Vulnerability fixing method and device, equipment and storage medium

By collecting data through web crawlers and traffic probe technology, building adversarial network models, generating and verifying defense strategies, we can solve the problems of unknown attacks and low manual processing efficiency of traditional network security defense technologies, achieve rapid response and dynamic defense, and improve the level of network security protection.

CN120768680AInactive Publication Date: 2025-10-10SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511270048.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-10-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional network security defense technologies are difficult to deal with unknown attacks, manual processing is inefficient, response speed is slow, defense strategies are difficult to adjust dynamically, and potential security risks and weak links in the defense system cannot be discovered in a timely manner.

Method used

External data is collected through web crawler technology, internal traffic data is obtained using port mirroring and traffic probe technology, a model to combat network attacks is built and the defense model is optimized, defense strategies are generated and verified, and a closed-loop protection is formed.

Benefits of technology

It has improved the level of network security protection, ensured the security and stability of cyberspace, and achieved rapid response and dynamic defense against unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768680A_ABST
    Figure CN120768680A_ABST
Patent Text Reader

Abstract

The invention discloses a vulnerability repairing method, device and equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: collecting initial external data and initial internal flow data, and preprocessing the initial external data and the initial internal flow data to obtain processed network data; constructing an initial attack model and an initial defense model, and optimizing the initial attack model and the initial defense model to determine a target attack model and a target defense model; inputting the target vulnerability data into a target defense model to generate a target defense strategy, configuring the target defense strategy by the target security device to obtain a defended security device, inputting the target attack data and the target traffic data into a target attack model, and outputting a target attack strategy; using the target attack strategy to attack the defended security device to obtain the target vulnerability, analyzing the target vulnerability to obtain a target repair strategy, performing sandbox verification on the target vulnerability and the target repair strategy, and executing the target repair strategy based on the verification result. And the network security protection level is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a vulnerability repair method, device, equipment and storage medium. Background Art

[0002] Currently, traditional network security defense technologies primarily include firewalls, intrusion detection systems (IDSs), intrusion prevention systems (IPSs), and antivirus software. Firewalls filter inbound and outbound network traffic using pre-defined access control rules, but they can only protect against known attack patterns and are ineffective against new attacks that exploit vulnerabilities. Intrusion detection systems rely on signature matching and abnormal behavior analysis, but their ability to detect unknown attacks is limited and prone to generating numerous false positives. Antivirus software primarily detects and eliminates known viruses, but is unable to effectively address vulnerability-based attacks and unknown malicious programs. Furthermore, these traditional defense technologies are often independent of each other, lacking effective coordination mechanisms, and thus fail to form a complete defense loop.

[0003] The process of detecting and preventing network security risks still suffers from high manual reliance and slow response times. For example, when a network security incident occurs, security personnel must manually analyze logs, identify vulnerabilities, and develop remediation strategies. This process is time-consuming and makes it difficult to effectively prevent attacks immediately. Furthermore, with the continuous expansion of network scale and the rapid evolution of attack methods, the efficiency and accuracy of manually processing massive amounts of security data are insufficient to meet actual needs, making it impossible to promptly identify potential security risks and weaknesses in defense systems.

[0004] Furthermore, traditional defense strategies are often based on fixed rules and historical experience, making it difficult to dynamically adjust to the real-time network security landscape and attack changes. Once new attack types or variants of attack methods emerge, existing defense strategies may become ineffective, leading to vulnerabilities in network security protection.

[0005] To sum up, how to improve the level of network security protection and ensure the security and stability of cyberspace is an urgent problem that needs to be solved. Summary of the Invention

[0006] In view of this, the purpose of the present invention is to provide a vulnerability repair method, device, equipment and storage medium that can improve the level of network security protection and ensure the security and stability of cyberspace. The specific solution is as follows:

[0007] In a first aspect, the present application provides a vulnerability repair method, comprising:

[0008] Collecting initial external data from a preset vulnerability database and a preset security information website using web crawler technology, obtaining initial internal traffic data using preset port mirroring technology and traffic probe technology, and preprocessing the initial external data and the initial internal traffic data to obtain processed network data;

[0009] Constructing an initial attack model based on adversarial network technology, optimizing the initial attack model to determine a target attack model, then constructing an initial defense model based on a target knowledge graph, and optimizing the initial defense model to determine a target defense model;

[0010] Inputting target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configuring the target defense strategy on a target security device to obtain a defended security device, and then inputting target attack data and target traffic data in the processed network data into the target attack model to output a target attack strategy;

[0011] The target attack strategy is used to attack the post-defense security device to obtain a target vulnerability, the target vulnerability is analyzed to obtain a target repair strategy, a sandbox verification operation is performed on the target vulnerability and the target repair strategy to obtain a corresponding verification result, and the target repair strategy is executed based on the verification result.

[0012] Optionally, the initial external data includes initial external network attack data and initial external network vulnerability data;

[0013] Accordingly, the initial external data collected from the preset vulnerability database and the preset security information website by using the web crawler technology includes:

[0014] Determine attack indicators in a pre-set format based on a pre-set security information website through a pre-set software development kit;

[0015] Using a preset API to collect initial external network attack data according to the attack indicator in the preset format;

[0016] Initial external network vulnerability data is collected from the preset vulnerability database through web crawler technology.

