A network security vulnerability automatic management method based on network security intelligence
By adopting an automated management method based on cybersecurity intelligence, the entire process of ECU cybersecurity vulnerability assessment and accurate risk assessment have been automated, solving the problems of low automation and poor collaboration in existing technologies, improving the efficiency and accuracy of vulnerability handling, and supporting collaborative handling across the industry chain.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SONKWO COM
- Filing Date
- 2025-10-15
- Publication Date
- 2026-06-02
Smart Images

Figure CN120979828B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security vulnerability management, and in particular to an automated network security vulnerability management method based on network security intelligence. Background Technology
[0002] With the development of automotive electronic control unit (ECU) technology, ECU cybersecurity risks are becoming increasingly prominent, and the discovery and handling of cybersecurity vulnerabilities has become a core aspect of cybersecurity management in the automotive industry. Currently, the industry largely relies on manual collection of cybersecurity intelligence, followed by manual analysis to assess vulnerability risks. This process lacks standardization and automation, resulting in low efficiency and susceptibility to human error.
[0003] In existing technologies, some solutions attempt to introduce automated tools for intelligence gathering, but these can only achieve simple aggregation of intelligence from a single source. They cannot perform standardized format conversion or multi-dimensional filtering of intelligence, and lack specific threat analysis and risk assessment mechanisms for ECU products, making it difficult to accurately identify ECU-related vulnerabilities. Furthermore, existing vulnerability management solutions are mostly limited to internal enterprise use and do not consider the collaborative needs of the upstream and downstream of the automotive industry chain. This can easily lead to gaps in vulnerability handling, resulting in prolonged remediation cycles.
[0004] The aforementioned shortcomings of existing technologies result in problems such as low automation, insufficient analytical accuracy, and poor collaboration in ECU cybersecurity vulnerability management. These shortcomings fail to meet the automotive industry's demand for efficient and accurate handling of cybersecurity vulnerabilities, necessitating a technical solution that can achieve automated intelligence processing, accurate risk assessment, and cross-stage collaborative management. Summary of the Invention
[0005] This application provides an automated management method for network security vulnerabilities based on network security intelligence, which can realize the automated collection, screening, analysis and vulnerability management of ECU network security intelligence, improve the efficiency and accuracy of vulnerability handling, and solve the problems of low automation and poor collaboration in existing technologies.
[0006] Firstly, this application provides an automated management method for network security vulnerabilities based on network security intelligence. This includes cybersecurity intelligence gathering, screening, storage and analysis, and vulnerability management. Cybersecurity intelligence gathering involves acquiring cybersecurity intelligence within a specified time period from multiple pre-defined authoritative vulnerability databases, including at least one database specifically for the automotive industry. This intelligence is then converted into a pre-defined standardized format, which must include fields such as vulnerability name, information source, vulnerability number, vulnerability reporting time, severity, vulnerability description, affected customers, related projects, and project contact person. Cybersecurity intelligence screening uses configurable keywords to filter collected intelligence, obtaining intelligence related to the target ECU product and pushing it to the corresponding project contact person. Cybersecurity intelligence storage and analysis involves uniformly archiving and storing the filtered intelligence, supporting multi-dimensional filtering based on vulnerability time period and affected products. It employs pre-defined threat analysis and risk assessment methods, including analyzing the cybersecurity assets affected by the vulnerability, identifying threat and damage scenarios, assessing the vulnerability's impact and attack feasibility, and determining whether the vulnerability corresponds to a vulnerability. Cybersecurity vulnerability management involves unified management of information classified as vulnerabilities, supporting new projects to query historical vulnerabilities through keyword matching to prevent recurrence. The vulnerability data storage format must include fields such as vulnerability name, vulnerability source, vulnerability number, discovery time, vulnerability description, impact scope, analysis results, and remediation plan.
[0007] By adopting the above technical solutions, the entire process of ECU network security intelligence collection and management is automated. Standardized format conversion ensures intelligence consistency, multi-dimensional screening and special threat analysis improve the accuracy of vulnerability identification, and the historical vulnerability query function prevents vulnerability reproduction, effectively solving the problems of low automation and insufficient analysis accuracy of existing technologies.
[0008] Furthermore, when using the preset threat analysis and risk assessment methods, a dynamic weight adaptive mechanism is introduced. This mechanism extracts the vehicle usage label and ECU function label of the ECU project, and determines the dynamic weights of the four impact dimensions of security, operation, privacy and property according to the preset label-dimensional weight mapping rules. The sum of the weights of each dimension is 1. The final impact rating is calculated by combining the original scores of each dimension, which is used in the vulnerability impact assessment stage.
[0009] By adopting the above technical solutions, the vulnerability impact assessment can be adapted to the scenario requirements of different ECU projects, dynamically adjust the weight of each impact dimension, improve the accuracy of impact rating, and avoid assessment bias caused by fixed weights.
[0010] Furthermore, it also includes an attack path prediction process. This process achieves linkage by synchronizing intelligence analysis data from the cybersecurity intelligence storage and analysis stage in real time through a data interface. It breaks down attack elements into three quantifiable indicators: attack cost, attack threshold, and attack window. It constructs a mapping relationship between current attack elements and attack feasibility to calculate the current attack feasibility. At the same time, it accesses attack technology evolution data and predicts the attack feasibility in the future within a time period that matches the update cycle of attack technology evolution data based on preset evolution rules. The prediction results are then synchronized to the risk rating sub-stage of the cybersecurity intelligence storage and analysis stage.
[0011] By adopting the above technical solutions, we can realize real-time calculation and future prediction of attack feasibility, provide early warning of potential attack risks, provide dynamic basis for vulnerability risk rating, and avoid risk misjudgment caused by relying solely on current data.
[0012] Furthermore, the attack path prediction process also includes an evolution coefficient self-learning process. This process crawls new attack technology entries from authoritative vulnerability databases in real time, extracts three types of features: attack technology type, threshold descent rate, and propagation speed. The mapping relationship between features and evolution coefficients is trained through a machine learning model that adjusts parameters based on historical prediction errors. The attack threshold descent coefficient and attack window extension coefficient are dynamically updated, and the model parameters are optimized based on the prediction error.
[0013] By adopting the above technical solutions, the attack evolution coefficient can dynamically iterate with the latest attack technologies without the need for manual parameter adjustment, thereby improving the timeliness and accuracy of attack feasibility prediction and adapting to the rapid changes in attack and defense technologies.
[0014] Furthermore, the cybersecurity vulnerability management process also includes a cross-enterprise collaboration process. This process constructs an encrypted industry chain collaboration database, stores the core business constraint information of upstream and downstream enterprises, calculates the cross-enterprise constraint satisfaction and the internal constraint satisfaction, generates a collaboration feasibility score, and outputs a collaboration handling plan only when the collaboration feasibility score reaches a preset threshold, and generates a time-series execution table to clarify the responsibility nodes of each enterprise.
[0015] By adopting the above technical solutions, we can achieve collaborative vulnerability handling among upstream and downstream enterprises in the automotive industry chain, clarify the responsibilities and timelines of each enterprise, solve the problems of poor collaboration and long repair cycles in existing technologies, and improve the efficiency of vulnerability handling.
[0016] Furthermore, it also includes a critical asset identification process. This process achieves linkage by synchronizing the vulnerability impact information of the network security intelligence storage and analysis links with the preliminary risk level data in real time through the data interface. It integrates three types of multimodal data of ECU assets: textual functional descriptions, numerical interactive data, and graph structure relationship data. Through a multimodal information fusion mechanism, it achieves multimodal information interaction, combines feature weight learning to output asset criticality scores, and calculates asset association criticality based on asset association strength to complete the critical asset identification.
[0017] By adopting the above technical solutions, multimodal data can be integrated to accurately identify key assets of the ECU, providing key targets for subsequent vulnerability analysis and handling, avoiding the waste of resources on non-critical assets, and improving the targeting of vulnerability management.
[0018] Furthermore, it also includes a hazard scenario enhancement process, which is automatically triggered after the critical asset is identified to achieve linkage. Based on the functional characteristics of the critical asset and historical hazard scenario data, a hazard scenario is generated through a scenario generation model. At the same time, a game system between attacking and defending agents is constructed to generate an attack and defense game scenario. The optimal hazard scenario is matched for the newly identified critical asset based on feature similarity.
[0019] By adopting the above technical solutions, diverse and realistic hazard scenarios are generated, providing a more comprehensive scenario basis for vulnerability risk assessment, improving the completeness of risk assessment, and avoiding the omission of potential hazards.
[0020] Furthermore, when using the pre-defined threat analysis and risk assessment methods, a higher-order probabilistic graphical model is introduced based on the dynamic weight adaptive mechanism. The final impact rating calculated by the dynamic weight is used as the input parameter of the higher-order probabilistic graphical model to model the higher-order dependencies between assets, vulnerabilities, and attacks. The posterior probability of risk nodes is dynamically updated in conjunction with Bayes' theorem, and the comprehensive risk value is calculated through the probability propagation algorithm.
