Centralized management and control platform and management and control method based on vulnerability defect publishing mechanism

By using a centralized management platform based on a vulnerability release mechanism, the platform integrates and intelligently analyzes data from multiple sources, generates customized risk levels for enterprises, and conducts targeted, graded push notifications and collaborative handling. This solves the problem of low efficiency in vulnerability management in existing technologies and enables precise vulnerability handling and cost reduction.

CN121508982APending Publication Date: 2026-02-10NINGDONG POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511700619.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-19
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing technologies lack centralized management solutions that integrate multi-party data, perform intelligent analysis, and drive efficient collaboration, resulting in long cycles, high costs, and poor results in the process of vulnerability discovery and remediation.

Method used

This paper provides a centralized management and control platform based on a vulnerability and defect release mechanism, including a data collection and aggregation module, a vulnerability analysis and assessment module, a vulnerability release and push module, a collaborative handling and process management module, and a panoramic situation display and reporting module. It can integrate and intelligently analyze data from multiple parties, generate customized risk levels for enterprises, and carry out targeted hierarchical push and collaborative handling.

Benefits of technology

Through data integration and intelligent analysis, vulnerabilities were accurately addressed, the repair cycle was shortened, costs were reduced, and control effectiveness was improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508982A_ABST
    Figure CN121508982A_ABST
Patent Text Reader

Abstract

The invention provides a centralized management and control platform and management and control method based on a vulnerability and defect release mechanism, and relates to the technical field of power system network security, the platform comprises: a data acquisition and convergence module obtaining vulnerability and defect data from a plurality of heterogeneous data sources, and mapping the vulnerability and defect data into unified standardized vulnerability data; the vulnerability analysis and evaluation module determines a potentially affected internal list and generates an enterprise customization risk level according to the standardized vulnerability data; a vulnerability publishing and pushing module generates a vulnerability announcement according to a risk assessment result, and performs directional and hierarchical pushing; the co-processing and process management module creates a processing task work order according to the vulnerability announcement, and assigns the work order to a person in charge; and the panoramic situation display and report module visually displays the vulnerability situation of the whole platform. According to the scheme, multi-party data can be integrated, intelligent analysis and driving efficient cooperation can be realized, management and control of vulnerability defects are realized, the period is shortened, the cost is reduced, and the management and control effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system network security technology, and in particular to a centralized management and control platform and method based on a vulnerability release mechanism. Background Technology

[0002] With the rapid development of information technology, software, hardware, and network systems have become increasingly complex, leading to an explosive growth in security vulnerabilities and flaws. If exploited by malicious attackers, these vulnerabilities can result in data breaches, service disruptions, financial losses, and even severe damage to critical infrastructure. Therefore, timely and effective detection, assessment, and remediation of vulnerabilities have become core aspects of cybersecurity efforts for enterprises and organizations.

[0003] However, in current operations, the management and response to vulnerabilities generally face severe challenges, with the following prominent problems: (1) Information silos and data overload: Vulnerability information comes from various channels, including national vulnerability databases (such as CNNVD), announcements from commercial security companies, open-source communities, and internal security scans and penetration tests. These data have different formats, different descriptions, and are numerous. Security teams need to invest a lot of manpower in manual collection, sorting, deduplication, and classification, which is inefficient and prone to missing key vulnerability information, resulting in security blind spots. (2) Difficulty in assessing the scope of impact: After obtaining publicly available vulnerability information, the most critical step is to determine whether it poses a threat to one's own business system. Traditional methods rely heavily on the manual experience and memory of security personnel, manually comparing the software versions affected by the vulnerability with the internal asset list. For large organizations with tens of thousands of assets, this process is not only time-consuming and laborious, but also difficult to guarantee accuracy, often resulting in misjudgments or omissions, either wasting resources to fix non-existent risks or ignoring real security vulnerabilities. (3) Confused risk prioritization: General vulnerability scoring systems (such as CVSS) provide a basic risk score, but do not consider the business context of a specific organization. A high-scoring vulnerability in CVSS may be fatal to a system directly exposed to the Internet, but may pose limited risk to the same system in a deeply isolated network environment. The lack of contextualized risk assessment that combines asset importance and existing protection measures leads to endless remediation work. Security teams often have difficulty making decisions about which vulnerabilities to fix and which to fix first, and cannot allocate limited resources to where they are most needed. (4) Inefficient collaborative handling: Vulnerability remediation involves multiple departments, such as security teams, operations teams, and development teams. Currently, notifications and written communication are generally conducted via email and instant messaging tools, resulting in a loose process. Vulnerability information transmission is not standardized, responsibility is not clearly defined, the remediation process is difficult to track, and closed-loop management is lacking. It is common for notifications to be sent but not received, the remediation progress is unknown, and whether the remediation was successful cannot be effectively verified, allowing vulnerabilities to persist for a long time even when known. (5) Lack of global situational awareness: Management cannot quickly and intuitively understand the vulnerability situation of the entire organization. Because the data is scattered across various tables and communication records, it is difficult to form a unified view and quantifiable reports, which hinders effective security management and decision-making.

[0004] In summary, existing technologies lack a centralized management solution that can integrate multi-party data, perform intelligent analysis, and drive efficient collaboration in the management of vulnerabilities and defects. This results in long cycles, high costs, and poor effectiveness in the process of vulnerability discovery and remediation. Summary of the Invention

[0005] In view of this, to address at least one of the above-mentioned shortcomings, it is necessary to propose a centralized management platform and management method based on a vulnerability and defect release mechanism. This platform and method can achieve the management and control of vulnerabilities and defects by integrating multi-party data, intelligent analysis, and driving efficient collaboration, thereby shortening the cycle, reducing costs, and improving management and control effectiveness.

