A method, device and storage device for assessing the damage degree of target software

By constructing a classification model for cyberspace attack detection, classification and constraint analysis of cyberspace attack events is carried out, and the degree of damage to the target software is evaluated, which solves the problem that the impact of cyberspace attacks cannot be accurately evaluated in the existing technology, and accurately evaluates and prevents software losses.

CN115941306BActive Publication Date: 2025-08-19CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211510177.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-29
Publication Date
2025-08-19
Estimated Expiration
2042-11-29

AI Technical Summary

Technical Problem

The existing technology cannot effectively evaluate the impact of cyberspace attacks on target software, resulting in the inability to accurately grasp the cyberspace situation and software losses.

Method used

By constructing a classification model for cyber-air attack detection, classifying the cyber-air event log data, filtering out the attack event data against the target software, performing optimization analysis and constraint analysis, determining the risk level of the attack event, and evaluating the damage level of the target software based on the risk level.

Benefits of technology

It realizes effective quantitative evaluation of network attack incidents, accurately assesses software losses, helps staff to prevent attack behavior in a timely manner, and ensures the safe operation of software assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941306B_ABST
    Figure CN115941306B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, specifically to a method, apparatus, and storage device for assessing the degree of damage to target software, designed to accurately assess the damage caused to target software by cyberspace attack events. The method comprises: classifying cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data; performing constraint analysis on the attack event classification result data to determine the risk level of each attack event in the attack event classification result data; and determining the degree of damage to the target software corresponding to the attack event based on the risk level of the attack event.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of network security technology, and more specifically, to a method, apparatus, and storage device for assessing the degree of damage to target software. Background Art

[0002] Cyberspace defense is a key research area. It aims to defend against cyberattacks originating in cyberspace, ensure the normal operation of software systems, and prevent targeted software from being affected by cyberattacks, leading to potential losses. Effective cyberspace defense requires observing and perceiving the cyberspace landscape and gaining a sound understanding of it. Existing technologies primarily rely on network security assessments, which are conducted by analyzing various network information and hardware indicators.

[0003] Existing network security assessments cannot effectively determine the impact of various events in cyberspace on target software. Summary of the Invention

[0004] The embodiments of the present application provide a method, apparatus, and storage device for assessing the degree of damage to target software, aiming to accurately assess the damage caused to the target software by a cyberspace attack event.

[0005] A first aspect of an embodiment of the present application provides a method for assessing the damage degree of target software, the method comprising:

[0006] Classify cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data;

[0007] performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data;

[0008] The degree of damage to the target software corresponding to the attack event is determined according to the danger level of the attack event.

[0009] Optionally, the step of constructing the cyber-attack detection classification model includes:

[0010] Taking the type of attack events affecting the target software as an optimization target, constructing an objective function space of the cyber attack detection classification model;

[0011] constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software;

[0012] The cyber attack detection classification model is constructed according to the objective function space and the decision space.

[0013] Optionally, the classifying the cyber event log data using the cyber attack detection classification model to obtain attack event classification result data includes:

[0014] inputting the cyber event log data into the cyber attack detection classification model;

[0015] Filtering attack event data targeting the target software from the cyberspace event log data using the cyberspace attack detection classification model;

[0016] The attack event data is optimized and analyzed to obtain the attack event classification result data.

[0017] Optionally, performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data includes:

[0018] For each attack event in the attack event classification result data, determining the target software corresponding to the attack event according to the attack event information of the attack event;

[0019] Determining the likelihood of the attack event affecting the target software based on pre-set constraints;

[0020] The danger level of the attack event is determined based on the likelihood that the attack event will affect the target software.

[0021] Optionally, the preset constraint condition includes at least one of the following: target software exists on the target hardware platform targeted by the attack event, a vulnerability exists in the target software targeted by the attack event, and the attack event exploits the vulnerability in the target software to launch an attack.

[0022] Optionally, determining the likelihood of the attack event affecting the target software based on pre-set constraints includes:

[0023] Determining, based on the attack event information of the attack event, the number of the attack events that satisfy the preset constraint condition;

[0024] The possibility of the attack event affecting the target software is determined based on the number of the preset constraint conditions satisfied by the attack event.

