Vulnerability verification method and device, computer equipment and readable storage medium

By having multiple vulnerability verification agents work together to automate the vulnerability verification process, the problem of time-consuming and labor-intensive traditional manual verification and the inadequacy of existing tools is solved, achieving efficient and accurate vulnerability verification and enhancing network security protection.

CN121770840APending Publication Date: 2026-03-31SHANGHAI DOUXIANG INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-24
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional vulnerability verification relies on manual operation, which is time-consuming, labor-intensive, and easily affected by subjective factors. It cannot efficiently cope with the high-frequency and high-complexity vulnerability verification needs, and existing automated tools have obvious shortcomings.

Method used

Multiple vulnerability verification agents work together to receive vulnerability reports, extract relevant information, and call upon the agents to perform vulnerability verification, including existence verification, impact scope verification, information search, and environment setup, thereby achieving automation and efficiency in vulnerability verification.

Benefits of technology

It improves the efficiency and accuracy of vulnerability verification, reduces human intervention, enhances network security protection capabilities, and ensures the continuity and stability of the vulnerability verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770840A_ABST
    Figure CN121770840A_ABST
Patent Text Reader

Abstract

The invention relates to a vulnerability verification method and device, computer equipment and a readable storage medium. The method comprises the steps of receiving a vulnerability verification request; the vulnerability verification request comprises a vulnerability report; extracting vulnerability related information in the vulnerability report, and determining at least one vulnerability verification agent required for responding to the vulnerability verification request according to the vulnerability related information; and performing vulnerability verification on the vulnerability report according to the vulnerability related information by calling at least one vulnerability verification agent. By adopting the method, vulnerability verification can be efficiently, accurately and automatically carried out, so that the network security protection capability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security management technology, and in particular to a vulnerability verification method, apparatus, computer equipment, and readable storage medium. Background Technology

[0002] With the rapid development of information technology, the complexity of internet applications and enterprise information systems is increasing daily, making cybersecurity issues more prominent. In the software development and deployment phase, the discovery and remediation of vulnerabilities are core elements in ensuring system security.

[0003] Traditional vulnerability verification relies primarily on manual operation, which has many drawbacks. Manual verification is time-consuming and labor-intensive, and easily affected by subjective factors, leading to errors and delays in the verification process. Furthermore, with the rapid increase in the number and complexity of vulnerability reports, manual verification is clearly inadequate to handle the high-frequency, high-complexity vulnerability verification demands.

[0004] While existing technologies have some automated tools to assist in vulnerability verification, they have significant shortcomings in many aspects and urgently need to be addressed. Summary of the Invention

[0005] Therefore, it is necessary to provide a vulnerability verification method, apparatus, computer equipment, and readable storage medium that can efficiently, accurately, and automatically perform vulnerability verification to improve network security protection capabilities.

[0006] Firstly, this application provides a vulnerability verification method, including:

[0007] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0008] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0009] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0010] In one embodiment, the vulnerability verification agent includes an existence verification agent and an impact scope verification agent; the vulnerability-related information includes a vulnerability type description and vulnerability code logic; accordingly, by invoking at least one vulnerability verification agent to perform vulnerability verification on the vulnerability report based on the vulnerability-related information, the following steps are taken:

[0011] The existence of a vulnerability in a vulnerability report is determined by invoking an existence verification agent to execute the vulnerability code logic.

[0012] If a target vulnerability exists in the vulnerability report and the vulnerability type corresponds to the vulnerability type description, a proof-of-concept (POC) is determined based on the vulnerability type description and the vulnerability code logic.

[0013] The scope of impact of a target vulnerability is determined by executing a Proof of Concept (POC) through an impact scope verification agent.

[0014] In one embodiment, the vulnerability verification agent further includes an information search agent; correspondingly, the scope of impact verification agent executes a Proof of Concept (POC) to determine the scope of impact of the target vulnerability, including:

[0015] By invoking an information search agent, verification reference information can be obtained from publicly available information;

[0016] By invoking the impact scope verification agent to execute the Proof of Concept (POC), the impact scope of the target vulnerability can be determined based on the verification reference information.

[0017] In one embodiment, the vulnerability-related information includes vulnerability environment description information, and the vulnerability verification agent also includes an environment setup agent; correspondingly, the scope of impact of the target vulnerability is determined by calling the scope of impact verification agent to execute the Proof of Concept (POC), including:

[0018] By calling the environment to build an intelligent agent, a verification environment corresponding to the target vulnerability is built according to the vulnerability environment description information;

[0019] By invoking the impact scope verification agent, a proof-of-concept (POC) is executed in the verification environment to determine the impact scope of the target vulnerability.

