Cybersecurity risk assessment analysis system, method, and related devices
By integrating physical security, network security, and management security modules, the network security risk assessment and analysis system solves the problem of inaccurate assessment in existing technologies, achieves comprehensive and closed-loop security protection for complex network environments, and improves security response speed and accuracy.
Patent Information
- Application Number
- CN202610508644.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-17
- Publication Date
- 2026-07-10
AI Technical Summary
Existing cybersecurity risk assessment methods fail to fully consider the combined impact of multiple dimensions such as physical security, network security, and management security, resulting in inaccurate assessment results that are difficult to meet the actual needs in complex network environments.
This invention provides a network security risk assessment and analysis system, including a physical security module, a network security module, a management security module, and a risk assessment and analysis module. By integrating access control management, monitoring, smoke alarms, and power management, it achieves real-time perception and data collection of the data center environment. Combined with system construction, network security management, and personnel safety management systems, it conducts multi-dimensional data analysis and real-time assessment.
It has achieved accurate identification and timely early warning of potential security risks, improved the speed and accuracy of security response, and built a comprehensive, closed-loop security protection system, ensuring comprehensive security from hardware to software, technology to management.
Smart Images

Figure CN122372582A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a network security risk assessment and analysis system, method and related equipment. Background Technology
[0002] Network security refers to the process of protecting the hardware, software, and data resources in a network system from accidental or malicious damage, alteration, or leakage, ensuring continuous and reliable system operation, and uninterrupted network services. With the rapid development of computer technology, network applications have expanded from early stand-alone computing and file processing to enterprise-level information processing and sharing systems based on complex intranets, extranets, and the global Internet. The increased processing and connectivity capabilities of systems have made network connection-based security issues increasingly prominent. Overall network security involves multiple levels, including physical security, network topology security, system security, application security, and management security.
[0003] In practical applications, network administrators need to effectively protect and control access to, read from, and write to local network information to prevent threats such as "backdoors," viruses, unauthorized access, denial-of-service attacks, unauthorized resource occupation, and network attacks. Security and confidentiality departments, on the other hand, need to filter and block illegal, harmful, or state secret-related information to prevent information leaks from causing losses to society and the nation. Computer security issues are like fire prevention and theft prevention; they require preventative measures. However, existing security threats are often insidious and sudden, and once they occur, they frequently cause significant losses.
[0004] Currently, cybersecurity risk assessment is a crucial tool for proactive defense and security management, and the comprehensiveness and accuracy of its assessment methods directly impact the effectiveness of cybersecurity protection. However, existing cybersecurity risk assessment methods are insufficient in their content coverage, failing to fully consider the combined impact of multiple dimensions such as physical security, network security, and management security. This results in inaccurate assessment results, making it difficult to meet the actual needs of today's complex network environment. Summary of the Invention
[0005] This application aims to at least address one of the aforementioned technical deficiencies. In view of this, this application provides a network security risk assessment and analysis system, apparatus, device, and readable storage medium to address the technical deficiency of inaccurate network security risk assessment in the prior art.
[0006] A network security risk assessment and analysis system includes: a physical security module, a network security module, a management security module, and a risk assessment and analysis module. The risk assessment and analysis module is connected to the physical security module, the network security module, and the management security module, respectively. The physical security module is responsible for collecting and recording physical security data of the target computer room and transmitting it to the risk assessment and analysis module. The physical security module includes an access control module for managing access permissions to the target computer room. The network security module is responsible for ensuring the security of data transmission, firewall security, and target server security of the target computer room and its corresponding target network security system, as well as recording and collecting network security data of the target computer room and transmitting it to the risk assessment and analysis module. The management security module is responsible for recording and collecting system management regulations, network security management regulations, personnel security management regulations, and maintenance management regulations of the target computer room and the target network security system, forming system management security data of the target computer room and the target network security system, and transmitting it to the risk assessment and analysis module. The risk assessment and analysis module is responsible for receiving and analyzing the various security data transmitted by the physical security module, the network security module, and the system management security module in real time, assessing the security risks existing in the target computer room, and issuing warnings based on preset warning conditions and the security risk assessment results of the target computer room.
[0007] Preferably, the target computer room is equipped with a monitoring module, a smoke alarm module, and a power supply module; the smoke alarm module includes a smoke sensor, an alarm, and a fire extinguisher; the monitoring module includes various first monitoring devices installed at the entrance of the target computer room and various second monitoring devices installed inside the target computer room, with each first monitoring device and each second monitoring device providing comprehensive real-time monitoring of the target computer room; the power supply module is responsible for providing uninterrupted power to all electrical equipment in the target computer room.
[0008] Preferably, the process by which the physical security module collects and records physical security data of the target computer room and transmits it to the risk assessment and analysis module includes: the access control management module analyzing the access control request permissions of the target computer room, prohibiting access access requests without permissions, granting access access requests with permissions, recording all access control information for access requests to the target computer room, and reporting it to the physical security module; the monitoring module collecting and reporting monitoring data from various monitoring devices in the target computer room to the physical security module; the smoke alarm module collecting and reporting smoke alarm information from the target computer room to the physical security module; the power supply module collecting and reporting power consumption data from the target computer room to the physical security module; and the physical security module integrating the access control information, monitoring data, smoke alarm information, and power consumption data of the target computer room to generate physical security data of the target computer room and transmitting it to the risk assessment and analysis module.
[0009] Preferably, the network security module accesses the target network platform through a preset encrypted access method based on the target server to conduct data exchange; the process of the network security module recording and collecting network security data of the target data center and transmitting it to the risk assessment and analysis module includes: the network security module collecting and checking the data transmission path, data, firewall and network security of the target data center and its corresponding target network security system, forming corresponding network security data, and transmitting the formed network security data to the target network platform through the target server.
[0010] Preferably, the process of the security management module recording and collecting system management regulations, network security management regulations, personnel security management regulations, and maintenance management regulations for the target computer room and the target network security system, and forming system management security data for the target computer room and the target network security system and transmitting it to the risk assessment and analysis module includes: the system construction management module constructing a simulated network for the target computer room based on the structural parameters and operating environment parameters of the target computer room, constructing corresponding system management regulations for the simulated network, and managing the constructed simulated network according to the constructed system management regulations, thus forming a system management data transmission management security module for the target computer room and the target network security system; and the network security management module constructing and managing the network security management regulations for the target computer room and the target network security system based on the constructed simulated network, and managing the constructed simulated network according to the constructed network security management regulations, thus forming a network security management data module for the target computer room and the target network security system. Data is transmitted to the management security module; the personnel security management module, based on the constructed simulated network and the constructed network security management system, constructs and manages the personnel involved in the target computer room and the constructed simulated network according to the personnel security management system of the target computer room and the target network security system, and generates personnel security management data for the target computer room and the target network security system, which is then transmitted to the management security module; the system maintenance management module, based on the constructed simulated network, constructs maintenance management system for the target computer room and the target network security system, and performs maintenance management on the constructed simulated network according to the constructed maintenance management system, generating maintenance management data for the target computer room and the target network security system, which is then transmitted to the management security module; the management security module collects, integrates, and analyzes the received system security management data, network security management data, personnel security management data, and maintenance management data, forming system security management data for the target computer room and the target network security system, which is then transmitted to the risk assessment and analysis module.
[0011] Preferably, the network security module accesses the target network platform through the target server; the fire extinguisher is connected to the alarm, and when the alarm sounds, the switch of the fire extinguisher is triggered simultaneously.
[0012] Preferably, the management security module includes a system construction management module, a network security management module, a personnel security management module, and a system maintenance management module. The system construction management module is responsible for building and managing the system management regulations for the target computer room and the target network security system and transmitting them to the management security module. The network security management module is responsible for building and managing the network security management regulations for the target computer room and the target network security system and transmitting them to the management security module. The personnel security management module is responsible for building and managing the personnel security management regulations for the target computer room and the target network security system and transmitting them to the management security module. The system maintenance management module is responsible for building and managing the maintenance management regulations for the target computer room and the target network security system and transmitting them to the management security module.
[0013] Preferably, the system further includes an early warning module and several key information infrastructure devices. The early warning module and each key information infrastructure device are connected, and the early warning module is connected to the risk assessment and analysis module. The early warning module includes a storage module. Each server hosting a key information infrastructure device is configured with a corresponding data cloud. Each data cloud has a corresponding backup cloud. Each data cloud and its corresponding backup cloud are connected via a virtual signal. The data cloud is responsible for transmitting the first target data from the target database to the early warning module, which then encrypts it twice before analyzing it and backing it up to its corresponding backup cloud and storage module. The early warning module performs fusion analysis on the relevant data from each of the key information infrastructure devices and issues an early warning, and synchronizes the early warning information to the risk assessment and analysis module.
[0014] Preferably, the early warning module further includes a display module, an alarm module, a data analysis module, and a data encryption module, with the storage module connected to the data analysis module. The data analysis module includes a decompression module, a calculation module, and a filtering analysis module. The data encryption module includes a first encryption module and a second encryption module. The first encryption module is linked to the second encryption module, and the encryption algorithm of the first encryption module is different from the encryption mode of the second encryption module. Based on this, the process of the data cloud transmitting the first target data of the target database to the early warning module for double encryption, analysis, and backup to the corresponding backup cloud and storage module includes: the data cloud transmitting the first target data of the target database to the decompression module; the decompression module parsing the first target data to obtain the first data and transmitting it to the calculation module. The system comprises the following modules: a calculation module receives and calculates the first data to obtain the second data, which is then transmitted to the filtering and analysis module; the filtering and analysis module receives and performs filtering and analysis on the second data to obtain the third data, which is then transmitted to the data cloud; data exceeding a preset warning value in the third data is reported to the alarm module and the display module, whereby the alarm module issues a data warning, and the display module displays the warning information and corresponding data from the alarm module; the data cloud transmits the third data to the first encryption module; the first encryption module receives and performs initial encryption on the third data to obtain the fourth data, which is then transmitted to the second encryption module; the second encryption module encrypts the fourth data to obtain the fifth data, which is then transmitted to the data cloud, whereby the data cloud backs up the fifth data to the backup cloud and the storage module.
[0015] A network security risk assessment and analysis method includes: constructing an access control management system for a target data center and implementing access control management for the target data center based on this system; collecting and recording access control management data and real-time monitoring data of the target data center based on the access control management system to determine the physical security data of the target data center; acquiring network security data of the target data center and its corresponding target network security system; constructing and managing system management systems, network security management systems, personnel security management systems, and maintenance management systems for the target data center and its target network security system; recording and collecting these systems based on the system management systems, network security management systems, personnel security management systems, and maintenance management systems of the target data center and its target network security system, and forming system management security data for the target data center and its target network security system; analyzing various security data of the target data center and its target network security system in real time, assessing the security risks existing in the target data center, and issuing warnings based on preset warning conditions and the security risk assessment results of the target data center; and encrypting the first target data in the target database twice before analysis, backup, and storage.
[0016] A network security risk assessment and analysis device includes: one or more processors and a memory; the memory stores computer-readable instructions, which, when executed by the one or more processors, implement the steps of the network security risk assessment and analysis method described above.
[0017] A readable storage medium storing computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of the network security risk assessment and analysis method described above.
[0018] As can be seen from the above introduction, when a network security risk assessment is required, this application provides a network security risk assessment and analysis system. By setting up a physical security module, a network security module, and a management security module, it comprehensively collects and monitors data from three core dimensions: the physical environment of the data center, network system operation, and personnel management. The physical security module integrates access control, monitoring, smoke alarms, and power management, enabling real-time perception of risks in the data center environment. The network security module covers data transmission, firewall, and server security. The management security module systematically incorporates system construction, network security, personnel safety, and maintenance management. This multi-dimensional and comprehensive assessment system effectively overcomes the shortcomings of traditional assessment methods that only focus on single or partial security elements, ensuring the comprehensiveness and systematic nature of the risk assessment. The risk assessment and analysis module is connected in real-time to the above three modules, continuously receiving and analyzing various security data from the physical, network, and management levels, realizing a shift from static assessment to dynamic monitoring. By real-time correlation and analysis of comprehensive data, the system can accurately identify potential security risks and issue timely warnings based on preset early warning conditions. This overcomes the shortcomings of traditional assessment methods, which are often lagging and passive, truly achieving prevention before problems arise and significantly improving the speed and accuracy of security response. It not only focuses on technical network security and physical environment security but also incorporates management systems into the risk assessment framework, achieving a high degree of integration between technology and management. By digitizing and incorporating data on soft factors such as personnel operating procedures and system maintenance processes into the analysis, it can effectively identify security vulnerabilities caused by management loopholes or human negligence. This constructs a comprehensive, closed-loop security protection system from hardware to software and from technology to management, providing practical and effective protection for the security of data centers and information systems in complex network environments. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort. Figure 1 This application provides a schematic diagram of a system architecture for implementing network security risk assessment and analysis; Figure 2 A flowchart for implementing a network security risk assessment and analysis method provided in this application; Figure 3 This is a hardware structure block diagram of a network security risk assessment and analysis device disclosed in this application. Detailed Implementation
[0020] The technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0021] Network security refers to the protection of a network system's hardware, software, and data from accidental or malicious damage, alteration, or leakage, ensuring continuous, reliable, and normal system operation and uninterrupted network services. From the perspective of network operators and administrators, the goal is to protect and control access to, read from, and write to local network information, preventing threats such as "backdoors," viruses, unauthorized access, denial-of-service attacks, and unauthorized occupation and control of network resources, and deterring and defending against cyberattacks. For security and confidentiality departments, the aim is to filter and block illegal, harmful, or state secret information to prevent leaks of confidential information, avoid harm to society, and prevent significant losses to the nation. Given that most current cybersecurity risk assessment and analysis solutions are ill-suited to complex and ever-changing business needs, the applicant has developed a cybersecurity risk assessment and analysis solution. This system digitizes and incorporates data on soft factors such as personnel operating procedures and system maintenance processes into its analysis. It can effectively identify security vulnerabilities caused by management loopholes or human negligence, thereby constructing a comprehensive, closed-loop security protection system that integrates hardware and software, as well as technology and management. This provides a practical and effective guarantee for the security of data centers and information systems in complex network environments.
[0022] The method provided in this application can be used in a wide variety of general-purpose or special-purpose computing device environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor devices, and distributed computing environments including any of the above devices. This application provides a network security risk assessment and analysis scheme, which can be applied to various information security management systems and to various computer terminals or smart terminals. The executing entity can be the processor or server of the computer terminal or smart terminal.
[0023] The following is combined with Figure 1 This application introduces an optional system architecture for implementing network security risk assessment and analysis, such as... Figure 1 As shown, the system may include: a physical security module, a network security module, a management security module, and a risk assessment and analysis module. The risk assessment and analysis module can be connected to the physical security module, the network security module, and the management security module, respectively.
[0024] The physical security module includes an access control module, which manages access permissions for the target computer room. The target computer room is the server room hosting the network system. The target computer room is equipped with a monitoring module, a smoke alarm module, and a power supply module; the smoke alarm module may include smoke sensors, alarms, and fire extinguishers. The monitoring module includes primary monitoring devices located at the entrance of the target computer room and secondary monitoring devices inside the target computer room, with each primary and secondary monitoring device providing comprehensive real-time monitoring of the target computer room; the power supply module is responsible for providing uninterrupted power to all electrical equipment in the target computer room.
[0025] Specifically, in practical applications, in order to ensure the physical and network security of the target data center, when selecting a location for the target data center, it is advisable to place it on the 3rd floor or above to ensure that the target data center is protected from natural disasters such as floods and insect infestations.
[0026] The necessity of setting up a monitoring module for the target computer room is to achieve comprehensive perception of its physical boundaries. The first monitoring device installed at the entrance of the target computer room is equivalent to the "first line of defense." By monitoring the entrance and exit of the target computer room 24 hours a day, it is possible to record the facial features, entry and exit times, and items carried by all personnel entering and exiting. This is not only a physical barrier to prevent unauthorized entry, but more importantly, it can compare the data with the implementation status of personnel security management systems in the management security module (such as whether equipment was taken out in violation of regulations, whether the card was swiped by the correct person), thereby discovering loopholes in the implementation of the system.
[0027] The secondary monitoring devices deployed inside the target data center function as "internal behavior audits." Core equipment (such as servers and switches) within the target data center is frequently operated, and the internal monitoring records the daily operational behaviors of maintenance personnel. In the event of a data breach or human-caused equipment damage, the specific operational process can be traced through the video recordings to determine whether it was an accidental error or malicious sabotage. The combination of entrance and internal monitoring eliminates blind spots in the target data center's surveillance, ensuring full visibility from entry to equipment operation, and providing objective physical behavioral evidence for the risk assessment and analysis module.