[0017] Optionally, the obtaining of initial internal traffic data by using a preset port mirroring technology and a traffic probe technology includes:

[0018] Use preset port mirroring technology to determine the target data collection method;

[0019] Acquiring initial internal flow data using the target data acquisition method according to flow probe technology;

[0020] The initial internal traffic data is obtained according to a flow probe technology by using the target data collection mode, and the initial internal traffic data includes:

[0021] The first internal traffic data is obtained according to a flow probe technology by using a zero-copy technology;

[0022] The second internal traffic data meeting the sensitive information condition is obtained according to a flow probe technology by using a deep packet inspection technology;

[0023] The network session graph is determined according to a flow probe technology by using a session-level behavior analysis technology, and the third internal traffic data is obtained based on the network session graph;

[0024] The first internal traffic data, the second internal traffic data and the third internal traffic data are integrated to generate the initial internal traffic data.

[0025] Optionally, the preprocessing of the initial external data and the initial internal traffic data to obtain the processed network data includes:

[0026] A data standardization framework is constructed, and the initial external data and the initial internal traffic data are mapped to standard fields according to the data standardization framework to generate standardized data;

[0027] The abnormal data in the standardized data are removed according to an isolation forest algorithm to determine the processed network data.

[0028] Optionally, the constructing of the initial attack model based on the adversarial network technology includes:

[0029] A preset attack rule is determined based on a preset attack mode;

[0030] An initial weak classifier is obtained, and the initial weak classifier is iterated based on preset training data and a preset loss function to determine a target classifier;

[0031] The initial attack model is constructed according to the preset attack rule, the target classifier and a preset deep learning model.

[0032] Optionally, the constructing of the initial defense model based on the target knowledge graph includes:

[0033] A target knowledge graph is constructed by integrating an inventory of the target security device, vulnerability database information and historical attack path data;

[0034] The target knowledge graph is analyzed by using a graph neural network to obtain a corresponding analysis result;

[0035] The corresponding topology-level defense rule is generated according to the analysis result;

[0036] An initial defense model is constructed based on the topology-level defense rules.

[0037] Optionally, configuring the target defense policy on a target security device to obtain a defensed security device includes:

[0038] The target defense strategy is sent to the target security device through a preset interface protocol, so that the target security device executes the target defense strategy to obtain a defense-posted security device.

[0039] In a second aspect, the present application provides a vulnerability repair device, comprising:

[0040] a data acquisition module for collecting initial external data from a preset vulnerability database and a preset security information website using a web crawler technology, acquiring initial internal traffic data using a preset port mirroring technology and a traffic probe technology, and preprocessing the initial external data and the initial internal traffic data to obtain processed network data;

[0041] A model determination module is used to construct an initial attack model based on adversarial network technology, optimize the initial attack model to determine a target attack model, then construct an initial defense model based on a target knowledge graph, and optimize the initial defense model to determine a target defense model;

[0042] a policy output module, configured to input target vulnerability data in the processed network data into the target defense model to generate a target defense policy, configure the target defense policy on a target security device to obtain a defended security device, and then input target attack data and target traffic data in the processed network data into the target attack model to output a target attack policy;

[0043] A policy execution module is used to use the target attack strategy to attack the post-defense security device to obtain a target vulnerability, analyze the target vulnerability to obtain a target repair strategy, perform a sandbox verification operation on the target vulnerability and the target repair strategy to obtain a corresponding verification result, and execute the target repair strategy based on the verification result.

[0044] In a third aspect, the present application provides an electronic device, comprising:

[0045] Memory, used to store computer programs;

[0046] A processor is used to execute the computer program to implement the vulnerability repair method as described above.

[0047] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the vulnerability repair method as described above is implemented.

[0048] In summary, the present application first collects initial external data from a preset vulnerability database and a preset security information website through web crawler technology, and obtains initial internal traffic data using preset port mirroring technology and traffic probe technology, and pre-processes the initial external data and the initial internal traffic data to obtain processed network data; constructs an initial attack model based on adversarial network technology, optimizes the initial attack model to determine the target attack model, and then constructs an initial defense model based on the target knowledge graph, and optimizes the initial defense model to determine the target defense model; inputs the target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configures the target defense strategy on the target security device to obtain a defended security device, and then inputs the target attack data and target traffic data in the processed network data into the target attack model to output a target attack strategy; uses the target attack strategy to attack the defended security device to obtain a target vulnerability, analyzes the target vulnerability to obtain a target repair strategy, performs sandbox verification operations on the target vulnerability and the target repair strategy to obtain corresponding verification results, and executes the target repair strategy based on the verification results. As can be seen from the above, this application collects initial external data from a preset vulnerability database and a preset security information website through web crawler technology, and uses preset port mirroring technology and traffic probe technology to obtain initial internal traffic data, pre-processes these initial internal and external data to obtain processed network data; constructs an initial attack model based on adversarial network technology and optimizes to determine the target attack model, constructs an initial defense model based on the target knowledge graph and optimizes to determine the target defense model; inputs the target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configures the strategy to the target security device to obtain a post-defense security device, and then inputs the target attack data and target traffic data in the processed network data into the target attack model to output the target attack strategy; uses the target attack strategy to attack the post-defense security device to obtain the target vulnerability, analyzes the vulnerability to obtain the target repair strategy, performs sandbox verification on the target vulnerability and the target repair strategy to obtain the verification result, and finally executes the target repair strategy based on the verification result. In this way, through multi-source data collection and processing, the attack and defense model is constructed and optimized, the corresponding strategy is generated, the vulnerability is discovered through attack and defense verification, and the sandbox verification is repaired, forming a closed-loop protection, improving the level of network security protection, and ensuring the security and stability of cyberspace. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0050] Figure 1 This is a diagram of the vulnerability repair system architecture disclosed in this application;