[0020] In one embodiment, vulnerability-related information is extracted from the vulnerability report, including:

[0021] Based on the type of vulnerability report content, select a target extraction agent from different information extraction agents;

[0022] By invoking the target extraction agent, the content of the vulnerability report is extracted to determine the vulnerability-related information in the vulnerability report.

[0023] In one embodiment, the method further includes:

[0024] Monitor the interruption status of the vulnerability verification process for each vulnerability verification agent;

[0025] If an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the target verification agent is invoked again.

[0026] In one embodiment, the method further includes:

[0027] Based on the vulnerability verification results of each vulnerability verification agent, a vulnerability verification report is generated.

[0028] Determine the report storage method corresponding to the vulnerability verification report based on the scope of the vulnerability's impact;

[0029] Store vulnerability verification reports according to the report storage method.

[0030] Secondly, this application also provides a vulnerability verification device, comprising:

[0031] The request receiving module is used to receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0032] The information extraction module is used to extract vulnerability-related information from vulnerability reports and, based on the vulnerability-related information, determine at least one vulnerability verification agent required to respond to a vulnerability verification request.

[0033] The vulnerability verification module is used to verify vulnerability reports based on vulnerability-related information by invoking at least one vulnerability verification agent.

[0034] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0035] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0036] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0037] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0038] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0039] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0040] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0041] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0042] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0043] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0044] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0045] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0046] The aforementioned vulnerability verification method, apparatus, computer equipment, and readable storage medium receive a vulnerability verification request, which includes a vulnerability report. They extract vulnerability-related information from the vulnerability report and, based on this information, determine at least one vulnerability verification agent required to respond to the request. By invoking this agent, they verify the vulnerability report based on the vulnerability-related information. During this process, because the vulnerability report carries vulnerability-related information, the vulnerability verification result is determined by invoking at least one agent and through collaborative work among the agents, the vulnerability reproduction and verification process is automated. This reduces or even eliminates manual intervention, improves the efficiency and accuracy of vulnerability verification, and ultimately enhances overall network security protection capabilities. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 This is a flowchart illustrating a vulnerability verification method in one embodiment;

[0049] Figure 2 This is a flowchart illustrating the vulnerability verification steps in one embodiment;

[0050] Figure 3 This is a flowchart illustrating the verification report storage step in one embodiment;

[0051] Figure 4 This is a flowchart illustrating the vulnerability verification method in another embodiment;

[0052] Figure 5This is a structural block diagram of a vulnerability verification device in one embodiment;

[0053] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0055] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0056] In one exemplary embodiment, such as Figure 1 As shown, a vulnerability verification method is provided. Taking the application of this method to a server as an example, the method includes the following steps:

[0057] S110 receives vulnerability verification requests.

[0058] The vulnerability verification request includes a vulnerability report. Optionally, the vulnerability report can be in the form of an attachment, an image, or text; this application makes no limitation on this.

[0059] Optionally, the vulnerability verification request can be uploaded by the user after logging into the vulnerability verification system. The vulnerability verification system corresponds to the vulnerability verification server provided in this application.

[0060] Optionally, the vulnerability verification request can be automatically generated and input into the vulnerability verification system when a vulnerability is detected during software development. For example, upon detecting a vulnerability during software development, a vulnerability report is automatically generated and sent to the vulnerability verification system to output a vulnerability verification request.

[0061] S120: Extract vulnerability-related information from the vulnerability report and, based on the vulnerability-related information, determine at least one vulnerability verification agent required to respond to the vulnerability verification request.

[0062] Among them, vulnerability-related information can be information related to the vulnerability existing in the vulnerability report. For example, vulnerability-related information can include at least one of the following: vulnerability description, vulnerability impact scope, vulnerability exploitation conditions, and vulnerability code.

[0063] It should be noted that an intelligent agent is a system capable of perceiving the environment, making autonomous decisions, and executing actions to achieve specific goals, possessing core characteristics such as autonomy, adaptability, interactivity, and learning ability. In this embodiment, the vulnerability verification agent is a pre-trained agent capable of performing vulnerability verification functions.

[0064] It is worth noting that in this embodiment, vulnerability verification is not accomplished by a single vulnerability verification agent, but rather by multiple vulnerability verification agents working together to complete the entire vulnerability verification process. Different vulnerability verification agents have different functional settings. For example, a vulnerability verification agent may include an information extraction agent, used to extract content from the vulnerability report to obtain vulnerability-related information from the report.

