Ship network security risk assessment method, system and equipment based on dynamic risk model, and medium

Through the dynamic risk model assessment method, the problems of full-factor characteristics and dynamic changes in ship network security assessment are solved, more accurate risk assessment and optimized management are achieved, and decision makers are assisted in identifying and prioritizing risks.

CN120750653AActive Publication Date: 2025-10-03YUANBAO TECH

Patent Information

Application Number
CN202511221326.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-10-03
Estimated Expiration
2045-08-29

AI Technical Summary

Technical Problem

Existing ship network security assessment methods fail to fully consider the characteristics of all factors, ignore the influencing factors such as assets, services, and results in the actual network system, do not establish unitized and scenario-based comprehensive analysis, do not consider time factors and risk evolution conditions, and rely on the experience of the assessor, resulting in inaccurate assessment results and difficulty in dealing with the correlation and dynamic changes of multiple risks.

Method used

An assessment method based on a dynamic risk model is adopted. By dividing the network area into assessment units, collecting all-factor data, building a risk scenario database, calculating the time-weighted and risk evolution values, establishing a dynamic risk model, considering the experience of the assessors, and optimizing the risk assessment results.

Benefits of technology

It achieves more accurate ship cybersecurity risk assessment, provides risk optimization management, assists decision makers in identifying and prioritizing risks, and improves the accuracy and dynamic adaptability of assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750653A_ABST
    Figure CN120750653A_ABST
Patent Text Reader

Abstract

The invention provides a ship network security risk assessment method, system and device based on a dynamic risk model, and a medium, and relates to the technical field of ship network security. Comprising the following steps: collecting a ship asset attribute data set and total factor data required by ship network security risk assessment, and determining vulnerability items; identifying potential network security risk scenes according to the types of historical ship network security events, and estimating the event influence degree and threat occurrence possibility of each risk scene; calculating a unit risk initial value and a unit average risk value corresponding to each risk scene according to the vulnerability severity degree, the event influence degree and the threat occurrence possibility corresponding to the vulnerability item in each risk scene; constructing a dynamic risk model based on time factor and risk evolution double-factor weighting; and calculating the risk value of each evaluation unit based on the dynamic risk model, and taking the maximum risk value as the network security risk evaluation value of the whole current ship. According to the invention, optimized management of ship network security risks is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of ship network security, and in particular to a ship network security risk assessment method, system, equipment and medium based on a dynamic risk model. Background Art

[0002] As the maritime industry continues to advance in digitalization and intelligence, the issue of ship cybersecurity is becoming increasingly prominent. From ship design and construction to operational management, network connectivity has become a core foundation for improving efficiency and enabling innovative applications such as remote monitoring and autonomous driving. However, this high level of connectivity also greatly expands the attack surface, exposing previously physically isolated OT (operational technology) systems to severe threats: critical navigation equipment (such as ECDIS and AIS) can be attacked, causing loss of control; ransomware can lock management systems, forcing ship suspensions; and sensitive data can be easily leaked. These risks directly endanger navigation safety and ship assets, and may also lead to significant economic losses, environmental pollution, and reputational damage.

[0003] Ship cybersecurity issues primarily include the following: 1. System software and hardware vulnerabilities; 2. Clear text transmission of ship industrial system protocols; 3. Prevalent weak passwords on shipboard equipment; 4. Remote operation and maintenance issues; and 5. Lack of management of physical interfaces. To address this, it is necessary to establish a ship cybersecurity risk assessment method that facilitates risk comparison, reflects dynamic risk changes, identifies risks, and facilitates rectification. Clear response measures should be formulated based on risk tolerance. Risk-dependent situations should be comprehensively analyzed on a unitized and scenario-based basis to develop risk management priority recommendations. Risk management should be implemented after accurate assessment to ensure ship cybersecurity.

[0004] Existing ship cybersecurity assessment methods are based on labeling and extracting security factors such as assets, threats, and vulnerabilities to construct security factors and risk assessment values. This technology has the following drawbacks: (1) The full range of factors in the ship cybersecurity risk assessment has not been fully considered, the assets, services, results and other factors in the actual network system have been ignored, and the comparison between risks has not been considered. A comprehensive and dynamic risk assessment correlation analysis mechanism has not been established; (2) The unitized and scenario-based comprehensive analysis dimensions have not yet been established, and the dynamic impact of time factors and risk evolution conditions on risks has not yet been identified; (3) The impact of the assessor’s subjective work experience on the risk assessment conclusion has not been considered; (4) There is no clear guidance on how risk assessment results can help organizations to decide the order in which to respond to risks and allocate subsequent resources, and assist decision makers in accurately identifying risks that need to be addressed first, which leads to insufficient dynamic and stable gains in ship network security.

