Security vulnerability handling methods, devices, equipment, and media based on large models

By using a large-model-based security vulnerability handling method, which utilizes work orders and session information to determine vulnerability status and generate response content, the high cost and low efficiency of manual handling methods are solved, and automated management and rapid response to security vulnerabilities are achieved.

CN120528678BActive Publication Date: 2026-04-03BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing security vulnerability handling processes rely heavily on manual processing, resulting in high costs, low efficiency, high vulnerability remediation delay rates, and a lack of effective and continuous experience accumulation mechanisms, making it difficult to meet the needs for rapid response and closed-loop security vulnerability handling.

Method used

A security vulnerability handling method based on a large model is adopted. By obtaining work order information and session information, the current processing status and intent identification results of the vulnerability are determined. The response content is generated using a large language model, and the security vulnerability handling process is automatically managed.

Benefits of technology

It improves the efficiency and accuracy of security vulnerability handling, reduces costs, realizes automated management of security vulnerabilities, overcomes the shortcomings of manual handling methods, and meets the needs of rapid response and closed-loop handling of security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528678B_ABST
    Figure CN120528678B_ABST
Patent Text Reader

Abstract

This application discloses a security vulnerability handling method, apparatus, device, medium, and product based on a large model in the field of network security technology. The method includes: first, acquiring target information, which includes work order information describing the target vulnerability and at least one round of dialogue information generated in a session associated with the target vulnerability, such that the dialogue information at least indicates a question to be answered associated with the target vulnerability; then, analyzing the target information to obtain analysis results; then, performing intent recognition processing based on the target information and analysis results to obtain intent recognition results; and finally, processing the target information, analysis results, and intent recognition results based on the large model to obtain the answer content corresponding to the question and displaying it to the questioner, so that the questioner can learn about the solution to the question through the answer content. This allows for automatic management of security vulnerabilities using a large model, overcoming the shortcomings of managing security vulnerabilities through extensive manual processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, device, medium, or product for handling security vulnerabilities based on a large model. Background Technology

[0002] A security vulnerability is a flaw in hardware, software, systems, or usage strategies that makes the corresponding deployed devices (such as computers) vulnerable to attacks such as viruses. Therefore, it is crucial to discover and fix security vulnerabilities in a timely manner.

[0003] However, existing security vulnerability handling processes involve a large amount of manual processing (such as repair and management), which has some drawbacks, such as high cost and high vulnerability repair overdue rate. Summary of the Invention

[0004] To address the aforementioned technical problems, this application provides a method, apparatus, device, medium, and product for handling security vulnerabilities based on a large model.

[0005] To achieve the above objectives, the technical solution provided in this application is as follows:

[0006] This application provides a security vulnerability handling method based on a large model. The method includes: acquiring target information, the target information including ticket information and at least one round of dialogue information, the ticket information describing a target vulnerability, the at least one round of dialogue information being generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least one unanswered question associated with the target vulnerability; determining the current processing status of the target vulnerability based on the target information; performing intent recognition processing based on the target information and the current processing status of the target vulnerability to obtain an intent recognition result; processing the target information, the current processing status of the target vulnerability, and the intent recognition result based on a large model to obtain the response content corresponding to the question; and displaying the response content.

[0007] In one possible implementation, determining the current processing status of the target vulnerability based on the target information includes: analyzing the target information to obtain analysis results, the analysis results including at least one of a first result and a second result, the first result indicating whether the question to be answered belongs to a question that has already been answered in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability when the question to be answered appeared; and determining the current processing status of the target vulnerability based on the analysis results.

[0008] In one possible implementation, the step of processing the target information, the analysis results, and the intent recognition results based on a large model to obtain the response content corresponding to the question includes: in response to the question to be answered being a composite question, processing the target information, the analysis results, and the intent recognition results based on a large model to obtain a question-and-answer knowledge graph, wherein the question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and the response content corresponding to each sub-question; and determining the response content corresponding to the question to be answered based on the question-and-answer knowledge graph.

[0009] In one possible implementation, the response content is determined by the large model based on some or all of the content in a pre-built knowledge base; the method further includes: in response to at least one piece of information reaching a preset condition, updating the knowledge base based on the at least one piece of information, wherein the at least one piece of information includes some or all of the target information, the question, the response content, and feedback information regarding the response content, and the preset condition includes: the case indicated by the at least one piece of information is different from historical cases recorded in the knowledge base; the case indicated by the at least one piece of information has changed compared to historical cases; the scenario indicated by the at least one piece of information is different from the scenario recorded in the knowledge base; the vulnerability type indicated by the at least one piece of information is different from the vulnerability type recorded in the knowledge base; the vulnerability remediation scheme indicated by the at least one piece of information has changed compared to the vulnerability remediation scheme recorded in the knowledge base; and the vulnerability security standard indicated by the at least one piece of information has changed compared to the vulnerability security standard recorded in the knowledge base.

[0010] In one possible implementation, the method is applied to a vulnerability management system for managing the handling of multiple vulnerabilities. Before displaying the response content, the method further includes: in response to a difference between the acquisition times of response content corresponding to at least two of the multiple vulnerabilities being less than a preset threshold, determining the timing for displaying the response content corresponding to each of the at least two vulnerabilities based on the vulnerability level information of each of the at least two vulnerabilities, wherein the at least two vulnerabilities include the target vulnerability, and the response content corresponding to the target vulnerability includes the response content corresponding to the question to be answered; displaying the response content includes: for any one of the at least two vulnerabilities, in response to reaching the timing for displaying the response content corresponding to that vulnerability, displaying the response content corresponding to that vulnerability.

[0011] In one possible implementation, the method is applied to a vulnerability management system, which processes dialogue information sent by multiple clients, including clients displaying web pages and clients displaying session groups. The dialogue information sent by the clients displaying web pages includes at least one round of dialogue information, or the dialogue information sent by the clients displaying session groups includes at least one round of dialogue information. Before displaying the response content, the method further includes: in response to a difference between the times at which the system generates response content based on the dialogue information sent by each client being less than a preset threshold, determining the response timing corresponding to each client based on the description information of each client; displaying the response content includes: for any one of the at least two clients, in response to reaching the response timing corresponding to that client, displaying the response content generated by the system based on the dialogue information sent by that client.

[0012] In one possible implementation, the method is applied to a vulnerability management system, wherein the remediation process of the target vulnerability is executed through a first login account of the vulnerability management system, and the processing progress of the target vulnerability is followed through a second login account of the vulnerability management system; the question to be answered is input through the first login account; and / or, the method further includes: in response to the inability to obtain the answer content corresponding to the question through the large model, sending a prompt message to the second login account, the prompt message indicating that the second login account should answer the question, and determining the answer content corresponding to the question based on the content input by the second login account for the question.

[0013] This application provides a security vulnerability processing device based on a large model, comprising: an acquisition unit for acquiring target information, the target information including work order information and at least one round of dialogue information, the work order information describing a target vulnerability, the at least one round of dialogue information being generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least one unanswered question associated with the target vulnerability; an analysis unit for analyzing the target information to obtain analysis results, the analysis results including a first result and / or a second result, the first result indicating whether the unanswered question belongs to a previously answered question in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability at the time the unanswered question appears; an identification unit for performing intent identification processing based on the target information and the analysis results to obtain intent identification results; a processing unit for processing the target information, the analysis results, and the intent identification results based on the large model to obtain the response content corresponding to the question; and a display unit for displaying the response content.

[0014] This application provides an electronic device, the device comprising: a processor and a memory; the memory for storing instructions or computer programs; the processor for executing the instructions or computer programs in the memory, so that the electronic device performs the security vulnerability handling method based on a large model provided in this application.

[0015] This application provides a computer-readable medium storing instructions or computer programs that, when executed on a device, cause the device to perform the large-model-based security vulnerability handling method provided in this application.

