Resource allocation method and device for public test task, equipment, storage medium and program product
By using a multi-dimensional evaluation model and dynamic adjustment factors, the problem of inaccurate resource allocation for crowdsourcing tasks under the traditional static model is solved, achieving precise resource allocation and improving the accuracy of resource allocation for crowdsourcing tasks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
- Filing Date
- 2026-01-13
- Publication Date
- 2026-04-28
AI Technical Summary
Traditional crowdsourcing task resource allocation relies on static models, leading to inaccurate resource allocation results.
A multi-dimensional evaluation model is adopted, which calculates multi-dimensional evaluation results, target skill tags and vulnerability categories through a preset indicator scoring model. Combined with market supply and demand coefficients and risk penalty factors, dynamic adjustment factors are used to accurately allocate resources.
This improved the accuracy of resource allocation for crowdsourcing testing tasks, avoided situations where incentives were excessive or insufficient, and achieved effective resource allocation.
Smart Images

Figure CN121937152A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a resource allocation method, apparatus, device, storage medium, and program product for crowdsourcing tasks. Background Technology
[0002] Crowdsourced security testing, as an effective model for discovering software vulnerabilities using collective wisdom, incentivizes external security researchers (white hats) to conduct simulated attacks and security tests on specific systems through bounties. It has become a crucial component of enterprises building proactive defense systems. The design of the incentive mechanism and subsequent resource allocation directly determine the activity level and the depth of vulnerability discovery within the crowdsourced testing ecosystem.
[0003] Traditional crowdsourcing testing task resource allocation mainly relies on static models, that is, setting a fixed reward range based on a common vulnerability scoring system (such as CVSS, short for Common Vulnerability Scoring System) or a predefined risk level, and allocating resources for crowdsourcing testing tasks based on the eligible reward.
[0004] However, the resource allocation results for the aforementioned crowdsourcing tasks are inaccurate. Summary of the Invention
[0005] Therefore, it is necessary to provide a method, apparatus, device, storage medium, and program product for allocating resources for crowdsourcing tasks that can improve the accuracy of resource allocation results in crowdsourcing tasks, in order to address the aforementioned technical problems.
[0006] Firstly, this application provides a resource allocation method for crowdsourcing testing tasks, including:
[0007] Obtain the crowd-testing task to be tested, which includes task description data;
[0008] The task description data is input into a preset index scoring model for processing, and the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task are calculated.
[0009] Dynamic adjustment factors are determined based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0010] Based on the multi-dimensional evaluation results and the dynamic adjustment factor, corresponding resources are allocated to the crowdsourcing task to be tested.
[0011] In one embodiment, the preset indicator scoring model includes an analysis sub-model and a preset scoring sub-model. The task description data is input into the preset indicator scoring model for processing to calculate the multi-dimensional evaluation results, target skill tags, and vulnerability categories of the task to be tested, including:
[0012] The task description data is input into the preset scoring sub-model for semantic parsing to obtain multiple keywords; the multiple keywords include keywords representing the vulnerability category;
[0013] The analysis sub-model is used to retrieve the business process, historical vulnerability cases, scoring rules and target skill tags of each keyword from the preset knowledge graph, and to perform combined analysis on the business process, historical vulnerability cases and scoring rules of each keyword to generate a scoring basis data package;
[0014] The scoring data package is input into the preset scoring sub-model for multi-dimensional evaluation to obtain the multi-dimensional evaluation results of the crowdsourcing task to be tested.
[0015] In one embodiment, the multi-dimensional assessment result includes a potential risk score, and the step of determining a dynamic adjustment factor based on the multi-dimensional assessment result, the target skill tag, and the vulnerability category includes:
[0016] Based on the knowledge graph, determine the current supply and demand data for the target skill tag;
[0017] Determine whether a remediation report should be submitted for the vulnerability category, determine the contribution factor of the target skill tag based on the determination result, and construct the market supply and demand coefficient based on the supply and demand data and the contribution factor of the target skill tag;
[0018] The risk penalty factor is constructed based on the preset environmental sensitivity and the potential risk score.
[0019] In one embodiment, the supply and demand data includes demand and supply, and determining the current supply and demand data for the target skill tag based on the knowledge graph includes:
[0020] Based on the knowledge graph, the number of crowdsourcing tasks associated with the target skill tag is determined as the demand.
[0021] Identify objects that are active within a preset period, filter the objects based on the target skill tags to obtain the number of target objects, and use the number of target objects as the supply.
[0022] In one embodiment, determining the contribution factor of the target skill tag based on the judgment result includes:
[0023] If the vulnerability category is submitting a remediation report, then the contribution factor of the target skill tag is determined based on the quality score of the remediation report;
[0024] If the vulnerability category is "no remediation report submitted", then the contribution factor of the target skill tag will be set to a preset contribution threshold.
[0025] In one embodiment, determining the resource allocation result of the crowdsourcing task to be tested based on the multi-dimensional evaluation results and the dynamic adjustment factor includes:
[0026] The multi-dimensional evaluation results are subjected to nonlinear calculations to obtain the basic excitation values;
[0027] The basic incentive value is adjusted by the market supply and demand coefficient to obtain the adjusted basic incentive value.
[0028] The resource allocation result of the crowdsourcing task to be tested is obtained by adjusting the adjusted base incentive value through a risk penalty factor.
[0029] Based on the resource allocation results of the crowdsourcing task to be tested, allocate corresponding resources to the crowdsourcing task to be tested.
[0030] Secondly, this application also provides a resource allocation device for crowdsourcing tasks, comprising:
[0031] The acquisition module is used to acquire the crowd-testing task to be tested, which includes task description data.
[0032] The processing module is used to input the task description data into a preset index scoring model for processing, and calculate the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task to be tested;
[0033] The determination module is used to determine dynamic adjustment factors based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0034] An adjustment module is used to determine the resource allocation result of the crowdsourcing task to be tested based on the multi-dimensional evaluation results and the dynamic adjustment factor.
[0035] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0036] Obtain the crowd-testing task to be tested, which includes task description data;
[0037] The task description data is input into a preset index scoring model for processing, and the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task are calculated.
[0038] Dynamic adjustment factors are determined based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0039] Based on the multi-dimensional evaluation results and the dynamic adjustment factor, corresponding resources are allocated to the crowdsourcing task to be tested.
[0040] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0041] Obtain the crowd-testing task to be tested, which includes task description data;
[0042] The task description data is input into a preset index scoring model for processing, and the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task are calculated.
