Big data-based security vulnerability management method and system
By constructing a real-time data acquisition and dynamic risk assessment mechanism, combined with a tiered response strategy and containerized verification, the issues of continuity and accuracy in security vulnerability management have been resolved, achieving efficient security vulnerability management and defense.
Patent Information
- Application Number
- CN202510895666.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2045-06-30
AI Technical Summary
Current technologies lack continuity in the management of security vulnerabilities, are not updated in a timely manner, and are difficult to accurately control and effectively handle the risks of unknown vulnerabilities, making it impossible to achieve pre-emptive prediction and optimized management.
A real-time data acquisition strategy is constructed, which acquires internal and external data through a distributed log collection component, dynamically updates asset profiles using a four-dimensional model, automatically isolates high-risk devices, dynamically configures firewall rules, and verifies the effectiveness of protection through a containerized sandbox, forming a closed-loop learning mechanism.
It enables precise management of security vulnerabilities, improves system efficiency and defense capabilities, reduces false alarms and missed detections, optimizes resource allocation, and enhances the efficiency and accuracy of security operations and maintenance.
Smart Images

Figure CN120602187B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of security vulnerability analysis, and particularly relates to a security vulnerability management method and system based on big data. BACKGROUND
[0002] The existing security vulnerabilities mainly rely on devices such as firewalls, and the management of vulnerabilities generally adopts a periodic updating mode, which lacks continuity, is not timely updated, and the feedback mechanism of security vulnerabilities is often handled by the user end after the failure, which is a post-treatment and cannot be analyzed and handled in advance, making it difficult to accurately control and effectively handle the risk of unknown vulnerabilities and effectively suppress the occurrence of security vulnerabilities.
[0003] For example, the invention patent with the application number CN202411294142.3 proposes a security vulnerability analysis and management system based on big data, which includes: a data acquisition module, the data acquisition module is used to collect big data information such as running logs, user behavior data, network traffic data from target software and systems; a vulnerability analysis module, the vulnerability analysis module is used to obtain the big data information in the data acquisition module, and obtain the protection strategy through the vulnerability analysis strategy; based on the initial overall protection strategy of each event unit queue, determine the to-be-activated phased protection strategy for each vulnerability threat information; a strategy execution module, the strategy execution module is used to execute the corresponding protection strategy automatically or under manual intervention according to the protection strategy in the vulnerability analysis module. However, the analysis of the security vulnerability is to analyze the running logs, user behavior data, and network traffic data, and then directly enter the protection strategy, which is difficult to accurately control and effectively handle the risk of unknown vulnerabilities.
[0004] Therefore, the present application aims to provide a security vulnerability management method based on big data, which can intelligently analyze security vulnerabilities, predict the future risk of vulnerabilities, and determine and optimize the management method according to the risk situation. SUMMARY
[0005] The purpose of the present application is to overcome the shortcomings in the prior art, solve or at least alleviate the problems of separation of risk control and copyright management, dependence on biological authentication hardware, and insufficient cooperation between blockchain and artificial intelligence in the field of digital media copyright transaction, and provide a security vulnerability management method and system based on big data.
[0006] To achieve the above-mentioned purpose, the present application provides the following technical scheme: a security vulnerability management method based on big data, comprising:
[0007] A real-time data acquisition strategy is constructed, and distributed log collection components are used to grab endogenous network device logs, server running states, and application system traffic data, and at the same time, API interfaces are used to synchronize vulnerability information from exogenous threat intelligence platforms;
[0008] A dynamic risk assessment model is constructed to update the risk assessment of security vulnerabilities in real time based on a four-dimensional model of IP address, service type, port number, and software version;
[0009] A vulnerability-asset intelligent correlation analysis is triggered when asset changes are detected, and the risk assessment engine is started only when the impact range of external vulnerability information matches the specific service version recorded in the asset library;
[0010] Response strategies are triggered according to risk value classification, including automatic isolation of high-risk devices, dynamic configuration of firewall rules, and generation of repair work orders;
[0011] After repair, the effectiveness of protection is verified through a containerized verification sandbox, and successful cases are converted into disposal rules and written into the knowledge base.
[0012] Preferably, the real-time data collection mechanism includes collecting endogenous data using distributed log collection system components, synchronizing vulnerability numbers, hazard levels, and affected product information from the national information security vulnerability sharing platform and the micro-step online threat intelligence platform.
