A scoring determination method, device, equipment and storage medium

By obtaining suppliers' supporting documents and using a neural network model to score them, the problem of inaccurate assessment of component suppliers' information security capabilities was solved, and component quality was guaranteed.

CN114881503BActive Publication Date: 2025-09-12CHINA FAW CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210554628.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-19
Publication Date
2025-09-12
Estimated Expiration
2042-05-19

AI Technical Summary

Technical Problem

In the information security development of intelligent connected vehicles, existing technologies lack effective methods to evaluate the information security capabilities of component suppliers, resulting in inaccurate component quality assessments.

Method used

By obtaining the supplier's supporting documents and using a neural network model to score, we determine the supplier's information security management capabilities, development capabilities, production capabilities, and operation and maintenance capabilities. By combining the weights to calculate the final score, we can achieve a comprehensive evaluation of the supplier.

Benefits of technology

It improves the accuracy of component supplier assessments, ensures component quality, and enhances the comprehensiveness and accuracy of information security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114881503B_ABST
    Figure CN114881503B_ABST
Patent Text Reader

Abstract

The present invention discloses a scoring determination method, apparatus, device, and storage medium. The method comprises: obtaining a corresponding certification document of a supplier to be tested; determining, based on the certification document corresponding to the supplier to be tested, the supplier's corresponding information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score; and determining a target score for the supplier to be tested based on the supplier's corresponding information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score. The technical solution of the present invention can improve the accuracy of component supplier evaluations in advance, thereby effectively ensuring component quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of vehicle technology, and more particularly to a scoring determination method, apparatus, device, and storage medium. Background Art

[0002] In the development of information security for intelligent connected vehicles, there is a lack of standardized analysis and evaluation methods to assess the information security capabilities of component suppliers before they are appointed. Furthermore, the analysis process cannot cover the entire V-model process for the development of automotive information security technology. This can easily lead to inaccurate assessments of component suppliers, leading to component quality issues. Summary of the Invention

[0003] The embodiments of the present invention provide a scoring determination method, apparatus, device, and storage medium, which can improve the accuracy of component supplier evaluation in advance, thereby effectively ensuring component quality.

[0004] According to one aspect of the present invention, a method for determining a score is provided, comprising:

[0005] Obtain the corresponding supporting documents of the supplier to be tested;

[0006] Determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score of the supplier to be tested based on the corresponding supporting documents of the supplier to be tested;

[0007] The target score corresponding to the supplier to be tested is determined based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested.

[0008] According to another aspect of the present invention, a score determination device is provided, the score determination device comprising:

[0009] The file acquisition module is used to obtain the corresponding supporting documents of the supplier to be tested;

[0010] A first score determination module is used to determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the supporting documents corresponding to the supplier to be tested;

[0011] The second score determination module is used to determine the target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested.

[0012] According to another aspect of the present invention, an electronic device is provided, comprising:

[0013] at least one processor; and

[0014] a memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the score determination method according to any embodiment of the present invention.

[0016] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the score determination method according to any embodiment of the present invention when executed.

[0017] The embodiment of the present invention obtains the corresponding certification documents of the supplier to be tested; determines the information security management capability score, information security development capability score, safety product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding certification documents of the supplier to be tested; and determines the corresponding target score of the supplier to be tested based on the information security management capability score, information security development capability score, safety product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested, so as to improve the accuracy of the component supplier evaluation in advance and thus effectively ensure the quality of the components.

[0018] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 is a flow chart of a scoring determination method in an embodiment of the present invention;

[0021] Figure 2 is a schematic structural diagram of a scoring determination device in an embodiment of the present invention;

[0022] Figure 3 It is a structural diagram of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0024] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0025] Example 1

[0026] Figure 1 This is a flow chart of a scoring determination method provided by an embodiment of the present invention. This embodiment is applicable to the case of scoring component suppliers. The method can be executed by a scoring determination device in an embodiment of the present invention, which can be implemented in software and / or hardware. Figure 1 As shown, the method specifically includes the following steps:

[0027] S110, obtaining the corresponding supporting documents of the supplier to be tested.

[0028] Among them, the supporting documents are documents proactively provided by the supplier to be tested, and the supporting documents are documents authorized for disclosure by the supplier to be tested, so as to facilitate the evaluation of the supplier to be tested based on the supporting documents.

