Asset and vulnerability association analysis system and method
The asset and vulnerability correlation analysis system, which uses multi-level vulnerability scanning and dynamic feature analysis, solves the problem that traditional vulnerability scanning technology cannot fully reflect multi-dimensional vulnerability risks and lacks dynamic correlation analysis, thus achieving more efficient network security protection decision support.
Patent Information
- Application Number
- CN202511021938.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-11-18
AI Technical Summary
Traditional vulnerability scanning techniques only detect single-level or static features, making it difficult to comprehensively reflect the multi-dimensional vulnerability risks of target assets. Furthermore, existing methods lack dynamic quantitative processing when analyzing the correlation between vulnerabilities and assets, leading to false positives or false negatives.
An asset and vulnerability correlation analysis system employs multi-level vulnerability scanning combined with dynamic feature analysis and quantitative correlation processing. The system performs multi-level scanning through a data acquisition module, calculates vulnerability scanning feature factors using a first analysis module, constructs factor change values using a second analysis module, and determines correlation coefficients using a correlation analysis module, thereby achieving dynamic correlation analysis.
This improves the accuracy and comprehensiveness of vulnerability correlation analysis, providing more reliable decision support for network security protection and ensuring the precision and comprehensiveness of vulnerability correlation analysis.
Smart Images

Figure CN120979697A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of correlation analysis, in particular to an asset and vulnerability correlation analysis system and method. BACKGROUND
[0002] With the rapid development of information technology, network security threats are becoming increasingly complex, and asset and vulnerability correlation analysis has become an important means to ensure network security.
[0003] Traditional vulnerability scanning technology usually only detects single-level or static features, which is difficult to fully reflect the multi-dimensional vulnerability risks of target assets. In addition, when analyzing the correlation between vulnerabilities and assets, existing methods often lack quantitative processing of dynamic changes, which leads to the inability to accurately identify potential security threats. Moreover, the correlation analysis between vulnerabilities and assets is usually based on simple statistics or threshold judgment, ignoring the trend of vulnerability characteristics and their impact on the overall security posture, which may result in false positives or false negatives. SUMMARY
[0004] The present application provides an asset and vulnerability correlation analysis system and method, which can combine multi-level vulnerability scanning, dynamic feature analysis and quantitative correlation processing of asset and vulnerability correlation analysis methods, improve the accuracy and comprehensiveness of vulnerability correlation analysis, and provide more reliable decision support for network security protection.
[0005] To achieve the above purpose, the present application provides an asset and vulnerability correlation analysis system, comprising: a data acquisition module for determining a target asset, using a vulnerability scanning tool to perform multi-level scanning according to the network traffic characteristics of the target asset, and obtaining a set of vulnerability feature data at multiple scanning levels; a first analysis module for analyzing the set of vulnerability feature data and calculating vulnerability scanning feature factors corresponding to the set of vulnerability feature data based on the analysis results; a second analysis module for constructing a vulnerability scanning feature factor sequence according to all vulnerability scanning feature factors and analyzing the vulnerability scanning feature factors to obtain a factor change degree value of the vulnerability scanning feature factors; a correlation analysis module for analyzing all factor change degree values and determining the correlation coefficient between the target asset and vulnerabilities based on the analysis results.
[0006] Further, the first analysis module is configured to: the first analysis module is configured to divide each vulnerability feature data in the set of vulnerability feature data into a plurality of vulnerability analysis windows according to the network communication period of the target asset; The first analysis module is configured to obtain the number of potential threat points in each vulnerability analysis window and the contextual performance of each potential threat point; The first analysis module is configured to obtain the vulnerability scanning characteristic factor of the corresponding vulnerability characteristic data based on the number of potential threat points in each vulnerability analysis window and the corresponding contextual performance.
[0007] Further, the first analysis module is configured to: The first analysis module is configured to determine, for each vulnerability analysis window, the number of potential threat points in the vulnerability analysis window, the distance of each potential threat point from the key protocol field, and the severity of each potential threat point. The first analysis module is configured to obtain the first coefficient corresponding to each potential threat point in the vulnerability analysis window based on the distance of the potential threat point from the key protocol field and the severity of the potential threat point. The first analysis module is configured to calculate the mean of the first coefficients corresponding to all potential threat points in the vulnerability analysis window to obtain the contextual performance of the potential threat points in the vulnerability analysis window.
