A network security health detection method, device, equipment, and storage medium
By obtaining and classifying network security-related indicators, calculating the closed-loop rate, and inputting it into the health scoring model, the problem of difficulty in quickly and comprehensively evaluating enterprise network security in the existing technology is solved, and a low-cost and efficient network security health assessment is achieved.
Patent Information
- Application Number
- CN202211137021.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-19
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-09-19
AI Technical Summary
The existing technology is difficult to quickly and comprehensively evaluate the network security and health of enterprises in multiple dimensions, and the evaluation cost is relatively high.
By obtaining the indicators of the number of high-risk vulnerabilities, the number of port opens, the number of information leakage events and the number of incident responses, performing grade classification and closed-loop rate calculation, inputting them into the target health score model to output the health score, and determining the network security health tag based on the scoring level.
It has achieved a rapid and multi-dimensional comprehensive evaluation of the network security and health of enterprises, reduced the cost of assessment, and accurately judged whether the enterprise has major network risks.
Smart Images

Figure CN115549992B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security health detection method, device, equipment, and storage medium. Background Art
[0002] The field of network security is actually a field of attack and defense, just like war. Only by knowing yourself and the enemy can you win every battle. How to correctly identify and evaluate the current status of your own network security is a key topic. Hackers will actively break into the system or remotely invade network vulnerabilities to conduct penetration attacks to threaten network security; therefore, it is necessary to detect and evaluate the network security of enterprises, and to achieve early detection and early resolution of network security problems through the health assessment of enterprises, so as to improve the overall level of information security. In the past, there have been some methods, such as graded protection assessment technology, which is also based on technical and management dimension assessment. The whole process lasts for a long time and is costly. The whole step is divided into classification, filing, rectification, assessment, and supervision. The management part requires interviews, inspections, and questionnaires, and the whole process is relatively cumbersome. There are also evaluation methods for single systems, such as penetration test assessment and scanner assessment. These evaluation methods are difficult to implement because they are too complex and costly, or they only focus on a certain point and cannot comprehensively evaluate the health of the enterprise.
[0003] In summary, how to achieve rapid, multi-dimensional and comprehensive evaluation of an enterprise's network security health and reduce the cost of evaluation is a technical problem that needs to be solved in this field. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a network security health detection method, device, equipment, and storage medium, which can achieve rapid, multi-dimensional and comprehensive evaluation of the network security health of an enterprise and reduce the evaluation cost. The specific scheme is as follows:
[0005] In a first aspect, the present application discloses a network security health detection method, comprising:
[0006] Obtain indicators of the number of high-risk vulnerabilities, the number of high-risk open ports, and the number of high-risk information leakage incidents;
[0007] Classify the incident response quantity indicators to determine the incident response quantity indicators of the corresponding grade category;
[0008] Determine the closed-loop rate of the corresponding quantity indicators based on the high-risk vulnerability quantity indicator, the high-risk port open quantity indicator, the high-risk information leakage incident quantity indicator and the incident response quantity indicator;
[0009] Inputting the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into a target health scoring model, so that the target health scoring model outputs a corresponding health score;
[0010] A health label for the enterprise network security is determined based on a score level corresponding to the health score.
[0011] Optionally, the obtaining of the number of high-risk vulnerabilities, the number of high-risk open ports, and the number of high-risk information leakage events includes:
[0012] Based on the preset technical indicator screening rules, high-risk vulnerability quantity indicators, high-risk port opening quantity indicators, and high-risk information leakage incident quantity indicators are screened out from the current technical indicators.
[0013] Optionally, the obtaining of the number of high-risk vulnerabilities, the number of high-risk open ports, and the number of high-risk information leakage events includes:
[0014] Obtain indicators of the number of high-risk vulnerabilities, the number of high-risk ports open, and the number of high-risk information leakage incidents through active and / or passive methods.
[0015] Optionally, before inputting the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into the target health scoring model, the step further includes:
[0016] A policy update file is obtained, and based on the policy update file, the weight setting in the original health score model and the coefficient setting for interval value calculation are adjusted to generate a target health score model.
