An Evaluation Method for Vulnerabilities in Industrial Internet of Things

By obtaining user usage records in the industrial Internet of Things and evaluating the impact of vulnerabilities and generating vulnerabilities lists, it solves the problem that users find it difficult to evaluate and deal with industrial Internet of Things vulnerabilities, and improves system security.

CN115883171BActive Publication Date: 2025-06-27SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211496160.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-06-27
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

In the prior art, vulnerability information in the industrial Internet of Things is complicated, and some users fail to effectively repair or protect, resulting in security risks.

Method used

By obtaining the user's subjective usage records or plans, calculate the usage preference value of each object, and objectively weighted evaluation of the existing vulnerabilities of the system to generate a list of system vulnerabilities based on preferences.

Benefits of technology

It effectively evaluates the impact and harm of vulnerabilities on the user's system use, and provides a reference tool for industrial Internet security gateways or vulnerability protection systems to protect or repair system systems, reducing security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883171B_ABST
    Figure CN115883171B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for evaluating vulnerabilities in the industrial Internet of Things, including: obtaining the usage preference value of each object according to the user's subjective usage record or plan; objectively weighting and evaluating the existing vulnerabilities in the system according to the usage preference value; and obtaining a preference-based system vulnerability list based on the usage preference value and the result of the objective weighting and evaluation. The beneficial effects of the present invention are as follows: It provides a reference for the industrial Internet security gateway or vulnerability protection system to protect the system or repair vulnerabilities, preventing potential safety hazards caused by users ignoring the repair or protection of dangerous vulnerabilities due to their lack of understanding of the impact of relevant system vulnerabilities on their own usage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and more specifically, to a method for evaluating vulnerabilities in industrial Internet of Things. Background Art

[0002] Industrial Internet of Things combines various information sensing devices, such as radio frequency identification devices, infrared sensors, global positioning systems, laser scanners, and even servers, personal mobile terminals such as personal mobile phones / smart watches / smart earphones, etc. Its purpose is to connect all items to the network for convenient identification. Therefore, vulnerabilities in current industrial Internet and Internet of Things have become the main targets of hackers. The usage levels of various devices in industrial Internet of Things are different, and the impacts of related vulnerabilities on users also vary according to usage preferences.

[0003] Due to the complexity of vulnerability information, some users do not repair or protect all vulnerabilities, which poses a considerable security risk. Therefore, a method is needed to determine the impacts and harm levels of various vulnerabilities on users' system usage according to their own usage and preference situations, for reference by industrial Internet security gateways or vulnerability protection systems for system protection or vulnerability repair. Summary of the Invention

[0004] The present invention provides a method for evaluating vulnerabilities in industrial Internet of Things, which solves the problem that existing vulnerability information is complex and some users do not repair or protect all vulnerabilities, thus causing security risks.

[0005] To solve the above problems, on the one hand, the present invention provides a method for evaluating vulnerabilities in industrial Internet of Things, including:

[0006] Obtaining the usage preference value of each object for the user according to the user's subjective usage record or plan;

[0007] Objectively weighting and evaluating the existing vulnerabilities in the system according to the usage preference value;

[0008] Obtaining a preference-based system vulnerability list based on the usage preference value and the result of objective weighted evaluation.

[0009] The object includes applications, software, and devices.

[0010] The obtaining the usage preference value of each object for the user according to the user's subjective usage record or plan includes:

[0011] Counting the frequency of each object being used in the system historical record or future plan;

[0012] Counting the duration of each object being used in the system historical record or future plan;

[0013] Calculate the duration from the closest activation time of each object in the future plan of the statistical system to the current moment;

[0014] Let the weight of the frequency of use of any object be w fre , and the weight of the duration of use be w dur , and the weight of the duration from the closest activation time to the current moment be w val , then its usage preference value in the system is:

[0015] P i =re i * fre +ur i * dur +al i * val

[0016] Among them, P i is the usage preference value of the object, fre i is the frequency of use of the object, dur i is the duration of use of the object, val i is the duration from the closest activation time of the object to the current moment;

[0017] Arrange all objects in the system in descending order according to the preference value to obtain the usage preference list.

