Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "CVSS" patented technology

The Common Vulnerability Scoring System (CVSS) is a free and open industry standard for assessing the severity of computer system security vulnerabilities. CVSS attempts to assign severity scores to vulnerabilities, allowing responders to prioritize responses and resources according to threat. Scores are calculated based on a formula that depends on several metrics that approximate ease of exploit and the impact of exploit. Scores range from 0 to 10, with 10 being the most severe. While many utilize only the CVSS Base score for determining severity, temporal and environmental scores also exist, to factor in availability of mitigations and how widespread vulnerable systems are within an organization, respectively.

Network security scene-oriented RAG construction method for CVE-ATTCK association fusion

PendingCN121841709AMake up for the shortcomings of not reflecting the full picture of the attackimprove accuracyKnowledge representationSecuring communicationShardAttack
The invention discloses a CVE-ATTamp (Cascade Vector Enhanced ATTamp) for a network security scene. The invention discloses a CK association fusion RAG construction method, and relates to the technical field of network security. The method comprises the following steps: (1) carrying out structured analysis and vectorization on CVE vulnerability information data, extracting features and fusing CVSS scores to carry out semantic embedding; (2) ATTamp; semantic modeling of a CK threat matrix is carried out, and a threat semantic space containing tactical level information is constructed; (3) heterogeneous knowledge association and graph construction: calculating cross-domain semantic similarity and establishing logic mapping between vulnerabilities and tactics in combination with expert rules to form a heterogeneous knowledge graph; and (4) attack logic-oriented RAG retrieval and generation: retrieving a key attack path sub-graph based on a hybrid scoring mechanism, and driving a large model to generate a security analysis report with logic depth. According to the method, attack logic is stored through mapping, so that the problems that the traditional RAG lacks inference ability and security data fragmentation are solved, and the accuracy and tactical value of automatic threat analysis are remarkably improved.
Owner:TAIZHOU RES INST ZHEJIANG UNIV OF TECH

Vulnerability scoring based on organization-specific metrics

In one example, a non-transitory computer-readable storage medium stores executable program instructions that detect, at a remote device node, vulnerability data associated with an exploitable vulnerability of a target enterprise network; retrieve, by a first local device node, the vulnerability data, which may include a CVSS score, determine, by a second local device node, a vulnerability score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest Impact (MHI) metric to capture reputation damage based on an outsized single impact attribute, and on a Modified Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability score VT.
Owner:JPMORGAN CHASE BANK NA

Risk evaluation for a vulnerability assessment system on a data communication network from a collection of threats

A private network is scanned to identify devices, and profiling identified devices for vulnerabilities. A score is determined from a Common Vulnerability Scoring System (CVSS) database for each vulnerability individually that characterizes severity. A score is determined for a collection of vulnerabilities. Exponential tapering functions curb an influence of large numbers of low priority threats on the collection score. The collection threat score increases with severity of the collection of vulnerabilities.
Owner:FORTINET INC

A method, device, medium and electronic equipment for generating a honeycomb transformation configuration

The application provides a honey array transformation configuration generation method and device, a medium and an electronic equipment, comprising: obtaining TTP information matching CVE to obtain CVE information; obtaining CVSS score according to the CVE information, selecting M CVE information associated with the highest score to generate corresponding CVE mirror configuration section; extracting scene feature information according to the TTP information to generate a feature mirror configuration section; generating a new honeypot configuration section of the service feature according to the TTP information; and mixing the CVE mirror configuration section, the feature mirror configuration section and the honeypot configuration section to generate a honey array transformation configuration file for transforming a trapping scene configuration. By designing the TTP scene information highly associated with the attacker's attack behavior and various threat modeling scales, the application completes the mapping of the attacker's behavior to the vulnerability and the service, selects the honeypot mirror of interest of the attacker, and highly adaptively generates the honey array transformation configuration file in combination with the scene information.
Owner:GUANGZHOU UNIVERSITY

Threat assessment method based on logic attack graph, ATTCK and CVSS

The invention discloses a method based on a logic attack graph and ATTamp; the invention discloses a threat assessment method for CK and CVSS, and the method comprises the steps: firstly obtaining preposition information needed by the successful implementation of a technology based on a minimum dependency set theory, setting predicate parameters, selecting proper predicates according to a preset target to form a necessary minimum condition set needed by an inference rule, and finally forming a rule set needed by the input of a MulVAL tool; meanwhile, constructing an input file of a MulVAL tool, and generating a logic attack graph and an attack chain by using the MulVAL tool; then constructing a technical node evaluation model and a vulnerability node evaluation model to comprehensively evaluate nodes in the logic attack graph, and performing normalization processing to obtain risk scores of the nodes; and finally, sorting the risk scores of the nodes according to the node types and reflecting the sorted risk scores in a logic attack graph. According to the method, the understanding depth of a potential attack path is improved, the accuracy of threat degree measurement is ensured, and then high-credibility threat information on an attack graph is fully reflected.
Owner:GUANGZHOU UNIVERSITY +1