[0006] In a first aspect, the present invention provides a centralized management and control platform based on a vulnerability and defect release mechanism. The centralized management and control platform includes: a data collection and aggregation module, a vulnerability analysis and assessment module, a vulnerability release and push module, a collaborative handling and process management module, and a panoramic situation display and reporting module.

[0007] The data acquisition and aggregation module is used to collect, crawl and receive raw vulnerability and defect data from multiple heterogeneous data sources, and map the vulnerability and defect data from different sources into a unified standardized data model to obtain standardized vulnerability data.

[0008] The vulnerability analysis and assessment module is used to determine a potentially affected internal list and generate a customized risk level for the enterprise based on the standardized vulnerability data, thereby obtaining a risk assessment result.

[0009] The vulnerability publication and push module is used to generate vulnerability announcements based on the risk assessment results and push them to predefined different roles and responsible parties in a targeted and hierarchical manner.

[0010] The collaborative handling and process management module is used to receive the vulnerability announcement, create handling task work orders based on the vulnerability announcement, and assign the created handling task work orders to the corresponding responsible personnel.

[0011] The panoramic situation display and reporting module is used to visually display the vulnerability situation of the entire platform; wherein, the vulnerability situation includes, but is not limited to: vulnerability risk distribution map, ranking of vulnerability handling efficiency of each department, statistics of high-risk vulnerabilities to be processed, and periodic vulnerability management reports.

[0012] Preferably, the heterogeneous data sources include, but are not limited to: national vulnerability databases, third-party security vendor vulnerability databases, open-source community security announcements, internal code audit tool reports, and external penetration test reports;

[0013] And / or,

[0014] The standardized data model includes: vulnerability number, CVE number, CVSS risk level, affected asset type, vulnerability description, remediation suggestion, disclosure time, data source, and extended fields for collaborative action; wherein, the extended fields include: an internal vulnerability identifier that represents a unique tracking number generated by the platform for each access vulnerability, a collaborative action status identifier that indicates the stage of the vulnerability in the internal handling process, and designated collaborative team members and remediation time limits.

[0015] Preferably, the vulnerability analysis and assessment module includes: an impact scope matching unit and a multi-dimensional risk assessment unit;

[0016] The impact scope matching unit is used to match the types of assets affected by the vulnerability with the IT assets, network devices, industrial control equipment and software components registered in the platform asset library to determine the list of potentially affected internal assets.

[0017] The multidimensional risk assessment unit is used to recalibrate risks based on the CVSS basic score and combined with internal environmental factors of the enterprise to generate a customized risk level for the enterprise; wherein, the environmental factors include: asset importance, the degree of attenuation of vulnerability exploitability under existing protection measures, and potential business impact.

[0018] Preferably, the multidimensional risk assessment unit is configured to perform the following operations when performing risk recalibration:

[0019] Construct a risk calibration weight matrix; the factors of this risk calibration weight matrix include: asset importance weight, existing protection measures mitigation coefficient, and vulnerability attack popularity;

[0020] Calculate the customized risk score: where the customized risk score = CVSS base score × asset importance weight × (1 - existing protection measures mitigation coefficient) + additional score for vulnerability attack popularity;

[0021] The risk level of the vulnerability is re-determined based on the customized risk score, resulting in the enterprise's customized risk level.

[0022] Preferably, the vulnerability release and push module includes: an announcement template library unit and a push channel management unit;

[0023] The announcement template library unit is used to provide customizable announcement templates for different vulnerability types and risk levels;

[0024] The push channel management unit is used to support the push of vulnerability announcements based on targeted and hierarchical mechanisms through email, instant messaging tools, internal work order systems and API interfaces.

[0025] Preferably, the push channel management unit includes: a role and subscription strategy management subunit, a content classification mechanism subunit, and a push triggering rule subunit;

[0026] The role and subscription policy management subunit is used by platform administrators to define different user roles and configure the vulnerability types, risk levels, and asset scope of concern for each role; and is also used for users to customize subscription policies.

[0027] The content classification mechanism subunit is used to push complete vulnerability announcements for urgent and high-risk vulnerabilities, and simplified security alerts for medium-risk and low-risk vulnerabilities; wherein, the vulnerability announcement includes: detailed technical details, exploit code and remediation plan; the security alert includes: vulnerability overview and remediation suggestions;

[0028] The push triggering rule subunit supports three modes: manual triggering, scheduled batch release, and automatic triggering based on risk level, ensuring that critical vulnerability information is communicated in a timely manner.

[0029] Preferably, the collaborative handling and process management module includes: a handling task work order creation unit, a task assignment unit, a process driving engine unit, a collaboration space unit, and an asset management and relationship mapping library unit;

[0030] The task creation unit is used to create a task creation unit based on the vulnerability announcement.

[0031] The task assignment unit is used to assign the disposal task work order to the corresponding system administrator, development team or security operation and maintenance personnel according to the asset responsibility relationship.

[0032] The process-driven engine unit is used to preset several states of the processing task work order and to track and update them throughout the entire repair lifecycle.

[0033] The collaborative space unit is used to provide an independent discussion area for each vulnerability handling task, supporting communication and uploading of remediation evidence by remediation personnel, security teams and administrators.

[0034] The asset management and relationship mapping library unit is used to store and manage all relevant IT and industrial control asset information of the enterprise.

[0035] Preferably, the collaborative processing and process management module further includes: an automatic reminder and upgrade unit, a repair and verification unit, and a closed-loop audit tracking unit;

[0036] The automatic reminder and escalation unit is used to automatically send a reminder notice to the responsible personnel when the task work order has not entered the next state within the set time limit; if it is not processed within the time limit, the task work order will be automatically reported to the responsible personnel's superior or a higher-level security administrator.

[0037] The repair verification unit is used to automatically trigger the verification process after the repair personnel mark the repair as completed. It can either call the integrated vulnerability scanning tool API to rescan the target asset or assign the verification task to the security team for manual confirmation.