[0017] Optionally, before obtaining the strategy update file, the method further includes:
[0018] The target label data is input into the preset data fitting model so that the preset data fitting model uses a linear regression algorithm to calculate the weights and coefficients of interval value calculations of various data indicators for the target label data, and outputs a strategy update file containing the corresponding target weights of each data and the target coefficients of interval value calculations of each data indicator.
[0019] Optionally, before inputting the target label data into the preset data fitting model, the method further includes:
[0020] Sampling historical data, and performing a health level labeling operation on the historical data to obtain label data;
[0021] The label data are scored to obtain target label data.
[0022] Optionally, the step of inputting the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index, and the corresponding closed-loop rate into a target health scoring model so that the target health scoring model outputs a corresponding health score includes:
[0023] The high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage incident quantity index, the incident response quantity index and the corresponding closed-loop rate are input into the target health scoring model, so that the target health scoring model calculates the health score based on the target weight and target interval value corresponding to each data indicator, and outputs the corresponding health score.
[0024] In a second aspect, the present application discloses a network security health detection device, comprising:
[0025] The first indicator acquisition module is used to obtain the number of high-risk vulnerabilities, the number of high-risk port openings, and the number of high-risk information leakage events;
[0026] The second indicator acquisition module is used to classify the event response quantity indicators to determine the event response quantity indicators of the corresponding level category;
[0027] A closed-loop rate determination module, configured to determine the closed-loop rates of corresponding quantity indicators based on the high-risk vulnerability quantity indicator, the high-risk port open quantity indicator, the high-risk information leakage event quantity indicator, and the event response quantity indicator;
[0028] A health scoring module, used to input the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into a target health scoring model, so that the target health scoring model outputs a corresponding health score;
[0029] The level determination module is used to determine the health label of the enterprise network security based on the score level corresponding to the health score.
[0030] In a third aspect, the present application discloses an electronic device, including:
[0031] Memory, used to store computer programs;
[0032] The processor is used to execute the computer program to implement the steps of the aforementioned disclosed network security health detection method.
[0033] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed network security health detection method are implemented.
[0034] It can be seen that the present application discloses a network security health detection method, including: obtaining a high-risk vulnerability quantity index, a high-risk port opening quantity index, and a high-risk information leakage event quantity index; classifying the event response quantity index to determine the event response quantity index of the corresponding level category; determining the closed-loop rate of the corresponding quantity index based on the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, and the event response quantity index; inputting the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, the event response quantity index, and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score; determining the health label of the enterprise network security based on the score level corresponding to the health score. It can be seen that the real data is fitted based on the various quantitative indicators obtained, and the quantitative indicators are input into the target health scoring model to automatically evaluate and score the network security health of the enterprise, and evaluate the network security health of the enterprise from multiple aspects from the perspective of multiple quantitative indicators, so that the network security health of the enterprise can be correctly evaluated based on the network security health. Whether there is a large network risk in the current enterprise. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0036] Figure 1 A flowchart of a network security health detection method disclosed in this application;
[0037] Figure 2 A flow chart of a model actual deployment interaction method disclosed in this application;
[0038] Figure 3 A flowchart of a specific network security health detection method disclosed in this application;
[0039] Figure 4 A diagram of inter-module calling relationships disclosed in this application;
[0040] Figure 5 This is a schematic diagram of the structure of a network security health detection device disclosed in this application;
[0041] Figure 6 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0043] The field of network security is actually a field of attack and defense, just like war. Only by knowing yourself and the enemy can you win every battle. How to correctly identify and evaluate the current network security status of your own party is a key topic. Hackers will actively break into the system or remotely invade network vulnerabilities to conduct penetration attacks to threaten network security; therefore, it is necessary to detect and evaluate the network security of enterprises, and through the health assessment of enterprises, network security problems can be discovered and solved early, and the overall level of information security can be improved. In the past, there have been some methods, such as security assessment, and single system evaluation methods, such as penetration test assessment and scanner assessment. These evaluation methods are difficult to implement because they are too complicated and costly, or they only focus on a certain point and cannot comprehensively evaluate the health of the enterprise.