[0043] Dynamic adjustment factors are determined based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0044] Based on the multi-dimensional evaluation results and the dynamic adjustment factor, corresponding resources are allocated to the crowdsourcing task to be tested.
[0045] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0046] Obtain the crowd-testing task to be tested, which includes task description data;
[0047] The task description data is input into a preset index scoring model for processing, and the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task are calculated.
[0048] Dynamic adjustment factors are determined based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0049] Based on the multi-dimensional evaluation results and the dynamic adjustment factor, corresponding resources are allocated to the crowdsourcing task to be tested.
[0050] The aforementioned resource allocation method, apparatus, equipment, storage medium, and program products for crowdsourcing testing tasks involve acquiring the crowdsourcing task to be tested, inputting the task description data into a preset indicator scoring model for processing, calculating the multi-dimensional evaluation results, target skill tags, and vulnerability categories of the crowdsourcing task to be tested, determining a dynamic adjustment factor based on the multi-dimensional evaluation results, target skill tags, and vulnerability categories, and allocating corresponding resources to the crowdsourcing task to be tested based on the multi-dimensional evaluation results and dynamic adjustment factors. By conducting multi-dimensional evaluation of crowdsourcing tasks, the effective identification of the task's own status is improved. Furthermore, based on the task's own information, market supply and demand coefficients and risk penalty factors are determined, achieving accurate identification of the external environment related to the crowdsourcing task. Finally, the incentive amount for the crowdsourcing task is determined jointly based on the multi-dimensional evaluation results and dynamic adjustment factors, ensuring that appropriate resources are allocated to the crowdsourcing task and avoiding situations of excessive or insufficient incentives, thus achieving effective resource allocation for crowdsourcing tasks. Compared to the inaccurate allocation results caused by traditional static models for crowdsourcing tasks, the above method analyzes crowdsourcing tasks using both internal and external data, which can accurately generate incentive amounts that match the value of the tasks, thus improving the accuracy of resource allocation results for crowdsourcing tasks. Attached Figure Description
[0051] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0052] Figure 1 This is an internal structural diagram of a computer device in one embodiment;
[0053] Figure 2 This is a flowchart illustrating the resource allocation method for a crowdsourcing task in one embodiment;
[0054] Figure 3 This is a flowchart illustrating the process of determining multi-dimensional evaluation results in one embodiment;
[0055] Figure 4 This is a flowchart illustrating the construction of a dynamic adjustment factor in one embodiment;
[0056] Figure 5 This is a flowchart illustrating the process of determining supply and demand data in one embodiment;
[0057] Figure 6 This is a flowchart illustrating the process of determining the contribution factor of a target skill tag in one embodiment.
[0058] Figure 7This is a schematic diagram illustrating the process of allocating corresponding resources to a crowdsourced testing task in one embodiment;
[0059] Figure 8 This is a flowchart illustrating the resource allocation method for a crowdsourcing task in another embodiment;
[0060] Figure 9 This is a structural block diagram of a resource allocation device for a crowdsourcing task in one embodiment. Detailed Implementation
[0061] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0062] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0063] Crowdsourced security testing, as an effective model for discovering software vulnerabilities using collective intelligence, incentivizes external security researchers (white hats) to conduct simulated attacks and security tests on specific systems through bounties. It has become a crucial component of enterprises building proactive defense systems. The design of the incentive mechanism and subsequent resource allocation directly determine the activity level and vulnerability discovery depth of the crowdsourced testing ecosystem. Traditional crowdsourced testing resource allocation primarily relies on static models, i.e., setting fixed reward ranges based on common vulnerability scoring systems (such as CVSS, or Common Vulnerability Scoring System) or predefined risk levels, and allocating resources based on eligible rewards. However, the resource allocation results of the above-mentioned crowdsourced testing tasks suffer from inaccuracies.
[0064] In view of the above-mentioned technical problems, this application provides a resource allocation method for crowdsourcing tasks that can improve the accuracy of resource allocation for crowdsourcing tasks. The following embodiments will specifically illustrate the resource allocation method for crowdsourcing tasks.
[0065] The resource allocation method for crowdsourcing tasks provided in this application embodiment can be applied to, for example... Figure 1 The computer device shown can be a server, and its internal structure diagram can be as follows: Figure 1As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs in the non-volatile storage media to run. The database stores the potential value, difficulty, and risk score of crowdsourcing tasks. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When executed by the processor, the computer program implements a ticket recognition method.
[0066] Those skilled in the art will understand that Figure 1 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0067] In one exemplary embodiment, such as Figure 2 As shown, a resource allocation method for crowdsourcing tasks is provided. This embodiment illustrates the method by applying it to a computer device. In this embodiment, the method includes:
[0068] S201, Obtain the crowdsourcing task to be tested.
[0069] The crowdsourced testing tasks to be tested include task description data. This data may include the task name, task ID, initiator, task type, test mode, start date, and end date. It may also include the architecture information of the object being tested. The data can be adaptively obtained based on the actual scenario requirements; there are no restrictions here.
[0070] In the embodiments of this application, the computer device can obtain the crowdsourcing task to be tested through an external database. The external database can be any type such as a CVE / CNVD vulnerability database, a GitHub code repository, a security technology blog, or other types of code repositories; there are no restrictions here. The computer device can also obtain the crowdsourcing task to be tested through internal data. The internal data can be any type such as data pre-stored in the enterprise CMDB asset library, historical crowdsourcing reports, business logic documents, or other types of data stored in a local database; there are no restrictions here.
[0071] S202, input the task description data into the preset index scoring model for processing, and calculate the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task.
[0072] The preset indicator scoring model can be any of the following: decision tree, support vector machine, clustering algorithm model, association rule mining algorithm model, dimensionality reduction algorithm model, and neural network model; other scoring models are also acceptable. The multi-dimensional evaluation results can include the potential value score, task difficulty score, and potential risk score of the crowdsourced testing task. The potential value score is used to predict the actual losses to core business after a vulnerability is exploited (e.g., the scale of data breach, service interruption duration); the task difficulty score is used to assess the depth of the technology stack, time cost, and prerequisites required to complete the task; the potential risk score is used to determine whether the testing behavior may cause irreversible negative impacts on the production environment (e.g., accidental data deletion, service downtime). Skill tags can be any of the following: IoT firmware reverse engineering capabilities, specific protocol analysis, SAP deep penetration capabilities; other specific skill tags are also acceptable. The target skill tag can be the skill tag corresponding to the crowdsourced testing task. The vulnerability category can be any of the following: program logic structure vulnerability, program design error vulnerability, vulnerability caused by open protocols, cross-site scripting vulnerability, weak password vulnerability; other types of vulnerabilities are also acceptable.
