Vulnerability discovery method, system and device based on extension and medium

By using an extension-based vulnerability discovery method, risk scores and dynamic resource allocation are generated through extension correlation analysis to identify unknown vulnerabilities. This solves the problems of insufficient vulnerability identification and rigid resource scheduling in traditional methods, and achieves efficient and reliable network security protection.

CN121530733APending Publication Date: 2026-02-13NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511943952.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing vulnerability discovery technologies based on rule bases and feature matching struggle to identify unknown vulnerabilities, suffer from rigid resource scheduling and crude risk assessment, resulting in high false negative rates and wasted resources, and are unable to effectively address complex zero-day vulnerabilities and new types of attacks.

Method used

An extension-based vulnerability discovery method is adopted. By acquiring vulnerability alarm data and system resource status information of the network system, risk scores are generated using extension correlation analysis. The vulnerability analysis mode and analysis scope are dynamically determined, unknown vulnerabilities are identified, and the allocation of computing resources is optimized. The contradiction between the transmission of vulnerability feature information and the known vulnerability object library is identified by using a preset rule base.

Benefits of technology

It improves the efficiency of identifying unknown vulnerabilities, reduces false alarm rates and resource waste, enhances the initiative and reliability of network security protection, and can effectively capture feature-mutated or combined vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530733A_ABST
    Figure CN121530733A_ABST
Patent Text Reader

Abstract

The invention relates to a vulnerability discovery method, system and device based on extension and a medium. The method comprises the following steps: acquiring vulnerability alarm data and system resource state information of a network system, wherein the vulnerability alarm data comprises vulnerability feature information; based on the vulnerability alarm data, generating a risk score by utilizing extension association analysis; determining a vulnerability analysis mode based on the risk score and the system resource state information, and determining an analysis range by using the mode; and in the analysis range, identifying a conduction contradiction between the vulnerability feature information and a known vulnerability matter element library through a preset rule library, and identifying an unknown vulnerability. According to the invention, unknown vulnerabilities can be found efficiently and accurately, and the initiative and reliability of network security protection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security, and in particular relates to vulnerability discovery methods, systems, devices and media based on extension theory. Background Technology

[0002] With the evolution of cybersecurity technology, vulnerability discovery technologies based on rule bases and feature matching have gradually become mainstream. These technologies use predefined vulnerability signatures (such as CVE databases) and static rule bases to perform real-time scanning and matching analysis of network system alert data (such as intrusion detection logs and abnormal traffic characteristics). Their core advantage lies in their ability to quickly identify known vulnerability patterns and trigger alert mechanisms. However, faced with increasingly complex zero-day vulnerabilities and new attack methods, traditional methods have revealed significant limitations. Traditional processing typically involves three steps: collecting vulnerability alert data (including attack vectors, impact range, and other characteristic information); performing feature matching using a fixed rule base; and outputting a vulnerability report and suggesting remediation solutions. While this model can efficiently handle known threats, it has fundamental flaws: It lacks identification of unknown vulnerabilities, relies excessively on historical vulnerability databases, and cannot capture feature variations or combinations of vulnerabilities through contradictory propagation analysis, resulting in a persistently high false negative rate; resource scheduling is rigid, employing a uniform analysis model that allocates the same computing resources regardless of risk level, which can easily lead to resource waste or response delays under high load scenarios; risk assessment is crude, relying on simple weighted or threshold-based scoring mechanisms, making it difficult to quantify the contradictory relationship between vulnerability characteristics and security status, easily leading to false positives or underestimation of risk. Summary of the Invention

[0003] Therefore, it is necessary to provide a vulnerability discovery method, system, device, and medium based on extension theory that can solve the above problems.

[0004] Firstly, this application provides a vulnerability discovery method based on extensionology, including:

[0005] Acquire vulnerability alert data and system resource status information of the network system. The vulnerability alert data includes vulnerability characteristic information.

[0006] Risk scores are generated based on vulnerability alert data using extensional correlation analysis.

[0007] Based on risk scoring and system resource status information, determine the vulnerability analysis model and use the vulnerability analysis model to determine the analysis scope.

[0008] Within the scope of analysis, unknown vulnerabilities are identified by using a pre-defined rule base to identify contradictions between vulnerability feature information and the known vulnerability object library.

[0009] In one embodiment, based on risk scoring and system resource status information, a vulnerability analysis model is determined, and the analysis scope is determined using the vulnerability analysis model, including:

[0010] Based on the risk score, the risk level range to which it belongs is determined by a preset range threshold division rule;

[0011] The corresponding vulnerability analysis mode is invoked according to the risk level range. The vulnerability analysis mode contains a set of correlation operators for extension correlation analysis.

[0012] Based on the set of related operators and system resource status information, the resource scheduling engine calculates the amount of computing resources required for the set of related operators and generates resource allocation parameters.

[0013] The scope of analysis is determined based on the analysis dimensions of resource allocation parameters and the set of related operators.

[0014] In one embodiment, a risk score is generated based on vulnerability alert data using extensional correlation analysis, including:

[0015] Extract key attribute parameters of vulnerability feature information from vulnerability alert data, construct the object element to be evaluated, and use the object element to participate in the generation of risk score;

[0016] Based on the preset safety state threshold range, the extension contradiction distance of each attribute parameter in the object to be evaluated is calculated.

[0017] By quantifying the extension contradiction distance of each attribute parameter in the object to be evaluated through a preset extension risk function, a single risk factor is generated.

