Intelligent equipment-oriented information security knowledge modeling method
By abstracting the information technology artifacts of smart devices into information items, building an information technology system model and generating an information security knowledge model, the problems of low efficiency and missed vulnerabilities in smart device security testing are solved, and more efficient information security testing is achieved.
Patent Information
- Application Number
- CN202510916681.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-03
AI Technical Summary
In existing technologies, security testing of smart devices requires a lot of manpower and material resources, and is limited by the technical level of testers, which may lead to missing potential vulnerabilities, resulting in serious security risks after the equipment is put into use. Traditional penetration testing methods have limitations in dealing with complexity.
Abstract the information technology artifacts of smart devices into information items, build an information technology system model, describe the attacker's permissions and attack categories, use the extended finite state machine to generate an information security knowledge model, and automatically generate test cases.
Through information security knowledge modeling, the efficiency of information security testing of smart devices is improved, which can better reflect the information security characteristics and application environment of the devices and provide better testing support.
Smart Images

Figure CN120750772A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of intelligent devices, and more specifically, relates to an information security knowledge modeling method for intelligent devices. Background Art
[0002] Smart devices are electronic devices with sensing, computing, connectivity, and interaction capabilities. They have been deeply applied to all aspects of social production and life, becoming the core force driving technological and economic development in the digital age. The information security of smart devices is crucial to their stable and reliable operation. Systematic and comprehensive information security testing is required to protect them from threats such as malicious attacks, data leaks, and functional abuse.
[0003] Currently, for smart devices, security testing methods such as penetration testing are often performed by external service providers, whose testers have no prior knowledge of the system (black box) or only limited prior knowledge (gray box). Therefore, testers need to collect information about the target smart device before the actual testing begins (for example, through reverse engineering techniques). In addition, the testing process is usually carried out by testers at the end of the development of the smart device, requiring a large investment of manpower and material resources, resulting in time delays and increased costs. Moreover, due to the technical limitations of the testers, potential vulnerabilities may be missed, resulting in serious security risks after the smart device is put into use. Because security testing requires identifying possible vulnerabilities in the system under test as much as possible, traditional penetration testing methods have limitations when dealing with the complexity of smart devices. Therefore, consideration is given to abstracting and modeling testing activities to support model-based test automation. Summary of the Invention
[0004] The purpose of the present invention is to overcome the shortcomings of the existing technology and provide an information security knowledge modeling method for smart devices. Based on the knowledge of network attacks and smart device vulnerabilities, the smart devices are abstracted and modeled to obtain an information security knowledge model of the smart devices, which is convenient for the automatic generation of test cases and other information during subsequent information security testing, thereby providing support for testers.
[0005] To achieve the above-mentioned purpose, the information security knowledge modeling method for smart devices of the present invention includes the following steps:
[0006] S1: Divide the information technology artifacts of smart devices into three categories: components, communication systems, and interfaces, and abstract each information technology artifact into an information item I i , i=1,2,…,N, N represents the number of information technology artifacts, each information item I i Described as a 5-tuple:
[0007] I i =(n i,b i ,t i ,app i ,p i )
[0008] Among them, n i Represents information item I i The name of the information item, which represents the identifier describing the information item; b i Represents information item I i Identifiers belonging to internal IT systems or external IT systems; i Represents information item I i Corresponding information technology artifact type; app i Represents information item I i The corresponding application, including the application name and application type; i Represents information item I i The corresponding security protection 3-tuple, p i =(SP i ,SC i ,SA i ), SP i Represents information item I i The corresponding security attribute set, SC i Represents information item I i Related security control set, SA i Represents information item I i A collection of related assets;
[0009] S2: Based on the connection relationship between each information technology artifact in the intelligent device information technology system, the adjacency matrix M between the information items is obtained. adj , thus obtaining the information technology system model M system =(Items,M adj ), Items represents the collection of all information items;
