A network vulnerability automatic reproduction verification method and system

By standardizing the processing and intelligence extraction of network vulnerability input information, candidate verification requests are generated and automatically verified, solving the problems of complex vulnerability information sources and insufficient consistency of verification results, and realizing an efficient and traceable vulnerability verification process.

CN122419969APending Publication Date: 2026-07-17HEFEI NETWORK INSTR TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HEFEI NETWORK INSTR TECH CO LTD
Filing Date
2026-06-05
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In the current network vulnerability verification process, the sources of vulnerability information are complex, the verification process relies heavily on human experience, and the consistency and traceability of verification results are insufficient.

Method used

By standardizing the vulnerability input information of the vulnerability to be verified, a standardized vulnerability task object is generated. Verifiability and network interaction applicability are judged, candidate vulnerability intelligence is obtained and refined, candidate verification requests are generated, network requests are initiated to the target verification link and verification evidence information is collected, and finally, the verification results are reproduced and confirmed by combining the rule hit information of the security detection equipment and archived.

Benefits of technology

It reduces reliance on human experience, improves the efficiency of automatic reproduction and verification in complex vulnerability scenarios, and enhances the consistency and traceability of verification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419969A_ABST
    Figure CN122419969A_ABST
Patent Text Reader

Abstract

本申请公开了一种网络漏洞自动复现验证方法及系统,该方法包括:获取待验证漏洞的漏洞输入信息并标准化处理,得到标准化漏洞任务对象;基于该对象进行可验证性判断和网络交互适用性判断;满足自动复现验证条件时获取候选漏洞情报并提炼得到结构化利用信息,不满足时生成终止原因信息;根据结构化利用信息和预设请求生成约束生成候选验证请求;向目标验证链路发起网络请求并采集验证证据信息;结合验证证据信息和规则命中信息进行复现确认,得到漏洞复现验证结果;并对验证过程信息和验证结果信息进行归档。该方法能够降低人工经验依赖,提高漏洞复现验证效率,并增强验证结果的一致性和可追溯性。
Need to check novelty before this filing date? Find Prior Art