[0013] Preferably, the dynamic asset fingerprint library periodically updates asset portraits and immediately reorganizes asset information when new service deployment or version upgrade is detected.
[0014] Preferably, the risk assessment engine uses a composite calculation model:
[0015] Risk value = base CVSS score × asset exposure coefficient.
[0016] Preferably, the hierarchical response strategy includes:
[0017] When the risk value is greater than the first threshold, device isolation, malicious IP blocking, and automatic patch deployment are performed;
[0018] When the risk value is between the first threshold and the second threshold, WAF rules are dynamically configured for traffic limiting and pushing of manual review work orders;
[0019] When the risk value is less than the second threshold, a repair work order is generated and an overdue automatic upgrade mechanism is set;
[0020] Wherein the second threshold is less than the first threshold.
[0021] Preferably, the operation of the containerized verification sandbox includes:
[0022] Clone the production environment configuration and inject vulnerability attack vectors. When an unauthorized access request returns a repair success status code, it is determined that the repair is effective, otherwise the disposal strategy is upgraded.
[0023] Preferably, the successful cases are converted into disposal rule writing knowledge base, at the same time, the false positive events are reduced by 0.2 CVSS weight coefficient, and the false negative events are increased by 15% behavior anomaly detection sensitivity threshold.
[0024] Preferably, the knowledge base system constructs a decision support system based on historical cases, adopts a relational database to store structured repair case records, and the core fields include vulnerability identifier, affected software name, version range limit, verified effective repair measures and other key dimensions.
[0025] A security vulnerability management system based on big data comprises:
[0026] A data acquisition module is configured to acquire internal and external source data through a distributed log component and an API interface.
[0027] An asset fingerprint management module is configured to maintain a dynamically updated four-dimensional asset portrait.
[0028] A risk assessment engine is configured to perform vulnerability-asset correlation analysis and risk value calculation.
[0029] A response strategy execution module is configured to call an automated tool to perform a protection operation according to a risk level.
[0030] A repair verification module is configured to test repair effectiveness through a containerized sandbox and update a knowledge base.
[0031] The repair verification module integrates a container orchestration framework to support rapid cloning of a production environment and simulation of attack vector injection.
[0032] The present application significantly improves the accuracy, efficiency and defense capability of security vulnerability management through the synergistic effect of real-time data acquisition, dynamic asset modeling, intelligent risk assessment, hierarchical response mechanism and closed-loop verification system. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 The main flowchart of the present application.
[0034] Figure 2 The security vulnerability repair flowchart of the present application.
[0035] Figure 3 The security vulnerability management system block diagram of the present application. DETAILED DESCRIPTION
[0036] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0037] Embodiment one
[0038] The embodiment provides an intelligence-driven network security vulnerability management system based on a big data environment, and comprises the following steps.
[0039] First, a real-time data acquisition mechanism is established, internal source network equipment logs, server running states and application system traffic data are captured through a distributed log collection component, and meanwhile, vulnerability numbers, hazard levels and impact product information of external source intelligence data sources including a national information security vulnerability sharing platform and a micro-step online threat intelligence platform are synchronized through API interfaces.
[0040] Secondly, a dynamic asset fingerprint library is constructed, asset portraits are updated every 5 minutes based on a four-dimensional model [IP address, service type, port number and software version], and asset information reorganization is triggered immediately when new deployment services or version upgrades are detected.
[0041] Then, vulnerability-asset intelligent correlation analysis is performed, and a risk assessment engine is started only when there is an intersection between the impact product range of external vulnerability intelligence and a specific service version recorded in the asset library, the engine adopts a composite calculation model to output a risk value = basic CVSS score x asset exposure coefficient, wherein the core database exposure coefficient is 1.5, and the office terminal is 0.8.
[0042] According to the risk value classification, a response strategy is triggered: when the risk value is greater than a first threshold value, a high-risk disposal process is automatically performed, including immediately isolating the equipment, blocking malicious IP and pulling patch deployment through a vendor API, when the risk value is in a second threshold value to the first threshold value interval, a web application firewall rule is dynamically configured to implement access flow control and push a manual review work order, and when the risk value is less than the second threshold value, a 72-hour repair work order is generated and an overdue automatic upgrade mechanism is set.
