The invention relates to the technical field of
network security, and discloses a security
vulnerability AI positioning method and
system based on log files. The method comprises the following steps: firstly, analyzing
user feedback describing
open source component security vulnerabilities to extract fault key entity information, screening related log entries based on the fault key entity information, and constructing a
vulnerability propagation graph; identifying a
vulnerability triggering
initial point set by using a
graph traversal algorithm and a graph neural network, calling a component vulnerability case
library to deduce a vulnerability utilization propagation chain and calculating a matching degree with a known
open source component vulnerability utilization chain feature, and obtaining a maximum probability vulnerability utilization propagation chain and an associated vulnerability triggering
initial point set; and generating a
root cause positioning report, and updating the
knowledge base or model training data according to a
user verification result. According to the method, the initial vulnerability point and the complete vulnerability propagation chain of the security vulnerability of the
open source component can be accurately and efficiently positioned, and the positioning accuracy and timeliness are improved.