Method, device, storage medium and electronic equipment for evaluating asset risk value

By calculating the sum of the loss value and probability value of a security incident, and combining the risk value range table with user input, the problem of inaccurate IT asset risk assessment in existing technologies is solved, enabling rapid and accurate risk assessment, adapting to situations where data is missing, and improving the efficiency of system security analysis.

CN114186861BActive Publication Date: 2025-11-04QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111521032.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-13
Publication Date
2025-11-04
Estimated Expiration
2041-12-13

AI Technical Summary

Technical Problem

The lack of a unified IT asset risk assessment model and algorithm in existing technologies makes it difficult to quickly and accurately assess IT asset risks in information security, and to quickly identify the asset risks that require the most attention in the system.

Method used

The risk value of a single asset is determined by calculating the sum of the loss value and the probability value of a security incident. By utilizing a risk value interval table and a level mapping rule, combined with the asset value and vulnerability level input by the user, a new risk assessment method and apparatus is provided, which is suitable for risk calculation in the case of missing data.

Benefits of technology

It improves the universality and accuracy of IT asset risk assessment, and can still effectively calculate risk values ​​even when data is incomplete, helping security operations personnel to quickly understand the system security status and identify high-risk assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114186861B_ABST
    Figure CN114186861B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method and device for evaluating asset risk value, a storage medium and an electronic device, the method comprising: obtaining a security event loss value of any asset; obtaining a security event occurrence possibility value of the any asset; and obtaining a risk value of the any asset according to at least one of the security event loss value and the security event occurrence possibility value. Compared with the prior art which determines a single asset risk value according to the product of the security event loss value and the security event occurrence possibility value, or according to the square root of the product, embodiments of the present application can obtain a single asset risk value according to one of the two parameters, so that the single asset risk value can be obtained even in the case of missing data (for example, missing vulnerability data, only attack data; or only vulnerability data, missing attack data), thereby improving the versatility of the technical solution.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of IT asset evaluation, and in particular, the embodiments of the present application relate to a method and device for evaluating asset risk value, a storage medium and an electronic device. BACKGROUND

[0002] In 2007, the state issued GB / T 20984-2007 Information Security Technology Information Security Risk Assessment Specification, which gave the guiding ideology of enterprise IT asset risk assessment, and pointed out that risk assessment should be evaluated from the vulnerability of assets, threats, and asset value. In 2015, GB / T 31509-2015 Information Security Risk Assessment Implementation Guide was developed based on the specification, which clearly defined the operational guidance standards for information security risk assessment. However, both standards do not provide specific evaluation models and algorithms, so the current information security IT asset risk assessment generally uses algorithms owned by each manufacturer, without uniform regulations.

[0003] Therefore, how to quickly and accurately provide information security IT asset risk calculation and analysis to help users quickly locate the most concerned asset risk in the information system has become a technical problem to be solved. SUMMARY

[0004] The purpose of the embodiments of the present application is to provide a method and device for evaluating asset risk value, a storage medium and an electronic device. The risk evaluation method of IT assets and asset groups provided by some embodiments of the present application realizes different dimension correlation analysis of the current system risk profile, facilitates security and operation personnel to quickly understand the current system asset security status, identifies high-risk assets and asset groups, and provides basic data for higher-level data statistical analysis.

[0005] In a first aspect, the embodiments of the present application provide a method for evaluating asset risk value, the method comprising: obtaining a security event loss value of any asset; obtaining a security event occurrence probability value of the any asset; and obtaining a risk value of the any asset according to at least one of the security event loss value and the security event occurrence probability value.

[0006] Compared with the technical solution of determining the risk value of a single asset according to the product of the security event loss value and the security event occurrence probability value and the square root of the product in the related art, some embodiments of the present application obtain the risk value of a single asset by summing the two parameters, so that the risk value of the single asset can still be obtained in the case of missing data (for example, missing vulnerability data, only attack data; or only vulnerability data, missing attack data), improving the universality of the technical solution.

[0007] In some embodiments, the risk value of the any asset is obtained according to at least one of the security event loss value and the security event occurrence possibility value, comprising: calculating a sum of the security event loss value and the security event occurrence possibility value to obtain the risk value of the any asset.

[0008] In some embodiments, the security event loss value of the any asset is obtained, comprising: obtaining an asset value of the any asset; obtaining a highest vulnerability level of the any asset, wherein the highest vulnerability level is a highest level selected from all vulnerability levels corresponding to the any asset; querying a risk value interval table according to the asset value and the highest vulnerability level to obtain the security event loss value; wherein the risk value interval table is obtained according to the principle that the higher the vulnerability level and the greater the asset value, the greater the risk value.

[0009] Some embodiments of the present application construct a risk value interval table according to the design idea of the risk value interval table, and then obtain the security event loss value and the possibility value range by the table lookup method, which improves the speed of obtaining the security event loss value and limits the risk range of assets of a certain level and vulnerabilities of a certain level.

[0010] In some embodiments, the security event loss value is obtained according to the asset value and the highest vulnerability level by querying the risk value interval table, comprising: according to the asset value and the highest vulnerability level, searching the risk value interval table to obtain a target risk value interval corresponding to the any asset; taking a minimum value of the target risk value interval as the security event loss value.

[0011] Some embodiments of the present application take the minimum value of the target risk value interval corresponding to the any asset on the risk value interval table as the security event loss value, which can determine a more accurate initial value for the risk value of the asset.

[0012] In some embodiments, the asset value of the any asset is determined by receiving input data of a user, wherein the input data is evaluated by the user according to the importance of a business running on the any asset.

[0013] Some embodiments of the present application determine the asset value by the evaluation of the user, which improves the universality of the technical solution.

[0014] In some embodiments, the highest vulnerability level of the any asset is obtained, comprising: obtaining unprocessed vulnerability information corresponding to the any asset; determining a plurality of vulnerability levels corresponding to the any asset according to the vulnerability information and a preset level mapping rule; selecting a highest level from the plurality of vulnerability levels as the highest vulnerability level.

[0015] Some embodiments of the present application provide a method for determining the highest vulnerability level of a single asset, so that the acquisition criteria of the highest vulnerability level is more unified, and the universality of the solution is improved.

[0016] In some embodiments, the vulnerability information includes scores corresponding to each piece of vulnerability, and the preset level mapping rule is a correspondence between a plurality of levels from low to high and the scores; wherein, the determining of the plurality of vulnerability levels corresponding to the any asset according to the vulnerability information and the preset level mapping rule includes: obtaining vulnerability levels corresponding to each piece of vulnerability respectively according to the scores corresponding to each piece of vulnerability and the preset level mapping rule.

[0017] Some embodiments of the present application provide a method for determining the vulnerability level corresponding to each vulnerability.

[0018] In some embodiments, the obtaining of the security event occurrence likelihood value of the any asset includes: obtaining a target risk value interval of the any asset; and obtaining the security event occurrence likelihood value according to the target risk value interval, a vulnerability occurrence weighting value and an alarm occurrence weighting value.

[0019] The security event occurrence likelihood value of some embodiments of the present application is related to at least one of the vulnerability occurrence weighting value and the alarm occurrence weighting value, so that the universality of the technical solution is stronger.