[0025] Optionally, determining the degree of damage to the target software corresponding to the attack event according to the danger level of the attack event includes:

[0026] Prioritize the target software corresponding to the attack event according to the danger level of the attack event, and obtain priority ranking result data of the target software;

[0027] determining the current operating capability of each target software in turn according to the order of the target software in the sorting result data;

[0028] The damage degree of the target software is determined according to the current operation capability of the target software and the normal operation capability of the target software.

[0029] Optionally, determining the current operating capability of each target software includes:

[0030] Determining the operational capability of the target software after experiencing the attack event;

[0031] Determining the operating capability of dependent software of target software that the target software depends on;

[0032] The current operating capability of the target software is determined according to the operating capability of the target software after experiencing the attack event and the operating capability of the dependent software.

[0033] According to a second aspect of an embodiment of the present application, there is provided a device for assessing the degree of damage to target software, the device comprising:

[0034] An attack detection classification module is used to classify cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data;

[0035] an attack event analysis module, configured to perform constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data;

[0036] The software evaluation module is used to determine the damage degree of the target software corresponding to the attack event according to the danger level of the attack event.

[0037] Optionally, the step of constructing the cyber-attack detection classification model includes:

[0038] Taking the type of attack events affecting the target software as an optimization target, constructing an objective function space of the cyber attack detection classification model;

[0039] constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software;

[0040] The cyber attack detection classification model is constructed according to the objective function space and the decision space.

[0041] Optionally, the attack detection and classification module includes:

[0042] a data input submodule, configured to input the cyberspace event log data into the cyberspace attack detection classification model;

[0043] an attack event data screening submodule, configured to screen attack event data targeting the target software from the cyberspace event log data using the cyberspace attack detection classification model;

[0044] The optimization analysis submodule is used to perform optimization analysis on the attack event data to obtain the attack event classification result data.

[0045] Optionally, the attack event analysis module includes:

[0046] a target software determination submodule, configured to determine, for each attack event in the attack event classification result data, the target software corresponding to the attack event according to the attack event information of the attack event;

[0047] A constraint analysis submodule, configured to determine the likelihood of the attack event affecting the target software based on pre-set constraint conditions;

[0048] The danger level determination submodule is used to determine the danger level of the attack event according to the possibility of the attack event affecting the target software.

[0049] Optionally, the preset constraint condition includes at least one of the following: target software exists on the target hardware platform targeted by the attack event, a vulnerability exists in the target software targeted by the attack event, and the attack event exploits the vulnerability in the target software to launch an attack.

[0050] Optionally, the constraint analysis submodule includes:

[0051] A first constraint condition analysis submodule, configured to determine, based on the attack event information of the attack event, the number of the attack events that satisfy the preset constraint conditions;

[0052] The second constraint condition analysis submodule is configured to determine the likelihood that the attack event will affect the target software based on the number of preset constraint conditions satisfied by the attack event.

[0053] Optionally, the software evaluation submodule includes:

[0054] The software sorting submodule is used to sort the target software corresponding to the attack event according to the danger level of the attack event, and obtain the sorting result data of the target software priority;

[0055] A current operating capability calculation submodule, configured to determine the current operating capability of each target software in sequence according to the target software order in the sorting result data;

[0056] The damage degree determination submodule is used to determine the damage degree of the target software according to the current operation capability of the target software and the normal operation capability of the target software.

[0057] Optionally, the current operating capacity calculation submodule includes:

[0058] A first operating capability determination submodule, configured to determine the operating capability of the target software after experiencing the attack event;

[0059] A second operating capability determination submodule is used to determine the operating capability of the dependent software of the target software that the target software depends on;

[0060] The third operating capability determination submodule is configured to determine the current operating capability of the target software according to the operating capability of the target software after experiencing the attack event and the operating capability of the dependent software.

[0061] A third aspect of an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method described in the first aspect of the present application are implemented.