[0038] The closed-loop audit tracking unit is used to fully record all operation logs, communication records and timestamps throughout the entire lifecycle of vulnerability discovery, release, assignment, repair to verification, forming an immutable audit chain.

[0039] Preferably, the centralized management and control platform further includes an optimization and feedback module; the optimization and feedback module includes a performance measurement unit, a process optimization analysis unit, and a feedback unit;

[0040] The performance measurement unit is used to automatically calculate and display key performance indicators (KPIs) for each team or individual based on the data from the task handling work orders; wherein the KPIs include: average remediation time, number of backlogged vulnerabilities, and on-time completion rate;

[0041] The process optimization and analysis unit is used to identify process bottlenecks by analyzing the time consumption of each stage in the life cycle, and to provide data basis for process optimization.

[0042] The feedback unit is used to send questionnaires to relevant personnel after the vulnerability handling loop is completed, collect feedback on the accuracy of the vulnerability announcement and the feasibility of the remediation suggestions, and use this feedback to optimize data analysis and announcement templates, forming a closed loop of continuous improvement.

[0043] Secondly, the present invention also provides a centralized management and control method based on a vulnerability and defect release mechanism. The implementing entity of this management and control method is a centralized management and control platform based on a vulnerability and defect release mechanism as described in any of the first aspects. The management and control method includes the following steps:

[0044] Step S1: Use the data acquisition and aggregation module to collect, crawl and receive raw vulnerability data from multiple heterogeneous data sources, and map the vulnerability data from different sources into a unified standardized data model to obtain standardized vulnerability data.

[0045] Step S2: Use the vulnerability analysis and assessment module to match standardized vulnerability data with assets in the asset management database to determine a potentially affected internal list; and combine environmental information to conduct a multi-dimensional risk assessment of vulnerabilities and generate a customized risk level for the enterprise.

[0046] Step S3: Utilize the vulnerability release and push module to generate vulnerability announcements based on the risk assessment results, and send the vulnerability announcements to relevant responsible personnel and security teams in a targeted and hierarchical manner according to predefined different roles, subscription policies and content classification mechanisms;

[0047] Step S4: Use the collaborative handling and process management module to create handling task work orders based on the vulnerability announcement and assign them to the corresponding responsible personnel; and track and promote the remediation process, and trigger the verification process after the remediation is completed;

[0048] Step S5: Utilize the panoramic situation display and reporting module to acquire data from each module in real time, dynamically visualize the vulnerability situation, handling progress and team performance of the entire platform, and regularly generate multi-dimensional quantitative reports to provide data support for security management decisions.

[0049] As can be seen from the above technical solution, the centralized management platform and centralized management method based on the vulnerability and defect release mechanism provided by this invention uses the centralized management platform as the implementing entity. In this centralized management platform, the data acquisition and aggregation module can collect, crawl, and receive raw vulnerability and defect data from multiple heterogeneous data sources, and map the obtained vulnerability and defect data to a unified standardized data model to obtain standardized vulnerability data; the vulnerability analysis and assessment module can determine the potentially affected internal list and generate customized risk levels for enterprises based on the standardized vulnerability data, obtaining risk assessment results; the vulnerability release and push module can generate vulnerability announcements based on the risk assessment results and push them to predefined different finalists and responsible parties in a targeted and hierarchical manner; the collaborative handling and process management module can receive vulnerability announcements, create handling task work orders based on the vulnerability announcements, and assign the created handling task work orders to the corresponding responsible personnel; the panoramic situation display and reporting module can visualize the vulnerability situation of the entire platform. Therefore, this solution can achieve the integration of multi-party data by collecting, crawling, and receiving vulnerability and defect data from multiple heterogeneous data sources. Meanwhile, through vulnerability analysis and assessment, risk assessment results that are more suitable for specific application scenarios were determined. Furthermore, through targeted and tiered push of vulnerability announcements and the assignment of handling task lists, this efficient and collaborative allocation and handling method has achieved accurate allocation of resources and precise handling of vulnerabilities, thereby greatly shortening the average repair cycle of vulnerabilities, reducing the handling cost of vulnerabilities, and making the control effect of vulnerabilities better. Attached Figure Description

[0050] Figure 1 This is a schematic diagram of a centralized management and control platform based on a vulnerability and defect release mechanism, provided as an embodiment of the present invention.

[0051] Figure 2This is a schematic diagram of a vulnerability analysis and assessment module provided in an embodiment of the present invention.

[0052] Figure 3 This is a schematic diagram of a vulnerability publishing and push module provided in an embodiment of the present invention.

[0053] Figure 4 This is a schematic diagram of a push channel management unit provided in an embodiment of the present invention.

[0054] Figure 5 This is a schematic diagram of a collaborative processing and process management module provided in an embodiment of the present invention.

[0055] Figure 6 This is a schematic diagram of an optimization and feedback module provided in an embodiment of the present invention.

[0056] Figure 7 A flowchart illustrating a centralized management method based on a vulnerability and defect release mechanism, provided as an embodiment of the present invention. Detailed Implementation

[0057] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0058] like Figure 1 As shown, the present invention provides a centralized management and control platform based on a vulnerability and defect release mechanism. The centralized management and control platform may include: a data acquisition and aggregation module 10, a vulnerability analysis and assessment module 20, a vulnerability release and push module 30, a collaborative handling and process management module 40, and a panoramic situation display and reporting module 50.

[0059] The data acquisition and aggregation module 10 is used to collect, crawl and receive raw vulnerability and defect data from multiple heterogeneous data sources, and map the vulnerability and defect data from different sources into a unified standardized data model to obtain standardized vulnerability data.

[0060] The vulnerability analysis and assessment module 20 is used to determine a potentially affected internal list and generate a customized risk level for the enterprise based on the standardized vulnerability data, thereby obtaining a risk assessment result.

