations triggered by a target vulnerability) sent by multiple clients, where the multiple clients include a client displaying a webpage and a client displaying a conversation group, and the conversation information sent by the client displaying the webpage includes information about at least one round of conversation, or the conversation information sent by the client displaying the conversation group includes information about at least one round of conversation, then the large-model-based security vulnerability handling method may include at least the following steps: In response to a difference between the times at which the system generates reply content based on the conversation information sent by each client being less than a preset threshold, it can be determined that the system may need to respond to questions sent by multiple client terminals simultaneously, and therefore, a corresponding reply timing for each client can be determined based on the descriptive information (e.g., priority) of each client; and for any of the at least two clients, in response to reaching the reply timing corresponding to that client, the reply content generated by the system based on the conversation information sent by that client is displayed. This enables automated scheduling of question responses in a multi-client unified service scenario, thereby further improving efficiency.

[0092] It should be noted that, for any client, the description information of the client can describe the characteristics of the client, and this application does not limit the implementation method of the description information. For example, it may include priority information, and may also include other information, such as the type of the client, the response requirements of the client, and other information.

[0093] Based on the above content of automatic scheduling, it can be known that in some scenarios, the vulnerability management system can be used in certain ways, such as Figure 4 The intelligent scheduling module shown implements the following functions: It integrates some priority information (such as vulnerability priority information, etc.) and uses operations research optimization algorithms to realize the allocation, scheduling, progress tracking and other links of some tasks (such as response tasks, etc.), thereby significantly improving resource utilization and repair efficiency. It should be noted that this application does not limit the implementation method of the intelligent scheduling module. For example, the module can be implemented using task scheduling and process management components based on AI and automation technology.

[0094] In addition, in order to better improve the vulnerability management effect, the present application also provides a possible implementation method of the above-mentioned large model-based security vulnerability processing method. In this way, when the reply content corresponding to the above-mentioned question to be answered is determined by the large model based on part or all of the content in the pre-built knowledge base, the large model-based security vulnerability processing method may also include: in response to at least one information meeting a preset condition, updating the knowledge base based on the at least one information, the at least one information includes the above-mentioned target information, the above-mentioned question to be answered, the current processing status of the above-mentioned target vulnerability, the above-mentioned intention recognition result, the reply content corresponding to the question to be answered, and part or all of the feedback information for the reply content, and the preset condition includes the at least one information The indicated case is different from the historical case recorded in the knowledge base, the case indicated by the at least one information has changed compared with the historical case, the scenario indicated by the at least one information (such as the vulnerability processing stage such as the false alarm confirmation stage) is different from the scenario recorded in the knowledge base, the vulnerability type indicated by the at least one information is different from the vulnerability type recorded in the knowledge base, the vulnerability repair solution indicated by the at least one information has changed compared with the vulnerability repair solution recorded in the knowledge base, and the vulnerability security standard indicated by the at least one information has changed compared with the vulnerability security standard recorded in the knowledge base. In this way, the knowledge base can be updated with the help of the data generated in the current round to improve the richness of the knowledge base, so that the solution determined based on the knowledge base is better.

[0095] It should be noted that, for the answer content corresponding to the above-mentioned question to be answered, the feedback information for the answer content can indicate the user's degree of recognition of the answer content, so that the feedback information can indicate whether the solution described by the answer content can successfully solve the problem. In addition, this application does not limit the implementation method of the feedback information. For example, it can be obtained based on some user operations, such as like operations or dislike operations. For another example, the feedback information can be obtained by analyzing the conversation subsequently triggered by the user.