[0016] This application provides a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for executing the large-model-based security vulnerability handling method provided in this application.

[0017] Compared with related technologies, this application has at least the following advantages:

[0018] In the technical solution provided in this application, target information is first obtained. This target information includes work order information describing a target vulnerability (such as any security vulnerability) and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing of the target vulnerability). This at least one round of dialogue information is designed to indicate at least the unanswered questions associated with the target vulnerability (such as the question entered in the current round), thereby enabling the at least one round of dialogue information to describe some problems encountered when dealing with the target vulnerability, such as errors that occur during the vulnerability remediation process. Then, based on the target information, the current processing status of the target vulnerability is determined, so that... The current processing status indicates the characteristics of the target vulnerability in the current round, such as the reasons why subsequent processing cannot be performed on the target vulnerability, and the current processing stage of the target vulnerability (e.g., vulnerability remediation stage, vulnerability testing stage, etc.). Then, based on the target information and the current processing status, intent recognition processing is performed to obtain intent recognition results, so that the intent recognition results can indicate the type of question to be answered (e.g., the vulnerability remediation solution is flawed, the vulnerability remediation cannot be completed on schedule, etc.), thus enabling the intent recognition results to represent the requirements in the current round. Secondly, based on a large model, such as a Large Language Model (LLM), the target information, the current processing status, and the intent recognition results are processed to obtain the corresponding answer content for the question, which is then displayed to the questioner. This allows the questioner to better understand the solution to the question through the answer content, so that the processing process for the target vulnerability can continue after the question is resolved. In this way, security vulnerabilities can be managed automatically with the help of a large model, thereby effectively overcoming the shortcomings of managing security vulnerabilities with a large amount of manual processing. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A schematic diagram illustrating a vulnerability management process implemented using extensive manual processing, as provided in this application embodiment;

[0021] Figure 2 A schematic diagram illustrating a manual vulnerability management process provided in an embodiment of this application;

[0022] Figure 3A flowchart illustrating a security vulnerability handling method based on a large model, provided in an embodiment of this application;

[0023] Figure 4 This application provides a schematic diagram of the structure of a vulnerability management system.

[0024] Figure 5 A schematic diagram of a vulnerability management system provided in an embodiment of this application;

[0025] Figure 6 A schematic diagram of a security vulnerability processing device based on a large model provided in this application embodiment;

[0026] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0027] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0028] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly inform the user that the requested operation will require obtaining and using the user's information, thereby enabling the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of the technical solution disclosed herein based on the prompt message.

[0029] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0030] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0031] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0032] Research has found that when security vulnerabilities are managed through extensive manual processing, this management method (such as...) Figure 1 The management method shown involves a large amount of manual processing, making it heavily reliant on human intervention. This results in at least the drawbacks described in ①-④ below. It should be noted that in this… Figure 1 In this context, "security" is short for "security party," which is responsible for developing and distributing remediation plans for security vulnerabilities and for tracking the progress of vulnerability resolution. "Business" is short for "business party," which is responsible for implementing the remediation plans for security vulnerabilities.

[0033] ①Because manual processes are relatively inefficient, the processing time for some manual processes (such as vulnerability patching) is relatively long. This may lead to situations where vulnerability patching is missed, not patched in a timely manner, or intervention is too late, thus affecting the effectiveness of security vulnerability management.

[0034] ② When security vulnerabilities are managed through extensive manual processing, the process of handling the vulnerability requires manual classification, allocation, communication and coordination of remediation plans, which is time-consuming and labor-intensive, and can easily lead to omissions of tasks and unclear responsibilities, resulting in a higher remediation rate.

[0035] ③ Because when relying on a large amount of manual processing to follow up on the handling of security vulnerabilities, there is a lack of an effective and continuous experience accumulation mechanism, making it difficult to form an efficient closed-loop management of vulnerabilities.

[0036] ④ With the increasing complexity of attack methods and the rise in human resource costs, vulnerability management solutions that rely heavily on manual processing not only present a significant increase in vulnerability management costs, but also struggle to meet the vulnerability management needs of some application scenarios, such as the need for rapid response to security vulnerabilities and closed-loop processing of security vulnerabilities.

[0037] The study also found that, in order to ensure the smooth execution of the security vulnerability remediation process, reduce the occurrence of overdue vulnerability remediation, and improve the vulnerability remediation rate, relevant personnel (such as...) can be responsible for this process. Figure 1 or Figure 2 The "security" mentioned refers to personnel who answer questions regarding various issues that arise during the vulnerability remediation process (such as those related to...). Figure 1 The document outlines several key points, including: answering questions, providing correct guidance (such as proactively confirming vulnerability remediation plans), and timely reminders (such as deadline reminders). It is evident that understanding and resolving security vulnerabilities is a crucial factor in vulnerability management. However, when relying heavily on manual methods to follow up on the processing of security vulnerabilities (such as remediation processes), the problems described in (1)-(4) below arise.

[0038] (1) When the process of handling security vulnerabilities is followed up by a large amount of manual processing, there will be problems of low efficiency and high cost. The reason for this problem is as follows: When the process of handling vulnerabilities is followed up by a large amount of manual processing, each vulnerability requires about 5 communications from different groups, so that more than 60% of these groups' time is spent on progress confirmation and follow-up.

[0039] (2) When the work order system used to follow up on the handling process of security vulnerabilities by relying on a lot of manual processing methods only supports one-way notification, cannot actively initiate sessions, and cannot actively collect and summarize information related to vulnerability handling (such as information related to vulnerability remediation) to promote and guide.

[0040] (3) When relying heavily on manual processing to follow up on the handling of security vulnerabilities, the following challenges arise in terms of working hours: If a 24 / 7 work schedule is not implemented, the workload of relevant personnel (such as those from...) will be affected. Figure 1 or Figure 2 The "security" personnel (as indicated) cannot be on duty and answer questions at all times, thus affecting the progress of vulnerability remediation; however, if a 24 / 7 shift is implemented, it will increase the additional manpower costs significantly, thereby leading to a substantial increase in vulnerability management costs.

[0041] (4) When relying on extensive manual processing to follow up on the handling of security vulnerabilities, a repetitive response dilemma arises. The reasons for this dilemma are as follows: For any given security vulnerability, the vulnerability remediation plan is relatively fixed, and the operations involved in handling the vulnerability (such as remediation, retesting, and extensions) are identical, making it difficult for relevant personnel (such as those from…) to… Figure 1 or Figure 2 The "safety" mentioned refers to personnel who have to answer the same questions repeatedly every day, resulting in low efficiency and high labor costs.

[0042] Based on the above research, in order to overcome the above problems, this application provides a security vulnerability processing method based on a large model. The method includes: first, acquiring target information, which includes work order information describing a target vulnerability (such as any security vulnerability), and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during its processing), so that the at least one round of dialogue information can at least indicate unanswered questions associated with the target vulnerability (such as questions entered in the current round), thereby enabling the at least one round of dialogue information to describe some problems encountered when dealing with the target vulnerability, such as errors occurring during the vulnerability remediation process; then, determining the current processing state of the target vulnerability based on the target information, so that the current processing state can represent the characteristics of the target vulnerability in the current round, such as the reasons why subsequent processing cannot be performed on the target vulnerability, and the current status of the target vulnerability. The process involves identifying the target information and the current processing status. First, it determines the processing stage (e.g., vulnerability remediation, vulnerability testing). Second, it uses a large model (e.g., LLM) to process the target information, analysis results, and intent identification results, thus indicating the type of problem (e.g., a flawed vulnerability remediation solution, or inability to complete vulnerability remediation on schedule). This allows the target to represent the current requirements. Third, it uses a large model (e.g., LLM) to process the target information, analysis results, and intent identification results, providing a response to the problem and displaying it to the questioner. This allows the questioner to better understand the solution and continue processing the vulnerability after resolving it. This automatic management of security vulnerabilities using a large model effectively overcomes the shortcomings of relying on extensive manual processing.