[0029] The supporting documents may include: management phase information, development phase information, production phase information, operation and maintenance phase information, and scrap phase information. The supporting documents may also include: team information corresponding to the supplier to be tested, component management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, training information corresponding to the supplier to be tested, TARA assessment information of the component development phase corresponding to the supplier to be tested, component security information corresponding to the supplier to be tested, security management tools corresponding to the supplier to be tested, production plan information corresponding to the supplier to be tested, component vulnerability information corresponding to the supplier to be tested, component service termination information corresponding to the supplier to be tested, and component log information corresponding to the supplier to be tested. The component security information corresponding to the supplier to be tested includes: the component storage security information corresponding to the supplier to be tested, the component operating system security information corresponding to the supplier to be tested, the component communication security information corresponding to the supplier to be tested, the component privacy security information corresponding to the supplier to be tested, the component access permission information corresponding to the supplier to be tested, the component debugging port security information corresponding to the supplier to be tested, at least one of the self-test report, the third-party test report and the TARA report; the component vulnerability information corresponding to the supplier to be tested includes: the component vulnerability identification strategy corresponding to the supplier to be tested, the component vulnerability source information corresponding to the supplier to be tested, the functional information of the component corresponding to the supplier to be tested after a network security incident occurs, the network security incident report and at least one of the solution strategies for the network security incident.

[0030] Specifically, a method for obtaining the certification file corresponding to the supplier to be tested may be: receiving the certification file sent by a terminal device corresponding to the supplier to be tested.

[0031] S120, determining the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding supporting documents of the supplier to be tested.

[0032] Specifically, the method for determining the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding supporting documents of the supplier to be tested can be: determining the information security management capability score corresponding to the supplier to be tested based on the management stage information, determining the information security development capability score corresponding to the supplier to be tested based on the development stage information, determining the security product production capability score corresponding to the supplier to be tested based on the production stage information, determining the information security operation and maintenance capability score corresponding to the supplier to be tested based on the operation and maintenance stage information, and determining the information security product scrapping capability score corresponding to the supplier to be tested based on the scrapping stage information.

[0033] Specifically, the method of determining the information security management capability score, information security development capability score, safety product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the supporting documents corresponding to the supplier to be tested can be: inputting the team information corresponding to the supplier to be tested, the parts management information corresponding to the supplier to be tested, the sub-supplier information corresponding to the supplier to be tested, and the training information corresponding to the supplier to be tested into a first model to obtain the information security management capability score corresponding to the supplier to be tested, wherein the first model is obtained by iteratively training a neural network model through a first sample set; inputting the TARA assessment information of the parts development stage corresponding to the supplier to be tested and the parts safety information corresponding to the supplier to be tested into a second model to obtain the information security development capability score corresponding to the supplier to be tested, Among them, the second model is obtained by iteratively training the neural network model with the second sample set; the security management tool corresponding to the supplier to be tested and the production plan information corresponding to the supplier to be tested are input into the third model to obtain the security product production capability score corresponding to the supplier to be tested, wherein the third model is obtained by iteratively training the neural network model with the third sample set; the component vulnerability information corresponding to the supplier to be tested is input into the fourth model to obtain the information security operation and maintenance capability score corresponding to the supplier to be tested, wherein the fourth model is obtained by iteratively training the neural network model with the fourth sample set; the component service termination information corresponding to the supplier to be tested and the component log information corresponding to the supplier to be tested are input into the fifth model to obtain the information security product scrapping capability score corresponding to the supplier to be tested, wherein the fifth model is obtained by iteratively training the neural network model with the fifth sample set.

[0034] S130, determining a target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested.

[0035] Specifically, the method for determining the target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested can be: pre-setting the weight of the information security management capability score, the weight of the information security development capability score, the weight of the security product production capability score, the weight of the information security operation and maintenance capability score, and the weight of the information security product scrapping capability score, and determining the target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, information security product scrapping capability score, the weight of the information security management capability score, the weight of the information security development capability score, the weight of the security product production capability score, the weight of the information security operation and maintenance capability score, and the weight of the information security product scrapping capability score corresponding to the supplier to be tested.