[0021] By adopting the above technical solutions, the complex dependencies between assets, vulnerabilities, and attacks can be captured, risk probabilities can be dynamically updated, the accuracy of comprehensive risk value calculation can be improved, and a more reliable basis can be provided for vulnerability priority ranking.
[0022] Furthermore, the attack path prediction process also includes a dynamic attack simulation process. This process constructs a dynamic probabilistic graph model and updates the node transfer probability in real time. It uses path search combined with probabilistic pruning to generate all effective attack paths, calculates the path existence probability based on the product of attack transfer probabilities between nodes, and models the attack propagation process through a dynamic model based on the evolution logic of attack propagation rate and asset association strength to predict the spatiotemporal distribution of the attack in the asset network.
[0023] By adopting the above technical solutions, all possible attack paths and attack propagation trends can be dynamically simulated, high-risk attack paths and their spatiotemporal distribution can be identified, providing precise guidance for the formulation of defense strategies and enhancing the foresight of vulnerability defense.
[0024] Furthermore, the vulnerability handling process in cybersecurity vulnerability management also includes an interpretable linkage process. This process takes the high-priority risk dimensions identified by dynamic weights as the handling targets, constructs a multi-objective optimization function, analyzes the rationality of the handling plan through causal inference, and outputs an interpretable report containing results, basis, and influencing factors. At the same time, it realizes the full-link automatic linkage of key asset identification, hazard scenario matching, risk assessment, and handling push, and the data flow delay of each link does not exceed the maximum tolerable delay of the link data processing.
[0025] By adopting the above technical solutions, we can achieve full-chain automatic linkage and interpretability of vulnerability handling, clarify the rationale for handling solutions, reduce the cost of manual intervention, ensure efficient data flow, and improve the timeliness and credibility of vulnerability handling.
[0026] In summary, this application has at least the following beneficial effects:
[0027] 1. Provides a fully automated management solution for ECU network security vulnerabilities, improving the efficiency and accuracy of handling.
[0028] 2. Enable attack path prediction and dynamic simulation to provide early warning of potential risks;
[0029] 3. Support cross-enterprise collaborative handling across the industry chain to shorten the vulnerability remediation cycle;
[0030] 4. It provides explainability of vulnerability handling, enhancing the credibility and feasibility of the solution.
[0031] It should be understood that the description in the Summary Section is not intended to limit the key or essential features of the embodiments of this application, nor is it intended to restrict the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0032] The above and other features, advantages, and aspects of the embodiments of this application will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:
[0033] Figure 1 A schematic diagram of an exemplary operating environment in which embodiments of this application can be implemented is shown.
[0034] Figure 2 A flowchart of an automated network security vulnerability management method based on network security intelligence, as described in an embodiment of this application, is shown. Detailed Implementation
[0035] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0036] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0037] This application provides an automated management method for cybersecurity vulnerabilities based on cybersecurity intelligence. It can automate the entire process of ECU vulnerability management from intelligence collection to handling, improve the accuracy of risk assessment, support industry chain collaboration and attack early warning, and also has the ability to explain the handling process, effectively solving the pain points of existing technologies.
[0038] Figure 1 A schematic diagram of an exemplary operating environment in which embodiments of this application can be implemented is shown.
[0039] Reference Figure 1 The operating environment includes core computing devices, data acquisition and transmission devices, storage devices, and network and security devices. These devices are interconnected through the network and together form a hardware system that supports the realization of the "automated management method for network security vulnerabilities based on network security intelligence".
[0040] The core computing equipment serves as the processing and decision-making hub of the entire management approach, including high-performance server clusters and optional edge computing nodes. The high-performance server clusters are equipped with multi-core CPUs, large-capacity memory, and high-speed storage, and are responsible for vulnerability data analysis, intelligence integration, and automated policy execution, supporting the real-time computation of massive amounts of security intelligence. Edge computing nodes are deployed near branch networks or business terminals, which can collect terminal vulnerability data nearby, reduce the data transmission pressure on the core servers, and improve the real-time performance of vulnerability discovery.
[0041] Data acquisition and transmission equipment serves as an information access channel, including vulnerability scanning devices, network traffic acquisition devices, and security intelligence receiving terminals. Vulnerability scanning devices encompass network vulnerability scanners and host vulnerability scanners. Network vulnerability scanners support vulnerability detection on multiple types of devices, while host vulnerability scanners detect local configuration defects and weak passwords. Both types of devices are interconnected with core computing devices and transmit scan results back in real time. Network traffic acquisition devices have throughput of gigabit-level or higher, assisting in the identification of hidden vulnerabilities by capturing network traffic and avoiding packet loss. Security intelligence receiving terminals have stable network connections and can access third-party intelligence sources to ensure the timeliness of intelligence updates.
[0042] Storage devices are used for the retention and retrospection of vulnerability data throughout its entire lifecycle, including a distributed storage system and an optional time-series database server. The distributed storage system adopts a multi-node redundant architecture, supports petabyte-level data storage, and has data backup and disaster recovery capabilities to prevent the loss of vulnerability data. The time-series database server is suitable for high-frequency, multi-dimensional vulnerability scanning scenarios, efficiently stores time-series vulnerability data, and facilitates the analysis of vulnerability outbreak trends.
[0043] Network and security equipment provides stability and security support for the operating environment, including enterprise-grade firewalls and intrusion prevention systems (IPS), network switches and routers; enterprise-grade firewalls and IPS are deployed at the network entry points of core computing and storage devices to restrict unauthorized access and block attacks targeting the management system; network switches and routers have high stability and support VLAN segmentation, which divides devices with different functions into independent VLANs to reduce the impact of broadcast storms on management processes.
[0044] The aforementioned devices form a collaborative hardware system through the network, ensuring the efficient and stable operation of the entire process of intelligence collection, screening, analysis, and vulnerability management in the "Automated Management Method for Network Security Vulnerabilities Based on Network Security Intelligence".
[0045] This application specifically discloses a method for automated management of network security vulnerabilities based on network security intelligence.
[0046] Figure 2 A flowchart of an automated network security vulnerability management method based on network security intelligence, as described in an embodiment of this application, is shown.
[0047] Reference Figure 2 The method specifically includes the following steps:
[0048] S1: Cybersecurity intelligence gathering.
[0049] In this step, cybersecurity intelligence for a specified time period is obtained from multiple pre-defined authoritative vulnerability databases that include at least a database of vulnerabilities specific to the automotive industry, and then converted into a pre-defined standardized format. This format must include fields such as vulnerability name, information source, vulnerability number, vulnerability reporting time, severity, vulnerability description, affected customers, related projects, and project contact person.
[0050] Specifically, the pre-set authoritative vulnerability database includes not only automotive industry-specific vulnerability databases (such as the CAVD database focusing on automotive ECU vulnerabilities), but also general cybersecurity vulnerability databases (such as CVE, NVD, CNVD, and CNNVD). Distributed crawling technology is used to achieve parallel acquisition of multi-source intelligence, with crawling tasks scheduled according to a pre-set time window. ( It can be configured according to the intelligence update frequency, such as This process is executed periodically (hourly) to ensure the timeliness of intelligence gathering. During intelligence acquisition, the original data formats from different databases need to be normalized, and a data format conversion function needs to be defined. ,in Raw intelligence data representing a specific database (including the database's unique field structure and data types). By using field mapping rules To convert to a preset standardized format, the mapping rules must meet the following requirements: for each field in the original data (For example, the "CVSSScore" field in the NVD database) can all find a unique corresponding target field (such as the "Severity" field) in the preset standardized format, and the data type of the converted field is consistent with the requirements of the target field (such as converting the character "High" to a numeric type). Numerical storage requirements that match the severity level.
[0051] To ensure the initial screening of the relevance between the collected intelligence and the target ECU product, a keyword matching filtering mechanism needs to be introduced during the intelligence acquisition phase, defining a matching degree calculation function `match`. ,in This refers to the text content of a single intelligence report (including fields such as vulnerability description and affected products). The keyword set for the target ECU product (such as ECU model "VCU-2023", functional module "battery management system", chip model "MCU-A53", etc.). The calculation method is as follows:
[0052]
[0053] In the formula, Keyword set The number of elements, count Keywords In intelligence text The number of times it appears in Keywords The weights are configured based on the importance of the keyword's association with the target ECU product, such as the weight of the ECU model. Functional module weight And satisfy Only when ( For the preset matching threshold, such as Only when this information is obtained is it retained and proceeded to the subsequent format conversion stage, in order to reduce the interference of invalid information on subsequent processes.
[0054] In addition, to verify the integrity of intelligence data, a data integrity check needs to be performed after format conversion, defining an integrity scoring function `intact`. ,in The converted, standardized format intelligence data, The calculation method is as follows:
[0055]
[0056] In the formula, The total number of fields included in the preset standardized format (i.e., the aforementioned 9 fields). for The number of non-empty fields in the table. Only when... To preset the integrity threshold, such as Only then is the intelligence deemed valid and stored in the intelligence cache. If inact If the missing data is not found, the supplementary data collection mechanism will be triggered to re-crawl the original data corresponding to the intelligence to fill in the missing fields. If the integrity requirements are still not met after 3 supplementary data collections, it will be marked as "pending manual completion" and stored separately to ensure that the intelligence data entering the subsequent stages has sufficient integrity to support the analysis needs.
