A method and device for quantitatively evaluating a network security situation
By applying Pareto analysis method in network security situation assessment, the network security situation evaluation elements are extracted and analyzed, and the problems of traditional prediction models' low prediction efficiency for mutation peaks and low processing efficiency for non-stationary data are solved, achieving more accurate network security situation evaluation and higher interpretability.
Patent Information
- Application Number
- CN202211511477.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-29
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-11-29
AI Technical Summary
Traditional timing prediction models are difficult to accurately predict mutation peaks of network security events, and the processing efficiency of non-stationary time series data is low, making it difficult to calculate the network security situation in real time, and the quantitative evaluation method is low interpretability.
The Pareto analysis method is used to extract network security situation evaluation elements from security assessment log data, analyze their impact categories, and conduct quantitative calculations to evaluate network security situation.
Through the application of Pareto analysis, the development trend of network security events can be predicted more accurately, the processing efficiency of non-stationary time series data is improved, real-time calculation of network security situations is achieved, and the interpretability of evaluation results is improved.
Smart Images

Figure CN115913733B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly to a method for quantitatively evaluating network security situation, a device for quantitatively evaluating network security situation, an electronic device, and a computer-readable storage medium. Background Art
[0002] Network security event prediction refers to judging and predicting the development trend and harm of major security events found in a network system, which is an important stage and the main goal of network security situation awareness. In a complex network security situation, the mutation peak generated by network security event data can identify important changes in the network situation. However, it is difficult for traditional time series prediction models to accurately predict the mutation peak, and when using traditional time series models to predict non-stationary time series data, it is difficult to transform the non-stationary time series data into stationary time series data without losing its own information.
[0003] Generally, a quantitative evaluation method can be used to evaluate the network security situation. However, this method has problems such as being difficult to calculate in real time, requiring a large computing platform and computing system, and at the same time, there are also problems with the degree of agreement with the real situation and low interpretability. Summary of the Invention
[0004] In view of the above problems, embodiments of the present invention are proposed to provide a method for quantitatively evaluating network security situation, a device for quantitatively evaluating network security situation, an electronic device, and a computer-readable storage medium that overcome the above problems or at least partially solve the above problems.
[0005] To solve the above problems, embodiments of the present invention disclose a method for quantitatively evaluating network security situation, the method comprising:
[0006] Obtaining security evaluation log data of a target network;
[0007] Extracting a plurality of network security situation evaluation elements from the security evaluation log data;
[0008] Using the Pareto analysis method to analyze the plurality of network security situation evaluation elements to obtain the influence categories to which the plurality of network security situation evaluation elements belong;
[0009] Determining a target network security situation evaluation element from the plurality of network security situation evaluation elements;
[0010] Quantitatively calculating the target network security situation evaluation element according to the target network security situation evaluation element and the influence category to which the target network security situation evaluation element belongs to obtain the security situation evaluation result of the target network.
[0011] Optionally, the Pareto analysis method is used to analyze the multiple network security situation assessment elements, and the influence categories to which the multiple network security situation assessment elements belong are obtained, including:
[0012] Use the Pareto analysis method to construct a network security assessment classification model;
[0013] Input the multiple network security situation assessment elements into the network security assessment classification model for processing to obtain multiple influence categories of any network security situation assessment element;
[0014] According to the Pareto optimum, determine the influence category to which any network security situation assessment element belongs from the multiple influence degree categories.
[0015] Optionally, the determining the influence category to which any network security situation assessment element belongs from the multiple influence degree categories according to the Pareto optimum includes:
[0016] According to the mapping relationship between the preset decision space and the objective function space, map the decision space to the objective function space to construct multiple objective functions; the influence category is the decision vector in the decision space; the objective function is used to characterize the probability that any influence category is the influence category to which the network security situation assessment element belongs;
[0017] According to the multiple objective function values respectively corresponding to any two decision vectors, determine the dominance relationship between the any two decision vectors;
[0018] According to the dominance relationship between the any two decision vectors, determine the influence category to which any network security situation assessment element belongs.
[0019] Optionally, the determining the dominance relationship between any two decision vectors according to the multiple objective function values respectively corresponding to the any two decision vectors includes:
[0020] Select a first decision vector and a second decision vector from the decision vectors in the decision space;
[0021] Judge whether the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and whether at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector;
[0022] If the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector, then the first decision vector dominates the second decision vector.
[0023] Optionally, determining the influence degree category to which any network security situation assessment element belongs according to the dominance relationship between any two decision vectors includes:
[0024] If the first decision vector is not dominated by any decision vector in the decision space, then determine the influence category corresponding to the first decision vector as the influence category to which any network security situation assessment element belongs.