A risk assessment method and system for large language model vulnerabilities

PendingCN122286781ALinguistic modelAttack
This invention discloses a risk assessment method and system for large language model (LLM) vulnerabilities, relating to the fields of artificial intelligence security and network security technology. The method includes the following steps: semantic-driven vulnerability modeling, constructing a large language model vulnerability feature identification model from three dimensions: attack mechanism, model behavior, and propagation impact; constructing a scoring system, introducing three key indicators—semantic manipulation complexity, model behavior impact, and attack propagation potential—onto the CVSS standard scoring mechanism; designing a scoring transfer judgment mechanism to calculate the score, obtaining the CVSS basic score, constructing an AI-extended risk factor for score transfer, the AI-extended risk factor being calculated from the quantified values ​​of the three key indicators and their corresponding weights, and using the AI-extended risk factor and the CVSS basic score to establish a comprehensive scoring function to obtain the comprehensive score. This invention achieves quantitative assessment and automated scoring of LLM vulnerabilities by extending new risk indicators based on CVSS.
Owner:TIANJIN UNIV

Machine learning techniques for generating common vulnerability scoring system vectors

ActiveUS20260119675A1Platform integrity maintainanceRating systemEngineering
Some embodiments provide techniques for generating common vulnerability scoring system (CVSS) vectors for vulnerabilities to use in scanning a computing environment for vulnerabilities. The techniques involve obtaining a textual description of a vulnerability; generating inputs for a plurality of ML models using the textual description of the vulnerability; providing the inputs to the plurality of ML models to obtain outputs indicating values of CVSS risk metrics; and storing the values of the CVSS risk metrics indicated by the outputs of the plurality of ML models in a vector to obtain the CVSS vector for the vulnerability.
Owner:RAPID7 INC

Vulnerability repair priority evaluation method, system and device and storage medium

PendingCN121389136APlatform integrity maintainanceVulnerability managementSecurity engineering
The invention discloses a vulnerability repair priority evaluation method, system and device and a storage medium, and the method comprises the steps: collecting vulnerability CVSS and EPSS scores, and carrying out normalization and discrimination enhancement processing; based on enterprise risk preference and asset exposure degree, respectively setting weights of CVSS and EPSS scores; performing weighted summation to obtain a vulnerability repair priority score; performing adaptive adjustment on the vulnerability repair priority score according to the vulnerability real-time influence; performing overall priority correction on the vulnerability repair priority score after self-adaptive adjustment in combination with a service scene, asset importance, historical processing conditions of vulnerabilities of the same type and a vulnerability introduction path length; and grading the vulnerabilities based on the vulnerability repair priority score after priority correction, and executing corresponding responses to different levels of vulnerabilities. According to the method, vulnerability management is changed from experience dependence to large-scale security engineering.
Owner:JIANGSU HONGXIN SYST INTEGRATION

A markov attack path prediction method based on cvss

The application discloses a Markov attack path prediction method based on CVSS, and specifically comprises the following steps: step 1, scanning network host vulnerability information to generate a configuration file of.nessus; step 2, generating an attack graph: importing the configuration file generated in the previous step into Mulval, associating information between various host vulnerabilities through Mulval, and generating an attack graph; step 3, constructing a state transition graph: obtaining a simplified state transition graph according to the attack graph generated in step 2; step 4, initializing a Markov probability transition matrix: obtaining a probability transition matrix according to the state transition graph; and step 5, predicting an attack path probability. The method adopts a mode of measuring attack benefits to accurately predict a path to a single vulnerability level, realizes multi-step and multi-time prediction, simplifies the prediction method, and solves the problems of path redundancy, rationality and effectiveness of prior probability setting in the prediction path of the Bayesian model.
Owner:XIAN UNIV OF TECH

Power network security vulnerability scanning evaluation method and system

The invention provides a power network security vulnerability scanning evaluation method and system, and relates to the technical field of power network security. The power network security vulnerability scanning and evaluating system comprises a master control server, a data acquisition module, a protocol analysis module, a vulnerability detection module and an intelligent analysis module, the data acquisition module, the protocol analysis module and the vulnerability detection module are all connected with the master control server, and the intelligent analysis module is carried in the master control server. The data acquisition module is connected with an agent module, and the agent module comprises a lightweight agent scanner and an agent-free scanning module unit. According to the method, the multi-modal risk assessment model is constructed, and the risk thermodynamic diagram conforming to industry characteristics is generated by integrating parameters such as vulnerability CVSS scores, power business influence degrees and repair complexity, so that the vulnerability priority ranking accuracy is greatly improved.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID NINGXIA ELECTRIC POWER COMPANY +1

