Security vulnerability information sharing and management system
By using the security vulnerability information sharing and management system, and employing information collection, analysis, and early warning modules to calculate risk indices, the system solves the problem of difficulty in detecting unknown vulnerabilities in existing technologies. This enables efficient vulnerability management and risk early warning, thereby enhancing the proactiveness and overall security of network security.
Patent Information
- Application Number
- CN202511772579.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-03-10
AI Technical Summary
Existing vulnerability scanning tools struggle to detect unknown vulnerabilities, while manual penetration testing is costly and inefficient, making it impossible to effectively manage cybersecurity vulnerabilities.
A security vulnerability information sharing and management system was designed, which includes information collection, analysis and early warning modules. It identifies and assesses potential vulnerabilities by calculating risk index and generates early warning reports.
It enhances the proactiveness and preventative nature of information security management, helps enterprises to promptly identify and fix security vulnerabilities, reduce potential risks, and improve overall security and trustworthiness.
Smart Images

Figure CN121644160A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information management, in particular to a security vulnerability information sharing and management system. BACKGROUND
[0002] Network information, generally refers to the data and content spread through network channels, including text, pictures, videos and other forms, network information security is a crucial issue in modern society, it is not only related to the protection of personal privacy, but also involves the maintenance of enterprise, government and even national security, with the rapid development of Internet technology and the increasingly wide application, network security problems have become increasingly complex and serious, network security refers to the protection of network system hardware, software and data from attack, damage, modification or leakage, to ensure the continuous and reliable normal operation of the system, and uninterrupted service, information security emphasizes the confidentiality, integrity and availability of information, to prevent unauthorized access, tampering or destruction of information, data security refers specifically to the security management of data, including the security control of data collection, storage, processing, transmission and other processes to protect the integrity and confidentiality of data, network security is the key to maintaining national security, social stability and personal privacy rights, security vulnerability information sharing and management is a key link in the field of network security, which involves vulnerability discovery, reporting, patching and information publishing and other aspects.
[0003] Although the existing vulnerability scanning tools can automatically find known vulnerabilities in the system, but for unknown vulnerabilities or new attack methods, the detection is still insufficient, in addition, manual penetration testing can find unknown vulnerabilities, but the cost is high and the efficiency is low. SUMMARY
[0004] (I) Technical problems solved
[0005] In view of the defects of the prior art, the present application provides a security vulnerability information sharing and management system, which has the advantages of considering the security vulnerabilities in the information sharing and transmission process from the aspects of enterprise information, transmission information, user information and hardware information, and improving the information security.
[0006] (II) Technical scheme
[0007] In order to achieve the above purpose, the present application provides the following technical scheme: a security vulnerability information sharing and management system, comprising an information collection module, an information analysis module, an evaluation module and an information early warning module;
[0008] The information collection module is used for connecting the Internet to collect enterprise information data , collecting transmission information data , collecting user information data , collecting hardware information data The collected information is then numbered to form separate datasets: enterprise information, transmission information, user information, and hardware information. These datasets are then sent to the information analysis module.
[0009] The information analysis module calculates the enterprise information risk index based on the enterprise information data set. The transmission information risk index is calculated based on the transmission information data set. The user information risk index is calculated based on the user information dataset. The hardware information risk index is calculated based on the hardware information dataset. ;
[0010] The information analysis module is based on the enterprise information risk index. Information transmission risk index User information risk index Hardware Information Risk Index Calculate the comprehensive risk index Send to the evaluation module;
[0011] The assessment module is based on a comprehensive risk index. It determines whether the current information contains dangerous vulnerabilities, and if it does, it sends a signal to the information warning module.
[0012] Preferably, the expression for the enterprise information data set is: , and These represent the first and last enterprise information data in the enterprise information dataset, respectively. The enterprise information data includes the enterprise's comprehensive management capabilities, data source security, technological development trends, and market demand, and its expression is: .
[0013] The expression for the transmitted information data set is: , and These represent the first and last transmitted information data in the transmitted information data set, respectively. The transmitted information data includes transmission efficiency, transmission speed, and transmission quantity, and its expression is: .
[0014] Preferably, the expression for the user information data set is: , and These represent the first and last user information data in the user information dataset, respectively. The user information data includes the number of user information data, the user's historical risk index, and the user data transmission frequency, expressed as follows: ;
[0015] The expression of the hardware information data set is: , and respectively represent the first hardware information data and the last hardware information data in the hardware information data set, and the hardware information data includes historical attack risk, hardware configuration performance, and hardware capacity data, and the expression is: .
[0016] Preferably, the enterprise information risk index is calculated according to the following formula:
[0017] In the above formula, represents the enterprise information risk coefficient under normal circumstances. Preferably, the transmission information risk index is calculated according to the following formula
[0018]
[0019] In the above formula, represents the transmission information risk coefficient under normal circumstances.