[0065] In one alternative implementation, a target extraction agent can be selected from different information extraction agents based on the report content type of the vulnerability report; by invoking the target extraction agent, the report content of the vulnerability report is extracted to determine the vulnerability-related information in the vulnerability report.

[0066] The vulnerability report can contain at least one of the following formats: text, images, and code. A target extraction agent is used to extract information from the vulnerability report.

[0067] Optionally, different types of information extraction agents can be pre-configured. For example, these may include image semantic information extraction agents, text semantic information extraction agents, and report content information extraction agents. Different content types correspond to different information extraction agents. For example, the correspondence between content types and reference extraction agents can be pre-determined, and the reference extraction agent corresponding to the report content type of the vulnerability report can be used as the target extraction agent.

[0068] Furthermore, by calling the interface through the intelligent agent, the target extraction intelligent agent is invoked, and the vulnerability report content is extracted based on the target extraction intelligent agent to extract vulnerability-related information from the vulnerability report.

[0069] Optionally, when the target extraction agent is an image semantic information extraction agent, this agent can extract key information from the image, such as network topology diagrams, code screenshots, and vulnerability location diagrams. By combining image recognition and image understanding technologies, the image content is analyzed to assist in the specific implementation of vulnerability reproduction and verification.

[0070] For example, Optical Character Recognition (OCR) and multimodal large model technology can be combined to parse image content, identify, and extract information that helps in vulnerability reproduction. By utilizing pre-trained image recognition models and multimodal large models, and fine-tuning them according to the needs of vulnerability verification, the ability to recognize and understand specific types of images (such as network topology diagrams and code screenshots) can be improved.

[0071] Optionally, when the target extraction agent is a text semantic information extraction agent, this agent can analyze the text content of the vulnerability report and extract the key elements required for vulnerability reproduction, including vulnerability description, scope of impact, and exploitation conditions. Through natural language processing technology, the extracted information is identified and structured for storage, ensuring the accuracy and completeness of subsequent processing.

[0072] For example, traditional Natural Language Processing (NLP) techniques can be combined with large language models to understand and extract key information, and the extracted results can be stored in a structured manner for subsequent use by agents. By training a dedicated NLP model and combining it with a large language model, the ability to identify security terms and technical details can be improved, ensuring the accurate extraction of key information.

[0073] S130, by invoking at least one vulnerability verification agent, performs vulnerability verification on the vulnerability report based on vulnerability-related information.

[0074] In one optional implementation, each vulnerability verification agent can perform vulnerability verification on the vulnerability report from different dimensions. Taking a vulnerability verification agent comprising a first vulnerability verification agent and a second vulnerability verification agent as an example, the first vulnerability verification agent can perform vulnerability verification on the vulnerability report based on vulnerability-related information to determine a first vulnerability verification result; the second vulnerability verification agent can perform vulnerability verification on the vulnerability report based on vulnerability-related information to determine a second vulnerability verification result. Further, based on the first vulnerability verification result and the second vulnerability verification result, a target vulnerability verification result is determined.

[0075] In another optional implementation, the vulnerability verification agents collaborate to verify the vulnerability report based on vulnerability-related information. Taking a vulnerability verification agent comprising a first, second, and third agent as an example, the first agent determines a first intermediate result based on the vulnerability-related information; the second agent determines a second intermediate result based on the first intermediate result; and the third agent verifies the vulnerability report based on the second intermediate result to determine the target vulnerability verification result.

[0076] It is worth noting that in scenarios involving collaborative vulnerability verification agents, a task orchestration agent can be pre-deployed to orchestrate the overall vulnerability verification process, including environment selection, task execution order, and result processing. Based on task scheduling algorithms, such as priority scheduling and dependency scheduling, the task execution order is dynamically adjusted to coordinate the work of each vulnerability verification agent, ensuring the efficiency and stability of the process.

[0077] It should be noted that in some embodiments, the interruption of the vulnerability verification process corresponding to each vulnerability verification agent can be monitored; if an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the target verification agent is called again.

[0078] Among them, the target verification agent is the vulnerability verification agent that interrupts the vulnerability verification process.

[0079] For example, if an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the problem and cause can be analyzed through a large model. Furthermore, if there is an abnormal operation of the target verification agent, the corresponding vulnerability verification task can be adjusted; if there is no abnormal operation of the target verification agent, the target verification agent can be called again to avoid interruption of the vulnerability verification process caused by the target vulnerability verification agent crashing, thus ensuring the continuity and stability of the vulnerability verification process.