[0036] Specifically, after determining the target score for the supplier to be tested based on its corresponding information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score, the supplier to be tested can be rated based on the target score to determine whether the supplier has passed the evaluation. For example, the rating criteria can be as shown in Table 1:

[0037] Table 1

[0038] Target score / full score Rating result E>=90% A Evaluation passed E>=80%&E<90% B Evaluation conditionally passed E<80% C Evaluation failed

[0039] Among them, the full score is the score corresponding to an ideal supplier, that is, the supplier's information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score are all full marks. If the ratio of the target score of the supplier to be tested to the full score is greater than or equal to 90%, the supplier to be tested is determined to be A-level and the evaluation passes; if the ratio of the target score of the supplier to be tested to the full score is greater than or equal to 80% and the ratio of the target score of the supplier to be tested to the full score is less than 90%, the supplier to be tested is determined to be B-level and the evaluation conditionally passes (as an alternative component supplier); if the ratio of the target score of the supplier to be tested to the full score is less than 80%, the supplier to be tested is determined to be C-level and the evaluation fails.

[0040] Optionally, the preparation documents include: team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, training information corresponding to the supplier to be tested, TARA assessment information of the parts development stage corresponding to the supplier to be tested, parts security information corresponding to the supplier to be tested, security management tools corresponding to the supplier to be tested, production plan information corresponding to the supplier to be tested, parts vulnerability information corresponding to the supplier to be tested, parts service termination information corresponding to the supplier to be tested, and parts log information corresponding to the supplier to be tested.

[0041] In a specific example, the supporting documents are evaluated based on the evaluation items in Table 2:

[0042] Table 2

[0043]

[0044]

[0045]

[0046] Specifically, after receiving the supporting document sent by the terminal device corresponding to the supplier to be tested, the supporting document is identified, and the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested are determined based on the identification result and the above-mentioned evaluation items. For example, the information security management capability score corresponding to the supplier to be tested may be determined based on the evaluation items corresponding to the management stage in Table 2, the information security development capability score corresponding to the supplier to be tested may be determined based on the evaluation items corresponding to the development stage in Table 2, the security product production capability score corresponding to the supplier to be tested may be determined based on the evaluation items corresponding to the production stage in Table 2, the information security operation and maintenance capability score corresponding to the supplier to be tested may be determined based on the evaluation items corresponding to the operation and maintenance stage in Table 2, and the information security product scrapping capability score corresponding to the supplier to be tested may be determined based on the evaluation items corresponding to the scrapping stage in Table 2.

[0047] The specific scoring rules are shown in Table 3:

[0048] Table 3

[0049] Fully comply with information security requirements and design specifications 10 points Only slight deviations will not affect the subsequent process or the realization of the OEM's requirements 8 points Satisfy defined requirements and have an impact on subsequent processes 6 points The process does not fully meet the defined requirements, which has a significant impact on subsequent processes 4 points Does not meet the requirements of the definition 0 points

[0050] For example, after receiving the certification file sent by the terminal device corresponding to the supplier to be tested, the certification file is identified to obtain the keywords in the certification file, and the similarity between the keywords in the certification file and the preset keywords is obtained. If the similarity is greater than the first similarity threshold, it is determined that the requirements are fully met and the score is 10 points; if the similarity is less than or equal to the first similarity threshold and greater than the second similarity threshold, it is determined that there is only a slight deviation and the requirements are basically met, and the score is 8 points; the second similarity threshold is less than the first similarity threshold, if the similarity is less than or equal to the second similarity threshold and greater than the third similarity threshold, and the second similarity threshold is greater than the third similarity threshold, it is determined that there is a large deviation and the requirements are partially met, and the score is 6 points; if the similarity is less than or equal to the third similarity threshold and greater than the fourth similarity threshold, it is determined that there is a large deviation and the requirements are not fully met, and the score is 4 points, and the third similarity threshold is greater than the fourth similarity threshold; if the similarity is less than or equal to the fourth similarity threshold, it is determined that the requirements are not met and the score is 0 point.

