Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

52 results about "Vulnerability management" patented technology

Vulnerability management is the "cyclical practice of identifying, classifying, prioritizing, remediating, and mitigating" software vulnerabilities. Vulnerability management is integral to computer security and network security, and must not be confused with Vulnerability assessment.

Internet of vehicles vulnerability management method, system and device based on block chain, and medium

The invention provides an Internet of Vehicles vulnerability management method, system, device and medium based on a block chain, and relates to the technical field of vehicle networks, the method can comprehensively identify potential safety risks of vehicles through a dynamic and static combined vulnerability detection mechanism, and generates a structured vulnerability report; hash abstract chaining evidence storage is performed on key data of reports and subsequent repair links by using a block chain, so that the whole process of vulnerability discovery, analysis and repair is ensured not to be tampered and traceable, and the authenticity and credibility of data are improved; the integrity of the report is verified at the cloud end, and an AI analysis engine is combined to associate a CVE database and threat intelligence, so that intelligent generation and decision support of a repair scheme are realized; the hash abstract on the chain of the OTA patch is verified at the vehicle end, so that the credibility of the patch source and the integrity of the content are guaranteed; and finally, through feedback of an installation result and secondary uplink archiving, complete closed-loop management from vulnerability discovery to repair verification is formed.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Collection analysis and utilization linkage method for full life cycle of vulnerability intelligence

PendingCN121530613AKnowledge representationSecuring communicationCollection analysisCritical information infrastructure
The invention discloses a collection, analysis and utilization linkage method for the full life cycle of vulnerability intelligence, which comprises the following steps: respectively acquiring original vulnerability intelligence of a plurality of heterogeneous data sources, and carrying out standardization processing on the original vulnerability intelligence to obtain vulnerability description information; constructing an asset knowledge graph, wherein the asset knowledge graph is used for representing IT asset objects in the enterprise and dependency and deployment relationships among the IT asset objects; performing graph traversal query on the vulnerability description information based on an asset knowledge graph, and identifying an affected asset list affected by vulnerabilities; and according to a preset response strategy, generating a safety response instruction from the affected asset list and sending the safety response instruction to the safety protection system. According to the method, the asset knowledge graph is constructed and the multi-source vulnerability information is subjected to standardization and mapping correlation analysis, so that the accurate and rapid identification of the affected assets of the power system and the automatic response strategy generation are realized, and the efficiency and the accuracy of the vulnerability management of the key information infrastructure of the power grid are effectively improved.
Owner:HUANENG POWER INT INC +1

Generative systems and methods for adaptive vulnerability management

Systems and methods are disclosed comprising instructions to collect vulnerability information over a network from a publishing source, collect network asset information of a communications network, generate a self-executing scanner agent configured to automatically scan the communications network for a known vulnerability based on an input including the collected vulnerability information and the collected network asset information, deploy the scanner agent at any network assets of the communications network that match a particular type of network asset indicated in the collected vulnerability information, generate a record including an indication of a particular network asset of the communications network in association with the known vulnerability in response to the scanner agent executing and detecting the known vulnerability in the particular network asset, and store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
Owner:T MOBILE US INC

Contextual vulnerability management

Techniques are described for providing a software-based platform for context-based vulnerability management of information technology (IT) environments. In some examples, a vulnerability management application collects vulnerability scan data, from potentially many different scanning agents, as well as vulnerability information from other third-party sources. The vulnerability management application also accesses asset and activity data associated with an IT environment. The vulnerability management application can provide a user interface contextualizing vulnerabilities, based on the contextual asset or activity data, allowing for user-configured or automated vulnerability risk adjustments to impact the management and remediation of vulnerabilities for the IT environment.
Owner:CISCO TECHNOLOGY INC

A network security vulnerability automatic management method based on network security intelligence

The application provides a network security vulnerability automatic management method based on network security intelligence, belongs to the field of network security vulnerability management, and is used for solving the problems of low automation, large risk assessment deviation and poor collaboration in the related art. The method comprises network security intelligence collection, screening, storage and analysis, attack path prediction, key asset identification, hazard scene enhancement and vulnerability management. Through technologies such as dynamic weight, high-order probability graph model and multi-agent game, accurate intelligence processing, dynamic risk quantification, attack forward-looking prediction and cross-enterprise collaborative disposal are realized, the vulnerability management efficiency and accuracy are improved, and the network security of the ECUs is ensured.
Owner:SONKWO COM

