Vulnerability fixing method and device for IT assets and storage medium

By using a dynamic risk assessment method based on attack graphs, the order of IT asset vulnerability remediation is determined, which solves the problem of low IT asset information security and achieves efficient and secure vulnerability remediation.

CN121792152APending Publication Date: 2026-04-03BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-19
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Current technologies have low information security for IT assets, and manual vulnerability repair is inefficient and difficult to fix in a timely manner, resulting in a high risk of information leakage.

Method used

Based on the pre-built attack graph, the shortest attack path and the importance of the target asset are determined, the dynamic risk level value is calculated, the priority of vulnerability remediation is sorted, and high-risk vulnerabilities are remediated in sequence.

Benefits of technology

It improved the information security of IT assets, reduced the impact of unpatched vulnerabilities on information security, and enhanced remediation efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792152A_ABST
    Figure CN121792152A_ABST
Patent Text Reader

Abstract

The invention discloses a bug fixing method and device for IT assets and a storage medium, and belongs to the technical field of network security. The vulnerability repairing method comprises the following steps: based on an attack graph, determining shortest attack step numbers corresponding to a plurality of shortest attack paths for attacking a plurality of vulnerability IT asset nodes from a preset IT asset node attack starting point, a target attack step weight corresponding to a target attack step, and a target asset importance degree value of a target IT asset node; according to the plurality of shortest attack step numbers, the plurality of target attack step weights and the plurality of target asset importance degree values, determining a dynamic risk degree value corresponding to a vulnerability in each vulnerability IT asset node; sorting the dynamic risk degree values corresponding to the vulnerabilities in the plurality of vulnerability IT asset nodes in a descending order to obtain a vulnerability repair sequence; and according to the vulnerability repairing sequence, repairing the vulnerabilities in the plurality of vulnerability IT asset nodes in sequence. The method and the device are used for improving information security of IT assets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and specifically to a vulnerability remediation method, device, and storage medium for IT assets. Background Technology

[0002] With the modernization of networks, enterprise intranets contain complex information technology assets (IT assets), such as servers, network devices, and applications. These IT assets often involve confidential information. To ensure the security monitoring and control of IT assets, current technology typically relies on manual vulnerability scanning tools to identify and patch vulnerabilities to avoid the risk of information leakage. However, faced with a massive number of vulnerabilities, manual patching is inefficient and difficult to perform in a timely manner, easily leading to some unpatched vulnerabilities impacting the information security of IT assets. Therefore, current technology suffers from a relatively low level of information security for IT assets. Summary of the Invention

[0003] The purpose of this application is to provide a method, device, storage medium, and program product for patching vulnerabilities in IT assets, in order to solve the problem of low information security of IT assets in the prior art.

[0004] To achieve the above objectives, the first aspect of this application provides a vulnerability remediation method for IT assets, the vulnerability remediation method comprising: Based on the pre-constructed attack graph, the shortest attack steps corresponding to multiple shortest attack paths from the preset attack starting point of the IT asset node to multiple vulnerable IT asset nodes are determined, the target attack step weights corresponding to the target attack steps involved in each shortest attack path, and the target asset importance values ​​of the target IT asset nodes corresponding to each target attack step. The attack graph includes multiple IT asset nodes, the asset importance values ​​corresponding to each IT asset node, the attack steps between multiple IT asset nodes, and the attack step weights corresponding to each attack step. The attack steps are used to characterize the asset connection relationships between multiple IT asset nodes. Based on multiple shortest attack steps, multiple target attack step weights, and multiple target asset importance values, determine the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node; The dynamic risk level values ​​corresponding to vulnerabilities in multiple vulnerable IT asset nodes are sorted in descending order to obtain the vulnerability remediation order for multiple vulnerable IT asset nodes. Based on the order of vulnerability remediation, vulnerabilities in multiple vulnerable IT asset nodes are remediated sequentially.

[0005] In this embodiment, the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node is determined based on multiple shortest attack steps, multiple target attack step weights, and multiple target asset importance values. This includes: determining the exploitability score corresponding to the vulnerability in each vulnerable IT asset node based on multiple shortest attack steps and multiple target attack step weights; determining the business impact score corresponding to the vulnerability in each vulnerable IT asset node based on multiple target asset importance values; and determining the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node based on the exploitability score and the corresponding business impact score.

[0006] In this embodiment of the application, the exploitability score corresponding to the vulnerability in each vulnerable IT asset node is determined based on multiple shortest attack steps and multiple target attack step weights. This includes determining the weighted sum between the reciprocal of the shortest attack step and the product of multiple target attack step weights to obtain the exploitability score corresponding to the vulnerability in each vulnerable IT asset node.