[0080] The aforementioned vulnerability verification method involves receiving a vulnerability verification request, which includes a vulnerability report. Vulnerability-related information is extracted from the vulnerability report, and based on this information, at least one vulnerability verification agent is determined to respond to the request. This agent is then invoked to verify the vulnerability report based on the relevant vulnerability information. During this process, because the vulnerability report contains vulnerability-related information, the verification result is determined by invoking at least one agent. Through the collaborative work of these agents, the vulnerability reproduction and verification process is automated, reducing or even eliminating manual intervention, improving the efficiency and accuracy of vulnerability verification, and ultimately enhancing overall network security protection capabilities.

[0081] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, the vulnerability verification agent includes an existence verification agent and an impact scope verification agent; the vulnerability-related information includes a vulnerability type description and vulnerability code logic. In this case, the process of calling at least one vulnerability verification agent to verify the vulnerability report based on the vulnerability-related information is refined.

[0082] See Figure 2The vulnerability verification steps shown include:

[0083] S210 determines the existence of a vulnerability in a vulnerability report by calling an existence verification agent to execute the vulnerability code logic.

[0084] The existence verification agent is used to determine whether a vulnerability actually exists in the vulnerability report, and if a vulnerability does exist, the vulnerability in the vulnerability report is used as the target vulnerability.

[0085] For example, vulnerability exploitation operations can be automatically executed based on the steps, conditions, and vulnerability code logic in the vulnerability report, and the existence of the vulnerability in the vulnerability report can be determined based on the execution results.

[0086] S220: If a target vulnerability exists in the vulnerability report and the vulnerability type corresponds to the vulnerability type description, a proof of concept (POC) is determined based on the vulnerability type description and the vulnerability code logic.

[0087] The vulnerability type description is used to describe the type of vulnerability present in the vulnerability report.

[0088] In one alternative implementation, if a vulnerability is found in the vulnerability report, the Proof of Concept (POC) can be determined directly based on the vulnerability type description and the vulnerability code logic.

[0089] In another alternative implementation, if a vulnerability is found in the vulnerability report, it can be determined whether the vulnerability is a target vulnerability. If so, the Proof of Concept (POC) can be determined based on the vulnerability type description and the vulnerability code logic.

[0090] S230 determines the scope of impact of the target vulnerability by invoking the scope of impact verification agent to execute the Proof of Concept (POC).

[0091] In one embodiment, if a vulnerability is found in a vulnerability report, or if it is determined that a vulnerability exists in a vulnerability report and whether the vulnerability is a target vulnerability, an impact scope verification agent can be invoked to automatically write a Proof-of-Concept (POC) code for vulnerability exploitation and execute the POC to further determine the impact scope and exploitability of the vulnerability in the vulnerability report, ensuring the comprehensiveness of vulnerability verification.

[0092] Correspondingly, the impact scope verification agent integrates multiple PoC generation tools and technologies, supports automated PoC writing for complex vulnerabilities, and can generate high-quality PoC code based on the detailed description in the vulnerability report.

[0093] In one alternative implementation, the vulnerability verification agent further includes an information search agent; correspondingly, the information search agent can be invoked to search for verification reference information from publicly available information; and the impact scope verification agent can be invoked to execute a proof-of-concept (POC) to determine the vulnerability impact scope of the target vulnerability based on the verification reference information.

[0094] The verification reference information is information that enables the vulnerability verification agent to perform vulnerability verification. The source of the verification reference information may include at least one of relevant technical documents, research papers and security bulletins, etc., and this application does not impose any restrictions on it.

[0095] For example, the information search agent can use web crawling technology and application programming interface (API) to automatically retrieve and obtain relevant technical documents, research papers and security bulletins to obtain verification reference information.

[0096] In this process, by invoking an information search agent, relevant information can be searched in the Internet and intelligence databases to supplement the background knowledge and technical details required for vulnerability verification, thereby improving the comprehensiveness and accuracy of vulnerability verification.

[0097] It should be noted that the existence verification agent and the scope of impact verification agent integrate multiple vulnerability exploitation tools and technologies, support the automated reproduction of complex vulnerabilities, and can handle multi-step and multi-condition vulnerability verification processes.

[0098] To further improve the accuracy of vulnerability verification results, in another optional implementation, the vulnerability-related information includes vulnerability environment description information, and the vulnerability verification agent also includes an environment building agent; accordingly, the environment building agent can be invoked to build the verification environment corresponding to the target vulnerability based on the vulnerability environment description information; and the impact scope verification agent can be invoked to execute a Proof of Concept (POC) in the verification environment to determine the vulnerability impact scope of the target vulnerability.

