POC-based vulnerability verification processing method and system

By using a Proof-of-Concept (POC)-based vulnerability verification and processing method, vulnerability feature monitoring values ​​and distribution heatmaps are obtained, and group analysis and risk assessment are performed. This solves the problem of insufficient accuracy and reliability of vulnerability verification in existing technologies, and achieves more efficient network security protection.

CN121056166APending Publication Date: 2025-12-02HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510933182.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-12-02

AI Technical Summary

Technical Problem

Existing vulnerability verification methods rely on single-dimensional detection data and lack analysis of vulnerability distribution, which makes it impossible to accurately identify the correlation and spread trend of vulnerabilities. Furthermore, when assessing system security, they ignore distribution characteristics and risk levels, resulting in insufficient accuracy and reliability.

Method used

By using a POC-based vulnerability verification and processing method, multiple vulnerability feature monitoring values ​​and distribution heatmaps of the vulnerability verification system are obtained, grouped and analyzed to determine the vulnerability distribution heatmap type, calculate the risk level and correlation factors, and determine whether the system vulnerability anomaly factors meet the preset security requirements.

Benefits of technology

It improves the accuracy and reliability of vulnerability verification, provides more effective technical support for network security protection, reduces false alarm rate, and ensures system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056166A_ABST
    Figure CN121056166A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a POC-based vulnerability verification processing method and system, and the method comprises the steps: determining a vulnerability verification system, and obtaining a plurality of vulnerability feature monitoring values and a vulnerability distribution thermodynamic diagram of the vulnerability verification system; each vulnerability distribution thermodynamic diagram is analyzed according to the vulnerability feature monitoring value, a vulnerability distribution thermodynamic diagram type corresponding to each vulnerability distribution thermodynamic diagram is determined, and the vulnerability distribution thermodynamic diagram type comprises a direct vulnerability distribution thermodynamic diagram and an indirect vulnerability distribution thermodynamic diagram; determining a system vulnerability abnormal factor of the vulnerability verification system according to the vulnerability feature monitoring value and the direct vulnerability distribution thermodynamic diagram; based on the relationship between the system vulnerability abnormal factor and the preset system vulnerability abnormal factor, whether the vulnerability verification system meets the preset security requirement or not is judged, the accuracy and reliability of vulnerability verification can be effectively improved, and more effective technical support is provided for network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically, to a vulnerability verification processing method and system based on Proof-of-Concept (POC). Background Technology

[0002] With the rapid development of information technology, cybersecurity issues are becoming increasingly prominent, and various systems are facing ever-increasing vulnerability threats. Vulnerability verification is a crucial step in ensuring system security, and vulnerability verification methods based on proof of concept (POC) can effectively simulate attack behaviors, verify the feasibility and severity of vulnerabilities, thereby providing a reliable basis for security protection.

[0003] Traditional vulnerability verification methods typically rely on static analysis or simple dynamic detection, making it difficult to comprehensively reflect the distribution characteristics and potential risks of vulnerabilities. For example, current technologies primarily rely on single-dimensional detection data, lacking analysis of vulnerability distribution, which leads to an inability to accurately identify the correlation and spread trends of vulnerabilities. Furthermore, when assessing system security, existing methods often rely solely on the number or severity of vulnerabilities, ignoring the distribution characteristics, risk levels, and dynamic changes in the overall system security status, resulting in insufficient accuracy and reliability of vulnerability verification. Summary of the Invention

[0004] This invention provides a vulnerability verification processing method and system based on Proof-of-Concept (POC). This invention can effectively improve the accuracy and reliability of vulnerability verification and provide more effective technical support for network security protection.

[0005] To achieve the above objectives, this invention provides a vulnerability verification processing method based on Proof-of-Concept (POC), comprising: Identify the vulnerability verification system and obtain multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system. The vulnerability distribution heatmap is analyzed based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap. The vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap. The system vulnerability anomaly factor of the vulnerability verification system is determined based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmap. Based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor, it is determined whether the vulnerability verification system meets the preset security requirements.