[0010] S3: Set the attacker's permissions to M att Described as a 2-tuple:
[0011] M att =(A,δ A )
[0012] Where A represents the attacker's permission set, A = {ReadWrite, Execute, Read, Write, FullControl}, ReadWrite represents read and write permissions, Execute represents execute permissions, Read represents read permissions, Write represents write permissions, and FullControl represents full control permissions; δ A:A→P(A) represents the mapping from a permission to its reachable subsequent permissions, and P(A) represents the power set of the attacker's permission set A:
[0013] δ A (ReadWrite)={ReadWrite,Execute,Read,Write,FullControl}
[0014] δ A (Execute)={Execute,Read,Write,FullControl}
[0015] δ A (Read)={Execute,Read,Write,FullControl}
[0016] δ A (Write)={ReadWrite,Execute,Read,Write,FullControl}
[0017] δ A (FullControl)={ReadWrite,FullControl}
[0018] S4: According to the specific situation of the smart device, set the attack mode set ATT, vulnerability set V and threat set U. Each attack mode, vulnerability and threat is set with an attack configuration. The combination of attack modes, vulnerabilities and threats with the same attack configuration is regarded as an attack category. The number of attack categories obtained is recorded as M, and the jth attack category is C. j , j=1,2,…,M, attack category C j Described as a 9-tuple:
[0019] C j =(u j ,a j ,f j ,v j ,l j ,s j ,cvss j ,evss j ,config j )
[0020] Among them, u j Indicates threat, j ∈U;a j Indicates the attack mode, a j ∈ATT;f j Indicates the parent-level attack mode. If the attack mode has a parent-level attack mode, then fj ∈ATT, otherwise f j =0;v j Indicates vulnerability, v j ∈V;l j Indicates the possibility level of the attack mode. If the current attack mode has no possibility level in the attack mode set ATT, it is set to the default level; j Indicates the severity level of the attack mode. If the current attack mode has no severity level in the attack mode set ATT, it is set to the default level; cvss j Indicates the CVSS rating applicable to the current attack category; evss j Indicates the exploitability subscore of the CVSS rating applicable to the current attack category; config j Indicates the attack configuration of the current attack category;
[0021] S5: Based on the extended finite state machine, the information security knowledge model M security Described as a 6-tuple:
[0022] M security =(S,∑E,∑C,S start ,Q,T)
[0023] Where: S is a non-empty set of finite states, the number of states it contains is K, and each state is state k ,k=1,2,…,K;each state k Described as a 3-tuple:
[0024]
[0025] Among them, i k Indicates state k The serial number of the corresponding information item, Indicates state k The corresponding information item, Indicates state k The attacker's authority corresponding to the information item, j k Indicates state k The serial number of the corresponding attack category, Indicates state k Attack configuration corresponding to the attack category;
[0026] ∑E represents a finite set of vulnerabilities; ∑C represents a finite set of output behaviors, S start represents the non-empty initial state set generated by the attacker attacking the system from the entrance, S start∈S; Q represents the set of state variables, which refers to the security attributes violated by the attack and the probability level of the attack; T represents a finite set of transitions, which contains the number of transitions D, and each transition is tran d , d=1,2,…,D, convert each tran d Described as a 3-tuple:
[0027] tran d =(S source,d ,S target,d ,A d )
[0028] Among them, S source,d ∈S represents the transformation tran d The source state, S target,d ∈S represents the transformation tran d The target state, A d Indicates that it is suitable for converting tran d A set of attack categories, including at least one threat category and one technical domain;
[0029] S6: Traverse all information items in the smart device information technology system model. If information item I i If it is a communication system or interface, a state is generated and its permission is ReadWrite; if the information item I i If it is a component, four states are generated for the information item, and the permissions are set to execute permission Excecute, read permission Read, write permission Write, and full control permission FullControl respectively;
[0030] All information items I i The generated states are merged to obtain the state set S;
[0031] S7: Define five types of transformations: self-transformation, transformation between component states, transformation from interface to communication system and vice versa, transformation from interface or communication system to component, and transformation from component to communication system; traverse all information items I in the intelligent device information technology system model. i , according to the five types of transformations defined, all possible transformations are generated. For each transformation, its target state is obtained, and then the attack configuration of the target state is obtained from the state set. According to the description of the attack category, all attack categories that match the technical domain and threat of the attack configuration of the target state are filtered to form the attack category set of the current transformation, thereby obtaining the 3-tuple of the transformation.
