Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

82 results about "Vulnerability scanning" patented technology

Vulnerability scanning is an inspection of the potential points of exploit on a computer or network to identify security holes. A vulnerability scan detects and classifies system weaknesses in computers, networks and communications equipment and predicts the effectiveness of countermeasures.

Adaptive scanning concurrent number adjusting method under microgrid isolation

The invention relates to the technical field of intelligent power grid network security, in particular to an adaptive scanning concurrency number adjusting method under micro-grid isolation, which comprises the following steps: S1, respectively deploying load monitoring nodes in a control area, a non-control area and a management information area, collecting service load and network state data of each area in real time through the load monitoring node; and S2, based on the collected service load and network state data, constructing a concurrent number calculation formula, and through dynamic concurrent adjustment driven by the real-time load, the vulnerability scanning efficiency is ensured, and the service operation of each region of the micro-grid is prevented from being interfered.
Owner:GUIZHOU POWER GRID CO LTD

Centralized Vulnerability Security Scanning And Distributed Detection

Techniques for a centralized vulnerability security scanning and distributed detection system are disclosed. Some techniques set forth a set of operations including receiving, in a first cloud environment of a cloud system, image scan results from a second cloud environment of the cloud system, receiving container identity data from a particular deployed container of a set of deployed containers in the first cloud environment, based on a comparison between the image scan results and the container identity data, determining that the particular deployed container of the set of deployed containers is running a vulnerable software product, and generating, for presentation on a graphic user interface (GUI), information associated with the vulnerable software product. The image scan results correspond to a vulnerability scan of a plurality of software products running in the set of deployed containers.
Owner:ORACLE INT CORP

Agentless Workload Vulnerability Scanning

Systems and methods provide agentless security assessment for workloads and cloud posture control across multi-cloud environments. Discovery modules are configured with collection intervals to ingest posture control data including assets, identities, configurations, activities, network flows, and build-time artifacts. A multi-cloud configuration inventory maintains current and historical states and produces misconfiguration and identity-activity findings. For workload vulnerability evaluation, an external snapshot manager obtains point-in-time root-disk state without installing an in-workload agent. A file system data processor derives operating system and package metadata, and a detector matches the metadata against a vulnerability feed refreshed on a recurring basis to identify vulnerabilities. Identified vulnerabilities are correlated with misconfiguration and activity findings to generate prioritized risk exposures. Results are stored per workload and presented through graphical user interfaces that display risk levels, timelines, alerts, and guided remediation, enabling continuous, low-overhead security coverage for cloud workloads and configurations.
Owner:ZSCALER INC

Penetration testing method and system based on multi-source data association and risk aggregation

PendingCN121814444ASecuring communicationRisk quantificationCritical information infrastructure
The invention provides a penetration testing method and system based on multi-source data association and risk aggregation, and the method comprises the steps: firstly carrying out the automatic collection and normalization processing of heterogeneous security data from penetration testing, source code detection, vulnerability scanning and the like, and breaking an information island; and intelligent association and attack path discovery are carried out on discrete vulnerabilities based on an attack chain model, and a dynamic risk quantification model fusing a business influence weight and attack path complexity is innovatively introduced to carry out comprehensive risk assessment. According to the technical scheme, the problems of data splitting, single analysis dimension and disjunction between risk assessment and services of a traditional scheme are effectively solved, accurate identification and quantitative grading of composite attack chain risks are finally achieved, the safety analysis operation efficiency is remarkably improved, expert knowledge is solidified in the system, and the safety analysis efficiency is improved. And a visual and reliable data support is provided for safety investment decision-making of key information infrastructure industries such as power generation and the like.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Method, device and equipment for training vulnerability scanning strategy matching model