[0007] In this embodiment of the application, the attack graph also includes the dependency weights between IT asset nodes corresponding to each attack step. Based on multiple target asset importance values, the business impact score corresponding to the vulnerability in each vulnerable IT asset node is determined, including: obtaining the target dependency weights between target asset nodes corresponding to each target attack step; and determining the business impact score corresponding to the vulnerability in each vulnerable IT asset node based on multiple target asset importance values ​​and the corresponding target dependency weights.

[0008] In this embodiment, the target IT asset nodes include vulnerable IT asset nodes and non-vulnerable IT asset nodes. Based on multiple target asset importance values ​​and corresponding target dependency weights, the business impact score corresponding to the vulnerability in each vulnerable IT asset node is determined, including: determining the sum of the products of the target asset importance value and the corresponding target dependency weight for each non-vulnerable IT asset node to obtain the total target asset importance value for all non-vulnerable IT asset nodes; and determining the sum of the target asset importance value for each vulnerable IT asset node and the total target asset importance value to obtain the business impact score corresponding to the vulnerability in each vulnerable IT asset node.

[0009] In this embodiment, the dynamic risk level of each vulnerability in an IT asset node is determined based on its exploitability score and its corresponding business impact score. This includes: obtaining the vulnerability exploitation pattern of each vulnerability in the IT asset node; determining the threat coefficient of each vulnerability in the IT asset node based on its exploitation pattern; performing a weighted summation of the exploitability score and the corresponding business impact score of each vulnerability in the IT asset node to obtain the initial dynamic risk level of each vulnerability in the IT asset node; and determining the product of the initial dynamic risk level of each vulnerability in the IT asset node and the corresponding threat coefficient to obtain the dynamic risk level of each vulnerability in the IT asset node.

[0010] In this embodiment of the application, the asset connection relationship includes at least one of the following: network connection relationship, trust relationship, and service dependency relationship.

[0011] A second aspect of this application provides a vulnerability remediation device for IT assets, comprising: a memory configured to store instructions; and a processor configured to retrieve instructions from the memory and, when executing the instructions, to implement the vulnerability remediation method for IT assets as described above.

[0012] A third aspect of this application provides a machine-readable storage medium storing instructions that cause a machine to execute the vulnerability remediation method for IT assets described above.

[0013] The fourth aspect of this application provides a computer program product, including a computer program that, when executed by a processor, implements the vulnerability remediation method for IT assets described above.

[0014] The above technical solution, based on a pre-constructed attack graph, determines the shortest attack steps corresponding to multiple shortest attack paths from a preset IT asset node attack starting point to multiple vulnerable IT asset nodes, the target attack step weights corresponding to the target attack steps involved in each shortest attack path, and the target asset importance value of each target IT asset node corresponding to each target attack step. The attack graph includes multiple IT asset nodes, the asset importance value corresponding to each IT asset node, the attack steps between multiple IT asset nodes, and the attack step weights corresponding to each attack step. Attack steps are used to characterize the asset connection relationships between multiple IT asset nodes, thereby determining the shortest attack steps based on multiple shortest attack paths. By using short attack steps, multiple target attack step weights, and multiple target asset importance values, the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node is determined. Based on this, compared with existing technologies, the dynamic risk level values ​​corresponding to the vulnerabilities in multiple vulnerable IT asset nodes can be sorted in descending order to obtain the vulnerability remediation order for multiple vulnerable IT asset nodes. Furthermore, according to the vulnerability remediation order, the vulnerabilities in multiple vulnerable IT asset nodes are remediated sequentially, that is, vulnerabilities with higher dynamic risk level values ​​are remediated first, reducing the impact of unremediated vulnerabilities on the information security of IT assets and improving the information security of IT assets.

[0015] Other features and advantages of the embodiments of this application will be described in detail in the following detailed description section. Attached Figure Description

[0016] The accompanying drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the following detailed description to explain the embodiments of this application, but do not constitute a limitation on the embodiments of this application. In the drawings: Figure 1 The illustration shows a flowchart of a vulnerability remediation method for IT assets according to an embodiment of this application; Figure 2 The illustration shows a flowchart of another vulnerability remediation method for IT assets according to an embodiment of this application; Figure 3 The diagram illustrates a structural schematic of an attack graph according to an embodiment of this application. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0018] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with relevant laws and regulations. In the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0019] It should be noted that if the embodiments of this application involve directional indicators (such as up, down, left, right, front, back, etc.), the directional indicators are only used to explain the relative positional relationship and movement of each component in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicators will also change accordingly.