[0028] The purpose of installing a smoke alarm module in the target data center is to cope with sudden physical environmental disasters. Traditional risk assessments often only focus on the logical damage caused by cyberattacks. However, in reality, physical environmental disasters can be devastating to data centers. Fires not only burn hardware and cause service interruptions, but also result in the permanent loss of core data. The collaboration of multiple components—sensors, alarms, and fire extinguishers—can improve the physical security of the target data center. The smoke sensor acts as the "sensing layer," responsible for real-time monitoring of smoke concentration in the air and triggering a signal immediately upon detecting an anomaly. The alarm acts as the "notification layer," issuing audible and visual alarms in the initial stages of a fire to remind personnel to evacuate promptly or handle the situation manually, preventing escalation. In practice, fire extinguishers can be connected to the alarm; when the alarm sounds, the fire extinguisher is activated simultaneously to extinguish the fire. The fire extinguisher acts as the "execution layer," serving as the last line of physical defense, automatically extinguishing initial fires without intervention and preventing their spread. The alarm records generated by this smoke alarm module are transmitted to the risk assessment and analysis module. If a data center frequently experiences false smoke alarms or genuine alarms, it indicates that the physical environment of the data center is at high risk, and the system will increase the physical security risk score of the data center based on this data.
[0029] Setting up a power module (uninterruptible power supply) for the target data center is crucial to ensuring the continuity of security assessments, as cybersecurity risk assessment is an ongoing process. If the data center suddenly loses power, not only will the business systems be paralyzed, but the aforementioned monitoring and smoke alarm modules will also fail, rendering the entire security system "blind" at critical moments. "Uninterruptible power supply" means that even if the mains power is interrupted, the power module (such as a UPS) can immediately take over the power supply. It is responsible for supplying power to "all electrical equipment in the target data center." It's important to emphasize that this is not only to ensure the business servers don't crash, but also to ensure that "the security modules themselves" (surveillance cameras, smoke sensors, access control systems) can continue to function normally in emergencies. Only by ensuring continuous power supply can the risk assessment and analysis module still receive the latest on-site data (such as footage of the moment the power went out, the final smoke concentration, etc.) during a disaster, thereby accurately determining the cause of the incident.
[0030] The aforementioned modules are not simply a collection of devices, but rather a complete physical security closed loop encompassing "environmental awareness—disaster prevention and control—capability maintenance." The monitoring module enables behavioral visibility, the smoke alarm module ensures hazard control, and the power module guarantees sustainable capability. This ensures that the physical security module provides the risk assessment and analysis module with a real, reliable, and continuous data source, fundamentally solving the problem of missing or interrupted physical security data in existing technologies. Therefore, based on this setup, the physical security module is responsible for collecting and recording the physical security data of the target data center and transmitting it to the risk assessment and analysis module for evaluation and analysis of the target data center's physical security.
[0031] The process by which the physical security module collects and records physical security data of the target computer room and transmits it to the risk assessment and analysis module may include the following: The access control management module analyzes the access control request permissions for the target computer room, prohibits access requests without authorization, and allows access requests with authorization. It also records the access control information of all access requests to the target computer room and reports it to the physical security module.
[0032] Specifically, if an access control system only handles opening and closing doors, it's just an ordinary electrical lock. However, the access control management module in this solution transforms physical access behavior into quantifiable, traceable, and analyzable security data through a series of actions. The target computer room is the physical carrier of core information assets. If anyone can freely enter and exit, then even the most powerful firewalls and sophisticated encryption algorithms deployed on servers become meaningless. Attackers can directly physically access servers, insert USB drives to steal data, or directly damage hardware. The access control management module has built-in permission logic judgment capabilities. It's not a simple switch, but an intelligent decision-making node. When someone requests to open the door, the module compares the "requester's identity (card swipe, fingerprint, face)" with the "pre-stored permission list in the system" in real time. Only if the algorithm determines that "permission is granted" will an opening signal be sent to the electric lock; if "permission is denied," it will be resolutely refused and recorded. This function achieves refined and automated control of the physical entrance to the computer room, ensuring that only authorized personnel can enter, thus physically blocking the risk of unauthorized intrusion.
[0033] Network security assessments cannot rely solely on "what happened," but also require analysis of "what was attempted to happen." Specifically, network security includes transmission security, data security, firewall security, and server security. The network security system, along with these components, forms a topology network to ensure the overall network security. When assessing the network security system's risks, its transmission paths, data, firewalls, and servers are examined separately. This application's network security system employs a hybrid approach combining a layered architecture and a star topology. Transmission security includes hot backup routing, NAT, and ACLs, ensuring data transmission security through the network security system. Data security includes disaster recovery backup and encryption protection. Disaster recovery backup is a virtual data cloud within the data security module, and encryption protection uses the DES encryption algorithm to encrypt data. Firewall security comprises firewall devices, intrusion prevention devices, and a DMS (Distributed Management System). Server security includes redundant zones and a DMS zone, ensuring the security of the network server.
[0034] Denied unauthorized access requests are often a significant precursor to potential attacks. The access control module possesses full event logging capabilities. It can record successful accesses (who, when, and through which door entered the server room—this forms the baseline of normal behavior); it can also record failed attempts (who (or unknown personnel) attempted, when, and how many times—this constitutes clues for threat intelligence). This "full logging" mechanism allows the physical security module to obtain complete physical access behavior data. Especially for "unauthorized access requests," the recorded data (such as time, frequency, and attempted credentials) is crucial for subsequent risk analysis. For example, if the access control module records that "an expired employee card attempted to open the door five times consecutively at 3 AM," this information itself is a high-value early warning clue for physical attacks. The access control module itself typically has limited storage and computing power. If data is only stored locally on the access controller, it cannot be correlated with network attack logs or personnel change information for analysis, turning the data into an information silo. The access control module generates raw event data in real time (including successful door opening records, failed attempts, device status, etc.). This data is transmitted in real-time (or near real-time) to the next-level physical security module. The physical security module aggregates data from multiple front-end devices such as access control, monitoring, smoke alarms, and power supplies, forming a complete picture of the data center's physical environment. This "front-end acquisition, back-end aggregation" architecture ensures that the risk assessment and analysis module can indirectly but in real-time obtain the most basic access control events through the physical security module. For example, when the risk assessment and analysis module performs cross-dimensional correlation analysis, it can query the physical security module: "During the period when the network security module detected abnormal data transmission from the server, who entered the data center according to the access control system?" Without the reporting function of the access control management module, this crucial time-related analysis would be impossible. The data reported by the access control management module can also, in turn, affect its own permission policies, forming a closed-loop management system. For example, the management security module (personnel security management) detects that "employee Zhang San's permissions have been revoked due to resignation." This change can be automatically or semi-automatically synchronized to the physical security module through the rule engine of the risk assessment and analysis module. The physical security module then updates the permission list in the access control management module, revoking Zhang San's access control permissions. This means that when Zhang San attempts to enter the computer room with an old access card that has not been returned, the access control module will refuse access because his "permissions have been analyzed and determined to be insufficient," and will record this failed "illegal attempt" and report it to the system. The entire process achieves second-level linkage between "personnel changes - system updates - physical execution." The access control module is equipped with functions such as "permission analysis, access control, full recording, and real-time reporting," aiming to upgrade traditional physical access control into an intelligent security sensing and execution node.This module constructs the first line of defense for the physical security of the data center by performing real-time permission assessment and precise control on every access request. By recording all access events, including successful and failed ones, it provides complete raw behavioral data for subsequent risk analysis. By reporting data to the physical security module in real time, it establishes a data link between physical security, network security, and management security. This design transforms the movement of people in the physical world into digital signals that can be perceived, traced, and analyzed by the system in real time. This lays a crucial data foundation for the risk assessment and analysis module to achieve cross-dimensional correlation analysis (such as "human-machine correspondence" and "behavioral auditing"), thereby comprehensively improving the entire system's ability to perceive, warn, and control physical intrusion risks.
[0035] The monitoring module collects and reports the monitoring data from various monitoring devices in the target computer room to the physical security module.
[0036] Specifically, the access control module reports structured text records (e.g., "Zhang San, employee ID 123, entered through Gate A at 14:30:25"). This record itself cannot be verified; the person swiping the card might not be Zhang San (e.g., the card was stolen), or Zhang San might have coerced someone else into entering. The video stream data provided by the monitoring module, however, provides physical verification of the access control records. The footage from the first monitoring device (at the entrance) can be compared to verify if the person swiping the card is indeed Zhang San (using facial recognition) or if the card and person were separated. The footage from the second monitoring device (inside) can record Zhang San's actions after entering the server room—whether he was performing routine server maintenance, copying data from a USB drive, or attempting to damage equipment. The monitoring module transforms the abstract access control logs into visualized behavioral evidence, allowing the risk assessment and analysis module to see "what actually happened," rather than just "what the system recorded," when conducting post-incident tracing. Data from a single camera is fragmented and localized. If the data from the entrance surveillance and internal surveillance are not integrated and reported, it's impossible to reconstruct a person's complete activity trajectory within the server room. The first surveillance device at the entrance records the physical characteristics and items carried by people entering and exiting; the second surveillance device inside the server room records the walking routes and operational details of people between devices. All this video data is reported to the physical security module, where it is stitched and correlated according to timeline and spatial location. This "comprehensive" data reporting allows the physical security module to construct a "personnel trajectory heatmap." For example, when the network security module detects an unauthorized intrusion into a server, the risk assessment and analysis module can request the physical security module to retrieve the surveillance footage of that server at the corresponding time period and location, accurately pinpointing who was standing in front of that server at that time. This spatiotemporal correlation capability is something a single camera cannot achieve.
[0037] Smoke sensors can only tell the system "there is smoke," but not "whether it's a fire or someone smoking." Power modules can only tell the system "there's a power outage," but not "whether it's due to line maintenance or someone cutting a cable." Sensor data is singular and incomplete. Video data reported by the monitoring module provides "visual context" for other sensor data. When the smoke alarm module is triggered, the physical safety module can immediately retrieve footage from a second monitoring device in the corresponding area, using manual or AI image recognition to confirm whether there is actually a flame, thus distinguishing between a real fire and a false alarm, avoiding unnecessary panic or power outages caused by false alarms. When the power module reports an anomaly, the monitoring screen can show whether anyone in the server room is performing improper operations or whether there is a liquid leak causing a short circuit. This complementarity of multi-source data greatly improves the accuracy of risk assessment. Monitoring data, as the most intuitive "live broadcast" and "video playback," helps the system (and maintenance personnel) quickly understand the true reasons behind other sensor data.
[0038] Traditional surveillance systems often operate independently, with recordings stored locally and only retrieved after an incident. This is a passive, offline data utilization method. The monitoring module in this application actively (or on demand) reports data to the physical security module, transforming video data from "offline archives" into "online data streams." The physical security module, or the upper-level risk assessment and analysis module, can analyze the real-time reported video streams (e.g., detecting crowd gatherings, unauthorized intrusions, and items left behind), triggering an alert immediately upon detecting anomalies. When investigating a security incident, the risk assessment and analysis module can intelligently search for specific features (e.g., "people in red clothes," "people carrying packages") from massive amounts of video footage through the physical security module, eliminating the need for manual frame-by-frame review. This "reporting" mechanism integrates video data into the overall big data pool of security assessment, making it active data that can be analyzed in real time, intelligently retrieved, and correlated, rather than simply video files dormant on a hard drive.
[0039] Therefore, the network security risk assessment and analysis system of this application sets up a monitoring module and reports the monitoring data of each monitoring device to the physical security module. This aims to upgrade the traditional video surveillance system to a "visual perception layer," injecting the most intuitive and richest physical world information into the entire risk assessment system. This module achieves visual verification of the access control module's records by reporting comprehensive video streams from the entrance and interior, ensuring "person-certificate verification" and traceability of behavior. Through continuous video acquisition of the computer room environment, it provides crucial visual context for sensor data such as smoke alarms and power monitoring, assisting the system in accurately determining the true cause of environmental anomalies. More importantly, by transforming video data from offline storage to online data streams, the upper-layer analysis module can perform real-time AI intelligent analysis of the physical space and establish multi-dimensional spatiotemporal correlations with network attack logs and personnel management data, thereby constructing a "what you see is what you get" three-dimensional security protection and assessment system.
[0040] The smoke alarm module collects and reports the smoke alarm information of the target computer room to the physical security module.
[0041] Specifically, if the access control module addresses "human intrusion" and the monitoring module addresses "visualization of behavior," then the smoke alarm module addresses "catastrophic environmental changes." These changes are characterized by their sudden occurrence, extreme destructive power, and the need for cross-system collaborative responses.
[0042] Access control modules can only detect "who entered the room," and while monitoring modules can see the footage, ordinary surveillance cameras may not be able to capture even the fine smoke in the early stages of a fire, or the footage will be interrupted if the camera is destroyed by fire. In other words, relying solely on "eyes" is insufficient to detect fires in the first instance, especially those hidden sources of fire such as those behind server racks, inside ceiling panels, or under floors. Smoke alarm modules are specialized chemical / physical sensing units. They do not rely on vision but use ionization or photoelectric principles to detect tiny smoke particles drifting in the air before visible flames. The "collection" action of the smoke alarm module allows the physical safety module to obtain the earliest and most sensitive disaster warning signal. This signal is unmatched by any other module, filling the gap in the physical safety sensing system's ability to detect "sudden changes in air chemical composition." If a smoke alarm only emits a piercing beep locally, and the server room happens to be unattended, then the alarm is meaningless. A fire will not stop spreading simply because no one hears it. The smoke sensor detects excessive smoke concentration and generates an alarm signal. This signal is immediately reported to the physical safety module. The physical safety module immediately notifies maintenance personnel via SMS and app push notifications. It automatically retrieves monitoring footage from the affected area for manual or AI-assisted fire confirmation. If a fire is confirmed, it automatically triggers fire extinguishers (such as heptafluoropropane gas extinguishing systems) to extinguish the fire; simultaneously, it links with the power module to cut off non-fire-fighting power (or ensure fire-fighting power supply) to prevent secondary disasters. This "reporting-linkage" mechanism transforms isolated local alarms into "triggers" for the entire intelligent prevention and control system. It achieves an automated closed loop from "perception" to "action," initiating fire extinguishing procedures within seconds to nip a fire in the bud. For the risk assessment and analysis module, it not only focuses on "whether there is a fire at this moment" but also on "how high the fire risk is here." A single "alarm" is a Boolean value (0 or 1), while continuous "reporting" forms an environmental health trend line. The smoke alarm module continuously collects smoke concentration data (even if it does not reach the alarm threshold) and reports it to the physical safety module, ultimately summarizing it in the risk assessment and analysis module. The system can learn the baseline of air quality in the computer room under normal conditions. If smoke concentration data shows a slow but continuous increase over the past week, even before reaching the alarm threshold, the risk assessment and analysis module can determine that "the computer room may have poor heat dissipation, aging and overheating equipment, or overheating of wiring insulation," thus providing an early warning of "increased fire risk" before a fire occurs. This accumulation and analysis of minute data gives the entire system predictive maintenance capabilities. It upgrades the smoke alarm module from a "reactive" alarm to a "preventative" environmental health monitoring device.
[0043] When conducting a retrospective investigation after a safety incident (even if it's not a fire, such as equipment damage), the historical data reported by the smoke alarm module is crucial "alibi" or "conviction evidence". For example, suppose a certain server suddenly crashes in the early morning, and the engineer suspects "overheat protection". Investigators can, through the system, retrieve the historical smoke concentration / temperature data reported by the smoke alarm module and stored by the physical security module during that period (many smoke alarms integrate temperature sensing). If the data shows a sharp rise in temperature before the crash, it can corroborate the judgment of "overheating"; if the data shows that the environment has been normal, environmental factors can be excluded, and software or hardware failures can be investigated instead. The data reported by the smoke alarm module provides an indispensable "environmental factor puzzle piece" for the analysis puzzle of the entire safety incident, ensuring the integrity of root cause analysis.
[0044] Therefore, this application sets up a smoke alarm module and reports its alarm information to the physical security module, aiming to upgrade the traditional standalone fire detector to an actively perceptive and collaborative intelligent security node. By collecting and perceiving smoke particles in the air of the computer room in real time, this module fills the gap in early warning of hidden fire hazards in the physical security system; by reporting alarm signals in real time, it triggers the physical security module and even the entire system to initiate multi-level linkage responses (such as video review, automatic fire extinguishing, power control), achieving the leap from single alarm to system collaboration; at the same time, by continuously reporting minute data such as smoke concentration, it provides valuable historical data on environmental health for the risk assessment and analysis module, supporting its predictive analysis and trend judgment of fire risks. This design enables the physical security module to comprehensively grasp the "physiological indicators" of the computer room, providing key environmental security dimension data support for the entire network security risk assessment system.