[0025] Optionally, performing quantization calculation on the target network security situation assessment element according to the target network security situation assessment element and the influence degree category to which the target network security situation assessment element belongs to obtain the security situation assessment result of the target network, including:
[0026] Quantize the target network security situation assessment element to obtain the quantization value of the target network security situation assessment element;
[0027] Calculate according to the quantization value of the target network security situation assessment element and the weight corresponding to the influence degree category to which the target network security situation assessment element belongs to determine the security situation assessment result of the target network.
[0028] Optionally, calculating according to the quantization value of the target network security situation assessment element and the weight corresponding to the influence degree category to which the target network security situation assessment element belongs to determine the security situation assessment result of the target network, including:
[0029] Use the analytic hierarchy process to determine the weight of the influence degree category to which the target network security situation assessment element belongs;
[0030] Perform network security situation quantization calculation on the quantization value of the target network security situation assessment element and the weight of the influence degree category to which the target network security situation assessment element belongs based on the aggregation function to obtain the security situation assessment result of the target network.
[0031] An embodiment of the present invention also discloses a quantization evaluation device for network security situation, and the device includes:
[0032] An acquisition module, configured to acquire security evaluation log data of a target network;
[0033] An extraction module, configured to extract a plurality of network security situation assessment elements from the security evaluation log data;
[0034] An analysis module, configured to analyze the plurality of network security situation assessment elements by using the Pareto analysis method to obtain the influence degree categories to which the plurality of network security situation assessment elements belong;
[0035] A determination module, configured to determine a target network security situation assessment element from the multiple network security situation assessment elements;
[0036] A calculation module, configured to perform quantitative calculation on the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, so as to obtain the security situation assessment result of the target network.
[0037] Optionally, the analysis module includes:
[0038] A model construction sub-module, configured to construct a network security assessment classification model by using the Pareto analysis method;
[0039] A model processing sub-module, configured to input the multiple network security situation assessment elements into the network security assessment classification model for processing, so as to obtain multiple impact categories of any network security situation assessment element;
[0040] A category determination sub-module, configured to determine the impact category to which any network security situation assessment element belongs from the multiple impact degree categories according to Pareto optimality.
[0041] Optionally, the impact category determination sub-module includes:
[0042] A mapping unit, configured to map the decision space to the objective function space according to a preset mapping relationship between the decision space and the objective function space, so as to construct multiple objective functions; the impact category is a decision vector in the decision space; the objective function is used to represent the probability that any impact category is the impact category to which the network security situation assessment element belongs;
[0043] A dominance relationship determination unit, configured to determine the dominance relationship between any two decision vectors according to the multiple objective function values respectively corresponding to the any two decision vectors;
[0044] An impact category determination unit, configured to determine the impact category to which any network security situation assessment element belongs according to the dominance relationship between the any two decision vectors.
[0045] Optionally, the dominance relationship determination unit includes:
[0046] A decision vector selection sub-unit, configured to select a first decision vector and a second decision vector from the decision vectors in the decision space;
[0047] A function value judgment sub-unit, configured to judge whether the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and whether at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector;
[0048] A vector domination determination subunit, configured to determine that the first decision vector dominates the second decision vector if the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and the objective function value corresponding to at least one of the first decision vectors is less than the objective function value corresponding to the second decision vector.
[0049] Optionally, the influence category determination unit includes:
[0050] An element influence category determination subunit, configured to determine the influence category to which the first decision vector belongs as the influence category to which any network security situation assessment element belongs if the first decision vector is not dominated by any decision vector in the decision space.
[0051] Optionally, the calculation module includes:
[0052] A quantization sub-module, configured to quantize the target network security situation assessment element to obtain a quantization value of the target network security situation assessment element;
[0053] An evaluation result determination sub-module, configured to calculate according to the quantization value of the target network security situation assessment element and the weight corresponding to the influence category to which the target network security situation assessment element belongs, and determine the security situation evaluation result of the target network.
[0054] Optionally, the evaluation result determination sub-module includes:
[0055] An analytic hierarchy process unit, configured to determine the weight of the influence category to which the target network security situation assessment element belongs by using the analytic hierarchy process;
[0056] A situation evaluation result determination unit, configured to perform network security situation quantization calculation on the quantization value of the target network security situation assessment element and the weight of the influence category to which the target network security situation assessment element belongs based on an aggregation function, and obtain the security situation evaluation result of the target network.
[0057] An embodiment of the present invention also discloses an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor, where when the computer program is executed by the processor, the steps of the quantization evaluation method for network security situation described above are implemented.
[0058] An embodiment of the present invention also discloses a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the quantization evaluation method for network security situation described above are implemented.