[0020] Furthermore, if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the technical solutions of various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0021] Figure 1 This illustration schematically depicts a flowchart of a vulnerability remediation method for IT assets according to an embodiment of this application. Figure 1 As shown in the illustration, this application provides a vulnerability remediation method for IT assets. Taking the application of this vulnerability remediation method to a processor as an example, the vulnerability remediation method may include the following steps: Step S101: Based on the pre-constructed attack graph, determine the shortest attack steps corresponding to the multiple shortest attack paths that attack multiple vulnerable IT asset nodes from the preset attack starting point of the IT asset node, the target attack step weights corresponding to the target attack steps involved in each shortest attack path, and the target asset importance value of each target IT asset node corresponding to each target attack step. The attack graph includes multiple IT asset nodes, the asset importance value corresponding to each IT asset node, the attack steps between multiple IT asset nodes, and the attack step weights corresponding to each attack step. The attack steps are used to characterize the asset connection relationship between multiple IT asset nodes.

[0022] Step S102: Determine the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node based on multiple shortest attack steps, multiple target attack step weights, and multiple target asset importance values.

[0023] Step S103: Sort the dynamic risk level values ​​corresponding to the vulnerabilities in multiple vulnerable IT asset nodes in descending order to obtain the vulnerability remediation order for multiple vulnerable IT asset nodes.

[0024] Step S104: According to the vulnerability remediation order, perform remediation operations on the vulnerabilities in multiple vulnerable IT asset nodes in sequence.

[0025] It can be understood that a pre-built attack graph is a visual graph composed of multiple asset nodes corresponding to multiple IT assets. The attack graph may include, but is not limited to, multiple IT asset nodes, the asset importance value corresponding to each IT asset node, attack steps between multiple IT asset nodes, and the attack step weight corresponding to each attack step. The preset IT asset node attack starting point is a pre-set IT asset node as the attack starting point for a vulnerability; for example, setting a firewall IT asset node as the attack starting point for a vulnerability. The vulnerable IT asset node is the IT asset node where the vulnerability resides. The shortest attack path is the shortest attack path from the preset IT asset node attack starting point to the vulnerable IT asset node. The shortest attack step count is the number of attack steps in the shortest attack path corresponding to each vulnerability. The target attack step is the attack step in the shortest attack path. Attack steps are used to represent the asset connection relationship between multiple IT asset nodes; the asset connection relationship is the association relationship between each IT asset. The target attack step weight is the preset weight corresponding to each attack step. The attack step weight is the preset weight corresponding to the attack step in the attack graph. The target IT asset node is the IT asset node in the attack graph that is associated with the target attack step. Target IT asset nodes include vulnerable IT asset nodes. The target asset importance value characterizes the importance of the target IT asset node in supporting business operations. The asset importance value is the asset importance value corresponding to each IT asset node in the attack graph. The dynamic risk value characterizes the level of security risk faced by the IT asset due to the existence of vulnerabilities in each vulnerable IT asset node. The vulnerability remediation order is the order in which multiple vulnerabilities are remediated based on the dynamic risk value. The remediation work consists of the relevant tasks for remediating vulnerabilities in each vulnerable IT asset node.

[0026] Specifically, since the pre-constructed attack graph includes, but is not limited to, multiple IT asset nodes, the asset importance value corresponding to each IT asset node, the attack steps between multiple IT asset nodes, and the attack step weight corresponding to each attack step, the processor can determine multiple shortest attack paths obtained by attacking multiple vulnerable IT asset nodes from a preset attack starting point on the pre-constructed attack graph. It can also determine the number of shortest attack steps corresponding to each shortest attack path, the target attack step weight corresponding to each target attack step involved in each shortest attack path, and the target asset importance value of the target IT asset node corresponding to each target attack step. Thus, the processor can determine the shortest attack steps and target attack steps based on the pre-constructed attack graph. The processor uses weights and importance values ​​of multiple target assets to determine the dynamic risk level of vulnerabilities in each vulnerable IT asset node. This determines the impact of vulnerabilities in each vulnerable IT asset node on the security of IT asset nodes in the attack graph. A higher dynamic risk level indicates a greater impact on IT asset security. To reduce the impact of vulnerabilities in each vulnerable IT asset node on the security of IT asset nodes in the attack graph, the processor can sort the dynamic risk level values ​​of vulnerabilities in multiple vulnerable IT asset nodes in descending order to obtain the vulnerability remediation order for multiple vulnerable IT asset nodes. Based on the vulnerability remediation order, the processor performs remediation operations on the vulnerabilities in multiple vulnerable IT asset nodes sequentially.