[0043] Among them, the real-time data acquisition mechanism realizes the comprehensive integration of internal and external source data through a distributed architecture. In terms of internal data acquisition, a proxy-based log collection framework is adopted, and a lightweight acquisition agent is deployed on each network device, physical server, virtual machine and container instance to continuously capture full-dimensional data including network device security audit logs, server CPU memory disk running indicators, application system HTTP request headers and response characteristics. These raw data are transmitted to the central processing platform through the message queue, and after format standardization, abnormal value cleaning and feature extraction, they are stored in a high-performance time series database. In terms of external intelligence synchronization, a standardized API connection channel is established, and the national information security vulnerability sharing platform and commercial threat intelligence services are automatically polled every hour to obtain key information such as vulnerability standard number, hazard level, affected product version range, vulnerability feature and repair suggestion. After semantic analysis and ontology mapping, these external intelligence are associated with internal source data to form a unified security data lake. The entire acquisition process adopts a stream processing architecture to ensure a data freshness of one thousandth of a second, providing real-time data support for subsequent analysis.
[0044] The asset fingerprint library, as the core infrastructure of the present application, accurately depicts asset characteristics using a four-dimensional model. This model uses IP addresses as an index basis and combines service types, port numbers and software versions to construct a complete asset portrait. At the data acquisition layer, a dual mechanism of active probing and passive listening is deployed: the active probing module performs a full network scan every 5 minutes to determine the service type and version information of open ports through protocol handshake and version identification algorithms; the passive listening module continuously analyzes the protocol characteristics and application identifiers in network traffic to capture asset change events. When the system detects new server deployment, container startup, software version upgrade or network topology adjustment, it immediately triggers the asset library reorganization process. This dynamic update mechanism ensures that the asset view is always synchronized with the actual environment, achieving an accuracy of 99.5% in testing. The asset library uses a distributed key-value storage architecture to support millisecond-level update responses and establishes a version history tracking function to trace back the asset state at any time point, providing a complete evidence chain for event investigation.
[0045] The risk assessment engine is the intelligent decision-making center of the application, using a condition-triggered correlation analysis mode. When the system receives new vulnerability information, it first extracts its key attributes such as the affected version range, and then scans all devices in the asset library that match the version range. Only when there is an exact match, can the engine start risk assessment calculation. This design avoids invalid scanning and improves system efficiency by more than 30%. In the risk calculation stage, a composite evaluation model is used: the base CVSS score is multiplied by the asset exposure coefficient to determine the final risk value. The exposure coefficient is set according to the asset business importance classification: core database servers are weighted by 1.5, Internet-exposed application servers are weighted by 1.2, internal management systems remain at 1.0 baseline, and office terminal devices are weighted down to 0.8. This dynamic weighting mechanism successfully avoids 85% of risk misjudgments in bank system tests. For example, the risk value of an Oracle vulnerability in a database server increases from 7.8 to 11.7 after weighting, triggering the highest level of response. When the calculation result exceeds 10.0, it is automatically handled as the highest risk to ensure that critical assets are given priority for protection.
[0046] The risk value-based hierarchical response system achieves precise resource scheduling. For ultra-high-risk (greater than the first threshold) vulnerabilities, the system immediately starts the emergency response protocol: first, isolate the target device network connection by modifying the switch configuration and host firewall rules, simultaneously deploy attack feature filtering rules on the border firewall to block malicious IP, and call the automated script to distribute security patches and restart services. The entire process is completed within 120 seconds and triggers the highest level of security alert. For high-risk (between the second threshold and the first threshold) vulnerabilities, the system implements defensive control measures: dynamically configure protection rules in the Web Application Firewall to block attack feature traffic, implement access rate limiting for suspicious sources, and generate repair work orders that require manual review by the security team, with a 30-minute timeout automatic escalation mechanism. For medium and low-risk (less than the second threshold) vulnerabilities, the standardized disposal process is adopted: create a 72-hour repair work order to automatically assign a responsible person, mark the asset library as "to be repaired", and send a warning notification 12 hours before expiration. If it is not handled within the specified period, the priority is automatically upgraded and the supervisor is notified. This hierarchical mechanism optimizes resource allocation and saves 40% of security operation and maintenance costs in e-commerce platform practice.