Data leakage protection and monitoring system

The invention discloses a data leakage protection and monitoring system, and relates to the technical field of data security supervision. The system specifically comprises a data classification and marking module, a data access control module, a data encryption module, a data monitoring and analysis module, a data auditing and reporting module, a data shielding and desensitization module and a threat intelligence and vulnerability management module. The data access control module sets different access permissions according to data classification and marks, the data encryption module carries out encryption protection on sensitive data, the data detection and analysis module monitors the flow and access conditions of the data, and the data auditing and reporting module records access and operation logs of the data. According to the method, an enterprise is helped to quickly deal with and solve security problems, the flow direction of the data is tracked, the source and the destination of the data are known, security holes and risk points in a data transmission path can be identified, and the enterprise is helped to enhance the security of data transmission.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Vulnerability management via a graphical interface

A computing machine displays a first interface region including indications of original software blocks and corresponding original vulnerability metrics, and a second interface region including subregions respectively associated with the original software blocks, each subregion presenting selectable compatible replacement software blocks and associated replacement vulnerability metrics. The computing machine presents aggregate vulnerability metrics including a first aggregate metric representing a count of vulnerabilities across the original software blocks and a second aggregate metric representing a count of vulnerabilities across indicated replacement software blocks. The computing machine receives a user selection of replacement software blocks for a selected subregion and responsively updates the associated replacement vulnerability metrics and the second aggregate metric to reflect vulnerabilities of the selected replacement software blocks. The computing machine displays a severity breakdown of vulnerabilities associated with at least one of the first aggregate metric or the second aggregate metric.
Owner:RAPIDFORT INC

A vulnerability patching method and system

ActiveCN122293434BAvoid additional scheduling overheadMaximize resource utilizationResource poolLower priority
The application provides a vulnerability repair method and system, and relates to the technical field of network security vulnerability verification and enterprise vulnerability management. The application obtains a task containing a vulnerability identifier, asset information and to-be-verified repair content, processes the task in parallel according to a pipeline split according to business execution steps, and configures a resource pool matching external dependencies for each stage; a stage fingerprint is generated when the task is transferred, a result is reused when a subtask is executed, otherwise the execution is scheduled according to vulnerability harm, asset importance and threat intelligence, and the vulnerability repair is completed according to the verification result. The application solves the problems of low throughput of the existing general pipeline, slow response of high-priority tasks, and easy starvation of low-priority tasks, and achieves the effect of collaborative optimization of throughput improvement, emergency task response acceleration and low-priority task starvation prevention without changing the original business and hardware.
Owner:CHINA UNICOM INTERNET OF THINGS CO LTD +1

Big model-based cvss intelligent scoring and repair decision method and system

The application provides a large model-based CVSS intelligent scoring and repair decision method and system, relates to the technical field of large model decision, and comprises the following steps: when it is detected that a CVSS score version is missing in vulnerability data information, a large model is used to analyze a CVSS index data set and output score index options, and a corresponding CVSS score is calculated; a risk repair data set is constructed according to asset information, vulnerability data and the CVSS score, a targeted repair scheme is generated by the large model, and the repair scheme is sent to a risk device for execution. The application realizes automatic completion of vulnerability scoring and generation of a device customized repair scheme, and improves vulnerability management efficiency.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

An intelligent network security situation monitoring and early warning platform for industrial control systems

ActiveCN116257021BMeet real-time monitoring and operation requirementsMeet traceable real-time monitoring operation requirementsTotal factory controlProgramme total factory controlData graphData acquisition
The application discloses an intelligent network security situation monitoring and early warning platform of an industrial control system, which comprises a device layer, a data acquisition layer, a data storage layer, an application service layer and a display layer; wherein the device layer comprises an industrial control host module, a network device module, a security device module and a third-party system; the data acquisition layer comprises an agent, a flow probe and a log collector; the data storage layer comprises a Redis cache, a MySQL database, an ELK real-time data analysis system and a Hadoop big data processing ecological module; distributed storage is adopted; the application service layer comprises an asset management module, a vulnerability management module, a threat analysis module, a workbench, a knowledge base, a data source management module, an alarm management module, a report management module, a device management module and a system management module; and the display layer comprises operation and maintenance monitoring, asset statistics, risk display and an industrial network topology, and is used for abstracting data and graphically displaying and providing visual display for final security operation.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE

Methods for handling code vulnerabilities

This application discloses a method for handling code vulnerabilities, relating to the field of vulnerability management technology. The method includes: scanning a target code segment to obtain initial vulnerability data, extracting features to form an initial vulnerability feature set, and obtaining category feature vectors; using a false positive detection model to filter the initial vulnerability feature set to obtain a vulnerability feature set; using a retrieval-enhanced generative agent to determine the false positive vulnerability feature set and non-false positive vulnerability feature set within the vulnerability feature set, as well as the corresponding processing actions; executing the processing actions to obtain the corresponding processing results, thereby determining the actual vulnerability data of the target code segment. This method solves the technical problems of dependency on project-specific code structures, difficulty in cross-project reuse, lengthy and difficult-to-maintain false positive lists as project scale expands, and increased maintenance costs due to code modifications leading to the recurrence of false positives. It achieves real-time analysis and processing, not only with high accuracy but also by generating effective processing solutions, thereby improving work efficiency.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Information security-based vulnerability management and control method and system

The application provides a vulnerability management and control method and system based on information security, which is applied to a vulnerability management and control system of information security, and comprises a server, a security vulnerability scanning module and a security management and control module. The security vulnerability scanning module is used for scanning security vulnerabilities, and the security management and control module is used for performing security management and control on the security vulnerabilities. First, the security vulnerabilities are scanned out by the security vulnerability scanning module, and are classified by the server according to types. Then, the security vulnerabilities are managed by the security management and control module according to strategies. Finally, the server proposes a high-risk and low-risk security patch upgrade package according to the high-risk and low-risk security vulnerabilities. The application can perform security management and control on the security vulnerabilities in a network, and has high practicability.
Owner:SHENZHEN POWER SUPPLY BUREAU

A vulnerability risk reachability analysis method, electronic device and storage medium

The present application relates to the technical field of data analysis, and particularly relates to a vulnerability risk reachability analysis method, an electronic device and a storage medium, wherein the initial risk evaluation value of a vulnerability is obtained by performing vulnerability scanning analysis on target code, and the reachability analysis weight is determined in combination with the path reachability analysis value and the conditional reachability analysis value, and finally the target risk evaluation is obtained, the actual possibility of the vulnerability being exploited is fully considered, compared with the traditional risk assessment based on inherent harm only, the real risk degree of the vulnerability can be more accurately reflected, a more reliable basis is provided for security decision, the target risk evaluation value can provide a reference for resource allocation, high-risk vulnerabilities can be preferentially processed in the vulnerability repair process, blind repair of vulnerabilities is avoided, and the efficiency of vulnerability management is greatly improved.
Owner:QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD

Cybersecurity vulnerability management program evaluation system

Methods and systems described herein are directed to measuring cybersecurity vulnerability management programs and readiness. A vulnerability management program evaluation system can define vulnerability management capabilities and technologies supporting execution of those capabilities. Once defined, the system can conduct an initial assessment including scoring for the capabilities representing a depth of vulnerability management, as well as scoring for the technologies representing a breadth of vulnerability management. To update the initial assessment, the system can track the ongoing progress of projects that can affect the depth and / or breadth of vulnerability management, and then recalculate the scoring. At any time, the system can combine the depth and breadth to determine a comprehensive vulnerability management score.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Blockchain-based methods, systems, devices, and media for managing vulnerabilities in the Internet of Vehicles (IoV).

This invention provides a blockchain-based method, system, device, and medium for managing vehicle network vulnerabilities, relating to the field of vehicle network technology. The method utilizes a dynamic and static vulnerability detection mechanism to comprehensively identify potential vehicle security risks and generate structured vulnerability reports. By using blockchain to hash and store key data from the report and subsequent remediation processes, the entire process of vulnerability discovery, analysis, and remediation is tamper-proof and traceable, enhancing data authenticity and trustworthiness. Cloud-based verification of report integrity, combined with an AI analysis engine linking CVE databases and threat intelligence, enables intelligent generation and decision support for remediation solutions. On-vehicle verification of OTA patches via on-chain hash digests ensures the credibility of patch sources and the integrity of content. Finally, feedback on installation results and re-archiving on the blockchain completes a closed-loop management system from vulnerability discovery to remediation verification.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Intelligent pre-boot indicators of vulnerability