[0096] Based on the above two paragraphs, it can be seen that in some scenarios, for the knowledge base deployed in the above-mentioned vulnerability management system, the knowledge base is not static, but will be updated as the processing process of the target vulnerability progresses, and the update process has the following characteristics: in the process of implementing multiple rounds of conversations through the system, new scenarios (such as newly emerging processing stages), new knowledge, and new experiences are collected, sorted, and verified in real time to maintain and upgrade the knowledge base, thereby achieving the effect of improving response accuracy, enhancing closed-loop efficiency, and reducing costs. Among them, the conditions that trigger the update may include: new historical cases, new scenarios, new vulnerability types, iterations of repair solutions, changes in security requirements, etc. In addition, the knowledge base can be implemented using a graph database built by constructing a knowledge graph to achieve rapid retrieval and reasoning. In addition, the content recorded in the knowledge base can be determined by double verification through a simulation environment and / or special audits, thereby ensuring the reliability of the knowledge. In addition, for the information generated during the vulnerability handling process (such as the real-time data stream mentioned above), experience can be extracted from the information and converted into standardized knowledge entries and stored in the knowledge base. Historical cases of successful problem solving similar to the information can also be recommended from the knowledge base with the help of similarity matching algorithms. The unstructured multi-round conversations recorded in the information can also be converted into structured knowledge entries and stored in the knowledge base. This is conducive to solving the problem of experience fragmentation in the vulnerability handling process.

[0097] It should be noted that the above-mentioned "simulation environment" is constructed and used before the above-mentioned vulnerability management system or knowledge base goes online, so that the simulation environment can simulate some usage scenarios of the system or the knowledge base, so that the knowledge base can be expanded based on these usage scenarios in the future. The above-mentioned "special review" is used to manually review some content in the knowledge base, such as content expanded to the knowledge base during the use of the system or the knowledge base, or randomly determined question and answer pairs, or frequently occurring questions and their answers, to confirm the accuracy of the content, so that manual corrections can be made when it is determined that the content is wrong (such as the answer to a question is wrong).

[0098] Research has found that in some scenarios, LLM cannot provide solutions to some problems. Therefore, in order to ensure the response experience, manual response can be introduced to the problem.

[0099] Based on the above research, in order to better improve the response effect, the present application also provides a possible implementation method of a security vulnerability processing method based on a large model. In this way, when the security vulnerability processing method based on a large model is applied to a vulnerability management system, the target vulnerability repair process is executed through the first login account of the vulnerability management system, and the processing progress of the target vulnerability is followed up through the second login account of the vulnerability management system, the method may also include the following steps: in response to the inability to obtain the response content corresponding to the question to be answered through the large model, a prompt message is sent to the second login account, the prompt message instructing the second login account to answer the question, and determining the response content corresponding to the question based on the content entered by the second login account for the question. In this way, it is possible to introduce manual responses when the solution to the problem cannot be determined with the help of the LLM, which is conducive to ensuring the response effect.

[0100] Based on the relevant content of the above-mentioned vulnerability management system, it can be known that the system can combine multiple rounds of conversations and machine learning algorithms to analyze the work order information in the current round (such as security vulnerability repair status, etc.), historical conversations, and current problems that need to be solved to identify whether the system is in a dialogue answering scenario or a dialogue refusal scenario in the current round, so that when it is determined that the system is in a dialogue answering scenario in the current round, the system can actively guide the user to quickly solve the problem based on the relevant information in the current round (such as the current status of the vulnerability, etc.), so as to achieve rapid response and reply to questions raised by users, and introduce manual processing when it is impossible to answer with the help of machine learning models.

[0101] In addition, in some scenarios, the above vulnerability management system can be used Figure 4 The vulnerability management system shown in the figure is implemented so that the system includes an input layer, an AI core layer, an execution layer, and an output layer. For ease of understanding, the relevant contents of these layers are introduced below.

[0102] For the above-mentioned input layer, the input data of the input layer includes the above-mentioned target information, and the input layer is at least used to perform data cleaning and integration processing on the target information, such as missing value processing, format standardization, deduplication, noise filtering, data association, data fusion, data enhancement and other processing, so as to realize the conversion of original messy data into high-quality, analyzable structured data.

