Automatic vulnerability grading and handling method

By implementing vulnerability classification models and automated processes on the operation platform, the problems of automation and inaccurate classification in vulnerability management have been solved, improving the efficiency and accuracy of vulnerability management and adapting to the personalized needs of enterprises.

CN120856404APending Publication Date: 2025-10-28BEIYIN FINANCIAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511009802.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing technologies lack sufficient automation in vulnerability management processes and a personalized grading mechanism, resulting in insufficient response timeliness and inaccurate grading, which fails to meet the complex security management needs of modern enterprises.

Method used

By inputting vulnerability rating models into the operation platform and combining them with vulnerability scanning equipment, an automated vulnerability risk rating and handling process can be achieved, including automated rating, assessment, expert confirmation, task assignment, and automatic re-verification, thus building a personalized vulnerability management closed loop.

Benefits of technology

It improves the efficiency and accuracy of vulnerability management, automates the entire process from vulnerability discovery to remediation verification, reduces the cost of manual intervention, and adapts to the personalized security needs of enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856404A_ABST
    Figure CN120856404A_ABST
Patent Text Reader

Abstract

The invention discloses an automatic vulnerability grading and handling method. The grading and handling method comprises the following steps: acquiring parameters input into a vulnerability grading model by a security operator on an operation platform; the operation platform calls scanning missing equipment to discover vulnerabilities; the operation platform completes automatic grading based on the vulnerability risk value according to the vulnerability grading model; the security operator carries out research and judgment analysis on vulnerabilities, judges whether false alarms exist or not, and if yes, ends the process; if not, executing the next step; the security expert confirms the vulnerability level and submits processing suggestions together; the vulnerability is issued to an asset responsible person corresponding to the asset; and the operation platform determines whether the vulnerability is overdue or not through a timed task, and if yes, the department leader of the asset responsible person is notified. And the efficiency and accuracy of vulnerability management are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of enterprise network security, and in particular to a method for automated vulnerability classification and handling. Background Technology

[0002] In today's rapidly evolving technological landscape, enterprises face increasingly complex and diverse security threats, making security operations a crucial element for their stable development. By establishing a systematic vulnerability management system—including conducting regular comprehensive vulnerability scans, timely risk assessments, developing and implementing remediation plans, and continuously monitoring and optimizing security—enterprises can build a multi-layered security protection system. This effectively reduces security risks and ensures the security of information systems and core data assets. This proactive defense strategy not only enhances an enterprise's security capabilities but also helps establish a long-term security operation mechanism, providing a solid guarantee for the enterprise's sustainable development.

[0003] In today's enterprise cybersecurity practices, vulnerability scanning devices have become indispensable security management tools. Enterprises typically deploy one or more vulnerability scanning solutions based on their asset types and security needs to build a comprehensive security protection system. These devices can systematically scan network assets to identify potential security vulnerabilities and weaknesses.

[0004] The existing technical solutions have the following two main limitations:

[0005] 1. Insufficient automation in vulnerability handling processes

[0006] The current solution suffers from significant efficiency bottlenecks in the vulnerability management closed loop. Throughout the entire lifecycle, from vulnerability identification and risk assessment to remediation verification, it relies excessively on manual intervention: security personnel need to manually assess risks, coordinate remediation efforts, and initiate secondary scans for verification. This non-automated processing mode leads to insufficient response time, prolongs vulnerability exposure time, and increases the enterprise's security risk exposure. Simultaneously, the lack of an intelligent remediation verification mechanism necessitates repeated manual confirmation of vulnerability remediation status, reducing overall security operation efficiency.

[0007] 2. The vulnerability rating mechanism lacks personalized adaptation.

[0008] Existing solutions generally adopt a uniform vulnerability rating standard, failing to fully consider the personalized security needs of enterprises. In fact, different enterprises have significantly different risk assessment standards for vulnerabilities based on factors such as their business characteristics (e.g., differences in industries such as finance, healthcare, and manufacturing), system architecture (cloud environment, hybrid architecture, traditional IDC, etc.), and network policies (internet exposure surface, degree of internal network isolation). A uniform rating standard may lead to the underestimation of critical vulnerabilities or the overemphasis on non-critical vulnerabilities, failing to effectively support enterprises' precise security decisions.

[0009] The limitations highlight the shortcomings of existing solutions in terms of automation and customization capabilities, making it difficult to meet the increasingly complex safety management needs of modern enterprises. Summary of the Invention

[0010] In view of the above problems, the present invention is proposed to provide an automated vulnerability classification and handling method to overcome or at least partially solve the above problems.