[0073] In the embodiments of this application, the computer device pre-stores multiple preset indicator scoring models. When a crowdsourcing task to be tested is obtained, the task is parsed to obtain task description data. Optionally, one type is selected from the preset indicator scoring models as the target model, and the task description data is input into the target model for identification to obtain multi-dimensional evaluation results, target skill tags, and vulnerability categories for the crowdsourcing task to be tested. Optionally, three types are selected from the preset indicator scoring models as a first target model, a second target model, and a third target model. The task description data is input into the first target model for identification to obtain multi-dimensional evaluation results for the crowdsourcing task to be tested; the task description data is input into the second target model for identification to obtain target skill tags for the crowdsourcing task to be tested; and the task description data is input into the second target model for identification to obtain vulnerability categories for the crowdsourcing task to be tested.
[0074] S203 determines dynamic adjustment factors based on multi-dimensional assessment results, target skill tags, and vulnerability categories.
[0075] The dynamic adjustment factors include a market supply and demand coefficient and a risk penalty factor. The market supply and demand coefficient is used to dynamically assess the scarcity of researchers with specific skills in the current market; the scarcer the researchers, the smaller the market supply and demand coefficient. The risk factor is used to constrain the linear penalty value related to environmental sensitivity for high-risk testing behaviors.
[0076] In the embodiments of this application, the computer device pre-defines a first correspondence between skill tags, vulnerability categories, and market supply and demand coefficients, and a second correspondence between potential risks and dynamic adjustment factors. Based on the obtained multi-dimensional assessment results, target skill tags, and vulnerability categories, the computer device can analyze the target skill tags and vulnerability categories through the first correspondence to determine the market supply and demand coefficients; and extract potential risk scores from the multi-dimensional assessment results, calculate the potential risk scores through the second correspondence, thereby determining the risk penalty factor.
[0077] S204. Allocate corresponding resources to the crowdsourcing task to be tested based on multi-dimensional evaluation results and dynamic adjustment factors.
[0078] The corresponding resources can be incentive amounts or reward amounts.
[0079] In the embodiments of this application, the computer device is pre-set with correction strategies for multi-dimensional evaluation results based on different dynamic adjustment factors. After determining the dynamic adjustment factors, the correction strategies corresponding to different dynamic adjustment factors are extracted to correct the multi-dimensional evaluation results, the resources required for the crowdsourcing task to be tested are calculated, and these resources are announced as incentive amounts or allocated to research safety officers (targets) matching the crowdsourcing task to be tested.
[0080] The resource allocation method for the aforementioned crowdsourcing testing tasks involves acquiring the tasks to be tested, inputting the task description data into a preset indicator scoring model for processing, calculating the multi-dimensional evaluation results, target skill tags, and vulnerability categories of the task, determining a dynamic adjustment factor based on these factors, and allocating corresponding resources to the task based on the multi-dimensional evaluation results and the dynamic adjustment factor. By conducting multi-dimensional evaluations of the crowdsourcing tasks, the effective identification of the task's own status is improved. Furthermore, based on the task's own information, market supply and demand coefficients and risk penalty factors are determined, achieving accurate identification of the external environment related to the task. Finally, the incentive amount for the task is determined jointly based on the multi-dimensional evaluation results and the dynamic adjustment factor, ensuring appropriate resource allocation and avoiding situations of excessive or insufficient incentives, thus achieving effective resource allocation for the crowdsourcing tasks. Compared to the inaccurate allocation results caused by traditional static models for crowdsourcing task resource allocation, the above method analyzes the task using both internal and external data, accurately generating an incentive amount that matches the task's value, thus improving the accuracy of the resource allocation results for crowdsourcing tasks.
[0081] In one exemplary embodiment, such as Figure 3 As shown, the preset indicator scoring model includes an analysis sub-model and a preset scoring sub-model. The analysis sub-model can be a RAG algorithm sub-model, and the preset scoring sub-model can be an LLM neural network structure. Task description data is input into the preset indicator scoring model for processing, and the multi-dimensional evaluation results, target skill tags, and vulnerability categories of the task to be tested are calculated, including:
[0082] S301, Input the task description data into the preset scoring sub-model for semantic parsing to obtain multiple keywords.
[0083] Keywords can include the name of the business system, vulnerability type, access permissions, etc., or other semantic information, depending on the actual scenario.
[0084] In the embodiments of this application, after obtaining the task description data, the computer device inputs the task description data into an LLM neural network structure for semantic parsing to identify multiple keywords. For example, when the task description data of the current crowdsourcing task to be tested is "ERP financial module logic vulnerability mining", the keywords identified by the LLM neural network structure are "financial module", "logic vulnerability", and "unauthorized access".
[0085] S302: Using the analysis sub-model, retrieve the business process, historical vulnerability cases, scoring rules, and target skill tags of each keyword from the preset knowledge graph, and perform combined analysis on the business process, historical vulnerability cases, and scoring rules of each keyword to generate a scoring basis data package.
[0086] In the embodiments of this application, the computer device pre-builds a knowledge graph before the crowdsourcing task is released. Optionally, the computer device connects to the enterprise's configuration management database (e.g., CMDB) in real time via an API interface to obtain server IP, operating system version, and middleware information, parses the business topology relationships in the database, and identifies the core business processes supported by the operating system. For example, the core business processes supported by the ERP system include "quarterly financial settlement" and "supply chain procurement payment." Simultaneously, it accesses external threat intelligence sources to capture historical vulnerability data related to specific components (such as SAP NetWeaver). The computer device uses a Named Entity Recognition (NER) model to extract "attack vectors" (such as RFC interface calls), "required permissions" (such as Developer Key), and "consequences" (such as arbitrary code execution) from unstructured vulnerability descriptions. Finally, based on all the acquired data, the following entities and relationships are constructed in a graph database (such as Neo4j): Entities: Asset (ERP core database), Component (SAP NetWeaver), Vulnerability (CVE-202X-XXXX), Business Process (financial settlement); Relationships: Asset -- [support] --> Business Process, Component -- [runs on] --> Asset, Vulnerability -- [exists in] --> Component, resulting in a knowledge graph. Through the constructed knowledge graph, the computer device can deduce that once Component is compromised, it will directly lead to the interruption of Business Process, thereby calculating potential business losses.