[0045] The power module collects the power consumption data of the target computer room and reports it to the physical security module.
[0046] Specifically, in practice, power is not only the "heart" of the computer room (providing energy), but also the "lifeline" and "important data source" of the entire security system. If the access control management module controls the entry and exit of personnel, the monitoring module records visual information, and the smoke alarm module senses environmental mutations, then the power module determines whether all these modules and the core business system can "survive" and "work properly". Once the power fails, the entire security protection system will instantly collapse, the access control cannot be opened, the monitoring cannot be seen, the network equipment shuts down, and the servers crash.
[0047] Power is the energy source for all electronic devices (including servers, network equipment, access control, monitoring, and smoke detectors). Without stable power, even the most powerful firewall is useless. The core function of a power module is to provide uninterrupted power, but simply "supplying power" is not enough; the system needs to know "how well it is supplying power." By collecting and reporting power consumption data (such as input voltage, output voltage, current, frequency, load rate, battery level, and battery temperature), the power module allows the physical security module to monitor the data center's "blood supply" status in real time. If the reported data shows severe fluctuations in mains voltage (such as frequent surges or drops), the physical security module can determine that the "mains quality is poor," indicating a risk of imminent power outage. If the UPS (Uninterruptible Power Supply) load rate consistently exceeds 80%, or the remaining battery power is below 20%, it indicates insufficient backup power reserves; once the mains power is interrupted, the system will quickly shut down. By analyzing the battery's charge / discharge curves and internal resistance changes, it is possible to predict whether the battery pack is nearing the end of its lifespan and whether it needs to be replaced prematurely. Many network security incidents or physical damage incidents are often rooted in or accompanied by abnormal power supply phenomena. Without data reported by the power supply module, these correlations cannot be established. For example, the power supply module, linked with the network security module, can report: "The core switch suddenly went offline at 2:03 AM." Investigators can then query the physical security module: "What was the power status at that time?" Historical data reported by the power supply module shows: From 2:00 AM to 2:02 AM, the mains input voltage continued to drop, and at 2:03 AM, the UPS stopped outputting power due to depleted batteries.
[0048] By analyzing data reported by the power module, the system can accurately determine that the root cause of the network outage was power depletion, rather than equipment malfunction or a hacker attack. This prevents the security team from wasting time on the wrong path and enables rapid root cause identification.
[0049] An alarm from a single module might be a false alarm, but if multiple modules show abnormal data simultaneously, the probability of an event occurring is extremely high. Power supply data is crucial evidence for verifying the authenticity of alarms from other modules.
[0050] For example, in a smoke alarm linkage scenario: when the smoke alarm module reports "smoke in the server room," if the power module simultaneously reports "sudden increase in current and sudden drop in voltage," it can be presumably determined that it is an electrical fire, and the system should immediately activate the highest level of emergency response (cut off non-fire-fighting power and activate gas extinguishing). When the access control module reports "server room door opened," if the power module simultaneously reports "power to a certain server rack was turned off," the system can infer that the person entering the server room may have maliciously cut off the power, and the equipment status of that server rack needs to be closely monitored. This cross-dimensional data correlation makes the risk assessment and analysis module's judgment more accurate, greatly reducing the false alarm rate and the missed alarm rate.
[0051] In practice, the power capacity of a data center is limited. If the number of devices in the racks continues to increase, the total load may exceed the design capacity, causing circuit breakers to trip or cables to overheat and catch fire. The power module continuously reports real-time power consumption data for each branch circuit, which the physical safety module then aggregates to form a load heat map. When the load of a PDU (Power Distribution Unit) exceeds 80% of its rated value, the system can issue an early warning, reminding the administrator to relocate or expand the equipment to avoid tripping. Long-term collected power consumption data helps administrators understand the actual energy consumption trends of the data center, providing a basis for decision-making regarding the installation of new equipment and ensuring that the physical infrastructure's capacity is not exceeded. The power module's data reporting transforms data center energy management from a passive "repair when it breaks" approach to proactive "predictive maintenance," effectively preventing physical safety incidents caused by overload. Risk assessment not only evaluates "current safety" but also "how long the system can withstand a disaster." The data reported by the power module is the sole basis for answering this question. The risk assessment analysis module can automatically calculate backup battery life based on the remaining battery capacity and current load power reported by the power module. The calculated "theoretical battery life" is compared with the preset "minimum downtime requirement" (such as an SLA (Service Level Agreement) requiring 2 hours of operation after a power outage). If the battery life significantly exceeds the requirement, the "power risk" score is low; if the battery life is insufficient, the system automatically increases the overall risk score of the data center and suggests battery expansion or adding a generator. This quantitative assessment allows managers to intuitively see their resources and weaknesses.
[0052] Therefore, this application sets up a power module and collects and reports power consumption data from the target data center, aiming to upgrade traditional power protection equipment into intelligent infrastructure nodes with proactive sensing and predictive maintenance. This module monitors and reports key power parameters such as voltage, current, load, and battery status in real time, providing the physical security module with fundamental data to assess the data center's "vital signs." On one hand, it enables early warning of potential risks such as abnormal mains power, battery degradation, and excessive load, ensuring the continuous operation of the security system itself. On the other hand, its reported data is deeply correlated with data from access control, monitoring, smoke alarms, and network security modules, providing crucial environmental evidence for tracing the root causes of security incidents. More importantly, it provides the core basis for the upper-level risk assessment and analysis module to calculate business continuity indicators, enabling the assessment of the overall security of the data center to move from qualitative to quantitative, and from static to dynamic, thereby constructing a comprehensive physical security perception system that is "energy visible, risk controllable, and fault traceable."
[0053] The physical security module integrates access control information, monitoring data, smoke alarm information, and power consumption data of the target computer room to generate physical security data of the target computer room and transmits it to the risk assessment and analysis module.
[0054] Specifically, the physical security module plays the role of a "data aggregation and preprocessing center" and an "abstraction layer of the physical world" in the overall system architecture. The four sub-modules—access control, monitoring, smoke alarm, and power supply—are distributed "sensory terminals," each generating raw data in different formats, dimensions, and time granularities (such as a card swipe record, a video stream, a smoke concentration value, or a set of voltage and current readings). Allowing this disorganized raw data to directly flood into the upper-level risk assessment and analysis module would cause the following problems: 1. Explosive data volume: Video streams and other data can overwhelm the core analysis modules.
[0055] 2. Inconsistent format: The analysis module needs to develop different parsers for each type of data.
[0056] 3. Lack of context: Isolated access control records and smoke alarm values are meaningless on their own and need to be combined to make a judgment.
[0057] The physical security module exists to solve the technical problem of "normalization, correlation and value extraction of multi-source heterogeneous physical data".
[0058] Access control systems may use database records (such as SQL), monitoring systems output video streams (such as RTSP, Real-Time Streaming Protocol), smoke detectors may transmit data via relay switches or Modbus (a serial communication protocol), and intelligent UPS (Uninterruptible Power Supply) may provide structured data via SNMP (Simple Network Management Protocol). The communication protocols, data formats, and semantic meanings of these data are completely different. The physical security module in this application acts as a "protocol adapter" and a "data normalization layer." It interfaces with four sub-modules, uniformly collecting various raw data (switching signals, analog signals, video streams, and structured logs). It converts this heterogeneous data into an internal standard format (e.g., standardized data packets with timestamps, device IDs, event types, and event values). Through the processing of the physical security module, the originally diverse underlying physical device data is transformed into structured "physical security data" that can be understood and processed by the upper-level analysis module. This allows the risk assessment and analysis module to be unconcerned about the brand of the access control system or the protocol of the camera, only needing to interface with the unified interface provided by the physical security module.
[0059] A single access control card swipe record has limited significance, but by combining it with surveillance footage from the same period and the power status at the time, a complete event can be reconstructed. This "fusion" process needs to be performed by the physical security module. Therefore, the physical security module in this application possesses an event correlation engine. For example: Original data A (access control): 14:30:25, Zhang San swipes his card to enter door A.
[0060] Raw data B (surveillance): 14:30:20-14:30:30, footage from camera at door A shows a man in red entering.
[0061] Raw data C (power supply): 14:30:25, no abnormal fluctuations in the current of the PDU (power distribution unit) in the cabinet near door A.
[0062] The physical security module aligns these three pieces of data (plus timestamp and location ID) in time and space, and merges them into a message with a complete context: "Zhang San (access control identity) entered through door A at 14:30:25. The monitoring screen shows that he was wearing red clothes and the power status of the area was normal when he entered." This integrated "physical security data" is no longer an isolated point, but forms a complete chain of physical events. After obtaining this data, the risk assessment and analysis module can directly use it to determine "whether the person and the certificate match" and "whether the environment was abnormal when entering," without having to painstakingly correlate the underlying data itself.
[0063] The raw data is massive, especially the video stream. If all the raw video, every access control record, and the smoke concentration value per second were transmitted to the risk assessment and analysis module in real time, it would exhaust network bandwidth and computing resources, causing the core analysis module to become overwhelmed by the data deluge and unable to function effectively. The physical security module, while fusing the data, performs feature extraction and data dimensionality reduction.
[0064] The physical security module handles video processing by not uploading the entire video stream directly, but instead using built-in AI analysis to upload only the analysis results (such as "personnel intrusion detected" or "no abnormalities in the footage") or keyframe screenshots, or only uploading video clips when an event is triggered.
[0065] The physical security module processes time-series data: it aggregates massive, millisecond-level voltage and current readings into statistical features (such as "voltage fluctuation amplitude in the past 5 minutes" and "current load rate").
[0066] The physical security module transmits refined, high-value-density "physical security data" (e.g., "14:30-14:35, Area A, one entry incident occurred, identity verification successful, no unusual items left behind, stable environmental power") to the risk assessment and analysis module. This allows the analysis module to focus more on the core risk assessment algorithm without expending resources on cleaning and organizing basic data, thereby improving the real-time performance and assessment efficiency of the entire system.
[0067] If the risk assessment and analysis module is directly coupled to the four sub-modules, once the equipment of one of the sub-modules is upgraded, the brand is changed, or the communication protocol changes (for example, replacing an old analog camera with a new AI camera), the risk assessment and analysis module needs to be modified to adapt to it, which will make the system extremely unstable and difficult to maintain.
[0068] Therefore, this application sets up a physical security module as a "buffer" or "shock-absorbing layer." The physical security module provides a stable and abstract physical security data interface to the risk assessment and analysis module. It also adapts to any changes that may occur in the four sub-modules. Changing the camera brand only requires modifying the video access adapter of the physical security module; the upper-layer interface and data structure remain completely unchanged. This design achieves "modular decoupling." If a new physical sensing dimension needs to be added in the future (e.g., adding a "leakage detection module"), only the corresponding access adapter needs to be added to the physical security module, and its internal fusion logic adjusted. The risk assessment and analysis module remains completely unaffected, continuing to process the data sent by the physical security module according to its original logic. This greatly enhances the scalability and robustness of the entire system.
[0069] The risk assessment and analysis module requires a holistic conclusion regarding the safety of the physical environment, rather than a collection of scattered data points. The physical security module generates a unified, high-level view of the physical security status by integrating data from all submodules. This view can be a structured data package containing the following information: (1) Intrusion status: Has someone illegally broken in? (2) Environmental conditions: Is there a fire, water damage, or power outage? (3) Personnel activity status: How many people are currently in the computer room? Who are they? What are they doing? When performing analysis, the risk assessment and analysis module only needs to request this "unified view" from the physical security module to quickly obtain comprehensive information about physical security and perform high-level integrated analysis with data from other dimensions (network, management). For example, it can quickly determine: "When a network attack occurs, does the physical environment simultaneously exhibit anomalies?" thereby identifying advanced threats that are coordinated internal and external.
[0070] Therefore, this application sets up a physical security module as the core aggregation and processing unit connecting various physical sensing sub-modules and the upper-level risk assessment and analysis module, aiming to solve the problems of heterogeneity, massive volume, correlation, and decoupling of multi-source physical security data. This module unifies and normalizes heterogeneous data from sub-modules such as access control, monitoring, smoke alarms, and power supplies, performing spatiotemporal alignment and event correlation to fuse isolated raw data points into high-value physical event information with complete context. Simultaneously, through feature extraction and data dimensionality reduction, this module transforms massive amounts of raw data (especially video streams) into lightweight, high-density physical security status data, significantly reducing the computational and communication burden on the core analysis module. More importantly, this design achieves modular decoupling between the underlying physical devices and the upper-level analysis logic, ensuring the system's stability and scalability in the face of technological iterations and functional expansions. Ultimately, the physical security module provides the risk assessment and analysis module with a unified, real-time, and accurate abstract view of the physical world, enabling the entire system to truly achieve deep collaborative and integrated analysis of the physical environment, network operation, and management system.
[0071] Furthermore, the network security module can be responsible for the security of data transmission, firewall security, and target server security of the target computer room and its corresponding target network security system.
[0072] Specifically, this application sets out "data transmission security, firewall security, and server security" to build a complete defense-in-depth system. In the field of cybersecurity, attacks are often multi-path and multi-layered. Focusing on only one aspect will create blind spots in defense.
[0073] Data transmission security (link layer): Data transmitted over a network is like a car traveling on a highway, easily "hijacked" or "eavesdropped on." Setting up data transmission security monitoring is to prevent data from being tampered with or leaked during its journey from the server to the user, or from the data center to the cloud. This is the most basic form of communication security.
[0074] Firewall security (boundary layer): A firewall is like a "security gate" or "wall" in the network world. Monitoring firewall security ensures that only legitimate traffic and data packets can enter the internal network, preventing external threats such as unauthorized access and DDoS attacks (distributed denial-of-service attacks) from crossing the boundary.
[0075] Target server security (core layer): The server is the final carrier of data and the core of business processing. Even if data transmission is encrypted and the firewall is strong, system vulnerabilities, malware, and unauthorized logins on the server itself can directly lead to system crashes or data theft.
[0076] By combining these three layers, the network security module of this solution achieves end-to-end monitoring from the external boundary (firewall), the transmission process (data link), to core assets (servers). This three-dimensional monitoring system enables the risk assessment and analysis module to obtain raw network security data from different dimensions, thereby more accurately determining the source and nature of threats.
[0077] In practice, to ensure data and network security, the network security module accesses the target network platform through the target server. Setting up "accessing the target network platform through the target server" is to achieve contextual correlation of network behavior. The network security module does not monitor the server in isolation, but rather accesses the network platform through the server. The target server serves as the hub for interaction between the enterprise's internal and external networks; all outward business requests and data exchanges pass through the target server. This setup allows the network security module to monitor both the server's own status (such as CPU load, port open status, and patch update status) and its behavioral data when accessing external network platforms (such as the accessed URL (Uniform Resource Locator), the characteristics of outward-sent data packets, and the external IP address connected). This design avoids the one-sidedness of "only looking at the internal and not the external" or "only looking at the external and not the internal." For example, if the server suddenly starts sending a large amount of data to an unknown external IP, this is an anomaly at both the "server security" level (potentially infected with a Trojan) and the "data transmission security" level (risk of data leakage). This correlational analysis is key to improving the accuracy of assessments.
[0078] Based on the above settings, the network security module is responsible for recording and collecting network security data from the target data center and transmitting it to the risk assessment and analysis module. The purpose of "recording and collecting data and transmitting it to the risk assessment and analysis module" is to achieve quantifiable dynamic assessment. In practice, inaccurate risk assessments often occur because they rely on static configuration checks or manual reporting rather than real-time operational data. In this solution, the network security module not only performs protective functions (such as firewall blocking), but more importantly, it has data collection capabilities. It records logs, alerts, and traffic characteristics generated by the protection devices. This collected raw data (such as "the firewall blocked 100 attacks this week," "the server has 3 high-risk vulnerabilities that have not been patched," and "the data transmission encryption protocol has expired") is transmitted to the risk assessment and analysis module in real time.
[0079] Based on this, the risk assessment and analysis module no longer assigns scores arbitrarily, but instead conducts comprehensive analysis based on these real-time, authentic network data. In this way, when network security risks increase (e.g., an increase in attack incidents), the system can immediately detect this and reflect it in the comprehensive assessment results, thereby triggering an early warning and achieving a leap from static assessment to dynamic, real-time assessment.
[0080] In practice, the network security module of this application accesses the target network platform via a preset encrypted access method to conduct data exchange. The preset encrypted access method can be categorized into three main types: link-layer encryption, network-layer encryption, and application-layer encryption. In practical applications, one or more combinations of these methods can be selected and described based on the system's protection level and the actual application scenario.