[0008] Further, the first analysis module is configured to: The first analysis module is configured to obtain the second coefficient based on the difference between the number of potential threat points in different two vulnerability analysis windows in the vulnerability characteristic data and the corresponding contextual performance. The first analysis module is configured to obtain the vulnerability scanning characteristic factor of the target vulnerability characteristic data based on the sum of the second coefficients corresponding to all different analysis windows in the vulnerability characteristic data.
[0009] Further, the second analysis module is configured to: The second analysis module is configured to determine the qth vulnerability scanning characteristic factor, determine the q+1th vulnerability scanning characteristic factor, and determine the q-1th vulnerability scanning characteristic factor from the sequence of vulnerability scanning characteristic factors. The second analysis module is configured to calculate the first vulnerability scanning characteristic factor difference between the qth vulnerability scanning characteristic factor and the q+1th vulnerability scanning characteristic factor. The second analysis module is configured to calculate the second vulnerability scanning characteristic factor difference between the qth vulnerability scanning characteristic factor and the q-1th vulnerability scanning characteristic factor. The second analysis module is configured to determine the absolute value of the difference between the first vulnerability scanning characteristic factor difference and the second vulnerability scanning characteristic factor difference as the factor change degree value of the qth vulnerability scanning characteristic factor.
[0010] Further, the correlation analysis module is configured to: The correlation analysis module is used to pre-set a preset curve fitting method, and perform curve fitting on all factor change values based on the preset curve fitting method to obtain factor change value curves. The correlation analysis module is used to determine the slope of the factor corresponding to each factor change value on the factor change value curve. The correlation analysis module is used to use the factor slope as the trend value of the change in the degree of change of each factor.
[0011] Furthermore, the correlation analysis module is used for: The correlation analysis module is used to extract the factor change degree value and change trend degree value corresponding to each vulnerability scanning feature factor; The correlation analysis module is used to determine the standard factor change value based on all factor change values, wherein the standard factor change value is the mean of the factor change values; The correlation analysis module is used to determine the correlation coefficient between the target asset and the vulnerability based on the standard factor change value and all change trend values.
[0012] Furthermore, the correlation analysis module is used for: The correlation analysis module is used to calculate the correlation coefficient between the target asset and the vulnerability according to the following formula: ; Where s is the correlation coefficient between the target asset and the vulnerability, sig() is the normalization function, n is the number of factor variation values, and g i h represents the factor change value corresponding to the change value of the i-th factor. i d represents the trend of change corresponding to the change value of the i-th factor. i The standard factor change value is the factor change value remaining after removing the change value of the i-th factor.
[0013] Furthermore, it also includes: The correlation judgment module is used to determine whether the target asset has a vulnerability correlation risk based on the relationship between the correlation coefficient and the preset correlation coefficient. When the correlation coefficient is less than the preset correlation coefficient, it is determined that the target asset does not have any vulnerability correlation risk. When the correlation coefficient is greater than or equal to the preset correlation coefficient, it is determined that the target asset has a vulnerability correlation risk.
[0014] To achieve the above objectives, the present invention also provides a method for asset-vulnerability correlation analysis, comprising: Identify the target asset, and use a vulnerability scanning tool to perform multi-level scanning based on the network traffic characteristics of the target asset to obtain vulnerability feature data sets under multiple scanning levels; The vulnerability feature data set is analyzed, and the vulnerability scanning feature factor corresponding to the vulnerability feature data set is calculated based on the analysis results; A vulnerability scanning feature factor sequence is constructed based on all vulnerability scanning feature factors, and the vulnerability scanning feature factors are analyzed to obtain the factor change value of the vulnerability scanning feature factors. The degree of change of all factors is analyzed, and the correlation coefficient between the target asset and the vulnerability is determined based on the analysis results.