[0059] The embodiments of the present invention have the following advantages:
[0060] In an embodiment of the present invention, first, security assessment log data of a target network is obtained, and multiple network security situation assessment elements are extracted from the security assessment log data; then, the Pareto analysis method is used to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong; finally, target network security situation assessment elements are determined from the multiple network security situation assessment elements, and based on the target network security situation assessment elements and the impact categories to which the target network security situation assessment elements belong, quantitative calculation is performed on the target network security situation assessment elements, and a security situation assessment result of the target network can be obtained. By using the Pareto analysis method in the embodiment of the present invention, the impact categories to which the network security situation assessment elements belong are obtained through analysis, and the security situation assessment result of the target network is obtained through quantitative calculation of the target network security situation assessment elements, thereby avoiding the problems that non-temporal data is difficult to be converted into temporal data and it is difficult to perform real-time calculation when evaluating the network security situation based on a quantitative evaluation method, which is beneficial to improving the coincidence degree and interpretability between the prediction result and the actual situation. Description of the Drawings
[0061] Figure 1 is a flowchart of the steps of a method for quantitatively evaluating a network security situation provided by an embodiment of the present invention;
[0062] Figure 2 is a flowchart of the steps of another method for quantitatively evaluating a network security situation provided by an embodiment of the present invention;
[0063] Figure 3 is a block diagram of the structure of a device for quantitatively evaluating a network security situation provided by an embodiment of the present invention. Detailed Embodiments
[0064] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0065] Network security event prediction refers to the judgment and prediction of the development trend and harm of major security events found in network systems. It is an important stage and the main goal of network security situation awareness. When conducting network security event prediction, it is necessary to analyze potential and possible attack paths, predict attack paths based on the vulnerability situation of the network and system, continuously learn new attack patterns, and reveal and understand the confusion and deception behaviors carried out by attackers. In the current complex network security situation, the mutation peak generated by network security event data can identify important changes in the network situation, but it is difficult for traditional time series prediction models to accurately predict the mutation peak. Moreover, when predicting non-stationary time series data using traditional time series models, it is difficult to transform non-stationary time series data into stationary time series data without losing its own information.
[0066] Generally, a quantitative evaluation method can be used to evaluate the network security situation. Compared with the qualitative evaluation method, the quantitative evaluation method is more objective and quantitative, and it is a commonly used evaluation method at present. However, this method has problems such as difficult real-time calculation, the need for large computing platforms and computing systems, and low degree of agreement with the real situation and interpretability.
[0067] One of the core concepts of the embodiments of the present invention is that, first, obtain the security evaluation log data of the target network, and extract multiple network security situation evaluation elements from the security evaluation log data; then use the Pareto analysis method to analyze the multiple network security situation evaluation elements to obtain the influence categories to which the multiple network security situation evaluation elements belong; finally, determine the target network security situation evaluation element from the multiple network security situation evaluation elements, and perform quantitative calculation on the target network security situation evaluation element according to the target network security situation evaluation element and the influence category to which the target network security situation evaluation element belongs, and the security situation evaluation result of the target network can be obtained. By using the Pareto analysis method, the embodiments of the present invention analyze the network security situation evaluation elements to obtain the belonging influence categories, and perform quantitative calculation on the target network security situation evaluation element to obtain the security situation evaluation result of the target network, thereby avoiding the problem that non-time series data is difficult to be transformed into time series data and the problem of difficult real-time calculation when evaluating the network security situation based on the quantitative evaluation method, which is beneficial to improving the degree of agreement between the prediction result and the real situation and the interpretability.
[0068] Refer to Figure 1 , which shows the step flowchart of a quantitative evaluation method for network security situation provided by the embodiments of the present invention. The method may specifically include the following steps:
[0069] Step 101, obtain the security evaluation log data of the target network.
[0070] The quantitative evaluation method of network security situation in the embodiments of the present invention can be applied to a server. The server can extract network security situation evaluation elements from security evaluation log data, and use the Pareto analysis method to analyze and obtain the impact categories to which the evaluation elements belong. Thus, in practical applications, after determining the target network security situation evaluation elements, their quantitative calculation can be performed to obtain the network security situation evaluation result of the target network.
[0071] The security evaluation log data can be log receipts that record network security events and can be used for network security evaluation. In the embodiments of the present invention, when it is necessary to evaluate the network security situation of a target network, the security evaluation log data of the target network can be obtained for analysis and evaluation.
[0072] Step 102: Extract multiple network security situation evaluation elements from the security evaluation log data.
[0073] In the embodiments of the present invention, multiple network security situation evaluation elements can be extracted from the network security evaluation log data that records network security events, so as to analyze the network security situation evaluation elements to evaluate the network security situation.
[0074] Step 103: Use the Pareto analysis method to analyze the multiple network security situation evaluation elements to obtain the impact categories to which the multiple network security situation evaluation elements belong.