[0005] In summary, the current ship safety risk assessment work is basically based on relevant standards and theoretical management methods. In the early stage of this assessment method, it is still necessary to use human subjective experience to assign values ​​to the ship network security assessment data. It cannot evaluate time factors and risk evolution conditions. There are problems such as oversimplification of complex risk situations, strong subjectivity, and a large reliance on the experience of the assessor. Secondly, it is difficult to handle multiple risks with strong correlation. Static analysis of a single risk cannot reflect the dynamic changes of risks, resulting in inaccurate assessment results. Summary of the Invention

[0006] In view of this, the embodiments of the present application provide a ship network security risk assessment method, system, equipment and medium based on a dynamic risk model, which takes into account complex risk situations, more accurately assesses the quantitative risks of ships in network security incident scenarios, and accurately identifies risks that need to be dealt with first.

[0007] The present application provides the following technical solution: a method for assessing ship network security risk based on a dynamic risk model, comprising: According to the principle of network security area division, the actual network area of ​​the ship is divided into multiple blocks, with a single block as the evaluation unit; Collecting a ship asset attribute data set to obtain an asset list, collecting all the element data required for ship cybersecurity risk assessment from the asset list to obtain a ship cybersecurity assessment data set, determining a vulnerable item list based on the ship cybersecurity assessment data set, and analyzing and determining the vulnerability severity corresponding to each vulnerable item; Based on historical ship cybersecurity incidents, a ship cybersecurity risk scenario database is constructed. Based on the actual needs of the current risk assessment, risk scenarios applicable to the current ship are screened from the ship cybersecurity risk scenario database to form a risk scenario database for the current ship cybersecurity assessment. The event impact and threat probability of each risk scenario in the risk scenario database are estimated; Calculate the unit risk initial value corresponding to each risk scenario based on the vulnerability severity, event impact, and threat occurrence probability of the vulnerability item in each risk scenario, and calculate the unit average risk value of all risk scenarios corresponding to the assessment unit; A time factor weight is defined for the unit risk initial value corresponding to each risk scenario, and a time-weighted risk value is calculated. A risk evolution dual-factor weight is defined for the unit average risk value, and a risk evolution value is calculated. The average of the time-weighted risk value and the risk evolution value is used as the risk value of the assessment unit, and a dynamic risk model based on the weighted dual factors of time and risk evolution is constructed. The risk evolution dual factors include the effectiveness of safety measures discovered during the assessment process and the residual risk constant. Calculate the risk value of each assessment unit, and use the maximum risk value as the current cybersecurity risk assessment value of the entire ship.

[0008] According to one embodiment of the present application, the ship asset attribute data set includes core shipboard control system assets, onboard information technology system assets, ship fusion system assets, and infrastructure and logical assets, and the asset list is obtained.

[0009] According to an embodiment of the present application, the event impact in the event impact degree includes security impact, environmental impact, compliance impact, economic and reputation impact; when estimating the event impact degree of each risk scenario, the security impact, environmental impact, and compliance impact are used as core factors, and the economic and reputation impact is used as a superimposed correction factor. The event impact degree of each risk scenario is calculated by the following formula: : .

[0010] According to one embodiment of the present application, the factors in the threat occurrence possibility include historical event frequency, navigation status weight and external threat level; the threat occurrence possibility P of each risk scenario is calculated by the following formula: .

[0011] According to an embodiment of the present application, the unit risk initial value corresponding to each risk scenario is calculated using the following formula:

[0012] in, represents the initial value of unit risk of the j-th risk scenario, Indicates the severity of vulnerability, It indicates the impact of the event, and P indicates the possibility of the threat occurring.

[0013] According to one embodiment of the present application, the time-weighted risk value is calculated by the following formula:

[0014] in, represents the time-weighted risk value, represents the time factor weight of the j-th risk scenario, Represents the initial unit risk value of the j-th risk scenario.

[0015] According to one embodiment of the present application, the risk evolution value is calculated by the following formula:

[0016] in, represents the risk evolution value, represents the average risk value of the unit, Indicates the effectiveness of safety measures. represents the residual risk constant, and t represents the time since the risk was discovered in the last round of risk assessment.