[0044] To this end, this application provides a network security health detection solution that can achieve rapid, multi-dimensional and comprehensive evaluation of the network security health of an enterprise and reduce the evaluation cost.
[0045] Reference Figure 1 As shown, an embodiment of the present invention discloses a network security health detection method, including:
[0046] Step S11: Obtain a number index of high-risk vulnerabilities, a number index of high-risk open ports, and a number index of high-risk information leakage events.
[0047] In this embodiment, based on the preset technical indicator screening rules, high-risk vulnerability quantity indicators, high-risk port opening quantity indicators, and high-risk information leakage incident quantity indicators are screened out from the current technical indicators. It can be understood that all computing indicators are divided into two major categories: management indicators and technical indicators, which respectively reflect the organization's security management capabilities and the current security risk status it faces. Among them, the technical indicator screening method: first, list all risk categories currently faced by the organization; conduct a qualitative analysis of each type of risk, where risks are divided into positive risks and negative risks; conduct a quantitative analysis of each type of risk, identify the probability of risk occurrence, the loss caused by the risk, and calculate the possible risk exposure; sort the risk categories according to the results of the quantitative analysis, and the risk categories with the larger risk exposure are given priority to be selected into the technical indicators, for example: screen 8 to 16 types of risks into the number of things indicator. The weights corresponding to the calculation of technical indicators are:
[0048] ;
[0049] After calculating the weights of the technical indicators and selecting some technical indicators from all the technical indicators, the management indicators are screened: first, after the technical indicators are screened, you only need to set the closed-loop rate of the corresponding risk disposal. The weights refer to the weights of the technical indicators. The logic behind this is that the risk categories with larger risk exposure should be identified, discovered and resolved as early as possible in management. The speed of resolution determines the strength of the corresponding management level.
[0050] In this embodiment, the number of high-risk vulnerabilities, the number of high-risk port openings, and the number of high-risk information leakage incidents are obtained in an active and / or passive manner. It can be understood that various data indicators are obtained in an active or passive manner, wherein the method of actively detecting data may specifically include but is not limited to: vulnerability scanning, Internet exposure information detection, etc.; the method of passively detecting data may specifically include but is not limited to: intrusion detection data, management state data, vulnerability closure rate, event closure rate, information leakage incident closure rate, etc. Various data indicators are obtained through different data acquisition methods, which expands the scope of data indicator acquisition, and thus provides a guarantee for comprehensively and objectively evaluating the real status of the enterprise's network security construction and the management status of network security. Among them, the quantitative indicators are key features in the model calculation, often quantifiable parameters, usually directly affecting the final result of the model, and there is often a mutually exclusive relationship between the indicators.
[0051] Step S12: classify the event response quantity indicators into different levels to determine the event response quantity indicators of corresponding level categories.
[0052] In this embodiment, the importance of assets is predefined and divided into levels 1, 2, and 3 according to the importance level, with the importance level decreasing in sequence; the response level of events is defined and divided into levels 1, 2, and 3 according to the severity level of the events, with the severity level decreasing in sequence; the acquired event response data indicators are classified according to the severity level, for example: high-risk vulnerabilities of assets to be disposed are divided into the number of high-risk vulnerabilities of first-level assets to be disposed, the number of high-risk vulnerabilities of second-level assets to be disposed, and the number of high-risk information leakage incidents to be disposed; the high-risk port opening conditions are divided into the number of non-standard ports opened for first-level assets to be disposed, and the number of non-standard ports opened for second-level assets to be disposed; high-risk information leakage incidents are divided into the number of level 1 incidents to be disposed, the number of level 2 incidents to be disposed, and the number of level 3 incidents to be disposed.
