Network security risk assessment method and system based on permission acquisition probability reasoning
By generating user permission transformation graphs and inferring the probability of attackers gaining permissions, this approach solves the problems of high subjectivity and low automation in existing network security risk assessments, and enables quantitative assessment and management of network security risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ARMY ENG UNIV OF PLA
- Filing Date
- 2022-10-31
- Publication Date
- 2026-04-14
AI Technical Summary
Existing cybersecurity risk assessment methods are highly subjective and have a low degree of automation, making it difficult to accurately assess the level of cybersecurity protection.
By formally defining network topology information, vulnerability patch information, device hardware and software information, a user permission transformation graph is generated to infer the probability of attackers gaining permissions, and network security risks are calculated by combining security risk measurement indicators.
It enables quantitative assessment of cybersecurity risks, accurately reflects changes in cybersecurity protection status, and provides a basis for cybersecurity management decisions.
Smart Images

Figure CN115694986B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a network security risk assessment method and system based on probabilistic reasoning for access control, belonging to the field of communication network security technology. Background Technology
[0002] Cybersecurity risk assessment refers to the process of evaluating the security attributes of a network system and the information it processes, transmits, and stores, including confidentiality, integrity, and availability. Cybersecurity risk assessment is a commonly used proactive network defense technique. It can qualitatively or quantitatively measure the level of cybersecurity protection by identifying assets, vulnerabilities, and threats within the network, calculating the probability of various cybersecurity incidents and corresponding losses. Assets refer to information or resources of value to the organization; vulnerabilities refer to assets or weaknesses in assets that may be exploited by threats; and threats refer to potential causes of undesirable incidents that could harm the system or organization.
[0003] Traditional cybersecurity risk assessment methods suffer from problems such as high subjectivity, low automation, and high algorithm complexity. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a network security risk assessment method and system based on permission acquisition probability reasoning, so as to solve the problems of strong subjectivity and low degree of automation in the prior art of network security risk assessment.
[0005] To solve the above-mentioned technical problems, the present invention is implemented using the following solution:
[0006] This invention provides a network security risk assessment method based on probabilistic reasoning for permission acquisition, comprising:
[0007] Formalize the input network topology information, vulnerability patch information, device hardware and software information, and other basic information;
[0008] Extract network user permission information and permission dependency information, and combine them with formally defined network topology information, vulnerability patch information, device hardware and software information and other basic information to generate a user permission transformation graph.
[0009] Based on the user permission transformation graph, infer the probability of an attacker obtaining user permissions after several steps of attack, starting from the initial permissions.
[0010] Calculate and assess cybersecurity risks based on pre-established security risk metrics.
[0011] This invention also provides a network security risk assessment system based on probabilistic reasoning for permission acquisition, comprising:
[0012] The network security information definition module is used to formally define the input network topology information, vulnerability patch information, device hardware and software information, and other basic information.
[0013] The user permission transformation graph generation module is used to extract network user permission information and permission dependency information, and combine them with formally defined network topology information, vulnerability patch information, device hardware and software information and other basic information to generate a user permission transformation graph.
[0014] The user permission acquisition probability inference module is used to infer the probability of an attacker acquiring user permissions after several steps of attack, starting from the initial permissions, based on the user permission transformation graph.
[0015] The cybersecurity risk assessment module is used to calculate and assess cybersecurity risks based on pre-established security risk metrics.
[0016] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: First, this invention accurately describes the input network topology information, hardware and software deployment information, vulnerability information, and other basic information in a formalized manner. Then, it extracts network user permission information and permission dependency information, and constructs a user permission transformation graph by combining the importance of user permissions and the difficulty of vulnerability exploitation. Next, it continuously uses the user's existing permissions to infer the permissions the user may obtain next. Finally, it calculates the probability of an attacker obtaining various user permissions, thereby quantitatively assessing network risks. This invention can reasonably assess current network security risks based on basic network information, and network security indicators can effectively reflect changes in the state of network security protection. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a network security risk assessment method based on probabilistic reasoning for permission acquisition provided in an embodiment of the present invention.
[0018] Figure 2 This is an example of a user permission conversion diagram provided in an embodiment of the present invention;
[0019] Figure 3 This is a schematic diagram of the reasoning process for an actual permission acquisition probability vector provided in an embodiment of the present invention;
[0020] Figure 4 This is a schematic diagram of a network framework for an experimental topology environment provided in an embodiment of the present invention; Detailed Implementation
[0021] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.