[0018] Based on the preset risk factor weighting rules, individual risk factors are weighted and integrated to output a comprehensive risk score.

[0019] In one embodiment, within the scope of analysis, unknown vulnerabilities are identified by using a preset rule base to identify contradictions in the transmission of vulnerability feature information and the known vulnerability object library, including:

[0020] Based on the scope of analysis, extract the elements to be evaluated;

[0021] The extension correlation degree between the object to be evaluated and each object in the known vulnerability object library is calculated using a preset rule base.

[0022] Based on extensional correlation, target matter elements that meet preset transmission conditions are identified.

[0023] Calculate the extensional conflict distance between the target matter-element and the matter-element to be evaluated, and determine the unknown vulnerability based on the extensional conflict distance between the target matter-element and the matter-element to be evaluated.

[0024] In one embodiment, the extensional conflict distance between the target matter-element and the matter-to-be-evaluated is calculated, and the unknown vulnerability is determined based on the extensional conflict distance between the target matter-element and the matter-to-be-evaluated, including:

[0025] Calculate the target matter element using the following formula. With the object to be evaluated Extensional contradiction distance :

[0026]

[0027] in, Let R be the value of the object element to be evaluated on the k-th characteristic attribute. For target matter element The standard value of the k-th feature attribute The difference between the upper and lower limits of the security status threshold field for the k-th attribute is given. The preset weight factor for the k-th attribute;

[0028] If a target matter exists Satisfying extensional contradiction distance Then it is determined that there is an unknown vulnerability in the object element R to be evaluated, where A preset conflict threshold is set.

[0029] In one embodiment, after identifying the unknown vulnerability, the process further includes:

[0030] Extract the features of the identified unknown vulnerabilities and generate new vulnerability element rules based on the identified unknown vulnerability features;

[0031] The newly added vulnerability object rules are written into the known vulnerability object library to form the updated object library;

[0032] Filter out extensional contradiction distance data generated when identifying unknown vulnerabilities in the updated object-element library;

[0033] Based on the selected extension contradiction distance data, the frequency of occurrence of each matter element feature combination is counted, and the matter element feature combinations with a frequency greater than a preset frequency threshold are extracted to obtain high-frequency feature combinations.

[0034] Based on high-frequency feature combinations, the judgment logic for propagating contradictions in the preset rule base is optimized. The optimization of the judgment logic includes adjusting rule weight parameters, logical operator types, or feature combination conditions, which are used to perform subsequent vulnerability analysis.

[0035] In one embodiment, after identifying the unknown vulnerability, the process further includes:

[0036] Extracting the extensional contradiction distance Target element and the attribute characteristics of the object element R to be evaluated;

[0037] A defense recommendation report is generated based on the extracted attribute features. The defense recommendation report includes at least one of the following: access control policy adjustment, intrusion detection rule update, or security patch deployment priority.

[0038] Secondly, this application also provides a vulnerability discovery system based on extension theory, including:

[0039] The data acquisition module is used to acquire vulnerability alarm data and system resource status information of the network system. The vulnerability alarm data includes vulnerability feature information.

[0040] The risk scoring module is used to generate risk scores based on vulnerability alert data using extensional correlation analysis.

[0041] The analysis strategy module is used to determine the vulnerability analysis mode based on the risk score and system resource status information, and to determine the analysis scope using the vulnerability analysis mode.

[0042] The vulnerability identification module is used to identify unknown vulnerabilities by using a preset rule base to identify contradictions between vulnerability feature information and the known vulnerability object library within the analysis scope.

[0043] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described vulnerability discovery method based on extensions.

[0044] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-described extension-based vulnerability discovery method.

[0045] The aforementioned vulnerability discovery method, system, computer equipment, and storage media based on extension theory acquire vulnerability alarm data and system resource status information from the network system. They then use extension theory correlation analysis to generate a risk score, dynamically determine the vulnerability analysis mode based on this score and system resource status information, and define the analysis scope accordingly. Within the analysis scope, a preset rule base is used to identify contradictions between vulnerability feature information and the known vulnerability object library to identify unknown vulnerabilities. Extension theory correlation analysis quantifies the risk score, avoiding the crude assessment of traditional simple weighting or threshold segmentation, reducing false positives or underestimation of risk. Based on the risk score and real-time system resource status, the analysis mode and scope are dynamically customized to optimize computing resource allocation and eliminate resource waste or response delays in high-load scenarios. Within the dynamically defined analysis scope, the mechanism for identifying contradictions between the rule base and the object library effectively captures feature-variant or combined vulnerabilities, achieving efficient discovery of unknown vulnerabilities and improving the initiative and reliability of network security protection. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is a flowchart of the vulnerability discovery method based on extension theory of the present invention;

[0048] Figure 2 This is a structural diagram of the vulnerability discovery system based on extension theory according to the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0050] In one embodiment, such as Figure 1 As shown, a vulnerability discovery method based on extension theory is provided.