[0020] In some embodiments, the obtaining of the security event occurrence likelihood value according to the target risk value interval, the vulnerability occurrence weighting value and the alarm occurrence weighting value includes: obtaining the security event occurrence likelihood value by solving the sum of the vulnerability occurrence weighting value and the alarm occurrence weighting value.

[0021] The security event occurrence likelihood value of some embodiments of the present application is equal to the sum of the vulnerability occurrence weighting value and the alarm occurrence weighting value, so that the estimation of the security event occurrence likelihood value is more accurate and comprehensive.

[0022] In some embodiments, the vulnerability occurrence weighting value is obtained by: obtaining unprocessed vulnerability information corresponding to the any asset, wherein the vulnerability information includes a plurality of vulnerabilities; obtaining vulnerability levels corresponding to each piece of vulnerability respectively, and counting the number of vulnerabilities included in each vulnerability level, wherein the vulnerability level is obtained by a preset level mapping rule; and determining the vulnerability occurrence weighting value according to the level values of each vulnerability level and the number of vulnerabilities of each vulnerability level.

[0023] Some embodiments of the present application provide a method for quantifying a vulnerability occurrence weighting value, so that the obtained vulnerability weighting value is more accurate and objective.

[0024] In some embodiments, the alarm occurrence weighting value is obtained by: obtaining unprocessed alarm information corresponding to the any asset, wherein the alarm information comprises a plurality of alarms; obtaining alarm levels corresponding to the respective alarms, and counting the number of alarms included in each alarm level, wherein the alarm level is obtained by a preset level mapping rule; determining the alarm occurrence weighting value according to the level values of the respective alarm levels and the number of alarms of the respective alarms.

[0025] Some embodiments of the present application provide a method for quantifying an alarm occurrence weighting value, so that the obtained alarm occurrence weighting value is more accurate and objective.

[0026] In some embodiments, the obtaining of the risk interval of the any asset comprises: obtaining an asset value of the any asset; obtaining a highest vulnerability level of the any asset, wherein the highest vulnerability level is the highest level selected from all vulnerability levels corresponding to the any asset; and obtaining the target risk value interval from a risk value interval table according to the asset value and the highest vulnerability level. The obtaining of the security event occurrence likelihood value according to the target risk value interval, a vulnerability occurrence weighting value and an alarm occurrence weighting value comprises: obtaining the extreme value of the security event occurrence likelihood value of the any asset according to the upper limit value and the lower limit value of the target risk value interval; and obtaining the security event occurrence likelihood value according to the extreme value, the vulnerability occurrence weighting value and the alarm occurrence weighting value.

[0027] In some embodiments, the security event occurrence likelihood value is determined by the following formula:

[0028] F possiblity =Vv+Va

[0029]

[0030]

[0031] wherein F possiblity represents the security event occurrence likelihood value, Vv represents the vulnerability occurrence weighting value, Va represents the alarm occurrence weighting value, num1 n represents the number of vulnerabilities corresponding to the level value n of the vulnerability level, and num2 iThe number of alarms corresponding to the level value i representing the alarm level, K1 and K2 are curve adjustment parameters, S is the extreme value (i.e. interval difference), and X is the proportion of vulnerability data in the security event occurrence probability value.

[0032] In some embodiments, the method further comprises: obtaining risk values of L assets by repeatedly performing the method of obtaining a risk value of any asset, wherein L is an integer greater than or equal to 0, and one asset corresponds to one risk value; taking the maximum value of the L risk values as a risk initial value of an asset group; obtaining weight values of the L assets, and obtaining an adjustment value according to at least the weight values; and obtaining a risk value of the asset group composed of the L assets according to the risk initial value and the adjustment value.

[0033] Some embodiments of the present application determine a risk value of an asset group composed of multiple assets through a risk initial value and an adjustment value, thereby improving the accuracy of the obtained risk value of the asset group.

[0034] In some embodiments, the obtaining of the weight values of the L assets and the obtaining of an adjustment value according to at least the weight values comprise: searching the asset group mapping table according to the risk values of the L assets to obtain a mapping result, wherein the mapping result comprises multiple risk levels corresponding to all assets and the number of assets included in each risk level; obtaining a highest risk level according to the mapping result; searching the asset group mapping table according to the highest risk level to obtain an asset group risk range; obtaining an adjustment parameter value according to the upper limit value and the lower limit value of the asset group risk range; and obtaining the adjustment value according to at least the number of assets, the weight values, and the adjustment parameter value.

[0035] In some embodiments, the obtaining of the weight values of the assets comprises: searching the asset group mapping table according to the risk values of the L assets to obtain the weight values of the assets, wherein the asset group mapping table comprises multiple risk levels, risk value ranges corresponding to each level in the multiple risk levels, and weight values corresponding to each risk value range.

[0036] In some embodiments of the present application, the weight values of the assets are obtained by searching a mapping table, thereby improving the speed of data processing.

[0037] In some embodiments, the risk value of the asset group is obtained by the following formula:

[0038]

[0039] wherein F group-risk The risk value of the asset group, r represents the risk initial value, n is the weight value of the asset, and num3 ncharacterizing the number of assets with weight value n, S1 represents the adjustment parameter value, k is a curve adjustment parameter, for the adjustment value.

[0040] Some embodiments of the present application provide a formula for calculating the risk value of an asset group, so that the obtained risk value of the asset group is more objective and accurate.

[0041] In a second aspect, some embodiments of the present application provide a device for evaluating the risk value of an asset, the method comprising: a security event loss value acquisition module configured to acquire the security event loss value of any asset; a security event occurrence possibility value acquisition module configured to acquire the security event occurrence possibility value of the any asset; and an any asset risk value acquisition module configured to obtain the risk value of the any asset according to at least one of the security event loss value and the security event occurrence possibility value.

[0042] In a third aspect, some embodiments of the present application provide a computer readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, can implement the method of any embodiment of the first aspect.

[0043] In a fourth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor, when executing the program, can implement the method of any embodiment of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0045] Figure 1 The system composition schematic diagram for evaluating the risk value of an asset provided by the embodiments of the present application;

[0046] Figure 2 One of the flowcharts of the method for evaluating the risk value of an asset provided by the embodiments of the present application;

[0047] Figure 3 The second flowchart of the method for evaluating the risk value of an asset provided by the embodiments of the present application;

[0048] Figure 4 The composition block diagram of the device for evaluating the risk value of an asset provided by the embodiments of the present application;

[0049] Figure 5 A schematic diagram of an electronic device according to an embodiment of the present application is provided. DETAILED DESCRIPTION

[0050] The technical solutions in the embodiments of the present application will be described below with reference to the drawings.

[0051] It should be noted that similar reference numerals and letters refer to like items in the following drawings, and therefore, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings. Meanwhile, in the description of the present application, the terms "first", "second", and the like are merely used to distinguish description, and cannot be understood as indicating or implying relative importance.

[0052] At least to achieve the technical problems described in the background section, in some embodiments of the present application, the risk status of assets and asset groups in a system is evaluated based on the vulnerability information (related to vulnerability information), alerts, and asset information of the assets in the system, according to a built-in computing model of the system, so that system operation personnel and security experts can quickly understand the current asset security profile, security risk trend, and targeted operation and disposal of high-risk assets and asset groups in the system.