[0075] The impact categories can include primary impact categories, secondary impact categories, and tertiary impact categories. In the embodiments of the present invention, by using the Pareto analysis method to analyze the network security situation evaluation elements, they can be classified and ranked according to the main characteristics of the network security situation evaluation elements. By classification, the primary and secondary influencing factors can be distinguished, so that the network security situation can be quantitatively evaluated for the network security situation evaluation elements of each level of impact categories. Specifically, in the Pareto analysis chart, the left vertical coordinate can be used to represent the frequency, the right vertical coordinate can be used to represent the frequency expressed as a percentage, the horizontal coordinate can be used to represent each security situation evaluation element that affects the network security situation, and the various security situation evaluation elements that affect the network security situation are arranged from left to right according to the impact size. The curve can be used to represent the cumulative percentage of the sizes of each security situation evaluation element. Through the Pareto analysis chart, the cumulative frequency of the curve can be divided into three levels, and the corresponding evaluation elements are divided into three categories: primary impact category evaluation elements, with a cumulative occurrence frequency of 0%-80%, which can be the main influencing elements; secondary impact category evaluation elements, with a cumulative occurrence frequency of 80%-90%, which can be the secondary influencing elements; tertiary impact category evaluation elements, with a cumulative occurrence frequency of 90%-100%, which can be the general influencing elements.
[0076] In an embodiment of the present invention, by using the Pareto analysis method to analyze the network security situation assessment elements, it is beneficial to avoid the problems that non-temporal data is difficult to be converted into temporal data and it is difficult to perform real-time calculation when evaluating the network security situation based on a quantitative evaluation method, and it is beneficial to improve the coincidence degree and interpretability between the prediction result and the real situation.
[0077] Step 104: Determine the target network security situation assessment element from the multiple network security situation assessment elements.
[0078] In a specific implementation, according to the specific requirements of different networks, the target network security situation assessment element can be determined from the multiple network security situation assessment elements, so as to evaluate the network security situation of the network. It should be noted that in a specific implementation, according to specific requirements, the target network security situation assessment element determined from the multiple network security situation assessment elements can be one, two, or multiple, and the present invention does not limit this here.
[0079] Step 105: Perform quantitative calculation on the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, so as to obtain the security situation assessment result of the target network.
[0080] In an embodiment of the present invention, after determining the target network security situation assessment element, quantitative calculation can be performed on the selected target network security situation assessment element according to the target network security situation assessment element and the corresponding impact category of the assessment element, so as to obtain the security situation assessment result of the target network, so that the user can predict the future network security development trend of the target network based on the security situation assessment result.
[0081] In an embodiment of the present invention, first, obtain the security assessment log data of the target network, and extract multiple network security situation assessment elements from the security assessment log data; then use the Pareto analysis method to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong; finally, determine the target network security situation assessment element from the multiple network security situation assessment elements, and perform quantitative calculation on the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, and the security situation assessment result of the target network can be obtained. In the embodiment of the present invention, by using the Pareto analysis method to analyze the network security situation assessment elements to obtain the belonging impact categories, and performing quantitative calculation on the target network security situation assessment element to obtain the security situation assessment result of the target network, the problems that non-temporal data is difficult to be converted into temporal data and it is difficult to perform real-time calculation when evaluating the network security situation based on a quantitative evaluation method are avoided, which is beneficial to improving the coincidence degree and interpretability between the prediction result and the real situation.
[0082] Refer to Figure 2 , which shows the flowchart of steps of another method for quantitatively evaluating the network security situation provided by an embodiment of the present invention. The method may specifically include the following steps:
[0083] Step 201, obtain the security assessment log data of the target network.
[0084] The method for quantitatively evaluating the network security situation in the embodiment of the present invention can be applied to a server. The server can extract network security situation evaluation elements from the security assessment log data and perform analysis using the Pareto analysis method to obtain the impact categories to which the evaluation elements belong. Thus, in practical applications, after determining the target network security situation evaluation elements, quantitative calculation can be performed on them to obtain the security situation evaluation result of the target network.
[0085] Step 202, extract multiple network security situation evaluation elements from the security assessment log data.
[0086] In the embodiment of the present invention, multiple network security situation evaluation elements can be extracted from the network security assessment log data recording network security events, so as to analyze the network security situation evaluation elements to evaluate the network security situation.
[0087] Step 203, use the Pareto analysis method to construct a network security assessment classification model.
[0088] In the embodiment of the present invention, the Pareto analysis method can be used to construct a network security assessment classification model, so as to classify the network security situation evaluation elements through the network security assessment classification model and determine the impact categories of the network security situation evaluation elements. By using the Pareto analysis method to analyze the network security situation evaluation elements, it is beneficial to avoid the problems that non-temporal data is difficult to be converted into temporal data and it is difficult to perform real-time calculation when evaluating the network security situation based on the quantitative evaluation method, and it is beneficial to improve the coincidence degree and interpretability between the prediction result and the actual situation.