[0087] Optionally, for the identified keywords, the analysis sub-model uses the keywords as anchors to perform multi-hop queries in a pre-defined knowledge graph, retrieving the associated business processes, historical vulnerability cases, and scoring rules. The retrieved information is then sequentially combined or concatenated to generate a scoring basis data package. Continuing the previous example, the analysis sub-model inputs the identified keywords into the pre-defined knowledge graph for retrieval, obtaining information such as "financial module" being associated with the "quarterly settlement" process (the associated business process), which processes over 1 billion yuan in daily cash flows (scoring rule); historically, "logic vulnerabilities" in this version of ERP typically involve complex RFC interface parameter tampering (historical vulnerability cases), making them extremely difficult to exploit (scoring rule). The retrieved information is then combined to obtain the scoring basis data package.
[0088] S303: Input the scoring data package into the preset scoring sub-model for multi-dimensional evaluation to obtain the multi-dimensional evaluation results of the crowdsourcing task to be tested.
[0089] In the embodiments of this application, the computer device simultaneously inputs the scoring basis data packet and task description data into the LLM neural network structure for indicator evaluation. This involves analyzing the degree of conformity between the task description data and the scoring rules in the scoring basis data packet, referencing scoring patterns from similar historical cases, and considering the synergistic effects of related indicators. Based on this comprehensive analysis, a specific score between 0 and 1 is given, generating a multi-dimensional evaluation result for the crowdsourced testing task. Continuing with the previous example, after identifying the scoring basis data packet and task description data for the crowdsourced testing task "ERP financial module logic vulnerability mining," the LLM neural network structure infers that if funds are stolen or data is tampered with in this module, it will lead to direct economic losses and severe compliance penalties, resulting in a potential value score of 0.95. Considering that the target system to which this module belongs is deployed deep within the intranet and is configured with WAF and RASP protection, attackers need to bypass multiple layers of defense and construct specific serialized data packets. Therefore, this task requires expert-level reverse engineering capabilities, resulting in a task difficulty score of 0.88. Since the testing target of the financial module is a production environment and involves high-frequency trading interfaces, high-concurrency scanning may lead to deadlocks or denial of service, resulting in a potential risk score of 0.75.
[0090] The above method, by evaluating crowdsourcing tasks using multi-dimensional indicators, helps to improve the accuracy of subsequent resource allocation results for crowdsourcing tasks.
[0091] In one exemplary embodiment, such as Figure 4 As shown, the multi-dimensional assessment results include a potential risk score. Dynamic adjustment factors are determined based on these multi-dimensional assessment results, target skill tags, and vulnerability categories, including:
[0092] S401, determine the current supply and demand data of target skill tags based on knowledge graphs.
[0093] The supply and demand data includes demand and supply. Demand is the number of tasks on the platform currently awaiting testing that require the specific skill. Supply is the number of active users with the specific skill certification within a preset period.
[0094] In the embodiments of this application, the knowledge graph pre-stores multiple skill tags and the corresponding crowdsourcing tasks and research security personnel (objects) for each skill tag. The crowdsourcing tasks and researchers corresponding to the skill tags are updated adaptively over time. Optionally, after determining the target skill tag, the computer device performs similarity matching between the target skill tag and preset skill tags. If the similarity is greater than or equal to a preset similarity threshold, the number of crowdsourcing tasks and researchers currently corresponding to the preset skill tag is determined, and the determined number of crowdsourcing tasks and researchers is used as the current supply and demand data for the target skill tag, i.e., demand and supply.
[0095] S402 determines whether a remediation report should be submitted for the vulnerability category, and determines the contribution factor of the target skill tag based on the determination result, and constructs the market supply and demand coefficient based on the supply and demand data and the contribution factor of the target skill tag.
[0096] In the embodiments of this application, for a vulnerability category, the computer device retrieves historical vulnerability cases corresponding to that vulnerability category from a preset knowledge graph, analyzes the historical vulnerability cases, and determines whether a repair report has been submitted for that vulnerability category. When a repair report has been submitted for the vulnerability category, the contribution factor of the target skill tag is determined based on the quality score of the repair report; when no repair report has been submitted for the vulnerability category, the contribution factor of the target skill tag is set to a preset contribution threshold. Finally, the market supply and demand coefficient is constructed through supply and demand data and the contribution factor of the target skill tag. Optionally, the market supply and demand coefficient can be expressed by the following relationship (1):
[0097] (1);
[0098] In the formula, For demand, For supply, As a contributing factor. This is a scarcity adjustment constant. To determine the weight of contribution rewards, And β can be set according to the actual needs of the scenario, for example It is 0.1. It is 0.5.
[0099] S403, construct risk penalty factors based on preset environmental sensitivity and potential risk scores.
[0100] The preset environment sensitivity includes production environment sensitivity, pre-release environment sensitivity, and sandbox environment sensitivity. The values for the preset environment sensitivity can be set according to actual scenario requirements; there are no restrictions here. For example, set it to 2000 for the production environment, 1000 for the pre-release environment, and 500 for the sandbox environment.
[0101] In the embodiments of this application, the test environment type of the crowdsourcing task to be tested is obtained, and the test environment type is matched with the environment type of the preset environment sensitivity. If the matching degree is greater than the preset matching degree threshold, the preset environment sensitivity corresponding to the environment type is taken as the environment sensitivity of the crowdsourcing task to be tested. The environment sensitivity is multiplied by the potential risk score to obtain the risk penalty factor. Optionally, the risk penalty factor can be represented by the following relationship (2):
[0102] (2);
[0103] In the formula, The environmental sensitivity of the test task to be evaluated. Score potential risks. This is a risk penalty factor.
[0104] The above method constructs dynamic adjustment factors through the self-information of the crowdsourcing task, which can analyze the crowdsourcing task from multiple dimensions and is conducive to improving the accuracy of subsequent crowdsourcing task resource allocation results.
[0105] In one exemplary embodiment, such as Figure 5 As shown, the current supply and demand data for the target skill tag is determined based on the knowledge graph, including:
[0106] S501, based on knowledge graphs, determines the number of crowdsourcing tasks associated with the target skill tags as the demand.
[0107] In the embodiments of this application, after the computer device determines the target skill tag, it performs similarity matching between the target skill tag and the preset skill tag. If the similarity is greater than or equal to the preset similarity threshold, it determines the number of crowd testing tasks currently corresponding to the preset skill tag, and the determined number of crowd testing tasks is used as the demand for the target skill tag.
[0108] S502, identify the objects active within the preset period, filter the objects according to the target skill tags, obtain the number of target objects, and use the number of target objects as the supply.