[0099] For example, the environment building agent can create the network environment required for vulnerability reproduction and verification in a specified Docker container, including the configuration of the operating system, applications, dependency libraries, etc.

[0100] To improve environment configuration efficiency, multiple environment configuration templates can be preset, and the appropriate verification environment can be automatically selected and configured according to the vulnerability type description, ensuring the consistency and controllability of the environment, thereby improving the accuracy of vulnerability verification.

[0101] In the above embodiments, by having an existence verification agent and an impact scope verification agent work together, it is possible to determine whether a vulnerability exists in the vulnerability report, and if a vulnerability exists, to determine the impact scope of the target vulnerability, which makes vulnerability verification more streamlined.

[0102] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, subsequent processes are supplemented to the vulnerability verification method provided in this application.

[0103] See Figure 3 The verification report storage steps shown include:

[0104] S310 generates a vulnerability verification report based on the vulnerability verification results of each vulnerability verification agent.

[0105] In this embodiment, a report writing agent can be pre-deployed, and a vulnerability verification report can be generated by calling the report writing agent.

[0106] For example, the report writing agent is responsible for analyzing the results of vulnerability reproduction and generating a detailed vulnerability verification report. The execution results of each vulnerability verification agent are summarized, and a structured report is generated using template technology, including vulnerability descriptions, verification processes, result analysis, and recommended measures.

[0107] Optionally, to facilitate user viewing and analysis, the vulnerability verification report supports multiple output formats, such as PDF and HTML.

[0108] S320: Determine the report storage method corresponding to the vulnerability verification report based on the scope of the vulnerability's impact.

[0109] S330 stores vulnerability verification reports according to the report storage method.

[0110] In one optional implementation, if the impact range of a vulnerability in the vulnerability impact range characterization report is less than a preset range threshold, the vulnerability verification report may not be stored; if the impact range of a vulnerability in the vulnerability impact range characterization report is not less than the preset range threshold, the vulnerability verification report may be stored in the corresponding report database. The preset range threshold may be determined based on human experience, and this application does not impose any limitations on it.

[0111] In another alternative implementation, if the vulnerability impact scope characterizes the scope of impact of the vulnerability in the vulnerability report, the vulnerability verification report can be stored in the corresponding report database.

[0112] In the above embodiments, the vulnerability verification results are merged to generate a vulnerability verification report, and the vulnerability verification report is stored according to the scope of vulnerability impact for easy review later.

[0113] Based on the technical solutions of the above embodiments, this application also provides an optional embodiment. In this optional embodiment, taking a pre-configured vulnerability verification agent including a report processing agent, an image semantic extraction agent, a task orchestration agent, an environment building agent, a vulnerability verification agent, a POC writing agent, a search agent, a report writing agent, and an exception handling agent as an example, and taking the existence of a remote code execution (RCE) vulnerability in the vulnerability report as an example, the vulnerability verification method provided by this application will be described in detail.

[0114] See Figure 4 The vulnerability verification method shown includes:

[0115] S401, receives vulnerability reports including RCE vulnerability descriptions;

[0116] The vulnerability report includes a text description, the system components affected by the vulnerability, relevant images (such as network topology diagrams and code screenshots), and attachments (such as log files and configuration files).

[0117] S402, invoke the report processing agent to analyze the report text and extract vulnerability-related information; and...

[0118] The vulnerability information includes: the vulnerability type is described as RCE, the scope of impact involves the input validation module of a web application, and the exploitation condition is specific malicious input;

[0119] S403, call the network topology map in the Agent analysis report to extract vulnerability-related information;

[0120] The vulnerability-related information includes: information about the servers and network devices involved, and the target system for the vulnerability exploitation;

[0121] S404 invokes the task orchestration agent to break down the vulnerability verification task into multiple sub-tasks based on vulnerability-related information.

[0122] The sub-tasks include environment setup, vulnerability reproduction, PoC writing and execution, and result analysis.

[0123] S405, the environment building agent is invoked to build a verification environment containing the target web application and its dependencies in a Docker container;

[0124] It should be noted that this step requires the installation of a specific version of the operating system, web server, database, etc., to ensure that the environment is consistent with the description in the vulnerability report, in order to simulate a real production environment and ensure the authenticity and accuracy of the vulnerability reproduction.