[0057] S2: Cybersecurity intelligence screening.
[0058] The configurable keywords here are not single - dimensional static words, but a "multi - level keyword system" constructed based on the full - life - cycle attributes of the target ECU product. This system includes three levels: the core attribute layer (such as ECU model, hardware version, software version), the functional attribute layer (such as control function module, communication protocol type), and the scenario attribute layer (such as applicable vehicle models, deployment locations). The keywords at each level can be flexibly added, deleted, or the weights adjusted by the user according to the actual project requirements. To achieve accurate screening, it is necessary to pre - process the intelligence text collected and format - converted in S1 first, including Chinese word segmentation (using the Jieba word - segmentation algorithm), stop - word removal (filtering meaningless words such as "of", "and"), and synonym normalization (such as unifying "electronic control unit" into "ECU"), to obtain the pre - processed intelligence text feature set , where is a single feature word, is the total number of feature words.
[0059] Based on the pre - processing results, the weighted cosine similarity algorithm is used to calculate the correlation degree between a single piece of intelligence and the target ECU product, and the correlation - degree calculation function is defined , where is the multi - level keyword system, is the th keyword, is the weight of this keyword (the weight value range of keywords in the core attribute layer is , the functional attribute layer is , the scenario attribute layer is , and it satisfies is the total number of keywords. The correlation - degree calculation formula is:
[0060]
[0061] In the formula, is the frequency of the keyword appearing in the intelligence text feature set . If does not appear, the value is taken as 0; the numerator part is the total weighted feature match, and the denominator part is the product of the modulus lengths of the weight vector and the frequency vector, used to normalize the correlation - degree result to ensure .
[0062] Set the correlation - degree threshold (configured according to the screening accuracy requirements, such as when pursuing high recall rate, when pursuing high precision). When , it is determined that this piece of intelligence is relevant to the target ECU product and enters the subsequent push link; if If the intelligence is deemed irrelevant, it is marked as "irrelevant intelligence" and archived in the backup database for subsequent manual review or keyword system optimization. During the push notification process, a "ECU Project - Interface Person" mapping table must first be established. This table stores the interface person information (name, email, instant messaging account) corresponding to each target ECU project, and the mapping relationship can be maintained in real time by the project administrator. For intelligence deemed relevant, the system automatically extracts the "related project" field from the intelligence, matches it with the corresponding interface person in the mapping table, and generates a push notification containing core intelligence information (vulnerability name, severity, vulnerability description, related project). It supports multi-channel push notifications (email, instant messaging tools, system internal messages) and records push time, push channel, read status, and other log information. This log information is synchronized to the S3 intelligence storage stage for subsequent tracing and auditing.
[0063] If the same person at the same interface is within the preset time window (like If multiple related intelligence reports are received within an hour, the system will trigger an intelligence aggregation mechanism. The intelligence reports will be sorted according to the following rules: severity from highest to lowest (CVSS scoring priority: Critical > High > Medium > Low), and vulnerability discovery time from newest to oldest. Duplicate or similar intelligence reports will be merged (by calculating the text similarity between reports). ,when When similar intelligence is identified, an "Intelligence Summary Report" is generated and pushed out in one go, avoiding redundant information to the contact person and improving communication efficiency.
[0064] S3: Cybersecurity intelligence storage and analysis.
[0065] In this step, the filtered intelligence is uniformly archived and stored, supporting multi-dimensional filtering based on vulnerability time periods and affected products. A pre-defined threat analysis and risk assessment method is employed, which includes analyzing the cybersecurity assets affected by the vulnerability, identifying threat and damage scenarios, assessing the vulnerability's impact and attack feasibility, and determining whether the weakness corresponding to the intelligence is indeed a vulnerability. A dynamic weight adaptive mechanism is introduced when using the pre-defined threat analysis and risk assessment method. This mechanism extracts vehicle usage and ECU function tags from the ECU project, determines the dynamic weights of four impact dimensions (security, operation, privacy, and property) based on pre-defined tag-dimensional weight mapping rules, and sums the weights of each dimension to 1. The final impact rating is calculated by combining the original scores of each dimension and used in the vulnerability impact assessment stage. Furthermore, a higher-order probabilistic graphical model is introduced based on the dynamic weight adaptive mechanism. The final impact rating calculated by the dynamic weights is used as the input parameter of the higher-order probabilistic graphical model to model the higher-order dependencies between assets, vulnerabilities, and attacks. The posterior probability of risk nodes is dynamically updated using Bayes' theorem, and a comprehensive risk value is calculated through a probability propagation algorithm.
[0066] In the intelligence storage stage, a hybrid storage architecture of "distributed relational database + time-series database" is adopted: the distributed relational database (such as a MySQL cluster) is used to store the structured data of the intelligence (such as pre-defined standardized format fields such as vulnerability number, severity, and related projects), supporting multi-dimensional filtering based on "vulnerability time period" (the query condition is the "vulnerability reporting time" field of the intelligence, accurate to the hour) and "affected products" (the query condition is the "affected customers" and "related projects" fields). The query efficiency is improved by a table partitioning and database partitioning strategy (based on the "vulnerability reporting time" table is partitioned monthly); the time-series database (such as the creation time, update time, and query frequency of the intelligence) is used to store the time-series data of the intelligence, which facilitates subsequent analysis of the efficiency of intelligence flow and popularity. At the same time, to ensure data security, the stored intelligence data is encrypted in a hierarchical manner: core fields (such as vulnerability description and related projects) use the AES-256 encryption algorithm, ordinary fields (such as information source and reporting time) use MD5 hash verification, and the encryption keys are uniformly managed by the Key Management System (KMS) and automatically rotated periodically (such as every 7 days).
[0067] In the "Analyzing the impact of vulnerabilities on cybersecurity assets" stage of threat analysis and risk assessment, it is necessary to first construct an ECU asset association network and define the asset node set. ( Representing a single ECU asset, including attributes such as asset ID, model, and function, as well as a set of edges connecting the assets. ( Representing ECU assets and The network relationships (such as communication dependencies and data interactions) are stored in a graph database (such as Neo4j). For a single piece of intelligence, the "vulnerability description" field is extracted to identify the asset characteristics that the vulnerability may affect (such as "affecting ECUs using CAN bus"). The asset association network is traversed to find asset nodes that match the characteristics and the nodes directly associated with them, thus forming a set of assets affected by the vulnerability. To locate the assets affected by the vulnerability.
[0068] In the "Identifying Threat and Damage Scenarios" section, the vulnerability impacts the set of assets. By combining a historical vulnerability handling case library (which stores the threat types and consequences of past vulnerabilities), cosine similarity matching is used to determine the similarity between historical cases and current vulnerabilities, and a similarity function is defined. ,in This is the feature vector of the current vulnerability (including vulnerability type, affected assets, and triggering conditions). The feature vectors of historical cases are calculated using the same formula as the correlation calculation in S2. The top three historical cases with the highest similarity are selected, and their threat scenarios (such as "unauthorized remote access" and "data tampering") and damage scenarios (such as "ECU malfunction" and "abnormal vehicle control") are extracted as candidate scenarios for the current vulnerability. The system then filters these scenarios based on the vulnerability's "severity" field. If the severity is "Critical" or "High", all candidate scenarios are retained; if it is "Medium" or "Low", only the threat scenario is retained, thus completing scenario identification.
[0069] In the "Assessing the Impact of the Vulnerability" step, relying on a dynamic weight adaptive mechanism, the vehicle usage label of the target ECU project is first extracted. (e.g., "passenger vehicles", "commercial vehicles", "new energy vehicles") and ECU function labels (e.g., "Powertrain Control", "Body Control", "Autonomous Driving"), query the preset "Label-Dimension Weight Mapping Table" to obtain safety information. ,operate ,privacy ,property The weights of the four influencing dimensions satisfy... (For example, the power control of new energy vehicles) , Subsequently, a raw score was given for each impact dimension, and a scoring function was defined. ),in The "Severity" field for intelligence (mapped to numerical values: Critical=10, High=8, Medium=5, Low=2). The scoring rules are based on functional labels and severity (such as the safety dimension scoring of the powertrain control ECU). Safety rating of the vehicle body control ECU. Ultimately affecting the rating , The higher the score, the greater the degree of influence.
[0070] In the "Assess Attack Feasibility" phase, based on the vulnerability's "Vulnerability Description" field, we extract the technical barriers required for the attack (e.g., "must master assembly language" or "must physically access the ECU"), equipment requirements (e.g., "must use a dedicated CAN bus tool" or "must use a network sniffing device"), and time costs (e.g., "attack time") "Hours" attack time The three categories of indicators (hours) are assigned values respectively. (Each indicator ranges from 1 to 5, where 1 represents the lowest barrier to entry / lowest cost, and 5 represents the highest barrier to entry / highest cost), Attack Feasibility Score A lower score indicates a higher feasibility of the attack. This will affect the final rating. And attack feasibility score If the intelligence is valid, the corresponding weakness is determined to be a vulnerability; otherwise, it is determined to be non-vulnerable, and is only archived to the intelligence database without proceeding to the subsequent vulnerability management stage.