[0017] This application also provides a ship network security risk assessment system based on a dynamic risk model, including: The block division module is used to divide the actual network area of ​​the ship into multiple blocks according to the network security area division principle, and use a single block as the evaluation unit; A vulnerability analysis module is used to collect a ship asset attribute data set to obtain an asset list, collect all the data elements required for ship cybersecurity risk assessment from the asset list to obtain a ship cybersecurity assessment data set, determine a vulnerable item list based on the ship cybersecurity assessment data set, and analyze and determine the vulnerability severity corresponding to each vulnerable item; A risk scenario analysis module is used to construct a ship cybersecurity risk scenario database based on historical ship cybersecurity incidents, screen out risk scenarios applicable to the current ship from the ship cybersecurity risk scenario database based on the actual needs of the current risk assessment, form a risk scenario database for the current ship cybersecurity assessment, and estimate the event impact and threat probability of each risk scenario in the risk scenario database; The initial risk value calculation module is used to calculate the initial risk value of each risk scenario according to the vulnerability severity, event impact and threat occurrence probability corresponding to the vulnerability item in each risk scenario, and calculate the average risk value of each risk scenario for all risk scenarios corresponding to the assessment unit; A dynamic risk model construction module is configured to define a time factor weight for each unit risk initial value corresponding to each risk scenario, and calculate a time-weighted risk value; define a risk evolution dual-factor weight for the unit average risk value, and calculate a risk evolution value; use the average of the time-weighted risk value and the risk evolution value as the risk value of the assessment unit, and construct a dynamic risk model based on the weighted dual factors of time and risk evolution; wherein the risk evolution dual factors include the effectiveness of safety measures discovered during the assessment process and the residual risk constant; The network security risk assessment module is used to calculate the risk value of each assessment unit and use the maximum risk value as the current network security risk assessment value of the entire ship.

[0018] The present application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned ship network security risk assessment method when executing the computer program.

[0019] The present application also provides a computer-readable storage medium, which stores a computer program for executing the above-mentioned ship network security risk assessment method.

[0020] Compared with traditional methods, the beneficial effects that can be achieved by at least one of the above-mentioned technical solutions adopted in the embodiments of this specification include at least the following: the embodiments of the present invention solve the problem of relatively single risk factors and insufficient correlation in the current assessment method through a full-factor, dynamically updated risk correlation analysis mechanism; by establishing a time factor and risk evolution condition mechanism to change the current static analysis working mechanism, thereby weakening the influence of the evaluator's subjective work experience on the risk assessment conclusion, so that the risk assessment results have a priority treatment gradient, so as to obtain the optimal order and resource allocation for responding to risks, assist decision makers in accurately identifying risks that need to be dealt with first, and realize the optimized management of ship network security risks.

[0021] By integrating the characteristics of the maritime industry and ship operations, the embodiment of the present invention establishes an applicable dynamic cybersecurity risk assessment model to replace the traditional general risk assessment model. It provides a richer input parameter function and can more accurately assess the quantitative risk of ships in cybersecurity incident scenarios. Whether it serves as a reference for cybersecurity compliance certification by classification societies or provides insurance companies with an intuitive underwriting basis, it has greater reference value and benefits. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0023] Figure 1 1 is a flow chart of a method for assessing ship network security risk based on a dynamic risk model according to an embodiment of the present invention; Figure 2 2. It is a schematic diagram of a ship network security risk assessment process according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a ship network structure according to an embodiment of the present invention; Figure 4 2. It is a schematic diagram of a ship network security risk assessment system according to an embodiment of the present invention; Figure 5 It is a structural schematic diagram of the computer device of the present invention. DETAILED DESCRIPTION

[0024] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0025] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the features in the following embodiments and embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.