[0103] For the above-mentioned AI core layer, the input data of the AI ​​core layer includes the output data of the above-mentioned input layer; and the AI ​​core layer includes a state tracking module, an intent recognition module and an automatic response generation module. Among them, the state tracking module is used to analyze the output data of the input layer to obtain an analysis result, so that the target vulnerability can be clearly identified through the analysis in the current scenario (such as the retest phase) and the problems that arise. This is conducive to the real-time or regular collection of online scenario data to ensure that the collected data is complete and accurate, covering the various operations and status information involved in the processing of the vulnerability. The intent recognition module is used to perform intent recognition on the output data of the input layer and the output data of the state tracking module to obtain an intent recognition result, so that the intent recognition result can at least indicate the type of problem. In addition, in some scenarios, the intent recognition module can also be used to extract some information (such as conversation records, new scenarios, etc.) from the input data of the intent recognition module to automatically update the knowledge base. The automatic response generation module is used to process the output data of the input layer (such as work order information, processing stage, etc.), the output data of the status tracking module, and the output data of the intention recognition module through the LLM model (such as constructing a question-and-answer knowledge graph to analyze complex questions into atomic question chains, etc.) to automatically generate response instructions, such as multimodal instructions generated based on the question-and-answer knowledge graph.

[0104] For the above-mentioned execution layer, the input data of the execution layer includes the output data of the above-mentioned AI core layer; and the execution layer includes a dialogue generation module and an intelligent scheduling module. Among them, the dialogue generation module is the core interactive component in the vulnerability management system, so that the natural language dialogue generated by the module can be used to realize the automated communication and collaborative management of the entire vulnerability handling process. In addition, the module can replace the repetitive dialogues (such as urging, repair indicators, system operations, etc.) involved in the vulnerability management solution implemented by manual means to achieve a humanized but more efficient interactive experience. The intelligent scheduling module is a task scheduling and process management component based on AI and automation technology, so that the module can realize the allocation, scheduling, progress tracking and other links of vulnerability repair tasks.

[0105] For the above-mentioned output layer, the input data of the output layer includes the output data of the above-mentioned execution layer; and the output layer includes a dialogue display module, a knowledge base update module and a report generation module. Among them, the dialogue display module can convert the input data of the output layer (such as problem solutions) into understandable and executable dialogue content and display it to the user, so as to drive human-computer collaboration to complete the vulnerability repair closed loop. The knowledge base update module is used to collect, organize and verify new scenarios, knowledge and experience in real time during multiple rounds of conversations, maintain and upgrade the current knowledge base, so as to improve response accuracy, enhance closed-loop efficiency and reduce costs. The report generation module is used to integrate all process data involved in the vulnerability handling process, and present key information (such as the repair process, problems encountered and handling status) in a combined and visual form to provide a basis for subsequent decision-making. It can be used for internal review and optimization, internal and external communication and reporting, and achieve the effect of knowledge and experience accumulation and team improvement.

[0106] It can be seen that for the above vulnerability management system, the following functions can be achieved through the system (such as Figure 5 Functions shown): Daily questions raised by users are automatically answered by the LLM model deployed in the system; the LLM model actively analyzes the status of the current round of work orders to guide users to better execute the vulnerability handling process; when the LLM model cannot answer the questions raised by users, manual intervention is introduced in a certain way to improve the vulnerability management effect while reducing labor costs, so that the labor costs can be used to solve other problems in the future.