[0020] Preferably, the user information risk index is calculated according to the following formula:
[0021]
[0022] In the above formula, represents the user information risk coefficient under normal circumstances.
[0023] Preferably, the hardware information risk index is calculated according to the following formula:
[0024]
[0025] In the above formula, represents the hardware information risk coefficient under normal circumstances.
[0026] Preferably, the comprehensive risk index is calculated according to the following formula:
[0027]
[0028] Preferably, the evaluation module compares the comprehensive risk index with a comprehensive risk threshold, and determines that there is a dangerous vulnerability when the comprehensive risk threshold is exceeded.
[0029] Preferably, the information warning module generates a dangerous vulnerability report according to the dangerous vulnerability and issues a warning.
[0030] Compared with the prior art, the present application provides a security vulnerability information sharing and management system with the following beneficial effects:
[0031] 1、The present application calculates the enterprise information risk index by enterprise information data set, judges the security vulnerability of enterprise information in information sharing from the nature of the enterprise, can help enterprises identify and assess potential security threats and vulnerabilities in the information sharing process, help enterprises can timely discover and repair security vulnerabilities, reduce potential losses, enterprises can better manage and reduce information security risks, protect themselves from potential security threats, calculate the transmission information risk index by transmission information data set , effectively identify and manage security vulnerabilities in information sharing, better understand their weaknesses in information sharing, and help enterprises take more proactive and preventive measures in information security management, thereby reducing potential security threats.
[0032] 2、The present application calculates the user information risk index by user information data set , filters and judges users, selects high-risk customers to improve the overall safety factor, calculates the hardware information risk index by hardware information data set , which can help organizations identify potential security risks and take appropriate protective measures, also improve the security of the organization, enhance trust, promote compliance, optimize resource allocation and improve competitiveness. BRIEF DESCRIPTION OF DRAWINGS
[0034] Figure 1 The structural system diagram of the present application is shown in the figure; DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0037] Please refer to Figure 1 , a security vulnerability information sharing and management system, comprising an information collection module, an information analysis module, an evaluation module and an information early warning module;
[0038] The information collection module is used to connect the Internet to collect enterprise information data , collect transmission information data , and collect user information data collecting, collecting hardware information data collecting, and numbering the collected information to form enterprise information data set, transmission information data set, user information data set, and hardware information data set, and then sending to information analysis module;
[0039] The expression of enterprise information data set is: , and represent the first and last enterprise information data in the enterprise information data set, respectively. Enterprise information data includes enterprise comprehensive management capability, data source security, technology development trend and market demand, and its expression is: Enterprise comprehensive management capability fully reflects the enterprise's multiple key aspects in the process of information transmission and sharing, including technical ability, management process and personnel quality, etc. Data source security fully reflects the enterprise's ability in data extraction process. Technology development trend and market demand facilitate further judgment of enterprise's risk in subsequent information acquisition;
[0040] The expression of transmission information data set is: , and represent the first and last transmission information data in the transmission information data set, respectively. Transmission information data includes transmission efficiency, transmission speed and transmission quantity, and its expression is: Transmission efficiency plays a core role in information security vulnerability management. It not only concerns the timeliness and accuracy of information, but also directly affects the security protection ability and business continuity of the organization. Transmission speed affects processing efficiency and is also related to the security defense ability and business continuity of the whole organization. Transmission quantity affects transmission efficiency and transmission speed, and is directly related to the load of the network;
[0041] The expression of user information data set is: , and represent the first and last user information data in the user information data set, respectively. User information data includes user information data quantity, user historical risk index and user data transmission frequency, and its expression is: User information data quantity and user data transmission frequency represent the load of user information, and user historical risk index can be used to comprehensively evaluate the user's processing ability for historical risk;
[0042] The expression of hardware information data set is: , and respectively represent the first hardware information data and the last hardware information data in the hardware information data set, the hardware information data including historical attack risk, hardware configuration performance, and hardware capacity data, and the expressions are as follows: The historical attack risk and the hardware configuration performance fully reflect the ability of hardware historical risk processing, and the hardware configuration performance is directly related to the security, reliability, and efficiency of the information system, and the efficiency configuration performance is directly related to the security, reliability, and efficiency of the information system.