[0018] The objective weighted evaluation of the existing vulnerabilities in the system according to the usage preference value includes:

[0019] Evaluate confidentiality to determine the confidentiality value;

[0020] Evaluate integrity to determine the integrity value;

[0021] Evaluate availability to determine the availability value;

[0022] Set the confidentiality weight, integrity weight and availability weight;

[0023] Calculate the evaluation value of any object in the usage preference list as:

[0024] E i =ec i * sec +nt i * int +se i * use

[0025] Among them, E i is the evaluation value of the object, sec i is the confidentiality value of the object, int iTake the integrity value for the object, use i Take the availability value for the object, w sec Is the confidentiality weight, w int Is the integrity weight, w use Is the availability weight.

[0026] The evaluation of the confidentiality to determine the confidentiality value includes:

[0027] If the exploitation of the vulnerability does not affect the confidentiality of any object in the usage preference list, then determine that the confidentiality value is the first preset value;

[0028] If the exploitation of the vulnerability can access some unauthorized information in any object in the usage preference list, resulting in the leakage of confidential information, then determine that the confidentiality value is the second preset value;

[0029] If the exploitation of the vulnerability can completely control and access any object in the usage preference list, then determine that the confidentiality value is the third preset value.

[0030] The evaluation of the integrity to determine the integrity value includes:

[0031] If the exploitation of the vulnerability does not affect the integrity of any object in the usage preference list, then determine that the integrity value is the first preset value;

[0032] If the exploitation of the vulnerability may modify some file configurations and information in any object in the usage preference list, and no control is obtained or only the file configurations and information can be modified within a limited range, then determine that the integrity value is the second preset value;

[0033] If the exploitation of the vulnerability can modify any file configurations and information of any object in the usage preference list, then determine that the integrity value is the third preset value.

[0034] The evaluation of the availability to determine the availability value includes:

[0035] If the exploitation of the vulnerability has no impact on the availability of any object in the usage preference list, then determine that the availability value is the first preset value;

[0036] If the exploitation of the vulnerability may cause a performance degradation or interruption in the availability aspect of any object in the usage preference list, then determine that the availability value is the second preset value;

[0037] If the exploitation of the vulnerability can cause any object in the usage preference list to be completely unavailable, then determine that the availability value is the third preset value.

[0038] The objective weighted evaluation of the existing vulnerabilities in the system according to the usage preference value also includes:

[0039] Vulnerabilities and their information are discovered through vulnerability scanning.

[0040] The preference-based system vulnerability list obtained based on the results of using preference values and objective weighted evaluation includes:

[0041] Set that there are n types of objects in the usage preference list, and set the weight of the usage preference value of any object to w p , and the weight of the evaluation value of the vulnerability for any object in the usage preference list has been obtained as w e ;

[0042] Calculate the impact evaluation value of the vulnerability on usage:

[0043]

[0044] Sort all the impact evaluation values of the vulnerabilities on usage in descending order to obtain a preference-based system vulnerability list.

[0045] On the one hand, a computer-readable storage medium is provided, in which multiple instructions are stored, and the instructions are suitable for being loaded by a processor to execute the above-mentioned method for evaluating industrial Internet of Things vulnerabilities.

[0046] The beneficial effects of the present invention are as follows: By summarizing the subjective usage records and plans of the system, and scoring the usage record items through weighted rules, a usage preference list of the system is obtained. The existing vulnerabilities of the system are objectively weighted and evaluated from the perspective of usage preferences to obtain a preference-based system vulnerability list, which can be used as a reference for the industrial Internet security gateway or vulnerability protection system to protect the system or repair vulnerabilities, preventing potential safety hazards caused by users ignoring the repair or protection of dangerous vulnerabilities due to their lack of understanding of the impact of relevant system vulnerabilities on their own usage. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0048] Figure 1 is a flowchart of a method for evaluating industrial Internet of Things vulnerabilities provided by an embodiment of the present invention;

[0049] Figure 2 is a block diagram of a method for evaluating industrial Internet of Things vulnerabilities provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.

[0051] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more features. In the description of the present invention, "a plurality" means two or more, unless otherwise specifically defined.