[0022] Example 1:
[0023] This embodiment provides a network security risk assessment method based on probabilistic reasoning for permission acquisition, such as... Figure 1 As shown, its basic process is divided into three stages: security information modeling, user permission acquisition probability inference, and network security risk measurement.
[0024] In the security information modeling phase, the main task is to uniformly model network topology information, vulnerability patch information, device hardware and software information, and other basic information to form a corresponding user permission transformation diagram, thereby accurately representing the relationship between key permissions in the network attack path.
[0025] In the probabilistic reasoning stage for acquiring user permissions, the main task is to determine the probability of acquiring various user permissions starting from a specific initial user permission and going through a specific number of steps, based on the established user permission transformation graph.
[0026] In the cybersecurity risk measurement phase, the main task is to calculate and assess the target cybersecurity risks based on the discovered user privilege acquisition probability and the established security risk measurement indicators.
[0027] (a) Formal definition of network security information
[0028] The inputs for generating the user permission transformation graph mainly include network topology information, vulnerability patch information, device hardware and software information, and other basic information.
[0029] Network topology information mainly includes information such as network devices, network device interfaces, network topology, and network security policies. Network devices are represented by a set P = {p...} i}(1≤i≤PN) means that p i Let PN be the number of network devices, and let PN be the number of network devices; network device interfaces are represented by a set. It means that among them For network devices p i The j-th interface, N j For network devices p i The number of interfaces; the network topology is represented by an undirected graph GT = (T, ET), where the nodes in the graph are network device interfaces T, and the links in the graph are... This indicates the data flow relationship between nodes. This indicates that data can be stored on device p. u The m-th interface and device p on v Bidirectional flow occurs on the link between the nth interface on device p. u and equipment p v It can be the same device or physically adjacent devices; network security policies use the set S = {(e, R} e)}(e∈ET) represents, where e is the target link for which the security policy applies. This is the set of access control lists corresponding to the target link, where and For each device p u The m-th interface and device p on v The nth interface on, h i This represents the i-th piece of hardware or software. Indicates that the interface is allowed. Access deployed on the interface Above, by software and hardware h i The network services provided.
[0030] Vulnerability patch information mainly includes basic information such as vulnerability databases, patch databases, attack databases, and patch vulnerability fixes. The vulnerability database uses a set V = {v...} i}(1≤i≤VN) means that v i VN represents the number of vulnerabilities, and VN represents the number of vulnerabilities; the patch repository uses a set C = {c i}(1≤i≤CN) means that c i Let represent the i-th patch, and CN represent the number of patches. The attack library is represented by the set VA = {(v,k,m)} (v∈V), where v represents the vulnerability used in the attack, k represents the attack consequence, k∈{User,Root} indicates that after using this attack, ordinary user privileges or administrator privileges on the network device will be obtained, m represents the attack method, and m∈{Local,Remote} indicates that the attack is initiated locally or remotely. The patch vulnerability repair is represented by the set CV = {(c,v)} (c∈C; v∈V), where (c,v) indicates that installing patch c can repair vulnerability v.
[0031] Device hardware and software information includes hardware libraries, hardware and software vulnerabilities, device hardware and software information, and device patches. The hardware and software libraries are represented by a set H = {h...} i}(1≤i≤HN) means that h i H represents the i-th piece of hardware or software, and HN represents the number of pieces of hardware or software; hardware or software vulnerabilities are represented by sets. This indicates that vmin represents the minimum version number and vmax represents the maximum version number. Let (v, h, vmax, vmin) represent natural numbers. This indicates that when the version number of the hardware / software h is greater than or equal to vmin and less than or equal to vmax, the hardware / software h possesses vulnerability v. The device hardware / software uses a set... Let (t, h, vs) represent that hardware and software h are deployed on network device interface t, with version number vs; device patches are represented by the set PC = {(p, c)} (p ∈ P; c ∈ C), where (p, c) represents that patch c is installed on network device p.
[0032] Other basic information includes the importance of user permissions and the difficulty of exploiting the vulnerability. The importance of user permissions is expressed using a function. This indicates the importance of user permissions; information about the difficulty of exploiting the vulnerability is expressed using a function. This indicates the difficulty of exploiting the vulnerability; It represents a positive real number.
[0033] (ii) Generate a user permission transformation diagram
[0034] The user permission transformation graph can be formally represented as GP = (NP, EP, Γ, Λ, Ξ), which is a directed graph where NP is a set of nodes representing network permissions; EP = {np i ,np j )} is an edge assemblage, edge(np) i ,np j This indicates that the user has obtained permission np. i Afterwards, there is a certain probability of obtaining NP privileges. j ;Γ:NP→{User,Root} is a node type function, where User represents that the node type is ordinary user privileges, and Root represents that the node type is administrator privileges; The input is a measure of the importance of user permissions; Let Ξ(ep) be the dependency mapping function, where ep∈EP represents the strength of the permission dependency.
