Asset vulnerability processing method and system
By implementing a method and system for handling asset vulnerabilities through work order distribution, tagging, and auditing nodes, the complexity of intranet asset vulnerability management has been solved. This has enabled digital management from discovery to remediation, improving efficiency, reducing costs, and providing a secure and reliable network environment.
Patent Information
- Application Number
- CN202511278510.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-09
- Publication Date
- 2025-11-07
AI Technical Summary
In existing technologies, the management process of intranet asset vulnerabilities is complex and lacks an efficient and unified work order process, resulting in low management efficiency and difficulty in achieving digital management from discovery to remediation.
This paper proposes a method and system for handling asset vulnerabilities. By distributing work orders, marking and reviewing nodes, work orders are automatically or manually dispatched to the responsible persons, and the permissions of the responsible persons are configured to achieve automated handling of vulnerabilities. The effectiveness of vulnerability remediation is verified by rescanning.
It improves the efficiency of vulnerability management, reduces management costs, and provides a more secure and reliable network environment.
Smart Images

Figure CN120912151A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of network security, and particularly relates to a method for automatically processing work orders of vulnerabilities of internal network assets discovered by scanning and a work order system applying the method. BACKGROUND
[0002] With the continuous improvement of enterprise informatization, the number of various IT assets, including servers, network devices, terminal devices, databases, etc., increases dramatically, and the management, monitoring and maintenance of these assets become increasingly complex. Therefore, enterprises need an efficient and unified internal network asset management platform to improve the informatization management level. The internal network asset management platform mainly involves enterprise informatization construction, network security, compliance requirements, management efficiency and user experience, etc. Among them, the entire process from discovering asset vulnerabilities to repairing vulnerabilities needs to be managed digitally, so the entire asset vulnerability processing process needs to be recorded to realize the processing of the work order process. SUMMARY
[0003] In view of the above background, the present application proposes an asset vulnerability processing method and system to improve the compliance management of internal network assets. The technical solution adopted by the present application is as follows.
[0004] In a first aspect, a method for processing asset vulnerabilities is proposed, which sequentially executes a work order distribution node, a marking node and an auditing node, wherein: The work order distribution node includes automatically creating a work order according to the vulnerability scanning result and automatically distributing it to the corresponding vulnerability person in charge, and if the automatic distribution fails, manually assigning it. The work order information includes vulnerability level, description, impact range and repair suggestion, and the vulnerability person in charge is determined according to a pre-set vulnerability level and person in charge permission matching relationship, including distribution person in charge, marking person in charge and auditing person in charge; The marking node includes that the vulnerability marking person in charge receiving the work order performs repair operation according to the work order information and actual situation, and adds a repair mark to the work order after completion; The auditing node includes auditing the work order after adding the repair mark, and closing all processing nodes of the work order after the auditing is passed.
[0005] Preferably, if the auditing is not passed, the work order is returned to the distribution person in charge for re-distribution.
[0006] In addition, the auditing node described above further includes an execution re-scanning node, which repeatedly scans the corresponding work order vulnerability by calling the parameters of the last vulnerability scanning to verify that the vulnerability is repaired, and if the re-scanning node fails, the work order is returned to the marking list.
[0007] Preferably, the automatic distribution failure includes a failure in matching the vulnerability responsible person or the matched responsible person not meeting the preset strategy. The failure in matching the responsible person includes adding the corresponding work order to an undistributed list if the responsible person configured by the preset strategy is empty, and manually assigning the work order by a distribution responsible person with authority.
[0008] Preferably, the work order information further includes a reminder trigger condition, and the reminder trigger condition includes a vulnerability level meeting a preset condition or triggering a vulnerability processing deadline. When the reminder condition is triggered, an email or a short message is sent to each responsible person corresponding to the work order.
[0009] Preferably, the work order distribution node further includes withdrawing and prematurely ending the work order, and if the work order is withdrawn or prematurely ended, a notification is simultaneously sent to the marked responsible person and the audit responsible person corresponding to the work order.
[0010] In a second aspect, an asset vulnerability processing system is provided, which applies the asset vulnerability processing method described above, and includes: A work order distribution module is configured to automatically create a work order according to a vulnerability scanning result and automatically distribute the work order to a corresponding vulnerability responsible person. If the automatic distribution fails, manual assignment is performed. The work order information includes a vulnerability level, a description, an influence range, and a repair suggestion. The vulnerability responsible person is determined according to a preset vulnerability level and a responsible person permission matching relationship, including a distribution responsible person, a marked responsible person, and an audit responsible person. A work order marking module is configured to enable a vulnerability marked responsible person receiving a work order to perform a repair operation according to work order information and actual conditions, and add a repair mark to the work order after completion. A work order audit module is configured to audit the work order after the repair mark is added, and close all processing nodes of the work order after the audit is passed.