[0006] Furthermore, when analyzing each vulnerability distribution heatmap based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, the process includes: Each vulnerability distribution heatmap is grouped to obtain several verification groups. Each verification group includes three verification units, namely a first verification unit, a second verification unit, and a third verification unit. The second verification unit is adjacent to the first verification unit and the third verification unit, respectively. Determine the vulnerability association monitoring set corresponding to each verification group, wherein the vulnerability association monitoring set includes the vulnerability association value between the second verification unit and the first verification unit, and the vulnerability association value between the second verification unit and the third verification unit; Based on the trigger time of POC verification, the risk level corresponding to each verification unit is obtained; Based on the risk level corresponding to each verification unit, a risk monitoring set corresponding to the verification group is obtained, wherein the risk monitoring set includes the risk monitoring values ​​of the second verification unit and the first verification unit, and the risk monitoring values ​​of the second verification unit and the third verification unit; Calculate the vulnerability association factor corresponding to the verification group based on the vulnerability association monitoring set and risk monitoring set corresponding to the verification group; Based on the vulnerability association factors and preset vulnerability association factors, the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap is determined.

[0007] Furthermore, when determining the vulnerability association monitoring set corresponding to each verification group, the following are included: Sort all vulnerability feature monitoring values ​​in the first verification unit in descending order to obtain the first vulnerability feature monitoring value sequence. Sort all vulnerability feature monitoring values ​​in the second verification unit in descending order to obtain the second vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the first vulnerability feature monitoring value sequence and the second vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the first verification unit. Sort all vulnerability feature monitoring values ​​in the third verification unit in descending order to obtain the third vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the second vulnerability feature monitoring value sequence and the third vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the third verification unit. The vulnerability association monitoring set is obtained based on the vulnerability association values ​​between the second verification unit and the first verification unit, and between the second verification unit and the third verification unit.

[0008] Furthermore, when determining the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap based on the vulnerability association factor and the preset vulnerability association factor, the process includes: When the vulnerability association factor is less than the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be an indirect vulnerability distribution heatmap. When the vulnerability association factor is greater than or equal to the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be a direct vulnerability distribution heatmap.

[0009] Furthermore, when determining the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmap, the following steps are included: The vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps are analyzed to determine the system vulnerability dispersion value of the vulnerability verification system. Obtain the preset security value of the vulnerability verification system, and determine the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value, and direct vulnerability distribution heatmap; Based on the system vulnerability dispersion value and the vulnerability risk value, the system vulnerability anomaly factor of the vulnerability verification system is obtained.

[0010] Furthermore, when analyzing the vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps to determine the system vulnerability dispersion value of the vulnerability verification system, the following steps are included: The direct vulnerability distribution heatmap is divided into multiple vulnerability distribution regions, and the number of vulnerability distribution regions is determined. By randomly pairing any two vulnerability distribution areas, multiple groups of bound vulnerability distribution areas are obtained. The vulnerability feature differences of the vulnerability verification system are obtained based on the differences in vulnerability feature monitoring values ​​between every two vulnerability distribution area groups. The system vulnerability dispersion value of the vulnerability verification system is determined based on the number of vulnerability distribution areas and the differences in vulnerability characteristics.

[0011] Further, when obtaining the preset security value of the vulnerability verification system and determining the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value, and direct vulnerability distribution heatmap, the process includes: Calculate the mean vulnerability feature monitoring value for each vulnerability distribution area based on the vulnerability feature monitoring value, and extract the mean of the maximum vulnerability feature monitoring value and the mean of the minimum vulnerability feature monitoring value; Obtain the preset security value, wherein the preset security value includes a first preset security value and a second preset security value, and the first preset security value is less than the second preset security value; Determine the absolute value of the first difference between the average value of the maximum vulnerability feature monitoring value and the second preset security value; Determine the absolute value of the second difference between the mean of the minimum vulnerability feature monitoring values ​​and the first preset security value; The vulnerability risk value of the vulnerability verification system is determined based on the absolute value of the first difference and the absolute value of the second difference.