[0071] In risk assessment incorporating higher-order probabilistic graphical models, Markov logic networks (MLNs) are used to construct the model and define a set of rules. ( Rules describing the relationships between assets, vulnerabilities, and attacks, such as "if ECU assets..." Vulnerability exists ,and and If related, then Increased risk of attack), each rule Corresponding weight (Trained from historical vulnerability data; the more important the rule, the greater its weight). The joint probability distribution of the model is:
[0072]
[0073] In the formula, The set of risk state variables for all assets ( for A certain state, such as "high risk", "medium risk" or "low risk". For rules In state The number of times the following is satisfied, The partition function. The final impact rating is calculated using dynamic weights. As input parameters, update the prior probabilities of asset nodes. Combined with Bayes' theorem To provide evidence of the current vulnerability (such as "the vulnerability has been verified to exist"), the posterior probability of the asset nodes is dynamically updated. Finally, the posterior probability is propagated through the asset association network using a probability propagation algorithm (such as belief propagation) to calculate the comprehensive risk value of each asset node. ( Risk status The score indicates high risk. Medium risk Low risk ), This is used for subsequent vulnerability priority ranking.
[0074] S4: Attack path prediction.
[0075] In this step, the method achieves real-time synchronization of intelligence analysis data from the network security intelligence storage and analysis stage through a data interface. Attack elements are broken down into three quantifiable indicators: attack cost, attack threshold, and attack window. A mapping relationship between current attack elements and attack feasibility is constructed to calculate current attack feasibility. Simultaneously, attack technology evolution data is accessed, and attack feasibility is predicted based on preset evolution rules within a timeframe matching the attack technology evolution data update cycle. The prediction results are synchronized to the risk rating sub-stage of the network security intelligence storage and analysis stage. The attack path prediction process also includes a self-learning process for evolution coefficients. This process crawls new attack technology entries from authoritative vulnerability databases in real time and extracts attack... The attack path prediction process includes three characteristics: technology type, threshold reduction rate, and propagation speed. A machine learning model, with parameters adjusted based on historical prediction errors, is used to train the mapping relationship between these characteristics and evolution coefficients. This dynamically updates the attack threshold reduction coefficient and attack window extension coefficient, and optimizes the model parameters based on prediction errors. The attack path prediction process also includes a dynamic attack deduction process. This process constructs a dynamic probabilistic graphical model and updates node transfer probabilities in real time. All valid attack paths are generated using path search combined with probabilistic pruning. The path existence probability is calculated based on the product of attack transfer probabilities between nodes. Simultaneously, a dynamic model based on the evolutionary logic of attack propagation rate and asset association strength is used to model the attack propagation process and predict the spatiotemporal distribution of attacks in the asset network.
[0076] Intelligence analysis data synchronized through data interfaces, specifically including the set of assets affected by vulnerabilities identified in S3. Overall risk value R and attack feasibility score These data serve as the foundational inputs for attack path prediction, ensuring consistency between the prediction process and previous analysis results. After breaking down attack elements into attack cost, attack threshold, and attack window, each metric needs to be quantified: Attack Cost (Unit: RMB 10,000) Calculated based on the equipment procurement cost and manpower / time cost required for exploiting the vulnerability. For example, "Dedicated sniffing equipment required (RMB 50,000) + 2 person-days of manpower (RMB 5,000)" corresponds to... Attack Threshold (Values range from 1 to 5, with 1 being the lowest and 5 being the highest). "2 people * days" means "the total manpower and time required to complete a certain task is 2 standard working days." This can be specifically reflected in two arrangements: one worker continuously working for 2 standard working days or two workers simultaneously working for 1 standard working day. The value is assigned based on the technical difficulty required to exploit the vulnerability, such as "requires mastery of assembly language and CAN protocol parsing." Attack window (Unit: hours), determined based on the duration the ECU is exposed to an attackable environment, such as "ECU network connection time during vehicle charging is 8 hours / day". When constructing the mapping relationship for the current attack feasibility, a weighted summation model is used to determine the current attack feasibility. ,in Set a maximum attack cost threshold (e.g., 200,000 yuan). Set a maximum attack window threshold (e.g., 24 hours). Weighting coefficients (satisfying) ,default The closer the value is to 1, the higher the feasibility of the current attack.
[0077] The attack technique evolution data is sourced from monthly technology trend reports of authoritative vulnerability databases (such as CVE and CAVD), including information such as the frequency of attack technique updates and the popularity of vulnerability exploitation tools. The preset evolution rules are based on the technology update cycle. Based on a benchmark of (e.g., 3 months), predict the future. Feasibility of attack within a specific time period ,in This is the attack threshold reduction factor (a correction factor for the lower threshold due to the widespread use of tools, with a value of 0-0.5). This is the attack window shortening coefficient (a correction coefficient for window shortening due to upgraded defense measures, with a value of 0-). ,like Then take 1, if Then take 0, and the prediction result is... This will be synchronized to the risk rating sub-process in S3 to adjust the overall risk value. .
[0078] During the self-learning process of evolution coefficients, new attack techniques crawled in real time need to be categorized by "Attack Technique Type" (e.g., "Remote Code Execution," "Man-in-the-Middle Attack," "Password Cracking") and "Threshold Decrease Rate." (e.g., "from 4 to 2, corresponding to...") "), "Speed of transmission" (Unit: Items / Month, e.g., "10 new use cases added each month, corresponding to...") Extract features and construct feature vectors. Typecode (Type) Encode the technology type, such as "remote code execution". Man-in-the-middle attack The model uses a random forest model to train the mapping relationship between features and evolution coefficients. The model input is... The output is and Model parameter optimization is based on prediction error. ,in To assess the feasibility of future attacks predicted by the model, To assess the feasibility of future attacks in actual observation, when At that time, the random forest's decision tree number, maximum depth, and other parameters are adjusted using gradient descent until... This enables dynamic optimization of the evolution coefficient.
[0079] During the dynamic simulation of the attack, the nodes of the dynamic probabilistic graphical model are ECU asset sets. Edges represent attack transfer relationships between assets, and node transfer probabilities. Indicates from assets Successful attack to The probability is calculated as follows: ,in For assets The overall risk value, for and The correlation strength (based on the S3 asset correlation network, with values ranging from 0 to 1, 0.8 for direct communication correlation and 0.3 for indirect correlation). To ensure the maximum combined risk value of all assets. The path search employs a depth-first search algorithm, starting from the assets affected by the vulnerability. Starting from the initial node, traverse all reachable nodes to generate attack paths, and then use probabilistic pruning to preserve the probability of path existence. Valid paths, probability of path existence , such as path The probability of its existence is Here, "path" refers to the sequence of ECU (Electronic Control Unit) asset nodes from the initial attack asset to the target asset; that is, the propagation trajectory (e.g., node sequence) of the asset nodes (such as network assets with different functions, ECUs) that the attack may pass through in the network. → → This indicates that the attack originated from the asset. Towards , and then (The path of transfer).
[0080] The attack propagation process is modeled using partial differential equations to describe the spatiotemporal distribution of the attack in the asset network, defining the attack propagation density function. , indicating at time (Unit: hour), Asset Location The degree of attack impact at (the spatial coordinate mapping value corresponding to the asset ID) satisfies the equation .in The attack propagation and diffusion coefficient (based on the speed of attack technique propagation). set up, Let be the Laplace operator, representing the rate of change of the attack's diffusion in space; It is a logistic growth term. Attack growth coefficient (based on asset correlation strength) The average value setting, Solving this equation using numerical methods (such as the finite difference method) yields results at different times. The following asset locations attack propagation density This allows for the prediction of the spatiotemporal distribution of attacks within the asset network, providing precise temporal and spatial guidance for defense strategy development.
[0081] S5: Identification of Key Assets.
[0082] In this step, the vulnerability impact information and preliminary risk level data of the network security intelligence storage and analysis process are synchronized in real time through the data interface. The three types of multimodal data of ECU assets are integrated: textual functional description, numerical interactive data, and graph structure relationship. Multimodal information interaction is achieved through a multimodal information fusion mechanism. The asset criticality score is output by combining feature weight learning, and the asset association criticality is calculated based on the asset association strength to complete the identification of critical assets.