[0089] Step 204, input the multiple network security situation evaluation elements into the network security assessment classification model for processing to obtain multiple impact categories of any network security situation evaluation element.
[0090] In the embodiment of the present invention, multiple network security situation evaluation elements can be input into the network security assessment classification model constructed by using the Pareto analysis method for analysis and processing to obtain multiple impact categories corresponding to each network security situation evaluation element.
[0091] Step 205, determine the impact category to which any network security situation evaluation element belongs from the multiple impact degree categories according to the Pareto optimality.
[0092] Exemplarily, if the impact categories corresponding to the network security situation assessment element A include primary impact categories and secondary impact categories, according to Pareto optimality, it can be determined that the impact category corresponding to the assessment element A is a primary impact category. In the embodiments of the present invention, data cleaning and data filtering can be performed through Pareto optimality to accurately locate an impact category to which the network security situation assessment element belongs, avoiding invalid or repeated operations on data.
[0093] In an alternative embodiment, the step 205 may include the following sub-steps S11 - S13:
[0094] Sub-step S11, according to the mapping relationship between the preset decision space and the objective function space, map the decision space to the objective function space to construct multiple objective functions; the impact category is a decision vector in the decision space; the objective function is used to represent the probability that any impact category is the impact category to which the network security situation assessment element belongs.
[0095] The preset mapping relationship between the decision space and the objective function space can be represented by a function. Specifically, it can be represented by f(x), x ∈ Ω for mapping, where Ω can be used to represent an n-dimensional decision space, x can be used to represent a decision vector in the decision space, and f(x) can be used to represent the objective function. Among them, mapping the decision space to the objective function space to construct multiple objective functions can be represented by the mathematical model min f(x) = (f 1 (x), f 2 (x), …, f k (x)), x ∈ Ω, f can represent mapping the n-dimensional decision space Ω to a k-dimensional objective space to obtain k objective functions f 1 (x), f 2 (x), …, f k (x), and the goal is to minimize it. The objective function can include all the optimization objectives of the optimization problem.
[0096] Sub-step S12, determine the dominance relationship between any two decision vectors according to the multiple objective function values respectively corresponding to the any two decision vectors.
[0097] After mapping the decision space to the objective function space to construct multiple objective functions, the dominance relationship between any two decision vectors can be determined according to the multiple objective function values respectively corresponding to the any two decision vectors.
[0098] In an alternative embodiment, the sub-step S12 may include the following sub-steps S121 - S123:
[0099] Sub-step S121: Select a first decision vector and a second decision vector from the decision vectors in the decision space.
[0100] The decision space may include multiple decision vectors. Any decision vector can be arbitrarily selected as the first decision vector x, and any other decision vector can be arbitrarily selected as the second decision vector y.
[0101] Sub-step S122: Determine whether the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and whether at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector.
[0102] Exemplarily, for two decision vectors x and y, determine whether any objective function value f 1 (x), f 2 (x), …, f k (x) is not greater than the objective function value f 1 (y), f 2 (y), …, f k (y), and whether at least one of the objective function values f 1 (x), f 2 (x), …, f k (x) is less than f 1 (y), f 2 (y), …, f k (y).
[0103] Sub-step S123: If the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector, then the first decision vector dominates the second decision vector.
[0104] If the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector, that is, f(x) is not greater than and at least less than f(y) on one objective, then the first decision vector x dominates the second decision vector y, or the second decision vector y is dominated by the first decision vector x, which can be denoted as f(x) < f(y).
[0105] When there is a mutual domination relationship between the first decision vector x and the second decision vector y, the first decision vector x and the second decision vector y can be compared. If f(x) and f(y) are equal on all objectives, then the first decision vector x and the second decision vector y are equivalent; if the first decision vector x and the second decision vector y neither dominate each other nor are equivalent, then the first decision vector x and the second decision vector y cannot be compared.
[0106] In the embodiment of the present invention, Pareto domination can define the relationship between the objective functions obtained from two different decision vectors, obtain the domination relationship between the two different decision vectors, so as to facilitate the comparison of the advantages and disadvantages between the two decision vectors. If the first decision vector x dominates the second decision vector y, it can indicate that x is stronger than the second decision vector y in the evaluation of all objective functions, and vice versa, it can indicate that the second decision vector y is stronger than the first decision vector x in the evaluation of all objective functions. If the first decision vector x is not dominated by any decision vector in the decision space, then the decision vector x can be a Pareto optimal solution, and the set of all Pareto optimal solutions can form a Pareto optimal solution set, that is, a non-fragmented set.
[0107] Sub-step S13: Determine the influence category to which any one of the network security situation assessment elements belongs according to the domination relationship between any two decision vectors.