[0032] The present invention provides an information security knowledge modeling method for smart devices. First, the information technology work of the smart device is abstracted as an information item for description. The adjacency matrix between the information items is obtained based on the connection relationship between each information technology artifact in the information technology system of the smart device, thereby generating an information technology system model. The attacker's permissions and attack categories are described, and the information security knowledge model of the smart device is generated based on an extended finite state machine. The state set and transition set in the information security knowledge model are generated based on the information in the generated information technology system model, thereby completing the construction of the information security knowledge model.
[0033] The present invention has the following beneficial effects:
[0034] 1) In the present invention, the information technology artifacts of smart devices are abstracted into information items and combined with the adjacency matrix to generate an information technology system model to better reflect the information characteristics of smart devices;
[0035] 2) The present invention describes the attacker's permissions and attack categories and then maps them to the system model, thereby obtaining an information security knowledge model that includes real network attack scenarios. It can better reflect the information security characteristics and application environment of smart devices and provide better support for information security testing of smart devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a flowchart of a specific implementation method of the information security knowledge modeling method for smart devices of the present invention;
[0037] Figure 2 This is an example diagram of possible conversions between the five attacker permissions in the present invention;
[0038] Figure 3 It is an example diagram of the attack categories in the present invention. DETAILED DESCRIPTION
[0039] The following describes the specific embodiments of the present invention in conjunction with the accompanying drawings so that those skilled in the art can better understand the present invention. It should be noted that in the following description, when detailed descriptions of known functions and designs may dilute the main content of the present invention, such descriptions will be omitted here.
[0040] Example
[0041] Figure 1 This is a flowchart of a specific implementation of the information security knowledge modeling method for smart devices of the present invention. Figure 1 As shown, the information security knowledge modeling method for smart devices of the present invention includes the following steps:
[0042] S101: Information Technology Artifact Description:
[0043] The information security of smart devices requires consideration of the information technology systems that may be affected by cyberattacks. In the smart device sector, information technology systems can be divided into internal and external information technology systems. Internal information technology systems include three types of information technology artifacts: components, communication systems, and interfaces. External systems, represented in the environment model, include all systems that communicate with smart devices at the information technology level or have an information technology impact, such as wireless communication terminals, backend servers, and test equipment. The information technology artifacts of external information technology systems can also be divided into three categories: components, communication systems, and interfaces.
[0044] Therefore, in the present invention, the information technology artifacts of smart devices are divided into three categories: components, communication systems and interfaces, and each information technology artifact is abstracted as an information item I. i , i=1,2,…,N, N represents the number of information technology artifacts, each information item I i Described as a 5-tuple:
[0045] I i =(n i ,b i ,t i ,app i ,p i )
[0046] in,
[0047] 1)n i Represents information item I i The name of the information item, representing an identifier that describes the information item (e.g., diagnostic CAN).
[0048] 2)b i Represents information item I i An identifier belonging to an internal information technology system or an external information technology system, in this embodiment, b i ∈{internal,external}.
[0049] 3)t i Represents information item I i The corresponding information technology artifact type. Different attacks can be carried out according to the type of information item. In practical applications, t i Multi-level types are used, that is, subtypes of information technology artifacts can also be included to better characterize the type information of information technology artifacts. For example, the type of a communication system can be expressed as {Communication, bus, dbus}, that is, the information item corresponds to the dbus communication system artifact.
[0050] 4) appi Represents information item I i The corresponding application includes the application name and application type. i If it does not exist, the default filler can be used to fill it.