[0026] like Figure 1 As shown, an embodiment of the present invention provides a ship network security risk assessment method based on a dynamic risk model, comprising: S101. Divide the actual network area of ​​the ship into multiple blocks according to the principle of network security area division, and use a single block as the evaluation unit; S102. Collect a ship asset attribute data set to obtain an asset list, collect all the data elements required for the ship cybersecurity risk assessment from the asset list, obtain a ship cybersecurity assessment data set, determine a list of vulnerable items based on the ship cybersecurity assessment data set, and analyze and determine the severity of the vulnerability corresponding to each vulnerable item; S103. Based on historical ship cybersecurity incidents, a ship cybersecurity risk scenario database is constructed. Based on the actual needs of the current risk assessment, the ship cybersecurity risk scenario database is screened for applicable risk scenarios for the current ship, forming a risk scenario database for the current ship cybersecurity assessment. The impact of the incident and the likelihood of threat occurrence for each risk scenario in the risk scenario database are estimated. S104. Calculate the initial unit risk value for each risk scenario based on the vulnerability severity, event impact, and threat likelihood corresponding to the vulnerability item in each risk scenario, and calculate the average unit risk value for all risk scenarios corresponding to the assessment unit. S105. Define a time factor weight for the initial unit risk value corresponding to each risk scenario to calculate a time-weighted risk value; define a risk evolution dual-factor weight for the unit average risk value to calculate a risk evolution value; use the average of the time-weighted risk value and the risk evolution value as the risk value of the assessment unit, and construct a dynamic risk model based on the weighted dual factors of time and risk evolution; wherein the risk evolution dual factors include the effectiveness of safety measures discovered during the assessment process and the residual risk constant; S106. Calculate the risk value of each assessment unit, and use the maximum risk value as the current cybersecurity risk assessment value of the entire ship.

[0027] An embodiment of the present invention proposes a method for ship network security risk assessment based on a dynamic risk model. First, full-factor data of a ship asset attribute dataset and a ship network security assessment dataset are collected, and then potential network security risk scenarios are identified based on common ship network security event types; next, a two-dimensional, time factor, and risk evolution dual-factor weighted dynamic risk model is constructed; then, based on the dynamic risk model, the risk scenarios of the asset dataset are analyzed and the accuracy of the model is adjusted; then, based on the optimized dynamic risk model, different network areas of the ship are evaluated; finally, the network security risk of the entire ship is evaluated in combination with the regional assessment result data; and then, a systematic method for effectively responding to risks and allocating resources is developed based on the risk assessment results, assisting decision makers in accurately identifying risks that need to be handled as a priority.

[0028] According to some embodiments of the present invention, in S101, the actual network area of ​​the ship is divided into multiple blocks according to the network security zone division principle. In the subsequent major assessment steps, each block network is used as a unit for assessment. Ultimately, all block networks are aggregated and analyzed to determine the overall network security risk level of the ship.

[0029] According to some embodiments of the present invention, in S102, all the data required for the ship network security risk assessment is collected, including: (1) Through drawing verification, crew self-inspection, on-site inspection, service provider inspection, technical testing, document review and other methods, the ship asset attribute data set is collected: mainly including core shipborne operation system (OT) assets, onboard information technology system (IT) assets, ship fusion system assets and infrastructure and logic assets, a total of four categories, to form an asset list.

[0030] (2) Collect ship network security assessment data sets from the above asset lists through vulnerability scanning, penetration testing, document review, on-site inspection, etc.: including network architecture data, security configuration data, vulnerability data, etc. Form a list of vulnerable items and analyze the severity of vulnerabilities in the ship network .

[0031] According to some embodiments of the present invention, in S103, historically publicized ship cybersecurity incidents are collected to construct a ship cybersecurity risk scenario database. Applicable risk scenarios are screened out according to the actual needs of the current assessment, and then the risk scenario database for this ship cybersecurity assessment is formed, and the event impact value of each risk scenario is estimated. , the possibility of threat occurrence .

[0032] According to some embodiments of the present invention, in S104, the initial unit risk value under each risk scenario is calculated. , and the unit average risk value .

[0033] According to some embodiments of the present invention, in S105, a dynamic risk model is constructed by introducing a weighted dual factor of time and risk evolution. Based on this dual-factor weighted dynamic risk model, a time-weighted risk and a risk evolution value are calculated to obtain the average of the two values, which is then used as the risk value for the unit area network.

[0034] (1) Time factor, which aims to take into account the difference between ship and maritime systems and traditional information system infrastructure. Once the systems, components and related supporting infrastructure are officially put into use, they will not be frequently iterated and changed, which will directly lead to a significant extension of the repair cycle of vulnerability vulnerabilities. Therefore, the derivative risk of vulnerability exposure time should be considered. Time factor weight value The schedule will be adjusted based on the subjective experience of the assessor and the schedule in the business continuity plan or vulnerability remediation management plan of the ship operator during the actual assessment process.

[0035] (2) Risk evolution factor, which aims to take into account the effectiveness of the safety measures actually implemented on board the ship At the same time, because the risk cannot be completely eliminated, the assessor needs to subjectively define a residual risk constant. , representing the residual cybersecurity risk that cannot be completely eliminated even after implementing various security measures. The risk evolution factor consists of two key values: the residual risk constant, which is adjusted based on the assessor's subjective experience during the actual assessment process, taking into account factors such as vessel type and the impact of risk scenarios and events. The effectiveness of security measures is calculated by weighting the ratio of identified security measures to the security measures that should have been implemented.