[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention discloses an asset-vulnerability correlation analysis system and method. The system includes: a data acquisition module that performs multi-level scanning using vulnerability scanning tools based on the network traffic characteristics of the target asset to obtain a vulnerability feature data set; a first analysis module that analyzes the vulnerability feature data set and calculates vulnerability scanning feature factors; a second analysis module that constructs a vulnerability scanning feature factor sequence and analyzes the vulnerability scanning feature factors to obtain the factor change degree values of the vulnerability scanning feature factors; and a correlation analysis module that analyzes all factor change degree values and determines the correlation coefficient between the target asset and the vulnerability based on the analysis results. This method combines multi-level vulnerability scanning, dynamic feature analysis, and quantitative correlation processing to improve the accuracy and comprehensiveness of vulnerability correlation analysis, providing more reliable decision support for network security protection. Attached Figure Description
[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This diagram illustrates the structure of an asset and vulnerability correlation analysis system according to an embodiment of the present invention. Figure 2 The diagram illustrates a flowchart of an asset and vulnerability correlation analysis method according to an embodiment of the present invention. Detailed Implementation
[0017] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0018] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0020] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0021] The following is a description of preferred embodiments of the present invention in conjunction with the accompanying drawings.
[0022] like Figure 1 As shown, an embodiment of the present invention discloses an asset and vulnerability correlation analysis system, comprising: The data acquisition module is used to identify the target asset and perform multi-level scanning using a vulnerability scanning tool based on the network traffic characteristics of the target asset to obtain a set of vulnerability feature data under multiple scanning levels. The first analysis module is used to analyze the vulnerability feature data set and calculate the vulnerability scanning feature factor corresponding to the vulnerability feature data set based on the analysis results. The second analysis module is used to construct a vulnerability scanning feature factor sequence based on all vulnerability scanning feature factors, and to analyze the vulnerability scanning feature factors to obtain the factor change value of the vulnerability scanning feature factors. The correlation analysis module is used to analyze the degree of change of all factors and determine the correlation coefficient between the target asset and the vulnerability based on the analysis results.
[0023] In this embodiment, network traffic characteristics are identified by collecting communication data of the target asset (such as protocol type, port, packet load, and interaction frequency) to determine its behavioral patterns. Hierarchical division is performed by scanning layer by layer according to the network protocol stack (such as TCP / IP layers), application logic (such as front-end / back-end), or attack surface (such as exposed interfaces and dependency libraries).
[0024] In this embodiment, the vulnerability characteristic data is abnormal protocol behavior traffic. Abnormal protocol behavior traffic refers to the abnormal traffic generated when the target asset is attacked by a vulnerability.
[0025] In some embodiments of this application, the first analysis module is used for: The first analysis module is used to divide each vulnerability feature data in the vulnerability feature data set into several vulnerability analysis windows according to the network communication cycle of the target asset; The first analysis module is used to obtain the number of potential threat points in each vulnerability analysis window, as well as the contextual behavior of each potential threat point; The first analysis module is used to obtain vulnerability scanning feature factors of the corresponding vulnerability feature data based on the number of potential threat points in each vulnerability analysis window and the corresponding context.
[0026] In this embodiment, the network communication cycle, such as the heartbeat interval and request / response cycle, and the vulnerability analysis window are time windows, such as every 5 seconds or every 20 data packets as one window.
[0027] In this embodiment, vulnerability feature data is divided into continuous / overlapping time periods according to the network communication cycle to ensure that each window covers the complete interaction process.
[0028] The beneficial effect of the above technical solution is that it divides each vulnerability feature data in the vulnerability feature data set into several vulnerability analysis windows, thereby improving the detection accuracy.
[0029] In some embodiments of this application, the first analysis module is used for: The first analysis module is used to determine, for each vulnerability analysis window, the number of potential threat points within the vulnerability analysis window, the distance between each potential threat point and the key protocol field, and the severity of each potential threat point; The first analysis module is used to obtain a first coefficient corresponding to each potential threat point in the vulnerability analysis window based on the distance between the potential threat point and the key protocol field and the severity of the potential threat point; The first analysis module is used to calculate the mean of the first coefficients corresponding to all potential threat points within the vulnerability analysis window, thereby obtaining the contextual performance of the potential threat points within the vulnerability analysis window.
[0030] In this embodiment, potential threats include suspicious parameters and abnormal traffic.
[0031] In this embodiment, the logical distance (such as hop count or offset) between each potential threat point and key protocol fields (such as HTTP headers and TCP ports) is determined. The specific determination process is well-established and will not be repeated here.
[0032] In this embodiment, the threat level is assigned based on the CVSS score.
[0033] In this embodiment, the first coefficient is calculated according to the following formula: ; Where a is the first coefficient, k1 is the degree of threat, and k2 is the distance.
[0034] In this embodiment, the more serious the threat and the closer it is to the key field, the higher the coefficient.