[0051] Figure 2 A flowchart of a vulnerability repair method disclosed in this application;

[0052] Figure 3 A flowchart of a specific vulnerability repair method disclosed in this application;

[0053] Figure 4 This is a schematic diagram of the structure of a vulnerability repair device disclosed in this application;

[0054] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0056] At present, traditional network security defense technologies mainly include firewalls, intrusion detection systems, intrusion prevention systems, and antivirus software. In the process of network security risk detection and defense, there are still problems such as high degree of manual dependence and slow response speed. At the same time, with the continuous expansion of network scale and the rapid evolution of attack methods, the efficiency and accuracy of manual processing of massive security data are difficult to meet actual needs, and potential security risks and weak links in the defense system cannot be discovered in time. In addition, traditional defense strategies are usually formulated based on fixed rules and historical experience, and it is difficult to dynamically adjust according to real-time network security situation and attack changes. In order to solve the above technical problems, the present application discloses a vulnerability repair method, device, equipment and storage medium, which can improve the level of network security protection and ensure the security and stability of cyberspace.

[0057] like Figure 1As shown, this application adopts a layered architecture design, which is divided into 4 layers, including attack simulation and vulnerability detection module, multi-source data acquisition module, defense strategy configuration module, and automatic repair module. The modules realize data interaction and collaborative work through standardized interfaces. The main function of the multi-source data acquisition module is to intelligently collect and pre-process multi-source data. The attack simulation and vulnerability detection module adopts a closed-loop attack-defense confrontation architecture. It simulates real attack scenarios by training attack models, and detects and analyzes system vulnerabilities in combination with defense models to form a complete "attack-detection-analysis" link. The defense strategy configuration module builds a dynamic strategy generation system based on the output results of the defense model and real-time network environment information, which is responsible for converting the analysis results of the defense model into feasible protection measures. The automatic repair module performs comprehensive analysis based on vulnerability characteristics and system context. Build a solution decision model and integrate multiple repair strategies.

[0058] See also Figure 2 As shown, an embodiment of the present invention discloses a vulnerability repair method, including:

[0059] Step S11: collect initial external data from a preset vulnerability database and a preset security information website using web crawler technology, and obtain initial internal traffic data using preset port mirroring technology and traffic probe technology, and pre-process the initial external data and the initial internal traffic data to obtain processed network data.

[0060] In this embodiment, when acquiring initial external network data, relevant data can be crawled by accessing the API of a mainstream threat intelligence platform. The initial external data includes initial external network attack data and initial external network vulnerability data. It is important to note that a preset software development kit (SDK) is used to determine attack indicators in a preset format based on a preset security information website; a preset API is used to collect initial external network attack data based on the attack indicators in the preset format; and web crawler technology is used to collect initial external network vulnerability data from a preset vulnerability database. Specifically, when acquiring external network attack data, attack indicators in STIX (Structured Threat Information Expression) format can be obtained through the SDK (Software Development Kit); OTX Python APIs can also be used to synchronize malicious IP addresses, domain names, file hashes, and other data; and advanced persistent threat intelligence can also be obtained through REST APIs. An incremental synchronization algorithm is used to retrieve only updated data based on timestamp comparison. An exponential backoff retry strategy is implemented to handle API call failures and ensure data integrity. When acquiring initial external vulnerability data, the system automatically synchronizes with official vulnerability repositories such as CVE (Common Vulnerabilities & Exposures) to obtain vulnerability descriptions, CVSS (Common Vulnerability Scoring System) scores, and exploit code. Furthermore, the system uses web crawler technology to monitor vendor security announcements, capture zero-day vulnerability warnings in real time, and receive real-time notifications of security patch releases.

[0061] In this embodiment, when acquiring initial internal traffic data, a target data collection method is determined using a preset port mirroring technology; the initial internal traffic data is acquired using the target data collection method according to the traffic probe technology; wherein, the acquisition of initial internal traffic data using the target data collection method according to the traffic probe technology includes: acquiring first internal traffic data using zero-copy technology according to the traffic probe technology; acquiring second internal traffic data that meets sensitive information conditions using deep packet inspection technology according to the traffic probe technology; determining a network session graph using session-level behavior analysis technology according to the traffic probe technology, and acquiring third internal traffic data based on the network session graph; and integrating the first internal traffic data, the second internal traffic data, and the third internal traffic data to generate initial internal traffic data. Specifically, by using traffic mirroring technology, multiple traffic mirroring methods such as SPAN (Switched Port Analyzer) ports are supported to achieve full traffic non-perceptual collection. Zero-copy technology is used to optimize traffic capture efficiency in high-concurrency scenarios, ensuring line-speed processing of traffic above 10Gbps and obtaining the first internal traffic data. By using deep packet inspection technology, application layer protocols can be identified based on regular expressions, sensitive information in the payload can be extracted, and private keys are required to parse potential attack behaviors in encrypted communications, i.e., the second internal traffic data. By using session-level behavior analysis technology, a network session graph can be constructed, recording multi-dimensional features such as source IP, destination IP, port, duration, and traffic size, i.e., the third internal traffic data, to identify abnormal session patterns.