[0061] The vulnerability publication and push module 30 is used to generate vulnerability announcements based on the risk assessment results and push them to predefined different roles and responsible parties in a targeted and hierarchical manner.

[0062] The collaborative handling and process management module 40 is used to receive the vulnerability announcement, create a handling task work order based on the vulnerability announcement, and assign the created handling task work order to the corresponding responsible personnel.

[0063] The panoramic situation display and reporting module 50 is used to visualize the vulnerability situation of the entire platform; wherein, the vulnerability situation includes, but is not limited to: vulnerability risk distribution map, ranking of vulnerability handling efficiency of each department, statistics of high-risk vulnerabilities to be processed, and periodic vulnerability management reports.

[0064] In this embodiment, vulnerability and defect data can be collected, crawled, and received from multiple heterogeneous data sources, enabling the integration of data from various parties. Simultaneously, through vulnerability analysis and assessment, risk assessment results more suited to specific application scenarios are determined. Furthermore, through targeted and tiered push notifications of vulnerability announcements and the assignment of handling task lists, this highly efficient and collaborative allocation and handling method achieves accurate resource allocation and precise vulnerability handling, thereby significantly shortening the average vulnerability repair cycle, reducing vulnerability handling costs, and resulting in better vulnerability management.

[0065] The following section provides a more detailed explanation of this solution, using the deployment of the centralized management and control platform based on the vulnerability and defect release mechanism of this invention by a provincial power grid company as an example.

[0066] A provincial power grid company deployed the centralized management and control platform of this invention to manage cybersecurity vulnerabilities in its power monitoring system. This power grid company oversees hundreds of substations and thousands of power monitoring devices, running various power-specific operating systems and industrial control software.

[0067] In the initial stage, platform initialization and power asset registration were carried out. Specifically, the power grid company's safety operation and maintenance team established a complete list of power monitoring system assets in the platform's asset management and relationship mapping database. Asset types include RTU remote terminal units, IED intelligent electronic devices, SCADA servers, engineering workstations, substation monitoring hosts, etc. Key attributes include IP address and network area (production control area, management information area), geographical location (substation, dispatch center), equipment model and firmware version (e.g., NS3000 monitoring system V2.5), voltage level (500kV, 220kV, 110kV, etc.), and responsible person (substation operation and maintenance personnel, system administrator). Asset importance is classified into core level (provincial dispatch center SCADA server, 500kV substation monitoring system), important level (regional dispatch center, 220kV substation), and general level (distribution automation terminal, electricity consumption information collection system).

[0068] The data acquisition and aggregation module 10 is used to automatically collect, crawl and receive raw vulnerability and defect information from multiple heterogeneous data sources, including but not limited to: national vulnerability databases, third-party security vendor vulnerability databases, open-source community security announcements, internal code audit tool reports and external penetration test reports.

[0069] In addition, the data acquisition and aggregation module 10 can also have a built-in data cleaning and standardization unit to map vulnerability information from different sources to a unified standardized data model. This standardized data model includes at least the vulnerability number, CVE number, CVSS risk level, affected asset type, vulnerability description, remediation suggestion, disclosure time, data source, and extended fields for collaborative processing. The extended fields may include: an internal vulnerability identifier representing a unique tracking number generated by the platform for each accessed vulnerability; a collaborative processing status identifier indicating the stage of the vulnerability's internal handling process; a field representing the designated collaborative team / personnel responsible for handling the vulnerability; and a remediation deadline field that is automatically calculated or manually specified based on the customized risk level.

[0070] For example, a specific instance might be as follows: One day, the platform collected information on power system vulnerabilities through various channels: obtaining early warning information from the National Energy Administration's power industry cybersecurity notification mechanism, obtaining security announcements from equipment manufacturers (such as NARI, XJ, and Sifang), obtaining industrial control system vulnerabilities from national-level vulnerability databases such as CNVD and CNNVD, and discovering potential risks through internal power monitoring system security detection tools. A typical case is that the platform collected information about an authentication bypass vulnerability (CVE-2023-XXXXX) in a certain model of substation monitoring machine, with a CVSS base score of 8.5 (high risk).

[0071] In addition, the data acquisition and aggregation module 10 can also have intelligent deduplication and correlation capabilities. When vulnerability information from different energy sources points to the same vulnerability, it can automatically merge them and retain all source information to form a complete vulnerability intelligence view.

[0072] The vulnerability analysis and assessment module 20 is connected to the data acquisition and aggregation module 10, and is used to perform in-depth analysis and risk assessment of the standardized vulnerability data. Specifically, for example... Figure 2 As shown, the vulnerability analysis and assessment module 20 may further include: an impact scope matching unit 201 and a multi-dimensional risk assessment unit 202;

[0073] The impact scope matching unit 201 is used to match the types of assets affected by the vulnerability with the IT assets, network devices, industrial control equipment and software components registered in the platform asset library to determine the list of potentially affected internal assets.

[0074] The multidimensional risk assessment unit 202 is used to recalibrate risks based on the CVSS basic score and combined with internal environmental factors of the enterprise to generate a customized risk level for the enterprise; wherein, the environmental factors include: asset importance, the degree of attenuation of vulnerability exploitability under existing protection measures, and potential business impact.

[0075] In this embodiment, the multidimensional risk assessment unit 202 can be configured to perform the following operations when performing risk recalibration:

[0076] Construct a risk calibration weight matrix; the factors of this risk calibration weight matrix include: asset importance weight, existing protection measures mitigation coefficient, and vulnerability attack popularity;

[0077] Calculate the customized risk score: where the customized risk score = CVSS base score × asset importance weight × (1 - existing protection measures mitigation coefficient) + additional score for vulnerability attack popularity;

[0078] The risk level of the vulnerability is re-determined based on the customized risk score, resulting in the enterprise's customized risk level.