[0035] The beneficial effects of the above technical solution are: the present invention calculates the mean of the first coefficients corresponding to all potential threat points in the vulnerability analysis window, obtains the contextual performance of potential threat points in the vulnerability analysis window, and takes the mean of the first coefficients of all threat points to reflect the overall threat density and criticality in the window.
[0036] In some embodiments of this application, the first analysis module is used for: The first analysis module is used to obtain a second coefficient based on the difference in the number of potential threat points in two different vulnerability analysis windows in the vulnerability feature data and the corresponding contextual differences. The first analysis module is used to obtain the vulnerability scanning feature factor of the target vulnerability feature data based on the sum of the second coefficients corresponding to all different analysis windows in the vulnerability feature data.
[0037] In this embodiment, the following differences are calculated by comparing any two analysis windows (such as windows A and B): The difference in the number of threat points is calculated as follows: (|Number of A - Number of B|). Poor contextual performance, poor contextual performance = (|A contextual performance - B contextual performance|). The second coefficient is calculated using the following formula: ; Where a2 is the second coefficient, n is the difference in the number of threat points, m is the difference in context performance, b1 is the first calculation weight, b2 is the second calculation weight, and b1+b2=1.
[0038] The beneficial effects of the above technical solution are: this invention quantifies the attack surface volatility of vulnerabilities by dynamically changing threats between windows; the higher the characteristic factor, the more active the vulnerability risk. This lays the foundation for asset-vulnerability correlation analysis.
[0039] In some embodiments of this application, the second analysis module is used for: The second analysis module is used to determine the q-th vulnerability scanning feature factor, the (q+1)-th vulnerability scanning feature factor, and the (q-1)-th vulnerability scanning feature factor from the vulnerability scanning feature factor sequence; The second analysis module is used to calculate the difference between the first vulnerability scanning feature factor of the q-th vulnerability scanning feature factor and the first vulnerability scanning feature factor of the (q+1)-th vulnerability scanning feature factor; The second analysis module is used to calculate the difference between the second vulnerability scanning feature factor of the q-th vulnerability scanning feature factor and the (q-1)-th vulnerability scanning feature factor; The second analysis module is used to determine the absolute value of the difference between the first vulnerability scanning feature factor difference and the second vulnerability scanning feature factor difference, as the factor change value of the qth vulnerability scanning feature factor.
[0040] The beneficial effects of the above technical solution are: the present invention determines the absolute value of the difference between the first vulnerability scanning feature factor difference and the second vulnerability scanning feature factor difference as the factor change degree value of the qth vulnerability scanning feature factor, thereby realizing the change analysis of the qth vulnerability scanning feature factor, and thus providing reliable technical support for asset-vulnerability correlation analysis.
[0041] In some embodiments of this application, the association analysis module is used for: The correlation analysis module is used to pre-set a preset curve fitting method, and perform curve fitting on all factor change values based on the preset curve fitting method to obtain factor change value curves. The correlation analysis module is used to determine the slope of the factor corresponding to each factor change value on the factor change value curve. The correlation analysis module is used to use the factor slope as the trend value of the change in the degree of change of each factor.
[0042] In this embodiment, the preset curve fitting methods include least squares method, nonlinear least squares method, etc., and can be selected according to the actual situation.
[0043] The beneficial effects of the above technical solution are: the present invention uses the factor slope as the trend value of the change of each factor, and the trend value can characterize the change of the factor, thereby further ensuring the accuracy of the asset-vulnerability correlation analysis.
[0044] In some embodiments of this application, the association analysis module is used for: The correlation analysis module is used to extract the factor change degree value and change trend degree value corresponding to each vulnerability scanning feature factor; The correlation analysis module is used to determine the standard factor change value based on all factor change values, wherein the standard factor change value is the mean of the factor change values; The correlation analysis module is used to determine the correlation coefficient between the target asset and the vulnerability based on the standard factor change value and all change trend values.
[0045] In this embodiment, as described above, each vulnerability scanning feature factor corresponds to a factor change degree value and a change trend degree value.
[0046] The beneficial effects of the above technical solution are: the present invention determines the correlation coefficient between the target asset and the vulnerability based on the standard factor change degree value and all change trend degree values, and can combine multi-level vulnerability scanning, dynamic feature analysis and quantitative correlation processing asset and vulnerability correlation analysis methods to improve the accuracy and comprehensiveness of vulnerability correlation analysis.
