Asset library model security risk situation assessment system and method thereof
Through multi-source streaming data fusion, multi-layer asset association map and reinforcement learning decision-making framework, the problem that existing technology is difficult to capture dynamic threats in real time and accurately evaluate risk propagation is solved, real-time risk assessment and adaptive defense of the asset library are achieved.
Patent Information
- Application Number
- CN202510323614.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing asset risk assessment methods are difficult to capture dynamic threats in real time, and they cannot accurately evaluate the spread path and impact range of risks between assets, resulting in lagging defense measures.
The multi-source streaming data fusion engine and distributed edge computing nodes are used for real-time data integration and feature extraction, and the attack path is simulated based on the multi-layer asset association map and Monte Carlo method, combined with the reinforcement learning decision framework and incremental model updates, to realize adaptive decision optimization and real-time risk assessment.
Real-time monitoring and risk assessment of dynamic threats are achieved, accurate analysis of asset associations and risk propagation, timely response to new attacks, and improved the real-time and accuracy of defense measures.
Smart Images

Figure CN120145400A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of asset risk assessment systems, and in particular to an asset library model security risk situation assessment system and method thereof. Background Art
[0002] Under the general trend of digital transformation, the asset libraries of various organizations are becoming increasingly large and complex, covering a variety of assets from IoT devices, network facilities to critical business systems. Asset security risk situation assessment is crucial for ensuring the stable operation of organizations and data security. Existing risk assessment methods are mostly based on static models and rule-driven, and it is difficult to cope with the dynamically changing network threat environment, there are technical bottlenecks. For example, the patent with the patent publication number CN113656802A relies on periodic manual inspections and offline data analysis, and the assessment cycle is usually at the hour level or even the day level. This assessment cannot capture dynamic threats such as zero-day attacks and lateral infiltrations, resulting in lagging defense measures. Traditional data fusion methods are difficult to meet the real-time requirements and cannot provide comprehensive and accurate data support for risk assessment in a timely manner. On the other hand, the association relationships between assets are intricate, involving multiple dimensions such as functional dependencies, data flow dependencies, and physical connections. Existing risk assessment models often cannot fully consider these complex association relationships, and it is difficult to accurately assess the propagation paths and influence scopes of risks among assets, resulting in the inability to predict high-risk areas in advance and take preventive measures in a timely manner. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to overcome the defects existing in the prior art. The present invention proposes an asset library model security risk situation assessment system and method thereof.
[0004] To solve the above technical problems, the technical solution adopted by the present invention is: An asset library model security risk situation assessment system, including:
[0005] A data collection and processing subsystem, including: a multi-source streaming data fusion engine for real-time integration of IoT device sensor data, network traffic logs, and external threat intelligence streams; a distributed edge computing node unit deployed on terminal devices to perform data denoising and feature extraction, and transmit the compressed data to the central server;
[0006] A dynamic risk assessment subsystem, including: a multi-layer asset association graph construction module for constructing the functional dependencies, data flow dependencies, and physical connection relationships of assets in the resource library based on a graph database; a risk propagation probability calculation module for simulating the conduction path of attacks from edge nodes to core resources using the Monte Carlo method; a time-sensitive analysis module for dynamically adjusting the threat weights in different time periods through a sliding window mechanism;
[0007] The adaptive decision-making optimization subsystem includes a reinforcement learning decision-making framework that takes asset risk values, network topology status, and real-time threat intelligence as input states, generates risk mitigation actions, and optimizes strategies based on a reward function; an incremental model update module that enables the risk assessment model to continuously absorb new attack feature data without full retraining.
[0008] The visualization and feedback control subsystem includes a risk tracing visualization interface that highlights key factor combinations leading to high risks through an attention mechanism; a digital twin attack and defense sand table that simulates the blocking effects of different defense scenarios on the attack chain.
[0009] A closed-loop feedback control loop where the user operation data of the visualization and feedback control subsystem adjusts the data collection priority of the data collection and processing subsystem in reverse, and the policy output of the adaptive decision-making optimization subsystem updates the analysis parameters of the dynamic risk assessment subsystem in real time.