[0125] S406, invoke the vulnerability verification agent to execute the vulnerable code according to the steps in the vulnerability report;

[0126] Understandably, executing vulnerable code attempts to trigger an RCE vulnerability, recording logs and results during the verification process;

[0127] S407, calls the POC to write the Agent to generate and execute the POC code that is vulnerable after the vulnerability is determined to exist;

[0128] Understandably, this step can further verify the exploitability of the vulnerability and ensure its actual existence and scope of impact.

[0129] It should be noted that during the verification process, the Search Agent can retrieve relevant technical documents, supplement the technical details of vulnerability exploitation, optimize the verification process, and improve the comprehensiveness and accuracy of the verification.

[0130] S408 calls the report writing agent to summarize the vulnerability verification process and results, and generates a vulnerability verification report that includes verification steps, result analysis and remediation suggestions;

[0131] The vulnerability verification report includes a vulnerability description, verification process, verification results, PoC code examples, and remediation suggestions to ensure the report's comprehensiveness and professionalism.

[0132] It is worth noting that during the vulnerability reproduction process, if the vulnerability verification agent fails to execute, the exception handling agent can automatically analyze the reasons for the failure through a large model, such as incorrect environment configuration or missing dependency libraries, adjust the environment configuration or reproduction steps, and re-execute the verification task to ensure the smooth progress of the process.

[0133] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0134] Based on the same inventive concept, this application also provides a vulnerability verification device for implementing the vulnerability verification method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more vulnerability verification device embodiments provided below can be found in the limitations of the vulnerability verification method described above, and will not be repeated here.

[0135] In one exemplary embodiment, such as Figure 5 As shown, a vulnerability verification device is provided, including: a request receiving module 510, an information extraction module 520, and a vulnerability verification module 530, wherein:

[0136] The request receiving module 510 is used to receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0137] The information extraction module 520 is used to extract vulnerability-related information from the vulnerability report and, based on the vulnerability-related information, determine at least one vulnerability verification agent required to respond to the vulnerability verification request.

[0138] The vulnerability verification module 530 is used to verify the vulnerability report based on vulnerability-related information by invoking at least one vulnerability verification agent.

[0139] In one embodiment, the vulnerability verification agent includes an existence verification agent and an impact scope verification agent; vulnerability-related information includes a vulnerability type description and vulnerability code logic; correspondingly, the vulnerability verification module 530 includes a first verification unit, used to determine the existence of the vulnerability in the vulnerability report by calling the existence verification agent to execute the vulnerability code logic; a first determination unit, used to determine a proof-of-concept (POC) based on the vulnerability type description and vulnerability code logic when a target vulnerability exists in the vulnerability report and the vulnerability type of the target vulnerability corresponds to the vulnerability type description; and a second verification unit, used to determine the vulnerability impact scope of the target vulnerability by calling the impact scope verification agent to execute the POC.

[0140] In one embodiment, the vulnerability verification agent further includes an information search agent; correspondingly, the second verification unit includes a search subunit for searching for verification reference information from publicly available information by invoking the information search agent; and a first determination subunit for executing a Proof of Concept (POC) by invoking the scope of impact verification agent to determine the scope of impact of the target vulnerability based on the verification reference information.

[0141] In one embodiment, the vulnerability-related information includes vulnerability environment description information, and the vulnerability verification agent also includes an environment building agent; correspondingly, the second verification unit includes an environment building subunit, which is used to build a verification environment corresponding to the target vulnerability by calling the environment building agent according to the vulnerability environment description information; and a second determination subunit, which is used to execute a POC in the verification environment by calling the impact scope verification agent to determine the vulnerability impact scope of the target vulnerability.

[0142] In one embodiment, the request receiving module 510 includes a selection unit, configured to select a target extraction agent from different information extraction agents according to the report content type of the vulnerability report; and an extraction unit, configured to extract the report content of the vulnerability report by calling the target extraction agent, so as to determine the vulnerability-related information in the vulnerability report.

[0143] In one embodiment, the vulnerability verification device includes a monitoring module, comprising a monitoring unit for monitoring the interruption of the vulnerability verification process corresponding to each vulnerability verification agent; and a calling unit for re-calling the target verification agent when an interruption is detected in the vulnerability verification process corresponding to the target verification agent.

[0144] In one embodiment, the vulnerability verification device includes a report storage module, comprising a report generation unit for generating a vulnerability verification report based on the vulnerability verification results corresponding to each vulnerability verification agent; a second determination unit for determining the report storage method corresponding to the vulnerability verification report based on the scope of vulnerability impact; and a storage unit for storing the vulnerability verification report according to the report storage method.