[0109] The preset period can be 30 days prior to the current time, or it can be set according to the actual needs of the scenario; there are no restrictions here.
[0110] In embodiments of this application, the computer device identifies objects active within a preset period from a knowledge graph. Optionally, object activity can be determined by the frequency of an object's (security officer's) logins to the system; if the login frequency exceeds a preset frequency threshold, the object is considered active. Alternatively, object activity can be determined by the number of times an object speaks; if the number of times speaks exceeds a preset number of times, the object is considered active. Furthermore, object activity can be determined by the online duration of an object (security officer); if the online duration exceeds a preset duration, the object is considered active. After identifying objects active within the preset period, the skill identifiers carried by the objects are matched with target skill tags. If the similarity is greater than a preset value, the corresponding object is designated as the target object, and the number of target objects is counted, which is then used as the supply quantity.
[0111] The above method constructs dynamic adjustment factors through the self-information of the crowdsourcing task, which can analyze the crowdsourcing task from multiple dimensions and is conducive to improving the accuracy of subsequent crowdsourcing task resource allocation results.
[0112] In one exemplary embodiment, such as Figure 6 As shown, the contribution factors of the target skill tag are determined based on the judgment results, including:
[0113] S601, if the vulnerability category is submitting a remediation report, then the contribution factor of the target skill tag is determined based on the quality score of the remediation report.
[0114] The quality score for the repair report is between 0 and 1.
[0115] In the embodiments of this application, when a vulnerability category of "submitting a remediation report" is detected, the instruction score of the remediation report is further determined. Optionally, regular expressions or keywords can be used to detect the existence of fields in the remediation report, that is, the ratio of existing fields to required fields is used as the quality score of the remediation report. Alternatively, the BERT-BiLSTM-CRF model can be used to extract technical entities from the remediation report, identify key entities among the technical entities, such as file names, function names, vulnerability categories, code snippets, etc., and use the ratio of the number of key entities to the expected number of entities as the quality score of the remediation report. Tests can also be run on the code in the remediation report, the ratio of the number of passed test cases to the total number of test cases can be calculated, and the difference between the value 1 and this ratio can be calculated to determine the final difference as the quality score of the remediation report. After the quality score is calculated, the quality score is determined as a contribution factor of the target skill tag.
[0116] S602, if the vulnerability category is "no remediation report submitted", then the contribution factor of the target skill tag is set to the preset contribution threshold.
[0117] The preset contribution threshold can be 0.
[0118] In the embodiments of this application, when the vulnerability category is detected as "no remediation report submitted", it indicates that there are no reference cases for the current vulnerability category, and the contribution factor of the target skill tag is set to 0.
[0119] The above method constructs dynamic adjustment factors through the self-information of the crowdsourcing task, which can analyze the crowdsourcing task from multiple dimensions and is conducive to improving the accuracy of subsequent crowdsourcing task resource allocation results.
[0120] In one exemplary embodiment, such as Figure 7 As shown, the resource allocation results for the crowdsourcing tasks to be tested are determined based on multi-dimensional evaluation results and dynamic adjustment factors, including:
[0121] S701 performs nonlinear calculations on the multi-dimensional evaluation results to obtain the basic excitation values.
[0122] In the embodiments of this application, after obtaining the multi-dimensional evaluation results, an initial incentive amount is obtained. The potential value score and task difficulty score in the multi-dimensional evaluation results are then non-linearly calculated with the initial incentive amount to obtain the basic incentive value. Optionally, the basic incentive value can be represented by the following relationship (3):
[0123] (3);
[0124] In the formula, This is the initial incentive amount. Rate the potential value. Rate the difficulty of the task. , These are the weighting coefficients, The basic stimulus value.
[0125] S702 adjusts the basic incentive value using the market supply and demand coefficient to obtain the adjusted basic incentive value.
[0126] In the embodiments of this application, for the market supply and demand coefficient, the market supply and demand coefficient is summed with a preset balance factor to obtain a first adjustment factor, which can be 1. Then, the first adjustment factor is multiplied with the basic incentive value to obtain the adjusted basic incentive value. Optionally, the adjusted basic incentive value can be represented by the following relationship (4):
[0127] (4);
[0128] In the formula, Based on the basic incentive value, The market supply and demand coefficient. This is the adjusted base excitation value.
[0129] S703 uses a risk penalty factor to make a second adjustment to the adjusted base incentive value, thereby obtaining the resource allocation result for the crowdsourcing task to be tested.
[0130] The resource allocation result for the crowdsourcing task to be tested can be a dynamic incentive amount.
[0131] In the embodiments of this application, for the risk penalty factor, the adjusted basic incentive value is subtracted from the risk penalty factor, i.e., the second adjustment, to obtain the dynamic incentive amount. Optionally, the dynamic incentive amount can be expressed by the following relationship (5):
[0132] (5);
[0133] In the formula, Based on the basic incentive value, The market supply and demand coefficient. As a risk penalty factor, This is the amount of the dynamic incentive.
[0134] S704: Allocate corresponding resources to the crowdsourcing task to be tested based on the resource allocation results of the crowdsourcing task to be tested.
[0135] In the embodiments of this application, after calculating the resource allocation result, the resource allocation result is announced as an incentive amount or the corresponding resources are allocated to the research safety officers (objects) who are matched with the crowdsourcing task to be tested.
[0136] In addition to the methods of all the above embodiments, a resource allocation method for crowdsourcing testing tasks is also provided, such as... Figure 8 As shown, the method includes:
[0137] S801, Obtain the crowd testing task to be tested, which includes task description data;
[0138] S802, Input the task description data into the preset scoring sub-model for semantic parsing to obtain multiple keywords; among the multiple keywords are keywords representing vulnerability categories;
[0139] S803 uses the analysis sub-model to retrieve the business process, historical vulnerability cases, scoring rules and target skill tags of each keyword from the preset knowledge graph, and performs combined analysis on the business process, historical vulnerability cases and scoring rules of each keyword to generate a scoring basis data package.
[0140] S804: Input the scoring data package into the preset scoring sub-model for multi-dimensional evaluation to obtain the multi-dimensional evaluation results of the crowdsourcing task to be tested.
[0141] S805, based on knowledge graphs, determines the number of crowdsourcing tasks associated with target skill tags as the demand.
[0142] S806, identify the objects active within the preset period, filter the objects according to the target skill tags, obtain the number of target objects, and use the number of target objects as the supply.