[0010] Preferably, the multi-source streaming data fusion engine is connected to the CVE vulnerability database, the dark web transaction monitoring platform, and the open-source intelligence aggregator in real time through an API. The data association and matching unit uses the cosine similarity algorithm to map the vulnerability features in the external threat intelligence to the device fingerprint information in the asset library in real time, generating a vulnerability-asset association matrix.
[0011] Preferably, the multi-layer asset association graph construction module defines a dependency strength index, quantifies the business continuity impact factor between assets, and uses a dynamic key node identification algorithm to calculate the node importance score.
[0012] Preferably, for the key node identification, the formula is: where PR(A i ) represents the importance score of asset node A i , d is the damping coefficient, ω i is the business impact factor, e ji is the dependency weight from asset A j to A i , and In(A i ) and out(A i ) respectively represent the sets of assets pointed to and pointed from by A i .
[0013] Preferably, the calculation formula for the dependency strength index defined in the multi-layer asset association graph construction module is D ij = α·log(1 + T com ) + β·S data , where T com is the communication frequency per unit time between assets i and j, S data is the transmission data sensitivity level, and α and β are dynamic adjustment coefficients.
[0014] Preferably, the formula for calculating the attack success probability by the Monte Carlo method in the attack chain simulation is as follows: where N is the total number of simulations, and Path k represents the path of the attacker from the edge node to the core resource in the k-th simulation, and p ij represents the single-step success probability of the attack penetrating from asset A i to A j .
[0015] Preferably, the risk propagation probability calculation module performs, based on the Markov chain Monte Carlo method, simulating the lateral movement path of the attacker in the graph, setting a dynamic termination condition: stopping when the length of the simulated attack path exceeds a preset threshold or reaching the core asset, outputting a heat map of the attack success probability, and marking high-risk conduction paths.
[0016] Preferably, the reinforcement learning decision framework adopts the twin-delayed deep deterministic policy gradient algorithm, and its reward function is:
[0017] R t = α·(TPR t - FPR t ) + β·e -td / τ + γ·log(1 + C c ), where TPR t is the true positive rate of risk prediction at time t, FPR t is the false positive rate at time t, t d is the delay time from risk identification to response action, C c is the number of affected core resources, and α, β, γ, τ are dynamic adjustment coefficients, which are automatically adjusted according to the system operation stage.
[0018] Preferably, the twin-delayed deep deterministic policy gradient algorithm adopts a prioritized experience replay mechanism, and assigns higher sampling weights to training samples with the following features, including decision trajectories that lead to damage to core assets, historical records of emerging attack patterns, and false alarm events actively corrected by users.
[0019] A method for assessing the security risk situation of an asset library model includes the following steps:
[0020] S1, real-time data fusion and feature extraction. Through distributed edge computing nodes deployed on terminal devices, real-time collection of IoT sensor data, network traffic logs, and external threat intelligence streams is carried out; a sliding time window mechanism is used to perform time alignment on multi-source data, and data denoising and feature vector extraction are performed; the processed data stream is compressed and transmitted to the central server, and is associated and matched with the CVE vulnerability database in real time;
[0021] S2, Dynamic risk assessment and propagation simulation. Construct a multi-layer asset association graph based on a graph database, define the functional dependence strength index, and use the Markov chain Monte Carlo method to simulate the attack path, and terminate the simulation when the conditions are met;
[0022] S3, Adaptive decision-making and feedback optimization. Input the asset risk value, topological state, and threat intelligence into the reinforcement learning framework of the double-delay deep deterministic policy gradient algorithm. Generate risk handling strategies through the reward function, and trigger incremental model updates. Dynamically adjust the data collection priority and the weights of the graph nodes according to the user's interactive operations on the attack path heat map in the visualization interface;
[0023] S4, Closed-loop defense execution. Verify the effectiveness of the handling strategy through a digital twin attack and defense sand table, automatically send defense instructions to the security device to execute the strategy, record the actual defense effect, and feedback it to the reinforcement learning experience pool to complete closed-loop optimization.