Embodiments of the present application provide a vulnerability scanning strategy matching model training method, device and equipment, and relate to the technical field of network security. The method comprises: obtaining vulnerability scanning records of network devices uploaded by a vulnerability scanning device, including: attribute information of the network devices, vulnerability scanning strategy parameters adopted by the vulnerability scanning device for scanning the network devices, and corresponding vulnerability scanning results; determining vulnerability scanning strategy target parameters corresponding to the network devices according to the vulnerability scanning strategy parameters and the corresponding vulnerability scanning results; generating device attribute samples according to the attribute information, and generating corresponding labels according to the corresponding vulnerability scanning strategy target parameters; generating a training set according to the samples and the labels; training a preset vulnerability scanning strategy matching model using the training set to obtain a model with strong matching capability, and then quickly matching vulnerability scanning strategy parameters corresponding to a network device to be scanned, i.e. a vulnerability scanning strategy, based on the model.
Owner:BEIJING RUIHESOFT CO LTD

Vulnerability scanning and attack detection methods, model training methods and devices

This application provides a vulnerability scanning attack detection method, model training method, and apparatus. The method includes: acquiring access logs and extracting key field information from the access logs; generating feature vectors based on the key field information; inputting the feature vectors into a vulnerability scanning attack detection model to obtain the analysis results output by the vulnerability scanning attack detection model; wherein, the vulnerability scanning attack detection model is obtained by pre-generating corresponding training feature vectors based on training logs, and training the model using the training feature vectors and labels used to characterize whether the training source IP address corresponding to the training logs exhibits vulnerability scanning attack behavior; the analysis results are used to characterize whether the behavior corresponding to the access logs is a vulnerability scanning attack behavior. This application improves the accuracy of vulnerability scanning attack behavior identification by analyzing the feature vectors of access logs using a machine learning model.
Owner:QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1

Method for securely deploying a software framework on a machine learning (ML) platform and a system thereof

The present disclosure provides a method for deploying the software framework on the ML Platform in a secure manner. In particular, the present disclosure provides a method for securely deploying the ML models or the algorithms into the system by providing a multi-level scanning procedure. In an embodiment, the disclosed method performs multiple vulnerability scans on the ML model or the algorithm at multiple stages to check for malware and ensure that only models / algorithms that pass the security checks are imported into the system. If the security scan detects vulnerabilities at any stage then the files are placed in a quarantined zone and the import process is terminated. Thereby protecting the system and making it cyber-secure.
Owner:HONEYWELL INTERNATIONAL INC

Method for vulnerability scanning and an arrangement for vulnerablity scanning

An arrangement and a method for vulnerability scanning in a network, the network comprising at least one host, such as an endpoint and / or a server. The method comprises collecting host specific information relating to resources of hosts in the network by detecting and / or analyzing processes executing at the hosts and / or network traffic at the hosts, the resources of the hosts relating to at least one of the following: processes being executed at the hosts, ports used by the hosts, protocols used by the hosts. The method further comprises building and / or updating a database comprising information relating to the hosts and resources of the hosts based at least in part of the collected host specific information and performing a vulnerability scan of the network by scanning the resources of the hosts at least in part based on the built database for the hosts.
Owner:F SECURE CORP

Trans-translation-unit code vulnerability scanning method, device and equipment and medium

The embodiment of the invention provides a cross-translation-unit code vulnerability scanning method and device, equipment and a medium, and the method comprises the following steps: carrying out static inspection on a target translation unit by using an abstract syntax tree, and extracting an external dependency relationship of the target translation unit based on a source code; on the basis of the extracted external dependency relationship, generating a dependency chain of the translation unit, deleting a circular reference in the dependency chain, and generating a dependency tree; according to the dependency tree, context information related to the target translation unit is loaded, and the context information comprises declarations, method signatures, function signatures, class definitions, macro definitions and namespace information; and assembling the loaded context information into a target translation unit, generating an assembled target translation unit, and executing a vulnerability detection tool to perform static vulnerability analysis on the assembled target translation unit. The efficiency and accuracy of cross-translation unit vulnerability analysis are improved through an incremental mode of loading the dependent content as required.
Owner:BEIHANG UNIV