[0012] Further, when obtaining the system vulnerability anomaly factor of the vulnerability verification system based on the system vulnerability dispersion value and the vulnerability risk value, it includes: The system vulnerability anomaly factor of the vulnerability verification system is calculated according to the following formula: ; Where q is the system vulnerability anomaly factor of the vulnerability verification system, tanh is the hyperbolic tangent function, w is the system vulnerability dispersion value, and e is the vulnerability risk value.

[0013] Furthermore, when determining whether the vulnerability verification system meets the preset security requirements based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor, the following steps are included: When the system vulnerability anomaly factor is less than the preset system vulnerability anomaly factor, it is determined that the vulnerability verification system does not meet the preset security requirements. When the system vulnerability anomaly factor is greater than or equal to the preset system vulnerability anomaly factor, the vulnerability verification system is determined to meet the preset security requirements.

[0014] To achieve the above objectives, the present invention also provides a vulnerability verification and processing system based on Proof-of-Concept (POC), comprising: The acquisition module is used to identify the vulnerability verification system and acquire multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system. The classification module is used to analyze each vulnerability distribution heatmap based on the vulnerability feature monitoring values, and determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, wherein the vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap; The determination module is used to determine the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring value and the direct vulnerability distribution heatmap; The verification module is used to determine whether the vulnerability verification system meets the preset security requirements based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention identifies a vulnerability verification system by acquiring multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps. Based on the vulnerability feature monitoring values, each vulnerability distribution heatmap is analyzed to determine its corresponding type, which includes direct and indirect vulnerability distribution heatmaps. The system vulnerability anomaly factors of the vulnerability verification system are determined based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmaps. Based on the relationship between the system vulnerability anomaly factors and preset system vulnerability anomaly factors, it is determined whether the vulnerability verification system meets preset security requirements. This effectively improves the accuracy and reliability of vulnerability verification, providing more effective technical support for network security protection. Attached Figure Description

[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 A flowchart illustrating a vulnerability verification processing method based on Proof-of-Concept (POC) is shown in an embodiment of the present invention. Figure 2 A schematic diagram of a vulnerability verification and processing system based on Proof of Concept (POC) is shown in an embodiment of the present invention. Detailed Implementation

[0017] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.

[0018] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.

[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0020] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0021] The following is a description of preferred embodiments of the present invention in conjunction with the accompanying drawings.

[0022] like Figure 1 As shown, an embodiment of the present invention discloses a vulnerability verification processing method based on Proof-of-Concept (POC), comprising: S110: Determine the vulnerability verification system, and obtain multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system; In this embodiment, the vulnerability verification system refers to the system that performs vulnerability verification processing.

[0023] In this embodiment, the vulnerability signature monitoring value is key quantitative data extracted after scanning and testing the vulnerability verification system using a Proof of Concept (POC) verification tool. It is used to assess the severity and scope of the vulnerability. Here, the vulnerability signature monitoring value represents the degree of vulnerability impact.

[0024] In this embodiment, the vulnerability distribution heatmap is based on vulnerability feature monitoring values ​​and uses visualization technology (such as color depth and area marking) to intuitively display the distribution of vulnerabilities in the vulnerability verification system.