[0107] In addition, for the above-mentioned vulnerability management system, the system has the following characteristics: the system is a multi-round conversation-driven vulnerability closed-loop management system, so that the system can realize the deep coupling of multi-round conversation technology and vulnerability management process, and dynamically promote the vulnerability processing closed loop through continuous interaction, and also make the update of the knowledge base involved in the system linked with the AI ​​core layer in real time to form a self-learning closed loop of data collection-knowledge precipitation-strategy optimization; the system adopts a cross-module collaborative decision-making mechanism, so that the AI ​​core layer in the system generates problem solutions by analyzing the data given by the input layer in the system and drives the execution layer in the system to collaborate, so that the execution layer can subsequently feed back to the AI ​​core layer, thus breaking the traditional security capability island and realizing seamless connection and intelligent collaboration of the entire vulnerability management process; based on the historical cases recorded in the knowledge base and the real-time data stream generated in the current round, the system parses the current round requirements through the intent recognition module in the system to generate solutions that meet the requirements, thereby improving the professionalism and executability of vulnerability handling suggestions; the system uses intelligent Scheduling, resource optimization algorithms, and operations research optimization algorithms are used to achieve reasonable task scheduling, which can significantly improve resource utilization and repair efficiency. The knowledge base update module in the system is a knowledge base update task triggered by conditions such as the emergence of new vulnerabilities, repair feedback, and changes in security standards, so as to automatically collect, verify, and store new knowledge in the knowledge base during the vulnerability handling process. Moreover, the knowledge base is a graph database obtained by constructing a knowledge graph to achieve fast retrieval and reasoning. The content recorded in the knowledge base needs to be double-checked by simulation environment and special audit to ensure the reliability of the knowledge. The system adopts a vulnerability management experience precipitation and reuse mechanism, so that the system can extract new experience in real time during the vulnerability handling process, convert it into standardized knowledge entries and store it in the knowledge base. It also enables the system to recommend successful historical cases recorded in the knowledge base based on the similarity matching algorithm to answer questions raised by users. It also enables the system to convert unstructured dialogues that appear in the vulnerability handling process into structured knowledge entries and store them in the knowledge base, solving the problem of experience fragmentation in the vulnerability management process.

[0108] It can be seen that the above-mentioned vulnerability management system has the following advantages: (1) The vulnerability management solution implemented by the system can improve timeliness, specifically: the system can realize automated and intelligent processing of each link in the vulnerability handling process, and can answer questions raised by users 24 hours a day, 7×24 hours, greatly reducing processing time, so that the vulnerability management solution implemented by the system can significantly improve efficiency and reduce the overdue rate of security vulnerabilities compared with the vulnerability management solution implemented manually; (2) The vulnerability management solution implemented by the system can enhance accuracy, specifically: the system uses AI to automatically monitor and analyze the work orders that need to be processed, reduce human misjudgment / omissions, promote processing in a timely manner, and avoid the risks caused by the accumulation of vulnerabilities; (3) The vulnerability management solution implemented by the system can achieve sustainable optimization, specifically: the system continuously optimizes the vulnerability management process through the historical data experience precipitation mechanism, improves the overall network security protection capabilities of the managed objects (such as hardware, software, systems, etc.), and provides strong guarantees for the stable operation of the objects.

[0109] Based on the large model-based security vulnerability processing method provided in the embodiment of the present application, the embodiment of the present application also provides a vulnerability processing device. Figure 6 Explain and illustrate. Figure 6 This is a schematic diagram of the structure of a vulnerability processing device provided in an embodiment of the present application. It should be noted that for the technical details of the vulnerability processing device provided in an embodiment of the present application, please refer to the relevant content of the security vulnerability processing method based on the large model above.

[0110] like Figure 6 As shown, the security vulnerability processing device 600 based on the large model provided in the embodiment of the present application includes:

[0111] An acquisition unit 601 is configured to acquire target information, the target information including ticket information and at least one round of conversation information, the ticket information describing a target vulnerability, the at least one round of conversation information generated in a session associated with the target vulnerability, and the at least one round of conversation information indicating at least unanswered questions associated with the target vulnerability;

[0112] A determining unit 602 is configured to determine a current processing state of the target vulnerability based on the target information;

[0113] An identification unit 603 is configured to perform intent identification processing based on the target information and the current processing state of the target vulnerability to obtain an intent identification result;

[0114] A processing unit 604 is configured to process the target information, the current processing status of the target vulnerability, and the intent recognition result based on the large model to obtain a response content corresponding to the question;

[0115] The display unit 605 is used to display the reply content.

[0116] In one possible implementation, the vulnerability processing device 600 can be implemented using any implementation of the vulnerability processing system provided in this application.

[0117] In one possible implementation, the determination unit 602 is specifically configured to: analyze the target information to obtain an analysis result, the analysis result including at least one of a first result and a second result, the first result indicating whether the question to be answered belongs to a question that has been answered in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability when the question to be answered appears; and determine the current processing status of the target vulnerability based on the analysis result.