[0011] According to one aspect of the present invention, an automated vulnerability classification and handling method is provided, the classification and handling method comprising:

[0012] Obtain the parameters that security operations personnel enter into the vulnerability rating model on the operations platform;

[0013] The operations platform uses vulnerability scanning equipment to discover vulnerabilities;

[0014] The operation platform completes automated vulnerability risk assessment based on the vulnerability risk value according to the vulnerability assessment model;

[0015] Security operations personnel analyze and assess the vulnerabilities to determine if they are false alarms. If so, the process ends; otherwise, the process proceeds to the next step.

[0016] Security experts confirmed the vulnerability level and submitted their proposed solutions.

[0017] The vulnerability was reported to the person responsible for the asset.

[0018] The operations platform uses a scheduled task to determine if a vulnerability has expired. If it has, the department head responsible for the assets will be notified.

[0019] Optionally, after notifying the department head responsible for the assets, the process may also include:

[0020] After receiving the overdue reminder, the department leader will forward the reminder to the person responsible for the assets.

[0021] After the person responsible for the assets has completed the disposal, they should submit feedback on the platform.

[0022] The operations platform performs automated vulnerability verification; once the verification is successful, the process ends.

[0023] If the re-inspection fails, the asset will be reissued to the person responsible for the assets until the re-inspection is passed.

[0024] Optionally, after the asset responsible person completes the disposal and submits it on the platform, the platform will automatically initiate a re-verification of the vulnerability by calling the corresponding vulnerability scanning device API interface based on the vulnerability data source.

[0025] Optionally, the re-verification of the vulnerability specifically includes:

[0026] After the asset manager has fixed the vulnerability, they should click the "Fix Complete" button on the platform.

[0027] The platform calls the vulnerability scanning API interface of the corresponding vulnerability scanning device based on the source of the vulnerability data;

[0028] Obtain all vulnerability information for the asset IP where the original vulnerability is located;

[0029] The data is compared with the original vulnerability data to determine if the original vulnerability exists. If it does not exist, the verification is successful; if it exists, feedback is sent to the person responsible for the assets.

[0030] Optionally, the processing method further includes:

[0031] The platform is configured with the necessary information to access the vulnerability scanning device. The vulnerability scanning interface of the vulnerability scanning device is called through a scheduled task or manually. The vulnerability scanning interface needs to be executed for a long time.

[0032] After obtaining the vulnerabilities identified by the vulnerability scanning device by querying the scan results through scheduled tasks, the platform reclassifies the vulnerabilities according to the configured vulnerability risk value calculation formula.

[0033] The vulnerability will be displayed on the page, along with its current status.

[0034] Optionally, the necessary information for the vulnerability scanning device includes: device name, device address, access username, and password.

[0035] This invention provides an automated vulnerability classification and handling method. The method includes: acquiring parameters from a vulnerability classification model entered by security operations personnel on an operations platform; the operations platform using a vulnerability scanning device to discover vulnerabilities; the operations platform automatically classifying vulnerabilities based on their risk values ​​according to the vulnerability classification model; security operations personnel analyzing the vulnerabilities to determine if they are false positives; if so, the process ends; if not, the process continues to the next step; security experts confirm the vulnerability level and submit their handling recommendations; the vulnerability is distributed to the asset manager responsible for the asset; the operations platform uses a scheduled task to determine if the vulnerability has expired; if so, the department head of the asset manager is notified. This method effectively improves the efficiency and accuracy of vulnerability management.

[0036] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0037] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 A flowchart illustrating an automated vulnerability classification and handling method provided in this embodiment of the invention;

[0039] Figure 2 A flowchart of a vulnerability verification method provided in an embodiment of the present invention. Detailed Implementation

[0040] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0041] The terms "comprising" and "having," and any variations thereof, in the specification, embodiments, claims, and drawings of this invention are intended to cover non-exclusive inclusion, such as including a series of steps or units.

[0042] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0043] like Figure 1 As shown, an automated vulnerability classification and handling method includes:

[0044] Security operations personnel input parameters from the vulnerability rating model into the operations platform;

[0045] The operations platform uses vulnerability scanning equipment to discover vulnerabilities;

[0046] The operation platform completes automated vulnerability rating based on vulnerability risk value (RS) according to the vulnerability rating model;

[0047] Security operations personnel analyze and assess the vulnerabilities to determine if they are false alarms. If so, the process ends; otherwise, the process proceeds to the next step.