[0062] Next, unified data preprocessing is required. First, a data normalization framework is constructed. Based on this framework, the initial external data and initial internal traffic data are mapped to standard fields to generate standardized data. Abnormal data in the standardized data is then removed using the isolation forest algorithm to determine the processed network data. Specifically, a unified data model is defined to map data from different sources to standard fields. Multi-threaded parallel processing is also supported to ensure the standardization of millions of logs per second and the efficiency of data preprocessing. After the data normalization framework is constructed, a feature engineering pipeline is constructed. Statistical features such as the number of connections and traffic peaks within a time window are extracted as time series features. Graph features such as node degree centrality and clustering coefficient are extracted and calculated as network topology features. Word embedding is performed on the log content, which is converted into vector representations as text features to generate standardized data. For abnormal data in the standardized data, an isolation forest algorithm is used to detect and filter outliers. By constructing multiple isolation trees and calculating the path length for each data point, noise and erroneous data are effectively removed to determine the processed network data, ensuring the purity of the training data. Furthermore, data desensitization is implemented to protect user privacy while preserving security features.

[0063] Step S12: construct an initial attack model based on adversarial network technology, optimize the initial attack model to determine the target attack model, then construct an initial defense model based on the target knowledge graph, and optimize the initial defense model to determine the target defense model.

[0064] In this embodiment, to construct an initial attack model, preset attack rules can be determined based on preset attack patterns. Initial weak classifiers are obtained and then iterated using a preset loss function based on preset training data to determine a target classifier. The initial attack model is then constructed based on the preset attack rules, the target classifier, and a preset deep learning model. Specifically, when constructing the attack model, the attack model is divided into three layers. The first layer is the rule-driven layer. This layer is built based on the knowledge and experience of network security experts. Common attack patterns are summarized into clear rules. For example, for SQL (Structured Query Language) injection attacks, rules are set to detect whether the input string contains specific SQL keywords and their combination patterns. For DDoS (Distributed Denial of Service) attacks, rules are used to determine whether the number of requests from the same IP address or IP segment per unit time exceeds a normal threshold. These rules can quickly identify attack behaviors that match known patterns, providing a foundation for attack detection. They offer fast response times and high accuracy, making them suitable for handling a large number of common attacks. The second layer is the machine learning layer. The machine learning layer uses traditional machine learning algorithms such as gradient boosting trees to iteratively train multiple weak classifiers and gradually fit the residuals of the previous round:

[0065] ;

[0066] in, is the prediction model of the gradient boosting model for the input x after the mth iteration; is the learning rate; To find the function h that minimizes the sum of subsequent loss functions; It is an incremental model; is the true label of the i-th training sample; is the feature input of the i-th training sample; L is the loss function.

[0067] By training on a large amount of labeled attack data, the model learns the differences in characteristics between attack behavior and normal network behavior. For example, it extracts features such as source IP address, destination IP address, port number, packet size, and transmission time interval from network traffic data, and trains the model to identify attack behaviors with specific feature combinations. These algorithms are capable of processing structured data and effectively identifying behaviors that vary from known attacks. This complements the rule-driven layer's shortcomings in addressing variant attacks and enhances the model's generalization capabilities. The third layer is the deep learning layer. This layer utilizes deep learning models such as long-short-term memory networks and Transformers. Because network attack behaviors often exhibit sequential and contextual dependencies, deep learning models excel at processing sequential data and can automatically learn patterns and regularities in attack behavior over time. The initial attack model is constructed based on the pre-set attack rules, target classifiers, and pre-set deep learning models derived from these three layers.

[0068] Furthermore, after the initial attack model is constructed, it is necessary to further optimize it through reinforcement learning. The attack process is abstracted into a Markov decision process, defined as a four-tuple (S, A, P, R), where S is the state space, representing the network environment state; A is the action space, representing the optional attack strategy; is the state transition probability, which means the probability of transitioning to state S' after executing action a in state S; is the reward function, which represents the reward value obtained after executing action a from state S and transferring to state S'. The next state reached by S after executing action a, also known as the successor state, is represented by S as the current state and a as the executed action. The initial attack model is optimized using a reinforcement learning algorithm. Each time the initial attack model executes an attack action, it receives corresponding reward or penalty feedback based on the attack outcome. For example, successful penetration of the target system receives a high reward, while being blocked by the defense system receives a negative reward. Through continuous trial and learning, the attack strategy is adjusted, enabling the attack model to automatically select the optimal attack path and method in complex and changing network environments, ultimately achieving the target attack model.