[0053] Step S13: Determine the closed-loop rate of the corresponding quantity indicators based on the high-risk vulnerability quantity indicator, the high-risk port open quantity indicator, the high-risk information leakage event quantity indicator and the event response quantity indicator.
[0054] In this embodiment, after determining various event quantity indicators, the corresponding event closed-loop rates are determined respectively, wherein the closed-loop rate is an evaluation of the handling rate after a vulnerability or event occurs, wherein the closed-loop rate calculation formula is as follows:
[0055] ;
[0056] Based on the above closed-loop rate calculation formula, the closed-loop rates of data indicators such as the number of high-risk vulnerabilities, the number of high-risk port openings, the number of high-risk information leakage incidents, and the number of incident responses are determined respectively, and the above closed-loop rates are divided into levels, for example: level 3 event closed-loop rate, level 2 event closed-loop rate, level 1 event closed-loop rate, high-risk vulnerability closed-loop rate, medium- and low-risk vulnerability closed-loop rate, and high-risk information leakage incident closed-loop rate.
[0057] Step S14: Input the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score.
[0058] In this embodiment, the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate are input into the target health score model, so that the target health score model calculates the health score based on the target weight and target interval value corresponding to each data index, and outputs the corresponding health score. It can be understood that, referring to Figure 2As shown in the figure, in the actual interactive deployment process, the health score is divided into three parts: the first part is the security detection part, the second part is the security management platform part, and the third part is the health score part. In the security detection part, various data indicators are collected by vulnerability scanners, exposure surface detection tools, and intrusion detection devices, and then the collected data indicators are classified into the following categories: security vulnerabilities, high-risk ports, intrusion detection, information leakage, etc. In the health score part, the health scoring device is used. The health scoring device usually interacts with the security management platform. All kinds of data of various indicators required for the health scoring can be stored in the security management platform, and the security management platform can obtain the processed and unprocessed data, thereby calculating the corresponding closed-loop rate and participating in the model operation.
[0059] In this embodiment, before the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage incident quantity index, the incident response quantity index and the corresponding closed-loop rate are input into the target health scoring model, it also includes: obtaining a policy update file, and adjusting the weight settings in the original health scoring model and the coefficient settings for interval value calculation based on the policy update file to generate a target health scoring model. It can be understood that the target health scoring model is pre-trained, and then the policy file is updated in the target health scoring model. It should be noted that when the target health scoring model is generated, the first policy file is used, and then, after a preset time period, the updated policy file is sent to the target health scoring model to replace the original policy file, and the weight settings and the coefficients for interval value calculation are updated to obtain a more complete target health scoring model.
[0060] Step S15: Determine a health label for enterprise network security based on the score level corresponding to the health score.
[0061] In this embodiment, after obtaining the health score of the enterprise network security, the health of the system is divided into four levels: healthy, good, passing, and unpassed. The corresponding score intervals are: healthy: [85, 100]; good: [70, 85]; passing: (55, 70]; unpassed: (0, 55], and then the corresponding score interval is determined according to the health score to determine the corresponding network security health label.
[0062] It can be seen that the present application discloses a network security health detection method, including: obtaining a high-risk vulnerability quantity index, a high-risk port opening quantity index, and a high-risk information leakage event quantity index; classifying the event response quantity index to determine the event response quantity index of the corresponding level category; determining the closed-loop rate of the corresponding quantity index based on the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, and the event response quantity index; inputting the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, the event response quantity index, and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score; determining the health label of the enterprise network security based on the score level corresponding to the health score. It can be seen that the real data is fitted based on the various quantitative indicators obtained, and the quantitative indicators are input into the target health scoring model to automatically evaluate and score the network security health of the enterprise, and evaluate the network security health of the enterprise from multiple aspects from the perspective of multiple quantitative indicators, so that the network security health of the enterprise can be correctly evaluated based on the network security health. Whether there is a large network risk in the current enterprise.