[0025] S120: Analyze each vulnerability distribution heatmap based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, wherein the vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap; In some embodiments of this application, when analyzing each vulnerability distribution heatmap based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, the following steps are included: Each vulnerability distribution heatmap is grouped to obtain several verification groups. Each verification group includes three verification units, namely a first verification unit, a second verification unit, and a third verification unit. The second verification unit is adjacent to the first verification unit and the third verification unit, respectively. Determine the vulnerability association monitoring set corresponding to each verification group, wherein the vulnerability association monitoring set includes the vulnerability association value between the second verification unit and the first verification unit, and the vulnerability association value between the second verification unit and the third verification unit; Based on the trigger time of POC verification, the risk level corresponding to each verification unit is obtained; Based on the risk level corresponding to each verification unit, a risk monitoring set corresponding to the verification group is obtained, wherein the risk monitoring set includes the risk monitoring values ​​of the second verification unit and the first verification unit, and the risk monitoring values ​​of the second verification unit and the third verification unit; Calculate the vulnerability association factor corresponding to the verification group based on the vulnerability association monitoring set and risk monitoring set corresponding to the verification group; Based on the vulnerability association factors and preset vulnerability association factors, the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap is determined.

[0026] In this embodiment, the present invention uses a clustering method to group each vulnerability distribution heatmap into several verification groups. The specific process is relatively mature and will not be described in detail here.

[0027] In this embodiment, when obtaining the risk level corresponding to each verification unit based on the trigger time of POC verification, the following steps are included: Trigger time: The time interval between POC injection and vulnerability triggering, reflecting the difficulty of exploitation.

[0028] The risk level for each verification unit is calculated using the following formula: ; Where y is the risk level, t1 is the trigger time, and t is the time threshold.

[0029] In this embodiment, when calculating the vulnerability association factor corresponding to the verification group based on the vulnerability association monitoring set and risk monitoring set corresponding to the verification group, the following steps are included: Configure a first calculation coefficient for the vulnerability association monitoring set, preferably 0.6, and configure a second calculation coefficient for the risk monitoring set, preferably 0.4; The vulnerability association factor corresponding to the verification group is calculated using the following formula: ; Where u is the vulnerability association factor corresponding to the verification group, p1 is the number of vulnerability association values ​​in the vulnerability association monitoring set, and a i Let a be the i-th vulnerability association value in the vulnerability association monitoring set. min a is the minimum vulnerability association value in the vulnerability association monitoring set. max p1 represents the maximum vulnerability association value in the vulnerability association monitoring set, p2 represents the number of risk levels in the risk monitoring set, and g represents the maximum vulnerability association value in the vulnerability association monitoring set. d For the i-th risk level in the risk monitoring set, k min k represents the minimum risk level in the risk monitoring set. max This represents the highest risk level within the risk monitoring cluster.

[0030] The beneficial effects of the above technical solution are: the present invention determines the vulnerability association monitoring set and the risk monitoring set, and calculates the vulnerability association factor corresponding to the verification group based on the vulnerability association monitoring set and the risk monitoring set, which can characterize the association of vulnerability risks within the verification group and lay the foundation for vulnerability verification processing of POC.

[0031] In some embodiments of this application, determining the vulnerability association monitoring set corresponding to each verification group includes: Sort all vulnerability feature monitoring values ​​in the first verification unit in descending order to obtain the first vulnerability feature monitoring value sequence. Sort all vulnerability feature monitoring values ​​in the second verification unit in descending order to obtain the second vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the first vulnerability feature monitoring value sequence and the second vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the first verification unit. Sort all vulnerability feature monitoring values ​​in the third verification unit in descending order to obtain the third vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the second vulnerability feature monitoring value sequence and the third vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the third verification unit. The vulnerability association monitoring set is obtained based on the vulnerability association values ​​between the second verification unit and the first verification unit, and between the second verification unit and the third verification unit.

[0032] In this embodiment, the vulnerability feature monitoring values ​​in the first vulnerability feature monitoring value sequence and the second vulnerability feature monitoring value sequence are extracted one-to-one in sequence. That is, the largest vulnerability feature monitoring value is extracted from the first vulnerability feature monitoring value sequence and the largest vulnerability feature monitoring value is extracted from the second vulnerability feature monitoring value sequence. The absolute value of the difference between the two vulnerability feature monitoring values ​​is calculated as a vulnerability association value. The remaining vulnerability feature monitoring values ​​are extracted one-to-one in sequence until all are extracted. It should be noted that if there is a single vulnerability feature monitoring value in the first vulnerability feature monitoring value sequence or the second vulnerability feature monitoring value sequence that has not been extracted, it can be deleted.