[0051] Optionally, the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score of the supplier to be tested are determined based on the corresponding supporting documents of the supplier to be tested, including:

[0052] Inputting team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, and training information corresponding to the supplier to be tested into a first model to obtain an information security management capability score corresponding to the supplier to be tested, wherein the first model is obtained by iteratively training a neural network model with a first sample set;

[0053] Inputting the TARA assessment information of the component development stage corresponding to the supplier to be tested and the component security information corresponding to the supplier to be tested into a second model to obtain an information security development capability score corresponding to the supplier to be tested, wherein the second model is obtained by iteratively training a neural network model with a second sample set;

[0054] Inputting the security management tool corresponding to the supplier to be tested and the production plan information corresponding to the supplier to be tested into a third model to obtain a safety product production capability score corresponding to the supplier to be tested, wherein the third model is obtained by iteratively training a neural network model with a third sample set;

[0055] Inputting component vulnerability information corresponding to the supplier to be tested into a fourth model to obtain an information security operation and maintenance capability score corresponding to the supplier to be tested, wherein the fourth model is obtained by iteratively training a neural network model using a fourth sample set;

[0056] The parts service termination information corresponding to the supplier to be tested and the parts log information corresponding to the supplier to be tested are input into the fifth model to obtain the information security product scrapping capability score corresponding to the supplier to be tested, wherein the fifth model is obtained by iteratively training the neural network model through the fifth sample set.

[0057] Among them, the first sample set includes: team information corresponding to the supplier sample, component management information corresponding to the supplier sample, sub-supplier information corresponding to the supplier sample, training information corresponding to the supplier sample, and information security management capability score corresponding to the supplier sample; the second sample set includes: TARA assessment information of the component development stage corresponding to the supplier sample, component security information corresponding to the supplier sample, and information security development capability score corresponding to the supplier sample; the third sample set includes: security management tools corresponding to the supplier sample, production plan information corresponding to the supplier sample, and security product production capability score corresponding to the supplier sample; the fourth sample set includes: component vulnerability information corresponding to the supplier sample and information security operation and maintenance capability score corresponding to the supplier sample; the fifth sample set includes: component service termination information corresponding to the supplier sample, component log information corresponding to the supplier sample, and information security product scrapping capability score corresponding to the supplier sample.

[0058] Specifically, the method of iteratively training the neural network model through the first sample set can be: establishing a neural network model; inputting the team information corresponding to the supplier sample in the first sample set, the parts management information corresponding to the supplier sample, the sub-supplier information corresponding to the supplier sample, and the training information corresponding to the supplier sample into the neural network model to obtain an information security management capability prediction score; training the parameters of the neural network model according to the first objective function generated according to the information security management capability prediction score and the information security management capability score corresponding to the supplier sample; returning to execute the operation of inputting the team information corresponding to the supplier sample in the first sample set, the parts management information corresponding to the supplier sample, the sub-supplier information corresponding to the supplier sample, and the training information corresponding to the supplier sample into the neural network model to obtain an information security management capability prediction score, until the first model is obtained.

[0059] Specifically, the method of iteratively training the neural network model through the second sample set can be: establishing a neural network model; inputting the TARA evaluation information of the component development stage corresponding to the supplier samples in the second sample set and the component safety information corresponding to the supplier samples into the neural network model to obtain an information security development capability prediction score; training the parameters of the neural network model according to the second objective function generated according to the information security development capability prediction score and the information security development capability score corresponding to the supplier samples; returning to execute the operation of inputting the TARA evaluation information of the component development stage corresponding to the supplier samples in the second sample set and the component safety information corresponding to the supplier samples into the neural network model to obtain an information security development capability prediction score, until the second model is obtained.

[0060] Specifically, the method of iteratively training the neural network model through the third sample set can be: establishing a neural network model; inputting the security management tools corresponding to the supplier samples in the third sample set and the production plan information corresponding to the supplier samples into the neural network model to obtain a safety product production capacity prediction score; training the parameters of the neural network model according to the third objective function generated according to the safety product production capacity prediction score and the safety product production capacity score corresponding to the supplier sample; returning to execute the operation of inputting the security management tools corresponding to the supplier samples in the third sample set and the production plan information corresponding to the supplier samples into the neural network model to obtain a safety product production capacity prediction score, until the third model is obtained.