[0063] Reference Figure 3 As shown, the embodiment of the present invention discloses a specific method for detecting the health of network security. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution. Specifically:
[0064] Step S21: Obtain a number of high-risk vulnerabilities, a number of high-risk open ports, and a number of high-risk information leakage events.
[0065] Step S22: classify the event response quantity indicators into different levels to determine the event response quantity indicators of corresponding level categories.
[0066] Step S23: Determine the closed-loop rate of the corresponding quantity indicators based on the high-risk vulnerability quantity indicator, the high-risk port open quantity indicator, the high-risk information leakage event quantity indicator and the event response quantity indicator.
[0067] For more detailed processing procedures in steps S21, S22, and S23, please refer to the aforementioned disclosed embodiments, which will not be described in detail here.
[0068] Step S24: sampling the historical data, and performing a health level marking operation on the historical data to obtain label data; scoring the label data to obtain target label data.
[0069] In this embodiment, since each indicator is selected based on the empirical value of the current historical data and has a certain universality, it is necessary to sample the historical data and label the historical data. The specific label content can be a specific level mark, and manual labeling can be performed during the labeling process. In this way, accurate sampling data, that is, target label data, can be obtained.
[0070] In this embodiment, refer to Figure 4 As shown, the health scoring device consists of a calculation module and a training module, wherein the training module is mainly responsible for taking the manually labeled data samples as input, calling the data fitting algorithm, generating the corresponding weights and coefficients, and updating the updated model to the calculation module. The training module operates in an offline mode and outputs the policy update file in the form of a file. The calculation module is mainly responsible for receiving the input parameters, calling the health model scoring algorithm to calculate, obtaining the health score of the enterprise, and outputting the health score and the corresponding health level according to the preset level and scoring rules. The calculation module updates the model calculation accuracy of the device by loading the policy update file. The health score is evaluated according to the technical dimension and the management dimension with reference to the evaluation of the level protection, which also meets the requirements of information security management. From the technical dimension, it is necessary to evaluate the attack surface, and comprehensively evaluate the risks faced by the current enterprise based on information such as vulnerabilities, information leakage, high-risk port opening, and the number of events. In the management dimension, in order to avoid tedious surveys and questionnaires for users, the statistical dimension is adopted to count the user's handling rate of vulnerabilities and events, thereby quantifying the management level.
[0071] , the calculation formulas of various indicators and intervals are shown in Table 1.
[0072] Table 1
[0073]
[0074] Step S25: Input the target label data into the preset data fitting model so that the preset data fitting model uses a linear regression algorithm to calculate the weights and coefficients of interval value calculations of various data indicators for the target label data, and outputs a strategy update file containing the corresponding target weights of each data and the target coefficients of interval value calculations of each data indicator.
[0075] In this embodiment, the weights and specific interval value calculation coefficients also need to be calculated based on the actual data fitting parameters. Data fitting requires a large number of data samples. The richer the samples, the more objective the fitted weights and coefficients will be. It is necessary to first obtain the corresponding enterprise data samples. The number of samples should be greater than 21, and it is recommended to exceed 100. The samples should be marked with a health level in advance according to the empirical value, and a Gaussian distribution should be used to generate corresponding scores for the samples within the corresponding level interval. After the operation is completed, the label data is generated and data fitting begins. Data fitting algorithm input: label data that has met the standards in advance; data fitting algorithm operation: linear regression algorithm is used; data fitting algorithm output: weights of each indicator and coefficients of the interval value calculation algorithm. Data fitting is a continuous task that needs to be carried out periodically, the authenticity of the model algorithm is verified regularly, and suitable samples are selected for fitting to generate reasonable parameters. For example, the weights and interval value coefficients are calculated by regression first to obtain the best practice parameters, as shown in Table 2:
[0076] Table 2
[0077]
[0078] It should be noted that code review can be used to determine whether the same indicators are used and whether the best practice weights and scoring coefficients are used.
[0079] Step S26: Obtain the policy update file, and adjust the weight settings in the original health score model and the coefficient settings for interval value calculation based on the policy update file to generate a target health score model.