[0035] Figure 2 An example user permission transformation graph is provided. In this example, there are 8 network permissions: P1, P2, P3, ..., P8. Four of these permissions are ordinary user permissions (represented by ellipses), and the remaining four are administrator permissions (represented by boxes). The number inside each node indicates the importance of the permission corresponding to that node, while the number on each edge indicates the strength of the permission dependency relationship. The larger the number, the greater the probability of obtaining the permission corresponding to the endpoint node after obtaining the permission corresponding to the starting node. For example, the permission dependency strength of edge (P6, P7) is 30, while the permission dependency strength of edge (P4, P7) is 5. Therefore, it is easier to obtain P6 first and then P7 than to obtain P4 first and then P7.
[0036] The main steps in generating the user permission transformation graph are divided into three stages: node addition, device access relationship processing, and edge addition. In the node addition stage, nodes corresponding to user permissions and administrator permissions are added for each device in the network. In the device access relationship processing stage, the corresponding network access relationships are obtained based on the network topology and network security policies. In the edge addition stage, based on the vulnerability type, local privilege escalation vulnerabilities and remote privilege escalation vulnerabilities are distinguished. Combined with the device patch installation status, the dependencies between permissions are determined, and edges are added to the corresponding nodes. Then, the weights of the edges are adjusted according to the severity of the vulnerabilities to achieve a holistic representation of basic network security information.
[0037] Specifically: Input: set of network devices P, set of network device interfaces T, network topology GT, set of network security policies S, set of vulnerabilities V, set of patches C, set of hardware and software H, set of hardware and software vulnerability mappings VH, set of device hardware and software mappings TH, set of device patch mappings TC, user permission importance measurement function Exploitation difficulty metric function Determine the strength of the permission dependency relationship Ξ(ep); Output: User permission transformation graph gp.
[0038] The steps are as follows:
[0039] Step 1: Construct the user permission transformation graph gp = (NP, EP, Γ, Λ, Ξ), and set...
[0040] Step 2: For each network device p∈P, add two nodes pUser and pRoot in gp, corresponding to the user permissions and administrator permissions of device p respectively, i.e. NP=NP∪pUser∪PRoot, and then set Γ(pUser)=User, Γ(pRoot)=Root and Λ(pUser)=0, Λ(pRoot)=0;
[0041] Step 3: Proceed to Step 2 to process the next network device, until all network devices have been processed, then proceed to Step 4;
[0042] Step 4: Based on the network topology GT and network security policy S, obtain the access relationships between devices and store them as a set PLINK = {(p m ,p n ,h i )} indicates that through network device p m Able to access network device p n Software and hardware deployed on h i Services provided;
[0043] Step 5: For each network device p∈P, find its deployed hardware and software and corresponding version number in the set TH, denoted as PH. Then, for each element (h', vs) in PH, according to the conditions h=h', vs≤vmax and vmin≤vs, find the corresponding vulnerability in the set VH. Finally, for each vulnerability v, count its corresponding asset set h* to form the vulnerability asset corresponding set PV={(p,v,h*)}.
[0044] Step 6: Find the patch installed on network device p in set PC, and denote it as FC. Then, for each patch c' in FC, find the vulnerability v that can be fixed in set CV according to the condition c = c'. All the found vulnerabilities form set FV.
[0045] Step 7: For each element (p, v, h*) in PV, if v exists in set FV, remove it from PV. Repeat this process until all elements in PV have been processed.
[0046] Step 8: For each element (p,v,h*) in PV, find the attack type k and attack method m corresponding to vulnerability v in VA, and form a quintuple (p,v,k,m,h*).
[0047] Step 9: For each quintuple (p, v, k, m, h*), when k = Root and m = Local, find the nodes corresponding to the User and Root permissions of device p in gp, and denote them as ns and nt respectively. If Then add an edge from node ns to node nt and set Ξ((ns,nt))=Γ(v); otherwise Ξ((ns,nt))=Ξ((ns,nt))+Γ(v);
[0048] Step 10: For each quintuple (p, v, k, m, h*), when k = User and m = Remote, for each element (p) in the set PLINK m ,p n ,h k If p n =p and h k If ∈h*, then look up device p in gp. m The nodes corresponding to root privileges and user privileges on network device p are denoted as ns and nt, respectively. If Then add an edge from node ns to node nt and set Ξ((ns,nt))=Γ(v); otherwise Ξ((ns,nt))=Ξ((ns,nt))+Γ(v); repeat this process until all elements in PLINK have been processed.