[0051] This embodiment illustrates the application of this method to terminal devices (such as vulnerability scanning probes deployed on an enterprise intranet). It is understood that this method can also be applied to cloud server clusters or distributed architectures consisting of terminals and servers (such as terminals collecting data and servers performing analysis), achieved through collaborative interaction between terminals and servers. In the implementation environment, the hardware architecture includes: network probe devices (used to collect vulnerability alarm data and system resource status information in real time), edge computing nodes (performing extension element construction and contradiction distance calculation), cloud computing servers (running resource scheduling engines and rule base matching engines), and storage devices (carrying a known vulnerability element library and a historical feature database). A typical application scenario is: when a network system faces a new type of attack, the terminal probe collects abnormal network request characteristics and server CPU load data; the server dynamically calls the corresponding analysis mode based on risk scoring, and the resource scheduling engine allocates GPU cluster resources according to real-time load; within the defined analysis scope, the rule base identifies the contradiction between the feature and the transmission of elements in the known network vulnerability element library, completing the discovery of unknown logical vulnerabilities and the generation of defense strategies in a hybrid architecture. In this embodiment, the method includes the following steps:

[0052] S01, Obtain vulnerability alert data and system resource status information of the network system. The vulnerability alert data includes vulnerability characteristic information.

[0053] The initial stage of the vulnerability discovery process involves acquiring vulnerability alert data and system resource status information from the network system. Vulnerability alert data consists of standardized data packets generated in real-time by network security monitoring devices (such as intrusion detection systems, firewall log collectors, or endpoint security agents). The data structure includes core fields of vulnerability characteristic information, covering attributes such as attack vector type, affected protocol port number, abnormal payload signature, impact scope identifier, vulnerability disclosure time, attack complexity, severity, lifecycle status, variant derivation, associated threat level, compatibility with protective measures, port status, protocol type, and key attribute parameters such as timestamps. This data can be continuously acquired from distributed probe devices through preset data acquisition interfaces (such as the Syslog protocol or API polling mechanism). System resource status information refers to a dynamic set of indicators of allocable computing resources in the current network environment, including quantitative parameters such as CPU utilization percentage, available GPU memory capacity, memory usage, network bandwidth throughput, and storage I / O latency. This information can be reported in real-time to servers or endpoints through resource monitoring agents (such as Prometheusexporter or custom performance collectors). During implementation, feature extraction and data cleaning are performed on vulnerability alert data to eliminate false alarm noise. The vulnerability alert data and system resource status information are transmitted to the server or terminal through a message queue (such as Kafka or RabbitMQ), and time series alignment and format standardization are performed to generate a unified input stream containing time window markers, providing a high-quality data foundation for subsequent extensional analysis.

[0054] S02, Based on vulnerability alert data, risk scores are generated using extensional correlation analysis.

[0055] Among them, extensional correlation analysis is a method for dynamically quantifying and evaluating vulnerability characteristics using the primitive model and contradiction transmission mechanism of extensional theory. In extensional theory, primitives include matter elements, event elements, and relation elements. In this invention, the relationship between the matter elements of a vulnerability is mainly analyzed by extensional correlation analysis, including constructing the matter element structure, calculating the contradiction distance, and quantifying the risk function. The risk score refers to the comprehensive risk value generated by weighted fusion, which is used to quantify the threat level of the vulnerability (range 0-100 points). In implementation, key attribute parameters of vulnerability feature information (such as attack vector type, abnormal payload signature, impact scope identifier, vulnerability disclosure time, attack complexity, severity, lifecycle status, variant derivation, associated threat level, compatibility with protective measures, port status, and protocol type) are extracted from vulnerability alert data to construct an object to be evaluated. This object is represented by a multi-dimensional attribute vector for subsequent risk assessment. Based on a preset security status threshold range (the upper and lower limit range defined by the security policy), the extensional inconsistency distance of each attribute parameter in the object is calculated. The inconsistency distance is normalized using a preset extensional risk function to generate individual risk factors. According to the preset risk factor weight allocation rules, the individual risk factors are weighted and fused to output a comprehensive risk score.

[0056] S03. Based on risk scoring and system resource status information, determine the vulnerability analysis mode and use the vulnerability analysis mode to determine the analysis scope.

[0057] The vulnerability analysis mode is a pre-configured set of analysis strategies, including combinations of correlation operators for extension correlation analysis (such as a set of mathematical operators for calculating contradiction distance). Each mode corresponds to a different risk level and has a specific analysis dimension. The analysis scope refers to the boundary and depth parameters of the vulnerability scan. In implementation, the risk level range is determined based on the risk score using preset interval threshold division rules; the corresponding vulnerability analysis mode is invoked according to the risk level range; based on the set of correlation operators and system resource status information, the resource scheduling engine calculates the amount of computing resources required for the set of operators, generating resource allocation parameters; based on the resource allocation parameters and the analysis dimension of the set of correlation operators, the analysis scope is dynamically determined, and adaptive resource allocation is achieved through an extension model, optimizing scanning efficiency under real-time resource constraints, avoiding high-load waste, and improving vulnerability discovery response speed.

[0058] S04. Within the scope of analysis, identify unknown vulnerabilities by using a preset rule base to identify contradictions between vulnerability feature information and the known vulnerability object library.

