The invention discloses a
vulnerability version
verification method,
system and equipment based on multi-source
heterogeneous information, and the method comprises the steps: obtaining
vulnerability information from a plurality of heterogeneous sources, extracting core elements, and carrying out formatting
processing and
verification to obtain structured
vulnerability entries; collecting or generating a concept
verification code, and positioning and generating through a vulnerability code if the concept verification code cannot be collected; performing automatic verification on the concept verification code, and recording a function call chain and a
system behavior; and migrating the successfully verified concept verification code to other versions of the
software, and determining the vulnerability influence range. The method further comprises the steps of selecting the core elements according to a preset priority rule, and
processing the core elements by adopting a conflict resolution rule; vulnerability code positioning comprises similarity calculation,
call graph analysis,
symbolic execution and large
language model generation; the automatic verification is executed and monitored in an
isolated environment;
code migration is realized by executing path
tree representation, binary code comparison and path alignment. According to the method, the influence range of the vulnerability in different
software versions can be accurately verified, and the vulnerability repairing efficiency is improved.