[0053] Please refer to Figure 1 , Figure 1 The system for evaluating asset risk values provided in some embodiments of the present application includes a plurality of terminal devices (for example, a first terminal device 101, a second terminal device 102, and a third terminal device 103) and a server 104. Figure 1 The terminal devices in the system are devices that need to be evaluated, Figure 1 The server 104 in the system can receive the alert information and vulnerability information (or referred to as vulnerability information) of the terminal devices through a network and obtain the risk values of the terminal devices (corresponding to the risk values of single assets) and the risk values of asset groups composed of the plurality of terminal devices according to the information. Figure 1 It can be understood that the alert information of the terminal devices can be alert information from a firewall or alert information detected by security software (for example, 360, etc.) installed on the terminal devices, and the embodiments of the present application do not limit the way in which the terminal devices obtain the alert information.

[0054] For example, in some embodiments of the present application,

[0055] The vulnerability information of the terminal devices in the system can be obtained by means of a scanner, and the embodiments of the present application do not limit the way in which the terminal devices obtain the vulnerability information. Figure 1

[0056] ​It should be noted that in some embodiments of the present application, the risk value of each terminal device can also be determined by the terminal device itself according to the alarm information and vulnerability information of the terminal device itself, and then the terminal device can send the risk value of the single asset calculated by the terminal device itself to the server 104, and the server 104 can finally determine the risk value of the asset group.

[0057] The implementation process of each step will be exemplarily described below. Figure 2 The method for evaluating the risk value of an asset is exemplarily described by Figure 1 the server or by Figure 1 each terminal of the server.

[0058] As shown in Figure 2 , the embodiments of the present application provide a method for evaluating the risk value of an asset, which comprises: S101, obtaining a security event loss value of any asset; S102, obtaining a security event occurrence possibility value of the asset; and S103, obtaining a risk value of the asset according to at least one of the security event loss value and the security event occurrence possibility value.

[0059] It can be understood that, compared with the technical solution of the related art for determining the risk value of a single asset according to the product of the security event loss value and the security event occurrence possibility value, the embodiments of the present application obtain the risk value of a single asset by summing the two parameters, so that the risk value of the single asset can still be obtained in the case of missing data (for example, missing vulnerability data, only attack data; or only vulnerability data, missing attack data), and the versatility of the technical solution is improved.

[0060] It should be noted that in some embodiments of the present application, the risk value of an asset group also needs to be obtained, and therefore in some embodiments of the present application, the method for evaluating the risk value of an asset also comprises: obtaining the risk values of L assets by repeatedly executing the method for obtaining the risk value of any asset as shown in Figure 2 , wherein L is an integer greater than or equal to zero, one asset corresponds to one risk value; taking the maximum value of the L risk values as an asset group risk initial value; obtaining a weight value of each asset in the L assets, and obtaining an adjustment value according to at least the weight value; obtaining the risk value of an asset group composed of the L assets according to the risk initial value and the adjustment value. The embodiments of the present application determine the risk value of an asset group composed of multiple assets by using an initial value and an adjustment value, and the accuracy of the obtained risk value of the asset group is improved.

[0061] The implementation process of each step will be exemplarily described below.

[0062] At least to improve the speed of obtaining the security event loss value, in some embodiments of the present application, S101 exemplarily comprises: obtaining an asset value of the any asset; obtaining a highest vulnerability level of the any asset; obtaining the security event loss value according to the asset value and the highest vulnerability level by querying a risk value interval table; wherein the risk value interval table is obtained according to the principle that the higher the vulnerability level and the greater the asset value, the greater the risk value. For example, the obtaining the security event loss value according to the asset value and the highest vulnerability level by querying the risk value interval table comprises: according to the asset value and the highest vulnerability level, searching the risk value interval table to obtain a target risk value interval corresponding to the any asset; taking the minimum value of the target risk value interval as the security event loss value. Some embodiments of the present application directly determine the asset risk range by table lookup, so that the relationship between the risk value range and the asset level and the vulnerability level is intuitive, clear and easy to understand.

[0063] For example, taking a single asset, i.e., a first asset, as an example to illustrate the process of obtaining a target risk value interval. In some embodiments of the present application, the risk value interval table comprises N levels of vulnerability levels and M levels of asset values; wherein the obtaining the security event loss value according to the asset value and the highest vulnerability threat level by querying the risk value interval table comprises: according to the obtained asset value of the first asset (i.e., a specific numerical value), determining the asset level to which the asset value corresponding to the first asset belongs from the M levels of asset values; according to the highest vulnerability level of the first asset, determining the vulnerability level to which the asset belongs from the N levels; and taking the minimum value of the risk value interval corresponding to the asset level and the vulnerability level of the first asset on the risk value interval table as the security event loss value.

[0064] The principle of obtaining the risk value interval table is briefly described below and a specific example of the risk value interval table is provided.

[0065] It can be understood that, similar to the "wooden bucket effect", the most serious vulnerability of the asset determines the maximum loss after the asset is successfully attacked. Therefore, a certain asset value, under a certain level of vulnerability, the risk range is predictable and clear. Therefore, the most serious vulnerability data determines the range of its minimum and maximum values. Because some embodiments of the present application need to consider the impact of the number of vulnerabilities (i.e., the number of vulnerabilities) and their corresponding levels, the number of threats (i.e., the number of alarms) and their corresponding levels on the overall risk value, the higher the vulnerability level and the higher the asset value, the greater the risk value. When the asset value is certain and the highest vulnerability level is certain, the risk range of the asset is determined, and the risk value range corresponding to various combinations of the two is determined and intuitive. The overall asset risk formula: In addition to the interval characteristics, it also reflects that the more the number of vulnerabilities or alarms and the higher the level, the greater the risk value, but it cannot be unlimitedly large because the loss has an upper limit, and the upper limit depends on the severity of the vulnerability.

[0066] According to the design principles of the above risk value interval table, an example is provided in Table 1 as follows. It should be noted that Table 1 below is only used to illustrate the value of the risk value interval, and it can be understood that those skilled in the art can design a risk value interval table according to the design principles of the provided risk value interval table and in combination with actual requirements to meet their own goals.

[0067] Table 1 Risk value interval table

[0068]

[0069] It can be understood that in Table 1, five levels of vulnerability levels (i.e., the vulnerability levels of the assets in Table 1 include: no vulnerability, low risk, medium risk, high risk, and crisis) and five levels of asset values (i.e., the five levels of asset values in the left column of Table 1 are value 1, value 2, value 3, value 4, and value 5), each level of vulnerability level corresponds to a risk value interval (i.e., an interval defined by a minimum value and a maximum value) in the risk value interval table of Table 1, and one level of asset value corresponds to all five levels of vulnerability in the risk value interval table of Table 1 (for example, the asset value of 1 corresponds to the vulnerability levels of no vulnerability, low risk, medium risk, high risk, and crisis, respectively, and the asset value of 2 also corresponds to the vulnerability levels of no vulnerability, low risk, medium risk, high risk, and crisis, respectively); wherein the process of obtaining the security event loss value according to the asset value and the highest vulnerability level in S101 is exemplarily includes: determining the asset level of the asset as the 3rd according to the asset value (for example, the asset value of the asset is value 3) from the five levels of asset values; determining the vulnerability level of the asset according to the highest vulnerability threat level that the asset can suffer (for example, the highest vulnerability threat level that the asset can suffer is medium risk) from the five levels of vulnerability threat levels in Table 1, which corresponds to the two columns of medium risk vulnerability; in Table 1, the minimum value (i.e., 0 in Table 1) of the target risk value interval corresponding to the vulnerability threat level of the asset (i.e., the two columns of data corresponding to medium risk vulnerability) is taken as the security event loss value of the asset in the row (i.e., the 3rd row) where the asset level of the asset is located.