[0052] In the present invention, the term "exemplary" is used to mean "serving as an example, illustration, or explanation". Any embodiment described as "exemplary" in the present invention is not necessarily to be construed as more preferred or more advantageous than other embodiments. In order for any person skilled in the art to implement and use the present invention, the following description is given. In the following description, details are set forth for the purpose of explanation. It should be understood that those of ordinary skill in the art can recognize that the present invention can be implemented without the use of these specific details. In other instances, well-known structures and processes are not described in detail to avoid unnecessary details from obscuring the description of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.

[0053] The present invention summarizes the subjective usage records and plans of the system (including but not limited to the historical usage records and future possible usage plans of workshop equipment, sensors, website servers, personal computers, mobile phone terminals, applications or software in the industrial Internet of Things, smart home appliances, etc.), scores the usage record items through weighting rules (including but not limited to weighting and evaluating from the perspectives of the usage duration, usage frequency, historical last usage time, future nearest planned usage time, historical usage and future usage plans of each device in the workshop within the industrial Internet, etc.), obtains the usage preference list of the system, objectively weights and evaluates the existing vulnerabilities of the system from the perspective of usage preferences (evaluates the impacts on the integrity, confidentiality, and availability of the devices / applications / software in the system in the preference list), and obtains the system vulnerability list based on preferences for reference by the industrial Internet security gateway or vulnerability protection system for system protection or vulnerability repair.

[0054] See Figure 1 , Figure 1 FIG. is a flowchart of a method for evaluating industrial Internet of Things vulnerabilities provided by an embodiment of the present invention. The method for evaluating industrial Internet of Things vulnerabilities includes S1 - S3:

[0055] S1. Obtain the usage preference value of each object for the user according to the subjective usage record or plan of the user; the objects include applications, software, and devices.

[0056] In this embodiment, summarize the user usage preference list according to the subjective usage record or plan (data such as usage frequency, usage duration, and nearest planned usage time) through rules.

[0057] Step S1 includes steps S11 - S15:

[0058] S11. Count the usage frequency of each object in the system historical record or future plan.

[0059] In this embodiment, count the usage frequency fre of a certain application / software / device, etc. in the system historical record or future plan. The higher the usage frequency, the higher the value of fre according to certain rules (for example, if it is known from the records in the past 3 months that a certain application is used on average once a week, it can be stipulated that its fre = 1, and it is stipulated that for each additional usage time per week of other applications, fre increases by 10%. If it is used once every 2 weeks, then fre = 0.5, and if it is used once every 3 weeks, then fre = 0.3...). Its preference weight parameter is w fre (0 ≤ w fre ≤ 1).

[0060] S12. Count the usage duration of each object in the system historical record or future plan.

[0061] In this embodiment, the duration dur of the use of an application / software / device, etc. in the historical records or future plans of the statistical system is counted. The higher the usage duration, the higher the value of dur according to certain rules (for example, if a workshop device is used for an average of 1 hour per day in the next 2 weeks, its dur can be specified as 1, and it is stipulated that for each additional 1 hour of daily usage duration of other devices, dur increases by 10%. If it is used for 1 hour every 2 days, then dur = 0.5; if it is used for 1 hour every 3 days, then dur = 0.3...). Its preference weight parameter is w dur (0 ≤ w dur ≤ 1).

[0062] S13. Count the duration from the closest activation time of each object in the future plan of the statistical system to the current moment.

[0063] In this embodiment, the duration val from the closest activation time of an application / software / device, etc. in the future plan of the statistical system to the current moment. The closer to the current moment, the higher the value of val according to certain rules (for example, if a device will be activated in the next 1 hour, its val can be specified as 1, and it is stipulated that for each 10 - minute advance in the activation time of other devices, val increases by 10%, and for each 1 - hour delay in the activation time, val decreases by 10%). Its preference weight parameter is w val (0 ≤ w val ≤ 1).

[0064] S14. Let the weight of the frequency of use of any object be w fre , the weight of the duration of use be w dur , and the weight of the duration from the closest activation time to the current moment be w val . Then its usage preference value in the system is:[[]]

[0065] P i = re i * fre + ur i * dur + al i * val

[0066] Among them, P i is the usage preference value of the object, fre i is the frequency of use of the object, dur i is the duration of use of the object, val i is the duration from the closest activation time of the object to the current moment.