[0081] 1. Network layer encryption (communication tunnel security) These encryption methods primarily protect the security of data transmission at the network layer (IP layer). They are typically used to build Virtual Private Networks (VPNs) that span public networks, ensuring that data is not eavesdropped on or tampered with during transmission.
[0082] (1) IPsec (Internet Protocol Security): It is currently the most commonly used network layer encryption protocol. It can encrypt and authenticate entire IP data packets. Its working mode is as follows: Transmission mode: Only the data payload of the IP packet is encrypted, which is usually used for direct communication between servers.
[0083] Tunnel mode: Encrypts the entire IP packet and adds a new IP header; typically used to build site-to-site VPNs.
[0084] For example, in practical applications, when a target data center needs to establish a secure channel with a remote target network platform, IPsec can ensure that all traffic passing through the Internet is encrypted.
[0085] (2) GRE over IPsec (Generic Routing Encapsulation over IPsec): GRE (Generic Routing Encapsulation) is used to encapsulate multiple network layer protocols, but it is not encrypted itself; when combined with IPsec, it can achieve encrypted transmission of data from multiple protocols.
[0086] 2. Transport layer encryption (end-to-end connection security) This is currently the most common encryption method, widely used in scenarios such as web access and email transmission. It establishes an encrypted connection above the transport layer (TCP / UDP, i.e., Transmission Control Protocol / User Datagram Protocol).
[0087] (1) TLS / SSL (Transport Layer Security / Secure Sockets Layer): This is the most widely used encryption protocol on the Internet. It authenticates users through digital certificates and encrypts communication sessions.
[0088] The specific agreement is as follows: 1) HTTPS: HTTP over TLS, which stands for HTTP Secure Hypertext Transfer Protocol. If the target network platform is a web service, and the target server is accessed via HTTPS, then TLS encryption is being used.
[0089] 2) FTPS: FTP over TLS, which is a secure file transfer protocol.
[0090] For example, in practical applications, if the network security module needs to access cloud API interfaces or web consoles, TLS / SSL is mandatory. It encrypts the data and verifies the identity of the target platform through certificates, preventing man-in-the-middle attacks.
[0091] 3) DTLS (Datagram Transport Layer Security): A TLS version based on UDP, suitable for real-time communication scenarios (such as audio and video, games), reducing latency while ensuring security.
[0092] 3. Application layer encryption (data itself is secure) This type of encryption does not rely on a transmission protocol; instead, it encrypts the data itself. Even if the data packet is intercepted at the network or transport layer, the attacker will only see the ciphertext.
[0093] (1) SSH (Secure Shell Protocol): Primarily used for remote login and command execution, but also supports port forwarding and file transfer. For example, in practical applications, if the target server needs to manage or access the backend resources of the target network platform via remote command line, SSH is the standard encryption method. It provides strong authentication (password or key) and encrypted communication channels.
[0094] (2) SFTP (SSH File Transfer Protocol) / SCP (Secure Copy Protocol): A file transfer encryption method based on the SSH protocol, used to securely exchange configuration files or data packets.
[0095] (3) SMTP over TLS / SSL (Simple Mail Transfer Protocol over TLS / SSL): Used for encrypted email communication.
[0096] Custom application-layer encryption: Implement encryption logic within the application (such as using AES (Advanced Encryption Standard) or SM4 (Chinese national cryptographic algorithm) to encrypt the message body), and then send it via protocols such as HTTP. In this method, even if the transmission link is intercepted, the data content remains secure.
[0097] 4. Data link layer encryption (physical link security) This type of encryption is typically used in private networks to protect point-to-point physical links.
[0098] (1) MACsec (Media Access Control Security): It operates at Layer 2 (Data Link Layer) of the OSI model (Open Systems Interconnection model). It can encrypt and perform integrity checks on Ethernet traffic within a local area network, ensuring secure communication between different servers under the same switch.
[0099] (2) IEEE 802.1AE: MACsec standard specification.
[0100] 5. National cryptographic algorithms (specific industry / national security standards) For application scenarios involving national security or important industries (such as finance, government, and power), the patent scheme usually emphasizes the use of commercial cryptographic algorithms recognized by the State Cryptography Administration, namely "national cryptographic algorithms".
[0101] (1)SM2: Elliptic curve-based public-key cryptography algorithm for digital signatures and key exchange (an alternative to RSA (RSA encryption algorithm)).
[0102] (3) SM3: Cryptographic hash algorithm, used to generate message digests (replace SHA (Secure Hash Algorithm)).
[0103] (4) SM4: Block cipher algorithm used for data encryption (replaces AES).
[0104] (5) SM9: Identity-based cryptography algorithm.
[0105] Therefore, the encryption methods preset in this application include, but are not limited to: TLS / SSL transport layer encryption based on digital certificates, used to ensure the security of Web service interactions with the target network platform; constructing an encrypted communication tunnel using the IPsec protocol, used to protect network layer data exchange between cross-regional computer rooms; and, for highly sensitive data, calling a national cryptographic algorithm library (such as SM4) to perform secondary encryption processing on application layer messages, ensuring that even if the transmission link is hijacked, the data content cannot be parsed. 6. Key exchange and authentication mechanism (backend support for encryption methods) When describing encryption methods, it is usually necessary to mention the accompanying key exchange mechanism to demonstrate the completeness of the scheme.
[0106] (1) Diffie-Hellman (DH, Diffie-Hellman Key Exchange) / ECDH (Elliptic Curve Diffie-Hellman Key Exchange): Used to negotiate session keys on insecure channels.
[0107] (2) PKI (Public Key Infrastructure): Verifies the identity of a target server or target network platform through digital certificates issued by a CA (Certificate Authority).
[0108] The process by which the network security module records and collects network security data from the target data center and transmits it to the risk assessment and analysis module may include: The network security module collects and inspects the data transmission paths, data, firewalls, and network security of the target computer room and its corresponding target network security system, and generates corresponding network security data. The generated network security data is then transmitted to the target network platform via the target server.
[0109] Specifically, the primary responsibility of network devices such as firewalls and switches is to forward business data. If network security modules directly poll these devices frequently or receive their logs, the large volume of monitoring data collection traffic will consume business bandwidth and may even increase the CPU load on network devices, leading to business forwarding delays or packet loss. Therefore, this application sets up a target server as a data relay station or data proxy. Firewalls, intrusion detection systems, and other devices first send logs and inspection results to a dedicated process (Agent) on the target server. The target server performs preliminary aggregation, compression, and encryption of the data, and then uses its own network connection to transmit it to the target network platform (or directly to the risk assessment and analysis module) through a potentially independent channel (or reuses a business channel but is prioritized by QoS). This design achieves logical separation between monitoring data flow and core business data flow. Even if the amount of monitoring data surges (such as a log explosion during a DDoS attack), it will not directly impact the performance of core switches and routers, ensuring the stability of the business network.
[0110] The data collected by the network security module includes "firewall interception logs" and "server login records." If this data is tampered with or forged by a man-in-the-middle attack, or if the collection path is hijacked, then the upper-level risk assessment and analysis module will be making decisions based on "false intelligence," with potentially disastrous consequences.
[0111] This application mandates that data pass through the target server, leveraging the server's own identity and encrypted channels to establish a trusted transmission path. The target server itself is a core asset within the data center, and its identity is rigorously authenticated (e.g., possessing a unique digital certificate or a fixed security key). The network security module can encapsulate data using preset encryption methods (such as TLS or IPsec) when sending data to the server, and when the server forwards data to the platform. This path ensures data integrity and authenticity. Upon receiving the data, the upper-layer risk assessment and analysis module can confirm: "This firewall log was indeed forwarded by authenticated server A within the target data center, and it has not been tampered with during transmission." This is equivalent to adding a "trusted stamp" to every reported network security data.
[0112] In large-scale network architectures, data is typically divided into "southbound data" (data generated by devices within the data center) and "northbound data" (data reported to the management platform). To comply with regulations (such as Cybersecurity Classified Protection 2.0), all external management data usually needs to be audited and controlled through a unified exit point. The target server serves as the unified aggregation point and exit proxy for network security data within the data center. All network security data sent to external target network platforms undergoes unified access control policy checks at the server level (e.g., whether reporting is allowed, whether data anonymization is required). The server logs all outgoing data, forming a complete data outgoing audit trail. This meets the requirements of Cybersecurity Classified Protection 2.0 regarding "data outbound security management" and "centralized log auditing." If a data breach needs to be traced in the future, it can be clearly determined: when, which server, which platform, and what network security data was reported. Both purely cloud-based and purely local analysis have drawbacks. Cloud analysis suffers from high latency and high bandwidth consumption; local analysis has limited capabilities and lacks a global perspective. By setting up a three-level pipeline of "network security module collection and inspection -> preliminary processing of target server -> in-depth analysis of target network platform", edge computing and cloud computing synergy are realized.
[0113] Level 1 (Network Security Module): Responsible for real-time inspection and emergency response. Upon detecting clear attack behavior (such as brute-force attacks), immediately block it locally and log the incident.
[0114] Level 2 (Target Server): Responsible for data aggregation, formatting, and correlation. It merges network security data from multiple sources (firewalls, IDS (Intrusion Detection Systems), and its own logs) into a standard "network security data" message.
[0115] Level 3 (Target Network Platform): Responsible for big data analysis, machine learning, and global situational awareness. It aggregates data from all data centers and performs correlation analysis of cross-domain attacks (e.g., determining whether it is a large-scale coordinated attack).
[0116] This architecture enables the entire system to possess both rapid response capabilities at the edge and in-depth analytical capabilities at the center. The data transmitted to the target network platform is cleaned and refined high-value information, rather than massive amounts of noise, thus achieving optimal resource allocation.
[0117] Therefore, this application sets up a network security module to collect and inspect the network security data, which is then transmitted to the target network platform via the target server. The aim is to build a reliable, efficient, and compliant data uplink channel and realize an intelligent analysis architecture that integrates edge and cloud.
[0118] This design achieves a lightweight logical separation between monitoring data flow and core business flow by using the target server as a data aggregation and forwarding proxy, avoiding the performance impact of monitoring traffic on core network equipment. By leveraging the target server's trusted identity and encrypted channels, it provides source authentication and integrity protection for reported data, ensuring the authenticity and reliability of the data used for upper-layer risk assessments. Simultaneously, this path complies with network security level protection requirements, forming a unified data exit and audit point. At a deeper level, this design constructs a three-tiered collaborative system of "local real-time inspection—edge aggregation and processing—cloud-based in-depth analysis," enabling urgent threats to be blocked locally within seconds, while complex threats are accurately identified in the cloud through global correlation, thus achieving a balance between timeliness in network security incident response and accuracy in risk analysis.
[0119] Specifically, the management security module of this application may include a system construction management module, a network security management module, a personnel security management module, and a system maintenance management module. The system construction management module is responsible for building and managing the system management regulations for the target computer room and the target network security system and transmitting them to the management security module.
[0120] Specifically, simply put, if other modules are "process management" and "post-event repair" performed after the system is built and running, then the system construction management module is responsible for "prevention" and "basic compliance." Traditional security assessments often only focus on the state of the system after it is running (such as whether it has been attacked or whether anyone has violated regulations). However, many times, the biggest security risks are actually planted during the system planning and construction phases.
[0121] If a data center was not built according to national standards (such as GB 50174 "Data Center Design Code") for site selection and cabling, or if a software system has architectural flaws in its design, then no amount of subsequent management improvements or firewall upgrades can fundamentally remedy these inherent defects. The system construction management module is responsible for collecting and reviewing "system management regulations." These regulations include not only routine rules but also normative documents from the system's construction phases, such as requirements analysis, design, selection, implementation, and delivery acceptance. By incorporating compliance data from the construction phase into risk assessment, the system can identify assets with inherent weaknesses that pose a high risk. For example, if a system's construction documentation is missing or the construction process does not meet security management requirements, the risk assessment and analysis module will determine that the system's fundamental risk is significantly higher than other compliant systems.
[0122] The "management of management systems" provides a benchmark for evaluation, with the system construction management module responsible for the "meta-systems" or "basic laws." It stipulates the standards and processes that should be followed in establishing the data center and network systems. The network security management module, personnel security management module, etc., are responsible for the "implementation of systems" or "operational procedures." After the system is built, they instruct operations personnel on how to configure firewalls and manage account passwords. The data output by the system construction management module serves as a "reference point" for evaluating the performance of other modules. For example, when checking personnel security management systems, the risk assessment and analysis module needs to refer back to the "job responsibility setting specifications" and "permission approval processes" defined in the system construction management module to determine whether current personnel operations are compliant.
[0123] Currently, most security assessment tools focus only on assets already in operation. By setting up a system construction management module, this solution extends the assessment scope to the system creation phase. This module records the construction standards of the "target data center" (e.g., whether seismic resistance, fire protection, and load-bearing design meet requirements) and the development process of the "target network security system" (e.g., whether the software code has undergone security audits and whether backdoors have been included). This gives the entire risk assessment and analysis system the capability of "full lifecycle management." When the system frequently experiences problems due to defects during construction, the data from this module can help analyze the root cause as "poor management during the construction phase," rather than simply attributing it to "operational errors during the operation and maintenance phase," thus achieving more accurate root cause analysis.
[0124] Therefore, this application establishes a system construction management module to fill the gap in existing technologies regarding security risk assessment during the system's "planning and design" and "development and construction" phases. By collecting and managing the system's regulations and implementation records during the construction period, a security baseline is established for the entire risk assessment system. This module not only serves as the data foundation for managing the security module and provides compliant operation criteria for other sub-modules such as network security management and personnel security management, but also acts as a bridge connecting physical security and network security, ensuring that every step from data center infrastructure construction to network security system deployment is regulated and traceable, thereby reducing systemic risks caused by improper planning or non-compliant construction at the source.
[0125] The process of the security management module recording and collecting system management regulations, network security management regulations, personnel security management regulations, and maintenance management regulations for the target data center and target network security system, and generating system management security data for the target data center and target network security system and transmitting it to the risk assessment and analysis module, includes the following: The system construction and management module constructs a simulated network for the target data center based on its structural parameters and operating environment parameters. It then establishes corresponding system management rules for the simulated network and manages the simulated network according to these rules. Finally, it transmits the system management data of the target data center and the target network security system to the management security module.
[0126] Specifically, if the system construction management module is only responsible for collecting static, documented "data center construction drawings" and "policy documents," then it is merely an electronic filing cabinet. However, by constructing a simulated network and verifying policies based on the simulated environment, it is upgraded to a "digital twin sandbox" and a "policy stress testing platform." Real data centers and network security systems are the production environments that support business operations. If a new, untested management policy is tried in a real environment (e.g., testing a policy to "automatically block frequently accessing IPs"), misconfiguration could lead to the wrongful blocking of legitimate IPs, business interruptions, or even system crashes. The production environment cannot be a "testing ground" for management policies. The system construction management module utilizes the target data center's structural parameters (such as rack layout, cabling topology, and equipment list) and operating environment parameters (such as power load, network bandwidth, and heat dissipation conditions) to construct a simulated network (i.e., a digital twin) that is highly consistent with the real environment. In this isolated simulated network, various system management policies can be boldly tested. For example, testing a policy to "automatically shut down non-core equipment when the data center temperature exceeds 35°C" can verify in the simulated environment whether this policy will mistakenly shut down core databases without affecting the operation of the real data center. By simulating attacks and failures, we can examine whether there are any blind spots in the existing system. For example, by simulating a scenario of "simultaneous interruption of dual mains power", we can test whether the "emergency plan management system" is truly effective and whether the UPS (uninterruptible power supply) and generator can seamlessly switch as required by the system.
[0127] Management systems cannot be generic templates; they must be tightly coupled with the physical structure and equipment performance of the data center. For example, a generic "fire emergency procedure" might stipulate "immediately cut off all power upon discovery of a fire," but if the data center's fire suppression system is a gas extinguishing system (which requires power to operate), this procedure would be counterproductive. The system construction and management module uses structural parameters and operating environment parameters as the "skeleton" and "flesh and blood" of the simulated network. Structural parameters determine the topology layout of the simulated network (e.g., where the core switches are located and how the server racks are arranged). Operating environment parameters give the simulated network dynamic behavior (e.g., device power consumption and network traffic characteristics). Management systems built upon this highly simulated network naturally possess the constraints and logic of the physical world. For example, the module can formulate a precise "rack load management procedure" based on the power distribution of devices in the simulated network, stipulating that "the power of each rack must not exceed 4.5kW." This value is not arbitrary but derived from precise calculations of the device parameters in the simulated network.