[0070] It should be noted that in some embodiments of the present application, the security event loss value f loss In relation to the highest level of vulnerability and business importance, for example, the more important the business, the greater the value of the asset corresponding to the business. In some embodiments of the present application, the security event loss value can be obtained according to the asset value and the highest vulnerability threat level, by querying Table 1 to obtain the target risk value interval corresponding to an asset, and then taking the minimum value included in the target risk value interval as the security event loss value of the asset. For example, if the asset value of a single asset is 1 and the highest threat is high risk, by querying Table 1, it can be known that the security event loss value f loss is 10.

[0071] The process of obtaining the asset value in Table 1 is exemplarily described below.

[0072] The asset value is evaluated as follows: in the standard mode, the asset value is defined by the following three attributes: confidentiality, integrity, and availability. In the advanced mode, the asset value is defined by the following seven attributes: confidentiality, integrity, availability, type, importance, impact degree, and impact range.

[0073] It can be understood that the asset value in the risk assessment is not measured by the economic value of the asset, but is determined by the achievement degree of the asset in the security attributes or the impact degree when the security attributes of the asset are not achieved, and the importance of the asset after being associated with the business. Different achievement degrees of the security attributes will make the asset have different values, different importance of the business will make the asset have different importance, and the threats faced by the asset, the vulnerabilities existing in the asset, and the security measures adopted will all have an impact on the achievement degree of the asset security attributes and the security degree of the business carried on the asset.

[0074] In order to improve the accuracy of obtaining the asset value and find a more accurate security event loss value through the risk value interval table, in some embodiments of the present application, S101 involves obtaining the asset value of the any asset, which exemplarily includes: determining the asset value of the any asset according to at least one of the achievement degree of a plurality of security attributes on the any asset and the importance of the business running on the any asset. Some embodiments of the present application determine the asset value by considering the achievement degree of the security attributes and / or the importance of the business running on the asset, so that the asset value obtained is more accurate and objective.

[0075] In some embodiments of the present application, the asset value of the any asset is determined by receiving input data of a user, wherein the input data is evaluated by the user according to the importance of the business running on the any asset.

[0076] In order to obtain the highest vulnerability level, it is necessary to confirm the highest vulnerability level (or level) statistically obtained on a certain asset and find a target risk value interval based on the highest vulnerability level from the risk value interval table. For example, in some embodiments of the present application, S101 involves obtaining the highest vulnerability threat level of the any asset, which exemplarily includes: obtaining unprocessed vulnerability information corresponding to the any asset; determining a plurality of vulnerability levels corresponding to the any asset according to the vulnerability information and a preset level mapping rule; and selecting the highest level from the plurality of vulnerability levels as the highest vulnerability level.

[0077] It can be understood that in order to obtain the highest vulnerability level, all vulnerability levels corresponding to the single asset need to be obtained, for example, in some embodiments of the present application, the vulnerability information includes scores corresponding to each vulnerability, and the preset level mapping rule is a correspondence between a plurality of levels from low to high and scores; wherein, the plurality of vulnerability levels corresponding to the single asset are determined according to the vulnerability information and the preset level mapping rule, which includes: obtaining the vulnerability levels corresponding to each vulnerability respectively according to the scores corresponding to each vulnerability and the preset level mapping rule.

[0078] The process of determining the security event loss value of any asset is described below in conjunction with two examples. Specifically, the process of determining the highest vulnerability level and obtaining the security event loss value is described below in conjunction with two asset examples.

[0079] Suppose the preset level mapping rule is: if the score of a vulnerability or an alert is 1 or 2, then the vulnerability level or the alert level corresponding to the vulnerability or the alert is low risk; if the score of a vulnerability or an alert is 3 or 4, then the vulnerability level or the alert level corresponding to the vulnerability or the alert is medium risk; if the score of a vulnerability or an alert is 5 to 7, then the vulnerability level or the alert level corresponding to the vulnerability or the alert is high risk; and if the score of a vulnerability or an alert is 8 to 10, then the vulnerability level or the alert level corresponding to the vulnerability or the alert is critical.

[0080] Example 1

[0081] First asset: 10.65.100.1 (represented by an IP address as a single asset)

[0082] Asset value of the first asset: 1 (corresponding to the row of asset value 1 in Table 1)

[0083] All unprocessed vulnerability information obtained by detecting the first asset using a scanner includes one vulnerability with a vulnerability score of 9 and one vulnerability with a vulnerability score of 4. After mapping each vulnerability according to the preset level mapping, it is determined that the vulnerability level corresponding to the vulnerability with a score of 9 is critical, and the vulnerability level corresponding to the vulnerability with a score of 4 is medium.

[0084] All unprocessed alert information obtained for the first asset includes one alert with an alert score of 9 and one alert with an alert score of 1. After mapping each alert according to the preset level mapping, it is determined that the alert level corresponding to the alert with a score of 9 is critical, and the alert level corresponding to the alert with a score of 1 is low.

[0085] Therefore, the highest vulnerability level corresponding to the first asset is confirmed to be critical by counting all the alarm levels and vulnerability levels on the first asset, so when confirming the security event loss value of the first asset by referring to Table 1, the column in which the asset value is 1 (i.e. the asset value of the target level is 1) and the vulnerability level is critical (i.e. the vulnerability threat level of the target level is critical) should be selected, and since the security event loss value of each asset is the minimum value of the interval corresponding to the corresponding level (critical in this example), the security event loss value corresponding to the first asset is confirmed to be 20 by referring to Table 1.

[0086] Example Two

[0087] Second asset: 10.65.100.3 (a single asset represented by an IP address)

[0088] Asset value of the second asset: 5 points (corresponding to the row in which the asset value is 5 in Table 1)

[0089] All the unprocessed vulnerability information obtained by detecting the second asset by using the scanner includes one vulnerability with a vulnerability score of 4 and one vulnerability with a vulnerability score of 1. After mapping each vulnerability according to the preset level mapping, it is determined that the vulnerability level corresponding to the vulnerability with a score of 4 is medium, and the vulnerability level corresponding to the vulnerability with a score of 1 is low.

[0090] All the unprocessed alarm information obtained for the second asset includes one alarm with an alarm score of 1. After mapping the alarm according to the preset level mapping, it is determined that the alarm level corresponding to the alarm with a score of 1 is low.

[0091] Therefore, the highest vulnerability threat level corresponding to the second asset is confirmed to be medium by counting all the alarm levels and vulnerability levels on the second asset, so when confirming the security event loss value of the second asset by referring to Table 1, the column in which the asset value is 5 and the vulnerability level is medium should be selected, and since the security event loss value of each asset is the minimum value of the interval corresponding to the highest vulnerability threat level, the security event loss value corresponding to the second asset is confirmed to be 30 by referring to Table 1.