[0059] The system includes a pre-configured set of extensional association rules, containing extensional association degree calculation logic and pre-defined transmission conditions (such as association degree thresholds or combined feature matching rules) for calculating the transmission of contradictions; a known vulnerability object library (a multi-dimensional object database storing historical vulnerability rules, using a relational database (such as MySQL) or NoSQL database, where each object represents a record. The storage structure includes: an object identifier, a unique ID such as UUID, used for indexing; and feature attribute fields, including attack vector types such as SQL injection, integer protocol port numbers, string-type abnormal payload signatures, and enumerated influence scope identifiers. The physical storage of attribute fields is in multi-dimensional vector format; for example, vector dimension n=5 corresponds to 5 key... Attributes. Standard value field, storing the baseline value of the attribute under the security state. Metadata, including creation timestamp and update flag. Feature attribute selection criteria: attributes are dynamically selected based on historical vulnerability data such as the NVD database and expert rules to ensure coverage and scalability; critical criteria: attributes with an attack frequency >100 times / month are selected, such as attack vector type and abnormal payload length, and weights are determined through statistical analysis, such as frequency statistics modules. Security relevance criteria: attributes must be mapped to the security state threshold domain; transmission contradictions are expressed quantitatively through extension contradiction distance, that is, the degree of deviation of the object to be evaluated from the objects in the known vulnerability object library in terms of feature attributes; identifying unknown vulnerabilities refers to the process of determining whether there are feature variations or combined new vulnerabilities based on topological contradiction distance. In implementation, the system extracts the constructed objects to be evaluated within the analysis scope and expresses vulnerability features through multi-dimensional attribute vectors. It calculates the extensional correlation degree between the object and each object in the known vulnerability object library using a pre-defined rule base (e.g., comparing feature attribute similarity using a correlation degree algorithm). Based on the extensional correlation degree, it identifies the set of target objects that meet pre-defined propagation conditions. It quantifies the deviation between the target object set and the objects to be evaluated using the extensional contradiction distance formula. If the extensional contradiction distance exceeds a pre-defined threshold, it determines the existence of an unknown vulnerability. Simultaneously, it can generate new vulnerability object rules to update the object library. By performing rule matching and contradiction calculation, it captures feature-mutated vulnerabilities that traditional methods cannot detect, thereby improving the initiative and reliability of network security protection.

[0060] The aforementioned vulnerability discovery method based on extension theory acquires vulnerability alert data and system resource status information of the network system. Based on this vulnerability alert data, it generates a risk score using extension theory correlation analysis. By constructing the object to be evaluated and calculating the extension contradiction distance, it quantifies the contradictory relationship between vulnerability features and security status, reducing false alarm rates and risk underestimation. Based on this risk score and system resource status information, it dynamically determines the vulnerability analysis mode and uses this mode to define the analysis scope, achieving adaptive allocation of computing resources and eliminating resource waste or response delays. Within the dynamically defined analysis scope, it identifies the transmission contradictions between vulnerability feature information and the known vulnerability object library through a preset rule base, capturing feature mutations or combination vulnerabilities, efficiently identifying unknown vulnerabilities, and improving the initiative and reliability of network security protection.

[0061] In one embodiment, based on risk scoring and system resource status information, a vulnerability analysis model is determined, and the analysis scope is determined using the vulnerability analysis model, including:

[0062] S11, based on risk score, determines the risk level range to which it belongs through preset interval threshold division rules;

[0063] S12, invoke the corresponding vulnerability analysis mode according to the risk level range. The vulnerability analysis mode contains a set of correlation operators for extension correlation analysis.

[0064] S13, Based on the set of association operators and system resource status information, the resource scheduling engine calculates the amount of computing resources required for the set of association operators and generates resource allocation parameters;

[0065] S14. Determine the analysis scope based on the analysis dimensions of resource allocation parameters and the set of associated operators.

[0066] Specifically, the preset threshold rule maps the risk score to discrete levels (low / medium / high risk), for example, a score of 0-30 is low risk, 31-70 is medium risk, and 71-100 is high risk. The scoring values ​​are based on historical vulnerability data statistics or expert rules, such as the CVSS 3.0 vulnerability scoring system and extensional model verification results. The interval thresholds are obtained through training with historical vulnerability data (10,000 samples from the NVD database). The risk grading model is then evaluated, showing an accuracy rate of 92%. Low-risk intervals correspond to negligible vulnerabilities (e.g., CVE score < 4.0), while high-risk intervals correspond to critical vulnerabilities (e.g., CVE score ≥ 9.0). Each risk level is associated with a pre-configured analysis mode: for low-risk modes, lightweight correlation operators (e.g., single-dimensional feature comparison) are invoked; for high-risk modes, composite operators (e.g., multi-dimensional contradiction propagation analysis, feature combination scanning) are invoked. The operator set is essentially a strategic combination of extensional correlation functions, including a contradiction distance calculation function set and a correlation evaluation function set. A computational resource model (e.g., GPU computing power requirements) is established based on the correlation operator set. ,in For single operator computation, The maximum allocable resource amount is calculated by combining system CPU utilization, memory availability, and other state parameters (parallelism factor) with a constrained optimization algorithm (linear programming). Output parameters include the number of scanning threads and memory quota. Based on the maximum allocable resource amount parameter and the operator analysis dimension, a scanning boundary is generated: horizontal range, which limits the target system components (e.g., scanning only Web service ports); vertical range, which controls the feature scanning depth (e.g., analyzing only the first 3 layers of the payload feature code coding structure). For example, when the resource parameter limits memory to <2GB, the analysis range is shrunk to a subset of high-weight feature attributes, and low-weight attributes are abandoned.

[0067] In one embodiment, a risk score is generated based on vulnerability alert data using extensional correlation analysis, including:

[0068] S21, extract the key attribute parameters of vulnerability feature information from vulnerability alarm data, construct the object element to be evaluated, and the object element to be evaluated is used to participate in the generation of risk score;

[0069] S22, based on the preset safety state threshold domain, calculate the extension contradiction distance of each attribute parameter in the object to be evaluated;

[0070] S23, by using a preset extension risk function, the extension contradiction distance of each attribute parameter in the object to be evaluated is quantified to generate a single risk factor;

[0071] S24: Based on the preset risk factor weighting rules, the individual risk factors are weighted and integrated to output a comprehensive risk score.