[0062] The target software damage assessment method provided in this application uses a cyber-attack detection and classification model to classify cyber-attack event log data to obtain attack event classification result data; constraint analysis is performed on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data; and based on the danger level of the attack event, the damage level of the target software corresponding to the attack event is determined. This method classifies cyber-attack events using a cyber-attack detection and classification model, analyzes the classified data, and obtains the danger level of each attack event, effectively quantitatively assessing the danger level of network attack events. This helps staff gain a clear understanding of the danger level of network attack events and, based on the danger level of network attack events, rationally assesses the damage level of the target software corresponding to the network attack events, enabling staff to clearly understand the losses caused by network attacks, helping to prevent various attacks that have already occurred, and helping staff to propose effective solutions based on existing software losses and the associated work task losses. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0064] Figure 1 This is a flowchart of a method for assessing the damage level of target software proposed in one embodiment of the present application;

[0065] Figure 2 2 is a schematic diagram of a target software damage assessment device according to an embodiment of the present application. DETAILED DESCRIPTION

[0066] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0067] refer to Figure 1 , Figure 1 This is a flow chart of a method for evaluating the degree of damage to target software proposed in one embodiment of the present application. Figure 1 As shown, the method includes the following steps:

[0068] S11: Classify the cyber event log data through the cyber attack detection classification model to obtain attack event classification result data.

[0069] In this embodiment, the cyber attack detection classification model is a model that classifies the categories of attack events occurring in cyberspace. The cyber event log data is data in the form of logs that records detailed information about events occurring in cyberspace. The attack event classification result data is data that places various types of attack events occurring in cyberspace into separate sets according to the type of attack.

[0070] In this embodiment, cyberspace event log data is recorded by a cyberspace terrain monitoring system that monitors and records cyberspace in real time. The system monitors each node in the cyberspace terrain and records events that occur in the cyberspace in a monitoring log, generating a cyberspace event log. A cyberspace terrain map is an entity relationship graph consisting of nodes and the relationships between nodes in the cyberspace. A cyberspace attack detection and classification model receives the cyberspace event log data, filters data corresponding to cyberspace attack events from the cyberspace event log data, and then classifies the data corresponding to the cyberspace attack events to generate attack event classification results.

[0071] In this embodiment, the classification of cyberspace attack events includes cyberspace terrain entity and relationship classification, cyberspace attack detection feature and anomaly classification, and neighborhood constraint classification. Cyberspace terrain and entity relationship classification means that cyberspace attack events target certain entities and relationships between entities in the cyberspace terrain, such as certain hardware platforms; cyberspace attack detection feature and anomaly classification means that cyberspace attack events cause certain anomalies in the characteristics of the attack target; domain constraints refer to semantic constraints on entities, relationships, and entity parameters. Domain constraint classification means that cyberspace attack events target the constraint relationships between entities, relationships, and entity parameters.

[0072] In this embodiment, the cyberspace event log data is classified using the cyberspace attack detection classification model to obtain attack event classification result data, including:

[0073] S11-1: Inputting the cyber event log data into the cyber attack detection classification model.

[0074] S11-2: Filtering attack event data targeting the target software from the cyberspace event log data using the cyberspace attack detection classification model.

[0075] In this embodiment, the cyberspace event log data includes log data of all events occurring in the cyberspace terrain, and the attack event data is log data of attack events occurring in the cyberspace terrain.

[0076] In this embodiment, the cyberspace event log data is input into the cyberspace attack detection classification model, and the cyberspace attack detection classification model filters out the attack event log data in the cyberspace events according to the keywords in the cyberspace event log.

[0077] For example, the keyword may be "software failure, external attack, etc."

[0078] S11-3: Optimizing and analyzing the attack event data to obtain attack event classification result data.

[0079] In this embodiment, the cyber attack detection classification model will extract features from the attack event log data to obtain feature vectors of the attack event data, and map the obtained vectors into the objective function space, perform optimization analysis on the data, and obtain attack event classification result data.

[0080] In another embodiment of the present application, the steps of constructing the cyber-attack detection classification model include:

[0081] S21: Taking the type of attack events that affect the target software as the optimization target, constructing the objective function space of the cyber attack detection classification model.

[0082] In this embodiment, the cyber-attack detection and classification model is essentially an optimization model with multiple optimization objectives, making it a multi-objective optimization model. The objective function space encompasses all objective functions of the cyber-attack detection and classification model, namely, optimization objective functions constructed based on the types of attack events affecting target software. The target software is the software program or software system running on the hardware platform.

[0083] In this embodiment, the type of attack event affecting the target software is used as the optimization target, and an optimization objective function corresponding to the optimization target is generated. Specifically, the objective function is composed of cyberspace terrain entity and relationship classification, cyberspace attack detection features and anomaly classification, and domain constraint classification, thereby forming an objective function space. The objective function is a function that contains the optimization target.