[0145] Each module in the aforementioned vulnerability verification device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0146] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 6As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a vulnerability verification method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0147] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0148] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0149] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0150] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0151] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0152] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0153] The existence of a vulnerability in a vulnerability report is determined by invoking an existence verification agent to execute the vulnerability code logic.

[0154] If a target vulnerability exists in the vulnerability report and the vulnerability type corresponds to the vulnerability type description, a proof-of-concept (POC) is determined based on the vulnerability type description and the vulnerability code logic.

[0155] The scope of impact of a target vulnerability is determined by executing a Proof of Concept (POC) through an impact scope verification agent.

[0156] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0157] By invoking an information search agent, verification reference information can be obtained from publicly available information;

[0158] By invoking the impact scope verification agent to execute the Proof of Concept (POC), the impact scope of the target vulnerability can be determined based on the verification reference information.

[0159] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0160] By calling the environment to build an intelligent agent, a verification environment corresponding to the target vulnerability is built according to the vulnerability environment description information;

[0161] By invoking the impact scope verification agent, a proof-of-concept (POC) is executed in the verification environment to determine the impact scope of the target vulnerability.

[0162] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0163] Based on the type of vulnerability report content, select a target extraction agent from different information extraction agents;

[0164] By invoking the target extraction agent, the content of the vulnerability report is extracted to determine the vulnerability-related information in the vulnerability report.

[0165] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0166] Monitor the interruption status of the vulnerability verification process for each vulnerability verification agent;

[0167] If an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the target verification agent is invoked again.

[0168] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0169] Based on the vulnerability verification results of each vulnerability verification agent, a vulnerability verification report is generated.

[0170] Determine the report storage method corresponding to the vulnerability verification report based on the scope of the vulnerability's impact;

[0171] Store vulnerability verification reports according to the report storage method.

[0172] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0173] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0174] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0175] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0176] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0177] The existence of a vulnerability in a vulnerability report is determined by invoking an existence verification agent to execute the vulnerability code logic.

[0178] If a target vulnerability exists in the vulnerability report and the vulnerability type corresponds to the vulnerability type description, a proof-of-concept (POC) is determined based on the vulnerability type description and the vulnerability code logic.

[0179] The scope of impact of a target vulnerability is determined by executing a Proof of Concept (POC) through an impact scope verification agent.

[0180] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0181] By invoking an information search agent, verification reference information can be obtained from publicly available information;

[0182] By invoking the impact scope verification agent to execute the Proof of Concept (POC), the impact scope of the target vulnerability can be determined based on the verification reference information.

[0183] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0184] By calling the environment to build an intelligent agent, a verification environment corresponding to the target vulnerability is built according to the vulnerability environment description information;

[0185] By invoking the impact scope verification agent, a proof-of-concept (POC) is executed in the verification environment to determine the impact scope of the target vulnerability.

[0186] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0187] Based on the type of vulnerability report content, select a target extraction agent from different information extraction agents;

[0188] By invoking the target extraction agent, the content of the vulnerability report is extracted to determine the vulnerability-related information in the vulnerability report.

[0189] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0190] Monitor the interruption status of the vulnerability verification process for each vulnerability verification agent;

[0191] If an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the target verification agent is invoked again.

[0192] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0193] Based on the vulnerability verification results of each vulnerability verification agent, a vulnerability verification report is generated.

[0194] Determine the report storage method corresponding to the vulnerability verification report based on the scope of the vulnerability's impact;

[0195] Store vulnerability verification reports according to the report storage method.

[0196] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0197] Receive vulnerability verification requests; the vulnerability verification request includes a vulnerability report.

[0198] Extract vulnerability-related information from the vulnerability report, and determine at least one vulnerability verification agent required to respond to the vulnerability verification request based on the vulnerability-related information;

[0199] By invoking at least one vulnerability verification agent, vulnerability reports are verified based on vulnerability-related information.

[0200] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0201] The existence of a vulnerability in a vulnerability report is determined by invoking an existence verification agent to execute the vulnerability code logic.

[0202] If a target vulnerability exists in the vulnerability report and the vulnerability type corresponds to the vulnerability type description, a proof-of-concept (POC) is determined based on the vulnerability type description and the vulnerability code logic.

[0203] The scope of impact of a target vulnerability is determined by executing a Proof of Concept (POC) through an impact scope verification agent.

[0204] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0205] By invoking an information search agent, verification reference information can be obtained from publicly available information;

[0206] By invoking the impact scope verification agent to execute the Proof of Concept (POC), the impact scope of the target vulnerability can be determined based on the verification reference information.