[0083] Vulnerabilities in data interface synchronization can affect asset information; specifically, vulnerabilities identified in S3 affect the asset set. And the corresponding asset attributes (such as model, functional modules); the preliminary risk level data is the final impact rating calculated based on dynamic weights in S3. Synchronizing this data ensures that critical asset identification focuses on high-risk related assets, avoiding indiscriminate analysis. The three types of multimodal data integrated need to be standardized first: for text-based functional descriptions (such as "responsible for the charging and discharging control of new energy vehicle power batteries"), the Word2Vec model is used to convert them into 300-dimensional text feature vectors. Each dimension represents the weight of a semantic feature; the larger the absolute value of the weight, the more important the semantic feature is to the representation of the asset's function. For numerical interaction data (such as "interacts with other ECUs 120 times per hour" or "data transmission bandwidth 10Mbps"), Min-Max normalization is used to map it to... The interval is used to obtain the numerical eigenvector. ( (For numerical indicators), the normalization formula is: ,in This is the original data. These represent the historical minimum and maximum values of the indicator, respectively. For graph-structured relationships (i.e., the ECU asset association network constructed in S3), a graph embedding algorithm (such as Node2Vec) is used to convert asset nodes into 128-dimensional graph feature vectors. Higher vector similarity indicates a stronger correlation between the asset's position and function within the network.
[0084] The multimodal information fusion mechanism employs a cross-attention mechanism to achieve interaction between data from different modalities, defining a fusion feature vector. The calculation process is as follows: First, calculate the cross-attention weights between the text modality and the numerical modality. The formula is ,in (Text feature dimension) (Numerical feature dimension) The dot product of the feature vectors of the two modalities is used to measure the correlation between the modalities; then, the cross-attention weights of this fusion result and the graph modality are calculated. The calculation logic is the same as described above, and the feature vectors are ultimately fused. By highlighting the feature contributions of highly correlated modalities through attention weighting, the fusion results can comprehensively represent asset attributes.
[0085] Feature weight learning employs a gradient boosting tree (GBDT) model to fuse feature vectors. Using the asset's "historical vulnerability impact frequency" (i.e., the number of times the asset was affected by past vulnerabilities) as input, the model trains a mapping relationship between features and asset importance. The model outputs the weights of each fused feature dimension. ,satisfy ( (This is the total dimension of the fused features), and then the asset criticality score is calculated by combining the fused feature vectors. ,in For the fused feature vector Each dimension value A higher score indicates that the asset itself is more critical.
[0086] Asset-related criticality calculation is based on the asset-related network in S3, defining assets. The key to the relationship ,in For assets The directly related asset set (i.e., the asset-related network with) (Nodes connected by edges) for and Association strength (value) Related assets The formula uses the criticality of related assets to inversely empower the current asset, reflecting the logic that "related assets of key assets also possess high importance." .
[0087] The final determination of critical assets requires combining their own criticality with the criticality of related assets, and defining comprehensive criticality. ,in To find the maximum correlation key of all assets, normalize the correlation key to map it to... Interval, weight These represent the importance ratio of the attribute itself and its related attributes, respectively. At that time, the asset was determined to be a critical asset and included as a key focus for subsequent vulnerability mitigation; if If so, it is determined to be a non-critical asset and only routine monitoring is performed.
[0088] S6: Enhanced hazardous scenarios.
[0089] In this step, the linkage is automatically triggered after the critical asset is identified. Based on the functional characteristics of the critical asset and historical hazard scenario data, a hazard scenario is generated through a scenario generation model. At the same time, a game system between attacking and defending agents is constructed to generate an attack and defense game scenario. The optimal hazard scenario is matched for the newly identified critical asset based on feature similarity.
[0090] The linkage trigger mechanism uses the output signal of the critical asset determination result in S5 as the trigger condition. When the system detects a critical asset set... ( When generating the number of key assets, the functional characteristics of each key asset are automatically extracted from the asset attribute library. (e.g., "charge and discharge regulation function of power control ECU" and "environmental perception function of autonomous driving ECU"), and retrieve relevant data from the historical hazard scenario database. This database stores records of past vulnerability hazard scenarios. Each record contains a scenario ID and three core types of information: associated asset function, hazard manifestation (e.g., "ECU function failure causes vehicle to fail to start"), and triggering conditions (e.g., "when the vulnerability is remotely exploited"), thus forming a historical scenario dataset. ( (Number of historical records).
[0091] The scene generation model uses a generative adversarial network (GAN), which consists of a generator. With discriminator Composition. Generator The input is a random latent vector. (Dimensions are set to 128, following a normal distribution) ) and key asset functional feature vector (Will (Converted to a 300-dimensional vector using Word2Vec), the output is candidate hazard scenario text; discriminator. The input consists of candidate scene text and real scene text from the historical scene dataset, and the output is the "realism score" of the text. The model training objective is to minimize the generator loss. With maximizing discriminator loss This continues until the model converges (the discriminator's truth score stabilizes at around 0.5), where... This represents the relationship between "random latent vector z" and "key asset functional feature vector". "Take the expected value, This indicates the "historical scene dataset" The mathematical expectation is taken from the real-world scenario text d. After training, the current key asset is input. The generator can output 3-5 candidate hazard scenarios that match the asset's functional characteristics. For example, for the power control ECU, it can generate scenarios such as "abnormal charge and discharge regulation function leading to battery overcharging" and "power output interruption causing vehicle stalling".
[0092] The attack and defense Boyi system employs a multi-agent reinforcement learning framework to construct attack agents. With defensive intelligent agents Action space of the attacking agent Includes exploit methods (such as "remote code execution" and "data tampering"), and target assets (from a collection of critical assets). (Select from ) Action space of the defensive agent It includes defensive measures (such as "patch updates", "access control", and "traffic monitoring") and defense targets (consistent with the assets targeted in the attack). The system defines the reward for the attacking agent using "attack success probability" and "defense cost" as reward functions. The probability of a successful attack is based on the probability of the attack path existing in S4. calculate; The attack cost is taken from the attack cost in S4. (normalized value), defensive agent reward This represents a normalized value for defense costs, such as patch development costs and equipment deployment costs. Agents are trained using a centralized training distributed execution (CTDE) framework until they reach Nash equilibrium (i.e., neither agent can improve its reward by unilaterally changing its actions). At this point, the combination of attack and defense actions (e.g., "the attacking agent uses remote code execution to attack the ECU, and the defending agent uses patch updates for defense") constitutes an attack-defense scenario, which is then added to the candidate hazard scenario set.
[0093] In the optimal hazard scenario matching process, the functional characteristics of newly identified key assets are first considered. Convert to feature vector Then, the text descriptions of all candidate scenes (including GAN-generated scenes and game-themed scenes) are converted into scene feature vectors. (Using Word2Vec, dimension 300). Calculate the cosine similarity between the two. Where • is the vector dot product, Let the vector magnitude be , Select the one with the highest similarity and The scenario with the highest similarity is selected as the optimal threat scenario. If the similarity of all scenarios is less than 0.7, the two scenarios with the highest similarity are selected and filtered in combination with the "severity" of the vulnerability in S3 - two scenarios are kept when the severity is "Critical" or "High", and one scenario is kept when the severity is "Medium" or "Low". The optimal threat scenario is finally determined and used to supplement the scenario and formulate the defense strategy for subsequent vulnerability risk assessment.
[0094] S7: Network security vulnerability management.
[0095] In this step, information identified as vulnerabilities is managed uniformly. New projects can use keyword matching to query historical vulnerabilities to prevent recurrence. The vulnerability data storage format must include fields such as vulnerability name, vulnerability source, vulnerability number, discovery time, vulnerability description, impact scope, analysis results, and remediation plan. The network security vulnerability management process also includes a cross-enterprise collaboration process. This process builds an encrypted industry chain collaboration database, stores the core business constraint information of upstream and downstream enterprises, calculates the cross-enterprise constraint satisfaction and the internal constraint satisfaction, generates a collaboration feasibility score, and outputs a collaborative remediation plan only when the collaboration feasibility score reaches a preset threshold. A time-series execution table is also generated to clarify the responsibility nodes of each enterprise. The vulnerability remediation process in network security vulnerability management also includes an interpretability linkage process. This process uses the high-priority risk dimensions identified by dynamic weights as the remediation target, constructs a multi-objective optimization function, analyzes the rationality of the remediation plan through causal inference, and outputs an interpretable report containing results, basis, and influencing factors. At the same time, it realizes full-link automatic linkage of key asset identification, hazard scenario matching, risk assessment, and remediation push, and the data flow delay of each link does not exceed the maximum tolerable delay of the link data processing.
[0096] When managing information identified as vulnerabilities in a unified manner, a dual-storage architecture of "relational database + blockchain" is adopted: the relational database (such as PostgreSQL) is used to store the structured fields of vulnerability data (i.e., 8 types of fields such as vulnerability name and vulnerability source), supporting multi-condition queries of SQL statements; the blockchain (adopting a consortium blockchain architecture, with nodes including vehicle manufacturers, ECU suppliers, and vulnerability detection agencies) is used to store the hash values and modification logs of vulnerability data, ensuring that the data is tamper-proof—each time vulnerability data is updated (such as supplementing the remediation plan), the system automatically calculates the SHA-256 hash value of the current data. (in The vulnerability data is presented as a string, and its hash value, update time, and operator information are written to the blockchain. Data integrity can be verified by comparing the hash value in the database with the value stored on the blockchain. When querying historical vulnerabilities for new projects, a weighted cosine similarity algorithm, consistent with S2, is used to calculate the correlation between the query keywords and the "vulnerability description" and "impact scope" fields of historical vulnerabilities. ,when When the vulnerability is detected, the system returns the matching historical vulnerability information and pushes the corresponding "handling solution" field content to help prevent the vulnerability from recurring in new projects.