[0108] After determining the domination relationship between any two decision vectors, the influence category to which any one of the network security situation assessment elements belongs can be determined according to the domination relationship between the decision vectors.
[0109] In an alternative embodiment, the sub-step S13 may include: if the first decision vector is not dominated by any decision vector in the decision space, then determine the influence category corresponding to the first decision vector as the influence category to which any one of the network security situation assessment elements belongs.
[0110] According to the domination relationship between the decision vectors, if the first decision vector is not dominated by any decision vector in the decision space, that is, the first decision vector is a Pareto optimal solution, then the influence category corresponding to the first decision vector can be determined as the influence category to which any one of the network security situation assessment elements belongs.
[0111] Step 206: Determine the target network security situation assessment element from the multiple network security situation assessment elements.
[0112] In a specific implementation, according to the specific requirements of different networks, target network security situation assessment elements can be determined from multiple network security situation assessment elements, so as to conduct a network security situation assessment on the network. It should be noted that in a specific implementation, according to specific requirements, the target network security situation assessment elements determined from multiple network security situation assessment elements can be one, two, or multiple, and the present invention does not limit this here.
[0113] Step 207: Perform a quantitative calculation on the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, so as to obtain the security situation assessment result of the target network.
[0114] In an embodiment of the present invention, after determining the target network security situation assessment element, a quantitative calculation can be performed on the selected target network security situation assessment element according to the target network security situation assessment element and the corresponding impact category, so as to obtain the security situation assessment result of the target network, enabling the user to predict the future network security development trend of the target network based on the security situation assessment result.
[0115] In an optional embodiment, step 207 may include the following sub-steps S21 - S22:
[0116] Sub-step S21: Quantify the target network security situation assessment element to obtain the quantification value of the target network security situation assessment element.
[0117] After determining the target network security situation assessment element, the target network security situation assessment element can be quantified. In a specific implementation, a quantification algorithm can be selected according to the needs of the assessment personnel and the characteristics of the specific assessment object. After quantifying the target network security situation assessment element using the quantification algorithm, the quantification value of the target network security situation assessment element can be obtained.
[0118] Sub-step S22: Calculate according to the quantification value of the target network security situation assessment element and the weight corresponding to the impact category to which the target network security situation assessment element belongs, and determine the security situation assessment result of the target network.
[0119] In an optional embodiment, sub-step S22 may include the following sub-steps S221 - S222:
[0120] Sub-step S221: Use the analytic hierarchy process to determine the weight of the impact category to which the target network security situation assessment element belongs.
[0121] Sub-step S222: Based on the quantization values of the target network security situation assessment elements and the weights of the impact categories to which the target network security situation assessment elements belong, perform network security situation quantization calculation using an aggregation function to obtain the security situation assessment result of the target network.
[0122] In an embodiment of the present invention, after obtaining the quantization values of the target network security situation assessment elements, the weights of the impact categories to which the target network security situation assessment elements belong can be determined first by using the analytic hierarchy process, and then based on the quantization values of the target network security situation assessment elements and the corresponding weights of the impact categories, perform network security situation quantization calculation using an aggregation function to determine the security situation assessment result of the target network.
[0123] In an embodiment of the present invention, first obtain the security assessment log data of the target network, and extract multiple network security situation assessment elements from the security assessment log data; then use the Pareto analysis method to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong; finally, determine the target network security situation assessment elements from the multiple network security situation assessment elements, and based on the target network security situation assessment elements and the impact categories to which the target network security situation assessment elements belong, perform quantization calculation on the target network security situation assessment elements to obtain the security situation assessment result of the target network. By using the Pareto analysis method in the embodiment of the present invention to analyze the network security situation assessment elements to obtain the impact categories to which they belong, and performing quantization calculation on the target network security situation assessment elements to obtain the security situation assessment result of the target network, it is possible to avoid the problem that non-temporal data is difficult to be converted into temporal data and the problem that it is difficult to perform real-time calculation when evaluating the network security situation based on the quantization evaluation method, which is beneficial to improving the coincidence degree and interpretability of the prediction result and the actual situation.
[0124] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0125] Refer to Figure 3 , which shows the structural block diagram of a quantization evaluation device for network security situation provided by an embodiment of the present invention, and specifically may include the following modules:
[0126] An acquisition module 301, configured to acquire the security assessment log data of the target network;
[0127] An extraction module 302, configured to extract a plurality of network security situation assessment elements from the security assessment log data;
[0128] An analysis module 303, configured to analyze the plurality of network security situation assessment elements by using the Pareto analysis method to obtain the impact categories to which the plurality of network security situation assessment elements belong;
[0129] A determination module 304, configured to determine a target network security situation assessment element from the plurality of network security situation assessment elements;
[0130] A calculation module 305, configured to perform quantitative calculation on the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, to obtain a security situation assessment result of the target network.