[0024] Compared with the prior art, the beneficial effects of the present invention are as follows: Through the multi-source streaming data fusion engine and the distributed edge computing nodes, the problem of multi-source data integration is solved, providing real-time and comprehensive data for evaluation; By using the multi-layer asset association graph and the Monte Carlo method, asset associations and risk propagations are accurately analyzed; With the help of the reinforcement learning decision-making framework and incremental model updates, adaptive decision-making optimization is achieved to timely respond to new attacks; Relying on the visualization interface and the closed-loop feedback control loop, the visualization effect and evaluation accuracy are improved. The problems in multiple aspects such as data fusion, association analysis, decision-making optimization, and visualization feedback in traditional evaluations are comprehensively solved. Description of the Drawings
[0025] The disclosure of the present invention will be described with reference to the accompanying drawings. It should be understood that the drawings are only for illustrative purposes and are not intended to limit the scope of protection of the present invention. In the drawings, the same reference numerals are used to refer to the same components. Among them:
[0026] Figure 1 Schematically shows a schematic flow framework diagram of a security risk situation assessment system and method for an asset library model proposed according to an embodiment of the present invention;
[0027] Figure 2 Schematically shows a risk handling and feedback flow chart of an adaptive decision-making optimization subsystem of a security risk situation assessment system and method for an asset library model proposed according to an embodiment of the present invention. Detailed Embodiments
[0028] It is easy to understand that according to the technical solution of the present invention, without changing the essence of the present invention, those of ordinary skill in the art can propose various interchangeable structural ways and implementation ways. Therefore, the following specific embodiments and the accompanying drawings are only exemplary descriptions of the technical solution of the present invention, and should not be regarded as all of the present invention or as a limitation or restriction on the technical solution of the present invention.
[0029] According to an embodiment of the present invention in combination with Figure 1 - Figure 2 shown, an asset library model security risk situation assessment system includes:
[0030] A data collection and processing subsystem, including a multi-source streaming data fusion engine for integrating IoT device sensor data, network traffic logs, and external threat intelligence streams in real time; a distributed edge computing node unit deployed on terminal devices to perform data denoising and feature extraction and transmit the compressed data to the central server. The distributed edge computing node unit uses lightweight data processing algorithms and a data denoising algorithm based on wavelet transform, which can effectively remove noise interference in the data and retain the key features of the data. In terms of feature extraction, for IoT device sensor data, by analyzing the measurement principle and data change rules of the sensor, features such as data change trends and abnormal fluctuation features are extracted; for network traffic logs, source IP, destination IP, port number, traffic size, and connection duration are extracted.
[0031] The multi-source streaming data fusion engine is connected to the CVE vulnerability database, dark web transaction monitoring platform, and open-source intelligence aggregator in real time through an API. The data association and matching unit uses the cosine similarity algorithm to map the vulnerability features in the external threat intelligence to the device fingerprint information in the asset library in real time to generate a vulnerability asset association matrix.
[0032] The data denoising and feature extraction algorithms can process different types of data more accurately, improve the data quality, provide a more reliable data basis for subsequent risk assessment, and the compression algorithm reduces the data transmission volume, reduces the network bandwidth pressure, ensures that the data can be transmitted to the central server in a timely and stable manner, and improves the real-time performance and stability of the system.
[0033] A dynamic risk assessment subsystem, including a multi-layer asset association graph construction module for constructing the functional dependence, data flow dependence, and physical connection relationship of assets in the resource library based on a graph database; a risk propagation probability calculation module for simulating the conduction path of attacks from edge nodes to core resources using the Monte Carlo method; a time-sensitive analysis module for dynamically adjusting the threat weights in different time periods through a sliding window mechanism: where W(t) is the comprehensive threat weight at the current moment, t i is the occurrence time of the i-th attack event, s iIndicates the severity score of the event, where λ is the attenuation factor, and the weight of the event decreases over time. When using the Monte Carlo method to simulate the attack path, in order to more accurately simulate the behavior of the attacker, an attacker behavior model is introduced. The model sets the behavior preferences of the attacker under different network environments and asset conditions based on historical attack data;
[0034] Meanwhile, during the simulation process, considering the dynamic changes in the network environment, in the time-sensitive analysis module, the size and sliding step of the sliding window are dynamically adjusted according to the business characteristics of the asset library and the frequency of risk changes. For asset libraries with busy operations and frequent risk changes, the size and sliding step of the sliding window are reduced to more finely capture the changes in threat weights; for relatively stable asset libraries, the size and sliding step of the sliding window are appropriately increased to reduce the consumption of computing resources.