[0084] For example, a cyber attack detection model is constructed using the Pareto optimal solution method. The Pareto optimal solution method is an algorithm for multi-objective optimization tasks, and the three attack event types mentioned above can be used as optimization targets to construct the objective function of this model.

[0085] S22: Constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software.

[0086] In this embodiment, the attack event vector refers to the feature vector corresponding to the network attack event, and the decision space is a space containing all possible variables of the objective function.

[0087] In this embodiment, attack event data in cyberspace is collected, and features are extracted from the attack event data in cyberspace to obtain feature vectors of corresponding attack events, i.e., attack event vectors. The extracted attack event vectors are used to construct the decision space of the cyberspace attack detection classification model.

[0088] For example, if n pieces of network attack event data are collected in the cyberspace, feature extraction is performed on these n pieces of attack event data to obtain n attack event vectors. Based on these n attack event vectors, a decision space of the attack detection classification model is constructed.

[0089] S23: Constructing the cyber attack detection classification model according to the objective function space and the decision space.

[0090] In this embodiment, after constructing the objective function space and the decision space, the objective function space and the decision space are connected so that the decision vector in the decision space can be mapped to the objective function space, thereby forming a cyber attack detection classification model.

[0091] In this embodiment, the objective function of the cyber-attack detection classification model can be expressed as:

[0092] min f(x)=(f1(x),f2(x),…f k (x)), x∈Ω (1)

[0093] Among them, f k (x) is the objective function, and Ω is the decision space. The objective function contains multiple problems that need to be optimized, and the decision space contains all decision variables.

[0094] In this embodiment, a cyberattack detection model is constructed using the Pareto optimal solution method. In the Pareto method, for two decision vectors x and y, if f(x) is not greater than f(y) on any objective and less than f(y) on at least one objective, then x dominates y, or y is dominated by x. If x and y mutually dominate, then x and y are comparable. If f(x) and f(y) are equal on all objectives, then x and y are equivalent. If x and y neither dominate nor are equivalent, then x and y are incomparable. The dominance of x on y is denoted as f(x) / f(y). Pareto dominance defines the relationship between the objective functions obtained by two different decision vectors, making it easy to compare the advantages and disadvantages of the two decision vectors. If x dominates y, then x is superior to y in all objective function evaluations; conversely, y is superior to x in all objective function evaluations. If decision vector x is not dominated by any vector in the decision space, then x is a Pareto optimal solution. The set of all Pareto-optimal solutions constitutes the Pareto-optimal solution set, also known as the non-inferior solution set. Leveraging this characteristic of the Pareto algorithm, all data vectors corresponding to each cyber attack event are fed into each objective function. The objective function for which the data vector for each cyber attack event performs best is determined, and the type of cyber attack event corresponding to that objective function is used as the attack type for that cyber attack event. Different types of cyber attack events are placed into their respective solution sets. Based on the three types of cyber attack events described in this application, three Pareto-optimal solution sets can be generated.

[0095] For example, suppose cyber attack event A contains 100 attack event data items. Of these, 50 items perform well in the objective function corresponding to the cyber terrain and entity relationship type, 20 items perform well in the objective function corresponding to the cyber attack detection feature and anomaly type, and 30 items perform well in the objective function corresponding to the domain constraint type. Therefore, this cyber attack event belongs to the cyber terrain and entity relationship type. The relevant data of cyber attack event A is placed in the optimal solution set for the cyber terrain and entity relationship classification.

[0096] In this embodiment, a cyber attack detection classification model is constructed based on a multi-objective optimization method, which can effectively classify cyber attack event data, provide convenience for subsequent calculations, save time for subsequent analysis and calculations, and analyze the impact of attack events while optimizing calculations, and discover hidden classifications of attack event data.

[0097] S12: performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data.

[0098] In this embodiment, constraint analysis refers to analyzing the attack event classification results, i.e., the attack event data in the classified data set, using pre-set constraint conditions. The criticality of an attack event refers to the degree of impact the attack event has on the operating capability of the target software.

[0099] In this embodiment, a conditional constraint analysis is performed on the data set of each attack event classification result to determine the danger level of each attack event.