[0067] In this embodiment, let an application / software / device be E, and the weight of the frequency of use of any object be w fre , the weight of the duration of use be w dur, the weight of the closest activation time duration from the current moment is w val It can be set according to actual needs.

[0068] S15. Arrange all objects in the system in descending order according to the preference value to obtain a usage preference list.

[0069] In this embodiment, all applications / software / devices in the system are listed in descending order according to the value of P to obtain a usage preference list.

[0070] S2. Objectively weight and evaluate the existing vulnerabilities in the system according to the usage preference value.

[0071] In this embodiment, the existing vulnerabilities in the system are objectively weighted and evaluated from the perspective of usage preference.

[0072] Step S2 includes steps S21 - S25:

[0073] S21. Evaluate the confidentiality to determine the confidentiality value; step S21 includes steps S211 - S213:

[0074] S211. If the exploitation of the vulnerability does not affect the confidentiality of any object in the usage preference list, determine that the confidentiality value is the first preset value.

[0075] In this embodiment, the exploitation of the vulnerability does not affect the confidentiality of a certain device / software / application in the preference list, sec = 0.

[0076] S212. If the exploitation of the vulnerability can access some unauthorized information in any object in the usage preference list, resulting in the leakage of confidential information, determine that the confidentiality value is the second preset value.

[0077] In this embodiment, the exploitation of the vulnerability can access some unauthorized information of a certain device / software / application in the preference list, resulting in the leakage of confidential information, sec = 1.

[0078] S213. If the exploitation of the vulnerability can completely control and access any object in the usage preference list, determine that the confidentiality value is the third preset value.

[0079] In this embodiment, the exploitation of the vulnerability can completely control and access a certain device / software / application in the preference list, sec = 2.

[0080] S22. Evaluate the integrity to determine the integrity value; step S22 includes steps S221 - S223:

[0081] S221. If the exploitation of the vulnerability does not affect the integrity of any object in the usage preference list, determine that the integrity value is the first preset value.

[0082] In this embodiment, after the vulnerability is exploited, it has no impact on the integrity of a certain device / software / application in the preference list, and int = 0.

[0083] S222. If, after the vulnerability is exploited, it may modify some file configurations and information in any object in the usage preference list, and no control is obtained or the file configurations and information can only be modified within a limited range, then determine that the integrity value is the second preset value.

[0084] In this embodiment, after the vulnerability is exploited, it may modify some file configurations and information of a certain device / software / application in the preference list, but no control will be obtained, or the file configurations and information can only be modified within a limited range, and int = 1.

[0085] S223. If, after the vulnerability is exploited, it can modify any file configurations and information of any object in the usage preference list, then determine that the integrity value is the third preset value.

[0086] In this embodiment, after the vulnerability is exploited, it can modify any file configurations and information of a certain device / software / application in the preference list, and int = 2.

[0087] S23. Evaluate the usability to determine the usability value; step S23 includes steps S231 - S233:

[0088] S231. If, after the vulnerability is exploited, it has no impact on the usability of any object in the usage preference list, then determine that the usability value is the first preset value.

[0089] In this embodiment, after the vulnerability is exploited, it has no impact on the usability of a certain device / software / application in the preference list, and use = 0.

[0090] S232. If, after the vulnerability is exploited, it may cause a performance reduction or interruption in the usability aspect of any object in the usage preference list, then determine that the usability value is the second preset value.

[0091] In this embodiment, after the vulnerability is exploited, it may cause a performance reduction or interruption in the usability aspect of a certain device / software / application in the preference list, and use = 1.

[0092] S233. If, after the vulnerability is exploited, it can cause any object in the usage preference list to be completely unavailable, then determine that the usability value is the third preset value.

[0093] In this embodiment, after the vulnerability is exploited, it can cause a certain device / software / application in the preference list to be completely unavailable, and use = 2.

[0094] S24. Set the confidentiality weight, integrity weight, and usability weight.

[0095] In this embodiment, the evaluation weights of confidentiality, integrity, and availability are set to w sec , w int , w use , satisfying 0 ≤ w sec , w int , w use ≤ 1, and the specific values are determined according to requirements.

