Grade protection evaluation data acquisition and analysis method and system based on offline form

A technology of data acquisition and analysis method, which is applied in the direction of database distribution/replication, digital data protection, structured data retrieval, etc., and can solve problems such as increasing the high cost of enterprises, not supporting offline electronic form import function, unfavorable security situation, etc.

Active Publication Date: 2020-11-13
NARI INFORMATION & COMM TECH
View PDF2 Cites 4 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Under the MLPS 2.0 evaluation index system, the index composition is more diverse, the evaluation objects cover a wider range, and the evaluation report is more closely related, which increases the complexity of the evaluation work and evaluation data analysis process
[0004] In response to this situation, some institutions use Excel calculation tables or commercial evaluation tools to carry out equal guarantee evaluation work and evaluation data analysis work; however, the current existing technical means have the following problems: (1) The import function of offline electronic forms is not supported, The data collected offline must be entered manually, which reduces the efficiency of the overall evaluation work; (2) Risk analysis model is not adopted, the risk level is based on human subjective decision-making, and the subjective intervention of personnel is too strong, which affects the accuracy of risk analysis and evaluation quality; (3) The data collected offline is distributed on different PCs. Considering that people are the weakest link in network security, sensitive data is prone to the risk of information leakage; (4) The data summary analysis is completed by the report compilers, and the statistical analysis results are relatively one-sided , which is not conducive to comprehensive analysis of the industry's network security situation; (5) Commercial evaluation tools must install a set of client and database on each PC, and each PC needs to be paid and authorized before it can be used, which increases the high cost of the enterprise ;(6) For the method of using Excel to calculate the form, the accuracy of the calculation result depends on the logical judgment of the personnel, resulting in the fluctuation of the final calculation result and risk judgment

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Grade protection evaluation data acquisition and analysis method and system based on offline form
  • Grade protection evaluation data acquisition and analysis method and system based on offline form
  • Grade protection evaluation data acquisition and analysis method and system based on offline form

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0085] The present invention will be further described below. The following examples are only used to illustrate the technical solution of the present invention more clearly, but not to limit the protection scope of the present invention.

[0086] see figure 2 , an embodiment of the present invention provides a method for collecting and analyzing graded protection evaluation data based on an offline form, including:

[0087] (1) Collect the information of the system under test; the collected information includes the extended scenarios required by the level protection 2.0 series to which the system under test belongs, the business information security protection level (S) and the system service security protection level (A);

[0088] Further, the business information security protection level (S) refers to the protection level for system data security, and S is Security. The system service security protection level (A) refers to the protection level for ensuring system avail...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a grade protection evaluation data acquisition and analysis method and system based on an offline form, and belongs to the technical field of network security grade protectiondata processing. The method comprises the steps: defining and generating an offline data acquisition form according to the features of a tested system, and manually acquiring and reporting data; verifying, analyzing and cleaning the acquired data based on an application knowledge base, and then nesting a structured data retrieval engine; calculating and analyzing the structured data, and matchingsafety suggestions according to the risk points; and completing report ontology library construction, and calling a base block library to generate a report based on elements such as a report mother set and an attribute index. The data processing method integrating acquisition, analysis, calculation and display is constructed by taking improvement of the equal insurance evaluation operation efficiency, quantification of risk analysis results, reduction of manual judgment intervention and avoidance of distributed data leakage as targets, and informatization support means of front-end and rear-end work of equal insurance evaluation are enriched and standardized.

Description

technical field [0001] The invention relates to the technical field of network security level protection data processing, and aims to provide a method and system for collecting and analyzing level protection evaluation data based on an offline form. Background technique [0002] On June 1, 2017, the "Network Security Law of the People's Republic of China" was officially implemented, and the hierarchical protection work has now embarked on a legalization process. Against such a background, graded protection 2.0 came into being, and on May 13, 2019, the State Administration for Market Regulation and the National Standardization Management Committee officially released the Basic Requirements for Graded Protection of Information Security Technology and Network Security (GB / T 22239-2019) and other national standards, marking that the country has entered the 2.0 era of information security technology and network security protection. [0003] On the basis of 1.0, graded protectio...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F16/215G06F16/27G06F21/62G06F21/64
CPCG06F16/215G06F16/27G06F21/6227G06F21/64Y04S10/50
Inventor 唐亚东刘寅栾国强杨维永罗黎明朱世顺刘苇祁龙云秦学嘉张鹏丁晓玉徐杰
Owner NARI INFORMATION & COMM TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products