[0100] In this embodiment, the step of performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data includes:

[0101] S12-1: For each attack event in the attack event classification result data, determine the target software corresponding to the attack event according to the attack event information of the attack event.

[0102] In this embodiment, the attack classification result data are multiple data sets, and a certain number of attack event data in each data set corresponds to an attack event. The types of attack events in the same data set are the same. The event information corresponding to each data is recorded in the cyberspace event log data. By reading the event information in the log, the details of each attack event can be determined. The log data records the start time and end time of each event, the relevant hardware platform and relevant target software of each event, and other information.

[0103] In this embodiment, the event information corresponding to the attack event recorded in the cyberspace event log data is read to determine the target software corresponding to each attack event in the attack event classification result data. Furthermore, the target software corresponding to the attack event is scanned and analyzed to determine whether there is a vulnerability in the target software corresponding to the attack event.

[0104] For example, in a dataset of attack event classification result data, it is determined that the target software of attack event A is software C on hardware platform B.

[0105] S12-2: Determine the likelihood of the attack event affecting the target software based on pre-set constraints.

[0106] In this embodiment, an attack event generally exploits a system vulnerability to attack the target software, thereby affecting the target software. The impact mainly manifests itself in affecting the operating capability of the software.

[0107] In this embodiment, after determining the target software corresponding to the attack event, the likelihood of the attack event affecting the target software is determined. This can also be considered as a detection of cyber attack points. Through this detection, it can be determined whether the target software is vulnerable to attack. If the target software under attack does not have exploitable vulnerabilities, the target software is not susceptible to the attack event.

[0108] In this embodiment, the preset constraint conditions include at least one of the following: the target software exists on the target hardware platform targeted by the attack event, there is a vulnerability in the target software targeted by the attack event, and the attack event exploits the vulnerability in the target software to attack.

[0109] Attack events from cyberspace generally target target software on the hardware platform. Therefore, the above constraints are set based on the characteristics of the attack events. Based on the pre-set constraints, the characteristics of the attack events can be analyzed accordingly. The more conditions an attack event meets, the higher the possibility that the attack event will affect the target software.

[0110] In this embodiment, determining the likelihood of the attack event affecting the target software based on pre-set constraints includes:

[0111] S12-2-1: Determine, based on the attack event information of the attack event, the number of the attack events that satisfy the preset constraint condition;

[0112] In this embodiment, the cyberspace event log data records attack event information of the attack event, and the number of constraints satisfied by the attack event is determined based on the attack event information.

[0113] For example, the cyberspace event log data records attack event A: hardware platform B was attacked at 1:00 p.m. on January 1, 2022. Software C was running on hardware platform B, and there was vulnerability D in software C. Attack action A did not successfully exploit vulnerability B. Then the number of pre-set constraints that attack event A meets is 2.

[0114] S12-2-2: Determine the likelihood that the attack event will affect the target software based on the number of pre-set constraints satisfied by the attack event.

[0115] In this embodiment, after determining the number of expected constraints satisfied by the attack event, the likelihood of the attack event affecting the target software is removed.

[0116] In this embodiment, the more constraints an attack event satisfies, the greater the likelihood that the attack event will affect the target software. Based on the number of constraints satisfied by the attack event, an impact level is set for the likelihood that the attack event will affect the target software, which can be set to low, medium, and high.

[0117] For example, when attack event A meets one preset constraint, the impact level is set to low; when attack event A meets two preset constraints, the impact level is set to medium; when event A meets three preset constraints, the impact level is set to high.

[0118] S12-3: Determine the danger level of the attack event based on the likelihood of the attack event affecting the target software.

[0119] In this embodiment, after determining the likelihood that the attack event will affect the target software, the danger level of the attack event is determined.

[0120] In this embodiment, the higher the impact level of the attack event, the higher the risk level of the attack event. When the impact level of the attack event is low, the risk level of the attack event is low; when the impact level of the attack event is medium, the risk level of the attack event is medium; and when the impact level of the attack event is high, the risk level of the attack event is high.

[0121] After determining the severity of an attack, a lower weight is assigned to a low-severity attack. A higher weight is assigned to a high-severity attack. The size of the weight represents the severity of the attack.