[0143] S807, determine whether to submit a remediation report based on the vulnerability category;
[0144] S808: If the vulnerability category is "submitted a remediation report", the contribution factor of the target skill tag is determined based on the quality score of the remediation report; if the vulnerability category is "no remediation report submitted", the contribution factor of the target skill tag is set to the preset contribution threshold.
[0145] S809, construct risk penalty factors based on preset environmental sensitivity and potential risk scores;
[0146] S810 performs nonlinear calculations on the multi-dimensional evaluation results to obtain the basic excitation values;
[0147] S811, the basic incentive value is adjusted first by the market supply and demand coefficient to obtain the adjusted basic incentive value;
[0148] S812, by applying a risk penalty factor to the adjusted base incentive value, the resource allocation result of the crowdsourcing task to be tested is obtained.
[0149] S813: Allocate corresponding resources to the crowdsourcing task to be tested based on the resource allocation results of the crowdsourcing task to be tested.
[0150] Each of the above steps has been described in the foregoing embodiments. For details, please refer to the foregoing content. They will not be repeated here.
[0151] The above embodiments are explained and illustrated by some examples below, which do not limit the technical solution.
[0152] Example 1: Incentive optimization for core business systems within large enterprise intranets.
[0153] This embodiment details the specific process of incentivizing and optimizing a crowdsourcing testing task for a core business system (such as an Enterprise Resource Planning (ERP) system or a Customer Relationship Management (CRM) system) within a large enterprise intranet environment. This scenario is characterized by a complex system environment, strong business criticality, high potential testing risks, and vulnerabilities often hidden deep within complex business logic, making them difficult to discover using automated tools.
[0154] Step 1: Deep asset association and knowledge graph construction based on CMDB.
[0155] Before the crowdsourcing testing task begins, the system first needs to build a security knowledge graph that reflects the company's real business logic. Unlike general vulnerability databases, this graph must be deeply integrated with the company's internal asset information.
[0156] The system connects to the enterprise's Configuration Management Database (CMDB) in real time via API. For ERP systems, the system not only obtains their server IP, operating system version (such as Red Hat 8.4) and middleware information (such as WebLogic 14c), but more importantly, it parses the business topology relationships in the CMDB to identify the core business processes supported by the ERP system—such as "quarterly financial settlement" and "supply chain procurement payment."
[0157] Simultaneously, the system accesses external threat intelligence sources to capture historical vulnerability data related to specific components (such as SAP NetWeaver). The system utilizes a Named Entity Recognition (NER) model to extract "attack vectors" (such as RFC interface calls), "required privileges" (such as Developer Keys), and "consequences" (such as arbitrary code execution) from unstructured vulnerability descriptions.
[0158] Based on the above data, the system constructs the following entities and relationships in a graph database (such as Neo4j):
[0159] Entities: Asset (ERP core database), Component (SAP NetWeaver), Vulnerability (CVE-202X-XXXX), BusinessProcess (financial settlement); Relationships: Asset --[supports]-->BusinessProcess, Component --[runs on]--> Asset, Vulnerability --[exists on]-->Component.
[0160] Through this structured mapping, the system can deduce that once a component is compromised, it will directly lead to the interruption of the Business Process, thereby calculating the potential business losses.
[0161] Step 2: Context-aware task value assessment based on LLM.
[0162] When an enterprise security team releases a crowdsourcing task titled "ERP Financial Module Logic Vulnerability Discovery", the system triggers an intelligent evaluation process.
[0163] Task semantic parsing: LLM first performs semantic analysis on the task description to identify keywords such as "financial module", "logic vulnerability", and "unauthorized access".
[0164] RAG Contextual Retrieval: The system uses these keywords as anchors to perform multi-hop queries within the knowledge graph. The system found that the "Finance Module" is associated with the "Quarterly Settlement" process, which handles over 1 billion yuan in cash flows daily; historically, "logic vulnerabilities" targeting this version of ERP have typically involved complex RFC interface parameter tampering, making them extremely difficult to exploit.
[0165] Three-Dimensional Value Reasoning: Potential Value (V): LLM combines business data reasoning to determine that if funds are stolen or data is tampered with in this module, it will lead to direct economic losses and severe compliance penalties. LLM gives it a value score of 0.95 (out of 1.0). Task Difficulty (D): Considering the target system is deployed deep within the internal network and is configured with WAF and RASP protection, attackers need to bypass multiple layers of defense and construct specific serialized data packets. LLM judges this task requires expert-level reverse engineering capabilities, giving it a difficulty score of 0.88. Potential Risk (R): Since the test target is a production environment and involves high-frequency trading interfaces, high-concurrency scanning may lead to deadlocks or denial of service. LLM assesses the risk score as 0.75.
[0166] Step 3: Dynamic incentive quota generation and strategy optimization.
[0167] The system calculates the final bonus based on a preset incentive strategy. This embodiment uses an exponential nonlinear fundamental function. ,in Yuan, .
[0168] Basic stimulus calculation:
[0169]
[0170] Calculation of dynamic adjustment factors: Market supply and demand coefficient ( System analysis revealed that white-hat hackers with deep SAP penetration capabilities are extremely scarce. (i.e., a 25% premium). The system's knowledge graph query revealed the current number of tasks requiring "SAP NetWeaver reverse engineering" skills. Only active white-hat hackers (targets) with this skill certification within the past 30 days... .
[0171] Setting scarcity parameters Initial contribution .
[0172] calculate .
[0173] Risk penalty factor ( ): High-risk testing in production environments ( The target environment is "production environment". The system retrieves the configuration table. Potential risk score .calculate Yuan.
[0174] Final incentive amount calculation:
[0175] .
[0176] Compared to the fixed "3,000 yuan for high-risk vulnerabilities" in the traditional model, this nonlinear dynamic incentive scheme offers a premium of nearly 8 times, accurately reflecting the extremely high technical threshold and market scarcity of this task.
[0177] Step 4: Feedback and closed loop throughout the entire life cycle.
[0178] After the task was completed, a white-hat hacker successfully discovered a vulnerability that bypassed authentication by constructing a special SOAP request. The system recorded detailed information about the vulnerability and the actual time spent by the white-hat hacker (approximately 120 hours).
[0179] The system stores the complete data chain of "task description - vulnerability details - actual time taken - reward payment" in the sample database. Comparison revealed a strong positive correlation between the difficulty predicted by LLM (0.88) and the actual time taken, validating the model's accuracy. Simultaneously, the system back-injected the vulnerability's attack pattern into the knowledge graph, updating the threat intelligence for the "SAPNetWeaver" component, making future assessments of similar components more accurate.