[0092] The process of obtaining the security event occurrence probability in S102 is described below.

[0093] In some embodiments of the present application, the process of obtaining the security event occurrence possibility value of the any asset in S102 exemplarily comprises: obtaining a target risk value interval of the any asset (the target risk value interval can refer to the example of obtaining the interval above); obtaining the security event occurrence possibility value according to the target risk value interval, the vulnerability occurrence weighted value and the alarm occurrence weighted value. That is, in some embodiments of the present application, the security event occurrence possibility value is related to the vulnerability occurrence weighted value and the alarm occurrence weighted value.

[0094] For example, in some embodiments of the present application, S102 exemplarily comprises: obtaining the security event occurrence possibility value by solving the sum of the vulnerability occurrence weighted value and the alarm occurrence weighted value.

[0095] In order to obtain the vulnerability occurrence weighted value, in some embodiments of the present application, the vulnerability occurrence weighted value in S102 is obtained by the following method: obtaining unprocessed vulnerability information corresponding to the any asset, wherein the vulnerability information comprises a plurality of vulnerabilities; obtaining vulnerability grades corresponding to the respective vulnerabilities, and counting the number of vulnerabilities included in each vulnerability grade; determining the vulnerability occurrence weighted value according to the grade value of each vulnerability grade and the number of vulnerabilities of each vulnerability grade.

[0096] In order to obtain the alarm occurrence weighted value, in some embodiments of the present application, the alarm occurrence weighted value in S102 is obtained by the following method: obtaining unprocessed alarm information corresponding to the any asset, wherein the alarm information comprises a plurality of alarms; obtaining alarm grades corresponding to the respective alarms, and counting the number of alarms included in each alarm grade; determining the alarm occurrence weighted value according to the grade value of each alarm grade and the number of alarms of each alarm grade.

[0097] In some embodiments, the acquiring the target risk value interval of the any asset comprises: acquiring an asset value of the any asset; acquiring a highest vulnerability level of the any asset, wherein the highest vulnerability level is a highest level selected from all vulnerability levels corresponding to the any asset; and querying a risk value interval table according to the asset value and the highest vulnerability level to obtain the target risk value interval, wherein the risk value interval table corresponds to an interval range of the highest vulnerability level of the any asset, and the interval range is the target risk value interval. The acquiring the security event occurrence probability value according to the target risk value interval, a vulnerability occurrence weighted value, and an alarm occurrence weighted value comprises: acquiring a maximum value of the security event occurrence probability value of the any asset according to an upper limit value and a lower limit value of the risk interval (for example, the maximum value is obtained by subtracting the lower limit value from the upper limit value); and acquiring the security event occurrence probability value according to the maximum value, the vulnerability occurrence weighted value, and the alarm occurrence weighted value.

[0098] For example, in some embodiments of the present application, the security event occurrence probability value is calculated according to the maximum value, the vulnerability occurrence weighted value, and the alarm occurrence weighted value by the following formula.

[0099] The number of vulnerability events of each level (or each grade) of the asset i is as follows: num11, num12, num13, num14, num15, num16, num17, num18, num19, num1 10 The number of alarm events of each level (or each grade) of the asset i is as follows: num21, num22, num23, num24, num25, num26, num27, num28, num29, num2 10 The security event occurrence probability value is calculated as follows:

[0100] F possiblity = Vv + Va

[0101]

[0102]

[0103] wherein F possiblity represents the security event occurrence probability value, Vv represents the vulnerability occurrence weighted value, Va represents the alarm occurrence weighted value, num1 n represents the number of vulnerabilities corresponding to the level number n of the vulnerability level, num2 inum1 = K1 * S + K2 * X * i, i = 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, wherein num1 represents the number of alerts corresponding to the level value i representing the alert level, K1 and K2 are curve adjustment parameters, S is the maximum value, and X is the proportion of vulnerability data in the security event occurrence probability value. That is, num1 = K1 * S + K2 * X * i, i = 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, wherein num1 represents the number of alerts corresponding to the level value i representing the alert level, K1 and K2 are curve adjustment parameters, S is the maximum value, and X is the proportion of vulnerability data in the security event occurrence probability value. n num2 = K1 * S + K2 * X * i, i = 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, wherein num2 represents the total number of alert entries of each level. For example, K1 and K2 are 600 by default. For example, X is the proportion of vulnerability data in the security event occurrence probability value, which is 0.5 by default. It should be noted that in the above formula, only the top 50 vulnerabilities and alerts are taken into account. The risk value of some embodiments of the present application can also be adjusted by multiple parameters, for example, the proportion of vulnerability and threat contribution to the risk value through the X parameter. i num2 = K1 * S + K2 * X * i, i = 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, wherein num2 represents the total number of alert entries of each level. For example, K1 and K2 are 600 by default. For example, X is the proportion of vulnerability data in the security event occurrence probability value, which is 0.5 by default. It should be noted that in the above formula, only the top 50 vulnerabilities and alerts are taken into account. The risk value of some embodiments of the present application can also be adjusted by multiple parameters, for example, the proportion of vulnerability and threat contribution to the risk value through the X parameter.

[0104] It can be understood that after obtaining the risk values of individual assets, the asset group risk value of an asset group composed of multiple assets can be solved based on the risk values. For example, in some embodiments of the present application, the risk values of L assets are obtained by repeatedly executing the method of obtaining the risk value of any asset, wherein L is an integer greater than or equal to zero, and one asset corresponds to one risk value; the maximum value of the L risk values is taken as the risk initial value of the asset group; the weight values of the assets in the L assets are obtained, and an adjustment value is obtained at least according to the weight values; and the risk value of the asset group is obtained according to the risk initial value and the adjustment value.

[0105] For example, in some embodiments of the present application, the obtaining of the weight values of the assets in the L assets and the obtaining of the adjustment value at least according to the weight values comprise: obtaining a mapping result from the asset group mapping table according to the risk values of the assets in the L assets, wherein the mapping result comprises multiple risk levels corresponding to all assets and the number of assets included in each risk level; obtaining the highest risk level according to the mapping result; obtaining the asset group risk range from the asset group mapping table according to the highest risk level; obtaining the adjustment parameter value (i.e., the value of the parameter S) according to the upper limit value and the lower limit value of the asset group risk range; and obtaining the adjustment value at least according to the number of assets, the weight values, and the adjustment parameter value.

[0106] For example, in some embodiments of the present application, the obtaining of the weight values of the assets comprises: querying the asset group mapping table by the risk values of the assets in the L assets to obtain the weight values of the assets, wherein the asset group mapping table comprises multiple risk levels, risk value ranges corresponding to each level in the multiple risk levels, and weight values corresponding to each risk value range.

[0107] The weight value of each asset can be obtained by referring to the asset group mapping table (e.g., Table 2 below) of all assets in the asset group. The asset group mapping table includes a plurality of asset risk levels, a risk value range corresponding to each asset risk level, and a weight value corresponding to each risk value range. In some embodiments of the present application, the weight value of each asset is obtained by referring to the asset group mapping table, which improves the speed of data processing.