[0122] In another embodiment of the present application, the risk level of the corresponding attack event can also be determined based on the importance of the target software. For example, when the target software is relatively important core software, the risk level of all attack events for the target software is set to high, regardless of how many constraints the attack event meets.

[0123] S13: Determine the damage degree of the target software corresponding to the attack event according to the danger level of the attack event.

[0124] In this embodiment, the degree of damage to the target software is the degree of degradation of the operating capability of the target software.

[0125] In this embodiment, after determining the danger level of the attack event, the damage level of the target software corresponding to the attack event can be determined.

[0126] In this embodiment, the step of determining the damage degree of the target software corresponding to the attack event according to the danger degree of the attack event includes:

[0127] S13 - 1 : Prioritizing target software corresponding to the attack event according to the danger level of the attack event, and obtaining priority ranking result data of the target software.

[0128] In this embodiment, attack events with a higher risk level have a higher weight among all attack events, and thus are given a higher priority for analysis, potentially causing greater damage to the entire platform. Attack events with a lower risk level have a lower weight among all attack events, and thus have less impact on the software, and thus are given a lower priority for analysis. The sorting result data is the result of sorting all software according to the risk level of the attack event they are subjected to. The sorting result data ranks the target software corresponding to all attack events.

[0129] For example, attack event A corresponds to software C. The danger level of attack event A is high, so software C has a high priority and is ranked higher; attack event B corresponds to software D. The danger level of attack event D is low, so software D has a low priority and is ranked lower.

[0130] S13-2: determining the current operating capability of each target software in turn according to the order of the target software in the sorting result data.

[0131] S13-3: Determine the damage degree of the target software according to the current operation capability of the target software and the normal operation capability of the target software.

[0132] In this embodiment, the current operating capability of the target software is the operating capability of the target software at the current moment. The normal operating capability of the target software is the operating capability of the target software under normal circumstances.

[0133] In this embodiment, the current operating capabilities of the target software are calculated sequentially, in descending order of priority, based on the target software order in the sorting result data. The degree of damage to the target software is then determined based on the difference between the target software's normal operating capability and its current operating capability. When the target software is damaged, the tasks and other functions performed by the target software are affected.

[0134] For example, the initial value of the target software's operational capability (POC) is 1, and after calculation, the current operational capability of the target software is 0.8, and the damage degree of the target software is 0.2, which means that the target software's operational capability is damaged by 20%.

[0135] In this embodiment, the step of determining the current operating capability of each target software in sequence according to the order of the target software in the sorting result data includes:

[0136] S13-2-1: Determine the operating capability of the target software after experiencing the attack event.

[0137] S13-2-2: Determine the operating capability of the dependent software of the target software that the target software depends on.

[0138] S13-3-3: Determine the current operating capability of the target software based on the operating capability of the target software after experiencing the attack event and the operating capability of the dependent software.

[0139] In this embodiment, the operating capability of the target software is considered based on two factors. The first factor is the decline in the operating capability of the target software after being attacked by cyberspace. The other factor is the operating capability of the target software after being affected by the dependent software when the target software has mutually dependent software.

[0140] In this embodiment, to determine the current operational capability of the target software, the target software's operational capability after experiencing a cyberattack is first determined. The operational capabilities of the target software's dependent software are then determined. Finally, based on the target software's operational capability after the attack and the operational capabilities of the dependent software, the current operational capability of the target software is determined. The operational capability of a single software can be determined based on analysis of the software's operational data.

[0141] For example, assuming that software A becomes the direct target of cyber attack X, and software A is dependent on software B, the current operational capability of software A is calculated as:

[0142] OC A (t')=Min(Max(POC A (t)-IF x (t'),0),OC B (t')) (2)

[0143] Among them, POC A (t) is the operating capability of software A at time t, IF x (t') is the influencing factor of attack action X at time t'>t, OC B (t') is the operating capability of software B at time t'>t, OC A (t') is the current operating capability of software A.

[0144] In another embodiment of the present application, software A is a terminal node in the cyberspace terrain. In this case, software A does not depend on any other software. The current operating capacity of software A is calculated as follows:

[0145] OC A (t')=Min(Max(POC A (t)-IF x (t'),0) (3)

[0146] In this case, POC can be considered A (t')=OC A (t').POC A (t') is the permanent running capability of software A at time t'>t.