[0131] In an alternative embodiment, the analysis module includes:
[0132] A model construction sub-module, configured to construct a network security assessment classification model by using the Pareto analysis method;
[0133] A model processing sub-module, configured to input the plurality of network security situation assessment elements into the network security assessment classification model for processing to obtain a plurality of impact categories of any network security situation assessment element;
[0134] A category determination sub-module, configured to determine the impact category to which any network security situation assessment element belongs from the plurality of impact degree categories according to the Pareto optimality.
[0135] In an alternative embodiment, the impact category determination sub-module includes:
[0136] A mapping unit, configured to map the decision space to the objective function space according to a preset mapping relationship between the decision space and the objective function space to construct a plurality of objective functions; the impact category is a decision vector in the decision space; the objective function is used to characterize the probability that any impact category is the impact category to which the network security situation assessment element belongs;
[0137] A domination relationship determination unit, configured to determine the domination relationship between any two decision vectors according to the plurality of objective function values respectively corresponding to the any two decision vectors;
[0138] An impact category determination unit, configured to determine the impact category to which any network security situation assessment element belongs according to the domination relationship between the any two decision vectors.
[0139] In an alternative embodiment, the domination relationship determination unit includes:
[0140] A decision vector selection subunit, configured to select a first decision vector and a second decision vector from the decision vectors in the decision space;
[0141] A function value judgment subunit, configured to judge whether the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and whether at least one of the objective function values corresponding to the first decision vectors is less than the objective function value corresponding to the second decision vector;
[0142] A vector domination determination subunit, configured to, if the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and at least one of the objective function values corresponding to the first decision vectors is less than the objective function value corresponding to the second decision vector, then the first decision vector dominates the second decision vector.
[0143] In an alternative embodiment, the influence category determination unit includes:
[0144] An element influence category determination subunit, configured to, if the first decision vector is not dominated by any decision vector in the decision space, then determine the influence category corresponding to the first decision vector as the influence category to which any network security situation assessment element belongs.
[0145] In an alternative embodiment, the calculation module includes:
[0146] A quantization sub-module, configured to quantize the target network security situation assessment element to obtain a quantization value of the target network security situation assessment element;
[0147] An evaluation result determination sub-module, configured to calculate according to the quantization value of the target network security situation assessment element and the weight corresponding to the influence category to which the target network security situation assessment element belongs, and determine the security situation evaluation result of the target network.
[0148] In an alternative embodiment, the evaluation result determination sub-module includes:
[0149] An analytic hierarchy process unit, configured to use the analytic hierarchy process to determine the weight of the influence category to which the target network security situation assessment element belongs;
[0150] A situation evaluation result determination unit, configured to perform network security situation quantization calculation on the quantization value of the target network security situation assessment element and the weight of the influence category to which the target network security situation assessment element belongs based on an aggregation function, to obtain the security situation evaluation result of the target network.
[0151] In an embodiment of the present invention, first, security assessment log data of a target network is obtained, and multiple network security situation assessment elements are extracted from the security assessment log data; then, the Pareto analysis method is used to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong; finally, target network security situation assessment elements are determined from the multiple network security situation assessment elements, and based on the target network security situation assessment elements and the impact categories to which the target network security situation assessment elements belong, quantitative calculation is performed on the target network security situation assessment elements, and a security situation assessment result of the target network can be obtained. By using the Pareto analysis method, the embodiment of the present invention analyzes the network security situation assessment elements to obtain the impact categories to which they belong, and performs quantitative calculation on the target network security situation assessment elements to obtain the security situation assessment result of the target network, thereby avoiding the problems that non-temporal data is difficult to be converted into temporal data and it is difficult to perform real-time calculation when evaluating the network security situation based on a quantitative evaluation method, which is beneficial to improving the coincidence degree and interpretability between the prediction result and the real situation.
[0152] For the apparatus embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.
[0153] An embodiment of the present invention further provides an electronic device, including:
[0154] It includes a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it realizes each process of the above-mentioned embodiment of the quantitative evaluation method for network security situation and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0155] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it realizes each process of the above-mentioned embodiment of the quantitative evaluation method for network security situation and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0156] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0157] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0158] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0159] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0161] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the embodiments of the present invention.
[0162] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising said element.