[0051] 5)p i Represents information item I i The corresponding security protection 3-tuple. Security protection refers to the measures taken during the development process to protect smart devices from network attacks. Security attributes, assets to be protected, and implemented security controls are mainly related to this purpose. Security attributes refer to the security-related functional attributes of security protection artifacts. In this embodiment, security attributes use six security attributes, namely confidentiality, integrity, availability, authentication, authorization, and non-repudiation. Assets include specific values that need to be protected. The purpose of a network attack is usually to obtain or destroy protected assets, including intellectual property, privacy, functional data, etc. Assets depend on systems, data, protocols, functions, and applications. Each asset contains at least one security attribute. Security control represents the type of security control technology used, which is related to the protection of security attributes. For example, "message encryption" is a type of security control that is related to ensuring the confidentiality of data.
[0052] Therefore, in the present invention, a security protection description in the form of a 3-tuple is provided for each information item of the smart device:
[0053] p i =(SP i ,SC i ,SA i )
[0054] in:
[0055] 1) SP i Represents information item I i The corresponding security attribute set, That is, the information item contains at least one security attribute.
[0056] 2)SC i Represents information item I i The set of associated security controls. This set may also be empty if an information item has no security controls or has not yet been defined in its current state.
[0057] 3)SA i Represents information item I iA collection of related assets. This set can also be empty if a project does not have any assets or they have not yet been finalized at the current stage of development.
[0058] For example, the security protection description of an information item is as follows:
[0059]
[0060] P1 describes a security protection without specifying security controls and assets.
[0061] S102: Constructing Information Technology System Model:
[0062] According to the connection relationship between each information technology artifact in the intelligent device information technology system, the adjacency matrix M between the information items is obtained. adj , thus obtaining the information technology system model M system =(Items,M adj ), Items represents the collection of all information items.
[0063] S103: Description of attacker's permissions:
[0064] After defining the system model and modeling its security protection, the next question is how to represent the attack path in the model. To facilitate description, the present invention proposes the concept of attacker permissions. Attacker permissions are an abstract category that describes the attacker's ability to carry out specific attacks on system model items. The present invention defines the following five permissions: ReadWrite (functional communication link), Execute (functional component), Read (functional component), Write (functional component), and FullControl (functional component). Figure 2 This diagram illustrates the possible transitions between the five attacker permissions in this invention. Starting with "Read / Write" permissions for the communication system on the left, any of the four permissions for the middle component can be obtained. Only with "Write" or "Full Control" permissions can access the communication system on the right be achieved.
[0065] The attacker's permissions and the assumption that they can access the connected communication system when write or full control permissions are achieved are used to map potential attack paths in the system model. To this end, a permission is assigned to each information item in the information technology system model, and the attack path is modeled as a series of attack steps leading to a specific permission. att Defined as a 2-tuple:
[0066] M att =(A,δ A )
[0067] in,
[0068] 1) A represents the attacker's permission set, A = {ReadWrite, Execute, Read, Write, FullControl};
[0069] 2)δ A :A→P(A) represents the mapping from one permission to its reachable subsequent permissions. P(A) represents the power set (the set of all subsets) of the attacker permission set A. The mappings of the five attacker permissions are as follows:
[0070] δ A (ReadWrite)={ReadWrite,Execute,Read,Write,FullControl}
[0071] δ A (Execute)={Execute,Read,Write,FullControl}
[0072] δ A (Read)={Execute,Read,Write,FullControl}
[0073] δ A (Write)={ReadWrite,Execute,Read,Write,FullControl}
[0074] δ A (FullControl)={ReadWrite,FullControl}
[0075] Applying attacker permissions to the information technology system model can be used to represent the attacker's attack path from the system entry (such as a Bluetooth communication interface) to a specific function within the smart device (such as full control of the music playback function).
[0076] S104: Attack Category Description:
[0077] In order to describe which attacks will lead to permission conversion (for example, from read / write to execute) and which vulnerabilities will be exploited, the present invention also describes the attack class. Since each attack step in the attack path uses a vulnerability exploit to exploit the vulnerability, the conversion between two attacker permissions can correspond to multiple attack classes. Each attack class has an attack configuration, which includes at least one threat category and a technology domain. The attack configuration will serve as the main basis for determining which attack classes will be used for permission conversion. Figure 3 This is an example diagram of the attack categories in the present invention. Figure 3As shown in Figure 1, the privileges of two attackers are converted through attacks, which are described by AC (Attack Category). Each privilege conversion passes through at least one AC, which includes attack-related data.