[0061] Specifically, the method of iteratively training the neural network model through the fourth sample set can be: establishing a neural network model; inputting the component vulnerability information corresponding to the supplier samples in the fourth sample set into the neural network model to obtain the information security operation and maintenance capability prediction score; training the parameters of the neural network model according to the fourth objective function generated according to the information security operation and maintenance capability prediction score and the information security operation and maintenance capability score corresponding to the supplier sample; returning to execute the operation of inputting the component vulnerability information corresponding to the supplier samples in the fourth sample set into the neural network model to obtain the information security operation and maintenance capability prediction score, until the fourth model is obtained.

[0062] Specifically, the method of iteratively training the neural network model through the fifth sample set can be: establishing a neural network model; inputting the parts service termination information corresponding to the supplier samples in the fifth sample set and the parts log information corresponding to the supplier samples into the neural network model to obtain the information security product scrapping capability prediction score; training the parameters of the neural network model according to the fifth objective function generated according to the information security product scrapping capability prediction score and the information security product scrapping capability score corresponding to the supplier samples; returning to execute the operation of inputting the parts service termination information corresponding to the supplier samples in the fifth sample set and the parts log information corresponding to the supplier samples into the neural network model to obtain the information security product scrapping capability prediction score, until the fifth model is obtained.

[0063] Optionally, the component security information corresponding to the supplier to be tested includes: the component storage security information corresponding to the supplier to be tested, the component operating system security information corresponding to the supplier to be tested, the component communication security information corresponding to the supplier to be tested, the component privacy security information corresponding to the supplier to be tested, the component access permission information corresponding to the supplier to be tested, the component debug port security information corresponding to the supplier to be tested, at least one of a self-test report, a third-party test report and a TARA report; the component vulnerability information corresponding to the supplier to be tested includes: the component vulnerability identification strategy corresponding to the supplier to be tested, the component vulnerability source information corresponding to the supplier to be tested, the functional information of the component corresponding to the supplier to be tested after a network security incident occurs, a network security incident report and at least one of a solution strategy for a network security incident.

[0064] Optionally, the first sample set includes: team information corresponding to the supplier sample, component management information corresponding to the supplier sample, sub-supplier information corresponding to the supplier sample, training information corresponding to the supplier sample, and information security management capability score corresponding to the supplier sample; the second sample set includes: TARA assessment information of the component development stage corresponding to the supplier sample, component security information corresponding to the supplier sample, and information security development capability score corresponding to the supplier sample; the third sample set includes: security management tools corresponding to the supplier sample, production plan information corresponding to the supplier sample, and security product production capability score corresponding to the supplier sample; the fourth sample set includes: component vulnerability information corresponding to the supplier sample and information security operation and maintenance capability score corresponding to the supplier sample; the fifth sample set includes: component service termination information corresponding to the supplier sample, component log information corresponding to the supplier sample, and information security product scrapping capability score corresponding to the supplier sample.

[0065] Optionally, iteratively training the neural network model using the first sample set includes:

[0066] Build a neural network model;

[0067] Inputting team information, parts management information, sub-supplier information, and training information corresponding to the supplier samples in the first sample set into a neural network model to obtain a prediction score for information security management capabilities;

[0068] Training the parameters of the neural network model according to a first objective function generated by the information security management capability prediction score and the information security management capability score corresponding to the supplier sample;

[0069] Return to executing the operation of inputting the team information corresponding to the supplier sample in the first sample set, the parts management information corresponding to the supplier sample, the sub-supplier information corresponding to the supplier sample, and the training information corresponding to the supplier sample into the neural network model to obtain the information security management capability prediction score until the first model is obtained.

[0070] The neural network model may be an LSTM model.

[0071] Among them, the sub-supplier information corresponding to the supplier sample is the secondary supplier information corresponding to the supplier sample.

[0072] The technical solution of this embodiment obtains the corresponding certification documents of the supplier to be tested; determines the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding certification documents of the supplier to be tested; and determines the corresponding target score of the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested, which can improve the accuracy of the component supplier evaluation in advance and thus effectively ensure the quality of components.

[0073] Example 2

[0074] Figure 2 This is a schematic diagram of the structure of a scoring determination device provided by an embodiment of the present invention. This embodiment is applicable to situations where scoring is determined. The device can be implemented in software and / or hardware. The device can be integrated into any device that provides a scoring determination function, such as Figure 2 As shown, the score determination device specifically includes: a file acquisition module 210 , a first score determination module 220 and a second score determination module 230 .