[0027] The above technical solution, based on a pre-constructed attack graph, determines the shortest attack steps corresponding to multiple shortest attack paths from a preset IT asset node attack starting point to multiple vulnerable IT asset nodes, the target attack step weights corresponding to the target attack steps involved in each shortest attack path, and the target asset importance value of each target IT asset node corresponding to each target attack step. The attack graph includes multiple IT asset nodes, the asset importance value corresponding to each IT asset node, the attack steps between multiple IT asset nodes, and the attack step weights corresponding to each attack step. Attack steps are used to characterize the asset connection relationships between multiple IT asset nodes, thereby determining the shortest attack steps based on multiple shortest attack paths. By using short attack steps, multiple target attack step weights, and multiple target asset importance values, the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node is determined. Based on this, compared with existing technologies, the dynamic risk level values ​​corresponding to the vulnerabilities in multiple vulnerable IT asset nodes can be sorted in descending order to obtain the vulnerability remediation order for multiple vulnerable IT asset nodes. Furthermore, according to the vulnerability remediation order, the vulnerabilities in multiple vulnerable IT asset nodes are remediated sequentially, that is, vulnerabilities with higher dynamic risk level values ​​are remediated first, reducing the impact of unremediated vulnerabilities on the information security of IT assets and improving the information security of IT assets.

[0028] In this embodiment, determining the dynamic risk level of a vulnerability in each vulnerable IT asset node based on multiple shortest attack steps, multiple target attack step weights, and multiple target asset importance values ​​may include: determining the exploitability score of a vulnerability in each vulnerable IT asset node based on multiple shortest attack steps and multiple target attack step weights; determining the business impact score of a vulnerability in each vulnerable IT asset node based on multiple target asset importance values; and determining the dynamic risk level of a vulnerability in each vulnerable IT asset node based on the exploitability score and the corresponding business impact score.

[0029] As can be understood, the exploitability score characterizes the ease with which an attacker can access and exploit vulnerabilities in each vulnerable IT asset node. The higher the exploitability score, the easier it is for an attacker to access and exploit the vulnerability. The business impact score is a quantitative measure of the negative impact an attacker has on the business supported by the IT asset.

[0030] Specifically, the processor can determine the exploitability score for each vulnerability in each vulnerable IT asset node based on the shortest attack path involving the shortest attack steps and the target attack step weight. In this case, the smaller the shortest attack steps and the higher the target attack step weight, the larger the exploitability score, indicating that the vulnerability in the vulnerable IT asset node is more easily accessed and exploited by attackers. The processor can also determine the business impact score for each vulnerability in each vulnerable IT asset node based on the target asset importance values ​​of each target IT asset involved in the shortest attack path. In this case, the larger the importance value of the target IT asset node, the larger the business impact score, indicating that the vulnerability has a greater impact on the business supported by the IT asset. Furthermore, the processor can also determine the dynamic risk level of vulnerabilities in each vulnerable IT asset node based on the exploitability score and the corresponding business impact score of the vulnerability in each vulnerable IT asset node. In this case, the higher the exploitability score and the higher the business impact score, the higher the dynamic risk level of the vulnerability in each vulnerable IT asset node, indicating the existence of the vulnerability and making the target IT asset node face greater risks.

[0031] The processor combines the availability score obtained by the shortest attack steps and the target attack step weight, and the business impact score obtained by the importance scores of multiple target assets, to determine the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node. This can avoid the one-sidedness of a single-dimensional assessment and make the dynamic risk level value more in line with the actual attack scenario.

[0032] In this embodiment of the application, determining the exploitability score corresponding to the vulnerability in each vulnerable IT asset node based on multiple shortest attack steps and multiple target attack step weights may include: determining the weighted sum between the reciprocal of the shortest attack steps and the product of multiple target attack step weights to obtain the exploitability score corresponding to the vulnerability in each vulnerable IT asset node.

[0033] Specifically, the processor can pre-determine the reciprocal of the shortest attack steps and the product of the weights of multiple target attack steps. The processor can also pre-obtain the weight coefficients corresponding to the products of the reciprocal of the shortest attack steps and the weights of multiple target attack steps. Based on this, the processor determines the sum of the products of the reciprocal of the shortest attack steps and the weights of multiple target attack steps with their corresponding weight coefficients. In other words, the processor determines the weighted sum of the products of the reciprocal of the shortest attack steps and the weights of multiple target attack steps, and can obtain the exploitability score for each vulnerability in each vulnerable IT asset node. Alternatively, the processor can determine the product of the reciprocal of the shortest attack steps and the weights of multiple target attack steps to obtain the exploitability score for each vulnerability in each vulnerable IT asset node. In this way, the processor quantifies the exploitability of vulnerabilities in each vulnerable IT asset node, more closely reflecting actual attack difficulty, improving the accuracy of the exploitability score, and making it more adaptable to attack scenarios.

[0034] In this embodiment of the application, the attack graph also includes the dependency weights between IT asset nodes corresponding to each attack step. Based on multiple target asset importance values, the business impact score value corresponding to the vulnerability in each vulnerable IT asset node is determined. This may include: obtaining the target dependency weights between target asset nodes corresponding to each target attack step; and determining the business impact score value corresponding to the vulnerability in each vulnerable IT asset node based on multiple target asset importance values ​​and the corresponding target dependency weights.