A method for implementing island network vulnerability scanning based on Metasploit technology

ActiveCN117040815BComputer networkAttack
The application discloses a method for realizing island network vulnerability scanning based on Metasploit technology, which comprises the following steps: setting an intermediate machine with traffic relay function in the island network; connecting to the intermediate machine from an external network and building a Metasploit environment on the intermediate machine; penetrating the intermediate machine by using modular components and related attack technology in the Metasploit and obtaining the access right to the internal island network; scanning the host and running service in the island network by using the vulnerability scanning module in the Metasploit and transmitting the scanning result back to the intermediate machine. The method can discover and repair the possible security vulnerability in the island network, can comprehensively and deeply scan the island network, can flexibly scan the vulnerability and manage the security of the island network from the external network, and can transmit the scanning result back to the intermediate machine in real time to deal with the possible security threat in time.
Owner:YUNNAN POWER GRID CO LTD

Industrial control system network vulnerability scanning preprocessing method and system

The invention belongs to the technical field of industrial control network vulnerability scanning, and relates to an industrial control system network vulnerability scanning preprocessing method and system. Determining a system scanning boundary according to the network configuration information and the real-time flow data of the industrial control system, and obtaining a survival IP address list, an open port list and a scanning tolerance degree based on the system scanning boundary; obtaining a scanning task workload and scanning load intensity based on the survival IP address list, the open port list and the scanning tolerance degree, and generating a scanning task based on the scanning task workload and the scanning load intensity; and carrying out network vulnerability scanning according to the scanning task and obtaining an unverified vulnerability list, obtaining a vulnerability set according to the unverified vulnerability list and the threat score, and verifying the vulnerability set by utilizing POC. Invalid scanning and over-scanning can be avoided, the scanning range can be narrowed according to the characteristics of the industrial control system, and a reasonable scanning load is generated, so that the scanning time is effectively shortened. The false alarm rate of vulnerability detection can be reduced.
Owner:XIAN THERMAL POWER RES INST CO LTD

Container vulnerability detection method and device, equipment and medium

The invention discloses a container vulnerability detection method and device, equipment and a medium, which are used for carrying out container vulnerability detection with low performance overhead and low invasiveness. According to the method, when a container detection instruction is received, identification information, carried in the container detection instruction, of a target container is identified, a set probe is injected into the target container based on the identification information, software information related to the target container in the running process is collected based on the probe, and the target container is detected according to the collected software information. The software information is matched with the pre-constructed vulnerability database to determine whether the container has the vulnerability, so that an agent does not need to be installed in the container, no root file system is mounted, the target container is completely not invaded, container vulnerability scanning with low performance overhead and low invasiveness can be realized, and the vulnerability scanning efficiency is improved. The software information obtained based on the probe reflects the software really loaded and executed in the actual running process of the container, false alarm can be avoided by conducting vulnerability detection based on the software information, and the vulnerability detection accuracy is improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Vulnerability scanning identification method and system for cybersecurity testing

This invention discloses a vulnerability scanning and identification method and system for information security compliance testing, relating to the field of information security technology. The vulnerability scanning and identification system for information security compliance testing includes an information security compliance testing identification module and an information security compliance testing adjustment module. This invention solves the problem of confusion between traditional test traffic and normal business traffic by embedding an information security compliance testing coloring mark containing a unique identifier in the protocol header of the information security compliance testing end; combined with the continuous monitoring of TCP sequence numbers and the verification mechanism of acknowledgment messages on the information security compliance testing monitoring end, it can accurately distinguish between valid test requests and network noise or packet loss; by establishing a full-cycle context coloring state, it realizes full lifecycle monitoring of test requests from entry point to key nodes and then to the return result.