[0049] Step 11: For each quintuple (p, v, k, m, h*), when k = Root and m = Remote, for each element (p, v, k, m, h*) in the set PLINK... m ,p n ,h k If p n =p and h k If ∈h*, then look up device p in gp. m The nodes corresponding to root privileges for the device and the network device p are denoted as ns and nt, respectively. If Then add an edge from node ns to node nt and set Ξ((ns,nt))=Γ(v); otherwise Ξ((ns,nt))=Ξ((ns,nt))+Γ(v); repeat this process until all elements in PLINK have been processed.
[0050] Step 12: Proceed to Step 8 to process the next element in PV, until all elements have been processed.
[0051] It should be noted that ns and nt in steps 9 to 11 above are only used as temporary definitions or markers.
[0052] III) Probability Reasoning for User Permission Acquisition
[0053] In the network attack path discovery phase, two concepts are introduced: attacker initial privileges and attacker final privileges. Attacker initial privileges refer to the probability that the attacker possesses various privileges under initial conditions. It can be obtained using the initial privilege probability vector I = (I1, I2, ..., I...). i ,…,I 2*PN ) indicates that I i Let A be the probability that an attacker gains the i-th privilege initially. Since each network device involves both user and administrator privileges, the vector dimension is 2*PN, where PN is the number of network devices. The attacker's final privileges refer to the probabilities of various privileges the attacker possesses after several attack steps. This can be represented by the actual privilege acquisition probability vector A = (A1, A2, ..., A...). i ,…,A 2*PN ) indicates that A i This is the probability that the attacker obtains the i-th permission at this point.
[0054] The key to calculating cybersecurity risks lies in inferring the probability vector A of actual privilege acquisition from an initial privilege acquisition probability vector I. This process can be mainly divided into three steps, such as... Figure 3 As shown.
[0055] The actual permission acquisition probability vector reasoning process mainly consists of three stages: user permission transformation graph initialization, user permission transformation graph reasoning, and actual permission acquisition probability vector generation. The basic idea is to generate multiple user permission transformation graphs based on the number of non-zero components in the initial permission probability vector. Initially, each user permission transformation graph is initialized with only one non-zero component, setting the permission acquisition probability of its corresponding node. Then, the next permission to be obtained is selected based on the permission dependency strength of each possible edge. For each attack, the original permission acquisition probability is discounted by a certain proportion until the maximum number of iterations is reached. After iteration, the permission acquisition probabilities of corresponding nodes on all user permission transformation graphs are accumulated, and the corresponding components of the actual permission acquisition probability vector are set, thus completing the calculation of the actual permission acquisition probability vector.
[0056] In the user permission transformation graph initialization phase, multiple user permission transformation graphs are created primarily using the initial permission acquisition probability vector, laying the foundation for later inference. Specifically, firstly, based on the number of non-zero elements in the initial permission acquisition probability vector I, a corresponding number of user permission transformation graphs are generated. Then, on each graph, only the node corresponding to a single non-zero component in I is assigned a permission acquisition probability, while the permission acquisition probability for all other nodes on that user permission transformation graph is set to 0. For example, in... Figure 3 Since the initial permission acquisition probability vector I has four non-zero components, four different user permission transformation graphs are generated. In the first graph, only the permission acquisition probability corresponding to node P1 is set to 0.4, while the permission acquisition probabilities corresponding to other nodes are all set to 0. The other user permission transformation graphs are set sequentially.
[0057] In the user permission transformation graph reasoning phase, the main process involves continuously and autonomously selecting the next attack permission on each user permission transformation graph generated for a corresponding number of iterations, based on a predefined attack threshold and maximum number of iterations, and adjusting the node permission acquisition probability in real time. Specifically, on each user permission transformation graph generated for a corresponding number of iterations, all edges pointing from nodes with a permission acquisition probability greater than 0 to nodes with a permission acquisition probability equal to 0 are found, forming a set cEdge. Then, the sum of the permission dependency strengths of all edges in cEdge is calculated, denoted as intension. Next, an integer r is randomly selected from the interval [0, Threshold]. If r is less than intension, then from all edges in cEdge, an edge is selected according to the permission dependency strength of each edge, based on probability. When edge (s k ,t k Once selected, update node t. k The probability of obtaining node permissions is Φ k (s k )*γ and The smaller of the two values, the former simulates the execution process of a one-step attack, while the latter ensures that the cumulative probability of obtaining permissions for the same node on all user permission transformation graphs does not exceed 1; if r is not less than intension, the attack is not executed in this iteration. After all user permission transformation graphs have undergone one iteration, the discount coefficient γ is updated to γ. 2 The iterative steps are repeated and γ is updated cyclically. 2 Until the maximum number of iterations MaxIter; where Threshold is the attack threshold, (s k ,t k ) represents an edge in the user permission transformation graph generated for the k-th corresponding number of edges, Φ k (s k ) and Φ k (t k ) represent nodes s in the user permission transformation graph generated for the kth corresponding quantity. k and t k The probability of obtaining permissions and Φ k (s k )>0,Φ k (t k ) = 0, γ (0 < γ < 1) is the discount factor, 1 ≤ k ≤ 2 * PN, and PN is the number of network devices.