[0108] In some embodiments of the present application, the risk value of the asset group is calculated by the following formula:

[0109]

[0110] wherein F gruop-risk represents the risk value of the asset group, r represents the initial risk value, n represents the weight value of the asset, num3 n represents the number of assets with the weight value n, S1 represents the adjustment parameter value, and k represents the curve adjustment parameter, In some embodiments, r represents the highest risk value obtained from the asset group, and S1 represents the score change range based on r. Some embodiments of the present application provide a formula for calculating the risk value of the asset group, which makes the obtained risk value of the asset group more objective and accurate. The risk value of some embodiments of the present application can also be adjusted by multiple parameters, for example, the adjustment of the risk differentiation degree on objects of different orders of magnitude (vulnerability, threat, asset) by the k parameter during calculation.

[0111] The following illustrates an example of obtaining the risk value of the asset group.

[0112] It can be understood that the calculation process of the parent group reuses the calculation results of its child groups, i.e., the risk value of the parent group is directly calculated from the risk values of its child groups. Therefore, the least calculation is performed from the leaf group to the root group (the benefit of incremental calculation decreases as the level increases). During calculation, the calculation is performed in descending order of DEPTH (group depth) because the recursive number of layers from the leaf group to the root group is different. If the calculation is not performed in descending order of DEPTH, the calculation power will be wasted in some group structures.

[0113] In some embodiments of the present application, the asset with the highest risk in the asset group determines the lower limit of the risk value of the asset group, and the number and severity level of the assets in the asset group determine the adjustment value of the risk value of the asset group.

[0114] Table 2 below is a risk level mapping table provided by some embodiments of the present application, and the following explains how to determine the risk value of an asset group in combination with this table.

[0115] Table 2 Asset Group Mapping Table

[0116] Asset risk Low risk Medium risk High risk Critical risk Score [0,20] (20,40] (40,60] (60,100] Weight mapping 1 4 7 9

[0117] The following describes the process of obtaining the risk value of a single asset and the risk value of an asset group in combination with Figure 3 and One specific examples.

[0118] First, assume the following asset data, which is represented by an IP address below to represent an asset.

[0119] Asset: 10.65.100.1

[0120] Second, the asset value of the above single asset is assigned according to the characteristics of the business running on the asset (corresponding to Figure 3 S305, i.e., obtaining asset value):

[0121] Asset: 10.65.100.1, asset value of the first asset: 1 point (such as a personal computer)

[0122] Third, assume that the following vulnerability data (i.e., vulnerability information) is obtained for the above asset, i.e., by performing Figure 3 S302 to obtain vulnerability information (or referred to as obtaining vulnerability information) to obtain the following vulnerability data:

[0123] Asset: 10.65.100.1, 10 points (score of the first vulnerability of the asset), "SQL vulnerability" (vulnerability type of the first vulnerability of the asset)

[0124] Asset: 10.65.100.1, 3 points (score of the second vulnerability of the first asset), "FTP denial of service" (vulnerability type of the second vulnerability of the asset)

[0125] Fourth, complete the score mapping according to the vulnerability score and the preset level mapping rule (i.e., corresponding to Figure 3 S304, calculate vulnerability)

[0126] Assume that some embodiments of the present application only map the score, and assume that the preset level mapping rule is as follows: 1-2 => 1 (low risk), 3-4 => 4 (medium risk), 5-7 => 7 (high risk), 8-10 => 9 (critical).

[0127] After mapping, the vulnerability levels of each vulnerability are as follows:

[0128] Asset 10.65.100.1, Critical (9), "SQL Vulnerability"

[0129] Asset 10.65.100.1, Medium (4), "FTP Denial of Service"

[0130] Step 5, collect and sort the alerts (i.e., corresponding to Figure 3 obtain the alert information of S301), assuming that there are the following alert data for the above asset:

[0131] Asset: 10.65.100.1, 10 points (score of the first alert of the asset), "SQL Injection" (alert type of the first alert of the asset)

[0132] Asset: 10.65.100.1, 2 points (score of the second alert of the asset), "Scan" (alert type of the second alert of the asset)

[0133] Step 6, complete the score mapping rule of each alert, i.e., calculate the threat score of each alert by Figure 3 S303:

[0134] Assuming that the score is mapped and the alert name is normalized, the preset mapping rule is: 1-2 => 1 (low risk), 3-4 => 4 (medium risk), 5-7 => 7 (high risk), 8-10 => 9 (critical).

[0135] In addition, some embodiments of the present application normalize the alert type and process the vulnerability data to obtain the following data:

[0136] Asset: 10.65.100.1, Critical (9), "Page Injection"

[0137] Asset: 10.65.100.1, Low Critical (1), "Illegal Scan"

[0138] Step 7, information aggregation, aggregate the information of the asset, as follows:

[0139] Asset: 10.65.100.1

[0140] Asset value: 1 point

[0141] Vulnerability:

[0142] Highest level: 9 (critical), including:

[0143] 9 (critical): 1

[0144] 7 (high risk): 0

[0145] 4 (medium risk): 1

[0146] 1 (low): 0

[0147] Alert:

[0148] Highest level: 9 (critical), in which:

[0149] 9 (critical): 1

[0150] 7 (high): 0

[0151] 4 (medium): 0

[0152] 1 (low): 1

[0153] Step 8, determine the target risk value interval of each asset by looking up Table 1, and determine the security event loss value according to the target risk value interval of each asset, and finally obtain the risk value of each asset, that is, the corresponding Figure 3 S306 calculates the risk value of a single asset.

[0154] The target risk value interval corresponding to the asset is obtained by looking up the risk value interval table (i.e. Table 1) through the asset value and the highest level vulnerability of any single asset as follows:

[0155] Asset: 10.65.100.1

[0156] Asset value: 1

[0157] Highest vulnerability (or called highest vulnerability level): 9 (critical)

[0158] Risk interval (i.e. the target risk value interval of this asset): [20-70] (obtained by looking up Table 1)

[0159] Step 9, calculate the risk value of each asset

[0160] It should be noted that the following uses asset 10.65.100.1 as an example to show the calculation method of the risk value of a single asset:

[0161] The summary of this asset is shown in Table 3 as follows:

[0162] Table 3 Information summary of assets

[0163]

[0164] In some embodiments, S103 exemplarily comprises: calculating the sum of the security event loss value and the security event occurrence possibility value to obtain the risk value of the any asset. For example, the total formula for calculating the risk value of the asset is: risk f loss +f possibility .

[0165] As before, the target risk value interval of this asset (value = 1, highest vulnerability = 9) is [20, 70] by looking up the risk zone table (i.e. Table 1) with the asset value and the highest vulnerability of this asset, then: Let fpossibilitybe the security incident occurrence possibility value of this asset. loss = the start value (or minimum value) of the target risk value interval = 20.

[0166] The security incident occurrence possibility value fpossibilityis calculated as: possibility = the upper limit value of the target risk value interval of this asset. possibility The maximum value of fpossibilityis 70 - 20 = 50, i.e. the adjustment range is 50, so the risk value Friskof this asset is between 20 and 70.