Mama-based hot rolled steel strip defect detection method

The invention belongs to the field of machine vision and industrial detection, and aims to solve the problems that CNN global features are weak, Transform calculation is complex and traditional Mamba local features are incomplete so as to realize high-precision and high-efficiency detection of a hot rolled steel strip. The method comprises the steps that 1, a steel surface image is received, a balanced data set is constructed through DDIM data enhancement, and data scarcity is relieved; 2, inputting a pre-trained SpDCH-Mama model (based on SparX-Mama improvement, including a backbone, a CVSS, a Hybrid Enhancement and a detection head), wherein the backbone alternately extracts multi-scale features by a'DPE-DMCA-VSS 'ganglion layer and a'DPE-VSS' common layer; the CVSS is fused with DWConv, Star Block and the like to strengthen local-global feature collaboration; the Hybrid Enhancement initializes the CNN sub-branch of the convolution kernel through Sobel to extract the edge, the VSS sub-branch complements the global, and the dynamic weight and the three-dimensional regularization suppression are subjected to over-fitting; the detection head fuses the features to predict the defect category probability and the bounding box offset; and 3, generating a detection result containing defect types and positions. According to the method, on an NEU-DET data set, the mAP at 0.5 reaches 82.4%, the mAP at 95 reaches 0.464, the method is superior to YOLO series and the like, and the method is suitable for industrial real-time quality inspection.
Owner:GUILIN UNIV OF ELECTRONIC TECH

A Reinforcement Learning-Based Adaptive Policy Generation Method and System for Heterogeneous Resource Scheduling

This invention relates to a method and system for generating adaptive strategies for heterogeneous resource scheduling based on reinforcement learning, belonging to the field of cloud computing security. The system comprises a container module, a CVSS database exploitation module, a state mapping module, and a defense environment. The method includes: acquiring all container instances in the current cloud environment and storing them in a container pool; recording the heterogeneous attributes and replica count of each type of container instance; calculating the vulnerability exploitation difficulty and multi-dimensional heterogeneity indicators of the current container pool; and using a reinforcement learning model to determine the defense strategy, inputting the current container pool state into the model, deciding on the defense strategy, and calculating the reward value by weighted summation of the vulnerability exploitation difficulty and heterogeneity indicators of the container pool. This invention comprehensively considers the multi-dimensional heterogeneous attributes and real-time state information of containers, adaptively selecting the optimal defense strategy to reduce defense costs and improve the system's real-time response capability and defense effectiveness.
Owner:韩道岐

Threat intelligence intelligent analysis method based on large model and knowledge graph

The invention relates to a threat intelligence intelligent analysis method based on a large model and a knowledge graph. The threat intelligence intelligent analysis method comprises the steps of performing automatic cleaning, structured extraction and consistent storage on multi-source heterogeneous data; performing multi-modal information retrieval and association; dynamically prompting engineering and reasoning enhancement; threat research and judgment and output can be explained. According to the application, through a two-channel mixed framework in which atlas retrieval and vector retrieval are coordinated, an assembly line of keyword extraction, vector recall, atlas association, fusion duplicate removal and assembly prompting is used, recall coverage and conclusion interpretability are improved, a landing lightweight threat scoring and grading mechanism is provided, and CVSS, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp, ATTamp and ATTamp are CK stage information is combined with retrieval evidences to obtain a unified total score and four-level judgment, so that direct access to an automatic disposal process is facilitated, a structured prompt and an explainable output scheme for evidence alignment are provided, input is organized by using an evidence block, a map path abstract and an event timeline, all conclusions can be traced back to an original text and a link, and the result is more accurate. And processing suggestions oriented to assets and businesses are generated in a linkage manner.
Owner:GUANGZHOU UNIVERSITY

Attack path prediction method and device based on asset analysis and graph convolutional neural network

ActiveCN121690656BAttackEngineering
The present disclosure belongs to the technical field of nuclear power and specifically relates to an attack path prediction method and device based on asset analysis and graph convolutional neural network. The present disclosure realizes rapid positioning and prediction of attack paths and improves the foresight of network security defense by modeling asset vulnerability, constructing an attack graph and utilizing a graph convolutional neural network for reasoning. Through vectorization modeling of asset vulnerability, the present disclosure converts traditional discrete vulnerability evaluation into continuous feature representation, realizing accurate quantification from coarse-grained CVSS score to multi-dimensional vulnerability features. The graph convolutional neural network is introduced for attack path prediction, which can effectively capture high-order adjacency relationships and nonlinear dependence features between assets.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