[0011] The asset vulnerability processing system described above further includes a re-scanning module configured to repeatedly scan a vulnerability of an audit-passed work order by calling parameters of the last vulnerability scanning, to verify whether the vulnerability is repaired.
[0012] The asset vulnerability processing system described above has at least the following beneficial effects: When the system discovers an asset vulnerability, a work order is created, and the work order is sequentially executed by distribution, marking, and rectification nodes according to preset rules. Each node is configured with a corresponding responsible person according to a preset strategy. Each node responsible person performs a vulnerability operation according to the work order information, and then hands over to the next node. Finally, an audit responsible person confirms the processing result. The vulnerability corresponding to the audit-passed work order can be repeatedly scanned according to needs, the scanning parameters are consistent with the parameters configured when the vulnerability is discovered, and whether the vulnerability is effectively processed can be verified. Not only is the efficiency of vulnerability management improved, but also the management cost is reduced, and a more secure and reliable network environment is provided for enterprises. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 This is a schematic diagram of the workflow of an embodiment of an asset vulnerability handling method; Figure 2 This is a schematic diagram of the module composition of an embodiment of an asset vulnerability handling system. Detailed Implementation
[0014] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application. Furthermore, it should be noted that, for ease of description, only the parts relevant to the application are shown in the accompanying drawings.
[0015] like Figure 1 As shown, an embodiment of an asset vulnerability handling method is proposed, which sequentially executes vulnerability handling nodes of work order distribution, marking, and review, wherein: The work order distribution node includes automatically creating work orders based on vulnerability scan results and automatically dispatching them to the corresponding vulnerability responsible persons. If automatic dispatch fails, manual assignment is performed. The work order information includes vulnerability level, description, scope of impact, and remediation suggestions. The vulnerability responsible persons are determined according to a preset vulnerability level and responsible person permission matching relationship, including the dispatch responsible person, the marking responsible person, and the review responsible person. The tagging node includes the vulnerability tagging responsible person who receives the work order, performs the repair operation according to the work order information and the actual situation, and adds a repair tag to the work order after completion; The review node includes reviewing work orders after adding a repair mark, and closing all processing nodes for the work order after the review is approved.
[0016] Ideally, if the review fails, the work order should be returned to the person responsible for distribution for redistribution.
[0017] Furthermore, following the aforementioned review node, there is also a rescan node, which calls the parameters of the last vulnerability scan to rescan the vulnerability of the corresponding work order to verify that the vulnerability has been fixed. If the rescan node fails, the work order is returned to the list of pending marking.
[0018] Preferably, the aforementioned automatic dispatch failure includes failure to match the responsible party for the vulnerability or the matched responsible party not conforming to the preset policy. The responsible party matching failure includes, if the responsible party configured in the preset policy is empty, adding the corresponding work order to the undistributed list, whereby a qualified dispatching responsible party manually assigns the work order.
[0019] Preferably, the aforementioned work order information also includes reminder triggering conditions, which include the vulnerability level reaching a preset condition or triggering the vulnerability handling deadline; when the reminder triggering condition is triggered, an email or SMS is sent to the respective responsible persons corresponding to the work order.
[0020] Preferably, the aforementioned work order distribution nodes also include the withdrawal and early termination of work orders, and if a work order is withdrawn or terminated early, a notification is sent to the person responsible for marking and reviewing the work order at the same time.
[0021] like Figure 2 As shown, an embodiment of an asset vulnerability handling system is proposed to implement the above-described asset vulnerability handling method. The system includes: The work order distribution module is used to automatically create work orders based on vulnerability scanning results and automatically dispatch them to the corresponding vulnerability responsible persons. If automatic dispatch fails, manual assignment is performed. The work order information includes vulnerability level, description, scope of impact and remediation suggestions. The vulnerability responsible persons are determined according to the preset vulnerability level and responsible person permission matching relationship, including the dispatch responsible person, the marking responsible person and the review responsible person. The work order marking module is used by the person responsible for marking vulnerabilities who receives a work order to perform repair operations based on the work order information and the actual situation, and then add a repair mark to the work order after completion. The work order review module is used to review work orders that have been marked for repair. Once the review is approved, all processing nodes of the work order will be closed.