[0036] According to some embodiments of the present invention, in S106, the above calculation process is repeated for other unit area networks to obtain the risk values ​​of all unit area networks. The "maximum-minimum principle" (or "pessimistic criterion") is adopted to take the largest unit area network risk value as the overall network security risk level of the ship.

[0037] like Figure 2 As shown, in a specific embodiment, the ship network security risk assessment method of this embodiment includes the following steps: Step 1: Divide the actual network area of ​​the ship into multiple blocks according to the principle of network security area division. In the subsequent main assessment steps, a single block network is used as the assessment object. Figure 3For example, the following block networks can be divided as evaluation objects: (1) integrated bridge network; (2) engine room control network; (3) crew entertainment network; (4) ship management network.

[0038] Step 2: Collect ship asset attribute data through methods such as drawing verification, crew self-inspection, on-site inspection, service provider inspection, technical testing, and document review. Collect ship network security assessment data sets from the above asset list through vulnerability scanning, penetration testing, document review, and on-site inspection. Multiple vulnerable items are obtained, each with a corresponding vulnerability severity level. Each vulnerability may be exploited in multiple different risk scenarios at the same time.

[0039] In specific implementation, the vulnerability severity V can be directly mapped to the degree of harm of the vulnerability, and is assessed using the CVSS scoring standard with a value range of [0,1], namely: The CVSS score ranges from 0 to 10. A higher score indicates a greater vulnerability risk, and the score needs to be divided by 10 to maintain V in the [0, 1] range.

[0040] Step 3: Collect historical ship cybersecurity incidents from major classification societies worldwide (e.g., China Classification Society (CCS), American Bureau of Shipping (ABS), Det Norske Veritas (DNV), etc.) and other public information channels, including media reports. This database will be used to analyze the risk scenarios involved. For specific assessment projects, appropriate risk scenarios will be selected from the historical risk event database based on the vessel's specific information. The impact level (I) and threat probability (P) of each risk scenario will be estimated. Detailed definitions and value selection methods are as follows: (1) Risk scenarios. Risk scenarios are defined as threat factors in assets that may trigger security incidents, such as satellite communication interference, malicious software on crew terminals, unauthorized access to ship control systems, and tampering with ship IoT data.

[0041] (2) Impact of the incident I (Impact). The impact of the incident is defined as the degree of negative impact that may be caused when a security incident occurs. Further classification and value ranges, as well as examples, are as follows: a. Safety impact [0,10]: impacts that directly affect the safety of ship navigation, such as death / ship sinking (value 10), serious injury to crew / loss of ship control (value 9), local function failure (value 6), and non-critical equipment alarm (value 2); b. Environmental impact [0,10], negative impacts on the aquatic environment, mainly including pollution caused by leakage of cargo holds (value 9), diffusion of ballast water pollution (value 7), and diffusion of waste oil in the engine room (value 4); c. Compliance impact [0,10]: impacts that may affect the issuance of compliance safety certification by classification societies or other regulatory bodies, such as data / certification fraud (value 10), failure to implement safety measures (value 8), audit failure / classification society downgrade (value 6), etc. d. Economic and reputational impact [0, 10]. This refers to the economic and negative reputational losses caused by security incidents, primarily including direct economic losses (e.g., tens of millions of USD for a single incident

[10] , millions of USD [5]), as well as cumulative vessel downtime losses (number of downtime days * 0.5), and reputational losses (widespread global media coverage, valued at 8, and penalties reported within the maritime industry, valued at 4).

[0042] In estimating the impact of an incident, security impact, environmental impact, and compliance impact are core factors, and economic and reputational impacts are superimposed correction factors. The calculation method is:

[0043] In specific implementation, the values ​​of each factor are subjectively defined based on experience, and the measurable qualitative scale refers to three levels: high, medium, and low. For example, the subjective qualitative scale for safety impact is divided into: navigation interruption - high; reduced navigation efficiency - medium; and almost no impact on navigation - low. Taking the incident of "the cargo control system of an oil tanker was hacked and damaged, resulting in crude oil leakage" as an example, the calculation process of the safety incident impact is as follows: Safety impact: Damage to the cargo control system does not affect the overall navigation safety of the ship, and the value is 5; Environmental impact: Crude oil transportation leakage causes serious marine water pollution, with a value of 9; Compliance impact: Failure to implement strict network security measures leads to a security incident, with a value of 8; Economic impact: Crude oil transportation is extremely valuable, and the losses from cargo loss and accident handling are estimated in tens of millions of US dollars, with a value of 10; Reputational impact: The oil spill had a severe impact and was reported by global media, so the value is 8.