[0035] It is understandable that the attack graph can also include the dependency weights between IT asset nodes corresponding to each attack step. The dependency weight is a quantitative indicator of the dependency relationship between the current IT asset node and the next IT asset node. The target dependency weight is the dependency weight between target asset nodes.

[0036] Specifically, the processor can pre-obtain the target dependency weights between target asset nodes corresponding to each target attack step, that is, obtain the target dependency weights between each target IT asset node on each shortest attack path and the next target IT asset node. Thus, the processor can determine the business impact score corresponding to the vulnerability in each vulnerable IT asset node based on the target asset importance value and the corresponding target dependency weight. By introducing target dependency weights, the processor converts the association between two target IT asset nodes corresponding to a target attack step into a calculable target dependency weight. Combined with the target asset importance value corresponding to each target IT asset node, this reflects both the business value of an individual target IT asset node and the strength of the dependency relationships between target IT asset nodes. This allows the business impact score to more accurately match the associated risks between target IT assets, improving the alignment of the business impact score with actual business risks.

[0037] In this embodiment, the target IT asset nodes include vulnerable IT asset nodes and non-vulnerable IT asset nodes. Based on multiple target asset importance values ​​and corresponding target dependency weights, the business impact score corresponding to the vulnerability in each vulnerable IT asset node is determined, including: determining the sum of the products of the target asset importance value and the corresponding target dependency weight for each non-vulnerable IT asset node to obtain the total target asset importance value for all non-vulnerable IT asset nodes; and determining the sum of the target asset importance value for each vulnerable IT asset node and the total target asset importance value to obtain the business impact score corresponding to the vulnerability in each vulnerable IT asset node.

[0038] It is understood that target IT asset nodes can include vulnerable IT asset nodes and non-vulnerable IT asset nodes. Non-vulnerable IT asset nodes are the remaining asset nodes along the shortest attack path corresponding to the vulnerable IT asset node, excluding the vulnerable IT asset node itself. The total target asset importance value is the target asset importance value corresponding to all non-vulnerable IT asset nodes.

[0039] Specifically, the processor can determine the sum of the products of the target asset importance value and the corresponding target dependency weight for each non-vulnerable IT asset node, to obtain the total target asset importance value for all non-vulnerable IT asset nodes. Further, the processor can determine the sum of the target asset importance values ​​for each vulnerable IT asset node on the shortest attack path and the total target asset importance values ​​for all non-vulnerable IT asset nodes, i.e., the business impact score for the vulnerability in each vulnerable IT asset node. The higher the target asset importance value and the corresponding target dependency weight for both non-vulnerable IT asset nodes and vulnerable IT asset nodes, the higher the business impact score. By combining the target asset importance values ​​of all IT asset nodes on the shortest attack path corresponding to vulnerable IT asset nodes, the processor can more accurately reflect the actual threat level of vulnerabilities on vulnerable IT asset nodes to the business, identify vulnerabilities with high threat levels, and prioritize subsequent remediation.

[0040] In this embodiment, the dynamic risk level of each vulnerability in an IT asset node is determined based on its exploitability score and its corresponding business impact score. This includes: obtaining the vulnerability exploitation pattern of each vulnerability in the IT asset node; determining the threat coefficient of each vulnerability in the IT asset node based on its exploitation pattern; performing a weighted summation of the exploitability score and the corresponding business impact score of each vulnerability in the IT asset node to obtain the initial dynamic risk level of each vulnerability in the IT asset node; and determining the product of the initial dynamic risk level of each vulnerability in the IT asset node and the corresponding threat coefficient to obtain the dynamic risk level of each vulnerability in the IT asset node.

[0041] It can be understood that vulnerability exploitation forms refer to the different states and implementation methods of exploiting vulnerabilities in various vulnerable IT asset nodes. Vulnerability exploitation forms can include field exploitation, exploit code, and theoretical exploitation. Field exploitation represents the practical propagation state of vulnerability exploitation, a form of exploitation with actual harmful cases. Exploit code is the technical implementation carrier of vulnerability exploitation, serving as a bridge between theoretical and field exploitation. Theoretical exploitation represents the conceptualization and demonstration state of vulnerability exploitation, derived solely from the vulnerability principle, without actual verification, and without corresponding executable code. The threat coefficient is a quantitative indicator of the degree of threat posed by vulnerabilities in various vulnerable IT asset nodes to the information security of IT assets.