[0167] The vulnerability occurrence weighted value is calculated by weighting the vulnerability of this asset: there are only 1 vulnerability of level 4 and 1 vulnerability of level 9, then:

[0168]

[0169] Similarly, the alarm occurrence weighted value is calculated as:

[0170] The alarm is weighted: there are only 1 alarm of level 1 and 1 alarm of level 9.

[0171]

[0172] Therefore, the security incident occurrence possibility value fpossibility= vulnerability occurrence weighted value + alarm occurrence weighted value = Vv+ Va= 11.48 + 11.3 = 22.78, i.e. the asset value of this asset is 1, the highest vulnerability is critical (9), and the security incident occurrence possibility value is 22.78. Its risk value f risk = f loss + f possibility = 20 + 22.78 = 42.78.

[0173] The following exemplary describes the risk value calculation process of the asset group, i.e. performing S307 to calculate the risk value of the asset group.

[0174] Suppose there are 4 assets in an asset group, and the risk values of each single asset are 11, 12, 55 and 80 respectively.

[0175] According to Table 2 above, the weight of each asset is obtained. For example, looking up Table 2, we get:

[0176] Asset A: risk 11, weight 1 (low risk)

[0177] Asset B: risk 12, weight 1 (low risk)

[0178] Asset C: Risk 55, Weight 7 (High)

[0179] Asset D: Risk 80, Weight 9 (Critical)

[0180] Substitute the above asset group risk value calculation formula, where r is the maximum risk value of all assets in the group, i.e. 80, and the right half of the arctan calculation is the same as the asset calculation formula, and the asset group risk interval corresponds to (60, 100].

[0181] For example, the right half of the arctan of the above asset group risk value calculation formula is equal to:

[0182] arctan((1st quantity * 2 1 + 2nd quantity * 2 2 + 3rd quantity * 2 3 … 9th quantity * 2 9 + 10th quantity * 2 10 ) / k1) * 2 / π * (100-80)

[0183] = arctan((2 * 2 1 + 0 * 2 2 + 0 * 2 3 + 0 * 2 4 + 0 * 2 5 + 0 * 2 6 + 1 * 2 7 + 0 * 2 8 + 1 * 2 9 + 0 * 2 10 ) / 600) * 2 / π * 20

[0184] = arctan((4 + 0 + 0 + 0 + 0 + 0 + 128 + 0 + 512 + 0) / 600) * (2 / π) * 20

[0185] = arctan(644 / 600)

[0186] = arctan(1.073) * 12.732

[0187] = 0.821 * 12.732

[0188] = 10.45

[0189] So Fgroup_risk = 80 + 10.45 = 90.45.

[0190] Please refer to Figure 4 , Figure 4 The device for evaluating asset risk values passed by the embodiments of the present application is shown, and it should be understood that the device is the same as the above Figure 2Corresponding to the method embodiments, it can execute the various steps involved in the above method embodiments. The specific functions of the device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here. The device includes at least one software function module that can be stored in memory or embedded in the device's operating system in the form of software or firmware. The device for assessing asset risk value includes: a security event loss value acquisition module 110, a security event occurrence probability value acquisition module 120, and a risk value acquisition module 130 for any asset.

[0191] The security incident loss value acquisition module 110 is configured to acquire the security incident loss value of any asset. The security incident occurrence probability value acquisition module 120 is configured to acquire the security incident occurrence probability value of the aforementioned asset. The risk value acquisition module 130 is configured to obtain the risk value of the aforementioned asset based on at least one of the security incident loss value and the security incident occurrence probability value.

[0192] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0193] Some embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any of the embodiments corresponding to the above-described method for assessing asset risk value.

[0194] like Figure 5 As shown, some embodiments of this application provide an electronic device 500, which includes a memory 510, a processor 520, and a computer program stored in the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 via a bus 530 and executes the program, it can implement the technical solutions described in any of the embodiments corresponding to the above methods.

[0195] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.

[0196] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code used to implement some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of the embodiments of this disclosure can be used to execute the instructions in the memory 510 to implement… Figure 2The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory well known to those skilled in the art.

[0197] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other means. The apparatus embodiments described above are only illustrative, for example, the flowcharts and block diagrams in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment or a part of code, which includes one or more executable instructions for implementing the specified logic function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order from that shown in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0198] In addition, the functional modules in the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0199] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various storage media that can store program codes.

[0200] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.

[0201] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.

[0202] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another, without necessarily requiring or implying any actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.

Claims

1. A method for assessing the risk value of an asset, characterized in that, The method is used in a system for assessing asset risk values. The system includes multiple terminal devices and a server. Each terminal device is a device that needs to be assessed for its assets. The server receives alarm and vulnerability information reported by these terminal devices via a network and, based on this information, obtains the risk value of each terminal device and the risk value of an asset group composed of multiple terminal devices. The system uses a built-in calculation model to assess the current risk status of assets and asset groups within the system, including: Obtain the security incident loss value for any asset; Obtain the probability value of a security event occurring for any of the aforementioned assets; The risk value of any one asset is obtained based on the loss value of the security incident and the probability value of the security incident, and the risk value of an asset group consisting of multiple assets is calculated based on the risk values ​​of each asset. Based on the risk value of the asset group, determine the current asset security status of the system and identify high-risk assets and asset groups; The step of obtaining the risk value of any asset based on the security incident loss value and the security incident probability value includes: calculating the sum of the security incident loss value and the security incident probability value to obtain the risk value of any asset; in: The process of obtaining the security incident loss value for any asset includes: Obtain the asset value of any of the aforementioned assets; Obtain the highest vulnerability level for any of the assets, wherein the highest vulnerability level is selected from all vulnerability levels corresponding to any of the assets; The loss value of the security incident is obtained by querying the risk value range table based on the asset value and the highest vulnerability level; The risk value range table is obtained based on the following principle: the higher the vulnerability level and the greater the asset value, the greater the risk value. The process of obtaining the target risk value range for any of the assets includes: Obtain the asset value of any of the aforementioned assets; Obtain the highest vulnerability level for any of the assets, wherein the highest vulnerability level is selected from all vulnerability levels corresponding to any of the assets; The target risk value range is obtained by querying the risk value range table based on the asset value and the highest vulnerability level; The method of obtaining the probability value of the security event based on the target risk value range, the vulnerability occurrence weighted value, and the alarm occurrence weighted value includes: The maximum and minimum values ​​of the probability of a security event occurring for any asset are obtained based on the upper and lower limits of the target risk value range. The probability value of the security event is obtained based on the maximum / minimum value, the vulnerability occurrence weighted value, and the alarm occurrence weighted value. The process of obtaining the probability value of a security event occurring for any of the assets includes: Obtain the target risk value range for any of the aforementioned assets; The probability value of the security event is obtained based on the target risk value range, the vulnerability occurrence weight value, and the alarm occurrence weight value. The probability of the security event occurring is determined using the following formula: in, Characterizes the probability value of the security event occurring. The vulnerability is represented by a weighted value. The weighted value representing the occurrence of the alarm is... The number of vulnerabilities corresponding to a vulnerability level value of n. The number of alarms corresponding to the level value i, which represents the alarm level, K1 and K2 are curve adjustment parameters, S is the maximum or minimum value, and X is the proportion of vulnerability data in the probability value of a security event.