A disclosed method provides a Device Integrity and Zero Trust (DIZ) protocol to implement proactive as well as reactive firmware vulnerability management. The DIZ protocol identifies device-level firmware versions and vulnerabilities and dynamically compiles appropriate firmware updates. The protocol may further construct a telemetry of the security vulnerability statistics for dynamic identification of Signs of Compromise (SoC) and collectively interpret various other platform telemetry stats for compiling vulnerability resolutions. An artificial intelligence (AI) based scalable and continuous Adaptive and Trust Assessment (ATA) method is employed for dynamic integration of partner solutions based on threat intelligence and remediation data. Disclosed solutions may further implement a geo location independent security adaption method. The identification and assessment of SoCs beneficially reduces an attacker's ability to breach an organization's IT systems. The DIZ protocol weeds out low-risk items from telemetry stats, and intelligently focuses on items most in need of remediation.
Owner:DELL PROD LP

Application-based vulnerability management method, device, medium and equipment

Embodiments of the present application provide a kind of based on application program's vulnerability management method, device, medium and equipment, the method includes: obtaining the vulnerability information of vulnerability to be detected;According to the positioning information, obtain the target development process execution file corresponding to the vulnerability to be detected;Judge whether the actual execution result of each link in target development process execution file is consistent with the expected execution result corresponding to vulnerability type;If not consistent, then the actual execution result and the expected execution result are not consistent in target development process execution file with the exception link marked. Utilize the embodiment of the present application, by setting the execution rule in each key link in development process execution file. After the vulnerability of application program appears, by comparing the actual execution result of each link in development process execution file with the expected execution result corresponding to the vulnerability type of the vulnerability to be detected, then the specific existing link of the vulnerability to be detected is located in development process execution file, and the specific reason of the vulnerability to be detected is analyzed.
Owner:PING AN TECH (SHENZHEN) CO LTD

Block chain client vulnerability management system and method based on artificial intelligence

The invention discloses a block chain client vulnerability management system and method based on artificial intelligence, and relates to the technical field of block chains, and the method comprises the steps: obtaining to-be-transmitted data and operation state information of nodes in a block chain; performing data fragmentation on the to-be-transmitted data; the sending end establishes a mapping relation between the data pieces, the sending end sends the data pieces to the receiving end through point-to-point transmission, and the sending end sends the hash values of the data pieces and the mapping relation between the data pieces to the receiving end through a block chain; the receiving end obtains data to be transmitted according to the mapping relation between the data pieces; according to the method, the to-be-transmitted data is fragmented, a mixed architecture of point-to-point transmission and block chain transmission is established, the integrity of the data is verified by using the non-tampering characteristic of the block chain, meanwhile, the direct transmission of the data in the block chain is reduced, the block chain nodes through which the data pass are reduced, and the security of the data is improved.
Owner:EAST CHINA UNIV OF TECH

Vulnerability tracking using scope and normalized offset

Source code is managed through a source code management system and one or more static application security testing scanners check the source-code for vulnerabilities. The scanners generate vulnerability reports that are processed by a vulnerability tracker. The vulnerability tracker computes the scopes of identified vulnerabilities from the source-code and generates scope and normalized offset fingerprints (e.g., hashes that uniquely identify vulnerabilities based on their surrounding scope). The fingerprints can be used for deduplication and vulnerability tracking. The vulnerability tracker may generate a refined vulnerability report that includes a set of deduplicated vulnerabilities with the corresponding fingerprints. The refined vulnerability report and related data may be stored in a vulnerability database for use in vulnerability management.
Owner:GITLAB INC

Ai-driven vulnerability management for legacy medical systems with advanced detection and proactive mitigation

One or more systems, devices, computer program products and / or computer-implemented methods of use provided herein relate to AI-driven vulnerability management for legacy medical systems. Accordingly, a system can comprise a memory that can store computer executable components. The system can further comprise a processor that can execute at least one of the computer executable components that collects information pertaining to a legacy medical system. In various aspects, at least one of the computer executable components can further leverage an artificial intelligence model and Retrieval Augmented Generation to detect a vulnerability in the legacy medical system. In various instances, the system can further generate a mitigation strategy for correcting the detected vulnerability. In various aspects, at least one of the computer executable components can further implement the mitigation strategy, thereby mitigating the detected vulnerability.
Owner:GE PRECISION HEALTHCARE LLC