[0118] In one possible implementation, the processing unit 604 is specifically used to: in response to the question to be answered being a complex question, process the target information, the analysis result and the intention recognition result based on a large model to obtain a question-and-answer knowledge graph, wherein the question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and the answer content corresponding to each sub-question; and determine the answer content corresponding to the question to be answered based on the question-and-answer knowledge graph.

[0119] In one possible implementation, the reply content is determined by the large model based on part or all of the content in a pre-built knowledge base;

[0120] The vulnerability processing device 600 further includes:

[0121] An updating unit is configured to update the knowledge base in response to at least one information meeting a preset condition, based on the at least one information, wherein the at least one information includes part or all of the target information, the question, the analysis result, the intention recognition result, the reply content, and the feedback information for the reply content, and the preset condition includes that the case indicated by the at least one information is different from the historical case recorded in the knowledge base, the case indicated by the at least one information has changed compared with the historical case, the scenario indicated by the at least one information is different from the scenario recorded in the knowledge base, the vulnerability type indicated by the at least one information is different from the vulnerability type recorded in the knowledge base, the vulnerability repair solution indicated by the at least one information has changed compared with the vulnerability repair solution recorded in the knowledge base, and the vulnerability security standard indicated by the at least one information has changed compared with the vulnerability security standard recorded in the knowledge base.

[0122] In one possible implementation, the vulnerability processing device 600 is used to manage the processing of multiple vulnerabilities;

[0123] The vulnerability processing device 600 further includes:

[0124] a first scheduling unit configured to, in response to a difference between times at which answer contents corresponding to at least two of the plurality of vulnerabilities are obtained being less than a preset threshold, determine, based on level information of each of the at least two vulnerabilities, a display timing of the answer contents corresponding to each of the at least two vulnerabilities, the at least two vulnerabilities including the target vulnerability, the answer contents corresponding to the target vulnerability including the answer contents corresponding to the question to be answered;

[0125] The display unit 605 is specifically configured to: for any vulnerability among the at least two vulnerabilities, in response to reaching a display timing for the response content corresponding to the vulnerability, display the response content corresponding to the vulnerability.

[0126] In one possible implementation, the vulnerability handling device 600 is configured to process conversation information sent by multiple clients, where the multiple clients include clients displaying web pages and clients displaying conversation groups, and the conversation information sent by the clients displaying web pages includes the at least one round of conversation information, or the conversation information sent by the clients displaying conversation groups includes the at least one round of conversation information.

[0127] The vulnerability processing device 600 further includes:

[0128] a second scheduling unit configured to determine, in response to a difference between times when the system generates a reply based on the conversation information sent by each client being less than a preset threshold, a reply timing corresponding to each client based on the description information of each client;

[0129] The display unit 605 is specifically configured to: for any client among the at least two clients, in response to reaching a reply timing corresponding to the client, display reply content generated by the system based on the dialogue information sent by the client.

[0130] In one possible implementation, the repair process of the target vulnerability is executed through the first login account of the vulnerability processing device 600, and the processing progress of the target vulnerability is followed up through the second login account of the vulnerability processing device 600; the question to be answered is input through the first login account; and / or the analysis unit is also used to: in response to the inability to obtain the answer content corresponding to the question through the large model, send a prompt message to the second login account, the prompt message instructing the second login account to answer the question, and determine the answer content corresponding to the question based on the content input by the second login account for the question.