[0079] In this embodiment, the enterprise-level risk level can include: emergency risk level, high-risk risk level, medium-risk level, and low-risk level. The remediation timeframe should be forcibly associated with the enterprise-level risk level; for example, an emergency risk requires a response within 24 hours, and a high-risk risk requires a response within 72 hours.

[0080] In this embodiment, regarding the scope of impact matching, the platform matches the affected device model (XX monitoring machine) and software version (V3.0-V3.5) with the asset database, automatically identifying 35 devices of this model operating within the affected version range across the province. This includes core monitoring equipment from two 500kV substations and eight 220kV substations. During the risk assessment process, the platform comprehensively considers the characteristics of the power system for risk recalibration. The asset importance weight is set at 1.5 (500kV substations are core business), the mitigation coefficient is set at 0.3 (equipment is located in the production control area and is isolated by firewalls), and the attack heat factor is set at 0.2 (recent APT attacks targeting the power system). The customized risk score is calculated using the formula: Customized Risk Score = 8.5 × 1.5 × (1 - 0.3) + 0.2 = 9.125. Based on this customized risk score, the risk level of the vulnerability is reclassified, resulting in an enterprise-specific customized risk level of "critical."

[0081] The vulnerability publication and push module 30 is connected to the vulnerability analysis and assessment module 20. It generates structured vulnerability announcements based on risk assessment results and pushes them in a targeted and tiered manner to predefined roles and responsible parties. Specifically, for example... Figure 3 As shown, the vulnerability release and push module 30 may include: an announcement template library unit 301 and a push channel management unit 302;

[0082] The announcement template library unit 301 is used to provide customizable announcement templates for different vulnerability types and risk levels;

[0083] The push channel management unit 302 is used to support the push of vulnerability announcements based on targeted and hierarchical mechanisms through email, instant messaging tools, internal work order systems and API interfaces.

[0084] In this embodiment, as Figure 4 As shown, the push channel management unit 302 may further include: a role and subscription strategy management subunit 3021, a content rating mechanism subunit 3022, and a push triggering rule subunit 3023;

[0085] The role and subscription policy management subunit 3021 is used by the platform administrator to define different user roles and configure the vulnerability types, risk levels and asset scope of concern for each role; and for users to customize subscription policies.

[0086] The content classification mechanism subunit 3022 is used to push complete vulnerability announcements for urgent and high-risk vulnerabilities, and simplified security alerts for medium-risk and low-risk vulnerabilities; wherein, the vulnerability announcement includes: detailed technical details, exploit code and remediation plan; the security alert only includes: vulnerability overview and remediation suggestions;

[0087] The push triggering rule subunit 3023 supports three modes: manual triggering, scheduled batch release, and automatic triggering based on risk level, ensuring that critical vulnerability information can be conveyed in a timely manner.

[0088] For example, the platform uses a power industry-specific template to generate structured announcements, including: "[Urgent] Security alert regarding a substation monitoring machine authentication bypass vulnerability. Affected systems: XX model monitoring machines V3.0-V3.5; Risk level: Urgent (internal rating); Repair timeframe: 24 hours; Affected sites: 500kV A substation, 500kV B substation, 220kV C substation, etc.; Recommended action: Immediately upgrade to version V3.6, temporary measures include…". In the targeted push mechanism, complete technical details are pushed to the technical personnel of relevant substations via the power dispatch data network; emergency alarms are sent to the provincial dispatch safety duty room via SMS and internal communication tools; summary information is sent to the leaders of the equipment management department; and the announcement is prominently displayed on the homepage of the power safety management platform.

[0089] The collaborative handling and process management module 40 is used to receive vulnerability announcements and create handling task work orders to drive the subsequent remediation closed loop. Specifically, such as... Figure 5 As shown, the collaborative handling and process management module 40 may include: a handling task work order creation unit 401, a task assignment unit 402, a process driving engine unit 403, a collaboration space unit 404, and an asset management and relationship mapping library unit 405.

[0090] The task creation unit 401 is used to create a task creation unit based on the vulnerability announcement.

[0091] The task assignment unit 402 is used to assign the disposal task work order to the corresponding system administrator, development team or security operation and maintenance personnel according to the asset responsibility relationship.

[0092] The process-driven engine unit 403 is used to preset several states of the processing task work order and track the entire repair life cycle to update the state; wherein, the several states may include states such as pending acceptance, repairing, pending verification, and closed.

[0093] The collaborative space unit 404 is used to provide an independent discussion area for each vulnerability handling task, supporting communication and uploading of remediation evidence by remediation personnel, security teams and administrators.

[0094] The asset management and relationship mapping library unit 405 is used to store and manage all relevant IT and industrial control asset information of the enterprise. This IT and industrial control asset information includes at least the asset's IP address, department, responsible person, running software and version, and the asset's importance level within the business system. In one embodiment, this library provides data support for the influence scope matching unit 201.

[0095] In one embodiment, such as Figure 5As shown, the collaborative processing and process management module 40 may also include: an automatic reminder and escalation unit 406, a repair and verification unit 407, and a closed-loop audit tracking unit 408;

[0096] The automatic reminder and escalation unit 406 is used to automatically send a reminder notice to the responsible personnel when the task work order has not entered the next state within the set time limit; if it is not processed within the time limit, the task work order is automatically reported to the responsible personnel's superior or a higher-level safety administrator.

[0097] The repair verification unit 407 is used to automatically trigger the verification process after the repair personnel mark the repair as completed. It can rescan the target asset by calling the integrated vulnerability scanning tool API, or assign the verification task to the security team for manual confirmation.

[0098] The closed-loop audit tracking unit 408 is used to fully record all operation logs, communication records and timestamps throughout the entire lifecycle of vulnerability discovery, release, assignment, repair to verification, forming an immutable audit chain.