[0043] Furthermore, this application does not limit the executing entity of the security vulnerability handling method based on large models. For example, the method can be applied to a terminal device or a server. Alternatively, the method can be implemented through data interaction between the terminal device and the server. The terminal device can be a smartphone, computer, personal digital assistant (PDA), tablet computer, etc. The server can be a standalone server, a cluster server, or a cloud server.

[0044] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0045] To better understand the technical solution provided in this application, the security vulnerability handling method based on a large model provided in this application will be explained below with reference to some accompanying figures. For example... Figure 3 As shown, the security vulnerability handling method based on a large model provided in this application includes S1-S5 below.

[0046] S1: Obtain target information, which includes ticket information and at least one round of dialogue information, the ticket information describing the target vulnerability, the at least one round of dialogue information generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least one unanswered question associated with the target vulnerability.

[0047] Among them, target information refers to information that needs to be referenced in the current round of response and may affect the final response result, such as... Figure 4 The input data for the input layer is shown.

[0048] In addition, the aforementioned target information may include at least work order information (such as...) Figure 4 The work order information shown) and at least one round of dialogue information (such as...) Figure 4 (The dialogue information shown).

[0049] Regarding the aforementioned work order information, this work order information describes the target vulnerability so that it can represent the characteristics of the target vulnerability in the current round; moreover, this application does not limit the implementation method of the work order information. For example, the work order information may include at least some fixed static information, such as the type of the target vulnerability, the danger level of the target vulnerability, and the attributes of the target vulnerability. Alternatively, the work order information may also include some dynamic information that may change, such as the remediation plan for the target vulnerability, and the executor of the remediation process (e.g., the...). Figure 1 The information includes: the person in charge of the work order; the current processing stage of the target vulnerability (such as repair, retesting, extension, exemption, etc.); the current repair status of the target vulnerability (such as repairing, paused repair, resumed repair, repair at which stage, etc.); and the problems encountered and their solutions during the handling of the target vulnerability.

[0050] Therefore, in one possible implementation, the aforementioned work order information can be updated based on data generated in real time during the handling of the target vulnerability (such as vulnerability remediation status, vulnerability handling stage, etc.), so that the work order information can accurately describe the characteristics of the target vulnerability in the current round. It should be noted that this application does not limit the initial value of the work order information; for example, the initial value can be determined by relevant personnel distributing the work order for the target vulnerability (e.g., ...). Figure 1 or Figure 2 The vulnerability distribution is implemented based on the work order information set during the vulnerability distribution process.

[0051] For the aforementioned at least one round of dialogue information, this at least one round of dialogue information is generated in a session associated with the aforementioned target vulnerability (such as a session triggered around the target vulnerability during the handling of the target vulnerability), so that the at least one round of dialogue information can at least indicate an unanswered question associated with the target vulnerability, such as the most recently raised question by the user regarding the target vulnerability in the current round. It should be noted that "around" means that the discussion revolves around the target vulnerability.

[0052] Therefore, if the current round refers to the first round of dialogue triggered for the target vulnerability, then the "at least one round of dialogue information" can include the user (e.g., by...). Figure 1 or Figure 2 The "business" mentioned refers to the first question raised by the personnel regarding the target vulnerability; however, if the current round refers to the Nth round of dialogue triggered for the target vulnerability, where N is a positive integer and N≥2, then the "at least one round of dialogue information" can include the first to N-1 rounds of dialogue (such as some historical questions and their corresponding answers), as well as the latest question raised by the user regarding the target vulnerability in the Nth round of dialogue. This ensures that the "at least one round of dialogue information" can accurately and completely represent the problems encountered by the user in the process of handling the target vulnerability (such as the vulnerability remediation process implemented by executing the remediation plan).

[0053] Research has found that in some scenarios, to better improve the effectiveness of security vulnerability handling, relevant personnel can pre-define standard operating procedures (SOPs) for the vulnerability, such as security vulnerability management documents, frequently asked questions and answers (FQA) documents, etc. Figure 5 The technical documents shown Figure 5 The security specification document shown Figure 5The document includes daily conversation logs and other materials to accurately and comprehensively indicate the security standards to be followed in handling the vulnerability, thereby enabling the document to represent the constraints set for the vulnerability.

[0054] Based on the above research, in one possible implementation, the target information may include not only work order information and at least one round of dialogue information, but also document information (such as SOP documents or...). Figure 4 The document information shown is used to more comprehensively describe the characteristics of the target vulnerability in the current round, such as vulnerability remediation status, historical dialogues, current issues, security standards, etc., so that the response content determined based on the target information is more accurate.

[0055] It should be noted that the aforementioned document information indicates the constraints (such as security standards) that need to be followed during the handling of the target vulnerability; moreover, this application does not limit the implementation method of the document information. For example, the document information may refer to some reference documents provided in advance by relevant personnel for the target vulnerability. Furthermore, in some scenarios, such as when security standards may change, the document information can be updated based on document adjustment information provided by relevant personnel during the handling of the target vulnerability, so that the document information can accurately represent the constraints that the target vulnerability needs to meet in the current round.

[0056] S2: Determine the current processing status of the target vulnerability based on the target information.

[0057] The current processing status of the target vulnerability can indicate the characteristics of the target vulnerability in the current round, such as the problems encountered that can hinder the subsequent processing of the target vulnerability, and the processing stage of the target vulnerability (such as the vulnerability repair stage, vulnerability retesting stage, etc.).

[0058] Furthermore, this application does not limit the implementation of the above-mentioned S2. For example, it can be implemented using any method that can analyze the current processing status of the target vulnerability from the target information, such as a pre-built script with the aforementioned functions, a pre-built rule with the aforementioned functions, or a pre-built machine learning model (such as LLM) with the aforementioned functions.

[0059] S3: Based on the target information and the current processing status of the target vulnerability, perform intent recognition processing to obtain the intent recognition result.

[0060] Among them, the intent recognition result (such as by Figure 4The data output by the intent recognition module shown can indicate the type of question to be answered, such as a defective vulnerability remediation plan or the inability to complete vulnerability remediation on schedule. This allows the intent recognition result to accurately represent the current requirements, such as which problem arises at which stage.

[0061] Furthermore, this application does not limit the implementation of S3 described above. For example, it can employ any method capable of achieving intent recognition, such as a pre-built script with the aforementioned functions, a pre-built rule with the aforementioned functions, a pre-built machine learning model with the aforementioned functions, or a method derived from... Figure 4 The intent recognition module shown is implemented as described. Furthermore, this application does not limit the implementation method of this machine learning model; for example, it can be implemented using any Natural Language Processing (NLP) model, such as LLM.

[0062] S4: Based on the large model, process the target information, the current processing status of the target vulnerability, and the intent recognition results to obtain the response content corresponding to the question to be answered.

[0063] The large model is used to analyze the answers based on the input data of the model (such as the target information, the current processing status of the target vulnerability, and the intent recognition results, etc.). Moreover, this application does not limit the implementation of the large model. For example, the large model may include one or more of the following: large language model, visual large model, speech large model, multimodal large model, etc.

[0064] The response to a pending question refers to the answer determined for that question in the current round, so that the response can indicate how to resolve the question in order to continue the subsequent process (such as the remediation process) for the target vulnerability.

[0065] Furthermore, this application does not limit the implementation of the above-mentioned S4. For example, it can specifically be: inputting the target information, the current processing status of the target vulnerability and the intent recognition result into the large model, so that the large model can perform answer analysis based on the target information, the current processing status of the target vulnerability and the intent recognition result, and obtain and output the answer content corresponding to the above-mentioned question to be answered.