[0078] In the present invention, according to the specific conditions of the smart device, an attack pattern set ATT, a vulnerability set V and a threat set U are set. Each attack pattern, vulnerability and threat is provided with an attack configuration, and the combination of attack patterns, vulnerabilities and threats with the same attack configuration is regarded as an attack category. In this embodiment, the attack patterns in the attack pattern set ATT adopt the CAPEC attack pattern categories that comply with MITRE, the vulnerabilities in the vulnerability set V adopt the vulnerability types defined in CWE, and the threats in the threat set U adopt the threat types defined in STRIDE. The number of attack categories obtained is recorded as M, and the jth attack category is C. j ,j=1,2,…,M. The attack category C j Described as a 9-tuple:
[0079] C j =(u j ,a j ,f j ,v j ,l j ,s j ,cvss j ,evss j ,config j )
[0080] in:
[0081] 1)u j Indicates threat, j ∈U.
[0082] 2)a j Indicates the attack mode, a j ∈ATT.
[0083] 3)f j Indicates the parent-level attack mode. If the attack mode has a parent-level attack mode, then f j ∈ATT, otherwise f j =0.
[0084] 4)v j Indicates vulnerability, v j ∈V.
[0085] 5)l j Indicates the probability level of the attack pattern. If the current attack pattern does not have a probability level in the attack pattern set ATT, it is set to the default level. Generally, the default level is set to a medium level.
[0086] 6)s j Indicates the severity level of the attack pattern. If the current attack pattern does not have a severity level in the attack pattern set ATT, the default level is set.
[0087] 7)cvss j Indicates the CVSS rating applicable to the current attack category.
[0088] 8)evss j Indicates the exploitability subscore of the CVSS rating applicable to the current attack category.
[0089] 9)config j Indicates the attack configuration of the current attack category, which includes at least one threat category and one technical domain.
[0090] S105: Constructing an information security knowledge model:
[0091] Based on the system model generated in steps S101-S104, an information security knowledge model of the smart device is constructed. In the present invention, the information security knowledge model M is transformed into an information security knowledge model based on an extended finite state machine (EFSM). security Described as a 6-tuple:
[0092] M security =(S,∑E,∑C,S start ,Q,T)
[0093] in:
[0094] 1) S is a non-empty set of finite states, the number of states it contains is K, and each state is state k ,k=1,2,…,K. Each state k Described as a 3-tuple:
[0095]
[0096] Among them, i k Indicates state k The serial number of the corresponding information item, Indicates state k The corresponding information item, Indicates state k The attacker's authority corresponding to the information item, j k Indicates state k The serial number of the corresponding attack category, Indicates state k Attack configuration corresponding to the attack category.
[0097] 2)∑E represents a finite set of vulnerabilities;
[0098] 3) ∑C represents a finite set of output behaviors. Since the present invention does not require explicit output behaviors,
[0099] 4)S start represents the non-empty initial state set generated by the attacker attacking the system from the entrance, S start ∈S.
[0100] 5) Q represents the set of state variables, which refers to the security properties violated by the attack and the probability level of the attack;
[0101] 6) T represents a finite set of transformations, the number of transformations it contains is D, and each transformation is tran d , d=1,2,…,D, convert each tran d Described as a 3-tuple:
[0102] tran d =(S source,d ,S target,d ,A d )
[0103] Among them, S source,d ∈S represents the transformation tran d The source state, S target,d ∈S represents the transformation tran d The target state, A d Indicates that it is suitable for converting tran d An attack category set consisting of a set of attack categories.
[0104] S106: Generate a state set of the information security knowledge model:
[0105] The state set S of the information security knowledge model is determined based on the information items in the system model and the attacker's permissions. The process for generating the state set S in the present invention is to traverse all information items in the smart device information technology system model, check their information technology artifact types, and generate corresponding permission states based on the information technology artifact types. The specific situation is as follows:
[0106] If the information item I i If it is a communication system or interface, a state is generated and its permission is set to read and write permission ReadWrite.