A vulnerability management method, device, storage medium and computer device

PendingCN122513164AVulnerability managementLife stage
The application provides a vulnerability management method and device, a storage medium and a computer device, wherein the method comprises: obtaining and storing asset vulnerability information corresponding to a target organization; for each vulnerability data, determining a target stage currently occupied by the vulnerability data from each life stage included in a preset vulnerability life cycle; according to the target stage, marking a state of the vulnerability data and interacting with a target person having a target agency authority matched with the target stage; generating interaction description information according to an interaction result, and determining a new target stage currently occupied by the asset vulnerability from the each life stage according to a target stage corresponding to a current state mark; the interaction description information is used for feedback to a corresponding target person in the new target life stage; returning to the step of marking a state of the vulnerability data according to the target stage until the stored vulnerability data is cleared.
Owner:HANGZHOU DPTECH TECH

Remote sensing satellite network security situational awareness method and system with dual prevention mechanism

ActiveCN121151901BImprove real-time performanceImprove collaborative decision-making capabilitiesMathematical modelsNetwork topologiesData setAttack
This invention discloses a remote sensing satellite network security situational awareness method and system with a dual prevention mechanism. The method includes: acquiring multi-source heterogeneous data from a remote sensing satellite ground system network; generating a structured dataset through cleaning, denoising, and standardization; recording network assets using an asset identification algorithm based on the structured dataset; and generating a risk heatmap of the network assets using a Bayesian network model and entropy weighting method; detecting abnormal traffic and behavior using a deep learning model based on the risk heatmap and the structured dataset; and generating a priority-marked list of vulnerabilities using a general vulnerability scoring standard and a threat intelligence database; and constructing a dynamic security situation map using a graph database and community discovery algorithm based on the risk heatmap and the vulnerability list. This invention improves the real-time fusion capability of multi-source heterogeneous data, enhances the dynamic attack chain reasoning mechanism, and enables collaborative decision-making for risk warning and vulnerability management.
Owner:NAT SATELLITE METEOROLOGICAL CENT

A security vulnerability management system of an intelligent networked vehicle terminal

The application relates to the technical field of data processing, in particular to a security vulnerability management system of an intelligent networked vehicle vehicle-mounted terminal, which comprises a data acquisition module used for acquiring event control data; a preliminary probability module used for calculating the preliminary abnormal probability of an event; an abnormal probability module used for obtaining the same event as a target event corresponding to an initiating terminal, and adjusting the preliminary abnormal probability of the target event in combination with the occurrence frequency of the event to obtain the abnormal probability of the target event; a control abnormality module used for calculating the continuous control abnormality parameter of the target event according to the control relationship of different events on the initiating terminal and the receiving terminal, and the sequence before and after the event occurs, and in combination with the abnormal probability of the event; and a vulnerability management module used for performing vulnerability risk assessment and repair by using the abnormal probability and the continuous control abnormality parameter of the event. The application guarantees the safety and reliability of the communication process of the intelligent networked vehicle.
Owner:CHINA MASCH HUANYU CERTIFICATION & INSPECTION CO LTD +1

A software trusted identification method based on distributed digital identity

This invention discloses a software trusted identification method based on distributed digital identity, comprising the following steps: Step 1, creation and storage of distributed digital identity for software; Step 2, intelligent generation of multi-source heterogeneous software bill of materials; Step 3, dynamic vulnerability management; Step 4, ensuring data flow and security. This invention achieves uniqueness, immutability, and cross-domain mutual recognition of software identity by constructing a distributed software identification system based on the W3C DID standard and combining a consortium blockchain and the InterPlanetary File System (IPS) dual storage engine; it achieves automatic extraction of dependencies from multiple heterogeneous projects and generation of dual-format software bill of materials files through a multi-language adapted intelligent software bill of materials parsing engine; it achieves accurate matching of component versions and vulnerabilities and minute-level response by constructing a local dynamic vulnerability database and introducing a semantic association rule engine; and it achieves decoupling and flexible expansion of identification management, software bill of materials generation, and vulnerability scanning through modular toolchain design.
Owner:HUZHOU COLLEGE

Vulnerability repair priority evaluation method, system and device and storage medium

PendingCN121389136APlatform integrity maintainanceVulnerability managementSecurity engineering
The invention discloses a vulnerability repair priority evaluation method, system and device and a storage medium, and the method comprises the steps: collecting vulnerability CVSS and EPSS scores, and carrying out normalization and discrimination enhancement processing; based on enterprise risk preference and asset exposure degree, respectively setting weights of CVSS and EPSS scores; performing weighted summation to obtain a vulnerability repair priority score; performing adaptive adjustment on the vulnerability repair priority score according to the vulnerability real-time influence; performing overall priority correction on the vulnerability repair priority score after self-adaptive adjustment in combination with a service scene, asset importance, historical processing conditions of vulnerabilities of the same type and a vulnerability introduction path length; and grading the vulnerabilities based on the vulnerability repair priority score after priority correction, and executing corresponding responses to different levels of vulnerabilities. According to the method, vulnerability management is changed from experience dependence to large-scale security engineering.
Owner:JIANGSU HONGXIN SYST INTEGRATION