[0066] For example, in some scenarios, such as when a robot answers questions, the aforementioned S4 may specifically include: first, the large model generates multimodal instructions (such as by...) based on the aforementioned target information, the current processing status of the aforementioned target vulnerability, and the aforementioned intent recognition results. Figure 4The data output by the automatic response generation module (as shown) enables the multimodal instruction to represent the multimodal data (such as images, videos, text, etc.) required when answering questions; then, robot dialogue is generated based on the multimodal instruction (e.g., through...). Figure 4 The dialogue generation module shown implements dialogue generation to obtain the response content corresponding to the above-mentioned question to be answered, so that the response content can express the solution to the question in natural language.

[0067] It should be noted that, for Figure 4 The dialogue generation module shown is an interactive component in the vulnerability management system. It enables automated communication and collaborative management of the entire vulnerability handling process through natural language dialogues generated by this module. Furthermore, this module can replace repetitive dialogues (such as reminders, remediation metrics, and system operations) involved in manually implemented vulnerability management solutions, achieving a more human-like yet efficient interactive experience.

[0068] S5: Display the answers to the questions that are yet to be answered.

[0069] It should be noted that this application does not limit the implementation method of S5. For example, S5 can be implemented by means of... Figure 4 The dialogue shown demonstrates how this module is implemented.

[0070] For example, if the above-mentioned "question to be answered" is raised by the user through a chat group, then S5 can specifically be: according to the rendering and display algorithm corresponding to the chat group, render and display the answer content corresponding to the question to be answered, so as to ensure that the answer content can be displayed in the chat group, so that the user can continue to initiate other conversations through the chat group.

[0071] For example, if the above-mentioned "question to be answered" is raised by the user through a webpage, then S5 can specifically be: according to the rendering and display algorithm corresponding to the webpage, render and display the answer content corresponding to the question to be answered, so as to ensure that the answer content can be displayed on the webpage, so that the user can continue to initiate other conversations through the webpage.

[0072] Based on the above S1 to S5, the automatic management scheme for security vulnerabilities provided in this application includes: first, acquiring target information, which includes work order information describing the target vulnerability (such as any security vulnerability) and at least one round of dialogue information generated in the session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing of the target vulnerability), so that the at least one round of dialogue information can at least indicate the unanswered questions associated with the target vulnerability (such as the question entered in the current round), thereby enabling the at least one round of dialogue information to describe some problems encountered when the target vulnerability is present, such as errors in the vulnerability repair process; then, determining the current processing status of the target vulnerability based on the target information, so that the current processing status can represent the characteristics of the target vulnerability in the current round, such as the reasons why subsequent processing cannot be performed on the target vulnerability, and the current status of the target vulnerability. The process involves several stages: first, the target information and the current processing status are processed to obtain an intent recognition result. This result indicates the type of problem (e.g., a flawed vulnerability remediation plan or failure to complete vulnerability remediation on schedule). This allows the intent recognition result to represent the current requirements. Second, a large model (e.g., an LLM model) is used to process the target information, the analysis result, and the intent recognition result to obtain the corresponding response, which is then presented to the problem's questioner. This allows the questioner to better understand the solution to the problem and continue processing the vulnerability after resolving it. This approach, using a large model, automatically manages security vulnerabilities, effectively overcoming the shortcomings of relying on extensive manual processing.

[0073] Furthermore, in some scenarios, the security vulnerability handling method based on large models provided in this application can be applied to vulnerability management systems, such as... Figure 4 or Figure 5 The vulnerability management system shown is designed to enable intelligent management of security vulnerabilities using artificial intelligence (AI) techniques, such as LLM.

[0074] As can be seen, in one possible implementation, when the security vulnerability handling method based on a large model provided in this application is applied to a vulnerability management system (such as...) Figure 4 or Figure 5The vulnerability management system shown can be used to perform the remediation process of the target vulnerability through the first login account of the vulnerability management system (such as the account used by the aforementioned business party when logging into the system), and to follow up on the processing progress of the target vulnerability through the second login account of the vulnerability management system (such as the account used by the aforementioned security party when logging into the system). The question to be answered can be entered through the first login account so that the question to be answered can indicate the problem encountered in the remediation process, so that the solution to the problem can be obtained through the system in the future, thereby improving the vulnerability remediation effect.

[0075] In addition, in order to better improve the response effect, this application also provides a possible implementation of the above-mentioned S2, in which S2 may specifically include steps 11-12 below.

[0076] Step 11: Analyze the target information to obtain the analysis results. The analysis results include at least one of the first result and the second result. The first result indicates whether the question to be answered belongs to the questions that have been answered in the above-mentioned at least one round of dialogue information. The second result indicates the processing stage of the target vulnerability when the question to be answered appears.

[0077] The analysis results can represent the tracking results of dialogue-related information (such as dialogue state, dialogue scenario, etc.) presented in the sessions initiated against the target vulnerability up to the current round, so that the analysis results (such as those from...) can be used to... Figure 4 The data output by the status tracking module shown can describe what kind of problem occurred at what stage of vulnerability handling at the current moment. Thus, the analysis results can not only indicate the scenario in which the problem to be solved now occurs (such as vulnerability repair scenario, vulnerability retest scenario, etc.), but also indicate whether the problem to be solved now is related to the problems that have been answered in the past.

[0078] Furthermore, the analysis results described above can include a first result (e.g., dialogue state) and / or a second result (e.g., dialogue scenario). The first result refers to the tracking results for the dialogue state, enabling it to indicate whether the question to be answered belongs to a previously answered question present in at least one round of dialogue information (e.g., a question raised by the user in rounds 1 to N-1 of the dialogue). This allows the first result to indicate whether the question to be answered is one that remains unresolved despite multiple responses, and further allows the first result to indicate, to some extent, the impact of the responses to these previously answered questions on the current problem that needs to be solved (e.g., the question to be answered). The second result refers to the tracking results for the dialogue scenario, enabling it to indicate the processing stage of the target vulnerability when the question to be answered appears (e.g., the moment the question to be answered appears in the conversation group), such as the vulnerability remediation stage, vulnerability retesting stage, extension application stage, etc., thus allowing the second result to clearly indicate at what stage the current problem that needs to be solved occurred.

[0079] Furthermore, this application does not limit the implementation of step 11 above. For example, it can employ any method capable of analyzing target information, such as a pre-built script with the analysis function, a pre-built rule with the analysis function, a pre-built machine learning model (such as LLM) with the analysis function, or a method provided by [other methods]. Figure 4 The status tracking module shown is implemented.

[0080] Step 12: Based on the above analysis results, determine the current processing status of the target vulnerability.

[0081] It should be noted that this application does not limit the implementation of step 12 above. For example, it can specifically be: determining the analysis results as the current processing status of the target vulnerability. Alternatively, in some scenarios, step 12 can specifically be: determining the current processing status of the target vulnerability based on the analysis results and the target information (such as information related to the target vulnerability recorded in the work order information), so that the current processing status can more comprehensively describe the characteristics of the target vulnerability in the current round, such as whether the problem encountered in the current round is a problem that has been solved by trying multiple solutions, what processing stage the target vulnerability is in in the current round (such as the vulnerability repair stage, vulnerability retesting stage, etc.), and the security standards that the target vulnerability needs to follow in the current round.

[0082] Based on the relevant content of steps 11 to 12 above, it can be seen that in some scenarios, for the vulnerability management system, the system determines the current processing status of the target vulnerability by analyzing the target information input in the current round, so that the current processing status can more comprehensively describe the characteristics of the target vulnerability in the current round, thereby making the response content determined based on the current processing status more accurate, which is conducive to improving the response effect.

[0083] Research has found that in some scenarios, users may ask complex questions, such as "Why can't I open the webpage? Can I apply for an extension to fix the vulnerability? How do I apply for an extension?" This makes answering the question a challenge.