[0058] In the actual permission acquisition probability vector generation stage, multiple user permission transformation graphs generated with corresponding quantities after iteration are merged to generate the final actual permission acquisition probability vector. Specifically, the permission acquisition probabilities of the same node in all user permission transformation graphs generated with corresponding quantities are summed to form the corresponding component in the actual permission acquisition probability vector A.
[0059] Specifically, input: the current user permission transformation graph set GP = {gp i}(1≤i≤N), where gp i =(NP i ,EP i ,Γ i ,Λ i ,Ξ i N is the number of current user permission transformation graphs; the set of current network permission acquisition probability mapping functions Φ = {Φ i}, where the function Represents the graph gp i The current permission acquisition probability of each node; attack threshold Threshold; maximum number of iterations MaxIter; discount factor γ; output: actual permission probability vector A = (A1, A2, ..., A i ,…,A 2*PN ).
[0060] IV) Cybersecurity Risk Assessment
[0061] Cybersecurity risk measurement indicators: Combining user permission transformation graphs and the relevant definitions of attacker permissions, we can find that asset value can be represented by the sensitivity of permissions; the higher the asset value, the more sensitive the corresponding permissions, because the greater the harm that can be caused by launching an attack after obtaining those permissions. Threat frequency can be represented by the distribution of attacker's initial permissions; the lower the frequency of threats, the lower the probability that the attacker initially possesses the corresponding permissions. Network security risk can be measured by the weighted average probability of an attacker obtaining sensitive permissions under different initial states, i.e.:
[0062]
[0063] Where PI represents the set of initial permission acquisition probability vectors, and each initial permission acquisition probability vector I in the set represents a different initial state; |PI| is the size of the set PI; n i It is the i-th node in the user permission transformation graph, Λ(n) i ) represents the node's sensitivity; A is the actual permission acquisition probability vector corresponding to the initial permission acquisition probability vector I. i It is the i-th component of A, indicating that after several attack steps, the attacker owns node n. i The probability of the corresponding permission, where PN is the number of network devices;
[0064] Based on formula (1), the current network security risks are calculated and assessed.
[0065] Example 2:
[0066] This embodiment provides a network security risk assessment system based on probabilistic reasoning for permission acquisition, including:
[0067] The network security information definition module is used to formally define the input network topology information, vulnerability patch information, device hardware and software information, and other basic information.
[0068] The user permission transformation graph generation module is used to extract network user permission information and permission dependency information, and combine them with formally defined network topology information, vulnerability patch information, device hardware and software information and other basic information to generate a user permission transformation graph.
[0069] The user permission acquisition probability inference module is used to infer the probability of an attacker acquiring user permissions after several steps of attack, starting from the initial permissions, based on the user permission transformation graph.
[0070] The cybersecurity risk assessment module is used to calculate and assess cybersecurity risks based on pre-established security risk metrics.
[0071] It should be noted that those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the system, module, device or unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0072] To verify the effectiveness of this invention, based on a company's actual network, the corresponding network hardware and software information and topology information were extracted. The basic topology of the experimental environment is as follows: Figure 4 As shown, this experimental environment consists of three parts: an external network, an internal network, and a demilitarized zone. The external network equipment includes an external network switch, an external network server 1, and an external network server 2. The internal network equipment includes user terminal 1, user terminal 2, user terminal 3, a user switch, a user router, and a firewall. The demilitarized zone includes a demilitarized zone switch, a database server, a web server, and an FTP server.
[0073] Different devices have different software and hardware systems installed, and their basic information is shown in Table 1.
[0074] Table 1 Network Equipment Hardware and Software Systems
[0075]
[0076]
[0077] Relying on Figure 4 Experiments were conducted using simulated networks to compare the effects of different network security strategies on network security risk indicators. Three simulated environments were created: Environment 1 had no security protection policies added to the firewall and router; Environment 2 added corresponding security protection policies only to the firewall to ensure all services were properly protected; Environment 3 added corresponding security protection policies not only to the firewall but also to the router to achieve mutual isolation between users and servers. The network security risk indicators for each environment are shown in Table 2.