[0096] S25. Calculate the evaluation value of any object in the usage preference list as:

[0097] E i = ec i * sec + nt i * int + se i * use

[0098] where E i is the evaluation value of the object, sec i is the confidentiality value of the object, int i is the integrity value of the object, use i is the availability value of the object, w sec is the confidentiality weight, w int is the integrity weight, w use is the availability weight.

[0099] S26. Discover vulnerabilities and their information through vulnerability scanning.

[0100] In this embodiment, there are various vulnerabilities and their information (including internal vulnerability identifiers, vulnerability names, vulnerability categories, CVE numbers, etc.) discovered in advance through vulnerability scanning (including but not limited to CGI vulnerability scanning, POP3 vulnerability scanning, FTP vulnerability scanning, SSH vulnerability scanning, HTTP vulnerability scanning, SMTP vulnerability scanning, IMAP vulnerability scanning, etc. These vulnerability scans are based on vulnerability libraries published on the network, and the scan results are matched and compared with relevant data in the network vulnerability library to obtain vulnerability information. In addition, it also includes various scans without corresponding network vulnerability libraries, such as Unicode directory traversal vulnerability detection, FTP weak password detection, etc. These scans use plugins (functional module technology) to perform simulated attacks to test the vulnerability information of the target host) in the system vulnerability database.

[0101] S3. Obtain a system vulnerability list based on preferences according to the usage preference values and the results of objective weighted evaluation. Step S3 includes steps S31 - S33:

[0102] S31. Set that there are n types of objects in the usage preference list, and set the weight of the usage preference value of any object to wp For any object in the usage preference list for which the evaluation value of the vulnerability has been obtained, the weight is w e .

[0103] In this embodiment, it is assumed that there are n different applications / software / devices in the preference list. According to step S1, the usage preference values P of each application / software / device in the industrial Internet have been obtained, and their weights are set as w p In step S2, the evaluation value E of each vulnerability for a certain device / software / application in the preference list has been obtained, and its weight is set as w e .

[0104] S32. Calculate the impact evaluation value of the vulnerability on usage:

[0105]

[0106] S33. Sort all the impact evaluation values of the vulnerabilities on usage in descending order to obtain a system vulnerability list based on preferences.

[0107] In this embodiment, all the impact evaluation values of the vulnerabilities on usage are sorted in descending order to obtain a system vulnerability list based on preferences. This list can be used as a reference for the industrial Internet security gateway or the vulnerability protection system for system protection or vulnerability patching.

[0108] In summary, by summarizing the subjective usage records and plans of the system, scoring the usage record items according to the weighting rules, obtaining the usage preference list of the system, objectively weighting and evaluating the existing vulnerabilities of the system from the perspective of usage preferences, and obtaining a system vulnerability list based on preferences. The evaluation method proposed by the present invention can be used for industrial Internet of Things, security gateways, vulnerability scanning systems, etc. to evaluate the impact of vulnerabilities on users.

[0109] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions or by controlling related hardware through instructions. The instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. For this purpose, an embodiment of the present invention provides a storage medium in which multiple instructions are stored, and the instructions can be loaded by a processor to execute the steps in any one of the evaluation methods for industrial Internet of Things vulnerabilities provided by the embodiments of the present invention.

[0110] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.

[0111] Since the instructions stored in the storage medium can execute the steps in any of the industrial Internet of Things vulnerability assessment methods provided by the embodiments of the present invention, the beneficial effects achievable by any of the industrial Internet of Things vulnerability assessment methods provided by the embodiments of the present invention can be realized. For details, refer to the previous embodiments and will not be elaborated here.