[0099] For example, the platform automatically creates 35 task orders (one for each affected device). These orders are automatically assigned to the maintenance personnel at the corresponding substations, with a 24-hour repair deadline set. If the deadline is exceeded, the task is automatically escalated to the substation manager and the provincial dispatch safety department. During on-site handling, maintenance personnel at a 500kV substation receive a work order and SMS notification; they view detailed repair guidelines on the platform and download the upgrade package; they apply for a temporary maintenance window according to the power system maintenance procedures; before performing the operation, they confirm the steps through the platform's collaboration space; after completing the upgrade, they upload the operation log and verification results. During the repair verification phase, the platform automatically calls the power monitoring system configuration verification tool to verify if the device version is updated; the provincial dispatch safety department remotely verifies the repaired device using a vulnerability scanning tool. Once the vulnerability repair is confirmed, the work order status changes to closed.

[0100] The panoramic situation display and reporting module 50 is connected to all functional modules of the platform and is used to visualize the vulnerability situation of the entire platform, including but not limited to: vulnerability risk distribution map, ranking of vulnerability handling efficiency of each department, statistics of high-risk vulnerabilities to be processed, and periodic vulnerability management reports.

[0101] In this embodiment, the panoramic situation display and reporting module 50 real-time monitoring screen displays an overview of the vulnerability situation of the provincial power monitoring system, the ranking of vulnerability handling progress in various regions, statistics of high-risk vulnerabilities to be processed, and recent vulnerability trend analysis.

[0102] In one embodiment, such as Figure 1 and 6As shown, the centralized management and control platform may also include: an optimization and feedback module 60; the optimization and feedback module 60 includes: a performance measurement unit 601, a process optimization analysis unit 602, and a feedback unit 603;

[0103] The performance measurement unit 601 is used to automatically calculate and display key performance indicators for each team or individual based on the data from the task handling work orders; wherein, the key performance indicators include: average repair time, number of backlogged vulnerabilities, and on-time completion rate;

[0104] The process optimization analysis unit 602 is used to identify process bottlenecks by analyzing the time consumption of each stage in the life cycle, and to provide data basis for process optimization.

[0105] The feedback unit 603 is used to send a questionnaire to relevant personnel after the vulnerability handling closed loop is completed, collect feedback on the accuracy of the vulnerability announcement and the feasibility of the remediation suggestions, and use this feedback to optimize data analysis and announcement templates, forming a closed loop of continuous improvement.

[0106] like Figure 7 As shown, the present invention also provides a centralized management and control method based on a vulnerability and defect release mechanism. The implementing entity of this management and control method is a centralized management and control platform based on a vulnerability and defect release mechanism as described above. The management and control method includes the following steps:

[0107] Step S1: Use the data acquisition and aggregation module 10 to collect, crawl and receive raw vulnerability data from multiple heterogeneous data sources, and map the vulnerability data from different sources into a unified standardized data model to obtain standardized vulnerability data.

[0108] This step aims to achieve centralized collection and standardization of vulnerability data, continuously collecting raw vulnerability data from multiple heterogeneous data sources both internally and externally, and then processing it through cleaning, deduplication, and standardization to transform it into a standardized data model that is consistent across the platform.

[0109] Step S2: Using the vulnerability analysis and assessment module 20, the standardized vulnerability data is matched with the assets in the asset management database to determine the potentially affected internal list; and, combined with environmental information, a multi-dimensional risk assessment of the vulnerabilities is conducted to generate a customized risk level for the enterprise.

[0110] This step aims to achieve accurate analysis and risk assessment of the vulnerability's impact. Specifically, it involves automatically matching standardized vulnerabilities with assets in the asset management database to determine a list of potentially affected assets. Combined with environmental context information, a multi-dimensional risk assessment of the vulnerability is conducted, generating a customized risk level and remediation timeline for the enterprise.

[0111] In this step, during the precise analysis and risk assessment of vulnerability impact, asset matching involves both fuzzy and precise matching of the affected vendors, products, and versions in the vulnerability information with the software / hardware vendor, name, and version number fields of assets in the asset database. For risk recalibration, the importance level of successfully matched assets is automatically obtained, the existing security measures for those assets are queried, and the current attack posture of the vulnerability is obtained from external intelligence sources. These factors are then combined to recalibrate the basic CVSS score using a risk assessment algorithm. For localizing remediation recommendations, general remediation recommendations can be adapted and refined based on the enterprise's internal technology stack and specifications, generating directly actionable internal remediation guidelines.

[0112] Step S3: Utilize the vulnerability release and push module 30 to generate vulnerability announcements based on the risk assessment results, and send the vulnerability announcements to relevant responsible personnel and security teams in a targeted and hierarchical manner according to predefined different roles, subscription policies and content classification mechanisms;

[0113] This step aims to achieve targeted and intelligent delivery of vulnerability announcements. Specifically, based on the risk assessment results, a suitable template is selected from the template library to generate a structured vulnerability announcement. Then, according to predefined roles, subscription policies, and content classification mechanisms, the vulnerability information is sent to relevant responsible personnel and security teams in a targeted and hierarchical manner through multiple push channels.

[0114] Step S4: Use the collaborative handling and process management module 40 to create a handling task work order based on the vulnerability announcement and assign it to the corresponding responsible personnel; and track and promote the remediation process, and trigger the verification process after the remediation is completed;

[0115] This step aims to achieve collaborative and closed-loop management of the remediation tasks. Specifically, remediation task work orders are automatically created based on vulnerability announcements and assigned to the relevant responsible parties. The process-driven engine unit 403 and the collaboration space unit 404 track and facilitate collaboration during the remediation process. After remediation is completed, a verification process is triggered to ensure the vulnerability is truly fixed. Finally, the work order is closed, completing the remediation loop.