[0084] Based on the above research, in order to solve the above problems, this application provides a possible implementation of the above S4. In this implementation, step 13 can specifically be: in response to the question to be answered being a composite question, the target information, the current processing status of the target vulnerability, and the intent recognition result are processed based on the large model to obtain a question-and-answer knowledge graph. The question-and-answer knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered (such as the sub-question "Why can't I open the webpage?", the sub-question "Can I apply for an extension to fix the vulnerability when the webpage cannot be opened?", the sub-question "How do I apply for an extension?", etc.) and the corresponding answer content for each sub-question, so that the question-and-answer knowledge graph can accurately and completely represent how to answer the composite question; based on the question-and-answer knowledge graph, the answer content corresponding to the question to be answered is determined, thus overcoming the defects caused by the composite question and improving the answering effect.

[0085] It should be noted that this application does not limit the implementation method of the above-mentioned question-and-answer knowledge graph. For example, in some scenarios, the question-and-answer knowledge graph may include at least one sub-question and the corresponding answer content for each sub-question. Furthermore, in some scenarios, the question-and-answer knowledge graph may include at least one sub-question and multimodal instructions generated for each sub-question, so that the answer content for each sub-question can be generated subsequently based on the multimodal instructions generated for each sub-question.

[0086] Research has revealed that in some scenarios, different users encounter largely similar problems while patching the same vulnerability. Therefore, to improve response effectiveness, a knowledge base (such as...) can be pre-built. Figure 4The knowledge base shown is used to represent solutions to some problems by recording historical cases (such as examples that describe the process of solving a problem). Based on this, in one possible implementation, the answer to the question can be determined by a large model based on some or all of the content in a pre-built knowledge base (such as historical cases matching the question, security standards matching the question), thus enabling a better determination of the solution to the problem under the guidance of the historical cases (and / or other content) recorded in the knowledge base.

[0087] It is evident that, in some scenarios, for vulnerability management systems, the system can first parse the current round's intent based on historical cases recorded in the knowledge base and real-time data streams generated during the handling of the target vulnerability, so that the intent can represent the current round's requirements. Then, guided by the historical cases and the intent, the system constructs a question-and-answer knowledge graph, so that the question-and-answer knowledge graph can represent the sub-questions decomposed from the current problem to be solved and the corresponding answers to each sub-question. This allows the system to subsequently use the question-and-answer knowledge graph to answer the current problem through multi-turn dialogue. This helps improve the professionalism and feasibility of the answers to the problems encountered in the vulnerability handling process, thereby improving the answering effect.

[0088] Research has found that in some scenarios, vulnerability handling systems may need to respond to multiple questions from different sources simultaneously. Therefore, to improve response efficiency, the system can be automated to schedule responses according to certain rules (such as...). Figure 4 The intelligent scheduling shown above optimizes the response process for these issues, thereby improving resource utilization and vulnerability handling efficiency. For clarity, two scenarios are explained below.

[0089] Scenario 1: In some scenarios, such as when a single system manages multiple vulnerabilities, if the security vulnerability handling method based on a large model provided in this application is applied to a vulnerability management system, and this system is used to manage the handling process of multiple vulnerabilities, then the security vulnerability handling method based on a large model may include at least the following steps: In response to the difference between the acquisition times of the response content corresponding to at least two of the multiple vulnerabilities being less than a preset threshold, it can be determined that the system may need to simultaneously respond to issues arising during the handling process of the at least two vulnerabilities. Therefore, based on the level information (such as priority) of each of the at least two vulnerabilities, the timing for displaying the response content corresponding to each of the at least two vulnerabilities can be determined. The at least two vulnerabilities include the aforementioned target vulnerability, and the response content corresponding to the target vulnerability includes the response content corresponding to the aforementioned unanswered questions. For any of the at least two vulnerabilities, in response to reaching the timing for displaying the response content corresponding to that vulnerability, the response content corresponding to that vulnerability is displayed. This enables automated scheduling of question responses in a scenario of unified management of multiple vulnerabilities, thereby improving efficiency.

[0090] It should be noted that, for any of the above at least two vulnerabilities, the corresponding response content is used to indicate how to resolve the latest issue raised by the user regarding that vulnerability in the current round; and the response content is determined by the vulnerability management system.

[0091] Scenario 2: In some scenarios, such as when a single system provides services to multiple clients simultaneously (e.g., session group clients and web page clients), if the security vulnerability handling method based on the large model provided in this application is applied to a vulnerability management system, and this system is used to process dialogue information sent by multiple clients (e.g., multi-round dialogue information triggered for a target vulnerability), these multiple clients include clients displaying web pages and clients displaying session groups. The dialogue information sent by the client displaying web pages includes at least one round of dialogue information, or the dialogue information sent by the client displaying session groups includes at least one round of dialogue information. Then, the security vulnerability handling method based on the large model can include at least the following steps: In response to the difference between the times when the system generates response content based on the dialogue information sent by each client being less than a preset threshold, it can be determined that the system may need to respond to questions sent by multiple clients simultaneously. Therefore, the response timing for each client can be determined based on the description information (e.g., priority information) of each client; For any one of at least two clients, in response to reaching the response timing corresponding to that client, the response content generated by the system based on the dialogue information sent by that client is displayed. This enables automated scheduling of question responses in a multi-client unified service scenario, thereby improving efficiency.

[0092] It should be noted that, for any client, the description information of the client can describe the characteristics of the client, and this application does not limit the implementation of the description information. For example, it may include priority information, or other information, such as the type of the client, the response requirements of the client, etc.

[0093] Based on the above content regarding automated scheduling, it can be seen that in some scenarios, the aforementioned vulnerability management system can, in certain ways, such as... Figure 4 The intelligent scheduling module shown implements the following functions: by integrating priority information (such as vulnerability priority information) and leveraging operations research optimization algorithms, it achieves the allocation, scheduling, and progress tracking of tasks (such as response tasks), thereby significantly improving resource utilization and repair efficiency. It should be noted that this application does not limit the implementation method of this intelligent scheduling module; for example, the module can be implemented using task scheduling and process management components based on AI and automation technologies.

[0094] Furthermore, to better improve vulnerability management effectiveness, this application also provides a possible implementation of the aforementioned security vulnerability handling method based on a large model. In this implementation, when the response content corresponding to the question to be answered is determined by the large model based on part or all of the content in a pre-built knowledge base, the security vulnerability handling method based on the large model may further include: updating the knowledge base based on the at least one piece of information in response to at least one piece of information reaching a preset condition. The at least one piece of information includes the target information, the question to be answered, the current processing status of the target vulnerability, the intent recognition result, the response content corresponding to the question to be answered, and part or all of the feedback information regarding the response content. The preset condition includes the at least one piece of information. The indicated cases differ from historical cases recorded in the knowledge base; the cases indicated by the at least one piece of information have changed compared to historical cases; the scenarios indicated by the at least one piece of information (such as vulnerability handling stages like false alarm confirmation stages) differ from scenarios recorded in the knowledge base; the vulnerability types indicated by the at least one piece of information differ from vulnerability types recorded in the knowledge base; the vulnerability remediation solutions indicated by the at least one piece of information have changed compared to vulnerability remediation solutions recorded in the knowledge base; and the vulnerability security standards indicated by the at least one piece of information have changed compared to vulnerability security standards recorded in the knowledge base. In this way, the knowledge base can be updated with data generated in the current round to improve its richness, thereby making the solutions determined based on the knowledge base better.

[0095] It should be noted that, regarding the responses to the aforementioned unanswered questions, the feedback information indicates the user's level of acceptance of the responses, thereby demonstrating whether the solution described in the responses can successfully solve the problem. Furthermore, this application does not limit the implementation method of the feedback information; for example, it can be based on user actions such as liking or disliking. Alternatively, the feedback information can be obtained by analyzing subsequent conversations triggered by the user.