[0072] For example, the object to be evaluated is used to participate in risk scoring, and the structured expression of vulnerability feature attributes is R=(feature attribute k, value). ), such as feature attributes like attack vector type, port status, protocol type, etc., with values ​​representing SQL injection type encoding, port number, protocol encoding, etc.; security threshold domain. These are dynamic values, such as for protocol ports: The maximum number of allowed ports, The baseline port number; the extension conflict distance is the calculated attribute value. With safety threshold domain deviation The degree to which quantified attributes deviate from the safety benchmark; the preset extension risk function is: Mapping the contradiction distance to a risk factor allows high-bias attributes to experience exponential risk growth; weighted fusion involves dynamically configuring weights based on vulnerability type. (Among them, the base weight of attack vector type is 0.6, which can be dynamically adjusted to 0.8 for network protocol vulnerabilities; the base weight of abnormal payload signature is 0.5, which can be dynamically adjusted to 0.6 for application layer vulnerabilities (such as SQL injection); the base weight of protocol port number is 0.4, which can be dynamically adjusted to 0.3 for distributed denial-of-service attacks; the impact scope identifier is 0.3, which is adjusted to 0.5 for IoT device vulnerabilities. Additionally, it can be adjusted according to scenario awareness: if the frequency of attack vector occurrences in vulnerability alert data is >50 times / hour (such as large-scale XSS attacks), the weight is increased to 0.8, and its update formula is...) If the system resource status shows CPU utilization > 80%, then reduce the calculation priority of low-weight attributes (such as the scope of influence identifier, e.g., weight × 0.8), and pass the risk scoring. Output the overall value.

[0073] In one embodiment, within the scope of analysis, unknown vulnerabilities are identified by using a preset rule base to identify contradictions in the transmission of vulnerability feature information and the known vulnerability object library, including:

[0074] S31, Based on the analysis scope, extract the elements to be evaluated;

[0075] S32, calculate the extension correlation degree between the object to be evaluated and each object in the known vulnerability object library through a preset rule base;

[0076] S33, based on extensional correlation, determines the target matter element that meets the preset transmission conditions;

[0077] S34, calculate the extensional conflict distance between the target matter and the matter to be evaluated, and determine the unknown vulnerability based on the extensional conflict distance between the target matter and the matter to be evaluated.

[0078] Specifically, in implementation, within the scope of analysis, the object elements to be evaluated, constructed based on vulnerability alert data, are extracted and analyzed using association functions in the rule base, such as... Quantify the similarity between the object element R to be evaluated and each object element in the vulnerability object element library, where Pre-configured attribute weights for the rule base; based on preset logical rules (such as...) Feature combination matching number 3, For the safety threshold range The threshold within the range (based on historical preset logical rules) is used to filter out target objects, ensuring that there is a potential contradiction transmission path between the target object and the object to be evaluated; unknown vulnerabilities are determined based on the extension contradiction distance between the target object and the object to be evaluated; through the vulnerability object library and the topological contradiction of the object to be evaluated in real time, the dynamic mining of feature combination variation vulnerabilities is realized, capturing feature variation vulnerabilities that cannot be covered by traditional rule bases.

[0079] In one embodiment, the extensional conflict distance between the target matter-element and the matter-to-be-evaluated is calculated, and the unknown vulnerability is determined based on the extensional conflict distance between the target matter-element and the matter-to-be-evaluated, including:

[0080] S41, Calculate the target object element using the following formula. With the object to be evaluated Extensional contradiction distance :

[0081]

[0082] in, Let R be the value of the object element to be evaluated on the k-th characteristic attribute. For target matter element The standard value of the k-th feature attribute The difference between the upper and lower limits of the security status threshold field for the k-th attribute is given. The preset weight factor for the k-th attribute;

[0083] S42, if the target object exists Satisfying extensional contradiction distance Then it is determined that there is an unknown vulnerability in the object element R to be evaluated, where A preset conflict threshold is set.

[0084] For example, based on the target object (i.e., candidate objects in the known vulnerability object library) and the object to be evaluated (vulnerability feature attribute vectors extracted from the analysis scope). ,in Let R be the value of the object element to be evaluated on the k-th characteristic attribute. The extension contradiction distance formula is used to quantify the attribute deviation between the two elements. In extension theory, the contradiction distance characterizes the degree of deviation between two objects on characteristic attributes. The general formula is defined as: Where d is the distance between the object element x to be evaluated and the classical domain boundary, and D represents the distance between the object element x to be evaluated and the section domain boundary. Based on this formula, through normalization processing, different features are... Unified mapping to Intervals are converted into membership degrees. To eliminate the magnitude differences in the correlation function values ​​of different features and make multiple features comparable, a normalization threshold is introduced. The absolute differences of each feature are relativized, i.e. In actual evaluation, different features have different degrees of influence on matter-element objects, therefore feature weights are introduced. For each feature, the square of the relative difference is multiplied by the corresponding weight. To highlight the contribution of key dimensions to distance calculation, reduce the interference of secondary dimensions, and meet the actual evaluation logic, weighted Euclidean distance calculation is used here:

[0085]