[0097] In cross-enterprise collaboration, the encrypted supply chain collaboration database uses the national cryptographic algorithm SM4 to encrypt the stored data. Core business constraint information specifically includes the update window period for vehicle manufacturers. (e.g., "the third weekend of each month"), test resource capacity (e.g., "can test 10 ECU models per day"), and the supplier's repair cycle. (e.g., "Power control ECU repair requires 14 days"). Calculate cross-enterprise constraint satisfaction. First, quantify the constraint information: map the update window period to an overlappable duration. (If the demand window for new projects overlaps with the update window of vehicle manufacturers by 5 days,) The test resource capacity is mapped to resource utilization. Repairing the period mapping to the period matching degree Then calculate by weighted summation. ,in The maximum duration of the update window for vehicle manufacturers (e.g., 7 days). Satisfaction of internal constraints within the enterprise The feasibility score is calculated by each company's internal system (e.g., suppliers calculate the repair cycle satisfaction based on their own production capacity). The preset threshold is set to 0.7. At the same time, a collaborative handling plan is output, and a time-series execution table is generated. Based on the timeline, the responsibility nodes of each enterprise are clearly defined (such as "the supplier completes the vulnerability repair on days 1-14", "the vehicle manufacturer completes the testing on days 15-16", "the update package is pushed on day 17"). Each node includes three types of information: responsible party, task content, and deadline.
[0098] In the process of interpretability linkage, the high-priority risk dimension is changed from The dynamic weight adaptive mechanism is determined by selecting the two most influential dimensions (such as the security dimension) with the highest weights. Operational dimensions If the high-priority dimension is safety and operation, then the disposal objective is taken as the objective. When constructing the multi-objective optimization function, the optimization objectives are "maximizing the reduction of risk in the high-priority dimension" and "minimizing the disposal cost". ,in These represent the risk reduction amounts in the safety and operational dimensions (based on the S3 comprehensive risk value). calculate, (Risk values before and after treatment, respectively) The target weight (consistent with the dimension weights) The solution involves the total cost of handling the situation (such as patch development costs and human resource costs). This function is solved using a non-dominated sorting genetic algorithm (NSGA-II) to obtain the Pareto optimal solution set, from which a solution that balances risk reduction and cost is selected.
[0099] Causal inference analysis employs the propensity score matching (PSM) method: the implemented sample of the proposed treatment plan is matched with historical unimplemented samples, and a propensity score is calculated for each sample. ( This indicates the implementation of the disposal plan. This indicates that it has not been implemented. As covariates, including vulnerability severity and the number of affected assets, nearest neighbor matching is used to find sample pairs with the closest propensity scores. The risk reduction effect of the matched samples is compared. If the sample is implemented... Significantly higher than the unimplemented sample (difference) If the results are as follows, the handling plan is deemed reasonable. The "results" in the explanatory report refer to the expected effects of the handling plan (e.g., "risk reduction of 1.5 in the safety dimension and 1.2 in the operational dimension"), the "basis" refers to the matching results of PSM causal inference and the risk reduction data, and the "influencing factors" refer to factors that may affect the implementation of the plan, such as handling costs and implementation cycle.
[0100] The entire chain is automatically linked, enabling data flow at each stage through pre-defined API interfaces: After S5 critical asset identification, the critical asset ID is synchronized to the S6 hazard scenario matching stage via the interface; after S6 outputs the optimal hazard scenario, it is synchronized to the S3 risk assessment stage to update the comprehensive risk value; after S3 updates the risk value, it triggers the generation of the S7 vulnerability mitigation plan; after the mitigation plan is generated, it is pushed to the corresponding project contact person via the interface, forming a closed loop of "identification-matching-assessment-mitigation". Data flow latency is minimized. The sum of data transmission and processing time in each stage ( , This represents the time delay from stage a to stage b. This refers to the latency from the generation of the S7 vulnerability mitigation plan to the dissemination of the plan (i.e., the dissemination of the plan to the relevant project contact person, supporting multiple channels such as email, instant messaging tools, and system internal messages), and the maximum tolerable latency for link data processing. Configure according to business needs (such as emergency vulnerability handling in the automotive industry). (hours), system real-time monitoring ,like If this occurs, an alarm mechanism will be triggered, notifying the administrator to investigate the bottleneck in the link.
[0101] This solution utilizes a comprehensive technical approach encompassing "precise intelligence gathering, dynamic risk quantification, attack prediction, key asset focus, scenario enhancement, and collaborative, explainable response" to create a progressively enhancing chain of technical effects.
[0102] First, S1 uses parallel data collection and standardized format conversion from multiple authoritative databases (including automotive industry-specific databases), coupled with data integrity verification and hierarchical encryption, to ensure that intelligence covers automotive ECU-specific scenarios. It also eliminates differences between multi-source data through format normalization and ensures data security through encrypted storage, providing comprehensive, standardized, and secure foundational data for subsequent analysis and avoiding analytical biases caused by missing intelligence or inconsistent formats. S2 relies on a multi-level keyword system and weighted cosine similarity filtering, combined with an intelligence aggregation and push mechanism, to accurately locate relevant intelligence for target ECUs and reduce redundant information. This improves filtering efficiency and reduces the information reception cost for contact persons, allowing for a focus on core intelligence in subsequent stages.
[0103] Secondly, S3 constructs an ECU asset association network and a high-order probabilistic graph model. On the one hand, through a dynamic weight adaptive mechanism, combined with ECU project label matching dimension weights, it adapts the vulnerability impact assessment to different vehicle models and functional scenarios, avoiding the one-size-fits-all problem of fixed weights. On the other hand, it updates the posterior probability of risk nodes through Bayes' theorem and calculates the comprehensive risk value through probability propagation algorithms, dynamically capturing the complex relationship between assets, vulnerabilities, and attacks. This upgrades risk assessment from "static qualitative" to "dynamic quantitative," significantly improving the accuracy and scenario adaptability of risk rating. S4 uses quantitative modeling of attack elements (cost, threshold, window) and self-learning of evolution coefficients (dynamically iterating parameters based on new attack technologies). Combined with dynamic probabilistic graph path prediction and propagation partial differential equation derivation, it can calculate the feasibility of the current attack in real time and predict the attack trend and spatiotemporal distribution in future periods. This transforms defense from "passive response" to "proactive foresight," providing a basis for deploying defense measures in advance.
[0104] Furthermore, S5 uses multimodal information fusion (text, numerical values, and graph structures) and GBDT feature weight learning, combined with asset association criticality calculation, to identify critical ECU assets from a dual dimension of "self-attribute + associated attributes," avoiding resource misallocation to non-critical assets, allowing vulnerability management to focus on core risk points and improving resource utilization efficiency. S6 uses a GAN generative model combined with historical scenario data to generate candidate hazard scenarios, and combines them with a multi-agent game system to build an attack and defense combination, supplementing the limitations of traditional scenario identification, enabling hazard analysis to cover "common scenarios + attack and defense game scenarios," providing more comprehensive scenario support for risk assessment, and avoiding the omission of potential hazards.
[0105] Finally, S7 achieves traceable management of vulnerability data through "relational database + blockchain". By combining cross-enterprise constraint satisfaction calculation and collaborative feasibility scoring, it breaks down information barriers in the industry chain, clarifies the responsibility nodes of each enterprise, solves the problem of cross-enterprise collaboration disconnect, and shortens the vulnerability remediation cycle. At the same time, it constructs a multi-objective optimization function with high-priority risk dimensions as the target, combines PSM causal inference to verify the rationality of the handling plan and generate an interpretable report, and is equipped with full-link automatic linkage and time delay monitoring. This ensures that the handling plan is "accurate and traceable" and guarantees the efficient operation of the process. Ultimately, it achieves full-process automation, accuracy and collaborative management from intelligence to handling, effectively solving the core pain points of insufficient automation, risk misjudgment, inefficient collaboration and lack of basis for handling in traditional vulnerability management.
[0106] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0107] In summary, this application has at least the following beneficial effects:
[0108] 1. Achieve fully automated management of network security vulnerabilities. By standardizing the collection of multi-source intelligence, accurately filtering keywords at multiple levels, dynamically quantifying risk assessment, and automatically linking the entire chain, it replaces the traditional manual management model, significantly reduces the cost of manual intervention, solves the problems of low automation and fragmented processes in traditional management, and improves the overall efficiency of vulnerability discovery and handling.
[0109] 2. Improve the accuracy and foresight of vulnerability risk assessment and defense. Rely on the dynamic weight adaptive mechanism to adapt to different ECU project scenarios. Combine with the high-order probabilistic graphical model to capture the complex relationship between assets, vulnerabilities and attacks. At the same time, through attack path prediction, evolution coefficient self-learning and attack propagation spatiotemporal extrapolation, identify high-risk attack trends in advance, and transform defense from passive response to proactive early warning to avoid security risks caused by risk misjudgment or defense lag.