[0096] Based on the above two paragraphs, it can be seen that in some scenarios, the knowledge base deployed in the vulnerability management system is not static but updates as the handling of the target vulnerability progresses. This update process has the following characteristics: during multi-round sessions through the system, new scenarios (such as newly emerging processing stages), new knowledge, and new experiences are collected, organized, and verified in real time to maintain and upgrade the knowledge base, thereby improving response accuracy, enhancing closed-loop efficiency, and reducing costs. The conditions triggering this update can include: the addition of historical cases, the emergence of new scenarios, new vulnerability types, iterative remediation solutions, and changes in security requirements. Furthermore, the knowledge base can be implemented using a graph database built by constructing a knowledge graph to achieve rapid retrieval and reasoning. In addition, the content recorded in the knowledge base can be determined through dual verification via simulated environments and / or special audits, thus ensuring the reliability of the knowledge. Furthermore, for information generated during vulnerability handling (such as the aforementioned real-time data stream), experience can be extracted from this information and converted into standardized knowledge items stored in the knowledge base. Similarly, a similarity matching algorithm can be used to recommend historical cases of successful problem-solving similar to this information from the knowledge base. Additionally, unstructured multi-turn dialogues recorded in this information can be converted into structured knowledge items and stored in the knowledge base. This helps to solve the problem of fragmented experience during vulnerability handling.

[0097] It should be noted that the aforementioned "simulation environment" was built and used before the vulnerability management system or knowledge base went online. This simulation environment was designed to mimic some usage scenarios of the system or knowledge base, allowing for subsequent expansion of the knowledge base based on these scenarios. The aforementioned "specialized review" is used to manually review certain content within the knowledge base, such as content added to the knowledge base during its use, randomly selected question-and-answer pairs, or frequently occurring questions and their answers. This review aims to confirm the accuracy of the content and allow for manual correction should errors be found (e.g., an incorrect answer to a question).

[0098] Research has found that in some scenarios, LLM cannot provide solutions to certain problems. Therefore, to ensure a good response experience, human intervention can be introduced to answer the questions.

[0099] Based on the above research, in order to better improve the response effect, this application also provides a possible implementation of the security vulnerability handling method based on the large model. In this method, when the security vulnerability handling method based on the large model is applied to the vulnerability management system, and the first login account of the vulnerability management system executes the remediation process of the target vulnerability, and the second login account of the vulnerability management system tracks the processing progress of the target vulnerability, the method may further include the following steps: in response to the inability to obtain the response content corresponding to the question to be answered through the large model, a prompt message is sent to the second login account, the prompt message instructing the second login account to answer the question, and the response content corresponding to the question is determined based on the content input by the second login account for the question. This enables the introduction of manual response when the solution to the question cannot be determined by the LLM, thereby helping to ensure the response effect.

[0100] Based on the aforementioned vulnerability management system, it is known that the system can combine multi-turn conversations and machine learning algorithms to analyze the work order information (such as the status of security vulnerability remediation), historical conversations, and the problem that needs to be solved in the current round. This allows the system to identify whether it is in a conversation response scenario or a conversation rejection scenario in the current round. When it is determined that the system is in a conversation response scenario in the current round, the system can proactively guide the user to quickly solve the problem based on relevant information in the current round (such as the current status of the vulnerability). This enables rapid response and reply to the user's questions. Furthermore, when the machine learning model cannot provide a reply, manual processing is introduced.

[0101] In addition, in some scenarios, the aforementioned vulnerability management system can be adopted. Figure 4 The vulnerability management system shown is implemented to include an input layer, an AI core layer, an execution layer, and an output layer. For ease of understanding, the relevant content of each layer is described below.

[0102] For the aforementioned input layer, the input data of the input layer includes the aforementioned target information, and the input layer is at least used for data cleaning and integration processing of the target information, such as missing value handling, format standardization, deduplication, noise filtering, data association, data fusion, data augmentation, etc., so as to transform the original messy data into high-quality, analyzable structured data.

[0103] For the aforementioned AI core layer, the input data includes the output data of the input layer; and the AI ​​core layer includes a state tracking module, an intent recognition module, and an automatic response generation module. The state tracking module analyzes the output data of the input layer to obtain analysis results, aiming to clarify the current scenario of the target vulnerability (e.g., the retesting phase) and the problems it presents. This facilitates real-time or periodic collection of online scenario data, ensuring the completeness and accuracy of the collected data, covering various operations and state information involved in the vulnerability handling process. The intent recognition module performs intent recognition on the output data of the input layer and the output data of the state tracking module to obtain intent recognition results, ensuring that the intent recognition results at least indicate the type of problem. Additionally, in some scenarios, the intent recognition module can also extract information (such as dialogue records, new scenario information, etc.) from its input data to automatically update the knowledge base. The automatic response generation module is used to process the output data of the input layer (such as work order information, processing stage information, etc.), the output data of the state tracking module, and the output data of the intent recognition module through the LLM model (such as constructing a question-and-answer knowledge graph to realize the analysis of complex questions into atomic question chains, etc.) to automatically generate response instructions, such as multimodal instructions generated based on the question-and-answer knowledge graph.

[0104] For the aforementioned execution layer, the input data includes the output data of the AI ​​core layer; and this execution layer includes a dialogue generation module and an intelligent scheduling module. The dialogue generation module is a core interactive component in the vulnerability management system, enabling automated communication and collaborative management of the entire vulnerability handling process through natural language dialogues generated by this module. Furthermore, this module can replace repetitive dialogues (such as reminders, remediation metrics, system operations, etc.) involved in vulnerability management solutions implemented manually, achieving a more human-like yet more efficient interactive experience. The intelligent scheduling module is a task scheduling and process management component based on AI and automation technologies, enabling it to allocate, schedule, and track the progress of vulnerability remediation tasks.

[0105] For the aforementioned output layer, its input data includes the output data of the execution layer. This output layer comprises a dialogue display module, a knowledge base update module, and a report generation module. The dialogue display module converts the input data (such as problem solutions) of the output layer into understandable and executable dialogue content for the user, driving human-machine collaboration to complete the vulnerability remediation loop. The knowledge base update module collects, organizes, and verifies new scenarios, knowledge, and experience in real time during multi-round conversations, maintaining and upgrading the current knowledge base to improve response accuracy, enhance loop efficiency, and reduce costs. The report generation module integrates all process data involved in vulnerability handling, presenting key information (remediation process, problems encountered, and handling status, etc.) in a combined and visualized format. This provides a basis for subsequent decision-making and can be used for internal review and optimization, internal and external communication and reporting, achieving the effects of knowledge and experience accumulation and team improvement.

[0106] It is evident that the aforementioned vulnerability management system can achieve the following functions (such as...). Figure 5 (The functions shown are as follows): The LLM model deployed in the system automatically answers the daily questions raised by users; the LLM model actively analyzes the status of the work orders in the current round to guide users to better perform the vulnerability handling process; when the LLM model cannot answer the questions raised by users, human intervention is introduced in a certain way to improve the vulnerability management effect while reducing human costs, so that human costs can be used to overcome other problems in the future.