[0048] Security experts confirmed the vulnerability level and submitted their proposed solutions.

[0049] The vulnerability was reported to the person responsible for the asset.

[0050] The operations platform uses scheduled tasks to determine if a vulnerability has expired. If it has, the platform is responsible for notifying the department head of the person in charge of the assets.

[0051] After receiving the overdue reminder, the department leader will forward the reminder to the person responsible for the assets.

[0052] After the person responsible for the assets has completed the disposal, they should submit feedback on the platform.

[0053] The operations platform performs automated verification of vulnerabilities. If the verification passes, the process ends; if the verification fails, the vulnerability is reissued to the asset manager until it passes.

[0054] The formula for calculating the risk score in the vulnerability definition model is as follows:

[0055] RS=(CVSS×Wcvss)+(A×Wa)+(E×We)+(C×Wc)

[0056] Wherein: CVSS: Baseline Risk Value, i.e., the CVSS v3.1 baseline score (0-10).

[0057] A: Asset Importance Classification (0-10), import asset IPs under different classifications via an Excel spreadsheet; E: Network Exposure Score (0-10), set the classification corresponding to different network partitions through the platform; C: Custom Adjustment Value.

[0058] Weighting coefficients: Wcvss: Basic risk weight (default 0.4); Wa: Asset impact weight (default 0.3); We: Environmental risk weight (default 0.2); Wc: Custom adjustment weight (default 0.1).

[0059] Note: The weighting coefficients can be adjusted according to the needs of the enterprise, and must satisfy Wcvss+Wa+We+Wc=1.

[0060] Based on the calculated Risk Value (RS), vulnerabilities are classified into the following levels (boundary values ​​can be adjusted according to enterprise needs):

[0061] Urgent: RS ≥ 8.5;

[0062] High: 6.5 ≤ RS < 8.5;

[0063] In China: 4.0 ≤ RS < 6.5;

[0064] Low: RS < 4.0.

[0065] The platform is configured with the necessary information for connecting to the vulnerability scanning device, such as device name, device address, access username, and password. It then initiates a call to the vulnerability scanning interface of the device via a scheduled task or manually. The vulnerability scanning interface typically takes a considerable amount of time to execute; the scan results can be queried via a scheduled task. After obtaining the vulnerabilities identified by the vulnerability scanning device, the platform re-classifies the vulnerabilities according to the configured vulnerability risk value calculation formula and displays the results on the page, along with the current status of the vulnerability. The displayed fields are as follows:

[0066]

[0067] The platform defines different expiration periods based on the different levels of vulnerabilities, such as 1 day for emergency, 3 days for high-risk, 5 days for medium-risk, and 7 days for low-risk. If the person responsible for the asset fails to complete the handling within the expiration period, the leader of the department where the person responsible for the asset is located will be notified, and the leader will then notify the person responsible for the asset again through the platform to handle the matter.

[0068] After the person responsible for the assets has dealt with the vulnerability and submitted it, the platform will automatically initiate a re-verification of the vulnerability by calling the corresponding vulnerability scanning device API interface based on the vulnerability's data source.

[0069] The re-inspection flowchart is as follows Figure 2 As shown, the specific method steps include:

[0070] After the asset manager has fixed the vulnerability, they should click the "Fix Complete" button on the platform.

[0071] The platform calls the vulnerability scanning API interface of the corresponding vulnerability scanning device based on the vulnerability data source (HIDS, Tianjing, etc.);

[0072] Obtain all vulnerability information for the asset IP where the original vulnerability is located;

[0073] The data is compared with the original vulnerability data to determine if the original vulnerability exists. If it does not exist, the verification is successful; if it exists, feedback is sent to the person responsible for the assets.

[0074] This invention provides an intelligent and automated vulnerability operation method, including:

[0075] Customizable vulnerability rating models: Security operations personnel can pre-configure personalized vulnerability rating models in the platform according to the specific needs of the enterprise, including dimensions such as business impact and asset importance.

[0076] Automated Workflow Engine: The platform is deeply integrated with vulnerability scanning tools to automate the entire process of scanning, classification, assignment, and verification.

[0077] (1) Automatically receive scan results and apply the classification model

[0078] (2) Intelligent assignment to security operations personnel for final assessment

[0079] (3) Automatically push vulnerability tasks and remediation suggestions to the asset manager.