2. The method as described in claim 1, characterized in that, The step of obtaining the security incident loss value by querying the risk value range table based on the asset value and the highest vulnerability level includes: Based on the asset value and the highest vulnerability level, the target risk value range corresponding to any asset is obtained by looking up the risk value range table. The minimum value of the target risk value range is taken as the loss value of the security event.

3. The method as described in claim 1, characterized in that, The asset value of any of the assets is determined by receiving user input data, wherein the input data is obtained by the user based on the importance of the business running on the asset.

4. The method as described in claim 1, characterized in that, Obtaining the highest vulnerability level for any of the assets includes: Obtain unprocessed vulnerability information corresponding to any of the aforementioned assets; Based on the vulnerability information and preset level mapping rules, multiple vulnerability levels corresponding to any one of the assets are determined; The highest vulnerability level is selected from the plurality of vulnerability levels as the highest vulnerability level.

5. The method as described in claim 4, characterized in that, The vulnerability information includes a score corresponding to each vulnerability, and the preset level mapping rule is the correspondence between multiple levels and scores from low to high; wherein, The step of determining multiple vulnerability levels corresponding to any one of the assets based on the vulnerability information and a preset level mapping rule includes: Based on the scores corresponding to each vulnerability and the preset level mapping rules, the vulnerability levels corresponding to each vulnerability are obtained.

6. The method as described in claim 1, characterized in that, The step of obtaining the probability value of the security event based on the target risk value range, the vulnerability occurrence weighted value, and the alarm occurrence weighted value includes: solving for the sum of the vulnerability occurrence weighted value and the alarm occurrence weighted value to obtain the probability value of the security event.

7. The method as described in claim 6, characterized in that, The vulnerability weighting value is obtained through the following method: Obtain unprocessed vulnerability information corresponding to any of the assets, wherein the vulnerability information includes multiple vulnerabilities; Obtain the vulnerability level corresponding to each vulnerability, and count the number of vulnerabilities included in each vulnerability level, wherein the vulnerability level is obtained through a preset level mapping rule; The vulnerability occurrence weighting value is determined based on the level value of each vulnerability level and the number of vulnerabilities in each vulnerability level.

8. The method as described in claim 7, characterized in that, The alarm occurrence weighting value is obtained through the following method: Obtain unprocessed alarm information corresponding to any of the assets, wherein the alarm information includes multiple alarms; Obtain the alarm level corresponding to each alarm and count the number of alarms included in each alarm level, wherein the alarm level is obtained through a preset level mapping rule; The alarm occurrence weighting value is determined based on the level value of each alarm level and the number of alarms for each alarm level.

9. The method as described in claim 1, characterized in that, The method further includes: By repeatedly executing the method to obtain the risk value of any asset, L risk values ​​of assets are obtained, where L is an integer greater than or equal to 0, and one risk value corresponds to one asset; The maximum value among L risk values ​​is taken as the initial risk value for the asset group; Obtain the weight value of each asset among the L assets, and obtain an adjustment value based at least on the weight value; The risk value of the asset group is obtained based on the initial risk value and the adjustment value.

10. The method as described in claim 9, characterized in that, The step of obtaining the weight value of each asset among the L assets, and obtaining an adjustment value based at least on the weight value, includes: The mapping result is obtained by looking up the asset group mapping table based on the risk value of each of the L assets. The mapping result includes multiple risk levels corresponding to all assets and the number of assets included in each risk level. The highest risk level is obtained based on the mapping result; The risk range of the asset group is obtained by looking up the asset group mapping table based on the highest risk level. The adjustment parameter value is obtained based on the upper and lower limits of the risk range of the asset group; The adjustment value is obtained based at least on the number of assets, the weight value, and the adjustment parameter value.

11. The method as described in claim 10, characterized in that, The step of obtaining the weight value of each asset includes: querying the asset group mapping table through the risk value of each asset among the L assets to obtain the weight value of each asset, wherein the asset group mapping table includes multiple risk levels and risk value ranges corresponding to each of the multiple risk levels and weight values ​​corresponding to each risk value range.

12. The method according to any one of claims 10-11, characterized in that, The risk value of the asset group is calculated using the following formula: 1 in, The risk value of the asset group is represented by r, the initial risk value is represented by r, and the weight of the asset is n. The number of assets with a weight value of n represents the number of assets, S1 represents the adjustment parameter value, and k is the curve adjustment parameter. The adjustment value is mentioned above.

13. An apparatus for assessing the risk value of an asset, characterized in that, A system for assessing asset risk values, the system using a built-in calculation model to evaluate the current risk status of assets and asset groups within the system, the apparatus comprising: The security incident loss value acquisition module is configured to acquire the security incident loss value of any asset. The security event probability value acquisition module is configured to acquire the security event probability value of any of the assets. The risk value acquisition module for any asset is configured to obtain the risk value of any asset based on at least one of the security event loss value and the security event occurrence probability value, and to calculate the risk value of an asset group consisting of multiple assets based on the risk values ​​of each asset; and to determine the current asset security status of the system based on the risk values ​​of the asset group, and to identify high-risk assets and asset groups. The security incident probability value acquisition module is configured to calculate the sum of the security incident loss value and the security incident probability value to obtain the risk value of any asset. in: The security event loss value acquisition module is configured as follows: Obtain the asset value of any of the aforementioned assets; Obtain the highest vulnerability level for any of the assets, wherein the highest vulnerability level is selected from all vulnerability levels corresponding to any of the assets; The loss value of the security incident is obtained by querying the risk value range table based on the asset value and the highest vulnerability level; The risk value range table is obtained based on the following principle: the higher the vulnerability level and the greater the asset value, the greater the risk value. The target risk value range for obtaining any one of the assets is configured as follows: Obtain the asset value of any of the aforementioned assets; Obtain the highest vulnerability level for any of the assets, wherein the highest vulnerability level is selected from all vulnerability levels corresponding to any of the assets; The target risk value range is obtained by querying the risk value range table based on the asset value and the highest vulnerability level; The method of obtaining the probability value of the security event based on the target risk value range, the vulnerability occurrence weighted value, and the alarm occurrence weighted value includes: The maximum and minimum values ​​of the probability of a security event occurring for any asset are obtained based on the upper and lower limits of the target risk value range. The probability value of the security event is obtained based on the maximum / minimum value, the vulnerability occurrence weighted value, and the alarm occurrence weighted value. The security event probability acquisition module is configured as follows: Obtain the target risk value range for any of the aforementioned assets; The probability value of the security event is obtained based on the target risk value range, the vulnerability occurrence weight value, and the alarm occurrence weight value. The probability of the security event occurring is determined using the following formula: in, Characterizes the probability value of the security event occurring. The vulnerability is represented by a weighted value. The weighted value representing the occurrence of the alarm is... The number of vulnerabilities corresponding to a vulnerability level value of n. The number of alarms corresponding to the level value i, which represents the alarm level, K1 and K2 are curve adjustment parameters, S is the maximum or minimum value, and X is the proportion of vulnerability data in the probability value of a security event.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it can implement the method described in any one of claims 1-12.

15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it can implement the method described in any one of claims 1-12.