[0107] If the information item I i If it is a component, four states are generated for the information item, and the permissions are set to execute permission Excecute, read permission Read, write permission Write, and full control permission FullControl respectively.
[0108] All information items I i The generated states are merged to obtain the state set S.
[0109] S107: Generate a transformation set for the information security knowledge model:
[0110] The transition set is first determined by the permission transitions defined for the attacker's permissions. This invention defines five types of transitions: self-transitions, transitions between component states, transitions from the interface to the communication system and vice versa, transitions from the interface or communication system to the component, and transitions from the component to the communication system. These five transition types define the possible transitions in the smart device information security knowledge model. For each transition, the attack class that causes the state transition must be determined. Therefore, the specific method for generating the transition set in this invention is as follows:
[0111] Traverse all information items I in the smart device information technology system model i , according to the five types of transformations defined, all possible transformations are generated. For each transformation, its target state is obtained, and then the attack configuration of the target state is obtained from the state set. According to the description of the attack category, all attack categories that match the technical domain and threat of the attack configuration of the target state are filtered to form the attack category set of the current transformation, thereby obtaining the 3-tuple of the transformation.
[0112] By adopting the above method, an information security knowledge model of smart devices for information security testing can be obtained. Testers can generate information security test cases for smart devices based on the information security knowledge model, thereby improving testing efficiency.
[0113] Although the above describes the illustrative specific embodiments of the present invention to facilitate understanding of the present invention by those skilled in the art, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concepts of the present invention are protected.
Claims
1. A method for modeling information security knowledge for smart devices, characterized by: The following steps are involved: S1: Divide the information technology artifacts of smart devices into three categories: components, communication systems, and interfaces, and abstract each information technology artifact into an information item I i , i=1,2,…,N, N represents the number of information technology artifacts, each information item I i Described as a 5-tuple: I i =(n i ,b i ,t i ,app i ,p i ) Among them, n i Represents information item I i The name of the information item, which represents the identifier describing the information item; b i Represents information item I i Identifiers belonging to internal IT systems or external IT systems; i Represents information item I i Corresponding information technology artifact type; app i Represents information item I i The corresponding application, including the application name and application type; i Represents information item I i The corresponding security protection 3-tuple, p i =(SP i ,SC i ,SA i ), SP i Represents information item I i The corresponding security attribute set, SC i Represents information item I i Related security control set, SA i Represents information item I i A collection of related assets; S2: Based on the connection relationship between each information technology artifact in the intelligent device information technology system, the adjacency matrix M between the information items is obtained. adj , thus obtaining the information technology system model M system =(Items,M adj ), Items represents the collection of all information items; S3: Set the attacker's permissions to M att Described as a 2-tuple: M att =(A,δ A ) Where A represents the attacker's permission set, A = {ReadWrite, Execute, Read, Write, FullControl}, ReadWrite represents read and write permissions, Execute represents execute permissions, Read represents read permissions, Write represents write permissions, and FullControl represents full control permissions; δ A :A→P(A) represents the mapping from a permission to its reachable subsequent permissions, and P(A) represents the power set of the attacker's permission set A: δ A (ReadWrite)={ReadWrite,Execute,Read,Write,FullControl} δ A (Execute)={Execute,Read,Write,FullControl} δ A (Read)={Execute,Read,Write,FullControl} δ A (Write)={ReadWrite,Execute,Read,Write,FullControl} δ A (FullControl)={ReadWrite,FullControl} S4: According to the specific situation of the smart device, set the attack mode set ATT, vulnerability set V and threat set U. Each attack mode, vulnerability and threat is set with an attack configuration. The combination of attack modes, vulnerabilities and threats with the same attack configuration is regarded as an attack category. The number of attack categories obtained is recorded as M, and the jth attack category is C. j , j=1,2,…,M, attack category C j Described as a 9-tuple: C j =(u j ,a j ,f j ,v j ,l j ,s j ,cvss j ,evss j ,config j ) Among