[0080] (4) Automatically trigger repair verification scan

[0081] Closed-loop management mechanism: Establish a complete closed loop from vulnerability discovery to remediation verification, significantly improve vulnerability handling efficiency, and reduce manual intervention costs.

[0082] This invention combines personalized vulnerability classification models with automated processes, enabling intelligent and precise vulnerability management, effectively improving the security operation efficiency of enterprises, and reducing security risks.

[0083] Beneficial effects:

[0084] Build an efficient and intelligent vulnerability management system to achieve comprehensive control and precise governance of enterprise security vulnerabilities. It integrates various types of vulnerability scanning devices, breaks down information silos, eliminates data flow barriers between devices, and builds a unified vulnerability management hub. This enables fully automated closed-loop management of the entire process from vulnerability discovery, assessment, remediation to verification, effectively improving the efficiency and accuracy of vulnerability management.

[0085] It also features highly flexible vulnerability classification configuration, allowing operations and management personnel to freely set classification rules for various vulnerabilities based on the organization's actual security strategy, business risk preferences, and industry standards. This makes vulnerability risk assessment more aligned with the company's actual situation and provides accurate priority ranking for subsequent vulnerability handling.

[0086] It provides an intuitive and convenient visualization interface for vulnerability remediation, clearly and graphically displaying each stage of vulnerability remediation. From the initial state when a vulnerability is discovered, to assignment to the responsible party and remediation operations, and finally to the verification and closure status, the progress of each stage is clearly visible. The visualization design greatly facilitates real-time tracking and monitoring of the entire vulnerability remediation process by operations and management personnel, helping them to promptly identify problems, coordinate resources, and ensure that vulnerabilities are resolved in a timely and effective manner.

[0087] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for automated vulnerability classification and handling, characterized in that, The classification and handling methods include: Obtain the parameters that security operations personnel enter into the vulnerability rating model on the operations platform; The operations platform uses vulnerability scanning equipment to discover vulnerabilities; The operation platform completes automated vulnerability risk assessment based on the vulnerability risk value according to the vulnerability assessment model; Security operations personnel analyze and assess the vulnerabilities to determine if they are false alarms. If so, the process ends; otherwise, the process proceeds to the next step. Security experts confirmed the vulnerability level and submitted their proposed solutions. The vulnerability was reported to the person responsible for the asset. The operations platform uses a scheduled task to determine if a vulnerability has expired. If it has, the department head responsible for the assets will be notified.

2. The method for automated vulnerability classification and handling according to claim 1, characterized in that, Following the notification to the department head responsible for the assets, the following also applies: After receiving the overdue reminder, the department leader will forward the reminder to the person responsible for the assets. After the person responsible for the assets has completed the disposal, they should submit feedback on the platform. The operations platform performs automated vulnerability verification; once the verification is successful, the process ends. If the re-inspection fails, the asset will be reissued to the person responsible for the assets until the re-inspection is passed.

3. The method for automated vulnerability classification and handling according to claim 1, characterized in that, After the asset responsible party completes the disposal and submits it on the platform, the platform will automatically initiate a re-verification of the vulnerability by calling the corresponding vulnerability scanning device API interface based on the vulnerability data source.

4. The method for automated vulnerability classification and handling according to claim 3, characterized in that, The verification of vulnerabilities specifically includes: After the asset manager has fixed the vulnerability, they should click the "Fix Complete" button on the platform. The platform calls the vulnerability scanning API interface of the corresponding vulnerability scanning device based on the source of the vulnerability data; Obtain all vulnerability information for the asset IP where the original vulnerability is located; The data is compared with the original vulnerability data to determine if the original vulnerability exists. If it does not exist, the verification is successful; if it exists, feedback is sent to the person responsible for the assets.

5. The method for automated vulnerability classification and handling according to claim 1, characterized in that, The disposal method also includes: The platform is configured with the necessary information to access the vulnerability scanning device. The vulnerability scanning interface of the vulnerability scanning device is called through a scheduled task or manually. The vulnerability scanning interface needs to be executed for a long time. After obtaining the vulnerabilities identified by the vulnerability scanning device by querying the scan results through scheduled tasks, the platform reclassifies the vulnerabilities according to the configured vulnerability risk value calculation formula. The vulnerability will be displayed on the page, along with its current status.

6. The method for automated vulnerability classification and handling according to claim 5, characterized in that, The necessary information for the vulnerability scanning device includes: device name, device address, access username, and password.