[0047] In some embodiments of this application, the association analysis module is used for: The correlation analysis module is used to calculate the correlation coefficient between the target asset and the vulnerability according to the following formula: ; Where s is the correlation coefficient between the target asset and the vulnerability, sig() is the normalization function, n is the number of factor variation values, and g i h represents the factor change value corresponding to the change value of the i-th factor. i d represents the trend of change corresponding to the change value of the i-th factor. i The standard factor change value is the factor change value remaining after removing the change value of the i-th factor.
[0048] In this embodiment, sig() is a normalization function that can be used for normalization.
[0049] In some embodiments of this application, it also includes: The correlation judgment module is used to determine whether the target asset has a vulnerability correlation risk based on the relationship between the correlation coefficient and the preset correlation coefficient. When the correlation coefficient is less than the preset correlation coefficient, it is determined that the target asset does not have any vulnerability correlation risk. When the correlation coefficient is greater than or equal to the preset correlation coefficient, it is determined that the target asset has a vulnerability correlation risk.
[0050] In this embodiment, the preset correlation coefficient is preferably 0.75, but it can be adjusted according to the actual situation.
[0051] The beneficial effects of the above technical solution are: the present invention determines whether the target asset has vulnerability correlation risk based on the relationship between the correlation coefficient and the preset correlation coefficient, ensuring the accuracy and efficiency of the judgment, and providing more reliable decision support for network security protection.
[0052] To further illustrate the technical concept of this invention, the technical solution of this invention will now be described in conjunction with specific application scenarios.
[0053] Correspondingly, such as Figure 2 As shown, this application also provides a method for asset-vulnerability correlation analysis, including: S110: Determine the target asset, and use a vulnerability scanning tool to perform multi-level scanning based on the network traffic characteristics of the target asset to obtain a set of vulnerability feature data under multiple scanning levels; S120: Analyze the vulnerability feature data set and calculate the vulnerability scanning feature factor corresponding to the vulnerability feature data set based on the analysis results; S130: Construct a vulnerability scanning feature factor sequence based on all vulnerability scanning feature factors, and analyze the vulnerability scanning feature factors to obtain the factor change value of the vulnerability scanning feature factors; S140: Analyze the degree of change of all factors and determine the correlation coefficient between the target asset and the vulnerability based on the analysis results.
[0054] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments or examples.
[0055] Although the invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the embodiments disclosed in this invention can be combined with each other in any way. The fact that not all of these combinations are described in this specification is merely for the sake of brevity and resource conservation.
[0056] It will be understood by those skilled in the art that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An asset and vulnerability correlation analysis system, characterized in that, include: The data acquisition module is used to identify the target asset and perform multi-level scanning using a vulnerability scanning tool based on the network traffic characteristics of the target asset to obtain a set of vulnerability feature data under multiple scanning levels. The first analysis module is used to analyze the vulnerability feature data set and calculate the vulnerability scanning feature factor corresponding to the vulnerability feature data set based on the analysis results. The second analysis module is used to construct a vulnerability scanning feature factor sequence based on all vulnerability scanning feature factors, and to analyze the vulnerability scanning feature factors to obtain the factor change value of the vulnerability scanning feature factors. The correlation analysis module is used to analyze the degree of change of all factors and determine the correlation coefficient between the target asset and the vulnerability based on the analysis results.
2. The asset and vulnerability correlation analysis system according to claim 1, characterized in that, The first analysis module is used for: The first analysis module is used to divide each vulnerability feature data in the vulnerability feature data set into several vulnerability analysis windows according to the network communication cycle of the target asset; The first analysis module is used to obtain the number of potential threat points in each vulnerability analysis window, as well as the contextual behavior of each potential threat point; The first analysis module is used to obtain vulnerability scanning feature factors of the corresponding vulnerability feature data based on the number of potential threat points in each vulnerability analysis window and the corresponding context.
3. The asset and vulnerability correlation analysis system according to claim 2, characterized in that, The first analysis module is used for: The first analysis module is used to determine, for each vulnerability analysis window, the number of potential threat points within the vulnerability analysis window, the distance between each potential threat point and the key protocol field, and the severity of each potential threat point; The first analysis module is used to obtain a first coefficient corresponding to each potential threat point in the vulnerability analysis window based on the distance between the potential threat point and the key protocol field and the severity of the potential threat point; The first analysis module is used to calculate the mean of the first coefficients corresponding to all potential threat points within the vulnerability analysis window, thereby obtaining the contextual performance of the potential threat points within the vulnerability analysis window.