[0128] When assessing the management security of a real system, the risk assessment and analysis module requires an "ideal state" or "design state" as a reference to determine whether the real state is "normal" or "deviations." The system construction and management module operates in a simulated network based on preset, idealized management systems, generating a set of management data that is "theoretically the most secure and compliant." This includes ideal access control policies, ideal patch update cycles, and ideal personnel operation process records. This verified idealized system management data generated from the simulated network is then transmitted to the management security module. The management security module (or directly the risk assessment and analysis module) compares the "operational management data" collected from the real system with this set of "simulated ideal data." This comparison can accurately quantify the "management deviations" of the real system. For example: Simulated data shows that core switch configuration file backups should be performed automatically every day. Real data shows that backup tasks failed for 3 days in the past week. Analysis conclusion: There is a risk of "inadequate implementation of regulations" in system management security, increasing the risk value. This assessment based on a "simulated benchmark" is far more scientific and accurate than simply checking "whether there are regulatory documents." Security is dynamic, and management systems need continuous evolution. Simulated networks provide a "laboratory" for optimizing these systems. For example, a security incident (such as a virus outbreak) occurs in a real system. Analysis reveals that the existing "patch management system" requires monthly updates, but the virus exploits a new vulnerability, rendering the system ineffective. In the simulated network, the "patch management system" is modified to "weekly updates," and a virus attack is simulated to verify the effectiveness and side effects of the new strategy (whether frequent restarts will cause business instability). After successful verification, the optimized system is deployed to the real system. This enables the entire security management system to have self-learning and continuous improvement capabilities. The simulated network becomes a "wind tunnel" for management systems; any modification must first be tested in the wind tunnel before being applied to the real world. The system construction management module builds a simulated network based on the target data center's structural and operational environment parameters, and constructs and verifies management systems for this simulated network, aiming to build a "digital twin-driven management security verification and benchmark generation system." This design first addresses the challenge of "not daring to try, not being able to make mistakes" in real production environments when implementing management systems. By pre-running and stress-testing in a high-fidelity simulated network, it enables the early detection and remediation of loopholes in management systems, ensuring their scientific validity and feasibility before implementation. Secondly, it utilizes structural and operational environment parameters to ensure precise adaptation between management systems and the physical entities and equipment performance of the data center, eliminating the disconnect between systems and reality. More importantly, this module uses the idealized management data generated in the simulated network as a "dynamic baseline," providing a quantitative comparative reference for subsequent management security assessments of the real system, enabling the risk assessment and analysis module to accurately identify deviations in system implementation.Ultimately, this design forms a closed loop of management security consisting of "simulation verification - real execution - deviation feedback - simulation optimization", enabling the management security capabilities of the entire system to have a continuously evolving vitality.
[0129] The network security management module constructs and manages the network security management system of the target computer room and the target network security system based on the constructed simulated network. It also manages the constructed simulated network according to the constructed network security management system and transmits the network security management data of the target computer room and the target network security system to the management security module.
[0130] Specifically, if the network security management module is only responsible for collecting static, documented "network security policy documents" (such as "firewalls should block external access"), it is merely an electronic policy assembler. However, by building and managing based on a simulated network, it is upgraded to a "wind tunnel laboratory for network security policies" and a "quantitative evaluation platform for defense effectiveness." The real network is the lifeline for continuous business operations. Directly applying untested network security management policies (e.g., new firewall policies, intrusion detection rules, or access control lists) poses two major risks: 1. Risk of false positives: The strategy may be too strict and incorrectly block normal business traffic (such as mistakenly identifying database synchronization traffic as an attack).
[0131] 2. Risk of ineffectiveness: The strategy may have vulnerabilities and cannot truly defend against the expected attacks, but the manager mistakenly believes that "having a strategy means we are safe".
[0132] The network security management module uses a simulated network (which accurately replicates the topology, configuration, and traffic characteristics of a real network) already built by the system construction management module as a test sandbox.
[0133] In this isolated simulated network, various pending network security management policies can be boldly deployed. For example, a policy of "blocking all overseas IPs from accessing the core database" can be tested to verify in a simulated environment whether this policy will simultaneously block legitimate cross-border business collaborations. By injecting attack traffic into the simulated network (such as simulating ransomware propagation), the newly established "virus protection management policy" can be tested to see if it can truly block the propagation path as expected.
[0134] Traditional network security management systems are often static (e.g., "passwords are changed every 90 days"), while network threats are dynamically evolving. Static systems are ill-equipped to handle new threats such as zero-day vulnerabilities and variant viruses. The network security management module uses a simulated network as a "threat training ground." It applies the latest threat intelligence obtained externally (such as new attack signatures and malicious IP address databases) to the simulated network. It observes how "honeypots" or simulated systems in the simulated network are affected by these new attacks, allowing for targeted adjustments to the network security management system (e.g., updating intrusion detection rule signatures and adjusting firewall blocking strategies). This gives the network security management system the ability to evolve dynamically. For example, when a new type of DDoS attack based on a specific protocol vulnerability breaks out globally, the network security management module can first reproduce the attack in a simulated network to verify the effectiveness of the existing "DDoS defense management system," quickly optimize new defense strategies, and then push them to the real network. This achieves a shift from "post-incident remediation" to "proactive defense."
[0135] When assessing the cybersecurity of a real system, the risk assessment and analysis module requires a "best practice baseline" or "theoretical defense value" to determine whether the current defense level is "excellent," "passable," or "weak." For example, the network security management module runs an optimized, ideal network security management system under controlled conditions in a simulated network and simulates various attacks for stress testing, recording the system's defense effectiveness under ideal conditions (e.g., "theoretically, it can defend against 99% of known SQL injection attacks," "theoretically, it takes an attacker an average of 30 minutes to breach the first line of defense"). This verified, idealized network security management data generated from the simulated network (i.e., the "theoretical defense baseline") is transmitted to the management security module. The management security module compares the "runtime security data" collected from the real network (e.g., "the firewall blocked 100 attacks this week, but only 1 successfully breached") with this "simulated ideal baseline." This comparison accurately quantifies the "defense effectiveness gap" in the real network. For example, ideally, the protection success rate against a vulnerability should be 100%. The actual protection success rate is only 80%. In real-world systems, network security management systems may exhibit implementation deviations or policy flaws, increasing the risk level. This assessment based on a "simulated baseline" is far more scientific than simply checking the "number of firewall rules."
[0136] Attackers' attack paths are often circuitous and complex. Security policies for a single device are insufficient to combat APT (Advanced Persistent Threat) attacks. In a simulated network, network security administrators can act as "attackers," attempting to breach defenses using various methods. The system automatically records every action the attacker takes and the vulnerabilities they exploit. Based on the simulation results, the network security management module can generate a "possible attacker path map" and identify the most critical nodes in the entire chain. For these critical nodes, corresponding network security management policies are strengthened (e.g., requiring not only firewall blocking but also adding log auditing on the server side and abnormal operation alerts on the user side). The system is then validated again in the simulated network to see if the strengthened policies have truly broken the attack chain. This upgrades network security management from "single-point defense" to "full-link collaborative defense." The simulated network becomes a simulation sandbox for attack chains, while the network security management module is responsible for transforming the simulation results into a comprehensive management system covering the network, hosts, applications, and data.
[0137] The network security management module is built upon a simulated network to construct and manage network security management policies, aiming to create a "digital twin-driven network security policy verification and effectiveness quantification system." It addresses the "no-trial-and-error" challenge of directly applying network security policies in real production environments by simulating various known and unknown attacks in a high-fidelity simulated network. This allows for attack load testing and policy stress testing of the network security management policies, ensuring their effectiveness and accuracy in the face of real threats and avoiding policy misjudgments or ineffectiveness. Secondly, leveraging the dynamic threat environment of the simulated network, it enables the network security management policies to continuously evolve, rapidly iterating and updating based on the latest threat intelligence, achieving a leap from static compliance to dynamic defense. More importantly, the module uses the idealized defense effectiveness data generated in the simulated network as a "security baseline," providing a quantifiable comparison standard for subsequent network security status assessments of real systems. This allows the risk assessment and analysis module to accurately identify weaknesses in the defense system and deviations in policy implementation. Ultimately, this design forms a proactive defense closed loop of "simulation-policy optimization-real-world execution-effectiveness feedback," significantly improving the entire system's survivability and responsiveness in network threat environments.
[0138] Based on the constructed simulated network and the constructed network security management system, the personnel safety management module constructs and manages the personnel involved in the target computer room and the constructed simulated network according to the personnel safety management system of the target computer room and the target network security system, and transmits the personnel safety management data of the target computer room and the target network security system to the management security module.
[0139] Specifically, if the system construction and management module builds a "digital twin" of the physical environment, and the network security management module builds a "tactical training ground" for technical defense, then the personnel security management module, based on these two, constructs regulations to address the most uncontrollable and weakest link in the network security chain—"human behavior." If the personnel security management module only collects employee job descriptions and training certificates, it's merely an electronic personnel file. However, by building and managing it based on a simulated network, it's upgraded to a "personnel behavior analysis and stress testing platform," capable of quantifying each person's security performance in actual network attack and defense scenarios. In real business systems, personnel permission settings often suffer from two major problems: excessive permissions and insufficient permissions. Directly adjusting permissions in the real system may lead to business interruptions or data leaks. The personnel security management module utilizes a pre-built simulated network (completely replicating the topology and data of the real system) and network security management regulations (defining technical defense strategies) to construct a "personnel operation sandbox." When new employees join or employees transfer to new positions, they can be granted the intended permissions in the simulated network to observe whether they can complete the assigned tasks and whether they access sensitive data beyond their responsibilities. For example, assigning a new operations engineer "server restart privileges" allows testing in a simulated network to see if they accidentally shut down core database services. Based on operation logs from the simulated network, the minimum necessary permissions for each role to complete their work can be accurately calculated, thereby optimizing personnel security management systems in real systems and achieving a true "principle of least privilege." Statistics show that over 90% of cyberattacks originate from some form of social engineering attack (such as phishing emails and phone scams). Traditional management systems can only stipulate "don't click suspicious links," but cannot quantify whether employees actually possess the ability to identify them. The personnel security management module uses the simulated network as a "social engineering training ground." Simulated phishing emails are sent to employees in the simulated network, observing which employees click the links and enter their account passwords. The system automatically records each "violation." Combined with the "normal behavior baseline" defined in the network security management system, it analyzes whether employees' operations in the simulated network deviate from the baseline (e.g., exporting large amounts of data during work hours, accessing unauthorized servers). This transforms "personnel security awareness" from a vague concept into a quantifiable risk indicator. For example, the system can generate a report stating: "Zhang San's click rate in the quarterly phishing test was 100%, indicating extremely high risk; Li Si's identification rate was 100%, indicating extremely low risk." This quantitative personnel safety management data is transmitted to the management security module, becoming an important part of the overall risk assessment.
[0140] When assessing personnel risks in a real system, the risk assessment and analysis module requires an "ideal behavior model" or "compliance behavior baseline" to determine whether actual operations are "normal" or "abnormal." The personnel safety management module, in a simulated network, has rigorously trained "model workers" or those operating under controlled conditions run standard operating procedures, recording theoretically the safest and most compliant personnel operation data. This includes standard login times, standard command sequences, and standard file access patterns. This idealized personnel safety management data (i.e., the "personnel behavior baseline") generated from the simulated network is transmitted to the management security module. The management security module compares the "running-state personnel behavior" (such as actual operation logs) collected from the real system with this "simulated-state ideal baseline." This comparison can accurately identify "abnormal human behavior." For example: the simulated baseline shows that maintenance personnel should log in to the server between 9:00 AM and 6:00 PM. Real data shows that a maintenance personnel logged into the core database at 2:00 AM for a week consecutively. This may indicate a risk of account theft or internal violations. This kind of abnormal behavior detection based on "simulated baseline" is far more intelligent than static "account lockout policies".
[0141] Real-world cyberattacks often combine technical and social engineering techniques. Simulating only technical attacks and defenses without considering human factors yields incomplete results. This simulation deploys both technical and social engineering attacks simultaneously within the simulated network. It observes how attackers breach the first line of defense by deceiving personnel, and then how they use compromised accounts to move laterally within the internal network. Based on the simulation results, the personnel security management module can specifically strengthen personnel security management systems, such as increasing the frequency of phishing drills targeting high-privilege personnel and implementing a two-person approval system. The same attack is then executed again in the simulated network to verify whether the strengthened systems effectively improve personnel's defensive capabilities. This transforms the personnel security management module from an isolated entity into one deeply integrated with network security management systems and system construction management, collectively forming a complete simulation environment capable of simulating real-world "human-machine combined attacks."
[0142] The personnel security management module is set up based on the constructed simulated network and network security management system to build and manage personnel security management systems. Its aim is to construct an intelligent personnel security management system where "human-caused risks are quantifiable, permission configurations are verifiable, and security awareness is measurable." It solves the "infeasibility" problem of directly testing personnel permissions and behaviors in a real production environment by constructing a "personnel operation sandbox" in a highly simulated network. This enables dynamic verification and precise convergence of personnel permission allocation, ensuring that each position only has the minimum permissions necessary to complete its business, thus reducing the risk of internal permission abuse at the source. Secondly, it uses the simulated network to conduct regular social engineering attack drills, quantifying employees' security awareness and anti-attack capabilities into assessable and traceable personnel risk indicators, transforming the originally abstract "human factor" into concrete risk assessment data. More importantly, this module uses the idealized personnel behavior data generated in the simulated network as a "behavioral baseline," providing a precise comparative reference for detecting abnormal personnel behavior in the real system (such as login outside of working hours, abnormal data access), enabling the risk assessment and analysis module to keenly detect deeper risks such as account theft and internal threats. Ultimately, this design incorporates "people," the most uncertain safety variable, into a closed-loop safety management system that can be simulated, assessed, and optimized throughout the entire lifecycle.
[0143] The system maintenance and management module establishes maintenance and management procedures for the target computer room and target network security system based on the constructed simulated network, performs maintenance and management of the constructed simulated network according to the established maintenance and management procedures, and transmits the maintenance and management data of the target computer room and target network security system to the management security module.
[0144] Specifically, the system maintenance management module is responsible for addressing the questions of "how to repair, how to maintain, and how to recover" the system during long-term operation. Building these systems based on a simulated network is precisely to avoid haphazard repairs and maintenance on the real system, which could lead to greater damage. System maintenance (such as patching, firmware upgrades, hardware replacement, and service restarts) is itself an "intervention" in the running system. Statistics show that a significant proportion of system failures are actually caused by improper maintenance operations (e.g., patch conflicts with existing software, incorrect upgrade order, accidental deletion of configuration files). The system maintenance management module uses a simulated network (which accurately replicates the hardware and software versions, configurations, and data of the real system) to build a "maintenance operation testbed." Before applying any maintenance operation to the real system, it is first fully executed on the simulated network. For example, the "monthly security patch update" process is tested in the simulated network to observe whether it conflicts with core business systems and to verify the effectiveness of rollback solutions. The compatibility and effectiveness of new maintenance tools (such as disk diagnostic tools and data backup and recovery tools) in the simulated environment are tested to ensure that they do not cause unexpected damage to the real system. Traditional maintenance management systems often employ a one-size-fits-all approach, such as quarterly dusting or annual battery replacement. This approach either leads to over-maintenance (wasting resources and increasing system downtime) or under-maintenance (equipment failing before its scheduled cycle). The system maintenance management module uses a simulated network as an "accelerated aging test platform." In this simulated network, virtual device replicas are subjected to loads and stresses exceeding those of the real environment, accelerating their "aging" process. Performance degradation curves and failure patterns of the simulated devices under different loads are observed, and fault prediction models are established. Based on these models, precise and dynamic maintenance plans can be developed. For example, simulation data shows that a certain model of hard drive has a mean time between failures (MTBF) of 180 days under specific loads. Based on this, the system maintenance management module can implement a policy whereby this model of hard drive is automatically added to a "replacement alert list" after 150 days of operation, and data migration is performed. This shift from "periodic maintenance" to "predictive maintenance" significantly improves system reliability while reducing unnecessary maintenance costs.