[0022] The aforementioned vulnerability handling system also includes a rescan module, which calls the parameters of the last vulnerability scan to rescan the vulnerabilities in the approved work order to verify that the vulnerabilities have been patched.
[0023] As described above, the technical solution of this invention creates a work order when the system discovers an asset vulnerability. According to preset rules, the work order is sequentially distributed, marked, and remediated at various nodes. Each node is configured with a responsible person according to a preset strategy. The responsible person at each node performs the vulnerability operation according to their authorized permissions based on the work order information and then hands it over to the next node. Finally, the responsible person at the review stage confirms the processing result. Furthermore, for vulnerabilities corresponding to approved work orders, repeated scanning can be configured as needed. The scanning parameters are consistent with the parameters used to discover the vulnerability, which can verify whether the vulnerability has been effectively addressed. This not only improves the efficiency of vulnerability management but also reduces management costs, providing enterprises with a more secure and reliable network environment.
[0024] Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc.
[0025] The foregoing description of the embodiments disclosed enables any person skilled in the art to make or use the present application. Modifications will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other embodiments without the use of the inventive faculty. Thus, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An asset vulnerability handling method characterized by, The vulnerability handling nodes, namely work order distribution, marking, and review, are executed sequentially, including: The work order distribution node includes automatically creating work orders based on vulnerability scanning results and automatically dispatching them to the corresponding vulnerability responsible persons. If automatic dispatch fails, manual assignment is performed. The work order information includes vulnerability level, description, scope of impact, and remediation suggestions. The vulnerability responsible persons are determined according to a preset vulnerability level and responsible person permission matching relationship, including the dispatch responsible person, the marking responsible person, and the review responsible person. The marking node includes the vulnerability marking responsible person who receives the work order performing repair operations based on the work order information and the actual situation, and adding a repair mark to the work order after completion; The review node includes reviewing work orders after adding repair tags, and closing all processing nodes of the work order after the review is approved.
2. The asset vulnerability handling method according to claim 1, characterized by, Following the audit node, a rescan node is executed, which involves re-scanning the vulnerabilities in the corresponding work order by calling the parameters of the last vulnerability scan to verify that the vulnerabilities have been patched.
3. The asset vulnerability handling method according to claim 2, characterized by, If the rescan node fails, the work order will be returned to the list of nodes to be marked.
4. The asset vulnerability handling method of claim 1, wherein, If the review fails, the work order will be returned to the person responsible for distribution for redistribution.
5. The asset vulnerability handling method of claim 1, wherein, The automatic dispatch failure includes failure to match the responsible party for the vulnerability or the matched responsible party not conforming to the preset strategy.
6. The asset vulnerability handling method of claim 5, wherein, The failure to match the responsible person includes adding the corresponding work order to the undistributed list if the responsible person configured in the preset strategy is empty, and having the authorized distribution responsible person manually assign it.
7. The asset vulnerability handling method of claim 1, wherein, The work order information also includes reminder triggering conditions, which include the vulnerability level reaching a preset condition or triggering the vulnerability handling deadline; when the reminder condition is triggered, an email or text message is sent to the responsible persons corresponding to the work order.
8. The method of claim 1, wherein, The work order distribution node also includes the ability to withdraw or terminate a work order early. If a work order is withdrawn or terminated early, a notification is sent to the person responsible for marking and reviewing the work order.
9. An asset vulnerability handling system, which applies the asset vulnerability handling method according to claims 1 to 8, characterized by, The system includes: The work order distribution module is used to automatically create work orders based on vulnerability scanning results and automatically dispatch them to the corresponding vulnerability responsible persons. If automatic dispatch fails, manual assignment is performed. The work order information includes vulnerability level, description, scope of impact and remediation suggestions. The vulnerability responsible persons are determined according to the preset vulnerability level and responsible person permission matching relationship, including the dispatch responsible person, the marking responsible person and the review responsible person. The work order marking module is used by the person responsible for marking vulnerabilities who receives a work order to perform repair operations based on the work order information and the actual situation, and then add a repair mark to the work order after completion. The work order review module is used to review work orders that have been marked for repair. Once the review is approved, all processing nodes of the work order will be closed.
10. The asset vulnerability processing system of claim 9, wherein, The system also includes a rescan module, which calls the parameters of the last vulnerability scan to rescan the vulnerabilities of the approved work orders in order to verify that the vulnerabilities have been patched.