[0180] Through this continuous iteration, the system not only optimizes the incentives for individual tasks, but also gradually builds a highly refined security awareness system specific to the enterprise.
[0181] Example 2: Incentives for vulnerability discovery in the open-source software supply chain.
[0182] This embodiment is applied to large open-source communities or enterprises that heavily rely on open-source components. Its goal is to incentivize global security researchers to proactively uncover hidden zero-day vulnerabilities within the software supply chain. Compared to enterprise intranet environments, open-source supply chains have more nodes and more complex dependencies, making the impact radius (i.e., the "explosion radius") of a single vulnerability often difficult to estimate.
[0183] Step 1: Panoramic data collection and construction of a knowledge graph for the software supply chain.
[0184] In this scenario, the data collection scope extends to the global open-source ecosystem. The system deploys a distributed crawler cluster to continuously monitor the following data sources:
[0185] Code hosting platform: Monitors key projects with over 1000 stars on GitHub and GitLab, and parses dependency configuration files such as package.json and pom.xml.
[0186] Package manager metadata: Synchronizes package downloads, version update history, and dependency tree from NPM and Maven Central.
[0187] Community Updates: We use NLP techniques to analyze technical discussions on Stack Overflow and Reddit to identify potential security vulnerabilities.
[0188] Based on the massive amount of data mentioned above, the system constructs a "software supply chain knowledge graph." The core entities of this graph include Package, Version, Developer, and Vulnerability. The core relationships include Dependencies, Maintain, and Effects.
[0189] For example, the graph clearly shows that Log4j-core 2.14.1 is directly depended on by tens of thousands of downstream projects such as Elasticsearch and Kafka, and these downstream projects are indirectly depended on by millions of end-user applications. This deep dependency chain is the basis for calculating the "explosion radius".
[0190] Step 2: LLM value assessment based on “explosion radius”.
[0191] When the system issues a vulnerability discovery task targeting "common Java logging components", the LLM evaluation model will focus on its cascading impact in the supply chain.
[0192] Dependency Depth and Breadth Analysis: LLM query of the knowledge graph revealed that the component has more than 50,000 direct downstream dependencies and more than 2 million indirect dependencies.
[0193] Core Functionality Correlation Inference: LLM code snippet analysis revealed that this component is frequently used to log sensitive operations such as user logins and payment transactions. This means that if an RCE vulnerability exists, attackers could easily gain core privileges.
[0194] Exploitability projection: Based on LLM and historical CVE data, if the component has a JNDI injection vulnerability, an attacker can trigger it remotely without authentication.
[0195] Based on the above reasoning, LLM's assessment results are as follows: Value: Extremely high (0.98), because its "explosion radius" covers hundreds of millions of devices worldwide. Difficulty: Moderate (0.65), because the code is open source and the logic is relatively clear. Risk: Low (0.20), because the testing is mainly conducted in local sandboxes or non-production environments.
[0196] Step 3: Introduce an ecological incentive model based on "community contribution factors".
[0197] This embodiment also uses a nonlinear incentive formula, but in view of the characteristics of the open source ecosystem, the "community contribution factor" is incorporated into the market supply and demand coefficient to reflect the scarce value of high-quality repair solutions.
[0198] The basic excitation function is set as follows To highlight the combined effect of high value and high difficulty. (Setting) Yuan.
[0199] Basic stimulus calculation:
[0200] .
[0201] Calculation of dynamic adjustment factor:
[0202] Market supply and demand coefficient ( Considering the global scarcity of Log4j-level vulnerabilities and the high-quality remediation solutions submitted by researchers (community contribution factor) The system will overlay the two and set... (i.e., a premium of 95%).
[0203] The task of investigating Log4j vulnerabilities has surged. Initially, there were very few white-hat hackers with advanced Java deserialization exploitation capabilities. .set up Furthermore, the researcher submitted a complete fix patch, which was rated as a high-quality contribution. Set weights .
[0204] Scarcity component: .
[0205] Contribution section: Total coefficient .
[0206] Risk penalty factor ( Since the test is conducted in a local sandbox, the risk is extremely low. The test environment is a local sandbox. Extremely low risk .calculate Yuan.
[0207] Final incentive amount calculation: .
[0208] Through non-linear amplification and a high market premium, this incentive program (approximately RMB 32,000) far exceeds conventional vulnerability bounties, greatly stimulating the enthusiasm of top white-hat hackers worldwide to participate in the construction of open-source supply chain security.
[0209] Step 4: Ecological security situation awareness and early warning.
[0210] Upon completion of the task, the system synchronizes the vulnerability characteristics and remediation solutions to the knowledge graph. Based on the updated graph, the system automatically performs a "reverse impact lookup" to identify all affected downstream projects (such as Elasticsearch) and automatically sends security alert emails to the maintainers of these projects, recommending version upgrades.
[0211] In addition, the system uses LLM to analyze the causes of vulnerabilities (such as JNDI injection) and performs "analogical reasoning" on other components with similar architectural characteristics in the graph to predict a list of components that may have similar vulnerabilities, thereby guiding the direction of the next stage of crowdsourcing tasks and achieving a leap from "single-point defense" to "area defense".
[0212] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0213] Based on the same inventive concept, this application also provides a resource allocation device for implementing the resource allocation method for crowdsourcing tasks as described above. The solution provided by this device is similar to the implementation described in the above method. Therefore, the specific limitations in one or more resource allocation device embodiments for crowdsourcing tasks provided below can be found in the limitations of the resource allocation method for crowdsourcing tasks described above, and will not be repeated here.
[0214] In one exemplary embodiment, such as Figure 9 As shown, a resource allocation device for a crowdsourcing task is provided, comprising: an acquisition module 91, a processing module 92, a determination module 93, and an adjustment module 94, wherein:
[0215] Module 91 is used to acquire the crowd testing task to be tested, which includes task description data.
[0216] Processing module 92 is used to input task description data into a preset index scoring model for processing, and calculate the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task to be tested;
[0217] Module 93 is used to determine dynamic adjustment factors based on multi-dimensional assessment results, target skill tags, and vulnerability categories; dynamic adjustment factors include market supply and demand coefficients and risk penalty factors.
[0218] Adjustment module 94 is used to determine the resource allocation results of the crowdsourcing task to be tested based on the multi-dimensional evaluation results and dynamic adjustment factors.