them, u j Indicates threat, j ∈U;a j Indicates the attack mode, a j ∈ATT;f j Indicates the parent-level attack mode. If the attack mode has a parent-level attack mode, then f j ∈ATT, otherwise f j =0;v j Indicates vulnerability, v j ∈V;l j Indicates the possibility level of the attack mode. If the current attack mode has no possibility level in the attack mode set ATT, it is set to the default level; j Indicates the severity level of the attack mode. If the current attack mode has no severity level in the attack mode set ATT, it is set to the default level; cvss j Indicates the CVSS rating applicable to the current attack category; evss j Indicates the exploitability subscore of the CVSS rating applicable to the current attack category; config j Indicates the attack configuration of the current attack category; S5: Based on the extended finite state machine, the information security knowledge model M security Described as a 6-tuple: M security =(S,∑E,∑C,S start ,Q,T) Where: S is a non-empty set of finite states, the number of states it contains is K, and each state is state k ,k=1,2,…,K;each state k Described as a 3-tuple: Among them, i k Indicates state k The serial number of the corresponding information item, Indicates state k The corresponding information item, Indicates state k The attacker's authority corresponding to the information item, j k Indicates state k The serial number of the corresponding attack category, Indicates state k Attack configuration corresponding to the attack category; ∑E represents a finite set of vulnerabilities; ∑C represents a finite set of output behaviors, S start represents the non-empty initial state set generated by the attacker attacking the system from the entrance, S start ∈S; Q represents the set of state variables, which refers to the security attributes violated by the attack and the probability level of the attack; T represents a finite set of transitions, which contains the number of transitions D, and each transition is tran d , d=1,2,…,D, convert each tran d Described as a 3-tuple: tran d =(S source,d ,S target,d ,A d ) Among them, S source,d ∈S represents the transformation tran d The source state, S target,d ∈S represents the transformation tran d The target state, A d Indicates that it is suitable for converting tran d A set of attack categories, including at least one threat category and one technical domain; S6: Traverse all information items in the smart device information technology system model. If information item I i If it is a communication system or interface, a state is generated and its permission is ReadWrite; if the information item I i If it is a component, four states are generated for the information item, and the permissions are set to execute permission Excecute, read permission Read, write permission Write, and full control permission FullControl respectively; All information items I i The generated states are merged to obtain the state set S; S7: Define five types of transformations: self-transformation, transformation between component states, transformation from interface to communication system and vice versa, transformation from interface or communication system to component, and transformation from component to communication system; traverse all information items I in the intelligent device information technology system model. i , according to the five types of transformations defined, all possible transformations are generated. For each transformation, its target state is obtained, and then the attack configuration of the target state is obtained from the state set. According to the description of the attack category, all attack categories that match the technical domain and threat of the attack configuration of the target state are filtered to form the attack category set of the current transformation, thereby obtaining the 3-tuple of the transformation.
2. The information security knowledge modeling method according to claim 1, characterized in that: The security attributes in step S1 include confidentiality, integrity and availability.
3. The information security knowledge modeling method according to claim 1, characterized in that: The security attributes in step S1 include confidentiality, integrity, availability, authentication, authorization and non-repudiation.
4. The information security knowledge modeling method according to claim 1, characterized in that: The attack patterns in the attack pattern set ATT in step S4 adopt the CAPEC attack pattern type defined by MITRE.
5. The information security knowledge modeling method according to claim 1, characterized in that: The vulnerabilities in the vulnerability set V in step S4 adopt vulnerability types that comply with the CWE definition.
6. The information security knowledge modeling method according to claim 1, characterized in that: The threats in the threat set U in step S4 adopt the threat types defined by STRIDE.
Citation Information
Patent Citations
Method and device for generating attack graph based on knowledge graph
CN108933793A
A method of constructing knowledge base for network security
CN109063205A
Application security demand analysis recommendation method based on knowledge graph
CN115599345A
Network threat knowledge graph construction method based on SecBABC
CN119106141A
Knowledge plane construction method and system based on ensemble learning and federal learning
CN119135379A