[0147] In this embodiment, because the software is running based on certain work tasks, at the beginning of the work task, the software's operating capability value (POC) is generally 1, that is, the software is considered to be in a completely orderly running state at the beginning of the work task.

[0148] In this embodiment, the types of cyber attack events are effectively classified by establishing an optimization model, and the association between cyber events and software is completed. Then, through constraint analysis, the cyber attack points are effectively detected, and then according to the danger level of each cyber attack event, the damage level of the target software corresponding to the cyber attack event is accurately evaluated. Through the analysis of various cyber attack events, the pattern of cyber attack is accurately grasped, the vulnerabilities of the platform and software can be detected in time, and the software losses caused by cyber attack events and the losses to the work tasks performed by the software can be effectively evaluated. It can help staff accurately perceive the cyber terrain situation, and then improve cyber defense measures, ensure the safe operation of software assets, and the orderly implementation of work tasks.

[0149] Based on the same inventive concept, an embodiment of the present application provides a device for evaluating the damage level of target software. Figure 2 , Figure 2 FIG. 2 is a schematic diagram of a target software damage assessment device 200 proposed in one embodiment of the present application. Figure 2 As shown, the device includes:

[0150] Attack detection classification module 201, used to classify cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data;

[0151] An attack event analysis module 202 is configured to perform constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data;

[0152] The software evaluation module 203 is configured to determine the damage degree of the target software corresponding to the attack event according to the danger level of the attack event.

[0153] Optionally, the step of constructing the cyber-attack detection classification model includes:

[0154] Taking the type of attack events affecting the target software as an optimization target, constructing an objective function space of the cyber attack detection classification model;

[0155] constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software;

[0156] The cyber attack detection classification model is constructed according to the objective function space and the decision space.

[0157] Optionally, the attack detection and classification module includes:

[0158] a data input submodule, configured to input the cyberspace event log data into the cyberspace attack detection classification model;

[0159] an attack event data screening submodule, configured to screen attack event data targeting the target software from the cyberspace event log data using the cyberspace attack detection classification model;

[0160] The optimization analysis submodule is used to perform optimization analysis on the attack event data to obtain the attack event classification result data.

[0161] Optionally, the attack event analysis module includes:

[0162] a target software determination submodule, configured to determine, for each attack event in the attack event classification result data, the target software corresponding to the attack event according to the attack event information of the attack event;

[0163] A constraint analysis submodule, configured to determine the likelihood of the attack event affecting the target software based on pre-set constraint conditions;

[0164] The danger level determination submodule is used to determine the danger level of the attack event according to the possibility of the attack event affecting the target software.

[0165] Optionally, the preset constraint condition includes at least one of the following: target software exists on the target hardware platform targeted by the attack event, a vulnerability exists in the target software targeted by the attack event, and the attack event exploits the vulnerability in the target software to launch an attack.

[0166] Optionally, the constraint analysis submodule includes:

[0167] A first constraint condition analysis submodule, configured to determine, based on the attack event information of the attack event, the number of the attack events that satisfy the preset constraint conditions;

[0168] The second constraint condition analysis submodule is configured to determine the likelihood that the attack event will affect the target software based on the number of preset constraint conditions satisfied by the attack event.

[0169] Optionally, the software evaluation submodule includes:

[0170] The software sorting submodule is used to sort the target software corresponding to the attack event according to the danger level of the attack event, and obtain the sorting result data of the target software priority;

[0171] A current operating capability calculation submodule, configured to determine the current operating capability of each target software in sequence according to the target software order in the sorting result data;

[0172] The damage degree determination submodule is used to determine the damage degree of the target software according to the current operation capability of the target software and the normal operation capability of the target software.

[0173] Optionally, the current operating capacity calculation submodule includes:

[0174] A first operating capability determination submodule, configured to determine the operating capability of the target software after experiencing the attack event;

[0175] A second operating capability determination submodule is used to determine the operating capability of the dependent software of the target software that the target software depends on;

[0176] The third operating capability determination submodule is configured to determine the current operating capability of the target software according to the operating capability of the target software after experiencing the attack event and the operating capability of the dependent software.

[0177] Based on the same inventive concept, another embodiment of the present application provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for assessing the degree of damage of target software as described in any of the above embodiments of the present application.