[0042] Specifically, the processor can pre-obtain the exploitation patterns corresponding to vulnerabilities in each vulnerable IT asset node, thereby determining the threat level of the vulnerabilities to the information security of the IT assets. In other words, the processor can determine the threat coefficient corresponding to the vulnerabilities in each vulnerable IT asset node based on the exploitation patterns. Based on this, the processor can perform a weighted summation of the exploitability score and the corresponding business impact score corresponding to the vulnerabilities in each vulnerable IT asset node to obtain the initial dynamic risk level value for each vulnerability. Furthermore, the processor determines the product of the initial dynamic risk level value and the corresponding threat coefficient, thus obtaining the dynamic risk level value for each vulnerability in the IT asset node. In other words, by introducing the exploitation patterns corresponding to vulnerabilities in each vulnerable IT asset node and determining the threat coefficient, the processor further refines the quantitative dimensions of the dynamic risk level value, allowing risk assessment to more accurately match the actual threat status of the vulnerabilities and improving the quantitative accuracy of vulnerability risk.

[0043] In this embodiment of the application, the asset connection relationship includes at least one of the following: network connection relationship, trust relationship, and service dependency relationship.

[0044] It can be understood that asset connectivity relationships include at least one of network connectivity relationships, trust relationships, and service dependencies. Network connectivity relationships are the physical or logical connections between IT assets based on network topology, communication links, and port protocols. Trust relationships are the trusted access associations established between IT assets based on identity authentication, permission configuration, and security policies. Service dependencies are the dependencies between IT assets based on business functions, service calls, and data interactions.

[0045] A specific embodiment of this application also provides a method for remediating vulnerabilities in IT assets, such as... Figure 2 As shown, the vulnerability remediation method may include: The processor can use cross-platform data collection tools and related network scanning technologies to identify IT assets (hardware, software, cloud resources) in the network and collect their asset attributes. Asset attributes may include, but are not limited to, IP address, operating system, open ports, installed software, services, business unit to which they belong, and asset importance level (e.g., core, important, general). The processor can also use vulnerability scanning tools to identify vulnerability information corresponding to vulnerabilities related to IT assets. This vulnerability information may include, but is not limited to, CVE number, CVSS baseline score, vulnerability type, and attack conditions.

[0046] Based on this, the processor can construct an asset relationship graph based on IT assets (entities) and their interconnections. These interconnections can include, but are not limited to, network connections, trust relationships (such as domain trust), and service dependencies. Vulnerabilities are then appended as attributes to the IT asset nodes containing those vulnerabilities. The processor can also integrate external attack chain knowledge bases (such as MITRE ATT&CK, CAPEC) to establish vulnerability exploitation rules. For example, if asset A has CVE-2023-1234 (allowing remote code execution), and asset A and asset B are on the same network segment, an attacker could exploit this vulnerability to compromise asset A from the outside and use it as a springboard to move laterally to asset B. Thus, the processor can pre-construct an attack graph. The attack edges on this graph represent the access privileges or network movement paths that might result from exploiting the vulnerability.

[0047] The processor identified a web server (IP: 10.0.1.10, Business Importance: Important) with an Apache Log4j2 vulnerability (CVE-2021-44228) and CVSS 10.0. It also discovered an internal database server (IP: 10.0.2.20, storing user data, Asset Importance Level: Core) with a weak password for its MySQL service. The knowledge graph construction module uses these two servers as nodes. The processor determined that the web server and database server are network reachable, and that the application on the web server needs to access the database. Based on the ATT&CK knowledge base, the module added a rule: exploiting the Log4j2 vulnerability (T1190) allows code execution on the web server (TA0002), potentially leading to a connection to the database server (TA0008) using a weak password (T1110). Asset importance levels include Core, Important, and General, with different target asset importance values ​​corresponding to different asset importance levels; for example, Core = 5, Important = 3, General = 1.

[0048] For the Log4j2 vulnerability in the web server, based on the attack graph and Dijkstra's shortest path algorithm, the shortest attack path from the preset attack starting point on the IT asset node to the IT asset node where the web server is located can be determined. The shortest attack path is defined as having 1 attack step, a path weight (i.e., target attack step weight) PathWeight of 0.52, and the target asset importance value for each target IT asset node. Target IT asset nodes include the vulnerable IT asset node and downstream IT asset nodes (i.e., non-vulnerable asset nodes). The vulnerable IT asset node has a core asset importance level; therefore, its corresponding target asset importance value is 5 (i.e.,...). The downstream IT asset node also has a core asset importance level, with a corresponding target asset importance value of 5 (i.e., Furthermore, the target dependency weight between the vulnerable IT asset node and the downstream IT asset node is 0.4. Based on this, the processor can determine the weighted sum between the reciprocal of the shortest attack steps and the product of the weights of multiple target attack steps to obtain the exploitability score corresponding to the vulnerability in the vulnerable IT asset node. The processor can determine the exploitability score corresponding to the vulnerability in the vulnerable IT asset node according to the following formula:

[0049] in, This refers to the exploitability score corresponding to the vulnerability in the vulnerable IT asset node. To minimize attack steps, The target attack step weight.