[0047] Embodiment Two
[0048] After the repair is completed, a containerized verification sandbox is started, the production environment configuration is cloned, and the corresponding vulnerability attack vector (such as SQL injection Payload) is injected. When an unauthorized access request is detected to return a repair success status code, it is determined that the repair is effective, otherwise the handling policy is triggered to upgrade; finally, successful cases are converted into handling rules and written into the knowledge base, and the risk model parameters are optimized simultaneously - false positive events reduce the CVSS weight coefficient by 0.2, and false negative events increase the behavior anomaly detection sensitivity threshold by 15%.
[0049] In the repair verification link, the Kubernetes-based containerized sandbox technology is adopted. When the repair completion notification is received, the system automatically extracts the detailed configuration of the target environment from the asset library, including the operating system version, software dependency, network topology and other parameters, accurately clones the production environment in the isolated sandbox cluster, and the verification personnel selects the corresponding attack vector script according to the vulnerability feature library to simulate the real attack scene for penetration testing. The effectiveness is determined by double standards: for identity verification type vulnerabilities, it is detected whether unauthorized access returns a repair success forbidden status code; for code execution type vulnerabilities, it is monitored whether the system log appears a malicious payload execution trace. The verification result triggers different disposal processes: the successful defense case immediately generates a disposal rule and writes it into the knowledge base, for example, the Apache vulnerability repair experience is converted into the persistent rule "detect Log4j2 vulnerability and force upgrade to ≥2.0 version", and the verification failure event triggers the risk value to increase by 0.5 and reassign the work order, and the security team is notified to intervene in the analysis. In the financial system test, this mechanism eliminates 12% of the repair blind area.
[0050] The knowledge base system is constructed based on the decision support system of historical cases. The structured repair case record is stored in a relational database with a storage structure. The core fields include vulnerability identifier, affected software name, version range limit, and verification effective repair measure. The system sets an automatic rule generation engine. When the container sandbox confirms that the protection is effective, the vulnerability characteristics and disposal scheme are extracted to generate standard rules. These rules form reusable knowledge assets. In the rule application stage, the system establishes a multi-level matching mechanism: the new vulnerability alarm is first scanned in the knowledge base for historical similar cases, and then matched with the same software version range, and finally matched with the disposal scheme of similar products.
[0051] The present application establishes a continuously evolving learning system. When a false positive event occurs, the system automatically starts the parameter calibration process: reduces the CVSS base score weight of the corresponding vulnerability type by 0.2, synchronously adjusts the correlation analysis sensitivity, avoids the repetition of similar errors, and reduces the weight from the second threshold in the false positive Oracle vulnerability case of an office system. The similar alarm is reduced by 90% in the subsequent stage. When a false negative event occurs, the system increases the abnormal behavior detection threshold by 15%, enhances the depth of log analysis, and expands the monitoring coverage. All parameter adjustment records are stored in the audit log, supporting version backtracking analysis. The security team can view the historical adjustment track to evaluate the optimization effect. In the trial operation for half a year, the mechanism promotes the system accuracy by 42%, realizes the fundamental change from static rules to dynamic learning,
[0052] The system of the application adopts a hierarchical distributed architecture design, and is divided into four functional areas at the hardware deployment level. Three high-performance servers are deployed in the data acquisition layer to form a log collection cluster. Through a gigabit optical fiber network, the core switch is accessed to ensure the collection throughput capacity of billions of logs per day. The analysis and calculation layer is equipped with a GPU accelerated server, which runs a risk assessment engine and a machine learning model. Through the RDMA high-speed network, a distributed memory database cluster is connected to store asset fingerprints. The response execution layer adopts a dual-active control node architecture to realize high-availability execution of automated scripts. Through a dedicated channel, the firewall management system is connected to verify the sandbox layer, which builds a three-node Kubernetes cluster. Each computing node is configured with a 32-core CPU, 256GB of memory and an NVMe storage pool. An isolated network domain is created through VXLAN technology. In actual deployment, financial customers choose a private deployment mode to integrate the four-layer architecture into a two-site three-center infrastructure. Small and medium-sized enterprises can use a modular cloud service solution to subscribe to functional components on demand.