[0075] Among them, the file acquisition module is used to obtain the corresponding supporting documents of the supplier to be tested;

[0076] A first score determination module is used to determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the supporting documents corresponding to the supplier to be tested;

[0077] The second score determination module is used to determine the target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested.

[0078] Optionally, the preparation documents include: team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, training information corresponding to the supplier to be tested, TARA assessment information of the parts development stage corresponding to the supplier to be tested, parts security information corresponding to the supplier to be tested, security management tools corresponding to the supplier to be tested, production plan information corresponding to the supplier to be tested, parts vulnerability information corresponding to the supplier to be tested, parts service termination information corresponding to the supplier to be tested, and parts log information corresponding to the supplier to be tested.

[0079] The above-mentioned product can execute the method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0080] The technical solution of this embodiment obtains the corresponding certification documents of the supplier to be tested; determines the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding certification documents of the supplier to be tested; and determines the corresponding target score of the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score and information security product scrapping capability score corresponding to the supplier to be tested, which can improve the accuracy of the component supplier evaluation in advance and thus effectively ensure the quality of components.

[0081] Example 3

[0082] Figure 3A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0083] like Figure 3 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0084] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0085] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the score determination method.

[0086] In some embodiments, the score determination method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the score determination method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the score determination method in any other suitable manner (e.g., by means of firmware).

[0087] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0088] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0089] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0090] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0091] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0092] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0093] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0094] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A scoring determination method, characterized in that: include: Obtain the corresponding supporting documents of the supplier to be tested; Determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score of the supplier to be tested based on the corresponding supporting documents of the supplier to be tested; Determine the target score for the supplier to be tested based on the supplier's corresponding information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score; The supporting documents include: management stage information, development stage information, production stage information, operation and maintenance stage information, and scrapping stage information; The determining of the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the corresponding supporting documents of the supplier to be tested includes: The information security management capability score corresponding to the supplier to be tested is determined based on the management stage information, the information security development capability score corresponding to the supplier to be tested is determined based on the development stage information, the security product production capability score corresponding to the supplier to be tested is determined based on the production stage information, the information security operation and maintenance capability score corresponding to the supplier to be tested is determined based on the operation and maintenance stage information, and the information security product scrapping capability score corresponding to the supplier to be tested is determined based on the scrapping stage information.

2. The method according to claim 1, characterized in that The preparation documents include: team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, training information corresponding to the supplier to be tested, TARA assessment information of the parts development stage corresponding to the supplier to be tested, parts security information corresponding to the supplier to be tested, security management tools corresponding to the supplier to be tested, production plan information corresponding to the supplier to be tested, parts vulnerability information corresponding to the supplier to be tested, parts service termination information corresponding to the supplier to be tested, and parts log information corresponding to the supplier to be tested.

3. The method according to claim 2, characterized in that Determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score of the supplier to be tested based on the corresponding supporting documents of the supplier to be tested, including: Inputting team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, and training information corresponding to the supplier to be tested into a first model to obtain an information security management capability score corresponding to the supplier to be tested, wherein the first model is obtained by iteratively training a neural network model with a first sample set; Inputting the TARA assessment information of the component development stage corresponding to the supplier to be tested and the component security information corresponding to the supplier to be tested into a second model to obtain an information security development capability score corresponding to the supplier to be tested, wherein the second model is obtained by iteratively training a neural network model with a second sample set; Inputting the security management tool corresponding to the supplier to be tested and the production plan information corresponding to the supplier to be tested into a third model to obtain a safety product production capability score corresponding to the supplier to be tested, wherein the third model is obtained by iteratively training a neural network model with a third sample set; Inputting component vulnerability information corresponding to the supplier to be tested into a fourth model to obtain an information security operation and maintenance capability score corresponding to the supplier to be tested, wherein the fourth model is obtained by iteratively training a neural network model using a fourth sample set; The parts service termination information corresponding to the supplier to be tested and the parts log information corresponding to the supplier to be tested are input into the fifth model to obtain the information security product scrapping capability score corresponding to the supplier to be tested, wherein the fifth model is obtained by iteratively training the neural network model through the fifth sample set.