[0069] In this embodiment, in order to construct an initial defense model, first, the inventory of the target security device, vulnerability library information and historical attack path data are integrated to construct a target knowledge graph; the target knowledge graph is analyzed by using a graph neural network to obtain a corresponding analysis result; corresponding topological level defense rules are generated according to the analysis result; and an initial defense model is constructed based on the topological level defense rules. Specifically, first, the network asset inventory, vulnerability library information and historical attack path data are integrated to construct a network security knowledge graph containing target entities and entity relationships. For example, a certain web server is marked as an asset entity, and its existing SQL injection vulnerability is marked as a vulnerability entity, and the two are connected through a "affected" relationship; at the same time, the path information of the attacker launching an attack by using the vulnerability is recorded to form a complete knowledge network. Then, the node embedding and graph convolution technology of GNN (Graph Neural Network, graph neural network) are used, and the system can deeply mine the hidden associations in the knowledge graph. For example, by analyzing, it is found that a certain type of vulnerability has a propagation rule under a specific network topology, or a potential path of an attacker attacking by using a combination of multiple vulnerabilities is identified. In the specific process, GNN updates the node features by iteration, learns the dependency relationship between nodes, and then infers the complex relationship between vulnerabilities, assets and attacks. Based on the analysis result of GNN, the system automatically generates topological level defense rules. For example, when it is detected that there are multiple unpatched remote code execution vulnerabilities in a certain subnet, and the subnet is connected to a core database, a rule of "blocking unnecessary port connections between the subnet and the database" is automatically generated; if a SQL injection attack pattern is identified, a strategy of "prohibiting related IP access to the database port and strictly filtering the input of the web application" is immediately generated. These rules cover the network layer, application layer and data layer, forming multi-level protection.

[0070] It can be understood that the defense model can be evaluated and optimized for defense effect by receiving feedback data. The defense effect is evaluated by defining multi-dimensional evaluation indexes, including:

[0071] Detection rate: detection rate = number of correctly identified attacks / actual number of attacks × 100%.

[0072] False positive rate: false positive rate = number of normal events incorrectly identified as attacks / total number of normal events × 100%.

[0073] Response time: defined as the time interval from the occurrence of an attack to the effectiveness of a defense measure, in seconds.

[0074] Attack blocking rate: attack blocking rate = number of attacks successfully blocked / number of attacks detected × 100%.

[0075] Additionally, when new attacks or defense failures are detected, model retraining is automatically triggered. For example, if a ransomware variant emerges that isn't blocked by the defense strategy, the system incorporates the new sample into the training set, adjusts the machine learning model parameters, and optimizes the rule generation logic to ensure the model quickly adapts to new threats.

[0076] Step S13: input the target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configure the target defense strategy on the target security device to obtain a defended security device, and then input the target attack data and target traffic data in the processed network data into the target attack model to output the target attack strategy.

[0077] In this embodiment, target vulnerability data is first extracted from processed network data and input into a target defense model. The target defense model generates targeted defense strategies based on vulnerability type, location, and hazard level, combined with its own algorithmic logic or a built-in security rule base. These targeted defense strategies are then deployed to target security devices, such as firewalls, intrusion prevention systems, and web application firewalls. These strategies are then transmitted to the target security devices via a pre-set interface protocol, allowing them to execute the strategies and become post-defense security devices. Specifically, standardized APIs are used to enable communication and interaction with various target security devices. The generated target defense strategies are then distributed to the target security devices in a standardized format via a unified interface protocol, ensuring compatibility and consistency across devices from different vendors and types. The configured target security devices become post-defense security devices, equipped with protection capabilities for identified vulnerabilities and capable of intercepting, detecting, or responding to threats within the network according to the defense strategies. This completes the closed loop of protection from vulnerability discovery to defense development and implementation, building a foundational line of defense for network security.

[0078] Furthermore, the targeted attack data and target traffic data are extracted from the processed network data and fed into the targeted attack model. The targeted attack data includes information such as the attack source IP address, attack method, and attack frequency, while the target traffic data reflects network traffic volume, protocol type, port distribution, and other characteristics. The targeted attack model analyzes these data to predict possible attack paths, methods, and intensity, and then outputs a targeted attack strategy.

[0079] Step S14: Use the target attack strategy to attack the post-defense security device to obtain a target vulnerability, analyze the target vulnerability to obtain a target repair strategy, perform a sandbox verification operation on the target vulnerability and the target repair strategy to obtain a corresponding verification result, and execute the target repair strategy based on the verification result.