[0080] In this embodiment, the policy update data is obtained from the training module, and then the weight setting and the coefficient setting of the interval value calculation in the health score model in the operation module are adjusted using the policy update data generated by the training module to generate a target health score model that meets the requirements.
[0081] Step S27: Input the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage incident quantity index, the incident response quantity index and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score.
[0082] In this embodiment, a table is designed to extract real data, and the health status is evaluated based on empirical values, with corresponding labels of healthy, good, passing, and failing. Based on the marked health status, a Gaussian distribution is used to randomly generate a health score within the health score range.
[0083] Step S28: Determine a health label for the enterprise network security based on the score level corresponding to the health score.
[0084] In this embodiment, the security management platform is connected to read the indicator data corresponding to each enterprise from the platform, and the health scoring algorithm is called to calculate the corresponding score for the enterprise, and the enterprise is labeled with a corresponding health label according to the corresponding score level.
[0085] It can be seen that the target health scoring model in this embodiment belongs to a complete quantitative assessment, and the evaluation result is a value from 0 to 100, which is called the information security health index. The target health scoring model starts from the four levels of comprehensive layer, thematic layer, object layer, and indicator layer. It follows a bottom-up, first local and then overall strategy, combines multi-layer weights and multiple types of indicators to objectively and comprehensively quantify the security status of the information system. The attack surface is the core, which is lightweight, efficient, and accurate; it can accurately determine the existence of risks, realize early detection and early resolution of security issues, and thus improve the overall level of information security.
[0086] Reference Figure 5 As shown, the embodiment of the present invention discloses a network security health detection device, including:
[0087] The first indicator acquisition module 11 is used to obtain the number of high-risk vulnerabilities, the number of high-risk port openings, and the number of high-risk information leakage events;
[0088] The second indicator acquisition module 12 is used to classify the event response quantity indicators to determine the event response quantity indicators of the corresponding level category;
[0089] A closed-loop rate determination module 13, configured to determine the closed-loop rate of the corresponding quantity index based on the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, and the event response quantity index;
[0090] The health scoring module 14 is used to input the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score;
[0091] The level determination module 15 is used to determine the health label of the enterprise network security based on the score level corresponding to the health score.
[0092] It can be seen that the present application discloses a network security health detection method, including: obtaining a high-risk vulnerability quantity index, a high-risk port opening quantity index, and a high-risk information leakage event quantity index; classifying the event response quantity index to determine the event response quantity index of the corresponding level category; determining the closed-loop rate of the corresponding quantity index based on the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, and the event response quantity index; inputting the high-risk vulnerability quantity index, the high-risk port opening quantity index, the high-risk information leakage event quantity index, the event response quantity index, and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model outputs the corresponding health score; determining the health label of the enterprise network security based on the score level corresponding to the health score. It can be seen that the real data is fitted based on the various quantitative indicators obtained, and the quantitative indicators are input into the target health scoring model to automatically evaluate and score the network security health of the enterprise, and evaluate the network security health of the enterprise from multiple aspects from the perspective of multiple quantitative indicators, so that the network security health of the enterprise can be correctly evaluated based on the network security health. Whether there is a large network risk in the current enterprise.
[0093] Furthermore, the present application also discloses an electronic device. Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.
[0094] Figure 6 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network security health detection method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0095] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0096] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0097] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0098] Among them, the operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, so as to realize the operation and processing of the processor 21 on the massive data 223 in the memory 22, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the network security health detection method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can also further include a computer program that can be used to complete other specific tasks. In addition to data transmitted from an external device received by the electronic device, the data 223 can also include data collected by its own input and output interface 25.
[0099] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed network security health detection method is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.
[0100] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0101] Professionals may further realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to the function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly implemented with a software module executed by a hardware or processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the technical field.