[0107] Furthermore, the aforementioned vulnerability management system possesses the following characteristics: It is a multi-turn session-driven closed-loop vulnerability management system, enabling deep coupling between multi-turn session technology and the vulnerability management process. Continuous interaction dynamically drives the vulnerability handling closed loop, and the system's knowledge base updates are linked in real-time with the AI ​​core layer, forming a self-learning closed loop of data collection, knowledge accumulation, and strategy optimization. The system employs a cross-module collaborative decision-making mechanism, allowing the AI ​​core layer to analyze data from the input layer, generate solutions, and drive collaboration within the execution layer. This allows the execution layer to subsequently feed back into the AI ​​core layer, breaking down traditional security capability silos and achieving seamless integration and intelligent collaboration throughout the vulnerability management process. Based on historical cases recorded in the knowledge base and real-time data streams generated in the current round, the system's intent recognition module analyzes the current round's requirements to generate solutions that meet those requirements, thereby improving the professionalism and executability of vulnerability handling recommendations. The system also utilizes intelligent... The system employs scheduling, resource optimization algorithms, and operations research optimization algorithms to achieve reasonable task scheduling, significantly improving resource utilization and remediation efficiency. The knowledge base update module is triggered by conditions such as the emergence of new vulnerabilities, remediation feedback, and changes in security standards. This allows for the automatic collection, verification, and storage of new knowledge into the knowledge base during vulnerability handling. The knowledge base is a graph database constructed from a knowledge graph, enabling rapid retrieval and reasoning. Furthermore, the content recorded in the knowledge base undergoes dual verification through simulated environments and specialized audits to ensure its reliability. The system utilizes a vulnerability management experience accumulation and reuse mechanism. This allows the system to extract new experiences in real-time during vulnerability handling, transforming them into standardized knowledge items and storing them in the knowledge base. It also enables the system to recommend successful historical cases recorded in the knowledge base based on similarity matching algorithms to answer user questions. Additionally, the system can convert unstructured dialogues that occur during vulnerability handling into structured knowledge items and store them in the knowledge base, addressing the problem of fragmented experience in vulnerability management.

[0108] It is evident that the aforementioned vulnerability management system possesses the following advantages: (i) The vulnerability management solution implemented through this system can improve timeliness. Specifically, the system automates and intelligently processes each stage of the vulnerability handling process, providing 24 / 7 answers to user questions and significantly reducing processing time. This results in a significantly higher efficiency and lower security vulnerability expiration rate compared to manual vulnerability management solutions. (ii) The vulnerability management solution implemented through this system can enhance accuracy. Specifically, the system uses AI to automatically monitor and analyze work orders that need processing, reducing human error / missed judgments, and promptly advancing processing to avoid risks caused by vulnerability accumulation. (iii) The vulnerability management solution implemented through this system can achieve continuous optimization. Specifically, the system continuously optimizes the vulnerability management process through a historical data experience accumulation mechanism, enhancing the overall network security protection capabilities of the managed objects (such as hardware, software, and systems), and providing strong support for the stable operation of these objects.

[0109] Based on the security vulnerability processing method based on large models provided in the embodiments of this application, the embodiments of this application also provide a vulnerability processing device, which is described below in conjunction with... Figure 6 Explanation and clarification will be provided. Among them, Figure 6 This is a schematic diagram of a vulnerability processing device provided in an embodiment of this application. It should be noted that for technical details of the vulnerability processing device provided in this embodiment, please refer to the relevant content above regarding the security vulnerability processing method based on a large model.

[0110] like Figure 6 As shown in the embodiment of this application, the security vulnerability processing device 600 based on a large model includes:

[0111] The acquisition unit 601 is used to acquire target information, the target information including work order information and at least one round of dialogue information, the work order information describing a target vulnerability, the at least one round of dialogue information being generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least one unanswered question associated with the target vulnerability.

[0112] The determining unit 602 is used to determine the current processing status of the target vulnerability based on the target information;

[0113] The identification unit 603 is used to perform intent identification processing based on the target information and the current processing status of the target vulnerability to obtain an intent identification result;

[0114] The processing unit 604 is used to process the target information, the current processing status of the target vulnerability, and the intent recognition result based on the large model to obtain the response content corresponding to the question;

[0115] Display unit 605 is used to display the content of the response.

[0116] In one possible implementation, the vulnerability handling device 600 can be implemented using any implementation of the vulnerability handling system provided in this application.

[0117] In one possible implementation, the determining unit 602 is specifically configured to: analyze the target information to obtain an analysis result, the analysis result including at least one of a first result and a second result, the first result indicating whether the question to be answered belongs to a question that has already been answered in the at least one round of dialogue information, and the second result indicating the processing stage of the target vulnerability when the question to be answered appears; and determine the current processing status of the target vulnerability based on the analysis result.

[0118] In one possible implementation, the processing unit 604 is specifically configured to: in response to the question to be answered being a composite question, process the target information, the analysis results, and the intent recognition results based on a large model to obtain a question-answering knowledge graph, wherein the question-answering knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and the corresponding answer content for each sub-question; and determine the answer content corresponding to the question to be answered based on the question-answering knowledge graph.

[0119] In one possible implementation, the response content is determined by the large model based on some or all of the content in a pre-built knowledge base;

[0120] The vulnerability handling device 600 further includes:

[0121] An update unit is configured to update the knowledge base based on at least one piece of information in response to at least one piece of information meeting a preset condition. The at least one piece of information includes some or all of the target information, the question, the analysis result, the intent recognition result, the response content, and feedback information regarding the response content. The preset condition includes: the case indicated by the at least one piece of information is different from historical cases recorded in the knowledge base; the case indicated by the at least one piece of information has changed compared to historical cases; the scenario indicated by the at least one piece of information is different from scenarios recorded in the knowledge base; the vulnerability type indicated by the at least one piece of information is different from vulnerability types recorded in the knowledge base; the vulnerability remediation scheme indicated by the at least one piece of information has changed compared to vulnerability remediation schemes recorded in the knowledge base; and the vulnerability security standard indicated by the at least one piece of information has changed compared to vulnerability security standards recorded in the knowledge base.

[0122] In one possible implementation, the vulnerability handling device 600 is used to manage the handling process of multiple vulnerabilities;

[0123] The vulnerability handling device 600 further includes:

[0124] The first scheduling unit is used to respond to the fact that the difference between the acquisition times of the response content corresponding to at least two of the plurality of vulnerabilities is less than a preset threshold, and to determine the display time of the response content corresponding to each of the at least two vulnerabilities based on the level information of each of the at least two vulnerabilities, wherein the at least two vulnerabilities include the target vulnerabilities, and the response content corresponding to the target vulnerabilities includes the response content corresponding to the question to be answered.

[0125] The display unit 605 is specifically used to: for any of the at least two vulnerabilities, in response to the timing of displaying the response content corresponding to the vulnerability, display the response content corresponding to the vulnerability.

[0126] In one possible implementation, the vulnerability processing device 600 is used to process dialogue information sent by multiple clients, including clients displaying web pages and clients displaying session groups. The dialogue information sent by the clients displaying web pages includes the at least one round of dialogue information, or the dialogue information sent by the clients displaying session groups includes the at least one round of dialogue information.

[0127] The vulnerability handling device 600 further includes:

[0128] The second scheduling unit is used to determine the response timing for each client based on the description information of each client when the difference between the times when the system generates response content based on the dialogue information sent by each client is less than a preset threshold.

[0129] The display unit 605 is specifically used to: for any one of the at least two clients, in response to the timing of the corresponding reply from that client, display the reply content generated by the system based on the dialogue information sent by that client.

[0130] In one possible implementation, the remediation process for the target vulnerability is performed through a first login account of the vulnerability handling device 600, and the progress of the target vulnerability handling is tracked through a second login account of the vulnerability handling device 600; the question to be answered is input through the first login account; and / or, the analysis unit is further configured to: in response to the inability to obtain the answer content corresponding to the question through the large model, send a prompt message to the second login account, the prompt message indicating that the second login account should answer the question, and determine the answer content corresponding to the question based on the content input by the second login account for the question.