[0053] The system workflow forms a complete closed loop. After obtaining raw logs and threat intelligence from the data acquisition layer, the analysis and calculation layer is input for asset modeling and risk assessment. The generated disposal instructions are transmitted to the response execution layer to schedule security devices. After completion, the verification sandbox is triggered for effect verification. The final result is deposited in the knowledge base to optimize subsequent decision-making.
[0054] The system can effectively reduce potential security vulnerability risks and form a quantifiable security value system. Combined with threat hunting and attack simulation technology, the active defense capability is continuously improved.
[0055] The contents not described in detail in the specification are all prior art known to those skilled in the art, and the model parameters of each electric appliance are not specifically limited, and conventional equipment can be used. In the technical solution, the electric appliance control elements not mentioned belong to prior art, and therefore are not shown in the drawings, and will not be described here.
[0056] The above is only a preferred specific embodiment of the application, but the protection scope of the application is not limited thereto. Any person skilled in the art can make equivalent replacements or changes to the technical solution and the inventive concept of the application within the technical scope disclosed by the application, which should be covered within the protection scope of the application.
Claims
1. A security vulnerability management method based on big data, characterized in that, include: Build a real-time data collection strategy, capture internal network device logs, server running status and application system traffic data through a distributed log collection component, and synchronize vulnerability information from external threat intelligence platforms through API interfaces; The real-time data acquisition mechanism includes: using distributed log collection system components to collect internal data, and synchronizing vulnerability numbers, severity levels, and affected product information with the National Information Security Vulnerability Sharing Platform and the Microstep Online Threat Intelligence Platform; A dynamic risk assessment model is constructed, based on a four-dimensional model of [IP address, service type, port number, software version] to build a dynamic asset fingerprint database, which is updated in real time to assess the risk of security vulnerabilities. The dynamic asset fingerprint database is updated periodically to create asset profiles and the asset information is immediately reorganized when new service deployments or version upgrades are detected. Response strategies are triggered based on risk level classification, including automatically isolating high-risk devices, dynamically configuring firewall rules, and generating remediation work orders; After the fix, the protection effectiveness is tested through a containerized verification sandbox, and successful cases are converted into handling rules and written into the knowledge base. The operation of the containerized verification sandbox includes: cloning the production environment configuration and injecting vulnerability attack vectors. When an unauthorized access request returns a fix success status code, the fix is deemed effective; otherwise, the handling strategy is upgraded. When an asset change is detected, a vulnerability-asset intelligent correlation analysis is triggered. The risk assessment engine is only activated when the impact of external vulnerability intelligence matches a specific service version recorded in the asset database. The risk assessment engine employs a composite calculation model: Risk Value = Baseline CVSS Score × Asset Exposure Coefficient; Tiered response strategies include: When the risk value exceeds the first threshold, device isolation, malicious IP blocking, and automatic patch deployment will be performed. When the risk value is between the first and second thresholds, WAF rules are dynamically configured to limit the rate and a manual review work order is pushed. When the risk value is less than the second threshold, a repair work order is generated and an automatic escalation mechanism for overdue issues is set. The second threshold is less than the first threshold.
2. The method according to claim 1, characterized in that, Successful cases are transformed into handling rules and written into the knowledge base. At the same time, the risk model parameters are optimized, reducing the CVSS weight coefficient of false alarm events by 0.2 and increasing the sensitivity threshold for detecting behavioral anomalies by 15% for false negative events.
3. A security vulnerability management system based on big data, used to implement the security vulnerability management method according to any one of claims 1-2, characterized in that, include: The data acquisition module is used to acquire internal and external source data through distributed log components and API interfaces; The asset fingerprint management module is used to maintain dynamically updated four-dimensional asset profiles; Risk assessment engine performs vulnerability-asset correlation analysis and risk value calculation; The response strategy execution module invokes automated tools to perform protective operations based on risk levels. The verification module was repaired, and the effectiveness of the repair was tested using a containerized sandbox, and the knowledge base was updated.
4. The system according to claim 3, characterized in that, The repair and verification module integrates the K-container orchestration framework, which supports rapid cloning of production environments and simulation of attack vector injection.
Citation Information
Patent Citations
Security vulnerability analysis and management system based on big data
CN119128913A
External attack surface management method and system based on attacker view angle
CN116708028A
Visual life cycle management method based on data
CN119621703A