[0035] The multi-layer asset association graph construction module defines a dependency strength index, quantifies the business continuity impact factor between assets, dynamically identifies the key node algorithm, and calculates the importance score of the node for asset key node identification. The formula is: Where PR(A i ) represents the importance score of asset node A i , d is the damping coefficient, ω i is the business impact factor, e ji is the dependency weight from asset A j to A i , and In(A i )out(A i ) represent the sets of assets pointed to and pointed by A i respectively.
[0036] According to the asset library model security risk situation assessment system of claim 3, characterized in that the calculation formula for the defined dependency strength index in the multi-layer asset association graph construction module is D ij =α·log(1+T com )+β·S data , where T com is the communication frequency per unit time between assets i and j, S data is the sensitivity level of the transmitted data, and α and β are dynamic adjustment coefficients.
[0037] The formula for calculating the attack success probability by the Monte Carlo method in the attack chain simulation: Where N is the total number of simulations, Path k represents the path of the attacker from the edge node to the core resource in the k-th simulation, and p ij represents the attack penetrating from asset A i to A jThe single-step success probability is calculated by the risk propagation probability calculation module. Based on the Markov Chain Monte Carlo method, it simulates the attacker's lateral movement path in the graph and sets a dynamic termination condition: stop when the length of the simulated attack path exceeds a preset threshold or reaches the core asset, output a heat map of the attack success probability, and mark the high-risk conduction paths.
[0038] Dynamically adjust the sliding window size and step length, which can flexibly adjust the accuracy of time-sensitive analysis according to the characteristics of the asset library, optimize the utilization efficiency of computing resources while ensuring the accuracy of risk assessment.
[0039] The adaptive decision-making optimization subsystem includes a reinforcement learning decision-making framework that takes asset risk values, network topology status, and real-time threat intelligence as input states, generates risk handling actions, and optimizes the strategy based on the reward function; an incremental model update module that enables the risk assessment model to continuously absorb new attack feature data without full retraining; and an online form of stochastic gradient descent, θ t+1 = θ t - η·▽ θ L(x t , y t , θ t ), where θ t is the model parameter at time t, η is the learning rate, and ▽ θ L is the gradient of the loss function with respect to the parameter, and (x t , y t ) represents the newly input data sample in real time; to further improve the efficiency and stability of the incremental model update, an adaptive learning rate adjustment strategy is adopted, which dynamically adjusts the learning rate according to the gradient change during the model training process. When the gradient is large, the learning rate is appropriately reduced to avoid over-updating the model and causing unstable training; when the gradient is small, the learning rate is appropriately increased to accelerate the convergence speed of the model, enabling the model to focus more on key state information and improve the accuracy of decision-making.
[0040] The reinforcement learning decision-making framework adopts the Twin Delayed Deep Deterministic Policy Gradient algorithm, and its reward function is:
[0041] R t = α·(TPR t - FPR t ) + β·e -td / τ + γ·log(1 + C c ), where TPR t is the true positive rate of risk prediction at time t, FPR t is the false positive rate at time t, t d is the delay time from risk identification to response action, and C cLet \(N\) be the number of affected core resources, and \(\alpha\), \(\beta\), \(\gamma\), \(\tau\) be dynamic adjustment coefficients that are automatically adjusted according to the system operation stage. The double-delay deep deterministic policy gradient algorithm adopts a prioritized experience replay mechanism, which assigns higher sampling weights to training samples with the following characteristics, including decision-making trajectories that lead to damage to core assets, historical records of emerging attack patterns, and false alarm events actively corrected by users.
[0042] The visualization and feedback control subsystem includes a risk traceability visualization interface that highlights key factor combinations leading to high risks through an attention mechanism, and a digital twin attack and defense sandbox that simulates the blocking effects of different defense schemes on the attack chain.
[0043] The closed-loop feedback control loop reversely adjusts the data collection priorities of the data collection and processing subsystem with the user operation data of the visualization and feedback control subsystem, and the analysis parameters of the dynamic risk assessment subsystem are updated in real time with the policy output of the adaptive decision optimization subsystem.