[0110] 3. Break down collaboration barriers in the automotive industry chain and ensure the interpretability of disposal plans. Store enterprise constraint information through an encrypted industry chain collaboration database, and generate a time-series execution table by combining collaboration feasibility scores to clarify the responsibility nodes of upstream and downstream enterprises and solve the problem of cross-enterprise collaboration disconnect. At the same time, construct an optimization function with high-priority risk dimensions as the target, verify the rationality of disposal plans through causal inference and generate interpretable reports to ensure that disposal decisions are scientific and credible, and to balance collaboration efficiency and disposal quality.
[0111] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. An automated management method for network security vulnerabilities based on network security intelligence, characterized in that, This includes cybersecurity intelligence gathering, cybersecurity intelligence screening, cybersecurity intelligence storage and analysis, and cybersecurity vulnerability management; Cybersecurity intelligence gathering obtains cybersecurity intelligence for a specified period from multiple pre-defined authoritative vulnerability databases, including at least a database of vulnerabilities specific to the automotive industry, and converts it into a pre-defined standardized format. This format must include fields such as vulnerability name, information source, vulnerability number, vulnerability reporting time, severity, vulnerability description, affected customers, related projects, and project contact person. Cybersecurity intelligence screening uses configurable keywords to filter collected intelligence, obtain intelligence related to the target ECU product, and push it to the corresponding project contact person; The cybersecurity intelligence storage and analysis system archives and stores the filtered intelligence in a unified manner, supports multi-dimensional filtering based on vulnerability time period and affected products, and adopts preset threat analysis and risk assessment methods. These methods include analyzing the cybersecurity assets affected by the vulnerability, identifying threat scenarios and damage scenarios, assessing the degree of vulnerability impact and attack feasibility, and determining whether the weakness corresponding to the intelligence is a vulnerability. Network security vulnerability management provides unified management of information classified as vulnerabilities. It supports new projects in querying historical vulnerabilities by keyword matching to prevent recurrence. The vulnerability data storage format must include fields such as vulnerability name, vulnerability source, vulnerability number, discovery time, vulnerability description, scope of impact, analysis results, and remediation plan. When using preset threat analysis and risk assessment methods for cybersecurity intelligence storage and analysis, a dynamic weight adaptive mechanism is introduced. This mechanism extracts vehicle usage tags and ECU function tags from ECU projects, and determines the dynamic weights of four impact dimensions—security, operation, privacy, and property—based on preset tag-dimension weight mapping rules. The sum of the weights of each dimension is 1. The final impact rating is calculated by combining the original scores of each dimension, and is used in the vulnerability impact assessment stage. When using preset threat analysis and risk assessment methods, a higher-order probabilistic graphical model is introduced on the basis of the dynamic weight adaptive mechanism. The final impact rating calculated by the dynamic weights is used as the input parameter of the higher-order probabilistic graphical model to model the higher-order dependencies between assets, vulnerabilities, and attacks. The posterior probability of risk nodes is dynamically updated by combining Bayes' theorem, and the comprehensive risk value is calculated through a probability propagation algorithm. In the "Analyzing the impact of vulnerabilities on cybersecurity assets" stage of threat analysis and risk assessment, it is necessary to first construct an ECU asset association network and define the asset set. , Representing a single ECU asset, it includes one or more attributes such as asset ID, model, and function, as well as a set of edges that associate the assets. , Representing ECU assets and The relationships between assets are identified, including one or more of communication dependencies and data interactions. This network is stored in a graph database. For a single piece of intelligence, the "vulnerability description" field is extracted to identify the characteristics of the assets affected by the vulnerability. The asset association network is traversed to find asset nodes that match the characteristics and their directly associated nodes, thus forming a set of assets affected by the vulnerability. Complete the location of assets affected by the vulnerability; In the "Identifying Threat and Damage Scenarios" section, the vulnerability impacts the set of assets. Combining a pre-configured historical vulnerability handling case library, which stores the threat types and consequences of past vulnerabilities, cosine similarity matching is used to determine the similarity between historical cases and current vulnerabilities, defining a similarity function. ,in This is the feature vector of the current vulnerability. Includes vulnerability type, affected assets, and triggering conditions. The feature vectors of the historical cases to be acquired are used; the top preset number of historical cases with the highest similarity are selected, and their threat scenarios and damage scenarios are extracted as candidate scenarios for the current vulnerability. The system then combines the vulnerability's "severity" field to filter and complete the scenario identification. In the "Assessing the Impact of the Vulnerability" step, relying on a dynamic weight adaptive mechanism, the vehicle usage label of the target ECU project is first extracted. With ECU function label The usage tags include one or more of "passenger vehicles," "commercial vehicles," and "new energy vehicles," while the function tags include one or more of "power control," "body control," and "autonomous driving." The preset "tag-dimension weight mapping table" is queried to obtain... Safety, operate, privacy, The weights of the four dimensions of property influence, satisfying... ; Subsequently, a raw score was calculated for each impact dimension, and a scoring function was defined. , ,in The "severity" field of the intelligence is mapped to a numerical value. The scoring rules, based on feature tags and severity, ultimately influence the rating. The higher the score, the greater the degree of influence. In the "Assess Attack Feasibility" phase, based on the "Vulnerability Description" field of the vulnerability, three types of indicators are extracted: the technical threshold required for the attack, the equipment requirements, and the time cost, and these are assigned values accordingly. Attack feasibility score The lower the score, the higher the feasibility of the attack; If the final impact rating is not lower than the preset impact rating threshold and the attack feasibility score is not higher than the preset feasibility score threshold, then the weakness corresponding to the intelligence is determined to be a vulnerability; otherwise, it is determined to be a non-vulnerability, and is only archived to the intelligence database without entering the subsequent vulnerability management stage. In risk assessment incorporating higher-order probabilistic graphical models, Markov logic networks are used to construct the model and define a set of rules. , Rules describing the relationships between assets, vulnerabilities, and attacks; each rule Corresponding weight , Trained from historical vulnerability data, the more important the rule, the greater its weight. The joint probability distribution of the model is as follows: In the formula, For the set of risk state variables of all assets, for A certain state, For rules In state The number of times the following is satisfied, The partition function calculates the final impact rating based on dynamic weights. As input parameters, update the prior probabilities of asset nodes. Combined with Bayes' theorem The posterior probability of asset nodes is dynamically updated based on evidence of the current vulnerability. Finally, using a probability propagation algorithm, the posterior probability is propagated through the asset association network to calculate the comprehensive risk value of each asset node. This is used for subsequent vulnerability priority ranking, where... Risk status The score; The method also includes an attack path prediction process, which achieves linkage by synchronizing intelligence analysis data from the network security intelligence storage and analysis stage in real time through a data interface. The attack elements are broken down into three quantifiable indicators: attack cost, attack threshold, and attack window. A mapping relationship between the current attack elements and attack feasibility is constructed to calculate the current attack feasibility. At the same time, attack technology evolution data is accessed, and attack feasibility is predicted in the future within a time period that matches the update cycle of the attack technology evolution data according to preset evolution rules. The prediction results are then synchronized to the risk rating sub-stage of the network security intelligence storage and analysis stage. The attack path prediction process also includes an evolution coefficient self-learning process. This process crawls new attack technology entries from authoritative vulnerability databases in real time, extracts three types of features: attack technology type, threshold descent rate, and propagation speed. It trains the mapping relationship between features and evolution coefficients through a machine learning model that adjusts parameters based on historical prediction errors, dynamically updates the attack threshold descent coefficient and attack window extension coefficient, and optimizes model parameters based on prediction errors. The attack path prediction process also includes a dynamic attack deduction process. This process constructs a dynamic probabilistic graph model and updates node transition probabilities in real time. It uses path search combined with probabilistic pruning to generate all effective attack paths, calculates the path existence probability based on the product of attack transition probabilities between nodes, and models the attack propagation process through a dynamic model based on the evolution logic of attack propagation rate and asset association strength to predict the spatiotemporal distribution of attacks in the asset network. Intelligence analysis data synchronized through data interfaces, specifically including a pre-determined set of assets affected by vulnerabilities. Overall risk value R and attack feasibility score These data serve as the basic input for attack path prediction. After breaking down attack elements into attack cost, attack threshold, and attack window, a weighted summation model is used to quantify each type of indicator and construct a mapping relationship for the current attack feasibility. Where C is a quantitative indicator of attack cost, T is a quantitative indicator of attack threshold, and W is a quantitative indicator of attack window, determined based on the duration of exposure in an attackable environment. To preset the maximum attack cost threshold, To preset the maximum attack window threshold, Let be the weighting coefficient, satisfying , The closer the value is to 1, the higher the feasibility of the current attack; The attack technique evolution data is sourced from the monthly technology trend report of a pre-configured vulnerability database. This data includes one or more of the following: attack technique update frequency and the prevalence of exploit tools. The prevalence of exploit tools is derived from the monthly technology trend report and is a quantitative indicator used to characterize the development status of exploit tools. Preset evolution rules are based on a preset technology update cycle. Based on this, predict the future. Feasibility