System and method for multi-source vulnerability management

A method for multi-source cloud infrastructure vulnerability management includes receiving cloud element information related to a cloud-based element in a cloud environment. The method also includes receiving first vulnerability information from a first vulnerability source and receiving second vulnerability information from a second vulnerability source. Cloud element context information is also received from the cloud environment regarding the cloud-based element. A multi-source vulnerability database is then generated from both the first vulnerability information and from the second vulnerability information. The cloud element information and the cloud element context information are then evaluated using the multi-source vulnerability database to generate a vulnerability assessment.
Owner:F5 NETWORKS INC

Method and device for analyzing vulnerability influence of open source component, and electronic equipment

The invention discloses an open source component vulnerability influence analysis method and device, and electronic equipment, and relates to the technical field of project development, the method comprises the following steps: calling a dependency graph associated with all development projects of a target enterprise, the dependency graph comprising node types of all data nodes and dependency relationships among the data nodes, the dependency relationship comprises a direct dependency relationship and a transitive dependency relationship; a dependency graph is adopted to analyze a dependency relationship and a cross-project chain of a vulnerability API of an open source component, component dependency chain information is obtained, a vulnerability influence result is analyzed based on the component dependency chain information, and fields included in the vulnerability influence result at least include a vulnerability influence path, a vulnerability level, an influence service number and a service environment. The technical problem that in the related technology, an open source component vulnerability management tool cannot determine the actual influence range of vulnerabilities, and safety risks faced by enterprises are increased is solved.
Owner:CHINA TOWER CO LTD

Comprehensive product type selection evaluation method based on autonomy of information system

PendingCN121638682AResourcesManufacturing computing systemsThe InternetAcquisition technique
The invention discloses a comprehensive product type selection evaluation method based on autonomy of an information system, and relates to the technical field of autonomy of the information system, and the method comprises the steps: carrying out the all-directional and multi-angle evaluation of candidate products through setting a plurality of dimensions, including performance, safety and technical suitability; specific characteristic parameters are subdivided under each dimension, in the performance aspect, such as processing speed, response time and resource occupancy rate, in the security aspect, such as encryption, authentication, authorization, auditing and vulnerability management, in the technical suitability aspect, such as compatibility with the system and integration difficulty. In addition, big data and Internet acquisition technologies are adopted to obtain feedback records of the user on the information system product, and bid evaluation of the characteristic parameters is determined according to the feedback records; meanwhile, by calculating the distance from the characteristic parameter corresponding to each quality attribute of each candidate product to bid evaluation and dividing a characteristic parameter evaluation interval, powerful support is provided for product model selection.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Vulnerability management method and device, storage medium and product

The invention discloses a vulnerability management method and device, a storage medium and a product, and relates to the technical field of security vulnerability management, and the method comprises the steps: carrying out the multi-dimensional risk assessment of a to-be-managed vulnerability, and obtaining an initial risk score of the to-be-managed vulnerability; collecting dynamic data of to-be-managed vulnerabilities, and updating the initial risk score in real time through the dynamic data to obtain a standard risk score; and sorting the to-be-managed vulnerabilities based on the standard risk scores to obtain a repair priority sequence of the to-be-managed vulnerabilities. According to the method, comprehensive and accurate assessment of the vulnerability risk is realized, the obtained standard risk score fits the threat situation of the vulnerability in real time, the repair resource distribution can be effectively optimized according to the repair priority sequence, the vulnerability management repair efficiency is improved, and the system security risk is remarkably reduced.
Owner:VIPSHOP (GUANGZHOU) SOFTWARE CO LTD

Vulnerability assessment of machine images in development phase

In an embodiment, a software object development system generates a pre-release version of a machine image of a software object, and transmits information associated with the pre-release version of the software object to a vulnerability management system. The vulnerability management system performs a vulnerability scan for known vulnerabilities(s) on the information associated with the pre-release version of the machine image of the software object. The vulnerability management system determines scan result(s) based on the vulnerability scan, and transmits, to the software object development system, a report comprising the scan result(s).
Owner:TENABLE INC