[0116] This step, in its collaborative and closed-loop management of task handling, firstly achieves automatic task assignment. The system automatically dispatches work orders based on pre-defined responsible personnel information in the asset database. If the responsible person is unknown, the task is assigned to the default security contact person within their department. Next, it facilitates collaboration and knowledge accumulation. In the collaborative space, all discussions about vulnerabilities, temporary solutions, and screenshots of remediation steps are recorded and automatically archived into the vulnerability's handling record, forming a searchable knowledge base. Finally, it achieves automated verification. During the remediation verification phase, the platform, through API, links with internal vulnerability scanners or configuration management databases to automatically obtain the latest scan results or software version information of the target asset, compares it with the vulnerability remediation requirements, and generates a verification report.

[0117] Step S5: Utilize the panoramic situation display and reporting module 50 to acquire data from each module in real time, dynamically visualize the vulnerability situation, handling progress and team performance of the entire platform, and regularly generate multi-dimensional quantitative reports to provide data support for security management decisions.

[0118] This step aims to achieve continuous monitoring and quantitative reporting of the overall situation. This involves acquiring data from various modules in real time, dynamically displaying the overall vulnerability risk situation, handling progress, and team performance, and regularly generating multi-dimensional quantitative reports to provide data support for security management decisions.

[0119] The inventive embodiments and system embodiments provided by this invention are based on the same inventive concept. For detailed description, please refer to the system embodiments, which will not be repeated here.

[0120] In summary, the centralized management platform and method based on the vulnerability and defect release mechanism provided by this invention have at least the following beneficial effects:

[0121] (1) Through the linkage of the vulnerability analysis and assessment module 20 and the asset management and relationship mapping library unit 405, the platform can automatically and accurately match vulnerability information with internal assets and quickly generate a list of potentially affected assets. This changes the traditional method of relying on manual memory and comparison, realizes impact range analysis at the minute level, and ensures the comprehensiveness and accuracy of the assessment;

[0122] (2) Through the multi-dimensional risk assessment unit 202, the platform incorporates internal environmental factors such as asset importance and existing protection measures on the basis of the general CVSS score, and recalibrates the vulnerability risk to generate a customized risk level for the enterprise. This enables the security team to clearly identify the vulnerabilities that truly pose an urgent threat to its own business, thereby prioritizing the allocation of resources for handling and maximizing the return on security investment;

[0123] (3) Through the vulnerability release and push module 30 and the collaborative handling and process management module 40, the platform has established a standardized process from vulnerability notification, task assignment, repair execution to result verification. The responsibilities are clear, the process is transparent, and there are reminder and escalation mechanisms, which completely changes the previous loose and inefficient collaboration mode, greatly shortens the average repair time of vulnerabilities, and ensures that every vulnerability can be tracked and closed.

[0124] (4) Through the panoramic situation display and reporting module 50, management and security teams can intuitively grasp the global vulnerability risk distribution, handling progress and team performance. This provides real-time and accurate data support for security situation assessment, resource allocation and management decisions, and promotes the evolution of vulnerability management from passive response to proactive control and quantitative management.

[0125] The present invention also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it runs the method as described in the above embodiments.

[0126] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method as described in any of the above embodiments.

[0127] The modules or units in the device of this invention can be merged, divided, and deleted according to actual needs. The above-disclosed embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of the invention. Those skilled in the art will understand that implementing all or part of the processes of the above embodiments and making equivalent changes according to the claims of this invention still fall within the scope of the invention.

Claims

1. A centralized management and control platform based on a vulnerability and defect release mechanism, characterized in that, The centralized management and control platform includes: a data collection and aggregation module, a vulnerability analysis and assessment module, a vulnerability release and push module, a collaborative handling and process management module, and a panoramic situation display and reporting module; The data acquisition and aggregation module is used to collect, crawl and receive raw vulnerability and defect data from multiple heterogeneous data sources, and map the vulnerability and defect data from different sources into a unified standardized data model to obtain standardized vulnerability data. The vulnerability analysis and assessment module is used to determine a potentially affected internal list and generate a customized risk level for the enterprise based on the standardized vulnerability data, thereby obtaining a risk assessment result. The vulnerability publication and push module is used to generate vulnerability announcements based on the risk assessment results and push them to predefined different roles and responsible parties in a targeted and hierarchical manner. The collaborative handling and process management module is used to receive the vulnerability announcement, create handling task work orders based on the vulnerability announcement, and assign the created handling task work orders to the corresponding responsible personnel. The panoramic situation display and reporting module is used to visually display the vulnerability situation of the entire platform; wherein, the vulnerability situation includes, but is not limited to: vulnerability risk distribution map, ranking of vulnerability handling efficiency of each department, statistics of high-risk vulnerabilities to be processed, and periodic vulnerability management reports.

2. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 1, characterized in that, The heterogeneous data sources include, but are not limited to: national vulnerability databases, third-party security vendor vulnerability databases, open-source community security announcements, internal code audit tool reports, and external penetration test reports; And / or, The standardized data model includes: vulnerability number, CVE number, CVSS risk level, affected asset type, vulnerability description, remediation suggestion, disclosure time, data source, and extended fields for collaborative action; wherein, the extended fields include: an internal vulnerability identifier that represents a unique tracking number generated by the platform for each access vulnerability, a collaborative action status identifier that indicates the stage of the vulnerability in the internal handling process, and designated collaborative team members and remediation time limits.

3. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 1, characterized in that, The vulnerability analysis and assessment module includes: an impact scope matching unit and a multi-dimensional risk assessment unit; The impact scope matching unit is used to match the types of assets affected by the vulnerability with the IT assets, network devices, industrial control equipment and software components registered in the platform asset library to determine the list of potentially affected internal assets. The multidimensional risk assessment unit is used to recalibrate risks based on the CVSS basic score and combined with internal environmental factors of the enterprise to generate a customized risk level for the enterprise; wherein, the environmental factors include: asset importance, the degree of attenuation of vulnerability exploitability under existing protection measures, and potential business impact.

4. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 3, characterized in that, When performing risk recalibration, the multidimensional risk assessment unit is configured to perform the following operations: Construct a risk calibration weight matrix; the factors of this risk calibration weight matrix include: asset importance weight, existing protection measures mitigation coefficient, and vulnerability attack popularity; Calculate the customized risk score: where the customized risk score = CVSS base score × asset importance weight × (1 - existing protection measures mitigation coefficient) + additional score for vulnerability attack popularity; The risk level of the vulnerability is re-determined based on the customized risk score, resulting in the enterprise's customized risk level.

5. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 1, characterized in that, The vulnerability release and push module includes: an announcement template library unit and a push channel management unit; The announcement template library unit is used to provide customizable announcement templates for different vulnerability types and risk levels; The push channel management unit is used to support the push of vulnerability announcements based on targeted and hierarchical mechanisms through email, instant messaging tools, internal work order systems and API interfaces.

6. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 5, characterized in that, The push channel management unit includes: a role and subscription strategy management subunit, a content classification mechanism subunit, and a push triggering rule subunit; The role and subscription policy management subunit is used by platform administrators to define different user roles and configure the vulnerability types, risk levels, and asset scope of concern for each role; and is also used for users to customize subscription policies. The content classification mechanism subunit is used to push complete vulnerability announcements for urgent and high-risk vulnerabilities, and simplified security alerts for medium-risk and low-risk vulnerabilities; wherein, the vulnerability announcement includes: detailed technical details, exploit code and remediation plan; the security alert includes: vulnerability overview and remediation suggestions; The push triggering rule subunit supports three modes: manual triggering, scheduled batch release, and automatic triggering based on risk level, ensuring that critical vulnerability information is communicated in a timely manner.

7. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 1, characterized in that, The collaborative handling and process management module includes: a task work order creation unit, a task assignment unit, a process driving engine unit, a collaboration space unit, and an asset management and relationship mapping library unit. The task creation unit is used to create a task creation unit based on the vulnerability announcement. The task assignment unit is used to assign the disposal task work order to the corresponding system administrator, development team or security operation and maintenance personnel according to the asset responsibility relationship. The process-driven engine unit is used to preset several states of the processing task work order and to track and update them throughout the entire repair lifecycle. The collaborative space unit is used to provide an independent discussion area for each vulnerability handling task, supporting communication and uploading of remediation evidence by remediation personnel, security teams and administrators. The asset management and relationship mapping library unit is used to store and manage all relevant IT and industrial control asset information of the enterprise.

8. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 7, characterized in that, The collaborative processing and process management module also includes: an automatic reminder and upgrade unit, a repair and verification unit, and a closed-loop audit tracking unit; The automatic reminder and escalation unit is used to automatically send a reminder notice to the responsible personnel when the task work order has not entered the next state within the set time limit; if it is not processed within the time limit, the task work order will be automatically reported to the responsible personnel's superior or a higher-level security administrator. The repair verification unit is used to automatically trigger the verification process after the repair personnel mark the repair as completed. It can either call the integrated vulnerability scanning tool API to rescan the target asset or assign the verification task to the security team for manual confirmation. The closed-loop audit tracking unit is used to fully record all operation logs, communication records and timestamps throughout the entire lifecycle of vulnerability discovery, release, assignment, repair to verification, forming an immutable audit chain.

9. The centralized management and control platform based on the vulnerability and defect release mechanism according to claim 1, characterized in that, The centralized management and control platform also includes an optimization and feedback module; the optimization and feedback module includes a performance measurement unit, a process optimization analysis unit, and a feedback unit. The performance measurement unit is used to automatically calculate and display key performance indicators (KPIs) for each team or individual based on the data from the task handling work orders; wherein the KPIs include: average remediation time, number of backlogged vulnerabilities, and on-time completion rate; The process optimization and analysis unit is used to identify process bottlenecks by analyzing the time consumption of each stage in the life cycle, and to provide data basis for process optimization. The feedback unit is used to send questionnaires to relevant personnel after the vulnerability handling loop is completed, collect feedback on the accuracy of the vulnerability announcement and the feasibility of the remediation suggestions, and use this feedback to optimize data analysis and announcement templates, forming a closed loop of continuous improvement.

10. A centralized management and control method based on a vulnerability and defect release mechanism, characterized in that, The implementation entity of this control method is a centralized control platform based on a vulnerability and defect release mechanism as described in any one of claims 1-9, and the control method includes the following steps: Step S1: Use the data acquisition and aggregation module to collect, crawl and receive raw vulnerability data from multiple heterogeneous data sources, and map the vulnerability data from different sources into a unified standardized data model to obtain standardized vulnerability data. Step S2: Use the vulnerability analysis and assessment module to match standardized vulnerability data with assets in the asset management database to determine a potentially affected internal list; and combine environmental information to conduct a multi-dimensional risk assessment of vulnerabilities and generate a customized risk level for the enterprise. Step S3: Utilize the vulnerability release and push module to generate vulnerability announcements based on the risk assessment results, and send the vulnerability announcements to relevant responsible personnel and security teams in a targeted and hierarchical manner according to predefined different roles, subscription policies and content classification mechanisms; Step S4: Use the collaborative handling and process management module to create handling task work orders based on the vulnerability announcement and assign them to the corresponding responsible personnel; and track and promote the remediation process, and trigger the verification process after the remediation is completed; Step S5: Utilize the panoramic situation display and reporting module to acquire data from each module in real time, dynamically visualize the vulnerability situation, handling progress and team performance of the entire platform, and regularly generate multi-dimensional quantitative reports to provide data support for security management decisions.