[0078] Table 2. Cybersecurity Risk Indicators under Different Security Protection Strategies
[0079] Serial Number environment Safety risk indicators 1 Environment 1 0.422 2 Environment 2 0.827 3 Environment 3 0.910
[0080] Experiments in simulated environments reveal that the network security risk assessment method based on probabilistic reasoning for access control can effectively assess the current network security risks, and the security risk metrics can effectively represent the magnitude of the current network security risk. Data in Table 1 shows that the network security risk assessment metrics are highly sensitive to network security configuration. The security risk metrics in Environment 1 are significantly higher than those in Environments 2 and 3, while Environment 3 is slightly higher than Environment 2. This aligns with theoretical analysis: when no security policies are implemented in the network, its security risk increases significantly, while appropriately implementing network security policies can effectively reduce network security risks.
[0081] In summary, this invention proposes a network security risk assessment method and system based on probabilistic reasoning of access control. It models and quantifies network vulnerabilities and risks, providing network security managers with direction for network maintenance and hardening decisions. The method uses data derived from knowledge reasoning as its basis, employs a generated network access control transformation graph as the carrier for calculating security risks, and statistically simulates attack routes based on randomly selected attack targets to calculate network security risk assessment values. Furthermore, the effectiveness of the method is verified by comparing the risk values under different configurations within the same network.
[0082] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0083] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0084] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0085] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0086] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.
Claims
1. A network security risk assessment method based on probabilistic reasoning for access control, characterized in that, include: Formalize the input network topology information, vulnerability patch information, device hardware and software information, and other basic information; Extract network user permission information and permission dependency information, and combine them with formally defined network topology information, vulnerability patch information, device hardware and software information and other basic information to generate a user permission transformation graph. Based on the user permission transformation graph, infer the probability of an attacker obtaining user permissions after several steps of attack, starting from the initial permissions. Calculate and assess cybersecurity risks based on pre-established security risk metrics; The network topology information includes network devices, network device interfaces, network topology, and network security policies; the vulnerability patch information includes vulnerability libraries, patch libraries, attack libraries, and patch vulnerability fixes; the device hardware and software information includes hardware and software libraries, hardware and software vulnerabilities, device hardware and software, and device patches; the other basic information includes user permission importance information and vulnerability exploitation difficulty information; and the generation of the user permission transformation graph includes: Add nodes corresponding to both regular user privileges and administrator privileges for each network device; Based on the network topology and network security policies, the access relationships between network devices are obtained; Based on the vulnerability type, local privilege escalation vulnerabilities and remote privilege escalation vulnerabilities are distinguished. The dependency relationship between network permissions is determined by combining the network device patch installation status. Edges are added between corresponding nodes, and the strength of the permission dependency relationship of the edges is adjusted according to the severity of the vulnerability to generate a user permission transformation graph. The attacker's initial privileges are obtained using an initial privilege acquisition probability vector. This indicates that the probability of an attacker gaining user privileges after several attack steps is represented by the actual privilege gain probability vector. express, To allow the attacker to obtain the first in the initial situation The probability of each permission. At this point, the attacker obtains the... The probability of each permission. The number of network devices; The inference of the probability of an attacker acquiring user permissions after several attack steps, starting from initial permissions, based on the user permission transformation graph includes: Based on the number of non-zero components in the probability vector obtained from the initial permissions, generate a corresponding number of user permission transformation graphs; In each user permission conversion graph generated for a corresponding number of times, based on the preset attack threshold and maximum number of iterations, the system continuously and autonomously selects the next attack permission and adjusts the permission acquisition probability corresponding to the node in real time. The user permission transformation graphs generated after the iteration are merged to generate the actual permission acquisition probability vector.