[0033] In this embodiment, by repeating the above steps, the vulnerability association values ​​between the second verification unit and the first verification unit, and the vulnerability association values ​​between the second verification unit and the third verification unit can be obtained.

[0034] The beneficial effects of the above technical solution are: the present invention obtains a vulnerability association monitoring set based on the vulnerability association values ​​between the second verification unit and the first verification unit, and between the second verification unit and the third verification unit, which can determine the distribution and association of all vulnerability feature monitoring values ​​in the verification group, laying the foundation for subsequent elimination of vulnerability feature monitoring values ​​with weak association.

[0035] In some embodiments of this application, as described above, a risk monitoring set corresponding to the verification group is obtained based on the risk level corresponding to each verification unit. The risk monitoring set includes the risk monitoring values ​​of the second verification unit and the first verification unit, and the risk monitoring values ​​of the second verification unit and the third verification unit. The method for determining the risk monitoring set is the same as that for the vulnerability association monitoring set, and can be adaptively determined. To avoid lengthiness, it will not be described again.

[0036] In some embodiments of this application, when determining the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap based on the vulnerability association factor and the preset vulnerability association factor, the following is included: When the vulnerability association factor is less than the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be an indirect vulnerability distribution heatmap. When the vulnerability association factor is greater than or equal to the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be a direct vulnerability distribution heatmap.

[0037] In this embodiment, the preset vulnerability association factor is preferably 6, but it can be adjusted adaptively according to the actual situation.

[0038] The beneficial effects of the above technical solution are: based on the vulnerability association factor and the preset vulnerability association factor, the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap can be determined, which can eliminate indirect vulnerability distribution heatmaps and effectively reduce the false alarm rate of vulnerability verification and processing.

[0039] S130: Determine the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmap; In some embodiments of this application, determining the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring value and the direct vulnerability distribution heatmap includes: The vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps are analyzed to determine the system vulnerability dispersion value of the vulnerability verification system. Obtain the preset security value of the vulnerability verification system, and determine the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value and direct vulnerability distribution heat map; Based on the system vulnerability dispersion value and the vulnerability risk value, the system vulnerability anomaly factor of the vulnerability verification system is obtained.

[0040] In some embodiments of this application, when analyzing the vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps to determine the system vulnerability dispersion value of the vulnerability verification system, the following steps are included: The direct vulnerability distribution heatmap is divided into multiple vulnerability distribution regions, and the number of vulnerability distribution regions is determined. By randomly pairing any two vulnerability distribution areas, multiple groups of bound vulnerability distribution areas are obtained. The vulnerability feature differences of the vulnerability verification system are obtained based on the differences in vulnerability feature monitoring values ​​between every two vulnerability distribution area groups. The system vulnerability dispersion value of the vulnerability verification system is determined based on the number of vulnerability distribution areas and the differences in vulnerability characteristics.

[0041] In this embodiment, the direct vulnerability distribution heatmap is divided into multiple vulnerability distribution areas, which is also based on the clustering method.

[0042] In this embodiment, when obtaining the vulnerability feature difference of the vulnerability verification system based on the difference in vulnerability feature monitoring values ​​in each of two vulnerability distribution area groups, the sum of vulnerability feature monitoring values ​​in each vulnerability distribution area group is calculated, and then the vulnerability feature difference of the vulnerability verification system is obtained based on the absolute value of the difference between the sums corresponding to the two bound vulnerability distribution area groups.

[0043] In this embodiment, the system vulnerability dispersion value of the vulnerability verification system is calculated according to the following formula: ; Where c is the system vulnerability dispersion value of the vulnerability verification system, m is the number of vulnerability feature differences, and v b Let m1 be the difference in the characteristics of the b-th vulnerability, and m1 be the number of vulnerability distribution areas.