[0131] Based on the relevant content of the above-mentioned vulnerability processing device 600, it can be known that the working principle of the device 600 includes: first obtaining target information, which includes work order information for describing the target vulnerability (such as any security vulnerability), and at least one round of dialogue information generated in the session associated with the target vulnerability (such as the session triggered around the target vulnerability during the processing period of the target vulnerability), so that the at least one round of dialogue information can at least indicate the questions to be answered associated with the target vulnerability (such as the questions input in the current round), so that the at least one round of dialogue information can describe some problems encountered when being in the target vulnerability, such as errors in the vulnerability repair process; then determine the current processing status of the target vulnerability based on the target information, so that the current processing status can indicate the characteristics of the target vulnerability in the current round, such as why subsequent processing cannot be performed on the target vulnerability, and what processing the target vulnerability is currently in. stage (such as vulnerability repair stage, vulnerability testing stage, etc.); then, intent recognition processing is performed based on the target information and the current processing status to obtain an intent recognition result, so that the intent recognition result can indicate what type of problem the question to be answered belongs to (such as defects in the vulnerability repair plan, inability to complete the vulnerability repair on schedule, etc.), so that the intent recognition result can represent the current round of needs; secondly, based on a large model (such as LLM and other models), the target information, the analysis result and the intent recognition result are processed to obtain the corresponding answer content of the question and display it to the questioner, so that the questioner can better understand the solution to the problem through the answer content, so as to continue to execute the processing process for the target vulnerability after solving the problem. In this way, security vulnerabilities can be automatically managed with the help of a large model, thereby effectively overcoming the defects that exist when security vulnerabilities are managed with a large amount of manual processing.

[0132] In addition, an embodiment of the present application also provides an electronic device, which includes a processor and a memory: the memory is used to store instructions or computer programs; the processor is used to execute the instructions or computer programs in the memory, so that the electronic device executes any implementation of the large model-based security vulnerability processing method provided in the embodiment of the present application.

[0133] See also Figure 7 , which shows a schematic structural diagram of an electronic device 700 suitable for implementing the embodiments of the present disclosure. The terminal devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0134] like Figure 7 As shown, the electronic device 700 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 are also stored in the RAM 703. The processing device 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0135] Typically, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 7 The electronic device 700 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0136] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.

[0137] The electronic device provided by the embodiment of the present disclosure and the method provided by the above embodiment belong to the same inventive concept. For technical details not fully described in this embodiment, please refer to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.

[0138] An embodiment of the present application also provides a computer-readable medium, in which instructions or computer programs are stored. When the instructions or computer program are executed on a device, the device executes any implementation of the large model-based security vulnerability processing method provided in the embodiment of the present application.

[0139] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0140] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0141] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0142] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device can perform the method.

[0143] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0144] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0145] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit / module does not, in some cases, limit the unit itself.

[0146] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0147] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0148] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0149] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0150] It should also be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0151] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0152] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security vulnerability processing method based on a large model, characterized in that: The method comprises: Obtaining target information, the target information including work order information and at least one round of dialogue information, the work order information describing a target vulnerability, the at least one round of dialogue information generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least unanswered questions associated with the target vulnerability; Determining a current processing status of the target vulnerability based on the target information; Performing intent recognition processing based on the target information and the current processing status of the target vulnerability to obtain an intent recognition result; Processing the target information, the current processing status of the target vulnerability, and the intent recognition result based on the large model to obtain a response content corresponding to the question; Display the content of the reply.

2. The method according to claim 1, characterized in that Determining a current processing status of the target vulnerability based on the target information includes: Analyzing the target information to obtain an analysis result, the analysis result including at least one of a first result indicating whether the question to be answered is a question that has been answered in the at least one round of dialogue information, and a second result indicating a processing stage of the target vulnerability when the question to be answered appears; According to the analysis result, the current processing status of the target vulnerability is determined.

3. The method according to claim 1, characterized in that The target information, the current processing status of the target vulnerability, and the intention recognition result are processed based on the large model to obtain a response content corresponding to the question, including: In response to the question to be answered being a complex question, the target information, the current processing status of the target vulnerability, and the intent recognition result are processed based on the large model to obtain a question-and-answer knowledge graph, where the question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and an answer content corresponding to each sub-question; Based on the question-answer knowledge graph, the answer content corresponding to the question to be answered is determined.