2. The network security risk assessment method based on permission acquisition probabilistic reasoning according to claim 1, characterized in that, Network devices adopt a cluster It means that among them For the first One network device, The number of network devices; network device interfaces use a set. It means that among them For network equipment The One interface, For network equipment The number of interfaces; the network topology uses an undirected graph. This indicates that the nodes in the diagram represent network device interfaces. The links in the diagram This indicates the data flow relationship between nodes. This indicates that data can be stored on the device. The first Interfaces and devices The first Bidirectional flow occurs on the links between interfaces; network security strategies employ a set... It means that among them The target link for which security policies are applied. This is the set of access control lists corresponding to the target link, where and respectively equipment The first Interfaces and devices The first One interface, Indicates the first Hardware and software, Indicates that the interface is allowed. Access deployed on the interface Above, by hardware and software The network services provided; The vulnerability database uses a collection It means that among them Indicates the first A vulnerability, The number of vulnerabilities; the patch library uses a collection. It means that among them Indicates the first One patch, The number of patches; the attack library uses a set. It means that among them This indicates the vulnerability used in the attack. Indicates the consequences of the attack. This indicates that after launching an attack using this method, ordinary user privileges or administrator privileges will be obtained on network devices. Indicates the method of attack. This indicates whether the attack was initiated locally or remotely; patch vulnerabilities are fixed using a collection approach. It means that among them Indicates the installation of patches Able to fix vulnerabilities ; Software and hardware libraries adopt a collection It means that among them Indicates the first Hardware and software, The number of hardware and software components; hardware and software vulnerabilities are handled in sets. It means that among them Indicates the minimum version number. Indicates the maximum version number. Represents natural numbers, Indicates when software and hardware The version number is greater than or equal to and less than or equal to At that time, hardware and software Vulnerable The equipment's hardware and software adopt an integrated approach. It means that among them Indicated at network device interface Software and hardware were deployed on it Its version number is Device patch collection It means that among them Indicates network device Patch installed ; User permission importance information is used in a function. This indicates the importance of user permissions; information about the difficulty of exploiting the vulnerability is expressed using a function. This indicates the difficulty of exploiting the vulnerability; It represents a positive real number.
3. The network security risk assessment method based on permission acquisition probabilistic reasoning according to claim 2, characterized in that, The user permission transformation graph is a directed graph. It means that among them It is a set of nodes representing network permissions; It is the combination of edges, edges This indicates that the user has obtained permission. Afterwards, there will be a chance to obtain further permissions. ; Functions for node types, This indicates that the type corresponding to this node is ordinary user permissions. This indicates that the node type has administrator privileges; The input is a measure of the importance of user permissions; For dependency mapping functions, Indicates the strength of permission dependencies; It represents a positive real number.
4. The network security risk assessment method based on permission acquisition probabilistic reasoning according to claim 1, characterized in that, The step of adding nodes corresponding to both regular user privileges and administrator privileges to all network devices includes: For network equipment Add corresponding network devices to the user permission transformation graph. Two nodes with ordinary user permissions and administrator permissions and and set , ,as well as and The value; The process of obtaining access relationships between network devices based on network topology and network security policies includes: According to network topology and cybersecurity strategies Obtain the access relationships between network devices and store them as a set. This indicates that through network devices Able to access network devices Software and hardware deployed on Services provided; The process involves differentiating between local and remote privilege escalation vulnerabilities based on vulnerability type, determining network permission dependencies based on network device patch installation status, adding edges between corresponding nodes, and adjusting the strength of permission dependencies on the edges according to the severity of the vulnerability to generate a user permission transformation graph, including: For network equipment In the set Locate the deployed software and hardware and their corresponding version numbers, and denote them as follows: ;right Each element According to the conditions , and In the set Search for the corresponding vulnerability in the middle. To compile a list of assets corresponding to all identified vulnerabilities. Generate a set of vulnerability assets. ; In the set Find network devices The installed patch is denoted as ;right Each patch In the set According to the conditions Find the vulnerabilities that can be fixed. All the vulnerabilities found are compiled into a set. ; for Each element in ,like In the set If it exists in the middle, then remove it from the middle. Delete; for Each element in In the set Find vulnerabilities in Corresponding attack types and attack methods , forming a quintuple ; for Each element in The quintuple ,when and At that time, locate the network device in the user permission transformation graph. of Permissions and The nodes corresponding to the permissions are respectively denoted as and ,like Then add a node Pointing to node The edge and set ,otherwise ;when and When, for a set Each element ,like and Then find the device in the user permission transformation graph. of Permissions and network devices of The nodes corresponding to the permissions are respectively denoted as and ,like Then add a node Pointing to node The edge and set ,otherwise ;when and When, for a set Each element ,like and Then find the device in the user permission transformation graph. of Permissions and network devices of The nodes corresponding to the permissions are respectively denoted as and ,like Then add a node Pointing to node The edge and set ,otherwise .