[0044] The beneficial effects of the above technical solution are: the present invention determines the system vulnerability dispersion value of the vulnerability verification system based on the number of vulnerability distribution areas and the differences in vulnerability characteristics, and obtains the dispersion degree of vulnerability feature monitoring values, which provides reliable technical support for vulnerability verification and processing, and further ensures the accuracy of vulnerability verification and processing.

[0045] In some embodiments of this application, when obtaining a preset security value of the vulnerability verification system and determining the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value, and direct vulnerability distribution heatmap, the process includes: Calculate the mean vulnerability feature monitoring value for each vulnerability distribution area based on the vulnerability feature monitoring value, and extract the mean of the maximum vulnerability feature monitoring value and the mean of the minimum vulnerability feature monitoring value; Obtain the preset security value, wherein the preset security value includes a first preset security value and a second preset security value, and the first preset security value is less than the second preset security value; Determine the absolute value of the first difference between the average value of the maximum vulnerability feature monitoring value and the second preset security value; Determine the absolute value of the second difference between the mean of the minimum vulnerability feature monitoring values ​​and the first preset security value; The vulnerability risk value of the vulnerability verification system is determined based on the absolute value of the first difference and the absolute value of the second difference.

[0046] In this embodiment, the first preset safety value is preferably 0.4, and the second preset safety value is preferably 0.7. The specific values ​​can be adjusted according to the actual situation.

[0047] In this embodiment, the product of the absolute value of the first difference and the absolute value of the second difference is used as the vulnerability risk value of the vulnerability verification system.

[0048] The beneficial effects of the above technical solution are: the present invention determines the vulnerability risk value of the vulnerability verification system based on the absolute value of the first difference and the absolute value of the second difference, obtains the risk level of the vulnerability feature monitoring value, provides reliable technical support for vulnerability verification processing, and further ensures the accuracy of vulnerability verification processing.

[0049] In some embodiments of this application, when obtaining the system vulnerability anomaly factor of the vulnerability verification system based on the system vulnerability dispersion value and the vulnerability risk value, the following steps are included: The system vulnerability anomaly factor of the vulnerability verification system is calculated according to the following formula: ; Where q is the system vulnerability anomaly factor of the vulnerability verification system, tanh is the hyperbolic tangent function, w is the system vulnerability dispersion value, and e is the vulnerability risk value.

[0050] S140: Based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor, determine whether the vulnerability verification system meets the preset security requirements.

[0051] In some embodiments of this application, when determining whether the vulnerability verification system meets preset security requirements based on the relationship between the system vulnerability anomaly factor and a preset system vulnerability anomaly factor, the following methods are included: When the system vulnerability anomaly factor is less than the preset system vulnerability anomaly factor, it is determined that the vulnerability verification system does not meet the preset security requirements. When the system vulnerability anomaly factor is greater than or equal to the preset system vulnerability anomaly factor, the vulnerability verification system is determined to meet the preset security requirements.

[0052] In this embodiment, the preset system vulnerability anomaly factor is preferably 3, but it can be adjusted adaptively according to the actual situation.

[0053] The beneficial effects of the above technical solution are: Based on the relationship between system vulnerability anomaly factors and preset system vulnerability anomaly factors, the present invention determines whether the vulnerability verification system meets preset security requirements, which can effectively improve the accuracy and reliability of vulnerability verification and provide more effective technical support for network security protection.

[0054] To further illustrate the technical concept of this invention, the technical solution of this invention will now be described in conjunction with specific application scenarios.

[0055] Correspondingly, such as Figure 2 As shown, this application also provides a vulnerability verification and processing system based on Proof-of-Concept (POC), including: The acquisition module is used to identify the vulnerability verification system and acquire multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system. The classification module is used to analyze each vulnerability distribution heatmap based on the vulnerability feature monitoring values, and determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, wherein the vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap; The determination module is used to determine the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring value and the direct vulnerability distribution heatmap; The verification module is used to determine whether the vulnerability verification system meets the preset security requirements based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor.