4. The method according to claim 1, wherein The reply content is determined by the large model based on part or all of the content in the pre-built knowledge base; The method further comprises: In response to at least one information meeting a preset condition, the knowledge base is updated based on the at least one information, wherein the at least one information includes the target information, the problem, the current processing status of the target vulnerability, the intention recognition result, the reply content, and part or all of the feedback information for the reply content. The preset condition includes that the case indicated by the at least one information is different from the historical case recorded in the knowledge base, the case indicated by the at least one information has changed compared with the historical case, the scenario indicated by the at least one information is different from the scenario recorded in the knowledge base, the vulnerability type indicated by the at least one information is different from the vulnerability type recorded in the knowledge base, the vulnerability repair solution indicated by the at least one information has changed compared with the vulnerability repair solution recorded in the knowledge base, and the vulnerability security standard indicated by the at least one information has changed compared with the vulnerability security standard recorded in the knowledge base.

5. The method according to claim 1, wherein The method is applied to a vulnerability management system, which is used to manage the processing of multiple vulnerabilities; Before displaying the reply content, the method further includes: In response to a difference between times at which answer contents corresponding to at least two of the multiple vulnerabilities are obtained being less than a preset threshold, determining, based on level information of each of the at least two vulnerabilities, a display timing for the answer contents corresponding to each of the at least two vulnerabilities, the at least two vulnerabilities including the target vulnerability, the answer contents corresponding to the target vulnerability including the answer content corresponding to the question to be answered; The display of the reply content includes: For any one of the at least two vulnerabilities, in response to reaching a display timing for the response content corresponding to the vulnerability, the response content corresponding to the vulnerability is displayed.

6. The method according to claim 1, characterized in that The method is applied to a vulnerability management system, wherein the system is configured to process conversation information sent by multiple clients, the multiple clients including clients displaying web pages and clients displaying conversation groups, the conversation information sent by the clients displaying web pages including the at least one round of conversation information, or the conversation information sent by the clients displaying conversation groups including the at least one round of conversation information; Before displaying the reply content, the method further includes: In response to a difference between times when the system generates reply content based on the conversation information sent by each client being less than a preset threshold, determining a reply timing corresponding to each client based on the description information of each client; The display of the reply content includes: For any one of the at least two clients, in response to reaching a reply timing corresponding to the client, a reply content generated by the system according to the dialogue information sent by the client is displayed.

7. The method according to any one of claims 1 to 6, characterized in that The method is applied to a vulnerability management system, wherein the repair process of the target vulnerability is executed through a first login account of the vulnerability management system, and the processing progress of the target vulnerability is followed up through a second login account of the vulnerability management system; The question to be answered is input through the first login account; and / or, The method further comprises: In response to the inability to obtain the answer content corresponding to the question through the large model, a prompt message is sent to the second login account, the prompt message instructing the second login account to answer the question, and determining the answer content corresponding to the question based on the content input by the second login account for the question.

8. A security vulnerability processing device based on a large model, characterized in that: include: an acquiring unit, configured to acquire target information, the target information including work order information and at least one round of dialogue information, the work order information describing a target vulnerability, the at least one round of dialogue information generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least unanswered questions associated with the target vulnerability; a determining unit, configured to determine a current processing state of the target vulnerability based on the target information; an identification unit, configured to perform intention identification processing based on the target information and the analysis result to obtain an intention identification result; a processing unit, configured to process the target information, the analysis result, and the intention recognition result based on the large model to obtain a response content corresponding to the question; A display unit is used to display the reply content.

9. An electronic device, characterized in that: The device includes: a processor and a memory; The memory is used to store instructions or computer programs; The processor is configured to execute the instructions or computer program in the memory, so that the electronic device executes the method according to any one of claims 1 to 7.

10. A computer-readable medium, characterized in that The computer-readable medium stores instructions or a computer program, and when the instructions or the computer program are executed on a device, the device is caused to execute the method according to any one of claims 1 to 7.

11. A computer program product, characterized in that The method comprises a computer program carried on a non-transitory computer-readable medium, the computer program comprising a program code for executing the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Security vulnerability management method and system and device

    CN104346571A

  • Work order processing method and device, equipment and storage medium

    CN115248845A

  • Protection method based on Internet of Vehicles product security vulnerability professional library CAVD

    CN116502238A

  • Information processing method and device based on large language model, equipment and storage medium

    CN117521675A

  • Maintenance suggestion generation method and system of automobile fault model based on deep learning

    CN117522372A