[0050] Thus, the processor can determine that the exploitability score corresponding to the vulnerability in the vulnerable IT asset node is 8.08.

[0051] The processor can also determine the sum of the products of the target asset importance value and the corresponding target dependency weight for each non-vulnerable IT asset node to obtain the total target asset importance value for all non-vulnerable IT asset nodes; and determine the sum of the target asset importance value for each vulnerable IT asset node and the total target asset importance value to obtain the business impact score for the vulnerability in each vulnerable IT asset node. The processor can also determine the business impact score for the vulnerability in each vulnerable IT asset node according to the following formula:

[0052] in, The business impact score for each vulnerability in each vulnerable IT asset node. This represents the importance value of the target asset corresponding to the vulnerable IT asset node. This represents the importance value of the target asset corresponding to the non-vulnerable IT asset node. The target dependency weights are those corresponding to non-vulnerable IT asset nodes.

[0053] Based on this, the processor can determine that the business impact score corresponding to the vulnerability in each vulnerable IT asset node is 7.

[0054] Because different exploitation methods pose different threats to IT asset security, different exploitation methods correspond to different threat coefficients: a threat coefficient of 1.2 for in-the-wild exploitation, 1.0 for exploit code, and 0.8 for theoretical exploitation. The processor can also identify weak password vulnerabilities as theoretical exploits, in which case the corresponding threat intelligence coefficient (i.e., threat coefficient) T = 0.8. The exploitability score and business impact score of each vulnerability in each vulnerable IT asset node are weighted and summed to obtain the initial dynamic risk level value of the vulnerability in each vulnerable IT asset node. The product of the initial dynamic risk level value and the corresponding threat coefficient is then determined to obtain the dynamic risk level value of the vulnerability in each vulnerable IT asset node. The processor can also determine the dynamic risk level value of the vulnerability in each vulnerable IT asset node using the following formula:

[0055] in, This represents the dynamic risk level value corresponding to the vulnerabilities in each vulnerable IT asset node. This refers to the exploitability score corresponding to the vulnerability in the vulnerable IT asset node. The business impact score for each vulnerability in each vulnerable IT asset node. Threat level.

[0056] Therefore, the processor can determine that the dynamic risk level of the vulnerability in the IT asset node is 60.75.

[0057] Based on the above scheme, the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node can be determined. These dynamic risk level values ​​are then sorted in descending order to obtain the vulnerability remediation order (i.e., a priority remediation list) for multiple vulnerable IT asset nodes. The Log4j2 vulnerability is then ranked according to its DRS score. Based on this remediation order, the vulnerabilities in the multiple vulnerable IT asset nodes are remediated sequentially, effectively cutting off the attack chain (while simultaneously protecting the web server itself and preventing attackers from entering the internal network).

[0058] Furthermore, in one specific embodiment, the attack graph can be as follows: Figure 3As shown, the database server and web server are IT asset nodes in the network identified by the asset discovery and inventory module. The nodes where the database server and web server reside are IT asset nodes. CVE-A and CVE-B are vulnerability information related to assets obtained through the vulnerability scanning and data acquisition module; the nodes where CVE-A and CVE-B reside are the IT asset nodes where the vulnerabilities are located. Based on this, the knowledge graph construction module integrates an external attack chain knowledge base, establishes vulnerability exploitation relationship rules, and constructs a unified graph in conjunction with asset relationships: an attacker can first exploit the CVE-A vulnerability to gain access to the database server via SQL injection, then exploit the CVE-B vulnerability to obtain weak password information for the web server, and finally successfully lateral move to the web server to perform operations using the weak password.

[0059] The technical effect achieved by the technical solution of this application embodiment is that by determining the dynamic risk level value corresponding to the vulnerability in each vulnerable IT asset node, the accuracy of the priority judgment of vulnerability repair can be improved. Moreover, the dynamic risk level value can be automatically adjusted with the dynamic changes of network topology, asset status and repair actions. It can also show the overall risk that can be mitigated by repairing the vulnerability based on the attack graph, which greatly enhances the effectiveness of security decision-making, enables the processor to concentrate resources to repair "fatal" vulnerabilities, and significantly improves security operation efficiency.

[0060] This application also provides a vulnerability remediation device for IT assets, including: a memory configured to store instructions; and a processor configured to retrieve instructions from the memory and, when executing the instructions, to implement the vulnerability remediation method for IT assets as described above.

[0061] This application also provides a machine-readable storage medium storing instructions that cause a machine to execute the vulnerability remediation method for IT assets described above.

[0062] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described vulnerability remediation method for IT assets.