[0086] The discrete deviations of multiple features are integrated into a single overall distance value, which intuitively quantifies the total deviation of the object being evaluated from the standard domain. For target matter element The standard value of the k-th feature attribute (the baseline value pre-stored in the known vulnerability feature database). The difference between the upper and lower limits of the security state threshold range for the k-th attribute (reflecting the security tolerance fluctuation range of the k-th attribute, used to normalize attribute deviations, such as network bandwidth attributes). (Can be set to a difference of 100Mbps-1Gbps) The preset weighting factor for the k-th attribute (dynamically configured according to the vulnerability type, such as attack vector weighting at 0.7); during calculation, computing power is dynamically allocated based on system resource status information (such as CPU utilization); if any matter exists... Satisfying extensional contradiction distance ( The default value for the preset contradiction threshold is 3. It can be optimized through training with historical vulnerability data, such as confusion matrix testing (minimum false positive rate when recall > 95%). Then, it is determined that there is an unknown vulnerability in the object R to be evaluated. By capturing significant deviations in feature attributes (e.g., when the payload feature code deviation exceeds the threshold), variant or combination vulnerabilities that cannot be covered by traditional rule bases are identified.

[0087] In one embodiment, after identifying the unknown vulnerability, the process further includes:

[0088] S51, extract the features of the identified unknown vulnerabilities, and generate new vulnerability element rules based on the identified unknown vulnerability features;

[0089] S52, write the newly added vulnerability object rules into the known vulnerability object library to form the updated object library;

[0090] S53, Filter out the extensional contradiction distance data generated when identifying unknown vulnerabilities in the history of the updated object element library;

[0091] S54. Based on the selected extension contradiction distance data, the frequency of occurrence of each matter element feature combination is counted, and the matter element feature combinations with a frequency greater than the preset frequency threshold are extracted to obtain high-frequency feature combinations.

[0092] S54. Based on high-frequency feature combinations, optimize the judgment logic for propagating contradictions in the preset rule base. The optimization of the judgment logic includes adjusting rule weight parameters, logical operator types, or feature combination conditions, which are used to perform subsequent vulnerability analysis.

[0093] Specifically, after identifying an unknown vulnerability, the characteristic attributes of the vulnerability (such as abnormal payload encoding patterns or attack vector combinations) are extracted, and new vulnerability object rules (structured data objects containing standard values ​​of characteristic attributes, security threshold domains, and propagation contradiction calculation parameters) are generated. These rules are then written into the known vulnerability object library to form an updated object library. Based on the updated object library, the extension contradiction distance data generated during the historical identification of unknown vulnerabilities is filtered out through frequency statistics. According to this extension contradiction distance data, high-frequency feature combinations that satisfy a preset frequency threshold (traversing all object combinations that satisfy extension contradiction distance data > preset contradiction threshold η, counting the combination labels of each object combination, establishing a global frequency mapping table, and filtering labels that satisfy a preset frequency threshold (>100 times / week)) are extracted (e.g., SQL injection + port 3306 occurrence frequency > 150 times / week). The propagation contradiction judgment logic in the preset rule library is optimized based on the high-frequency feature combinations—including adjusting the rule weight parameters (if the high-frequency combination is an attack vector type = XSS and...). If port number = 80, the original weight will be increased from 0.5 to 0.7 to ensure that subsequent analysis prioritizes matching this combination. The logical operator type will be switched (if a high-frequency combination involves multiple attributes, such as protocol type OR port number, the original AND operator will be changed to OR to expand the matching range and reduce false negatives). Alternatively, the feature combination conditions will be reconstructed (adding conditions such as IF(protocol type = HTTP and payload length > 1000) THEN risk level = HIGH and embedding them into the rule base). This will enable the optimized rule base to have adaptive evolution capabilities, forming a technical closed loop of vulnerability identification, knowledge accumulation, and rule optimization, and solving the problem of defense lag caused by static updates of traditional vulnerability databases.

[0094] In one embodiment, after identifying the unknown vulnerability, the process further includes:

[0095] S61, Extract the extensional conflict distance. Target element and the attribute characteristics of the object element R to be evaluated;

[0096] S62, Generate a defense recommendation report based on the extracted attribute features. The defense recommendation report includes at least one of the following: access control policy adjustment, intrusion detection rule update, or security patch deployment priority.

[0097] For example, after identifying an unknown vulnerability, extracting the target object set that satisfies... Target element and the attribute characteristics of the object R to be evaluated (a set of high-risk attributes such as the attack vector type, impact scope identifier, and payload signature), such as when When dealing with SQL injection vulnerability objects, the system extracts the characteristics of abnormal query statements and protocol port statuses from R. Based on the extracted attribute characteristics, a defense strategy engine generates a defense recommendation report, including three types of dynamic response measures: access control policy adjustment (dynamically closing high-risk ports based on attack vector characteristics, such as closing the rarely used port 8081), intrusion detection rule update (generating new detection regular expressions based on payload signatures), and security patch deployment priority (classifying emergency / non-emergency patch levels based on impact scope identifiers). By directly mapping technical vulnerability characteristics to defense actions, an integrated detection-response mechanism is formed.