[0080] In this embodiment, a generated targeted attack strategy is used to launch a simulated attack against the post-defense security device. Following the path, methods, and cadence planned in the targeted attack strategy, the post-defense security device, already equipped with the defense strategy, is tested. This attack operation discovers target vulnerabilities that remain in the post-defense security device and are not covered by the existing defense strategy. Once the target vulnerability is identified, an in-depth analysis is conducted on the vulnerability's characteristics, causes, impact, and potential exploitation methods. Multiple remediation strategies, such as patch deployment, configuration adjustments, emergency response strategies, and service degradation, are integrated to develop a corresponding targeted remediation strategy. Subsequently, a sandbox validation operation is performed on the target vulnerability and the targeted remediation strategy. The sandbox, as an isolated testing environment, simulates real-world network scenarios without impacting actual business systems. Within the sandbox, the environment in which the target vulnerability exists is replicated. The targeted remediation strategy is then applied, and the corresponding attack test is re-initiated to observe whether the vulnerability is successfully blocked, whether the remediation strategy effectively protects against the attack, and whether the remediation operation has any unintended impact on the system's normal functionality and performance, such as causing legitimate data packets to be intercepted or significantly reducing system response speed. Through such verification, verification results can be obtained that include repair effects, potential side effects, compatibility issues, etc.

[0081] Finally, the target remediation strategy is executed based on the verification results. If the verification results show that the remediation strategy can completely block the vulnerability and has no adverse impact on the normal operation of the system, then the remediation strategy will be officially deployed to the actual network security equipment; if the verification process finds that the remediation strategy has defects, such as only partially resisting attacks, or causing new compatibility issues, then it is necessary to adjust and optimize the remediation strategy based on the verification results, and then perform sandbox verification again until the ideal verification results are obtained before actual deployment. This entire process forms a closed loop of "attack to discover vulnerabilities → analysis and formulation of repairs → sandbox verification → implementation", ensuring that each remediation strategy can accurately and effectively resolve vulnerability problems, while minimizing interference with existing systems and continuously improving the reliability and stability of network security protection.

[0082] As can be seen from the above, the embodiment of the present application collects initial external data from a preset vulnerability database and a preset security information website through network crawler technology, and at the same time uses preset port mirroring technology and traffic probe technology to obtain initial internal traffic data, pre-processes these initial internal and external data to obtain processed network data; constructs an initial attack model based on adversarial network technology and optimizes to determine the target attack model, constructs an initial defense model based on the target knowledge graph and optimizes to determine the target defense model; inputs the target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configures the strategy to the target security device to obtain a post-defense security device, then inputs the target attack data and target traffic data in the processed network data into the target attack model to output the target attack strategy; uses the target attack strategy to attack the post-defense security device to obtain the target vulnerability, analyzes the vulnerability to obtain the target repair strategy, performs sandbox verification operation on the target vulnerability and the target repair strategy to obtain the verification result, and finally executes the target repair strategy based on the verification result. In this way, through multi-source data collection and processing, the attack and defense model is constructed and optimized, the corresponding strategy is generated, the vulnerability is discovered through attack and defense verification, and the vulnerability is repaired after sandbox verification, forming a closed-loop protection, improving the level of network security protection, and ensuring the security and stability of cyberspace.

[0083] Based on the above embodiment, it can be seen that the present application discloses a vulnerability repair method that can improve the level of network security protection and ensure the security and stability of the network space. Figure 3 The following describes in detail how to fix the vulnerability shown.

[0084] First, this application uses web crawler technology to collect initial external attack data from a pre-set security information website and initial external vulnerability data from a pre-set vulnerability database. Furthermore, traffic mirroring technology is used to identify multiple traffic data collection methods, and initial internal traffic data is obtained through these data collection methods. The obtained initial external attack data, initial external vulnerability data, and initial internal traffic data are uniformly preprocessed using a data standardization framework to obtain processed network data.

[0085] Then, adversarial network technology is used to build an initial attack model, which is then optimized to determine the target attack model. At the same time, an initial defense model is constructed based on the target knowledge graph, and then the target defense model is obtained through optimization.

[0086] Next, target vulnerability data is extracted from the processed network data and fed into a target defense model to generate a targeted defense strategy. These targeted defense strategies are then deployed on the target security devices, enabling them to execute the targeted defense strategies and thus create a defended security device. Target attack data and target traffic data are also extracted from the processed network data and fed into the target attack model. The target attack model analyzes these data, predicts possible attack paths, methods, and intensities, and then outputs a targeted attack strategy.

[0087] Finally, the generated targeted attack strategy is used to launch a simulated attack against the protected security device, identifying any remaining target vulnerabilities not covered by the existing defense strategy. Once the target vulnerability is identified, an in-depth analysis is conducted on its characteristics, causes, scope of impact, and potential exploitation methods, leading to the development of a corresponding targeted remediation strategy. The target vulnerability and the targeted remediation strategy are then verified in a sandbox. If the verification process reveals flaws in the remediation strategy, the remediation strategy is adjusted and optimized based on the verification results. If the verification results indicate that the remediation strategy can completely block the vulnerability, the targeted remediation strategy is executed.

[0088] See also Figure 4 As shown, an embodiment of the present invention discloses a vulnerability repair device, comprising:

[0089] a data acquisition module 11 for collecting initial external data from a preset vulnerability database and a preset security information website using a web crawler technique, obtaining initial internal traffic data using a preset port mirroring technique and a traffic probe technique, and preprocessing the initial external data and the initial internal traffic data to obtain processed network data;

[0090] A model determination module 12 is configured to construct an initial attack model based on adversarial network technology, optimize the initial attack model to determine a target attack model, then construct an initial defense model based on a target knowledge graph, and optimize the initial defense model to determine a target defense model;

[0091] a policy output module 13, configured to input the target vulnerability data in the processed network data into the target defense model to generate a target defense policy, configure the target defense policy on the target security device to obtain a defended security device, and then input the target attack data and target traffic data in the processed network data into the target attack model to output a target attack policy;

[0092] The policy execution module 14 is used to use the target attack strategy to attack the post-defense security device to obtain the target vulnerability, analyze the target vulnerability to obtain the target repair strategy, perform sandbox verification operations on the target vulnerability and the target repair strategy to obtain corresponding verification results, and execute the target repair strategy based on the verification results.