[0063] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0064] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0065] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0066] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0067] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0068] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, like read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0069] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0070] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0071] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for remediating vulnerabilities in IT assets, characterized in that, The vulnerability remediation method includes: Based on a pre-constructed attack graph, the shortest attack steps corresponding to multiple shortest attack paths that attack multiple vulnerable IT asset nodes from a preset attack starting point are determined, the target attack step weights corresponding to the target attack steps involved in each shortest attack path, and the target asset importance values ​​of the target IT asset nodes corresponding to each target attack step. The attack graph includes multiple IT asset nodes, asset importance values ​​corresponding to each IT asset node, attack steps between the multiple IT asset nodes, and attack step weights corresponding to each attack step. The attack steps are used to characterize the asset connection relationships between the multiple IT asset nodes. Based on the multiple shortest attack steps, the multiple target attack step weights, and the multiple target asset importance values, determine the dynamic risk level value corresponding to the vulnerability in each of the vulnerability IT asset nodes; The dynamic risk level values ​​corresponding to the vulnerabilities in the multiple vulnerable IT asset nodes are sorted in descending order to obtain the vulnerability remediation order for the multiple vulnerable IT asset nodes; According to the described vulnerability remediation order, the vulnerabilities in multiple vulnerable IT asset nodes are remediated sequentially.

2. The method according to claim 1, characterized in that, The step of determining the dynamic risk level value corresponding to the vulnerability in each of the vulnerable IT asset nodes based on multiple shortest attack steps, multiple target attack step weights, and multiple target asset importance values ​​includes: Based on the multiple shortest attack steps and the multiple target attack step weights, determine the exploitability score corresponding to the vulnerability in each of the vulnerability IT asset nodes; Based on the multiple importance values ​​of the target assets, determine the business impact score corresponding to the vulnerability in each of the vulnerability IT asset nodes; Based on the availability score and business impact score of the vulnerability in each of the aforementioned vulnerable IT asset nodes, the dynamic risk level value corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes is determined.

3. The method according to claim 2, characterized in that, The step of determining the exploitability score corresponding to the vulnerability in each of the vulnerable IT asset nodes based on multiple shortest attack steps and multiple target attack step weights includes: The weighted sum between the reciprocal of the shortest attack steps and the product of the weights of the multiple target attack steps is determined to obtain the exploitability score corresponding to the vulnerability in each of the vulnerability IT asset nodes.

4. The method according to claim 2, characterized in that, The attack graph also includes dependency weights between IT asset nodes corresponding to each attack step. The step of determining the business impact score corresponding to the vulnerability in each vulnerable IT asset node based on multiple target asset importance values ​​includes: Obtain the target dependency weights between the target asset nodes corresponding to each of the target attack steps; Based on the importance values ​​of multiple target assets and the corresponding target dependency weights, the business impact score of the vulnerability in each vulnerability IT asset node is determined.

5. The method according to claim 4, characterized in that, The target IT asset nodes include the vulnerable IT asset nodes and non-vulnerable IT asset nodes. The business impact score value corresponding to the vulnerability in each vulnerable IT asset node is determined based on multiple target asset importance values ​​and the corresponding target dependency weights, including: The sum of the products of the target asset importance value and the corresponding target dependency weight for each non-vulnerable IT asset node is determined to obtain the total target asset importance value for all non-vulnerable IT asset nodes. The sum of the importance value of the target asset corresponding to each vulnerable IT asset node and the total importance value of the target asset is determined to obtain the business impact score of the vulnerability in each vulnerable IT asset node.

6. The method according to claim 2, characterized in that, The step of determining the dynamic risk level value corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes based on the exploitability score and the corresponding business impact score of the vulnerability in each vulnerable IT asset node includes: Obtain the vulnerability exploitation patterns corresponding to the vulnerabilities in each of the aforementioned vulnerable IT asset nodes; Based on the vulnerability exploitation patterns corresponding to the vulnerabilities in each of the aforementioned vulnerable IT asset nodes, the threat coefficient corresponding to the vulnerabilities in each of the aforementioned vulnerable IT asset nodes is determined. The exploitability score and the business impact score corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes are weighted and summed to obtain the initial dynamic risk level value corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes. The product of the initial dynamic risk level value corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes and the corresponding threat coefficient is determined to obtain the dynamic risk level value corresponding to the vulnerability in each of the aforementioned vulnerable IT asset nodes.

7. The method according to claim 1, characterized in that, The asset connectivity relationship includes at least one of network connectivity, trust relationship and service dependency relationship.

8. A vulnerability remediation device for IT assets, characterized in that, include: The memory is configured to store instructions; as well as A processor is configured to retrieve the instructions from the memory and, when executing the instructions, to implement the vulnerability remediation method for IT assets according to any one of claims 1 to 7.

9. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores instructions for causing the machine to perform a vulnerability remediation method for IT assets according to any one of claims 1 to 7.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the vulnerability remediation method for IT assets according to any one of claims 1 to 7.