of attack within a specific time period ,in This represents the attack threshold reduction factor for pre-acquisition. To obtain the attack window shortening coefficient, if Then take 1, if Then take 0, and the prediction result is... This will be synchronized to the risk rating sub-process to adjust the overall risk value. ; During the self-learning process of evolution coefficients, new attack technology entries crawled in real time need to be categorized by "Attack Technology Type" and "Threshold Decrease Rate". "Speed of transmission" Extract features and construct feature vectors Typecode Typecode is the technology type encoding. A random forest model is used to train the mapping relationship between features and evolution coefficients. The model input is... The output is and Model parameter optimization is based on prediction error ,in To assess the feasibility of future attacks predicted by the model, To assess the feasibility of future attacks in actual observation, when At that time, the number of decision trees and the maximum depth parameter of the random forest are adjusted using the gradient descent method until... This enables dynamic optimization of the evolution coefficient; During the dynamic simulation of the attack, the nodes of the dynamic probabilistic graphical model are the ECU asset set. Edges represent attack transfer relationships between assets, and node transfer probabilities. Indicates from assets Successful attack to The probability is calculated as follows: ,in For assets The overall risk value, for and The strength of the association, To ensure the maximum combined risk value of all assets. The path search employs a depth-first search algorithm, starting from the assets affected by the vulnerability. Starting from the initial node, traverse all reachable nodes to generate attack paths, and then use probabilistic pruning to preserve the probability of path existence. Valid paths, probability of path existence ; The attack propagation process is modeled using partial differential equations to describe the spatiotemporal distribution of the attack in the asset network, defining the attack propagation density function. , indicating at time Asset location The degree of impact of the attack at that location satisfies the equation Where asset location x is the spatial coordinate mapping value corresponding to asset ID, The attack propagation and diffusion coefficient is based on the speed at which the attack technique spreads. set up, Let be the Laplace operator, representing the rate of change of the attack's diffusion in space; It is a logistic growth term. The attack growth coefficient is based on the asset correlation strength. By setting the average value and solving the equation numerically, we can obtain the values at different times. The following asset locations attack propagation density This allows for the prediction of the spatiotemporal distribution of attacks within the asset network, providing precise temporal and spatial guidance for the formulation of defense strategies. The method also includes a critical asset identification process. This process achieves linkage by synchronizing the vulnerability impact asset information and preliminary risk level data of the network security intelligence storage and analysis link in real time through a data interface. It integrates three types of multimodal data of ECU assets: textual functional description, numerical interactive data, and graph structure relationship. Multimodal information interaction is achieved through a multimodal information fusion mechanism. The criticality score of the asset is output by combining feature weight learning, and the criticality of the asset association is calculated based on the asset association strength to complete the critical asset identification. The multimodal information fusion mechanism employs a cross-attention mechanism to achieve interaction between data from different modalities, defining a fusion feature vector. The calculation process is as follows: First, calculate the cross-attention weights between the text modality and the numerical modality. The formula is ,in Dimensions representing text features Dimensions representing numerical features The dot product of the feature vectors of the two modes is used to measure the correlation between modes; then the fusion result is calculated. Cross-attention weights with graph modalities Finally, the feature vectors are fused. By highlighting the feature contributions of highly correlated modalities through attention weighting, we can ensure that the fusion results can comprehensively represent asset attributes. Feature weight learning employs a gradient boosting tree model to fuse feature vectors. Using the "frequency of historical vulnerability impact" of an asset as input, the model trains a mapping relationship between features and asset importance; the model outputs the weights of each fused feature dimension. ,satisfy , The total dimension of the fused features is then combined with the fused feature vector to calculate the asset criticality score. ,in For the fused feature vector Each dimension value A higher score indicates that the asset itself is more critical; Asset-related criticality calculation is based on asset-related networks, defining assets. The key to the relationship ,in For assets The set of directly related assets, that is, the asset association network with Nodes connected by edges for and correlation strength Related assets Key scores; The final determination of critical assets requires combining their own criticality with the criticality of related assets, and defining comprehensive criticality. ,in To find the maximum correlation key of all assets, normalize the correlation key to map it to... Interval, weight These represent the importance ratios of the attribute itself and related attributes, respectively; when At that time, the asset was determined to be a critical asset and included as a key focus for subsequent vulnerability mitigation; if If it is not a critical asset, it will be classified as a non-critical asset and will only be subject to routine monitoring. The method also includes a hazard scenario enhancement process, which is automatically triggered after the critical asset is identified to achieve linkage. Based on the functional characteristics of the critical asset and historical hazard scenario data, a hazard scenario is generated through a scenario generation model. At the same time, a game system between attacking and defending agents is constructed to generate an attack and defense game scenario. The optimal hazard scenario is matched for the newly identified critical asset based on feature similarity. The linkage trigger mechanism uses the output signal of the critical asset determination result in S5 as the trigger condition. When the system detects a critical asset set... During generation, To determine the number of key assets, the system automatically extracts the functional characteristics of each key asset from the asset attribute database. It also retrieves relevant data from a historical vulnerability scenario database—this database stores records of past vulnerability vulnerability scenarios. Each record contains a scenario ID and three core pieces of information: associated asset function, vulnerability manifestation, and triggering conditions, forming a historical scenario dataset. , This represents the number of historical records. The scene generation model uses a generative adversarial network, consisting of a generator. With discriminator Composition, generator The input is a pre-obtained random latent vector. Key asset functional feature vector The output is candidate hazard scenario text; discriminator The input consists of candidate scene text and real scene text from the historical scene dataset, and the output is the "realism score" of the text. The model training objective is to minimize the generator loss. With maximizing discriminator loss Until the model converges, the discriminator's truth score stabilizes at the preset score, where This represents the relationship between "random latent vector z" and "key asset functional feature vector". "Take the expected value, This indicates the "historical scene dataset" The mathematical expectation of the real-world scenario text d is taken; The attack-defense game system employs a multi-agent reinforcement learning framework to construct attack agents. With defensive intelligent agents Attacking the action space of intelligent agents Includes exploit methods, target assets, and the action space of the defensive agent. Including defensive measures and targets, the system defines the reward for the attacking agent using "attack success probability" and "defense cost" as reward functions. , The probability of a successful attack is based on the probability of the attack path existing. calculate; The cost of the attack, derived from the cost of the attack. The normalized value, the reward of the defensive agent , To normalize the defense cost, the agent is trained through a centralized training distributed execution framework until the two reach a Nash equilibrium, that is, one party cannot improve its reward by changing its actions alone. At this point, the combination of offensive and defensive actions constitutes an offensive and defensive game scenario, which is added to the candidate hazard scenario set. In the optimal hazard scenario matching process, the functional characteristics of newly identified key assets are first considered. Convert to feature vector Then, the text descriptions of all candidate scenes are converted into scene feature vectors. Calculate the cosine similarity between the two. Where • is the vector dot product, Let the vector magnitude be , Select the one with the highest similarity and The scenario with the highest similarity is selected as the optimal threat scenario. If the similarity of all scenarios is lower than the preset similarity threshold, the scenario with the highest similarity among the preset number of similar scenarios is selected. The number of scenarios to be retained is adjusted when filtering based on the "severity" of the vulnerability, and the optimal threat scenario is finally determined. This scenario is then used to supplement the scenario for subsequent vulnerability risk assessment and to formulate defense strategies.
2. The automated network security vulnerability management method based on network security intelligence according to claim 1, characterized in that, Cybersecurity vulnerability management also includes cross-enterprise collaboration processes. This process constructs an encrypted supply chain collaboration database, storing core business constraint information of upstream and downstream enterprises. Calculate the cross-enterprise constraint satisfaction and the internal enterprise constraint satisfaction to generate a collaborative feasibility score. The cross-enterprise constraint satisfaction is a three-party constraint compatibility index obtained by weighted summation based on the overlap duration of the update window, the utilization rate of test resources, and the matching degree of the repair cycle. The internal enterprise constraint satisfaction is calculated by each enterprise's internal system based on its own capacity conditions. A collaborative handling plan is output only when the collaborative feasibility score reaches a preset threshold, and a time-series execution table is generated to clarify the responsibility nodes of each enterprise.
3. The automated network security vulnerability management method based on network security intelligence according to claim 2, characterized in that, The vulnerability remediation phase of cybersecurity vulnerability management also includes an explainability-based collaborative process. This process uses the high-priority risk dimensions identified by dynamic weights as the treatment objectives, and constructs a multi-objective optimization function. The rationality of the treatment plan is analyzed through causal inference, and an explainable report containing results, evidence, and influencing factors is output. Simultaneously, it achieves fully automated linkage across the entire chain, including critical asset identification, hazard scenario matching, risk assessment, and disposal notification. Furthermore, the data transfer delay at each stage of the link does not exceed the maximum tolerable delay for link data processing.