[0044] In summary, the calculation process is: The result exceeds the limit and the value is 10.

[0045] (3) Probability of threat occurrence P. The probability of threat occurrence is defined as the probability of a threat occurring to a ship, and is further categorized and has a range of values ​​(specific values ​​are subjectively defined based on experience). Examples are as follows: a. Historical event weight: The estimated probability weight of historical safety events, i.e. [historical event frequency (such as IMO report data) * 0.4]; b. Navigation status weight: The navigation status affects the probability of threat occurrence, i.e. [0.2 for anchoring near the shore, 0.6 for sailing on the high seas, 0.8 for sailing in narrow waterways]; c. External threat level: For example, the US-CERT will issue relevant maritime alert levels, which can be used as a direct reference for the probability of external threats, that is, [external threat level (such as maritime APT organization activity) * 0.3].

[0046] After the above factors are accumulated, P is normalized to (0,1) through the Sigmoid function. The calculation method is:

[0047] Step 4: Calculate the initial unit risk value under each risk scenario . And the total risk value of the unit area .

[0048] in, Represents the initial unit risk value of the j-th risk scenario. Indicates the severity of vulnerability. A vulnerability item can correspond to multiple risk scenarios. In the calculation of a single risk scenario, the "maximum-minimum principle" can be adopted to select the highest value of vulnerability severity for calculation. It indicates the impact of the event, and P indicates the possibility of the threat occurring. It represents the total risk value of the unit area. Multiple risk scenarios can exist simultaneously in a unit area network, and their cumulative total value is used as a parameter for subsequent dynamic two-factor weighting.

[0049] Step 5: Introduce the dual-factor weighting of time and risk evolution to build a dynamic risk model: (1) The time factor weight is determined based on the existing BCP (Business Continuity Plan) or vulnerability management and remediation plan at the time of the ship assessment, and is determined based on the subjective experience of the assessor. Each unit risk initial value may correspond to a different time weight. Examples of the meanings of different predefined weight values ​​are as follows: Time factor weight value The value is (0,1]. The urgency of risk repair is low, which can be regarded as risk acceptance or discretionary disposal. =0.2; the risk has a high urgency to repair and should be dealt with first, so define =0.6, the risk repair urgency is the highest, and the occurrence of a safety incident is almost inevitable. It must be handled immediately before the ship sails. = 1. Finally, the time-weighted risk value can be obtained: .

[0050] (2) The weight of risk evolution factors includes the effectiveness of safety measures found during the assessment process. , residual risk constant C. Effectiveness of safety measures The residual risk constant, C, represents the ratio of implemented safety precautions to required precautions. This represents the residual risk that cannot be completely eliminated, regardless of the precautions implemented. This is a fundamental characteristic of risk: risk cannot be completely eliminated 100%. The value of the residual risk constant, C, also depends on the assessor's subjective experience and is an important factor in adjusting the accuracy of model calculations.

[0051]

[0052] Based on the dynamic risk model with dual weights of time and risk evolution, the time-weighted risk and risk evolution values ​​are calculated as follows: Time-weighted VaR:

[0053] Risk evolution: The value range of C is (0,1], and t is the time since the last round of risk assessment, in months.

[0054] Single area The dynamic two-factor weighted risk is:

[0055] in, represents the time-weighted risk value, represents the time factor weight of the j-th risk scenario, represents the initial value of unit risk of the j-th risk scenario, represents the risk evolution value, represents the average risk value of the unit, Indicates the effectiveness of safety measures. represents the residual risk constant, and t represents the time since the risk was discovered in the last round of risk assessment.

[0056] Step 6. Repeat the above calculation process for all other regional networks to obtain the dynamic two-factor weighted risk value of all regions. Adopt the "maximum-minimum principle" (or "pessimism criterion") and take the maximum value as the risk value of the entire ship. This method also conforms to the "shortest board effect" in network security.