4. The asset and vulnerability correlation analysis system according to claim 3, characterized in that, The first analysis module is used for: The first analysis module is used to obtain a second coefficient based on the difference in the number of potential threat points in two different vulnerability analysis windows in the vulnerability feature data and the corresponding contextual differences. The first analysis module is used to obtain the vulnerability scanning feature factor of the target vulnerability feature data based on the sum of the second coefficients corresponding to all different analysis windows in the vulnerability feature data.
5. The asset and vulnerability correlation analysis system according to claim 1, characterized in that, The second analysis module is used for: The second analysis module is used to determine the q-th vulnerability scanning feature factor, the (q+1)-th vulnerability scanning feature factor, and the (q-1)-th vulnerability scanning feature factor from the vulnerability scanning feature factor sequence; The second analysis module is used to calculate the difference between the first vulnerability scanning feature factor of the q-th vulnerability scanning feature factor and the first vulnerability scanning feature factor of the (q+1)-th vulnerability scanning feature factor; The second analysis module is used to calculate the difference between the second vulnerability scanning feature factor of the q-th vulnerability scanning feature factor and the (q-1)-th vulnerability scanning feature factor; The second analysis module is used to determine the absolute value of the difference between the first vulnerability scanning feature factor difference and the second vulnerability scanning feature factor difference, as the factor change value of the qth vulnerability scanning feature factor.
6. The asset and vulnerability correlation analysis system according to claim 1, characterized in that, The correlation analysis module is used for: The correlation analysis module is used to pre-set a preset curve fitting method, and perform curve fitting on all factor change values based on the preset curve fitting method to obtain factor change value curves. The correlation analysis module is used to determine the slope of the factor corresponding to each factor change value on the factor change value curve. The correlation analysis module is used to use the factor slope as the trend value of the change in the degree of change of each factor.
7. The asset and vulnerability correlation analysis system according to claim 6, characterized in that, The correlation analysis module is used for: The correlation analysis module is used to extract the factor change degree value and change trend degree value corresponding to each vulnerability scanning feature factor; The correlation analysis module is used to determine the standard factor change value based on all factor change values, wherein the standard factor change value is the mean of the factor change values; The correlation analysis module is used to determine the correlation coefficient between the target asset and the vulnerability based on the standard factor change value and all change trend values.
8. The asset and vulnerability correlation analysis system according to claim 7, characterized in that, The correlation analysis module is used for: The correlation analysis module is used to calculate the correlation coefficient between the target asset and the vulnerability according to the following formula: ; Where s is the correlation coefficient between the target asset and the vulnerability, sig() is the normalization function, n is the number of factor variation values, and g i h represents the factor change value corresponding to the change value of the i-th factor. i d represents the trend of change corresponding to the change value of the i-th factor. i The standard factor change value is the factor change value remaining after removing the change value of the i-th factor.
9. The asset and vulnerability correlation analysis system according to claim 1, characterized in that, Also includes: The correlation judgment module is used to determine whether the target asset has a vulnerability correlation risk based on the relationship between the correlation coefficient and the preset correlation coefficient. When the correlation coefficient is less than the preset correlation coefficient, it is determined that the target asset does not have any vulnerability correlation risk. When the correlation coefficient is greater than or equal to the preset correlation coefficient, it is determined that the target asset has a vulnerability correlation risk.
10. An asset-vulnerability correlation analysis method, applied to the asset-vulnerability correlation analysis system as described in any one of claims 1-9, characterized in that, include: Identify the target asset, and use a vulnerability scanning tool to perform multi-level scanning based on the network traffic characteristics of the target asset to obtain vulnerability feature data sets under multiple scanning levels; The vulnerability feature data set is analyzed, and the vulnerability scanning feature factor corresponding to the vulnerability feature data set is calculated based on the analysis results; A vulnerability scanning feature factor sequence is constructed based on all vulnerability scanning feature factors, and the vulnerability scanning feature factors are analyzed to obtain the factor change value of the vulnerability scanning feature factors. The degree of change of all factors is analyzed, and the correlation coefficient between the target asset and the vulnerability is determined based on the analysis results.