[0163] The above has introduced in detail a quantitative evaluation method and device for a network security situation provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A quantitative evaluation method for network security situation, characterized in that, the method includes: Obtaining security assessment log data of the target network; Extracting multiple network security situation assessment elements from the security assessment log data; Using the Pareto analysis method to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong; Determining the target network security situation assessment element from the multiple network security situation assessment elements; According to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs, performing quantitative calculation on the target network security situation assessment element to obtain the security situation assessment result of the target network; Among them, the step of using the Pareto analysis method to analyze the multiple network security situation assessment elements to obtain the impact categories to which the multiple network security situation assessment elements belong includes: Using the Pareto analysis method to construct a network security assessment classification model; Inputting the multiple network security situation assessment elements into the network security assessment classification model for processing to obtain multiple impact categories of any network security situation assessment element; According to Pareto optimality, determining the impact category to which any network security situation assessment element belongs from the multiple impact categories; The step of determining the impact category to which any network security situation assessment element belongs from the multiple impact categories according to Pareto optimality includes: According to the mapping relationship between the preset decision space and the objective function space, mapping the decision space to the objective function space to construct multiple objective functions; the impact category is the decision vector in the decision space; the objective function is used to represent the probability that any impact category is the impact category to which the network security situation assessment element belongs; Determining the dominance relationship between any two decision vectors according to the multiple objective function values respectively corresponding to the any two decision vectors; Determining the impact category to which any network security situation assessment element belongs according to the dominance relationship between the any two decision vectors.
2. The method according to claim 1, characterized in that, the step of determining the dominance relationship between any two decision vectors according to the multiple objective function values respectively corresponding to the any two decision vectors includes: Selecting a first decision vector and a second decision vector from the decision vectors in the decision space; Judging whether the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and whether at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector; If the objective function value corresponding to the first decision vector is not greater than the objective function value corresponding to the second decision vector, and at least one of the objective function values corresponding to the first decision vector is less than the objective function value corresponding to the second decision vector, then the first decision vector dominates the second decision vector.
3. The method according to claim 2, characterized in that, the step of determining the impact category to which any network security situation assessment element belongs according to the dominance relationship between the any two decision vectors includes: If the first decision vector is not dominated by any decision vector in the decision space, determine the impact category corresponding to the first decision vector as the impact category to which any network security situation assessment element belongs.
4. The method according to claim 1, wherein, the quantifying and calculating the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs to obtain the security situation assessment result of the target network includes: quantifying the target network security situation assessment element to obtain a quantified value of the target network security situation assessment element; calculating according to the quantified value of the target network security situation assessment element and the weight corresponding to the impact category to which the target network security situation assessment element belongs to determine the security situation assessment result of the target network.
5. The method according to claim 4, wherein, the calculating according to the quantified value of the target network security situation assessment element and the weight corresponding to the impact category to which the target network security situation assessment element belongs to determine the security situation assessment result of the target network includes: using the analytic hierarchy process to determine the weight of the impact category to which the target network security situation assessment element belongs; performing network security situation quantification calculation on the quantified value of the target network security situation assessment element and the weight of the impact category to which the target network security situation assessment element belongs based on an aggregation function to obtain the security situation assessment result of the target network.
6. A quantitative evaluation device for network security situation, wherein, the device includes: an acquisition module for acquiring security assessment log data of a target network; an extraction module for extracting a plurality of network security situation assessment elements from the security assessment log data; an analysis module for analyzing the plurality of network security situation assessment elements by using the Pareto analysis method to obtain the impact categories to which the plurality of network security situation assessment elements belong; a determination module for determining a target network security situation assessment element from the plurality of network security situation assessment elements; a calculation module for quantifying and calculating the target network security situation assessment element according to the target network security situation assessment element and the impact category to which the target network security situation assessment element belongs to obtain the security situation assessment result of the target network; wherein, the analysis module includes: a model construction sub-module for constructing a network security assessment classification model by using the Pareto analysis method; a model processing sub-module for inputting the plurality of network security situation assessment elements into the network security assessment classification model for processing to obtain multiple impact categories of any network security situation assessment element; a category determination sub-module for determining the impact category to which any network security situation assessment element belongs from the multiple impact categories according to Pareto optimality; the impact category determination sub-module includes: A mapping unit, configured to map the decision space to the objective function space according to a preset mapping relationship between the decision space and the objective function space, and construct a plurality of objective functions; the influence category is a decision vector in the decision space; The objective function is used to characterize the probability that any influence category is the influence category to which the network security situation assessment element belongs; A dominance relationship determination unit, configured to determine the dominance relationship between any two decision vectors according to the objective function values respectively corresponding to the any two decision vectors; An influence category determination unit, configured to determine the influence category to which any network security situation assessment element belongs according to the dominance relationship between the any two decision vectors.
7. An electronic device, characterized in that, it includes: a processor, a memory, and a computer program stored on the memory and capable of running on the processor, and when the computer program is executed by the processor, the steps of the method for quantitatively evaluating the network security situation according to any one of claims 1-5 are implemented.
8. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method for quantitatively evaluating the network security situation according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Method and apparatus for evaluating network security situation
CN108683663A
Network security situation awareness system and method
CN110445807A