[0044] A method for assessing the security risk situation of an asset library model includes the following steps:
[0045] S1. Real-time data fusion and feature extraction: Real-time collect IoT sensor data, network traffic logs, and external threat intelligence streams through distributed edge computing nodes deployed on terminal devices; use a sliding time window mechanism to perform time alignment on multi-source data, perform data denoising and feature vector extraction; compress and transmit the processed data stream to the central server, and perform real-time association matching with the CVE vulnerability database.
[0046] S2. Dynamic risk assessment and propagation simulation: Construct a multi-layer asset association graph based on a graph database, define a functional dependence strength index, and use the Markov chain Monte Carlo method to simulate the attack path and terminate the simulation when the conditions are met.
[0047] S3. Adaptive decision-making and feedback optimization: Input the asset risk value, topology status, and threat intelligence into the reinforcement learning framework of the double-delay deep deterministic policy gradient algorithm, generate risk disposal strategies through a reward function, and trigger incremental model updates. Dynamically adjust the data collection priorities and graph node weights according to the user's interactive operations on the attack path heat map in the visualization interface.
[0048] S4. Closed-loop defense execution: Verify the effectiveness of the disposal strategy through a digital twin attack and defense sandbox, automatically send defense instructions to security devices to execute the strategy, record the actual defense effect, and feedback it to the reinforcement learning experience pool to complete closed-loop optimization.
[0049] The technical scope of the present invention is not limited to the content described above. Those skilled in the art can make various deformations and modifications to the above embodiments without departing from the technical idea of the present invention, and these deformations and modifications shall fall within the protection scope of the present invention.
Claims
1. An asset library model security risk situation assessment system, characterized in that: include: Data acquisition and processing subsystem, Includes, a multi-source streaming data fusion engine for real-time integration of IoT device sensor data, network traffic logs and external threat intelligence streams; Distributed edge computing node units are deployed on terminal devices to perform data denoising and feature extraction, and transmit compressed data to the central server; The dynamic risk assessment subsystem includes a multi-layer asset association graph construction module, which constructs the functional dependency, data flow dependency and physical connection relationship of assets in the resource library based on the graph database; The risk propagation probability calculation module uses the Monte Carlo method to simulate the attack transmission path from edge nodes to core resources; The time-sensitive analysis module dynamically adjusts the threat weights of different time periods through a sliding window mechanism; Adaptive decision optimization subsystem, including: reinforcement learning decision framework, which takes asset risk value, network topology status and real-time threat intelligence as input, generates risk disposal actions and optimizes strategies based on reward functions; incremental model update module, which enables the risk assessment model to continuously absorb new attack feature data without full retraining; The visualization and feedback control subsystem includes a risk tracing visualization interface that highlights the key combinations of factors that lead to high risks through an attention mechanism; a digital twin attack and defense sandbox that simulates the blocking effects of different defense schemes on the attack chain; In a closed-loop feedback control loop, the user operation data of the visualization and feedback control subsystem reversely adjusts the data acquisition priority of the data acquisition and processing subsystem, and the strategy output of the adaptive decision optimization subsystem updates the analysis parameters of the dynamic risk assessment subsystem in real time.
2. The asset library model security risk situation assessment system according to claim 1 is characterized in that: The multi-source streaming data fusion engine connects to the CVE vulnerability database, dark web transaction monitoring platform and open source intelligence aggregator in real time through API. The data association matching unit uses the cosine similarity algorithm to map the vulnerability features in the external threat intelligence with the device fingerprint information in the asset library in real time to generate a vulnerability asset association matrix.
3. The asset library model security risk situation assessment system according to claim 1 is characterized in that: The multi-layer asset association graph construction module defines dependency strength indicators, quantifies business continuity impact factors between assets, dynamically identifies key node algorithms, and calculates node importance scores.
4. The asset library model security risk situation assessment system according to claim 3 is characterized in that: The formula for key node identification is: Among them, PR(A i ) represents asset node A i The importance score of is, d is the damping coefficient, ω i is the business impact factor, e ji It is asset A j To A i The dependency weight of In(A i )out(A i ) represent A i A collection of assets that point to and are pointed to.