[0102] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0103] The above is a detailed introduction to a network security health detection method, device, equipment, and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A network security health detection method, It is characterized in that include: Obtain indicators of the number of high-risk vulnerabilities, the number of high-risk open ports, and the number of high-risk information leakage incidents; Classifying the incident response quantity indicators to determine the incident response quantity indicators of the corresponding level categories; wherein the incident response quantity indicators are the total quantity indicators of the high-risk vulnerability quantity indicators, the high-risk port open quantity indicators, and the high-risk information leakage event quantity indicators; Determine the closed-loop rate of the corresponding quantity indicators based on the high-risk vulnerability quantity indicator, the high-risk port open quantity indicator, the high-risk information leakage incident quantity indicator and the incident response quantity indicator; The high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate are input into the target health scoring model, so that the target health scoring model calculates the health score based on the target weight and target interval value corresponding to each data indicator, and outputs the corresponding health score; wherein, ; A health label for the enterprise network security is determined based on a score level corresponding to the health score.
2. The network security health detection method according to claim 1, It is characterized in that The obtaining of the number of high-risk vulnerabilities, the number of high-risk port openings, and the number of high-risk information leakage incidents includes: Based on the preset technical indicator screening rules, high-risk vulnerability quantity indicators, high-risk port opening quantity indicators, and high-risk information leakage incident quantity indicators are screened out from the current technical indicators.
3. The network security health detection method according to claim 1, It is characterized in that The obtaining of the number of high-risk vulnerabilities, the number of high-risk port openings, and the number of high-risk information leakage incidents includes: Obtain indicators of the number of high-risk vulnerabilities, the number of high-risk ports open, and the number of high-risk information leakage incidents through active and / or passive methods.
4. The network security health detection method according to claim 1, It is characterized in that Before inputting the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into the target health scoring model, the method further includes: A policy update file is obtained, and based on the policy update file, the weight setting in the original health score model and the coefficient setting for interval value calculation are adjusted to generate a target health score model.
5. The network security health detection method according to claim 4, It is characterized in that Before obtaining the strategy update file, the method further includes: The target label data is input into the preset data fitting model so that the preset data fitting model uses a linear regression algorithm to calculate the weights and coefficients of interval value calculations of various data indicators for the target label data, and outputs a strategy update file containing the corresponding target weights of each data and the target coefficients of interval value calculations of each data indicator.
6. The network security health detection method according to claim 5, It is characterized in that Before inputting the target label data into the preset data fitting model, the method further includes: Sampling historical data, and performing a health level labeling operation on the historical data to obtain label data; The label data are scored to obtain target label data.
7. A network security health detection device, It is characterized in that include: The first indicator acquisition module is used to acquire the number indicator of high-risk vulnerabilities, the number indicator of open high-risk ports, and the number indicator of high-risk information leakage events; The second indicator acquisition module is used to classify the level of the event response number indicator to determine the event response number indicator corresponding to the level category; wherein, the event response number indicator is the total number indicator of the number indicator of high-risk vulnerabilities, the number indicator of open high-risk ports, and the number indicator of high-risk information leakage events; The closed-loop rate determination module is used to determine the closed-loop rate of the corresponding number indicators based on the number indicator of high-risk vulnerabilities, the number indicator of open high-risk ports, the number indicator of high-risk information leakage events, and the event response number indicator; The health scoring module is used to input the high-risk vulnerability quantity index, the high-risk port open quantity index, the high-risk information leakage event quantity index, the event response quantity index and the corresponding closed-loop rate into the target health scoring model, so that the target health scoring model calculates the health score based on the target weight and target interval value corresponding to each data indicator, and outputs the corresponding health score; wherein, ; The level determination module is used to determine the health label of the enterprise network security based on the score level corresponding to the health score.
8. An electronic device, Characterized in that, Comprising: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the network security health detection method according to any one of claims 1 to 6.
9. A computer-readable storage medium, Characterized in that, For storing a computer program; wherein, when the computer program is executed by a processor, the steps of the network security health detection method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method for calculating operation health degree of aircraft development project
CN102509021A
Network security situation analysis model and network security assessment method
CN109246153A