[0145] The most crucial part of maintenance management procedures is the "emergency plan," which outlines how to recover when the system actually fails. However, emergency plans are often static documents, never tested in real-world scenarios. Only when a fire or system outage occurs do they prove ineffective. The system maintenance management module utilizes a simulated network to regularly conduct "fault drills" and "red-blue team" exercises (the red team represents attackers or disruptors, and the blue team represents defenders or maintainers). In the simulated network, various faults are artificially created (such as simulating a core switch failure, database corruption, or power outage in the server room). The maintenance team then performs recovery operations according to the established emergency plan in the "maintenance management procedure." The system automatically records each step of the recovery operation and the time taken, evaluating the effectiveness of the plan. Executing the emergency plan in the simulated network generates "ideal recovery data" (e.g., "a core switch failure should be recovered within 30 minutes"). This verified maintenance management data generated from the simulated network (i.e., the "emergency recovery baseline") is transmitted to the management security module. When a real system failure occurs, the actual recovery process is compared to this "simulated baseline." For example, in a real system, a core switch failure took one hour to recover. By comparing this to the simulated baseline of 30 minutes, the problem can be accurately identified: was it due to operator unfamiliarity, or the lack of spare parts on-site? This allows for targeted optimization of the "maintenance management system" (such as increasing the frequency of drills or adjusting the location of the spare parts warehouse).
[0146] Maintenance is essentially about "change." Every change carries risk. Without strict process control, change is a gamble. Operations personnel propose change requests (such as "upgrading the database version"). In a simulated network, the entire change process is executed, its impact on business is observed, and a "Change Impact Analysis Report" is generated. Based on the simulation results, specific change steps and rollback plans are optimized and formalized as change operation standards, incorporated into the "Maintenance Management System." Following the optimized standard process, the change is executed on the real system. The execution process and results of the real change are recorded and compared with simulation data to form knowledge accumulation for optimizing the next simulation. This ensures that every maintenance operation undergoes a complete closed loop of "simulation-optimization-execution-review," minimizing change risks.
[0147] The system maintenance management module is set up to build and manage maintenance management systems based on the constructed simulation network, aiming to construct an intelligent system maintenance management system with "zero-risk verification, predictive maintenance, and dynamic emergency response." It addresses the "inherent risks" of directly performing maintenance operations in a real production environment by establishing a "maintenance operation testbed" in a high-fidelity simulation network. This allows for the pre-verification and optimization of all maintenance processes, including patch updates, hardware replacements, and configuration changes, ensuring that every real maintenance operation is based on a thoroughly tested standard process, fundamentally avoiding maintenance failures that could "cause problems instead of solving them." Secondly, it utilizes the simulation network for accelerated aging testing and fault injection drills, upgrading the maintenance cycle from traditional "periodic maintenance" to data-driven "predictive maintenance." Furthermore, through routine simulation drills of emergency plans, it generates a quantifiable "emergency recovery baseline." Ultimately, this module transmits the idealized maintenance process and emergency response data verified in the simulated network as the "maintenance performance benchmark" to the management security module. This provides crucial data support for the risk assessment and analysis module to evaluate the "maintainability" and "business continuity assurance capability" of the real system, forming a closed loop of full lifecycle maintenance management from "simulation verification to precise execution to emergency optimization".
[0148] Based on this, the management security module can collect, integrate, and analyze the received system security management data, network security management data, personnel security management data, and maintenance management data to form system security management data for the target computer room and the target network security system, and then transmit it to the risk assessment and analysis module.
[0149] Specifically, the four sub-modules report their respective "original management records" (such as a policy document, a training record, or a change order). Directly feeding this scattered and heterogeneous raw data to the risk assessment and analysis module would cause "data overload" and a "semantic gap," preventing the analysis module from understanding the risk implications behind this management data. The management security module exists to solve the technical problem of "normalizing, correlating, and semanticizing risk from multi-source management data."
[0150] Technical issue: The data structures output by the four sub-modules are completely different.
[0151] System construction management module: May output structured asset list, configuration item data (CMDB, configuration management database), and construction compliance report (such as PDF / XML).
[0152] Network security management module: May output firewall policy library version, vulnerability scan report (such as JSON / CSV), and security incident ticket.
[0153] Personnel safety management module: May output employee information table (database records), training completion status (boolean value), and permission allocation list.
[0154] System maintenance management module: May output maintenance work orders (including time, operator, equipment, and steps), emergency plan documents, and spare parts inventory list.
[0155] The management security module first acts as a "protocol adapter," connecting to the four sub-modules to collect raw data of different formats and protocols. Then, through a built-in data cleaning and transformation engine, all data is converted into an internal standard format (e.g., standardized data tuples with "object-attribute-value-timestamp-source"). After normalization, the originally chaotic management data becomes a well-organized "management data pool," laying the foundation for subsequent integrated analysis. Single-dimensional management data has limited value; only by linking them can deep-seated management vulnerabilities be discovered. For example, linking "personnel have permission" with "the asset corresponding to that permission has a high-risk vulnerability" constitutes a complete "internal risk scenario."
[0156] The management security module utilizes a correlation analysis engine to deeply integrate data from four sub-modules based on timelines, asset axes, and personnel axes. It links different management events occurring within the same time period. For example, it correlates the "server launch time recorded by the system construction module" with the "first failure time recorded by the maintenance module" to assess the initial stability of new equipment. It also binds different management data for the same asset. For instance, it packages "the switch's construction compliance report," "its access control policy," "the list of personnel responsible for operation and maintenance," and "the most recent maintenance work order" into a single asset management view. Furthermore, it correlates the job responsibilities, operation records, and permission assignments of the same personnel to construct a holistic profile of their behavior. This correlation connects previously isolated management points into a "management knowledge graph" reflecting the overall management landscape. For example, when the network security module reports "a server has been attacked," the management security module can immediately retrieve all associated management data: "Who built this server? Who is maintaining it? How often is patching required? Was it actually patched?" This provides a complete context for root cause analysis.
[0157] Original management records (such as "Zhang San attended the training") are events, while risk assessment requires status and trends (such as "Personnel safety awareness score 85 points"). The management security module needs to transform these "events" into "indicators." The management security module has a built-in risk indicator calculation engine that aggregates and refines the correlated data to generate high-level system security management data. This includes, but is not limited to: (1) Compliance indicators: the deviation rate between various management systems and actual operations (e.g., "the patch update system requires monthly updates, but the actual implementation deviation is 3 days").
[0158] (2) Coverage indicator: Whether key assets are covered by management system (e.g., "Does the core database have a backup system? Is it implemented?").
[0159] (3) Timeliness indicators: the efficiency of the management process (e.g., "the average time from the discovery of a vulnerability to the completion of the repair").
[0160] (4) Effectiveness indicators: the effectiveness of personnel training (e.g., "personnel identification rate in phishing email drills").
[0161] (5) Data dimensionality reduction: In this way, the management security module extracts massive and detailed management logs into lightweight, high-value-density risk indicator data.
[0162] The final system security management data generated by the security management module is a structured data packet that encapsulates the comprehensive health status of the entire target data center from a management perspective. This highly condensed system security management data is transmitted to the risk assessment and analysis module in real time. After receiving physical environment data from the physical security module and technical attack data from the network security module, the risk assessment and analysis module combines this management-dimensional data to conduct a comprehensive assessment based on a "physical-network-management" framework.
[0163] For example: The physical security management module reports: access control records show someone entered the server room late at night. The network security management module reports: no network attack logs were found during this period. The management security module reports: system security management data shows there were approved "emergency hardware maintenance work orders" during this period. The risk assessment and analysis module analyzes the data from the above module reports and concludes that it is determined to be "compliant emergency maintenance," does not trigger a high-risk warning, and avoids false alarms.
[0164] The management security module collects, integrates, and analyzes data from four management sub-modules: system construction, network security, personnel security, and system maintenance. Its aim is to build a "data governance and risk extraction center at the management dimension." First, the management security module addresses the heterogeneity of multi-source management data through data access and normalization, transforming scattered policy records, work order logs, and personnel files into a unified data pool. Second, through multi-dimensional correlation analysis based on time, assets, and personnel, it connects isolated management points into a "management knowledge graph" reflecting the overall management picture, constructing a complete management context for each asset and personnel. Furthermore, this module utilizes a risk indicator calculation engine to extract high-level quantitative risk indicators such as compliance, coverage, and timeliness from raw management events, achieving a value leap from "raw records" to "risk information." Finally, the management security module outputs a structured, lightweight system security management data set to the risk assessment and analysis module. This data encapsulates the overall health status and key risk indicators of the entire target data center at the management dimension. This design enables the upper-level analysis module to seamlessly incorporate the abstract dimension of "management security" into the comprehensive risk assessment system, forming a deep integration and collaborative analysis with physical security and network security data, thereby achieving comprehensive, three-dimensional, and accurate risk quantification and situational awareness of the target data center's "technology + management + environment".
[0165] The network security management module is responsible for building and managing the network security management system of the target computer room and the target network security system, and transmitting it to the management security module.
[0166] In simple terms, if the network security module is responsible for technical execution (like a security guard on patrol, responsible for specific security operations), then the network security management module is responsible for policy and regulations (like a team leader who plans patrol routes, responsible for formulating and supervising regulations). In practice, a common misconception regarding incomplete network security assessments is that only technical vulnerabilities are assessed, while management deficiencies are ignored. The network security module is responsible for data transmission, firewalls, and server security, collecting real-time data at the technical layer (such as attack logs, number of vulnerabilities, and configuration errors). The network security management module, however, is responsible for policy and regulatory data at the management level (such as whether there are clear password policies, vulnerability remediation procedures, and emergency response plans). If only the technical module exists, the system can detect "firewall rule configuration errors," but it won't know why—is it human error or a lack of policy requirements? By introducing a network security management module, policy documents and process specifications are digitized and incorporated into the assessment, achieving a leap from "discovering phenomena" to "tracing the root cause."
[0167] The output of the network security module serves as the "legal basis" for evaluating the performance of other modules. The network security management module first defines and manages "network security management policies" (e.g., requiring firewall rules to be updated quarterly, all systems to use complex passwords of at least 12 characters, and high-risk vulnerabilities to be patched within 24 hours). This policy data is transmitted to the management security module for aggregation and ultimately passed to the risk assessment and analysis module. Upon receiving technical data from the network security module (e.g., "firewall rules haven't been updated for 180 days," "server has weak passwords"), the risk assessment and analysis module compares it with the policy data from the network security management module. This setup ensures that the assessment is not an isolated scoring process but a compliance check based on rules. The system can automatically determine if "the current technical state violates established management policies," thus accurately identifying security risks caused by management vulnerabilities. For example, even if the system is not currently under attack, if it violates the policy requirement to "install antivirus software," the risk assessment and analysis module will increase its risk score accordingly.
[0168] In traditional cybersecurity assessments, management regulations are often static documents stored in a filing cabinet, with assessments simply involving checking "present" or "absent." The cybersecurity module in this application, however, imbues its sub-modules with dynamic attributes through their respective construction and management functions. "Construction" means regulations can be created and versioned within the system. "Management" means the implementation of regulations can be tracked. For example, after a regulation is updated, the system can check whether subsequent technical operations comply with the new regulations. This makes cybersecurity management more than just empty words. When a cyberattack occurs, the risk assessment and analysis module not only records the attack itself but also verifies whether the "emergency response system" exists, has been activated, and whether the response process is compliant. This dynamic and executable design of management regulations enables the entire security system to monitor management actions themselves, compensating for the shortcomings of relying solely on technical tools to detect "management inaction."
[0169] The cybersecurity management module aims to transform non-technical factors like "institutional regulations" into quantifiable and correlated assessment data. By creating a closed-loop comparison between the "institutional regulations" and the technical data collected by the cybersecurity module, it addresses the disconnect between security assessment and management processes in existing technologies. The cybersecurity management module not only provides compliance benchmarks for the configuration and operation of the cybersecurity module but also injects management-level judgment criteria into the risk assessment and analysis module. This enables the system to accurately identify deep-seated security vulnerabilities caused by management oversights (such as missing regulations or procedural violations), achieving a leap from single-technology protection to comprehensive risk assessment integrating technology and management.
[0170] The personnel security management module is responsible for building and managing the personnel security management system for the target computer room and the target network security system, and transmitting it to the management security module.
[0171] Specifically, if the network security module addresses the defense against machine-to-machine attacks, the system construction and management module addresses compliance throughout the system lifecycle, and the network security management module addresses the standardization of network operation procedures, then the personnel security management module addresses risk control of the core variable of human behavior and permissions.
[0172] Numerous security incidents indicate that 80% or more of breaches (intrusion incidents) involve human factors, including malicious leaks by insiders, unintentional negligence (such as clicking on phishing emails or using weak passwords), or abuse of privileges. Traditional technical tools (such as firewalls and IDS (Intrusion Detection Systems)) cannot identify these risks stemming from the human element. The personnel security management module is responsible for building and managing personnel security management policies. These policies are not merely employee handbooks, but rather a data-driven basis for understanding human behavior. They cover roles and permissions (who (system administrators, ordinary employees, third-party maintenance personnel) should have what level of access privileges?), security training (have personnel received sufficient security awareness training to identify phishing emails?), and departures and transfers (when personnel leave, are their account privileges promptly revoked? Is there a risk of dormant accounts?). By digitizing these policies and incorporating them into evaluations, the system gains the ability to perceive the state of the human element. For example, when the risk assessment and analysis module discovers that a high-privilege account is exporting a large amount of data at 3 AM, it will combine the "job responsibilities" and "operation time regulations" in the personnel security management module to determine whether this constitutes a violation, thereby accurately identifying potential internal threats.
[0173] The key to the personnel security management module lies in its ability to link people in the physical world with their identities in the digital world. This module defines and manages policies such as "only system maintenance personnel have permission to enter the core computer room" and "only database administrators have permission to perform data backup operations." This policy data is transmitted to the management security module and simultaneously shared with the risk assessment and analysis module as a benchmark for evaluation.
[0174] The personnel safety management module is linked with the physical security module: When the access control system of the physical security module records that "Zhang San" swipes to open the computer room door, the risk assessment and analysis module will immediately query the personnel safety management module: "Is Zhang San currently in a position that allows him to enter the computer room? Is his safety awareness training valid?" If Zhang San has been transferred to another position but his access control privileges have not been revoked, the system will determine him as high risk.
[0175] The personnel security management module works in conjunction with the network security module: when the same user, "Zhang San," performs a high-risk operation on the server, the system checks the "authorization scope" in the personnel security management module to determine if the operation exceeds authorized limits. This setup enables real-time comparison of physical identity, digital identity, and permission systems, constructing a true "least privilege principle" closed loop and preventing security vulnerabilities caused by excessive or residual permissions. Why is deleting a file sometimes considered a fault and sometimes an attack? The key lies in the operator's identity and intent. The personnel security management module gives the original technical logs a "personnel context." Without the personnel security management module, the system can only record: "192.168.1.10 executed the rm-rf / * command (database deletion command) at 14:30." With the personnel security management module, the system can further record: "Executor: Li Si (Position: Junior Operations Engineer; Status: Probationary; Authorization: Only has log viewing permissions)." Based on the policy data (job responsibilities, authorization scope, training records) provided by the personnel security management module, the risk assessment and analysis module can conduct deeper intent analysis: if the operator has the authority and operates within the prescribed working hours, it may be considered routine maintenance. If the operator lacks authority, is outside their scope of responsibility, or operates outside of working hours, the system will combine data from the network security module to determine whether it is account theft or unauthorized operation by internal personnel, thereby triggering different levels of alerts. This contextual analysis based on "people" greatly improves the accuracy and intelligence of risk assessment.
[0176] The personnel security management module aims to incorporate "people," the most active security variable, into the quantitative assessment system. By constructing and managing institutional data such as personnel permissions, job responsibilities, and training status, it provides crucial identity and authorization context for access records in the physical security module and operation logs in the network security module. This module enables mapping and correlation analysis between physical world personnel and digital world identities, allowing the risk assessment and analysis module to accurately distinguish between legitimate operations and potential threats (such as internal unauthorized access, abuse of privileges, and identity impersonation). This effectively compensates for the shortcomings of existing technologies that only focus on technical and system vulnerabilities while neglecting human risk factors, thus constructing a complete security assessment closed loop from technical defense to personnel management.
[0177] The system maintenance and management module is responsible for building and managing the maintenance and management system of the target computer room and the target network security system, and transmitting it to the management security module.
[0178] Specifically, if we compare the entire safety system to a car: the system construction and management module is the "car manufacturing standards" (determining the quality of the finished product); the network security management module is the "traffic rules" (stipulating how to drive); the personnel safety management module is the "driver qualifications" (stipulating who can drive); and the system maintenance management module is the "regular maintenance and repair records" (determining whether the car can continue to drive safely without malfunctions).