5. The asset library model security risk situation assessment system according to claim 3 is characterized in that: The calculation formula for defining the dependency strength index in the multi-layer asset association graph construction module is D ij =α·log(1+T com )+β·S data , where T com is the communication frequency per unit time between assets i and j, S data is the sensitivity level of the transmitted data, and α and β are dynamic adjustment coefficients.
6. The asset library model security risk situation assessment system according to claim 1, characterized in that: The formula for calculating the attack success probability in the attack chain simulation using the Monte Carlo method is: Where N is the total number of simulations, Path k represents the attacker's path from the edge node to the core resource in the kth simulation, p ij Indicates that the attack comes from asset A i Infiltration into A j The probability of a single-step success.
7. The asset library model security risk situation assessment system according to claim 6, characterized in that: The risk propagation probability calculation module is executed based on the Markov chain Monte Carlo method to simulate the attacker's lateral movement path in the graph and set dynamic termination conditions: when the length of the simulated attack path exceeds a preset threshold or reaches the core asset, it stops, outputs a heat map of the attack success probability, and marks the high-risk conduction path.
8. The asset library model security risk situation assessment system according to claim 1, characterized in that: The reinforcement learning decision framework adopts a double-delayed deep deterministic policy gradient algorithm, and its reward function is: R t =α·(TPR t -FPR t )+β·e -td / τ +γ·log(1+C c ), where TPR t is the true positive rate of risk prediction at time t, FPR t is the false alarm rate at time t, t d is the delay time from risk identification to response action, C c is the number of affected core resources, α, β, γ, τ are dynamic adjustment coefficients, which are automatically adjusted according to the system operation stage.
9. The asset library model security risk situation assessment system according to claim 8, characterized in that: The dual-delay deep deterministic policy gradient algorithm adopts a priority experience replay mechanism to give higher sampling weights to training samples containing the following features, including decision trajectories that lead to damage to core assets, historical records of new attack modes, and false positive events that are actively corrected by users.
10. The method for assessing the security risk situation of an asset library model according to any one of claims 1 to 9, characterized in that: The following steps are involved: S1, real-time data fusion and feature extraction, collects IoT sensor data, network traffic logs and external threat intelligence streams in real time through distributed edge computing nodes deployed on terminal devices; uses a sliding time window mechanism to time align multi-source data, perform data denoising and feature vector extraction; compresses and transmits the processed data stream to the central server, and performs real-time correlation matching with the CVE vulnerability database; S2, dynamic risk assessment and propagation simulation, builds a multi-layer asset association map based on the graph database, defines the functional dependency strength index, uses the Markov chain Monte Carlo method to simulate the attack path, and terminates the simulation when the conditions are met; S3, adaptive decision-making and feedback optimization, inputs asset risk value, topological status and threat intelligence into the double-delay deep deterministic policy gradient algorithm reinforcement learning framework, generates risk disposal strategies through reward functions, and triggers incremental model updates. According to the user's interactive operation on the attack path heat map in the visualization interface, it dynamically adjusts the data collection priority and graph node weights; S4, closed-loop defense execution verifies the effectiveness of the disposal strategy through the digital twin attack and defense sandbox, automatically issues defense instructions to security devices to execute the strategy, records the actual defense effect and feeds back to the reinforcement learning experience pool to complete the closed-loop optimization.
Citation Information
Patent Citations
Knowledge federal undirected graph-based federal ring detection method, system and device, and medium
CN113656802A
Network security management method and management system
CN118250074A
Network anomaly detection method and device, computer equipment, readable storage medium and program product
CN118473782A
Asset risk tracing method and device
CN119205351A
Method for calculating and analysing risks and corresponding device
EP2816773A1
Cited By
Data resource migration risk prediction method and system, terminal equipment and storage medium
CN120448161A
Data resource migration risk prediction method, system, terminal device and storage medium
CN120448161B
Network security alarm noise reduction and triage system based on AI baseline
CN120915581A
Intelligent risk early warning and prevention and control platform based on enterprise management and construction method thereof
CN121119687A
Information security risk classification method and system
CN121125247A