Method for realizing software bill of material creation management and software component analysis function based on block chain alliance chain and micro-service architecture

The invention discloses a method for realizing software bill of material creation management and software component analysis functions based on a block chain alliance chain and a micro-service architecture, and the method comprises the steps: S1, tool construction: constructing each micro-service business and an alliance chain multi-channel network required by a tool, and deploying an intelligent contract on the alliance chain; s2, user authentication is carried out, the user is managed, and a software component analysis platform / block chain access control problem is perfected; s3, generation and distribution of a software bill of material: for storage of the software bill of material, in combination with the block chain in the previous step, performing storage in a manner of "under-chain storage and on-chain indexing" so as to protect core data from being tampered while relieving the storage pressure of the block chain; and S4, license compliance and security vulnerability scanning: on the basis of the software material list, comparing existing vulnerability information and license information according to a specific scanning strategy for a certain software project, evaluating the vulnerability risk of the software project and checking the license violation condition of the software project, and finally forming a visual report.
Owner:NANJING KUANGJI INFORMATION TECH CO LTD +1

Data full-flow vulnerability collection method and device, equipment, storage medium and product

PendingCN121396832ASecuring communicationTime segmentJunction point
The invention provides a data full-flow vulnerability collection method and apparatus, a device, a storage medium and a product. The method comprises the steps of obtaining a historical work record; the historical work record comprises work stage time sequence information of the target object; based on the working stage time sequence information of the target object, determining the proportion of target junction points in each preset time period; the target handover point is a handover time point between a following stage and a previous stage of the following stage in the historical work record, and the following stage is a stage following the current stage of the target object in the historical work record; predicting the next stage of the target object from a plurality of following stages based on the proportion of the target intersection points in each preset time period; and when the current stage is completed, performing data full-flow vulnerability collection on the target object by adopting the predicted vulnerability scanning tool corresponding to the next stage. According to the method, more matched vulnerability scanning tools can be used in different stages of the target network and the system, and the overall vulnerability scanning effect is improved.
Owner:CHINA MOBILE GRP QINGHAI CO LTD +1

Vulnerability centralized management and control system and method for power monitoring system

The invention provides a centralized vulnerability management and control system and method for a power monitoring system, and relates to the technical field of power system network security, and the system comprises a plurality of distributed vulnerability collection devices which are used for executing non-intrusive lossless vulnerability scanning and collecting vulnerability data; the vulnerability centralized management system is used for issuing a vulnerability scanning task instruction, receiving vulnerability data, managing a vulnerability knowledge base and realizing summarization and synchronization of the vulnerability data; the vulnerability centralized management system is also used for storing vulnerability data of each security area and sharing data with the CSM platform; the CSM platform is used for generating a disposal work order after receiving the vulnerability data, and assigning the disposal work order to a corresponding disposal department; receiving a processing result fed back by the processing department, and transmitting the processing result to the vulnerability centralized management system; and the vulnerability centralized management system is also used for triggering a retest task according to the processing result, so that the corresponding vulnerability acquisition device executes retest. According to the scheme, vulnerability management and control can be effectively realized in time, and safe and stable operation of the power system is guaranteed.
Owner:NINGDONG POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER +1

Artificial intelligence network asset vulnerability scanning method, device, equipment, medium and program product

The application provides an AI network asset vulnerability scanning method and device, equipment, medium and program product, and relates to the technical field of network security automation and artificial intelligence. The method comprises the following steps: obtaining a vulnerability scanning request, wherein the vulnerability scanning request at least comprises a target unit name; obtaining a network asset list corresponding to the target unit based on the target unit name, wherein the network asset list is used for recording network asset information visible to the public network of the target unit; obtaining external script files cited in a corresponding webpage based on the network asset information; performing reverse analysis on the external script files by using a large model, identifying interface calling information and corresponding encryption logic information in the external script files; and performing network asset vulnerability scanning on the target unit based on the interface calling information and the encryption logic information.