[0093] As can be seen from the above, this application collects initial external data from a preset vulnerability database and a preset security information website through web crawler technology, and uses preset port mirroring technology and traffic probe technology to obtain initial internal traffic data, pre-processes these initial internal and external data to obtain processed network data; constructs an initial attack model based on adversarial network technology and optimizes to determine the target attack model, constructs an initial defense model based on the target knowledge graph and optimizes to determine the target defense model; inputs the target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configures the strategy to the target security device to obtain a post-defense security device, and then inputs the target attack data and target traffic data in the processed network data into the target attack model to output the target attack strategy; uses the target attack strategy to attack the post-defense security device to obtain the target vulnerability, analyzes the vulnerability to obtain the target repair strategy, performs sandbox verification on the target vulnerability and the target repair strategy to obtain the verification result, and finally executes the target repair strategy based on the verification result. In this way, through multi-source data collection and processing, the attack and defense model is constructed and optimized, the corresponding strategy is generated, the vulnerability is discovered through attack and defense verification, and the sandbox verification is repaired, forming a closed-loop protection, improving the level of network security protection, and ensuring the security and stability of cyberspace.

[0094] In some specific implementations, the initial external data includes initial external network attack data and initial external network vulnerability data;

[0095] Accordingly, the data acquisition module 11 may specifically include:

[0096] an attack indicator determination unit, configured to determine an attack indicator in a preset format based on a preset security information website using a preset software development toolkit;

[0097] An attack data collection unit, configured to collect initial external network attack data according to the attack indicator in the preset format using a preset API;

[0098] The vulnerability data collection unit is used to collect initial external network vulnerability data from a preset vulnerability database through network crawler technology.

[0099] In some specific implementations, the data acquisition module 11 may specifically include:

[0100] A collection mode determination unit, configured to determine a target data collection mode using a preset port mirroring technology;

[0101] A flow data acquisition unit, configured to acquire initial internal flow data using the target data acquisition method according to flow probe technology;

[0102] The flow data acquisition unit may specifically include:

[0103] A first internal traffic data acquisition subunit is configured to acquire first internal traffic data using a zero-copy technology based on a traffic probe technology;

[0104] A second internal traffic data acquisition subunit is configured to acquire second internal traffic data meeting the sensitive information condition by using a deep packet inspection technology based on a traffic probe technology;

[0105] a third internal traffic data acquisition subunit, configured to determine a network session graph using a session-level behavior analysis technology based on the traffic probe technology, and acquire third internal traffic data based on the network session graph;

[0106] The initial internal flow data generating subunit is configured to integrate the first internal flow data, the second internal flow data, and the third internal flow data to generate initial internal flow data.

[0107] In some specific implementations, the data acquisition module 11 may specifically include:

[0108] a standardized data generating unit, configured to construct a data standardization framework, and map the initial external data and the initial internal traffic data to standard fields according to the data standardization framework to generate standardized data;

[0109] The processed network data determining unit is configured to eliminate abnormal data in the standardized data according to an isolation forest algorithm to determine processed network data.

[0110] In some specific implementations, the model determination module 12 may specifically include:

[0111] A preset attack rule determining unit, configured to determine a preset attack rule based on a preset attack mode;

[0112] A target classifier determination unit is used to obtain an initial weak classifier, and iterate the initial weak classifier using a preset loss function based on preset training data to determine a target classifier;

[0113] An initial attack model construction unit is used to construct an initial attack model according to the preset attack rules, the target classifier and the preset deep learning model.

[0114] In some specific implementations, the model determination module 12 may specifically include:

[0115] A knowledge graph construction unit, configured to integrate the list of target security devices, vulnerability database information, and historical attack path data to construct a target knowledge graph;

[0116] A result acquisition unit, configured to analyze the target knowledge graph using a graph neural network to obtain corresponding analysis results;

[0117] A rule generating unit, configured to generate corresponding topology-level defense rules according to the analysis results;

[0118] The initial defense model building unit is used to build an initial defense model based on the topology-level defense rules.

[0119] In some specific implementations, the strategy output module 13 may specifically include:

[0120] The security device acquisition unit is configured to send the target defense policy to the target security device via a preset interface protocol, so that the target security device executes the target defense policy to obtain a defensed security device.

[0121] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 5 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram should not be considered as any limitation to the scope of application of the present application.

[0122] Figure 5 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the vulnerability remediation method disclosed in any of the aforementioned embodiments. Furthermore, the electronic device 20 in this embodiment may be a computer.

[0123] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0124] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0125] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, and can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of implementing the vulnerability repair method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program capable of completing other specific tasks.