[0098] The aforementioned vulnerability discovery method based on extension theory acquires vulnerability alarm data and system resource status information, extracts key attribute parameters using extension theory correlation analysis to construct the object to be evaluated, calculates the extension contradiction distance, and generates a quantitative risk score through a preset risk function, thus solving the problem of coarse risk assessment. It accurately quantifies vulnerability threats through a contradiction propagation mechanism, reducing false alarm rates and risk underestimation. Based on the risk score and real-time resource status, it dynamically divides risk level intervals and calls corresponding vulnerability analysis modes (including a set of correlation operators). A resource scheduling engine calculates resource allocation parameters to determine the analysis scope, eliminating resource scheduling rigidity, optimizing computational resource allocation, and avoiding waste or delays under high load. Within the dynamically defined analysis scope, it calculates the extension correlation degree between the object to be evaluated and the known vulnerability object library using a preset rule base. After identifying the target object set, it calculates the extension contradiction distance. When a preset threshold is met, an unknown vulnerability is identified. To address the issue of missing unknown vulnerability identification, it uses a contradiction propagation mechanism to capture feature mutations or combination-type vulnerabilities. For example, it calculates deviations using formulas and generates new vulnerability object rules to update the library. Combined with subsequent high-frequency feature combinations, it optimizes the rule base judgment logic, achieving adaptive evolution and improving vulnerability discovery efficiency. To enable efficient and accurate discovery of unknown vulnerabilities, thereby enhancing the proactiveness and reliability of network security protection.

[0099] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0100] Based on the same inventive concept, this application also provides an extension-based vulnerability discovery system for implementing the extension-based vulnerability discovery method described above. The solution provided by this device is similar to the implementation scheme described in the above method; therefore, the specific limitations of one or more extension-based vulnerability discovery system embodiments provided below can be found in the limitations of the extension-based vulnerability discovery method described above, and will not be repeated here.

[0101] In one exemplary embodiment, such as Figure 2 As shown, a vulnerability discovery system based on extensionology is provided, including:

[0102] Data acquisition module 101 is used to acquire vulnerability alarm data and system resource status information of the network system. The vulnerability alarm data includes vulnerability feature information.

[0103] Risk scoring module 102 is used to generate risk scores based on vulnerability alert data using extensional correlation analysis;

[0104] The analysis strategy module 103 is used to determine the vulnerability analysis mode based on the risk score and system resource status information, and to determine the analysis scope using the vulnerability analysis mode.

[0105] The vulnerability identification module 104 is used to identify unknown vulnerabilities by identifying contradictions between vulnerability feature information and the known vulnerability object library through a preset rule base within the analysis scope.

[0106] In one embodiment, the analysis strategy module 103 is further configured to:

[0107] Based on the risk score, the risk level range to which it belongs is determined by a preset range threshold division rule;

[0108] The corresponding vulnerability analysis mode is invoked according to the risk level range. The vulnerability analysis mode contains a set of correlation operators for extension correlation analysis.

[0109] Based on the set of related operators and system resource status information, the resource scheduling engine calculates the amount of computing resources required for the set of related operators and generates resource allocation parameters.

[0110] The scope of analysis is determined based on the analysis dimensions of resource allocation parameters and the set of related operators.

[0111] In one embodiment, the risk scoring module 102 is further configured to:

[0112] Extract key attribute parameters of vulnerability feature information from vulnerability alert data, construct the object element to be evaluated, and use the object element to participate in the generation of risk score;

[0113] Based on the preset safety state threshold range, the extension contradiction distance of each attribute parameter in the object to be evaluated is calculated.

[0114] By quantifying the extension contradiction distance of each attribute parameter in the object to be evaluated through a preset extension risk function, a single risk factor is generated.

[0115] Based on the preset risk factor weighting rules, individual risk factors are weighted and integrated to output a comprehensive risk score.

[0116] In one embodiment, the vulnerability identification module 104 is further configured to:

[0117] Based on the scope of analysis, extract the elements to be evaluated;

[0118] The extension correlation degree between the object to be evaluated and each object in the known vulnerability object library is calculated using a preset rule base.

[0119] Based on extensional correlation, target matter elements that meet preset transmission conditions are identified.

[0120] Calculate the extensional conflict distance between the target matter-element and the matter-element to be evaluated, and determine the unknown vulnerability based on the extensional conflict distance between the target matter-element and the matter-element to be evaluated.

[0121] In one embodiment, the vulnerability identification module 104 is further configured to:

[0122] Calculate the target matter element using the following formula. With the object to be evaluated Extensional contradiction distance :

[0123]

[0124] in, Let R be the value of the object element to be evaluated on the k-th characteristic attribute. For target matter element The standard value of the k-th feature attribute The difference between the upper and lower limits of the security status threshold field for the k-th attribute is given. The preset weight factor for the k-th attribute;

[0125] If a target matter exists Satisfying extensional contradiction distance Then it is determined that there is an unknown vulnerability in the object element R to be evaluated, where A preset conflict threshold is set.

[0126] In one embodiment, the vulnerability identification module 104 is further configured to:

[0127] Extract the features of the identified unknown vulnerabilities and generate new vulnerability element rules based on the identified unknown vulnerability features;

[0128] The newly added vulnerability object rules are written into the known vulnerability object library to form the updated object library;

[0129] Filter out extensional contradiction distance data generated when identifying unknown vulnerabilities in the updated object-element library;

[0130] Based on the selected extension contradiction distance data, the frequency of occurrence of each matter element feature combination is counted, and the matter element feature combinations with a frequency greater than a preset frequency threshold are extracted to obtain high-frequency feature combinations.

[0131] Based on high-frequency feature combinations, the judgment logic for propagating contradictions in the preset rule base is optimized. The optimization of the judgment logic includes adjusting rule weight parameters, logical operator types, or feature combination conditions, which are used to perform subsequent vulnerability analysis.

[0132] In one embodiment, the vulnerability identification module 104 is further configured to:

[0133] Extracting the extensional contradiction distance Target element and the attribute characteristics of the object element R to be evaluated;

[0134] A defense recommendation report is generated based on the extracted attribute features. The defense recommendation report includes at least one of the following: access control policy adjustment, intrusion detection rule update, or security patch deployment priority.