5. The network security risk assessment method based on permission acquisition probabilistic reasoning according to claim 1, characterized in that, The step of obtaining the number of non-zero components in the probability vector based on the initial permissions and generating a corresponding number of user permission transformation graphs further includes: For each user permission transformation graph generated with a corresponding number of nodes, set the permission acquisition probability for each node corresponding to a non-zero component, and set the permission acquisition probability of the remaining nodes in each user permission transformation graph generated with a corresponding number of nodes to 0. In each user permission conversion graph generated for a corresponding number of iterations, based on a preset attack threshold and maximum iteration count, the system continuously and autonomously selects the next attack permission and adjusts the permission acquisition probability of nodes in real time, including: In each user permission transformation graph generated for a corresponding number of nodes, a set is formed by connecting all edges from nodes with a permission acquisition probability greater than 0 to nodes with a permission acquisition probability equal to 0. and calculate The sum of the permission dependency strengths of all edges in the middle ; In the interval [0, Randomly select an integer from [the data]. ,like Less than Then in Of all the edges, select one edge based on the strength of the edge's permission dependency relationship. and update the edges Corresponding node The probability of obtaining permission is and The smaller value in; if Not less than If the attack fails, the attack will not be executed in this iteration. Iterate and update repeatedly for until the maximum number of iterations. ; in, Attack threshold Indicates the first The edges in the user permission conversion graph generated corresponding to the number of Zhangs. and They represent the first Nodes in the user permission conversion graph generated corresponding to the number of Zhang and The probability of obtaining permissions and , , This is the discount factor. , The number of network devices; The process of merging the corresponding number of user permission transformation graphs generated after iteration to generate an actual permission acquisition probability vector includes: After the iteration is completed, the probability of obtaining the corresponding number of user permissions generated in the transformation graph is accumulated to generate the corresponding component in the actual permission acquisition probability vector.
6. The network security risk assessment method based on permission acquisition probabilistic reasoning according to claim 1, characterized in that, The pre-established security risk measurement index is: ; in, This represents the set of initial permission acquisition probability vectors, where each initial permission acquisition probability vector in the set... Indicates different initial states; For set Size; It is the first in the user permission transformation graph. 1 node Indicates the sensitivity of the node; Obtain the probability vector for initial permissions The corresponding probability vector of actual permission acquisition. yes The Each component represents the number of nodes the attacker possesses after several attack steps. The probability of the corresponding permissions. This refers to the number of network devices.
7. A network security risk assessment system based on probabilistic reasoning for access control, characterized in that, include: The network security information definition module is used to formally define the input network topology information, vulnerability patch information, device hardware and software information, and other basic information. The user permission transformation graph generation module is used to extract network user permission information and permission dependency information, and combine them with formally defined network topology information, vulnerability patch information, device hardware and software information and other basic information to generate a user permission transformation graph. The user permission acquisition probability inference module is used to infer the probability of an attacker acquiring user permissions after several steps of attack, starting from the initial permissions, based on the user permission transformation graph. The cybersecurity risk assessment module is used to calculate and assess cybersecurity risks based on pre-established security risk metrics. The network topology information includes network devices, network device interfaces, network topology, and network security policies; the vulnerability patch information includes vulnerability libraries, patch libraries, attack libraries, and patch vulnerability fixes; the device hardware and software information includes hardware and software libraries, hardware and software vulnerabilities, device hardware and software, and device patches; the other basic information includes user permission importance information and vulnerability exploitation difficulty information; and the generation of the user permission transformation graph includes: Add nodes corresponding to both regular user privileges and administrator privileges for each network device; Based on the network topology and network security policies, the access relationships between network devices are obtained; Based on the vulnerability type, local privilege escalation vulnerabilities and remote privilege escalation vulnerabilities are distinguished. The dependency relationship between network permissions is determined by combining the network device patch installation status. Edges are added between corresponding nodes, and the strength of the permission dependency relationship of the edges is adjusted according to the severity of the vulnerability to generate a user permission transformation graph. The attacker's initial privileges are obtained using an initial privilege acquisition probability vector. This indicates that the probability of an attacker gaining user privileges after several attack steps is represented by the actual privilege gain probability vector. express, To allow the attacker to obtain the first in the initial situation The probability of each permission. At this point, the attacker obtains the... The probability of each permission. The number of network devices; The inference of the probability of an attacker acquiring user permissions after several attack steps, starting from initial permissions, based on the user permission transformation graph includes: Based on the number of non-zero components in the probability vector obtained from the initial permissions, generate a corresponding number of user permission transformation graphs; In each user permission conversion graph generated for a corresponding number of times, based on the preset attack threshold and maximum number of iterations, the system continuously and autonomously selects the next attack permission and adjusts the permission acquisition probability corresponding to the node in real time. The user permission transformation graphs generated after the iteration are merged to generate the actual permission acquisition probability vector.