[0056] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments or examples.

[0057] Although the invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the embodiments disclosed in this invention can be combined with each other in any way. The fact that not all of these combinations are described in this specification is merely for the sake of brevity and resource conservation.

[0058] It will be understood by those skilled in the art that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A vulnerability verification and processing method based on Proof-of-Concept (POC), characterized in that, include: Identify the vulnerability verification system and obtain multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system. The vulnerability distribution heatmap is analyzed based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap. The vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap. The system vulnerability anomaly factor of the vulnerability verification system is determined based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmap. Based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor, it is determined whether the vulnerability verification system meets the preset security requirements.

2. The vulnerability verification and processing method based on Proof-of-Concept (POC) according to claim 1, characterized in that, When analyzing each vulnerability distribution heatmap based on the vulnerability feature monitoring values ​​to determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, the following steps are included: Each vulnerability distribution heatmap is grouped to obtain several verification groups. Each verification group includes three verification units, namely a first verification unit, a second verification unit, and a third verification unit. The second verification unit is adjacent to the first verification unit and the third verification unit, respectively. Determine the vulnerability association monitoring set corresponding to each verification group, wherein the vulnerability association monitoring set includes the vulnerability association value between the second verification unit and the first verification unit, and the vulnerability association value between the second verification unit and the third verification unit; Based on the trigger time of POC verification, the risk level corresponding to each verification unit is obtained; Based on the risk level corresponding to each verification unit, a risk monitoring set corresponding to the verification group is obtained, wherein the risk monitoring set includes the risk monitoring values ​​of the second verification unit and the first verification unit, and the risk monitoring values ​​of the second verification unit and the third verification unit; Calculate the vulnerability association factor corresponding to the verification group based on the vulnerability association monitoring set and risk monitoring set corresponding to the verification group; Based on the vulnerability association factors and preset vulnerability association factors, the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap is determined.

3. The vulnerability verification and processing method based on Proof-of-Concept (POC) according to claim 2, characterized in that, When determining the vulnerability association monitoring set corresponding to each verification group, the following are included: Sort all vulnerability feature monitoring values ​​in the first verification unit in descending order to obtain the first vulnerability feature monitoring value sequence. Sort all vulnerability feature monitoring values ​​in the second verification unit in descending order to obtain the second vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the first vulnerability feature monitoring value sequence and the second vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the first verification unit. Sort all vulnerability feature monitoring values ​​in the third verification unit in descending order to obtain the third vulnerability feature monitoring value sequence. The vulnerability feature monitoring values ​​in the second vulnerability feature monitoring value sequence and the third vulnerability feature monitoring value sequence are extracted one by one in sequence, and the absolute value of the difference between the two extracted vulnerability feature monitoring values ​​is calculated as the vulnerability association value between the second verification unit and the third verification unit. The vulnerability association monitoring set is obtained based on the vulnerability association values ​​between the second verification unit and the first verification unit, and between the second verification unit and the third verification unit.

4. The vulnerability verification and processing method based on Proof-of-Concept (POC) according to claim 2, characterized in that, When determining the type of vulnerability distribution heatmap corresponding to each vulnerability distribution heatmap based on the vulnerability association factor and the preset vulnerability association factor, the following is included: When the vulnerability association factor is less than the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be an indirect vulnerability distribution heatmap. When the vulnerability association factor is greater than or equal to the preset vulnerability association factor, the corresponding vulnerability distribution heatmap is determined to be a direct vulnerability distribution heatmap.

5. The vulnerability verification and processing method based on POC according to claim 1, characterized in that, When determining the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring values ​​and the direct vulnerability distribution heatmap, the following are included: The vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps are analyzed to determine the system vulnerability dispersion value of the vulnerability verification system. Obtain the preset security value of the vulnerability verification system, and determine the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value, and direct vulnerability distribution heatmap; Based on the system vulnerability dispersion value and the vulnerability risk value, the system vulnerability anomaly factor of the vulnerability verification system is obtained.