[0179] Every system (whether it's a precision air conditioner or UPS power supply in a data center, or a server's hard drive or operating system) will experience a period of performance degradation and increased failure rate after being put into use. Without continuous maintenance, the system's security will decrease over time. The system maintenance management module is responsible for building and managing maintenance management procedures. These procedures are not simply "repair manuals," but rather standardized processes to ensure the long-term stable operation of the system, including: (1) Daily inspection system: Is the equipment operating status checked every day (such as indicator lights, temperature and humidity, noise)? (2) Regular maintenance system: Does the equipment need regular dust removal, lubrication, and calibration (such as fire extinguisher pressure check, UPS battery health test)? (3) Fault Repair System: What is the repair reporting process when equipment malfunctions? What is the repair time limit? How to verify the repair effect? By digitizing these maintenance procedures and incorporating them into the evaluation, the system gained the ability to perceive "health trends." The risk assessment and analysis module no longer only looks at whether it is safe "at this moment," but can also determine "how long has this server been without maintenance? How many hours has the hard drive been running continuously? Is there a potential risk of downtime due to lack of maintenance?" Maintenance itself is a form of "intervention" in the system. As the saying goes, "Maintenance is necessary, but maintenance operations are also one of the biggest destabilizing factors in a system." The core of this module is to regulate this intervention behavior. The system maintenance management module defines maintenance procedures, such as "Maintenance of core equipment must be completed with a maintenance request form," "It must be approved," "It must be scheduled during off-peak business periods," "Backup must be performed before any changes," and "Functional testing must be conducted after maintenance." This policy data is transmitted to the risk assessment and analysis module as an evaluation benchmark.
[0180] The system maintenance management module and the network security module work together: When the network security module detects that a core switch suddenly restarts during peak business hours, the risk assessment and analysis module will immediately query the system maintenance management module: "Is there an approved maintenance plan at this moment?" If not, it is judged as "illegal restart" or "fault", and the risk score rises sharply; if there is, it is regarded as "planned change" and normal monitoring is carried out.
[0181] The system maintenance management module is linked with the personnel safety management module: When performing maintenance operations, the system will verify whether the "operator" has the qualifications to maintain the equipment (such as whether he / she holds an electrician's certificate and has been trained by the original manufacturer).
[0182] This setup enables full-process monitoring of "changes." It can effectively identify "configuration drift" (i.e., maintenance personnel modifying security configurations without authorization to save time) and "misoperation" (such as accidentally deleting the wrong configuration file), minimizing human error risks during maintenance.
[0183] In reality, systems will inevitably malfunction. What happens when a malfunction occurs? Are there contingency plans? Are these plans effective? These are the questions the system maintenance management module aims to answer. This module not only collects procedures but, more importantly, manages their "executability" and "historical records." It can store and manage contingency plans for various malfunctions (such as power outages in the data center, core switch failures, and data corruption). It records whether these plans have been regularly practiced, whether the practice was successful, and whether personnel are familiar with the procedures. It also records the cause, handling process, and corrective measures for each malfunction. When a real malfunction occurs, the risk assessment and analysis module can conduct an "emergency response capability assessment" based on this data. If a data center has a written emergency plan but hasn't practiced it for three years, the system will determine its "emergency response capability" to be extremely low in the event of a fire or system downtime, thus raising the overall risk level of the data center. This assessment of "system resilience" is something static assessments cannot achieve. The system maintenance management module aims to incorporate "system lifecycle operation and maintenance support capabilities" into the core indicators of risk assessment. By constructing and managing institutional data such as daily inspections, regular maintenance, fault repair, change control, and emergency response, it provides the network security module's technical monitoring data with a "system health history" and "change context." This module effectively fills the gap in existing technologies that only focus on the initial state of system construction and current operation, while neglecting the "dynamic impact of the maintenance process on the system's security status." Through data linkage with modules such as physical security, network security, and personnel security, it enables the risk assessment and analysis module to accurately identify equipment aging risks caused by maintenance deficiencies, configuration risks caused by uncontrolled changes, and business continuity risks caused by insufficient emergency response, thereby constructing a complete security assessment closed loop from "stable operation" to "continuous reliability."
[0184] The security management module is responsible for recording and collecting the system management regulations, network security management regulations, personnel security management regulations, and maintenance management regulations of the target computer room and the target network security system, and generating system management security data of the target computer room and the target network security system, which is then transmitted to the risk assessment and analysis module.
[0185] Specifically, the patent application explains the necessity of setting up a "management security module" and having it undertake the function of "aggregating and forming system management security data". The key is to clearly explain its role as the "central nervous system" or "data fusion device" in the entire system architecture.
[0186] The aforementioned four sub-modules (system construction management module, network security management module, personnel security management module, and system maintenance management module) are used to manage their respective regulations. However, these regulations are scattered, heterogeneous, and isolated. If these original policy documents or scattered data are simply dumped onto the risk assessment and analysis module, the analysis module will be unable to process them effectively. This is like sending tactile, auditory, and visual signals directly to the motor nerves without processing them in the brain; it will only cause chaos.
[0187] The management security module exists to solve the technical problem of "data aggregation and homogenization." System construction management regulations might be documents (such as PDFs / Words), network security management regulations might be records from a process approval system (such as XML data), personnel security management regulations might be personnel information tables from an HR system (such as database records), and system maintenance management regulations might be logs from a work order system (such as text files). These data have completely different formats, structures, and update frequencies. The risk assessment and analysis module cannot directly read and analyze this diverse data. The management security module acts as a "data adapter." It is responsible for interfacing with the four sub-modules, uniformly collecting these raw policy data from different sources and in different formats. Through the processing of this module, the originally scattered "policy documents" are transformed into structured "system management security data," enabling the risk assessment and analysis module to read and understand this management dimension information through a unified interface. Individual policy data often has limited meaning, but correlating them can reveal deeper problems. This "correlation" action needs to be completed by the management security module.
[0188] For example, the personnel security management module says "Zhang San has permission," and the system maintenance management module's record shows "Zhang San is performing system maintenance." These two data entries appear normal individually. The management security module merges these two data entries (plus timestamps, device IDs, etc.) into a contextualized message: "Zhang San (personnel data) performed maintenance operations on the core switch at a specific time, according to the maintenance management system (process data)." This correlated and merged "system management security data" is no longer an isolated point but forms a complete chain of management actions. After obtaining this data, the risk assessment and analysis module can directly use it to determine "whether the operation is compliant" and "whether the permissions match," without needing to painstakingly correlate the underlying data itself.
[0189] If the risk assessment and analysis module is directly coupled to the four (and potentially more in the future) management sub-modules, any change in the interface or data structure of any sub-module (e.g., the personnel safety management module changes its database) would require modifications to the risk assessment and analysis module to adapt, leading to system instability and difficulty in maintenance. This application sets up a management security module as a "middle layer." The management security module provides a stable and unified data interface to the risk assessment and analysis module. It also adapts to various changes that may occur in the four sub-modules. This design achieves "modular decoupling." If a new management dimension needs to be added in the future (e.g., adding a "supplier safety management module"), only the data acquisition adapter of the management security module needs modification; the risk assessment and analysis module remains completely unaffected, continuing to process the standardized data sent by the management security module according to its original logic. This significantly enhances the scalability and robustness of the entire system.
[0190] The raw policy data can be massive and redundant (e.g., containing tens of thousands of user login logs). Directly transmitting all this raw data to the risk assessment and analysis module would consume significant network bandwidth and computing resources, leading to decreased analysis efficiency. The management security module, after collecting the data, performs preliminary cleaning, aggregation, and refinement. Based on preset rules, it aggregates raw data such as "personnel card swipe records," "policy document version numbers," and "maintenance work order status" into valuable "management indicators," such as "number of missing policy items," "permission violation rate," and "maintenance timeout rate." What is transmitted to the risk assessment and analysis module is refined, high-value-density "system management security data." This allows the analysis module to focus more on core risk assessment algorithms without expending resources on cleaning and organizing basic data, thereby improving the real-time performance and assessment efficiency of the entire system.
[0191] Therefore, this application sets up a management security module as the core hub connecting the four management sub-modules and the risk assessment and analysis module, aiming to solve the problems of heterogeneity, correlation, and decoupling of multi-source management data. This module uniformly records and collects policy data scattered across various dimensions such as system construction, network security, personnel security, and system maintenance, performs normalization, correlation fusion, and aggregation extraction on this data, ultimately forming structured and standardized system management security data. This design not only provides high-quality, easily processed input data for the upper-level risk assessment and analysis module, enabling complete traceability of the management behavior chain, but also ensures the system's stability and scalability when facing future expansions in management dimensions through modular decoupling. It transforms the originally abstract concept of "management security" into quantifiable and analyzable technical indicators, thereby enabling the entire risk assessment system to truly achieve deep integration and collaborative analysis of technical and management data.
[0192] Based on this, the risk assessment and analysis module of this application can be responsible for receiving and analyzing the various security data transmitted by the physical security module, network security module and system management security module in real time, assessing the security risks existing in the target computer room and issuing warnings based on preset warning conditions and the security risk assessment results of the target computer room.
[0193] Specifically, all the modules (physical security module, network security module, and system management security module) described above are equivalent to the "five senses" and "nerve endings" of the human body, responsible for sensing and collecting raw signals from different dimensions. However, without the brain's comprehensive processing of these signals, a person cannot form a holistic judgment of the environment, let alone react in a timely manner. The existence of the risk assessment and analysis module is to solve a series of core technical problems, including "fusion analysis of multi-source heterogeneous data," "quantitative assessment of security status," and "automated response to risk outcomes."
[0194] The physical security module sends "access control records" and "smoke alarms," the network security module sends "attack logs" and "vulnerability lists," and the management security module sends "compliance data." These data are completely independent at the underlying level, forming so-called "information silos." No single module can detect complex, cross-dimensional risks.
[0195] The risk assessment and analysis module acts as a "data fusion engine." It aligns and correlates data from these three dimensions (physical, network, and management) along both time and spatial axes. This fusion analysis can uncover "hidden risks" that would be impossible to detect with a single module.
[0196] For example, a network security module report stating "the server suffered a brute-force attack" might seem like a simple network attack on its own. However, if simultaneously the physical security module shows "abnormal card swipe records during the attack" and the management security module indicates "the server lacks maintenance procedures," the analysis module can deduce that this might be a targeted attack orchestrated by internal and external collusion, with a risk level far exceeding that of a simple network attack. This deep correlation capability is something no single module possesses.
[0197] Raw data itself lacks "value judgment." If a smoke alarm goes off, is it a false alarm or a real fire? If a server has a vulnerability, is it high-risk or low-risk? Without quantification, it's impossible to determine response priorities. The risk assessment and analysis module incorporates assessment algorithms and models. It transforms received raw security data (physical events, cyberattacks, management deficiencies) into quantifiable risk values (e.g., classifying risks into high, medium, and low levels, or providing a risk index from 0 to 100). This quantitative assessment transforms security management from "gut feeling" to "data-driven." The module comprehensively considers the severity of vulnerabilities, the importance of assets, the vulnerability of the physical environment, and the completeness of management systems, ultimately providing an objective and scientific comprehensive risk score. For example, a data center located in a flood-prone area (high physical risk) and lacking disaster recovery backup systems (high management risk) will have a high comprehensive risk score even without a temporary cyberattack.
[0198] Single sensors or detection methods are prone to false alarms. For example, a smoke sensor might falsely detect dust, and an intrusion detection system might falsely detect normal traffic. If each module issues warnings independently, it can lead to an "alarm storm," leaving maintenance personnel confused and ultimately causing them to ignore truly important alarms. The risk assessment and analysis module utilizes multi-source data for cross-validation. It doesn't immediately determine a high-risk fire based on an isolated "smoke alarm." It simultaneously requests data from other modules for verification: for example, it can query the monitoring module to confirm if there is visible smoke or flames on the screen; it can query the power module to confirm if there are abnormal current fluctuations; it can query the personnel management module to confirm if there are any maintenance approval records for hot work. Only when multi-dimensional data simultaneously confirms the existence of a risk (e.g., smoke alarm + visible flames + no hot work records) will the module trigger the highest level of fire warning. This "judgment mechanism" based on multi-source data collaboration greatly reduces the false alarm and missed alarm rates, ensuring the accuracy and reliability of the warnings. The ultimate goal of assessment is action. The risk assessment and analysis module is not only the analysis center but also the control command issuance center for the entire system.
[0199] The risk assessment and analysis module receives data from the physical security management module, network security management module, and administrative security module. Its processing involves analyzing, integrating, and quantitatively assessing the received data. The final output (early warning) is triggered when the assessment result (risk value) exceeds a preset threshold (early warning condition), and the module immediately issues an early warning command. This early warning can be multi-layered. (1) Notification-type warning: The risk is low, and an email or SMS notification is sent to the administrator.
[0200] (2) Blocking warning: The risk is high. The network security module can be directly linked to dynamically modify the firewall policy to block the attacking IP; or the physical security module can be linked to lock the access control to prevent people from escaping or entering.
[0201] (3) Disaster warning: The risk is extremely high, and backup power or data backup process can be activated.
[0202] This automated closed loop of "perception-analysis-decision-execution" truly achieves proactive defense, curbing the spread of risks in the shortest possible time and minimizing losses.
[0203] Therefore, this application includes a risk assessment and analysis module, aiming to construct the "decision-making center" of the entire network security risk assessment system. This module solves the "information silo" problem in existing technologies, where multi-source security information cannot be collaboratively analyzed, by receiving and deeply integrating heterogeneous data from three dimensions: physical environment, network operation, and management system. It utilizes a built-in assessment model to transform raw data into quantified risk values, enabling a scientific, dynamic, and comprehensive assessment of the target data center's security status. More importantly, this module effectively filters out false alarms through cross-validation of multi-source data, ensuring the accuracy of early warnings; and by automatically triggering tiered early warnings based on preset conditions, it achieves a leap from "passive monitoring" to "proactive response," completing a closed-loop security protection system of "perception-analysis-decision-execution," greatly enhancing the entire system's risk prevention and control capabilities and automation level in complex network environments.
[0204] Among them, the preset early warning conditions are the core rule engine for achieving automated risk assessment and response. These conditions are not set out of thin air, but are formulated closely around the data characteristics of the three dimensions of physical environment, network security, and management system, combined with the actual business needs and security standards (such as Cybersecurity Classified Protection 2.0 and ISO 27001) of the target data center.
[0205] Generally, preset warning conditions can be categorized into the following four main types, each corresponding to different risk scenarios: 1. Triggering conditions based on single-point thresholds This type of condition is the simplest and most direct; an alert is triggered when a metric from a single data source exceeds or falls below a set threshold. It serves as the system's "bottom-line defense."
[0206] (1) Physical security category: Access control anomaly: The same access card fails to open multiple times in a short period of time (e.g., within 1 minute); door opening requests outside of working hours; access control is forcibly opened (abnormal door magnetic signal).
[0207] Abnormal environment: Smoke sensor concentration exceeds threshold; computer room temperature or humidity is too high / too low; UPS power supply (uninterruptible power supply) load exceeds 80% or battery power is below 20%.
[0208] Monitoring and analysis: AI video analysis detected objects left behind, people engaging in violent activities (fighting), or people falling to the ground in the computer room.
[0209] (2) Network security: Attack thresholds: The firewall or IPS (Intrusion Prevention System) blocks more than 100 attacks within 1 minute; the connection request rate of a synchronous flood attack from the same source IP exceeds 1000 per second.
[0210] Vulnerability Risk: The target server was found to have a high-risk vulnerability with a CVSS (Common Vulnerability Scoring System) score of 9.0 or higher, which has not been patched.
[0211] Performance anomaly: Core server CPU utilization exceeded 95% for 5 consecutive minutes; switch bandwidth utilization exceeded 90%.
[0212] (3) Management and security category: System deficiency: A core system (such as the Emergency Response Plan) has exceeded its update period (e.g., it has not been revised for more than 1 year).
[0213] Maintenance overdue: The equipment has exceeded the prescribed maintenance period (such as fire extinguisher annual inspection expired, server dust removal not performed).
[0214] 2. Composite conditions based on multi-source association analysis These types of early warning conditions require the risk assessment and analysis module to integrate data from two or more modules for logical judgment, aiming to discover hidden and complex attack behaviors.
[0215] (1) Physical + Network (Collusion between internal and external parties / Identity impersonation): For example, when the physical security module detects that "personnel A enters the computer room through the access control," the network security module detects that "personnel A's account is logging in on an external network." (This means that the account may have been stolen, or that the person entering the computer room is not the account holder.)
[0216] (2) Physical + Management (Violation of regulations): For example, the physical security module records "someone entered the computer room at 2 a.m.", but the management security module (personnel / maintenance) cannot find "an approved overtime maintenance application at 2 a.m.".
[0217] (3) Network + Management (Abuse of Rights): For example, the network security module detects that "an account is exporting a large amount of sensitive data in batches," while the management security module (personnel security) shows that the account holder's job title is "front desk clerk" and that they do not have data export permissions.