[0178] Based on the same inventive concept, another embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When executed by the processor, the steps of the method for assessing the degree of damage of target software described in any of the above embodiments of the present application are implemented.

[0179] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0180] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0181] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0182] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0183] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0184] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0185] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0186] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0187] The above describes in detail the target software damage assessment method, apparatus, device, and storage medium provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only intended to help understand the method and core concept of the present application. At the same time, for those skilled in the art, based on the concept of the present application, there may be changes in the specific implementation methods and application scope. In summary, the contents of this specification should not be understood as limiting the present application.

Claims

1. A method for assessing the damage degree of target software, characterized in that: The method comprises: Classify cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data; performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data; Determining the extent of damage to the target software corresponding to the attack event based on the danger level of the attack event; The steps of constructing the cyber attack detection classification model include: Taking the type of attack events affecting the target software as an optimization target, constructing an objective function space of the cyber-attack detection classification model, wherein the objective function space includes all objective functions of the cyber-attack detection classification model, and the objective function is an optimization objective function constructed based on the attack events affecting the target software; constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software, wherein the decision space is a space containing possible variables of the objective function; The cyber attack detection classification model is constructed according to the objective function space and the decision space.

2. The method according to claim 1, characterized in that The cyberspace event log data is classified by the cyberspace attack detection classification model to obtain attack event classification result data, including: inputting the cyber event log data into the cyber attack detection classification model; Filtering attack event data targeting the target software from the cyberspace event log data using the cyberspace attack detection classification model; The attack event data is optimized and analyzed to obtain the attack event classification result data.

3. The method according to claim 1, characterized in that The performing constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data includes: For each attack event in the attack event classification result data, determining the target software corresponding to the attack event according to the attack event information of the attack event; Determining the likelihood of the attack event affecting the target software based on pre-set constraints; The danger level of the attack event is determined based on the likelihood that the attack event will affect the target software.

4. According to the method of claim 3, the pre-set constraint conditions include at least one of the following: the target software exists on the target hardware platform targeted by the attack event, there is a vulnerability in the target software targeted by the attack event, and the attack event exploits the vulnerability in the target software to attack.

5. The method according to claim 3, characterized in that Determining the likelihood of the attack event affecting the target software based on pre-set constraints includes: Determining, based on the attack event information of the attack event, the number of the attack events that satisfy the preset constraint condition; The possibility of the attack event affecting the target software is determined based on the number of the preset constraint conditions satisfied by the attack event.

6. The method according to claim 1, characterized in that Determining the damage degree of the target software corresponding to the attack event according to the danger degree of the attack event includes: Prioritize the target software corresponding to the attack event according to the danger level of the attack event, and obtain priority ranking result data of the target software; determining the current operating capability of each target software in turn according to the order of the target software in the sorting result data; The damage degree of the target software is determined according to the current operation capability of the target software and the normal operation capability of the target software.

7. The method according to claim 6, characterized in that Determining the current operating capability of each target software includes: Determining the operational capability of the target software after experiencing the attack event; Determining the operating capability of dependent software of target software that the target software depends on; The current operating capability of the target software is determined according to the operating capability of the target software after experiencing the attack event and the operating capability of the dependent software.

8. A device for assessing the damage level of target software, characterized in that: The device comprises: An attack detection classification module is used to classify cyberspace event log data using a cyberspace attack detection classification model to obtain attack event classification result data; an attack event analysis module, configured to perform constraint analysis on the attack event classification result data to determine the danger level of each attack event in the attack event classification result data; A software evaluation module, configured to determine the degree of damage to the target software corresponding to the attack event based on the danger level of the attack event; The steps of constructing the cyber attack detection classification model include: Taking the type of attack events affecting the target software as an optimization target, constructing an objective function space of the cyber-attack detection classification model, wherein the objective function space includes all objective functions of the cyber-attack detection classification model, and the objective function is an optimization objective function constructed based on the attack events affecting the target software; constructing a decision space of the cyber attack detection classification model based on all attack event vectors attacking the target software, wherein the decision space is a space containing possible variables of the objective function; The cyber attack detection classification model is constructed according to the objective function space and the decision space.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Method and device for determining Web application protecting effect

    CN108229176A