[0126] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the vulnerability repair method disclosed above is implemented. For the specific steps of this method, please refer to the corresponding content disclosed in the above embodiments and will not be repeated here.

[0127] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0128] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0129] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0130] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0131] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A vulnerability repair method, characterized in that: include: Collecting initial external data from a preset vulnerability database and a preset security information website using web crawler technology, obtaining initial internal traffic data using preset port mirroring technology and traffic probe technology, and preprocessing the initial external data and the initial internal traffic data to obtain processed network data; Constructing an initial attack model based on adversarial network technology, optimizing the initial attack model to determine a target attack model, then constructing an initial defense model based on a target knowledge graph, and optimizing the initial defense model to determine a target defense model; Inputting target vulnerability data in the processed network data into the target defense model to generate a target defense strategy, configuring the target defense strategy on a target security device to obtain a defended security device, and then inputting target attack data and target traffic data in the processed network data into the target attack model to output a target attack strategy; The target attack strategy is used to attack the post-defense security device to obtain a target vulnerability, the target vulnerability is analyzed to obtain a target repair strategy, a sandbox verification operation is performed on the target vulnerability and the target repair strategy to obtain a corresponding verification result, and the target repair strategy is executed based on the verification result.

2. The vulnerability repair method according to claim 1, characterized in that: The initial external data includes initial external network attack data and initial external network vulnerability data; Accordingly, the initial external data collected from the preset vulnerability database and the preset security information website by using the web crawler technology includes: Determine attack indicators in a pre-defined format based on a pre-defined security information website through a pre-defined software development kit; Using a preset API to collect initial external network attack data according to the attack indicator in the preset format; Initial external network vulnerability data is collected from the preset vulnerability database through web crawler technology.

3. The vulnerability repair method according to claim 1, characterized in that: The method of obtaining initial internal traffic data by using the preset port mirroring technology and the traffic probe technology includes: Use preset port mirroring technology to determine the target data collection method; Acquiring initial internal flow data using the target data acquisition method according to flow probe technology; Wherein, the obtaining of initial internal flow data using the target data collection method according to the flow probe technology includes: Acquire first internal traffic data using zero-copy technology according to traffic probe technology; Acquire second internal traffic data that meets the sensitive information condition through deep packet inspection technology based on traffic probe technology; determining a network session graph using a session-level behavior analysis technique based on the traffic probe technique, and obtaining third internal traffic data based on the network session graph; The first internal flow data, the second internal flow data, and the third internal flow data are integrated to generate initial internal flow data.

4. The vulnerability repair method according to claim 1, characterized in that: The preprocessing of the initial external data and the initial internal traffic data to obtain processed network data includes: Building a data standardization framework, and mapping the initial external data and the initial internal traffic data to standard fields according to the data standardization framework to generate standardized data; Abnormal data in the standardized data is removed according to the isolation forest algorithm to determine processed network data.

5. The vulnerability repair method according to claim 1, characterized in that: The initial attack model is constructed based on the adversarial network technology, including: Determining a preset attack rule based on a preset attack pattern; Obtain an initial weak classifier, and iterate the initial weak classifier using a preset loss function based on preset training data to determine a target classifier; An initial attack model is constructed according to the preset attack rules, the target classifier and the preset deep learning model.

6. The vulnerability repair method according to claim 1, characterized in that: The initial defense model is constructed based on the target knowledge graph, including: Integrate the target security device inventory, vulnerability database information, and historical attack path data to build a target knowledge graph; Analyze the target knowledge graph using a graph neural network to obtain corresponding analysis results; Generate corresponding topology-level defense rules according to the analysis results; An initial defense model is constructed based on the topology-level defense rules.

7. The vulnerability repair method according to claim 1, characterized in that: The step of configuring the target defense policy on a target security device to obtain a defensed security device includes: The target defense strategy is sent to the target security device through a preset interface protocol, so that the target security device executes the target defense strategy to obtain a defense-posted security device.

8. A vulnerability repair device, characterized in that: include: a data acquisition module for collecting initial external data from a preset vulnerability database and a preset security information website using a web crawler technology, acquiring initial internal traffic data using a preset port mirroring technology and a traffic probe technology, and preprocessing the initial external data and the initial internal traffic data to obtain processed network data; A model determination module is used to construct an initial attack model based on adversarial network technology, optimize the initial attack model to determine a target attack model, then construct an initial defense model based on a target knowledge graph, and optimize the initial defense model to determine a target defense model; a policy output module, configured to input target vulnerability data in the processed network data into the target defense model to generate a target defense policy, configure the target defense policy on a target security device to obtain a defended security device, and then input target attack data and target traffic data in the processed network data into the target attack model to output a target attack policy; A policy execution module is used to use the target attack strategy to attack the post-defense security device to obtain a target vulnerability, analyze the target vulnerability to obtain a target repair strategy, perform a sandbox verification operation on the target vulnerability and the target repair strategy to obtain a corresponding verification result, and execute the target repair strategy based on the verification result.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the vulnerability repair method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the vulnerability repair method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Network security attack and defense method and device and storage medium

    CN113259392A

  • Network security protection method and system based on digital twin technology

    CN120602133A