[0218] (4) Physical + Network + Management (Comprehensive Judgment of Major Accidents): For example: Smoke alarm triggered + monitoring video confirms flames + power module reports sudden voltage drop + personnel management shows no one in the computer room. At this time, the system should determine it as the highest level "fire emergency warning".
[0219] 3. Conditions based on state accumulation and trend analysis These conditions focus on the long-term changes and cumulative effects of risk, and are used to predict potential systemic problems.
[0220] (1) Frequency accumulation: For example: the power module of a certain server rack experienced more than 3 voltage fluctuations in the past 7 days; a certain server experienced more than 5 abnormal restarts in a week.
[0221] (2) Rate change: For example, the rate at which the number of bad sectors in a disk array increases suddenly accelerates (e.g., from 1 new bad sector per day to 100 new bad sectors per day).
[0222] (3) Personnel behavior profile: For example, the number of times an operations and maintenance personnel logged in after get off work in the past week far exceeded their average behavior baseline over the past 3 months.
[0223] 4. Logical conditions based on compliance checks These conditions directly correspond to laws, regulations, or internal corporate rules, ensuring that the system is always in a compliant state.
[0224] (1) Personnel qualifications: For example, the relevant qualification certificates of special equipment operators (such as electricians and fire duty officers) have expired for more than 30 days.
[0225] (2) Audit compliance: For example, the system log retention time is less than 6 months (which does not comply with the requirements of the Cybersecurity Law).
[0226] (3) Dual-person operation principle: For example, when making configuration changes to the core switch, the network security module detects that only one person is performing the operation, which violates the "dual-person mutual inspection" principle stipulated in the "Maintenance Management System".
[0227] Therefore, the pre-set early warning conditions in this application include, but are not limited to: (1) single threshold conditions, used to monitor the instantaneous exceedance of physical environment, network performance and vulnerabilities; (2) correlation analysis conditions, used to identify complex attacks and violations across multiple dimensions of physical, network and management; (3) cumulative trend conditions, used to detect system performance degradation and abnormal personnel behavior; (4) compliance logic conditions, used to ensure that the system operation complies with the requirements of national laws and regulations and the company's internal management system.
[0228] Specifically, the system of this application also includes an early warning module and several key information infrastructure devices; each key information infrastructure device is connected to the early warning module, and the early warning module can be connected to the risk assessment and analysis module; the early warning module may include a storage module; each server hosting each key information infrastructure device is configured with a corresponding data cloud; each data cloud has a corresponding backup cloud; each data cloud and its corresponding backup cloud are connected via a virtual signal; the data cloud is responsible for transmitting the first target data of the target database to the early warning module for double encryption before analysis and backup to its corresponding backup cloud and storage module; the early warning module can perform fusion analysis of relevant data from each key information infrastructure device and issue an early warning, and synchronize the early warning information to the risk assessment and analysis module. For example, the topology network between the early warning module and each key information infrastructure device can be a star structure, and the early warning module is essentially a master controller. Furthermore, the early warning module may also include a display module, an alarm module, a data analysis module, and a data encryption module. The storage module can be connected to the data analysis module. The data analysis module includes a decompression module, a calculation module, and a filtering analysis module. The data encryption module includes a first encryption module and a second encryption module. The first encryption module and the second encryption module are linked, and the encryption algorithm of the first encryption module is different from the encryption mode of the second encryption module. The encryption algorithm of the first encryption module is preferably symmetric encryption technology, and the encryption algorithm of the second encryption module is specified or formulated by the administrator.
[0229] Based on this, the process by which the data cloud transmits the first target data of the target database to the early warning module for double encryption, analysis, and backup to the corresponding backup cloud and storage module can include the following: The data cloud transmits the first target data of the target database to the decompression module; the decompression module parses the first target data to obtain the first data and transmits it to the calculation module; the calculation module receives and calculates the first data to obtain the second data and transmits it to the filtering and analysis module; the filtering and analysis module receives and filters the second data to obtain the third data and transmits it to the data cloud, and reports the data in the third data that exceeds the preset early warning value to the alarm module and the display module, which then issues a data warning and displays the warning information and corresponding data; the data cloud transmits the third data to the first encryption module; the first encryption module receives and encrypts the third data for the first time to obtain the fourth data and transmits it to the second encryption module; the second encryption module is responsible for encrypting the fourth data to obtain the fifth data and transmits it to the data cloud, which then backs up the fifth data to the backup cloud and storage module.
[0230] Specifically, a complete processing flow from the data cloud to the early warning module and backup cloud is set up, aiming to build a data lifecycle security management system integrating intelligent analysis, defense in depth, and reliable storage. This process first standardizes and parses the raw data through a decompression module, laying the foundation for subsequent intelligent processing. Then, the computation module extracts features and refines the value of the raw data, transforming massive amounts of monitoring data into high-value quantitative indicators. Subsequently, the filtering and analysis module acts as an intelligent decision-making node, performing real-time analysis of the indicators and reporting only critical risk data (third data) exceeding preset warning values to the alarm and display module for second-level early warning. Simultaneously, the tagged data is transmitted back to the cloud, achieving a perfect balance between data noise reduction and real-time response. In the data transmission and storage phase, the system employs an innovative dual heterogeneous encryption mechanism: the first and second encryption modules are cascaded using different encryption algorithms to build a defense-in-depth system, greatly enhancing the data's resistance to cracking. Finally, the encrypted fifth data is simultaneously transmitted to the backup cloud and local storage modules, forming a "local + cloud" multi-layered insurance, ensuring the confidentiality, integrity, and high availability of core data assets. This design enables closed-loop management across the entire chain, from data collection, intelligent analysis, risk warning to secure storage.
[0231] The data analysis module accesses the data in the storage module, parses, calculates, and selects data values that exceed a preset threshold range, and transmits them to a virtual storage space in the early warning module. If the data exceeds the preset threshold range, the alarm module activates and the alarm sounds. If the data does not exceed the preset threshold range, the alarm does not sound, and important data is stored separately in a backup cloud to prevent data loss due to network accidents. It is worth noting that the data within the preset threshold range is also encrypted to prevent theft in the event of data loss.
[0232] The following is combined with Figure 2 This paper introduces the implementation process of the network security risk assessment and analysis method presented in this application, such as... Figure 2 As shown, the process may include the following steps: Step S101, establishing an access control management system for the target computer room and implementing access control management for the target computer room based on this system. Step S102, based on the access control management system for the target computer room, collecting and recording access control management data and real-time monitoring data of the target computer room to determine the physical security data of the target computer room. Step S103, acquiring network security data of the target computer room and its corresponding target network security system. Step S104, establishing and managing the system management system, network security management system, personnel security management system, and maintenance management system for the target computer room and target network security system. Step S105, based on the system management system, network security management system, personnel security management system, and maintenance management system for the target computer room and target network security system, recording and collecting these systems to form system management security data for the target computer room and target network security system. Step S106: Analyze various security data of the target data center and the target network security system in real time, assess the security risks existing in the target data center, and issue warnings based on preset warning conditions and the security risk assessment results of the target data center. Step S107: Encrypt the first target data in the target database twice before analysis, backup, and storage. The specific implementation process of steps S101-S107 can be referred to the interaction process of the various modules of the aforementioned network security risk assessment and analysis system, and will not be elaborated here.
[0233] The network security risk assessment and analysis system provided in this application can be applied to network security risk assessment and analysis devices, such as terminals: mobile phones, computers, etc. Optionally, Figure 3 The hardware structure block diagram of the network security risk assessment and analysis device is shown, with reference to... Figure 3The hardware structure of the network security risk assessment and analysis device may include: at least one processor 1, at least one communication interface 2, at least one memory 3, and at least one communication bus 4. In this application, the number of processor 1, communication interface 2, memory 3, and communication bus 4 is at least one, and the processor 1, communication interface 2, and memory 3 communicate with each other through the communication bus 4. The processor 1 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement this application; the memory 3 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device; wherein, the memory stores a program, and the processor can call the program stored in the memory, the program being used to implement various processing flows in the aforementioned terminal network security risk assessment and analysis scheme. This application also provides a readable storage medium that can store a program suitable for processor execution, the program being used to implement various processing flows of the aforementioned terminal in the network security risk assessment and analysis scheme. Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The various embodiments described in this specification are presented in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. The various embodiments can be combined with each other. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A network security risk assessment and analysis system, characterized in that, The system includes: a physical security module, a network security module, a management security module, and a risk assessment and analysis module; The risk assessment and analysis module is connected to the physical security module, the network security module, and the management security module, respectively. The physical security module is responsible for collecting and recording the physical security data of the target computer room and transmitting it to the risk assessment and analysis module; wherein, the physical security module includes an access control management module, which is used to manage the access control permissions of the target computer room; The network security module is responsible for ensuring the security of data transmission, firewall security, and target server security of the target computer room and its corresponding target network security system, as well as recording and collecting network security data of the target computer room and transmitting it to the risk assessment and analysis module. The management security module is responsible for recording and collecting the system management system, network security management system, personnel security management system, and maintenance management system of the target computer room and the target network security system, and generating system management security data of the target computer room and the target network security system and transmitting it to the risk assessment and analysis module. The risk assessment and analysis module is responsible for receiving and analyzing the various security data transmitted by the physical security module, the network security module, and the system management security module in real time, assessing the security risks existing in the target computer room, and issuing warnings based on preset warning conditions and the security risk assessment results of the target computer room.
2. The system according to claim 1, characterized in that, The target computer room is equipped with a monitoring module, a smoke alarm module, and a power supply module. The smoke alarm module includes a smoke sensor, an alarm, and a fire extinguisher. The monitoring module includes first monitoring devices installed at the entrance of the target computer room and second monitoring devices installed inside the target computer room. Each first monitoring device and each second monitoring device provides comprehensive real-time monitoring of the target computer room. The power supply module is responsible for providing uninterrupted power to all electrical equipment in the target computer room.
3. The system according to claim 2, characterized in that, The process by which the physical security module collects and records the physical security data of the target computer room and transmits it to the risk assessment and analysis module includes: The access control management module analyzes the access control request permissions for the target computer room, prohibits access access requests without permission, and allows access access requests with permission. It also records the access control information of all access access requests to the target computer room and reports it to the physical security module. The monitoring module collects and reports the monitoring data of each monitoring device in the target computer room to the physical security module; The smoke alarm module collects and reports the smoke alarm information of the target computer room to the physical security module; The power module collects and reports the power consumption data of the target computer room to the physical security module; The physical security module integrates the access control information, monitoring data, smoke alarm information, and power consumption data of the target computer room to generate physical security data of the target computer room and transmits it to the risk assessment and analysis module.
4. The system according to claim 1, characterized in that, The network security module accesses the target network platform using a preset encrypted access method based on the target server to exchange data. The process by which the network security module records and collects network security data of the target computer room and transmits it to the risk assessment and analysis module includes: The network security module collects and inspects the data transmission paths, data, firewalls, and network security of the target computer room and its corresponding target network security system, and generates corresponding network security data. The generated network security data is then transmitted to the target network platform via the target server.
5. The system according to claim 1, characterized in that, The process by which the management security module records and collects the system management regulations, network security management regulations, personnel security management regulations, and maintenance management regulations of the target computer room and the target network security system, and generates system management security data for the target computer room and the target network security system and transmits it to the risk assessment and analysis module includes: The system construction and management module constructs a simulated network of the target computer room based on the structural parameters and operating environment parameters of the target computer room, and constructs corresponding system management rules for the simulated network and manages the constructed simulated network according to the constructed system management rules, and transmits the system management data of the target computer room and the target network security system to the management security module. The network security management module constructs and manages the network security management system of the target computer room and the target network security system based on the constructed simulated network, and manages the constructed simulated network according to the constructed network security management system, and transmits the network security management data of the target computer room and the target network security system to the management security module. The personnel safety management module, based on the constructed simulated network and the constructed network security management system, constructs and manages the personnel involved in the target computer room and the constructed simulated network according to the personnel safety management system of the target computer room and the target network security system, and transmits the personnel safety management data of the target computer room and the target network security system to the management security module. The system maintenance and management module constructs a maintenance and management system for the target computer room and the target network security system based on the constructed simulated network, performs maintenance and management on the constructed simulated network according to the constructed maintenance and management system, and transmits the maintenance and management data of the target computer room and the target network security system to the management security module. The management security module collects, integrates, and analyzes the received system security management data, network security management data, personnel security management data, and maintenance management data to form the system security management data of the target computer room and the target network security system, and then transmits it to the risk assessment and analysis module.
6. The system according to claim 2, characterized in that, The network security module accesses the target network platform through the target server; The fire extinguisher is connected to the alarm. When the alarm sounds, the switch of the fire extinguisher is activated simultaneously.
7. The system according to claim 1, characterized in that, The management security module includes a system construction management module, a network security management module, a personnel security management module, and a system maintenance management module; The system construction and management module is responsible for building and managing the system management rules for the target computer room and the target network security system, and transmitting them to the management security module; The network security management module is responsible for building and managing the network security management system of the target computer room and the target network security system, and transmitting it to the management security module; The personnel security management module is responsible for building and managing the personnel security management system of the target computer room and the target network security system, and transmitting it to the management security module; The system maintenance and management module is responsible for building and managing the maintenance and management system of the target computer room and the target network security system, and transmitting it to the management security module.
8. The system according to claim 1, characterized in that, The system also includes an early warning module and several key information infrastructure devices. The early warning module and each key information infrastructure device are connected, and the early warning module is connected to the risk assessment and analysis module. The early warning module includes a storage module. Each server hosting each key information infrastructure device is configured with a corresponding data cloud. Each data cloud has a corresponding backup cloud. Each data cloud and its corresponding backup cloud are connected via a virtual signal. The data cloud is responsible for transmitting the first target data from the target database to the early warning module, encrypting it twice, analyzing it, and then backing it up to its corresponding backup cloud and the storage module. The early warning module integrates and analyzes the relevant data of each of the key information infrastructure devices and issues an early warning, and synchronizes the early warning information to the risk assessment and analysis module.
9. The system according to claim 8, characterized in that, The early warning module further includes a display module, an alarm module, a data analysis module, and a data encryption module. The storage module is connected to the data analysis module. The data analysis module includes a decompression module, a calculation module, and a filtering analysis module. The data encryption module includes a first encryption module and a second encryption module. The first encryption module is linked to the second encryption module, and the encryption algorithm of the first encryption module is different from the encryption mode of the second encryption module. Based on this, the process by which the data cloud transmits the first target data of the target database to the early warning module for double encryption, analysis, and backup to the corresponding backup cloud and storage module includes: The data cloud transmits the first target data of the target database to the decompression module; The decompression module parses the first target data to obtain first data and transmits it to the calculation module; The calculation module receives and calculates the first data to obtain the second data and transmits it to the filtering and analysis module; The filtering and analysis module receives and filters the second data to obtain the third data and transmits it to the data cloud. It also reports the data in the third data that exceeds the preset warning value to the alarm module and the display module. The warning module issues a data warning, and the display module displays the warning information and corresponding data from the warning module. The data cloud transmits the third data to the first encryption module; The first encryption module receives and encrypts the third data for the first time to obtain the fourth data, which is then transmitted to the second encryption module. The second encryption module is responsible for encrypting the fourth data, obtaining the fifth data, and then transmitting it to the data cloud. The data cloud then backs up the fifth data to the backup cloud and the storage module.
10. A method for assessing and analyzing network security risks, characterized in that, The method includes: Establish an access control system for the target computer room, and implement access control management for the target computer room in accordance with the access control system. Based on the access control management system of the target computer room, collect and record the access control management data and real-time monitoring data of the target computer room to determine the physical security data of the target computer room; Obtain network security data of the target computer room and its corresponding target network security system; Establish and manage the system management system, network security management system, personnel security management system, and maintenance management system for the target computer room and the target network security system; Based on the system management system, network security management system, personnel security management system, and maintenance management system of the target computer room and the target network security system, record and collect the system management system, network security management system, personnel security management system, and maintenance management system of the target computer room and the target network security system, and form system management security data of the target computer room and the target network security system; Real-time analysis of various security data of the target computer room and the target network security system; assessment of the security risks existing in the target computer room; and issuance of early warnings based on preset early warning conditions and the security risk assessment results of the target computer room. The target data in the target database is encrypted twice before analysis, backup, and storage.
11. A network security risk assessment and analysis device, characterized in that, include: One or more processors, and a memory; the memory stores computer-readable instructions that, when executed by the one or more processors, implement the steps of the network security risk assessment and analysis method as described in claim 10.
12. A readable storage medium, characterized in that: The readable storage medium stores computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of the network security risk assessment and analysis method as described in claim 10.