6. The vulnerability verification and processing method based on POC according to claim 5, characterized in that, When analyzing the vulnerability feature monitoring values ​​and direct vulnerability distribution heatmaps to determine the system vulnerability dispersion value of the vulnerability verification system, the following steps are included: The direct vulnerability distribution heatmap is divided into multiple vulnerability distribution regions, and the number of vulnerability distribution regions is determined. By randomly pairing any two vulnerability distribution areas, multiple groups of bound vulnerability distribution areas are obtained. The vulnerability feature differences of the vulnerability verification system are obtained based on the differences in vulnerability feature monitoring values ​​between every two vulnerability distribution area groups. The system vulnerability dispersion value of the vulnerability verification system is determined based on the number of vulnerability distribution areas and the differences in vulnerability characteristics.

7. The vulnerability verification and processing method based on POC according to claim 5, characterized in that, When obtaining the preset security value of the vulnerability verification system, and determining the vulnerability risk value of the vulnerability verification system based on the preset security value, vulnerability feature monitoring value, and direct vulnerability distribution heatmap, the process includes: Calculate the mean vulnerability feature monitoring value for each vulnerability distribution area based on the vulnerability feature monitoring value, and extract the mean of the maximum vulnerability feature monitoring value and the mean of the minimum vulnerability feature monitoring value; Obtain the preset security value, wherein the preset security value includes a first preset security value and a second preset security value, and the first preset security value is less than the second preset security value; Determine the absolute value of the first difference between the average value of the maximum vulnerability feature monitoring value and the second preset security value; Determine the absolute value of the second difference between the mean of the minimum vulnerability feature monitoring values ​​and the first preset security value; The vulnerability risk value of the vulnerability verification system is determined based on the absolute value of the first difference and the absolute value of the second difference.

8. The vulnerability verification and processing method based on POC according to claim 5, characterized in that, When obtaining the system vulnerability anomaly factor of the vulnerability verification system based on the system vulnerability dispersion value and the vulnerability risk value, the following are included: The system vulnerability anomaly factor of the vulnerability verification system is calculated according to the following formula: ; Where q is the system vulnerability anomaly factor of the vulnerability verification system, tanh is the hyperbolic tangent function, w is the system vulnerability dispersion value, and e is the vulnerability risk value.

9. The vulnerability verification and processing method based on Proof-of-Concept (POC) according to claim 1, characterized in that, When determining whether the vulnerability verification system meets preset security requirements based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor, the following steps are included: When the system vulnerability anomaly factor is less than the preset system vulnerability anomaly factor, it is determined that the vulnerability verification system does not meet the preset security requirements. When the system vulnerability anomaly factor is greater than or equal to the preset system vulnerability anomaly factor, the vulnerability verification system is determined to meet the preset security requirements.

10. A vulnerability verification and processing system based on Proof-of-Concept (POC), applied to the vulnerability verification and processing method based on POC as described in any one of claims 1-9, characterized in that, include: The acquisition module is used to identify the vulnerability verification system and acquire multiple vulnerability feature monitoring values ​​and vulnerability distribution heatmaps of the vulnerability verification system. The classification module is used to analyze each vulnerability distribution heatmap based on the vulnerability feature monitoring values, and determine the vulnerability distribution heatmap type corresponding to each vulnerability distribution heatmap, wherein the vulnerability distribution heatmap type includes direct vulnerability distribution heatmap and indirect vulnerability distribution heatmap; The determination module is used to determine the system vulnerability anomaly factor of the vulnerability verification system based on the vulnerability feature monitoring value and the direct vulnerability distribution heatmap; The verification module is used to determine whether the vulnerability verification system meets the preset security requirements based on the relationship between the system vulnerability anomaly factor and the preset system vulnerability anomaly factor.