[0057] like Figure 4 As shown, the present application also provides a ship network security risk assessment system 200 based on a dynamic risk model, comprising: The block division module 201 is used to divide the actual network area of ​​the ship into multiple blocks according to the network security area division principle, and use a single block as an evaluation unit; Vulnerability analysis module 202 is used to collect a ship asset attribute data set to obtain an asset list, collect all the data elements required for ship cybersecurity risk assessment from the asset list to obtain a ship cybersecurity assessment data set, determine a vulnerability list based on the ship cybersecurity assessment data set, and analyze and determine the vulnerability severity corresponding to each vulnerability item; The risk scenario analysis module 203 is used to construct a ship cybersecurity risk scenario database based on historical ship cybersecurity incidents, filter out risk scenarios applicable to the current ship from the ship cybersecurity risk scenario database according to the actual needs of the current risk assessment, form a risk scenario database for the current ship cybersecurity assessment, and estimate the event impact and threat probability of each risk scenario in the risk scenario database; The initial risk value calculation module 204 is configured to calculate the initial unit risk value corresponding to each risk scenario based on the vulnerability severity, event impact, and threat occurrence probability corresponding to the vulnerability item in each risk scenario, and to obtain the average unit risk value of all risk scenarios corresponding to the assessment unit. The dynamic risk model construction module 205 is configured to define a time factor weight for each unit risk initial value corresponding to each risk scenario, and calculate a time-weighted risk value; define a risk evolution dual-factor weight for the unit average risk value, and calculate a risk evolution value; use the average of the time-weighted risk value and the risk evolution value as the risk value of the assessment unit, and construct a dynamic risk model based on the weighted dual factors of time and risk evolution; wherein the risk evolution dual factors include the effectiveness of safety measures discovered during the assessment process and the residual risk constant; The network security risk assessment module 206 is configured to calculate the risk value of each assessment unit and use the maximum risk value as the current network security risk assessment value of the entire ship.

[0058] The ship cybersecurity risk assessment system of an embodiment of the present invention applies the aforementioned ship cybersecurity risk assessment method to construct a two-factor weighted dynamic risk model based on two dimensions: time and risk evolution. This model constructs a visual combination of the two dimensions of risk likelihood and impact, integrates time and risk evolution to comprehensively identify risks, and then orchestrates risk response measures based on the ship cybersecurity risk assessment results. The dynamic risk model bridges risks and measures, helping decision-makers accurately identify risks that require priority, ensuring a relatively stable security risk status for the overall ship network environment.

[0059] In one embodiment, a computer device is provided, such as Figure 5As shown, it includes a memory 301, a processor 302, and a computer program stored in the memory 301 and executable on the processor 302. When the processor 302 executes the computer program, the above-mentioned ship network security risk assessment method is implemented.

[0060] Specifically, the computer device may be a computer terminal, a server or a similar computing device.

[0061] In this embodiment, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program for executing the above-mentioned ship network security risk assessment method.

[0062] Specifically, computer-readable storage media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer-readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable storage media does not include transitory media such as modulated data signals and carrier waves.

[0063] Obviously, those skilled in the art should understand that the various modules or steps of the above-mentioned embodiments of the present invention can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices. Alternatively, they can be implemented using program code executable by the computing device, so that they can be stored in a storage device and executed by the computing device. In some cases, the steps shown or described can be performed in a different order than herein, or they can be made into separate integrated circuit modules, or multiple modules or steps can be made into a single integrated circuit module for implementation. Thus, the embodiments of the present invention are not limited to any specific combination of hardware and software.

[0064] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A ship network security risk assessment method based on a dynamic risk model, characterized in that: include: According to the principle of network security area division, the actual network area of ​​the ship is divided into multiple blocks, with a single block as the evaluation unit; Collecting a ship asset attribute data set to obtain an asset list, collecting all the element data required for ship cybersecurity risk assessment from the asset list to obtain a ship cybersecurity assessment data set, determining a vulnerable item list based on the ship cybersecurity assessment data set, and analyzing and determining the vulnerability severity corresponding to each vulnerable item; Based on historical ship cybersecurity incidents, a ship cybersecurity risk scenario database is constructed. Based on the actual needs of the current risk assessment, risk scenarios applicable to the current ship are screened from the ship cybersecurity risk scenario database to form a risk scenario database for the current ship cybersecurity assessment. The event impact and threat probability of each risk scenario in the risk scenario database are estimated; Calculate the unit risk initial value corresponding to each risk scenario based on the vulnerability severity, event impact, and threat occurrence probability corresponding to the vulnerability item in each risk scenario, and calculate the unit average risk value of all risk scenarios corresponding to the assessment unit; Defining a time factor weight for the unit risk initial value corresponding to each risk scenario, and calculating a time-weighted risk value; Defining a risk evolution dual-factor weight for the unit average risk value, and calculating and obtaining a risk evolution value; The average of the time-weighted risk value and the risk evolution value is used as the risk value of the assessment unit, and a dynamic risk model based on the weighting of the time factor and the risk evolution factor is constructed; wherein the risk evolution factor includes the effectiveness of the safety measures discovered during the assessment process and the residual risk constant; Calculate the risk value of each assessment unit, and use the maximum risk value as the current cybersecurity risk assessment value of the entire ship.