[0207] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0208] By calling the environment to build an intelligent agent, a verification environment corresponding to the target vulnerability is built according to the vulnerability environment description information;

[0209] By invoking the impact scope verification agent, a proof-of-concept (POC) is executed in the verification environment to determine the impact scope of the target vulnerability.

[0210] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0211] Based on the type of vulnerability report content, select a target extraction agent from different information extraction agents;

[0212] By invoking the target extraction agent, the content of the vulnerability report is extracted to determine the vulnerability-related information in the vulnerability report.

[0213] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0214] Monitor the interruption status of the vulnerability verification process for each vulnerability verification agent;

[0215] If an interruption is detected in the vulnerability verification process corresponding to the target verification agent, the target verification agent is invoked again.

[0216] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:

[0217] Based on the vulnerability verification results of each vulnerability verification agent, a vulnerability verification report is generated.

[0218] Determine the report storage method corresponding to the vulnerability verification report based on the scope of the vulnerability's impact;

[0219] Store vulnerability verification reports according to the report storage method.

[0220] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0221] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0222] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0223] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A vulnerability verification method characterized by, The method comprises: receiving a vulnerability verification request; the vulnerability verification request comprises a vulnerability report; extracting vulnerability-related information in the vulnerability report, and determining at least one vulnerability verification agent required for responding to the vulnerability verification request according to the vulnerability-related information; verifying the vulnerability report according to the vulnerability-related information by calling the at least one vulnerability verification agent.

2. The method of claim 1, wherein, The vulnerability verification agent comprises an existence verification agent and an influence range verification agent; the vulnerability-related information comprises vulnerability type description and vulnerability code logic; correspondingly, the vulnerability verification of the vulnerability report according to the vulnerability-related information by calling the at least one vulnerability verification agent comprises: determining vulnerability existence of the vulnerability report by calling the existence verification agent to execute the vulnerability code logic; in the case that a target vulnerability exists in the vulnerability report and the vulnerability type of the target vulnerability corresponds to the vulnerability type description, determining a proof of concept (POC) according to the vulnerability type description and the vulnerability code logic; determining a vulnerability influence range of the target vulnerability by calling the influence range verification agent to execute the POC.

3. The method of claim 2, wherein, The vulnerability verification agent further comprises an information search agent; correspondingly, the determination of the vulnerability influence range of the target vulnerability by calling the influence range verification agent to execute the POC comprises: searching for verification reference information from public information by calling the information search agent; determining the vulnerability influence range of the target vulnerability according to the verification reference information by calling the influence range verification agent to execute the POC.

4. The method of claim 2, wherein, The vulnerability-related information comprises vulnerability environment description information, and the vulnerability verification agent further comprises an environment building agent; correspondingly, the determination of the vulnerability influence range of the target vulnerability by calling the influence range verification agent to execute the POC comprises: building a verification environment corresponding to the target vulnerability according to the vulnerability environment description information by calling the environment building agent; determining the vulnerability influence range of the target vulnerability by calling the influence range verification agent to execute the POC in the verification environment.

5. The method according to any one of claims 1-4, characterized in that, The extraction of the vulnerability-related information in the vulnerability report comprises: selecting a target extraction agent from different information extraction agents according to a report content type of the vulnerability report; extracting report content of the vulnerability report by calling the target extraction agent to determine the vulnerability-related information in the vulnerability report.

6. The method according to any one of claims 1-4, characterized in that, The method further comprises: monitoring interruption of a vulnerability verification process corresponding to each vulnerability verification agent; re-calling a target verification agent in the case that the vulnerability verification process corresponding to the target verification agent is interrupted.

7. The method of claim 2, wherein, The method further comprises: generating a vulnerability verification report according to a vulnerability verification result corresponding to each vulnerability verification agent; determining a report storage mode corresponding to the vulnerability verification report according to the vulnerability influence range; storing the vulnerability verification report according to the report storage mode.

8. A vulnerability verification apparatus characterized by comprising: The device comprises: a request receiving module, configured to receive a vulnerability verification request, wherein the vulnerability verification request comprises a vulnerability report; an information extracting module, configured to extract vulnerability-related information in the vulnerability report, and determine at least one vulnerability verification intelligent agent required for responding to the vulnerability verification request according to the vulnerability-related information; a vulnerability verification module, configured to perform vulnerability verification on the vulnerability report according to the vulnerability-related information by calling the at least one vulnerability verification intelligent agent. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor implements the steps of the method of any one of claims 1-7 when executing the computer program.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the method of any one of claims 1-7.