[0043] The information analysis module calculates the enterprise information risk index according to the enterprise information data set ;
[0044] The calculation formula of the enterprise information risk index is as follows:
[0045]
[0046] The enterprise information risk index is calculated through the enterprise information data set, and the security vulnerabilities of enterprise information in information sharing are judged from the nature of the enterprise, which can help the enterprise to identify and evaluate the security threats and vulnerabilities that may be encountered in the information sharing process, help the enterprise to discover and repair security vulnerabilities in time, reduce potential losses, and better manage and reduce information security risks, and protect the enterprise from potential security threats. In the above formula, represents the enterprise information risk coefficient under the normal condition;
[0047] The transmission information risk index is calculated according to the transmission information data set ;
[0048] The calculation formula of the transmission information risk index is as follows:
[0049]
[0050] The transmission information risk index is calculated through the transmission information data set , effectively identifying and managing security vulnerabilities in information sharing, better understanding the weak links in information sharing, and helping enterprises to take more proactive and preventive measures in information security management, thereby reducing potential security threats. In the above formula, represents the transmission information risk coefficient under the normal condition;
[0051] The user information risk index is calculated according to the user information data set ;
[0052] The calculation formula of the user information risk index is as follows:
[0053]
[0054] Calculate the user information risk index using information data sets. By screening and judging users and eliminating high-risk customers, the overall security level can be improved. In the above formula, This represents the risk coefficient of user information under normal circumstances;
[0055] The hardware information risk index is calculated based on the hardware information data set. ;
[0056] Hardware Information Risk Index The calculation method is as follows:
[0057]
[0058] The hardware information risk index is calculated using a hardware information data set. It can help organizations identify potential security risks and take corresponding protective measures, and can also improve organizational security, enhance trust, promote compliance, optimize resource allocation, and improve competitiveness. In the above formula, This represents the hardware information risk coefficient under normal circumstances;
[0059] The information analysis module is based on the enterprise information risk index. Information transmission risk index User information risk index Hardware Information Risk Index Calculate the comprehensive risk index Send to the evaluation module;
[0060] Overall Risk Index The calculation method is as follows:
[0061]
[0062] The assessment module will integrate the risk index. The system compares the vulnerability with a comprehensive risk threshold. If the vulnerability exceeds the comprehensive risk threshold, a dangerous vulnerability is identified, and a signal is sent to the information warning module.
[0063] The information early warning module generates a vulnerability report based on the vulnerability and issues an early warning.
[0064] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A security vulnerability information sharing and management system, characterized by: The information collection module, the information analysis module, the evaluation module and the information early warning module are included. The information collection module is used for connecting the Internet to collect enterprise information data collecting, transmitting information data collecting, user information data collecting, hardware information data collecting, and numbering the collected information to form enterprise information data set, transmission information data set, user information data set and hardware information data set respectively, and then sending to the information analysis module The information analysis module calculates an enterprise information risk index according to the enterprise information data set calculates a transmission information risk index according to the transmission information data set calculates a user information risk index according to the user information data set calculates a hardware information risk index according to the hardware information data set ; The information analysis module is based on the enterprise information risk index. Information transmission risk index User information risk index Hardware Information Risk Index Calculate the comprehensive risk index Send to the evaluation module; The evaluation module judges whether the current information has dangerous vulnerabilities according to the comprehensive risk index judges whether the current information has dangerous vulnerabilities, and sends a signal to the information warning module in the case of judging that there are dangerous vulnerabilities.
2. The security vulnerability information sharing and management system of claim 1, wherein: The expression of the enterprise information data set is: , and respectively represent the first and last enterprise information data in the enterprise information data set, and the enterprise information data includes enterprise comprehensive management capability, data source security, technology development trend and market demand, and the expression is: , The expression of the transmission information data set is: , and respectively represent the first and last transmission information data in the transmission information data set, and the expression of the transmission information data includes transmission efficiency, transmission speed, and transmission quantity: .
3. The security vulnerability information sharing and management system of claim 1, wherein: The expression of the user information data set is: , and represent the first and last user information data in the user information data set respectively, which includes the number of user information data, user historical risk index, and user data transmission frequency, and the expression is: ; The expression of the hardware information data set is: , and respectively represent the first hardware information data and the last hardware information data in the hardware information data set, which includes historical attack risk, hardware configuration performance, and hardware capacity data, the expression of which is: .
4. The security vulnerability information sharing and management system of claim 1, wherein: The enterprise information risk index The calculation formula is as follows: , In the above formula, represents the enterprise information risk coefficient under the normal condition.
5. The security vulnerability information sharing and management system of claim 1, wherein: The transmission information risk index The calculation formula is as follows: , In the above formula, represents the risk coefficient of the conventional downlink transmission information.
6. The security vulnerability information sharing and management system of claim 1, wherein: The user information risk index The calculation formula is as follows: , In the above formula, represents the user information risk coefficient under the conventional.
7. The security vulnerability information sharing and management system of claim 1, wherein: The hardware information risk index The calculation method is as follows: , In the above formula, represents the hardware information risk coefficient under the normal condition.
8. The security vulnerability information sharing and management system of claim 1, wherein: The composite risk index is calculated as follows: 。 9. The security vulnerability information sharing and management system of claim 1, wherein: The assessment module compares the composite risk index In the case of exceeding the composite risk threshold, it is determined that there is a dangerous vulnerability.
10. The security vulnerability information sharing and management system of claim 1, wherein: The information early warning module generates a dangerous vulnerability report according to the dangerous vulnerability and issues a warning.