2. The ship network security risk assessment method according to claim 1 is characterized in that: The ship asset attribute data set includes core shipboard control system assets, onboard information technology system assets, ship fusion system assets, and infrastructure and logic assets, and the asset list is obtained.

3. The ship network security risk assessment method according to claim 1, characterized in that: The event impact in the event impact level includes security impact, environmental impact, compliance impact, economic and reputational impact; when estimating the event impact level of each risk scenario, the security impact, environmental impact, and compliance impact are used as core factors, and the economic and reputational impact is used as a superimposed correction factor. The event impact level of each risk scenario is calculated using the following formula: : 。 4. The ship network security risk assessment method according to claim 1, characterized in that: The factors in the threat probability include the frequency of historical events, the navigation status weight and the external threat level. The threat probability P of each risk scenario is calculated by the following formula: 。 5. The ship network security risk assessment method according to claim 1, characterized in that: The initial unit risk value corresponding to each risk scenario is calculated using the following formula: in, represents the initial value of unit risk of the j-th risk scenario, Indicates the severity of vulnerability, It indicates the impact of the event, and P indicates the possibility of the threat occurring.

6. The ship network security risk assessment method according to claim 1, characterized in that: The time-weighted risk value is calculated by the following formula: in, represents the time-weighted risk value, represents the time factor weight of the j-th risk scenario, Represents the initial unit risk value of the j-th risk scenario.

7. The ship network security risk assessment method according to claim 1, characterized in that: The risk evolution value is calculated by the following formula: in, represents the risk evolution value, represents the average risk value of the unit, Indicates the effectiveness of safety measures. represents the residual risk constant, and t represents the time since the risk was discovered in the last round of risk assessment.

8. A ship network security risk assessment system based on a dynamic risk model, characterized in that: include: The block division module is used to divide the actual network area of ​​the ship into multiple blocks according to the network security area division principle, and use a single block as the evaluation unit; A vulnerability analysis module is used to collect a ship asset attribute data set to obtain an asset list, collect all the data elements required for ship cybersecurity risk assessment from the asset list to obtain a ship cybersecurity assessment data set, determine a vulnerable item list based on the ship cybersecurity assessment data set, and analyze and determine the vulnerability severity corresponding to each vulnerable item; A risk scenario analysis module is used to construct a ship cybersecurity risk scenario database based on historical ship cybersecurity incidents, screen out risk scenarios applicable to the current ship from the ship cybersecurity risk scenario database based on the actual needs of the current risk assessment, form a risk scenario database for the current ship cybersecurity assessment, and estimate the event impact and threat probability of each risk scenario in the risk scenario database; The initial risk value calculation module is used to calculate the initial risk value of each risk scenario according to the vulnerability severity, event impact and threat occurrence probability corresponding to the vulnerability item in each risk scenario, and calculate the average risk value of each risk scenario for all risk scenarios corresponding to the assessment unit; A dynamic risk model construction module is used to define a time factor weight for the unit risk initial value corresponding to each risk scenario, and calculate a time-weighted risk value; Defining a risk evolution dual-factor weight for the unit average risk value, and calculating and obtaining a risk evolution value; The average of the time-weighted risk value and the risk evolution value is used as the risk value of the assessment unit, and a dynamic risk model based on the weighting of the time factor and the risk evolution factor is constructed; wherein the risk evolution factor includes the effectiveness of the safety measures discovered during the assessment process and the residual risk constant; The network security risk assessment module is used to calculate the risk value of each assessment unit and use the maximum risk value as the current network security risk assessment value of the entire ship.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the ship network security risk assessment method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program for executing the ship network security risk assessment method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network security risk assessment method

    CN107204876A

  • Network information security risk assessment model and method

    CN111507597A

  • Ship network security assessment method and system, storage medium and terminal

    CN112330141A

  • Network security risk quantification method and device, computer equipment and storage medium

    CN115361241A

  • Risk assessment method and system for shipborne computer system

    CN120449159A

Cited By

  • Network security risk prevention and control method and device, computer equipment and medium

    CN121037102A