[0135] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the steps of the extension-based vulnerability discovery method as described above.

[0136] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0137] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The components described as separate parts may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0138] The above-described embodiments are merely illustrative of several implementation methods of the embodiments of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the embodiments of this application, and these modifications and improvements all fall within the protection scope of the embodiments of this application.

Claims

1. A vulnerability discovery method based on extension theory, characterized in that, The method includes: Acquire vulnerability alert data and system resource status information of the network system, wherein the vulnerability alert data includes vulnerability characteristic information; Based on the vulnerability alert data, a risk score is generated using extensional correlation analysis. Based on the risk score and system resource status information, a vulnerability analysis mode is determined and the analysis scope is determined using the vulnerability analysis mode. Within the scope of the analysis, unknown vulnerabilities are identified by using a preset rule base to identify contradictions between the vulnerability feature information and the known vulnerability object library.

2. The method according to claim 1, characterized in that, The process of determining a vulnerability analysis mode based on the risk score and system resource status information, and then using the vulnerability analysis mode to determine the analysis scope, includes: Based on the risk score, the risk level range to which it belongs is determined by a preset interval threshold division rule; The corresponding vulnerability analysis mode is invoked according to the risk level range, and the vulnerability analysis mode includes a set of correlation operators for extension correlation analysis; Based on the set of related operators and the system resource status information, the resource scheduling engine calculates the amount of computing resources required for the set of related operators and generates resource allocation parameters. The analysis scope is determined based on the resource allocation parameters and the analysis dimensions of the set of correlation operators.

3. The method according to claim 1, characterized in that, The process of generating a risk score based on the vulnerability alert data using extensional correlation analysis includes: Extract key attribute parameters of vulnerability feature information from the vulnerability alarm data, construct the object element to be evaluated, and the object element to be evaluated is used to participate in the generation of the risk score; Based on the preset safety state threshold range, the extension contradiction distance of each attribute parameter in the object to be evaluated is calculated. The extension contradiction distance of each attribute parameter in the object to be evaluated is quantified by a preset extension risk function to generate a single risk factor. The individual risk factors are weighted and fused according to the preset risk factor weight allocation rules to output a comprehensive risk score.

4. The method according to claim 3, characterized in that, Within the scope of the analysis, the identification of unknown vulnerabilities involves recognizing contradictions between the vulnerability feature information and the known vulnerability object library through a preset rule base, including: Based on the aforementioned analysis scope, the object element to be evaluated is extracted; The extension correlation degree between the object to be evaluated and each object in the known vulnerability object library is calculated using the preset rule base. Based on the aforementioned extension correlation, target matter elements that meet the preset transmission conditions are determined; Calculate the extensional conflict distance between the target matter and the matter to be evaluated, and determine the unknown vulnerability based on the extensional conflict distance between the target matter and the matter to be evaluated.

5. The method according to claim 4, characterized in that, The calculation of the extensional conflict distance between the target matter and the matter to be evaluated, and the determination of unknown vulnerabilities based on the extensional conflict distance between the target matter and the matter to be evaluated, includes: The target object element is calculated using the following formula. With the object to be evaluated Extensional contradiction distance : in, Let R be the value of the object element to be evaluated on the k-th characteristic attribute. For target matter element The standard value of the k-th feature attribute The difference between the upper and lower limits of the security status threshold field for the k-th attribute is given. The preset weight factor for the k-th attribute; If a target matter exists Satisfying extensional contradiction distance Then it is determined that there is an unknown vulnerability in the object R to be evaluated, wherein A preset conflict threshold is set.

6. The method according to claim 5, characterized in that, After identifying the unknown vulnerability, the method also includes: Extract the features of the identified unknown vulnerabilities, and generate new vulnerability element rules based on the identified unknown vulnerability features; The newly added vulnerability object rules are written into the known vulnerability object library to form an updated object library. The updated object-element library is used to filter out extensional contradiction distance data generated during the historical identification of unknown vulnerabilities; Based on the selected extension contradiction distance data, the frequency of occurrence of each matter element feature combination is counted, and the matter element feature combinations with a frequency greater than a preset frequency threshold are extracted to obtain high-frequency feature combinations. Based on the high-frequency feature combination, the judgment logic for propagating contradictions in the preset rule base is optimized. The optimized judgment logic includes adjusting the rule weight parameters, logical operator types, or feature combination conditions for subsequent vulnerability analysis.

7. The method according to claim 5, characterized in that, After identifying the unknown vulnerability, the process also includes: Extract the extensional contradiction distance Target element and the attribute characteristics of the object element R to be evaluated; A defense recommendation report is generated based on the extracted attribute features. The defense recommendation report includes at least one of the following: access control policy adjustment, intrusion detection rule update, or security patch deployment priority.

8. A vulnerability discovery system based on extension theory, characterized in that, The system includes: The data acquisition module is used to acquire vulnerability alarm data and system resource status information of the network system, wherein the vulnerability alarm data includes vulnerability feature information; The risk scoring module is used to generate a risk score based on the vulnerability alarm data using extensional correlation analysis. The analysis strategy module is used to determine the vulnerability analysis mode based on the risk score and system resource status information, and to determine the analysis scope using the vulnerability analysis mode. The vulnerability identification module is used to identify contradictions between the vulnerability feature information and the known vulnerability object library within the analysis scope, and to identify unknown vulnerabilities.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.