[0219] In an exemplary embodiment, the processing module 92 includes:
[0220] The parsing unit is used to input task description data into a preset scoring sub-model for semantic parsing to obtain multiple keywords; among the multiple keywords are keywords representing vulnerability categories;
[0221] The retrieval unit is used to retrieve the business process, historical vulnerability cases, scoring rules and target skill tags of each keyword from the preset knowledge graph using the analysis sub-model, and to perform combined analysis on the business process, historical vulnerability cases and scoring rules of each keyword to generate a scoring basis data package.
[0222] The evaluation unit is used to input the scoring basis data package into the preset scoring sub-model for multi-dimensional evaluation, and obtain the multi-dimensional evaluation results of the crowdsourcing task to be tested.
[0223] In one exemplary embodiment, the determining module 93 includes:
[0224] The determination unit is used to determine the current supply and demand data for target skill tags based on the knowledge graph.
[0225] The judgment unit is used to determine whether a remediation report should be submitted for a vulnerability category, and to determine the contribution factor of the target skill tag based on the judgment result, and to construct the market supply and demand coefficient based on the supply and demand data and the contribution factor of the target skill tag;
[0226] The construction unit is used to construct risk penalty factors based on preset environmental sensitivity and potential risk scores.
[0227] In an exemplary embodiment, the determining unit includes:
[0228] The sub-unit is determined based on the knowledge graph to identify the number of crowdsourcing tasks associated with the target skill tag as the demand.
[0229] The filtering sub-unit is used to identify objects that are active within a preset period, filter objects based on target skill tags, obtain the number of target objects, and use the number of target objects as the supply.
[0230] In an exemplary embodiment, the aforementioned determination unit is configured to: determine the contribution factor of the target skill tag based on the quality score of the repair report when the vulnerability category is "submitted repair report"; and set the contribution factor of the target skill tag to a preset contribution threshold when the vulnerability category is "no repair report submitted".
[0231] In one exemplary embodiment, the adjustment module 94 includes:
[0232] The computing unit is used to perform nonlinear calculations on the multi-dimensional evaluation results to obtain the basic excitation values;
[0233] The first adjustment unit is used to make a first adjustment to the basic incentive value through the market supply and demand coefficient to obtain the adjusted basic incentive value.
[0234] The second adjustment unit is used to make a second adjustment to the adjusted basic incentive value through the risk penalty factor to obtain the resource allocation result of the crowdsourcing task to be tested.
[0235] The allocation unit is used to allocate corresponding resources to the crowdsourcing task to be tested based on the resource allocation results of the crowdsourcing task to be tested.
[0236] Each module in the resource allocation device for the aforementioned crowdsourcing task can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0237] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program that, when executed by the processor, implements the steps in the above-described method embodiments.
[0238] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0239] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0240] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0241] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0242] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A resource allocation method for crowdsourcing testing tasks, characterized in that, The method includes: Obtain the crowd-testing task to be tested, which includes task description data; The task description data is input into a preset index scoring model for processing, and the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task are calculated. Dynamic adjustment factors are determined based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors. Based on the multi-dimensional evaluation results and the dynamic adjustment factor, corresponding resources are allocated to the crowdsourcing task to be tested.
2. The method according to claim 1, characterized in that, The preset indicator scoring model includes an analysis sub-model and a preset scoring sub-model. The task description data is input into the preset indicator scoring model for processing, and the multi-dimensional evaluation results, target skill tags, and vulnerability categories of the task to be tested are calculated, including: The task description data is input into the preset scoring sub-model for semantic parsing to obtain multiple keywords; the multiple keywords include keywords representing the vulnerability category; The analysis sub-model is used to retrieve the business process, historical vulnerability cases, scoring rules and target skill tags of each keyword from the preset knowledge graph, and to perform combined analysis on the business process, historical vulnerability cases and scoring rules of each keyword to generate a scoring basis data package; The scoring data package is input into the preset scoring sub-model for multi-dimensional evaluation to obtain the multi-dimensional evaluation results of the crowdsourcing task to be tested.
3. The method according to claim 2, characterized in that, The multi-dimensional assessment results include a potential risk score. The determination of dynamic adjustment factors based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories includes: Based on the knowledge graph, determine the current supply and demand data for the target skill tag; Determine whether a remediation report should be submitted for the vulnerability category, determine the contribution factor of the target skill tag based on the determination result, and construct the market supply and demand coefficient based on the supply and demand data and the contribution factor of the target skill tag; The risk penalty factor is constructed based on the preset environmental sensitivity and the potential risk score.
4. The method according to claim 3, characterized in that, The supply and demand data includes demand and supply. Determining the current supply and demand data for the target skill tag based on the knowledge graph includes: Based on the knowledge graph, the number of crowdsourcing tasks associated with the target skill tag is determined as the demand. Identify objects that are active within a preset period, filter the objects based on the target skill tags to obtain the number of target objects, and use the number of target objects as the supply.
5. The method according to claim 3, characterized in that, The step of determining the contribution factor of the target skill tag based on the judgment result includes: If the vulnerability category is submitting a remediation report, then the contribution factor of the target skill tag is determined based on the quality score of the remediation report; If the vulnerability category is "no remediation report submitted", then the contribution factor of the target skill tag will be set to a preset contribution threshold.
6. The method according to any one of claims 1-5, characterized in that, The process of determining the resource allocation result for the crowdsourcing task to be tested based on the multi-dimensional evaluation results and the dynamic adjustment factor includes: The multi-dimensional evaluation results are subjected to nonlinear calculations to obtain the basic excitation values; The basic incentive value is adjusted by the market supply and demand coefficient to obtain the adjusted basic incentive value. The resource allocation result of the crowdsourcing task to be tested is obtained by adjusting the adjusted base incentive value through a risk penalty factor. Based on the resource allocation results of the crowdsourcing task to be tested, allocate corresponding resources to the crowdsourcing task to be tested.
7. A resource allocation device for a crowdsourcing testing task, characterized in that, The device includes: The acquisition module is used to acquire the crowd-testing task to be tested, which includes task description data. The processing module is used to input the task description data into a preset index scoring model for processing, and calculate the multi-dimensional evaluation results, target skill tags and vulnerability categories of the crowd-tested task to be tested; The determination module is used to determine dynamic adjustment factors based on the multi-dimensional assessment results, the target skill tags, and the vulnerability categories; the dynamic adjustment factors include market supply and demand coefficients and risk penalty factors. The adjustment module is used to determine the resource allocation result of the crowdsourcing task to be tested based on the multi-dimensional evaluation results and the dynamic adjustment factor.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.