[0112] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. An evaluation method for vulnerabilities in the industrial Internet of Things, characterized in that Including: Obtaining the usage preference value of each object for the user according to the user's subjective usage records or plans; Objectively weighting and evaluating the existing vulnerabilities in the system according to the usage preference values; Obtaining a preference-based system vulnerability list based on the usage preference values and the results of the objective weighting evaluation; The obtaining of the usage preference value of each object for the user according to the user's subjective usage records or plans includes: Counting the usage frequency of each object in the system history records or future plans; Counting the usage duration of each object in the system history records or future plans; Counting the duration from the closest activation time of each object in the system future plan to the current moment; Let the weight of the frequency of use of any object be w fre , and the weight of the duration of use be w dur , and the weight of the duration from the closest activation time to the current moment be w val , then its usage preference value in the system is: P i = fre i * w fre + dur i * w dur + val i * w val Among them, P i is the usage preference value of the object, fre i is the frequency of use of the object, dur i is the duration of use of the object, val i is the duration from the closest activation time of the object to the current moment; Sorting all objects in the system from largest to smallest according to the preference values to obtain a usage preference list; The objectively weighting and evaluating the existing vulnerabilities in the system according to the usage preference values includes: Evaluating confidentiality to determine the confidentiality value; Evaluating integrity to determine the integrity value; Evaluating availability to determine the availability value; Setting the confidentiality weight, integrity weight and availability weight; Calculating the evaluation value of any object in the usage preference list as: E i = sec i * w sec + int i * w int + use i * w use Among them, E i is the evaluation value of the object, sec i is the confidentiality value of the object, int i is the integrity value of the object, use i is the availability value of the object, w sec is the confidentiality weight, w int is the integrity weight, w use is the availability weight; The obtaining of a preference-based system vulnerability list based on the usage preference values and the results of the objective weighting evaluation includes: Set that there are n types of objects in the usage preference list, and set the weight of the usage preference value of any object to w p , and the weight of the evaluation value of the vulnerability for any object in the usage preference list is w e ; Calculating the evaluation value of the impact of the vulnerability on usage: Sorting all the evaluation values of the impact of the vulnerabilities on usage according to the size to obtain a preference-based system vulnerability list.

2. The evaluation method for industrial Internet of Things vulnerabilities according to claim 1, wherein The objects include applications, software and devices.

3. The evaluation method for industrial Internet of Things vulnerabilities according to claim 1, characterized in that The evaluating confidentiality to determine the confidentiality value includes: If the exploitation of the vulnerability has no impact on the confidentiality of any object in the usage preference list, determining that the confidentiality value is the first preset value; If the exploitation of the vulnerability can access some unauthorized information in any object in the usage preference list, resulting in the leakage of confidential information, determining that the confidentiality value is the second preset value; If the exploitation of the vulnerability can completely control and access any object in the usage preference list, determining that the confidentiality value is the third preset value.

4. The evaluation method for industrial Internet of Things vulnerabilities according to claim 1, characterized in that The evaluating integrity to determine the integrity value includes: If the exploitation of the vulnerability has no impact on the integrity of any object in the usage preference list, determining that the integrity value is the first preset value; If the exploitation of the vulnerability may modify some file configurations and information in any object in the usage preference list, and no control is obtained or only the file configurations and information can be modified within a limited range, determining that the integrity value is the second preset value; If the exploitation of the vulnerability can modify any file configurations and information of any object in the usage preference list, determining that the integrity value is the third preset value.

5. The evaluation method of industrial Internet of Things vulnerabilities according to claim 1, characterized in that The evaluating availability to determine the availability value includes: If the exploitation of the vulnerability has no impact on the availability of any object in the usage preference list, determining that the availability value is the first preset value; If the exploitation of the vulnerability may cause a performance reduction or interruption in the availability aspect of any object in the usage preference list, determining that the availability value is the second preset value; If the exploitation of the vulnerability can cause any object in the usage preference list to be completely unavailable, determining that the availability value is the third preset value.

6. The evaluation method for industrial Internet of Things vulnerabilities according to claim 1, wherein The objectively weighting and evaluating the existing vulnerabilities in the system according to the usage preference values further includes: Vulnerabilities and their information are discovered through vulnerability scanning.

7. A computer-readable storage medium, characterized in that, Multiple instructions are stored in the storage medium, and the instructions are suitable for being loaded by a processor to execute an evaluation method for an industrial Internet of Things vulnerability according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Large-scale wireless sensor network time synchronizer based on clock frequency dynamic detection

    CN104105195A

  • Industrial Internet security assessment method and system based on multiple attributes

    CN111565201A