Dynamic policy-based configuration baseline intelligent auditing system and method

The application discloses a dynamic policy-based configuration baseline intelligent auditing system and method, relates to the technical field of configuration baseline intelligent auditing, and comprises the following steps: standardizing and preprocessing a configuration baseline to be examined; constructing a time sequence trajectory graph based on a configuration baseline change record, predicting a potential risk trigger probability by adopting a lightweight time sequence analysis model, and generating an auditing priority list by combining configuration entropy and risk weight; simulating a preset attack scene in an isolated sandbox, verifying the defense resilience of the configuration baseline, and completing risk grading by combining a CVSS score. Through the standardization preprocessing step, the application realizes format normalization and redundant cleaning of configuration baselines from different sources, effectively solves the multi-source configuration heterogeneity problem, reduces errors caused by manual intervention, lays a precise data foundation for subsequent auditing links, and significantly improves the processing efficiency of large-scale configuration baselines.
Owner:SICHUAN RONGKE ZHILIAN TECH CO LTD

Attack path prediction method and device based on asset analysis and graph convolutional neural network

The invention belongs to the technical field of nuclear power, and particularly relates to an attack path prediction method and device based on asset analysis and a graph convolutional neural network. According to the method and the device, the asset vulnerability is modeled, the attack graph is constructed, and the graph convolutional neural network is used for reasoning, so that the attack path is quickly positioned and predicted, and the perspectiveness of network security defense is improved. Through asset vulnerability vectorization modeling, traditional discrete vulnerability assessment is converted into continuous feature representation, and accurate quantization from coarse-grained CVSS scoring to multi-dimensional vulnerability features is realized. The graph convolutional neural network is introduced to carry out attack path prediction, so that the high-order adjacency relation and nonlinear dependency characteristics among assets can be effectively captured.
Owner:CHINA NUCLEAR POWER OPERATION TECH CORP

Determining a security score in binary software code

Systems, methods, and software can be used to determine a security score of a binary software code. In some aspects, a computer-implemented method comprises: receiving a binary software code; inspecting the binary software code to determine at least one Common Vulnerability Scoring Standard (CVSS) factor; and determining a CVSS score based on the at least one CVSS factor.
Owner:BLACKBERRY LTD

A vulnerability assessment method and device for virtual resources, a storage medium and an electronic device

ActiveCN116961945BMitigating the risk of attacksImprove governance efficiencySecuring communicationAttackOpen source
The embodiment of the application provides a virtual resource vulnerability assessment method and device, a storage medium and an electronic device, the method comprises the following steps: obtaining the basic information of the vulnerability of the virtual resource, and performing basic score grading on the virtual resource according to the basic information of the vulnerability, to obtain a basic score; determining the vulnerability time factor score, the vulnerability environment factor score and the virtual asset factor score of the virtual resource according to the basic information of the vulnerability respectively; performing secondary vulnerability grading on the virtual asset according to the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual asset factor score, to obtain a secondary grading result; and generating a vulnerability assessment result of the virtual resource according to the secondary grading result, which can solve the problem that the CVSS vulnerability score cannot objectively reflect the influence of the vulnerability on the real environment in the related art, and through the secondary vulnerability grading on the basic score, the final vulnerability assessment result is obtained, the risk of open source software supply chain attack is alleviated, and the efficiency of open source governance is improved.
Owner:ZTE CORP

Method, device, equipment and medium for evaluating safety integrity level of oil and gas storage and transportation information physical system

PendingCN121069868AProgramme controlMathematical modelsSafety Integrity LevelPhysical system
The invention discloses an oil and gas storage and transportation information physical system safety integrity grade evaluation method, device and equipment and a medium, and relates to the field of oil and gas storage and transportation, and the method comprises the steps: employing a Cyber-HAZOP identification method to construct a corresponding information physical risk guide word for an oil and gas station; according to the guide word, identifying a network threat and a risk of a physical process; taking the risk as a top event of a Cyber-Bow-tie model, and adopting a set Cyber-HAZOP-Bow-tie mapping rule to establish a risk cross-domain evolution model based on the Cyber-Bow-tie so as to construct a cross-domain causal chain; in combination with a set Cyber-Bow-tie-LOPA mapping rule, an information physics cross-domain risk quantitative evaluation model is established; and based on the quantitative evaluation model and in combination with the CVSS score, determining the safety integrity level of the oil and gas station. Therefore, the method can adapt to the characteristics of strong coupling and multi-dimensional risk propagation of information physics in an oil and gas storage and transportation system, achieves the comprehensive analysis of an information physics risk coupling path, and remarkably improves the reliability of safety integrity level evaluation of the information physics system.
Owner:CHINA UNIV OF PETROLEUM (BEIJING)