Automatic penetration testing system

PendingCN121309146ASecuring communicationHosting environmentVulnerability scanning
The invention discloses an automatic penetration test system, and relates to the technical field of network security. The system comprises a man-machine interaction unit, an information collection and analysis unit, a vulnerability scanning and analysis unit, a penetration strategy decision unit, a penetration task execution unit, a tool calling auxiliary interface and a plurality of integrated test tools, the information collection and analysis unit comprises a host information collection and analysis sub-unit and a system configuration information collection and analysis sub-unit, and the various integrated test tools comprise an information collection tool, a vulnerability scanning tool and a penetration test tool which cooperate with one another to test the information collection tool, the vulnerability scanning tool and the penetration test tool. The purpose of making penetration test decisions and automatic testing according to the detected local area network host environment and features and penetration test tool features and functions can be achieved, then penetration test experience of experts can be replaced, repeated test steps and processes are automated, manpower and time cost consumed by enterprises is effectively reduced, and the efficiency of the enterprises is improved. And the penetration test efficiency is effectively improved.
Owner:CHENGDU GUOXINAN INFORMATION IND BASE CO LTD

Implementing Federal Information Processing Standards (FIPS) Compliance Checks Within the Software Development Process

PendingUS20260141078A1Reverse engineeringPlatform integrity maintainanceSoftware development processInformation processing
Systems and methods for implementing a FIPS compliance check within the software development process include receiving a Software Bill of Materials (SBOM) associated with software in production; performing a vulnerability scan based on the SBOM; extracting a list of dependencies of the software based on the SBOM and generating a list of cryptographic dependencies associated with the software; and generating a FIPS compliance report for the software based on the vulnerability scan and the list of cryptographic dependencies.
Owner:ZSCALER INC

Safety monitoring management method and system based on vulnerability scanning

The invention discloses a security monitoring management method and system based on vulnerability scanning, relates to the technical field of security monitoring, and solves the problems that vulnerability information and a risk assessment result cannot be effectively integrated with asset information, and operation and maintenance personnel are difficult to comprehensively understand the security condition of assets. According to the method, the state information of the power grid assets is collected in real time, online and offline, newly added or ownership change and other conditions of the equipment can be found in time, the dynamic changes are updated to the asset portraits in real time, and the real-time performance and accuracy of the asset information are ensured. Moreover, the vulnerability scanning result and the risk assessment result are closely combined with the power grid asset information to generate the asset portrait containing the vulnerability description, the severity level and the risk value, so that the operation and maintenance personnel can comprehensively understand the security condition of each asset. The control capability of operation and maintenance personnel on the safety state of the power grid assets is improved, the operation and maintenance personnel can be helped to quickly identify and preferentially process high-risk assets, and the overall safety of a power grid system is effectively improved.
Owner:GUANGXI POWER GRID CORP

Cloud host vulnerability scanning method and device, computer equipment, readable storage medium and program product

The invention relates to a cloud host vulnerability scanning method and device, computer equipment, a readable storage medium and a program product. The method comprises the following steps: in response to a vulnerability scanning instruction, obtaining software bill of material data of a target cloud host, and storing the software bill of material data in a graph structure; performing feature extraction on the software bill of material data to obtain multi-dimensional feature data; inputting the multi-dimensional feature data into a pre-trained graph neural network model to obtain a vulnerability prediction result, the training data of the graph neural network model including historical multi-dimensional feature data marked with a vulnerability type tag and an abnormal degree tag, and the prediction result including at least one of a vulnerability type, a vulnerability number and a vulnerability confidence; and based on the prediction result, generating and outputting a vulnerability scanning report of the target cloud host. By adopting the method, the comprehensiveness, accuracy and efficiency of vulnerability scanning can be improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method and device for flashing upgrade package of vehicle

