The application provides a
system vulnerability attack disposal method, program product, storage medium and equipment. In the method, based on asset topology data and component
vulnerability data of a target
system, an initial
attack graph is constructed, the influence of a
security policy of asset configuration is considered, the
attack success probability corresponding to each edge in the initial
attack graph is determined, the initial
attack graph is optimized, an optimized
attack graph is obtained, then, a
minimum cut set is solved in the optimized attack graph, and a minimum edge set capable of
cutting all paths from an initial node to a final node, that is, a minimum disposal set, is generated. In this way, by analyzing the minimum disposal set on the constructed attack graph, the
vulnerability disposal efficiency is effectively improved, the security operation cost is reduced, meanwhile, the attack graph is optimized according to the
security policy of asset configuration, the information expression of the attack graph is more accurate, and the accuracy of vulnerability disposal is improved.