4. The method according to claim 3, characterized in that The component security information corresponding to the supplier to be tested includes: the component storage security information corresponding to the supplier to be tested, the component operating system security information corresponding to the supplier to be tested, the component communication security information corresponding to the supplier to be tested, the component privacy security information corresponding to the supplier to be tested, the component access permission information corresponding to the supplier to be tested, the component debugging port security information corresponding to the supplier to be tested, at least one of the self-test report, the third-party test report and the TARA report; the component vulnerability information corresponding to the supplier to be tested includes: the component vulnerability identification strategy corresponding to the supplier to be tested, the component vulnerability source information corresponding to the supplier to be tested, the functional information of the component corresponding to the supplier to be tested after a network security incident occurs, the network security incident report and at least one of the solution strategies for the network security incident.

5. The method according to claim 3, characterized in that The first sample set includes: team information corresponding to the supplier sample, component management information corresponding to the supplier sample, sub-supplier information corresponding to the supplier sample, training information corresponding to the supplier sample, and information security management capability score corresponding to the supplier sample; the second sample set includes: TARA assessment information of the component development stage corresponding to the supplier sample, component security information corresponding to the supplier sample, and information security development capability score corresponding to the supplier sample; the third sample set includes: security management tools corresponding to the supplier sample, production plan information corresponding to the supplier sample, and security product production capability score corresponding to the supplier sample; the fourth sample set includes: component vulnerability information corresponding to the supplier sample and information security operation and maintenance capability score corresponding to the supplier sample; the fifth sample set includes: component service termination information corresponding to the supplier sample, component log information corresponding to the supplier sample, and the score corresponding to the supplier sample.

6. The method according to claim 5, characterized in that Iteratively training the neural network model using the first sample set includes: Build a neural network model; Inputting team information, parts management information, sub-supplier information, and training information corresponding to the supplier samples in the first sample set into a neural network model to obtain a prediction score for information security management capabilities; Training the parameters of the neural network model according to a first objective function generated by the information security management capability prediction score and the information security management capability score corresponding to the supplier sample; Return to executing the operation of inputting the team information corresponding to the supplier sample in the first sample set, the parts management information corresponding to the supplier sample, the sub-supplier information corresponding to the supplier sample, and the training information corresponding to the supplier sample into the neural network model to obtain the information security management capability prediction score until the first model is obtained.

7. A scoring determination device, characterized in that: include: The file acquisition module is used to obtain the corresponding supporting documents of the supplier to be tested; A first score determination module is used to determine the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested based on the supporting documents corresponding to the supplier to be tested; A second score determination module is used to determine a target score corresponding to the supplier to be tested based on the information security management capability score, information security development capability score, security product production capability score, information security operation and maintenance capability score, and information security product scrapping capability score corresponding to the supplier to be tested; The supporting documents include: management stage information, development stage information, production stage information, operation and maintenance stage information, and scrapping stage information; The first score determination module is specifically configured to: The information security management capability score corresponding to the supplier to be tested is determined based on the management stage information, the information security development capability score corresponding to the supplier to be tested is determined based on the development stage information, the security product production capability score corresponding to the supplier to be tested is determined based on the production stage information, the information security operation and maintenance capability score corresponding to the supplier to be tested is determined based on the operation and maintenance stage information, and the information security product scrapping capability score corresponding to the supplier to be tested is determined based on the scrapping stage information.

8. The device according to claim 7, characterized in that The preparation documents include: team information corresponding to the supplier to be tested, parts management information corresponding to the supplier to be tested, sub-supplier information corresponding to the supplier to be tested, training information corresponding to the supplier to be tested, TARA assessment information of the parts development stage corresponding to the supplier to be tested, parts security information corresponding to the supplier to be tested, security management tools corresponding to the supplier to be tested, production plan information corresponding to the supplier to be tested, parts vulnerability information corresponding to the supplier to be tested, parts service termination information corresponding to the supplier to be tested, and parts log information corresponding to the supplier to be tested.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the score determination method according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the score determination method according to any one of claims 1 to 6 when executed.

Citation Information

Patent Citations

  • Power equipment supplier evaluation method and device

    CN111242430A

  • Vehicle information safety level evaluation method and device, electronic equipment and medium

    CN112686499A