The invention provides a method and a device for flashing an upgrade package of a vehicle, and relates to the technical field of vehicles, in response to the condition that a supplier passes multiple authentications, vulnerability scanning is performed on the upgrade package uploaded by the supplier, if the vulnerability scanning is not abnormal, encryption processing is performed on the upgrade package through a random secret key to obtain encrypted upgrade content, and the encrypted upgrade content is sent to the vehicle. The upgrade package and the random secret key are signed based on a Hash algorithm and a PKI system to obtain an abstract value, an encryption secret key and an upgrade package certificate; transmitting an encrypted upgrade package formed by combining the encrypted upgrade content, the abstract value, the encryption key and the upgrade package certificate to a main node corresponding to the upgrade scene, so that the main node performs certificate chain verification based on a preset root certificate and the upgrade package certificate; and if the hash algorithm verifies that the corresponding first hash value after the abstract value is unsigned is consistent with the second hash value corresponding to the original upgrading content, executing upgrading. Therefore, reliable updating of the vehicle system in a complex upgrading environment is guaranteed.
Owner:LIUZHOU WULING NEW ENERGY VEHICLE CO LTD

Methods, apparatus, computer equipment, and media for constructing a code repair knowledge base

This invention provides a method, apparatus, computer device, and medium for constructing a code repair knowledge base. The method includes the following steps: using multiple vulnerability scanning tools to perform static vulnerability scanning on the code recorded in a version control tool, recording each vulnerability and its corresponding vulnerability information; obtaining the commit records of the vulnerability locations in chronological order, detecting whether the vulnerability disappeared after the commit, and if the vulnerability disappeared, recording the commit information, code differences, and abstract syntax tree changes of the version control tool from the existence of the vulnerability to its disappearance; extracting vector features from the commit information, code differences, and abstract syntax tree changes, generating vectorized feature information; constructing a vector database using the vectorized feature information, and constructing a code repair knowledge base using the vector database. This solution improves the intelligence level of vulnerability repair by constructing a code repair knowledge base.
Owner:BEIHANG UNIV

Automatic operation and maintenance method and system for OA system based on multi-script collaboration

PendingCN121547262ASecuring communicationAttackTrace evidence
The invention discloses an automatic operation and maintenance method and system for an OA system based on multi-script collaboration, and the method and system achieve the full-life-cycle management from the initial deployment of a server cluster to the later continuous operation and maintenance through designing a series of automatic scripts which are decoupled in function and work cooperatively. According to the invention, an efficient, stable and safe automatic operation and maintenance system is constructed by modules such as an initialization script module, a service installation script module, an automatic backup script module, a service monitoring script module, a log cutting script module, a security defense script module, an artificial security defense script module, a backup data server and a central server; according to the method, the labor cost of OA system operation and maintenance is remarkably reduced, the system deployment efficiency, the service availability and the security protection capability are improved, the method is especially good at coping with common network threats such as CC attacks and vulnerability scanning, and detailed traceability evidence can be provided for network attack and defense drilling.
Owner:GUANGXI TEACHERS EDUCATION UNIV +1

Asset fingerprint identification method and device of intranet host

The invention aims to provide an asset fingerprint identification method and device for an intranet host. The method comprises the following steps: firstly, determining a survival host in an intranet in a stateless port scanning mode; secondly, further automatically acquiring detailed asset information according to a corresponding relationship between a preset port protocol and an asset information type; and finally, matching the obtained asset information with the fingerprint feature library to identify the fingerprint information of the assets, so that the intranet asset fingerprints can be rapidly and comprehensively identified. Meanwhile, asset transaction monitoring and asset vulnerability scanning are realized based on asset information, so that potential security risks of an intranet host can be found in time.
Owner:XIAN JIAODA JIEPU NETWORK SCI & TECH CO LTD

Systems and methods for translating different vulnerability scan results into a standardized format and for certifying target resources against detection of vulnerabilities

A computer-implemented method includes: receiving a request to scan a resource for detection of a vulnerability, the resource comprising one or more of: a component of an application, a code-base of the application, or a third-party library associated with the application; determining one or more matching vulnerability scanning operators among a plurality of vulnerability scanning operators based at least in part on one or more properties associated with the request; transmitting the request to the one or more matching vulnerability scanning operators, the one or more matching vulnerability scanning operators having access to the resource; receiving an initial result associated with the request from the one or more matching vulnerability scanning operators; obtaining a predetermined format for the initial result; generating a translated result by modifying the initial result based on the predetermined format; and transmitting the translated result to a source of the request.
Owner:CAPITAL ONE SERVICES LLC