[0131] Based on the aforementioned content regarding the vulnerability processing device 600, its working principle includes: first, acquiring target information, which includes work order information describing the target vulnerability (such as any security vulnerability) and at least one round of dialogue information generated in a session associated with the target vulnerability (such as a session triggered around the target vulnerability during the processing of the target vulnerability), so that the at least one round of dialogue information can at least indicate the unanswered questions associated with the target vulnerability (such as the question entered in the current round), thereby enabling the at least one round of dialogue information to describe some problems encountered when dealing with the target vulnerability, such as errors in the vulnerability remediation process; then, determining the current processing status of the target vulnerability based on the target information, so that the current processing status can represent the characteristics of the target vulnerability in the current round, such as the reason why subsequent processing cannot be performed on the target vulnerability, and the current processing status of the target vulnerability. The process involves several stages: (e.g., vulnerability remediation stage, vulnerability testing stage); then, based on the target information and the current processing status, intent recognition processing is performed to obtain intent recognition results. These results indicate the type of problem to be addressed (e.g., the vulnerability remediation solution is flawed, or the vulnerability remediation cannot be completed on schedule), thus representing the current requirements. Next, based on a large model (e.g., LLM model), the target information, analysis results, and intent recognition results are processed to obtain the corresponding response to the problem, which is then presented to the problem's questioner. This allows the questioner to better understand the solution to the problem and continue the processing of the target vulnerability after resolving it. This approach, utilizing a large model, automatically manages security vulnerabilities, effectively overcoming the shortcomings of relying on extensive manual processing.

[0132] In addition, this application also provides an electronic device, the device including a processor and a memory: the memory is used to store instructions or computer programs; the processor is used to execute the instructions or computer programs in the memory, so that the electronic device performs any implementation of the security vulnerability handling method based on a large model provided in this application.

[0133] See Figure 7 The diagram illustrates a structural schematic of an electronic device 700 suitable for implementing embodiments of the present disclosure. Terminal devices in embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0134] like Figure 7 As shown, the electronic device 700 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device 700. The processing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0135] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic device 700 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 7 An electronic device 700 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0136] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 709, or installed from storage device 708, or installed from ROM 702. When the computer program is executed by processing device 701, it performs the functions defined in the methods of embodiments of this disclosure.

[0137] The electronic device provided in this embodiment belongs to the same inventive concept as the method provided in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0138] This application also provides a computer-readable medium storing instructions or computer programs that, when executed on a device, cause the device to perform any implementation of the large-model-based security vulnerability handling method provided in this application.

[0139] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0140] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0141] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0142] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, enable the electronic device to perform the aforementioned methods.

[0143] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0144] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0145] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units / modules do not necessarily limit the specific unit itself.

[0146] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0147] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0148] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.

[0149] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0150] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0151] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0152] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security vulnerability handling method based on a large model, characterized in that, The method includes: Obtain target information, which includes ticket information and at least one round of dialogue information, wherein the ticket information describes a target vulnerability, and the at least one round of dialogue information is generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicates at least one unanswered question associated with the target vulnerability; The current processing status of the target vulnerability is determined based on the target information, and the current processing status at least indicates the processing stage of the target vulnerability; Intent recognition results are obtained by performing intent recognition processing based on the target information and the current processing status of the target vulnerability; Based on the large model, the target information, the current processing status of the target vulnerability, and the intent recognition result are processed to obtain the response content corresponding to the question; The content of the response is displayed.

2. The method according to claim 1, characterized in that, Determining the current processing status of the target vulnerability based on the target information includes: The target information is analyzed to obtain analysis results, which include at least one of a first result and a second result. The first result indicates whether the question to be answered belongs to a question that has already been answered in the at least one round of dialogue information. The second result indicates the processing stage of the target vulnerability when the question to be answered appears. Based on the analysis results, the current processing status of the target vulnerability is determined.

3. The method according to claim 1, characterized in that, The process of processing the target information, the current processing status of the target vulnerability, and the intent recognition result based on the large model to obtain the response content corresponding to the question includes: In response to the fact that the question to be answered is a complex question, the target information, the current processing status of the target vulnerability, and the intent recognition result are processed based on the large model to obtain a question-answering knowledge graph. The question-answering knowledge graph indicates at least one sub-question obtained by decomposing the question to be answered and the corresponding answer content for each sub-question. Based on the question-and-answer knowledge graph, the corresponding response content for the question to be answered is determined.

4. The method according to claim 1, characterized in that, The response content is determined by the large model based on some or all of the content in a pre-built knowledge base; The method further includes: In response to at least one piece of information meeting a preset condition, the knowledge base is updated based on the at least one piece of information. The at least one piece of information includes some or all of the target information, the problem, the current processing status of the target vulnerability, the intent recognition result, the response content, and feedback information regarding the response content. The preset condition includes: the case indicated by the at least one piece of information is different from historical cases recorded in the knowledge base; the case indicated by the at least one piece of information has changed compared to historical cases; the scenario indicated by the at least one piece of information is different from the scenario recorded in the knowledge base; the vulnerability type indicated by the at least one piece of information is different from the vulnerability type recorded in the knowledge base; the vulnerability remediation scheme indicated by the at least one piece of information has changed compared to the vulnerability remediation scheme recorded in the knowledge base; and the vulnerability security standard indicated by the at least one piece of information has changed compared to the vulnerability security standard recorded in the knowledge base.

5. The method according to claim 1, characterized in that, The method is applied to a vulnerability management system, which manages the handling process of multiple vulnerabilities. Before displaying the response content, the method further includes: In response to the fact that the difference between the acquisition times of the response content corresponding to at least two of the plurality of vulnerabilities is less than a preset threshold, the timing of displaying the response content corresponding to each of the at least two vulnerabilities is determined based on the level information of each of the at least two vulnerabilities. The at least two vulnerabilities include the target vulnerability, and the response content corresponding to the target vulnerability includes the response content corresponding to the question to be answered. The presentation of the response content includes: For any one of the at least two vulnerabilities, in response to the timing of displaying the response content corresponding to the vulnerability, the response content corresponding to the vulnerability is displayed.

6. The method according to claim 1, characterized in that, The method is applied to a vulnerability management system, which is used to process dialogue information sent by multiple clients, including clients that display web pages and clients that display session groups. The dialogue information sent by the clients that display web pages includes the at least one round of dialogue information, or the dialogue information sent by the clients that display session groups includes the at least one round of dialogue information. Before displaying the response content, the method further includes: In response to the difference between the times when the system generates response content based on the dialogue information sent by each client being less than a preset threshold, the system determines the response timing for each client based on the description information of each client. The presentation of the response content includes: For any one of the at least two clients, in response to the timing of the corresponding response from that client, the system displays the response content generated by the system based on the dialogue information sent by that client.

7. The method according to any one of claims 1-6, characterized in that, The method is applied to a vulnerability management system, whereby the first login account of the vulnerability management system executes the remediation process for the target vulnerability, and the second login account of the vulnerability management system tracks the progress of the target vulnerability's processing. The question to be answered was entered through the first login account; And / or, The method further includes: In response to the inability to obtain the answer to the question through the large model, a prompt message is sent to the second login account, indicating that the second login account should answer the question, and the answer to the question is determined based on the content entered by the second login account for the question.

8. A security vulnerability processing device based on a large model, characterized in that, include: An acquisition unit is used to acquire target information, the target information including work order information and at least one round of dialogue information, the work order information describing a target vulnerability, the at least one round of dialogue information being generated in a session associated with the target vulnerability, and the at least one round of dialogue information indicating at least one unanswered question associated with the target vulnerability; A determining unit is configured to determine the current processing status of the target vulnerability based on the target information, wherein the current processing status at least indicates the processing stage of the target vulnerability; The identification unit is used to perform intent identification processing based on the target information and the current processing status of the target vulnerability to obtain the intent identification result; The processing unit is used to process the target information, the current processing status of the target vulnerability, and the intent recognition result based on the large model to obtain the response content corresponding to the question; The display unit is used to display the content of the response.

9. An electronic device, characterized in that, The device includes: a processor and a memory; The memory is used to store instructions or computer programs; The processor is configured to execute the instructions or computer program in the memory to cause the electronic device to perform the method according to any one of claims 1-7.

10. A computer-readable medium, characterized in that, The computer-readable medium stores instructions or computer programs that, when executed on the device, cause the device to perform the method according to any one of claims 1-7.

11. A computer program product, characterized in that, It includes a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Intelligent question answering method and device for vulnerability repair, computer equipment and storage medium

    CN120106138A