Method and system for security evaluation of self-developed information system code in large enterprises

The application provides a large enterprise internal self-development information system code security evaluation method and system. The application uses code security visualization integrated management technology, distributed message queue technology, flow collection technology and vulnerability detection technology to realize security detection of enterprise internal self-development system code, high-risk vulnerability scanning, effectively solve the problem of frequent security vulnerabilities of self-development information system after online, and provide real-time reliable data support for the code security situation and information security situation of the development department at all levels for the company information management layer through the visualization integrated management technology. In addition, the application can be applied to the large enterprise internal self-development information system development team, and the information security vulnerability detection is carried out on the code side before the information system is online, so that the information security vulnerability can be found in time and effectively.
Owner:CHINA NAT PETROLEUM CORP +1

Vulnerability information processing method and device, and electronic equipment

This application provides a method, apparatus, and electronic device for processing vulnerability information, which can be applied to the field of vulnerability scanning technology. The method for processing vulnerability information includes: scanning a preset hierarchical folder to obtain a set of scan reports, wherein the set of scan reports includes at least one scan report obtained by scanning a device or system using at least one scanning tool, and the at least one scan report has at least one data structure; parsing the set of scan reports using a first rule; for scan reports in the set that fail to be parsed, sequentially switching to parsing using at least one second rule until parsing is successful, to obtain a set of vulnerability information; establishing a correspondence between at least one vulnerability identifier in the set of vulnerability information; and comparing multiple vulnerability information items in the set of vulnerability information based on the correspondence to obtain a vulnerability comparison result.
Owner:DAWNING CLOUD COMPUTING TECH CO LTD +1

A software trusted identification method based on distributed digital identity

This invention discloses a software trusted identification method based on distributed digital identity, comprising the following steps: Step 1, creation and storage of distributed digital identity for software; Step 2, intelligent generation of multi-source heterogeneous software bill of materials; Step 3, dynamic vulnerability management; Step 4, ensuring data flow and security. This invention achieves uniqueness, immutability, and cross-domain mutual recognition of software identity by constructing a distributed software identification system based on the W3C DID standard and combining a consortium blockchain and the InterPlanetary File System (IPS) dual storage engine; it achieves automatic extraction of dependencies from multiple heterogeneous projects and generation of dual-format software bill of materials files through a multi-language adapted intelligent software bill of materials parsing engine; it achieves accurate matching of component versions and vulnerabilities and minute-level response by constructing a local dynamic vulnerability database and introducing a semantic association rule engine; and it achieves decoupling and flexible expansion of identification management, software bill of materials generation, and vulnerability scanning through modular toolchain design.
Owner:HUZHOU COLLEGE

Asset vulnerability repairing method and device, equipment, storage medium and program product

The invention provides an asset vulnerability repairing method and device, equipment, a storage medium and a program product, and relates to the field of financial science and technology or other related fields. The method comprises the following steps: acquiring a vulnerability scanning report of a server cluster, and standardizing the vulnerability scanning report to obtain vulnerability scanning data of a target vulnerability; according to a vulnerability knowledge base and an asset fingerprint database, determining an asset identifier corresponding to the vulnerability identifier and an asset feature parameter corresponding to the asset identifier, the vulnerability knowledge base including a mapping relationship between the vulnerability identifier, the vulnerability type, the vulnerability influence range and the asset identifier, and the asset fingerprint database including a mapping relationship between the asset identifier and the asset feature parameter; and determining a target repair scheme of the target vulnerability according to the asset feature parameters, the vulnerability type and the vulnerability influence range, and repairing the target vulnerability according to the target repair scheme. According to the method, the problem of low decision efficiency caused by vulnerability and asset splitting is solved, the vulnerability scanning efficiency is improved, and accurate vulnerability positioning is realized.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA