A network security capability evaluation method, device and equipment
By acquiring security event data and configuration parameters from the network security protection system, and calculating the evaluation value of each security event, the problem of the inability to effectively assess network security capabilities in existing technologies is solved, and accurate assessment of network security capabilities is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEUSOFT CORP
- Filing Date
- 2022-12-01
- Publication Date
- 2026-07-24
AI Technical Summary
Existing technologies lack effective methods for rating cybersecurity capabilities, making it impossible to effectively evaluate cybersecurity capabilities.
By obtaining basic data and configuration parameters of security events from the network security protection system, an evaluation value for each security event is calculated, and these evaluation values are used to assess the overall network security capability.
It enables effective evaluation of cybersecurity capabilities, characterizes the current level of ability to defend against security incidents, and provides an overall evaluation value for cybersecurity capabilities.
Smart Images

Figure CN116032536B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, specifically to a network security capability evaluation method, apparatus, and equipment. Background Technology
[0002] With the rapid development of the internet, mobile networks, and the Internet of Things, human social, economic, and daily activities are rapidly becoming networked. Simultaneously, cyber threats have entered an era of advanced threats. Any system within an enterprise that stores data has become a target for attackers. Security incidents are typically only discovered after they occur and the data has been widely circulated online, making it difficult to pinpoint the specific time and manner of the incident.
[0003] Against this backdrop, whether driven by self-interest or social responsibility, enterprises have begun building more sophisticated internal security analytics systems. As society as a whole undergoes digital transformation, cybersecurity is crucial for the digital transformation of enterprise businesses.
[0004] However, the current lack of effective methods for rating cybersecurity capabilities makes it impossible to effectively evaluate cybersecurity capabilities. Summary of the Invention
[0005] In view of this, embodiments of this application provide a method, apparatus, and device for evaluating network security capabilities, which can evaluate network security capabilities.
[0006] To address the above problems, the technical solutions provided in this application are as follows:
[0007] A method for evaluating network security capabilities, the method comprising:
[0008] The basic data of each security event among multiple security events is obtained from the network security protection system, and the basic data is used to characterize the event occurrence status.
[0009] Obtain the configuration parameters for each security event, including relevant configuration parameters for the event occurrence state;
[0010] Based on the basic data and configuration parameters of the target security event, an evaluation value for the target security event is obtained; the evaluation value of the target security event is used to characterize the level of ability to defend against the target security event; the target security event is any one of a plurality of security events;
[0011] A network security capability evaluation value is obtained based on the evaluation values of multiple security events.
[0012] In one possible implementation, the basic data of each security event includes the number of times the event has been handled, the number of times the event has not been handled, and the attack stage to which it belongs. The configuration parameters of each security event include the counting frequency of the handled event, the counting frequency of the unhandled event, the risk level weight, and the weight of the attack stage to which it belongs. The step of obtaining the evaluation value of the target security event based on the basic data and configuration parameters of the target security event includes:
[0013] The coefficient of the event handling status of the target security event is calculated based on the number of times the event has been handled and the counting frequency of the handled status.
[0014] Calculate the coefficient of the unhandled state of the target security event based on the number of times the unhandled state occurs and the counting frequency of the unhandled state.
[0015] The evaluation value of the target security event is obtained by adding the coefficient of the event's "handled" status to the coefficient of the event's "unhandled" status, and then multiplying the coefficient by the risk level weight and the weight of the attack stage to which the target security event belongs.
[0016] In one possible implementation, calculating the coefficient of the event handling status of the target security event based on the number of times the event has been handled and the counting frequency of the handled status includes:
[0017] The coefficient of the event handling status of the target security event is obtained by dividing the number of times the event has been handled by the counting frequency of the handled status by the integer part of the result.
[0018] The step of calculating the coefficient of the unhandled state of the target security event based on the number of times the unhandled state of the target security event occurs and the counting frequency of the unhandled state includes:
[0019] The coefficient of the unhandled state of the target security event is obtained by dividing the number of times the event is in an unhandled state by the counting frequency of the unhandled state and rounding down.
[0020] In one possible implementation, obtaining the network security capability evaluation value based on the evaluation values of multiple security events includes:
[0021] The minimum value between the sum of the evaluation values of multiple security events and a preset value is determined as the network security capability evaluation value.
[0022] In one possible implementation, the method further includes:
[0023] The attack phase to which each of the aforementioned security events belongs is identified as the first target phase;
[0024] The attack phases belonging to the first target phase in the attack matrix are marked first, and an attack matrix defense capability coverage map is generated.
[0025] In one possible implementation, the method further includes:
[0026] The attack phase that the network security protection system can defend against is defined as the second target phase;
[0027] The attack phases belonging to the second target phase in the attack matrix are marked first to generate an attack matrix defense capability coverage map.
[0028] In one possible implementation, the method further includes:
[0029] Security events with a non-zero number of unresolved events are classified as the third target phase of the attack.
[0030] A second mark is applied to the attack phases belonging to the third target phase in the attack matrix to generate an attack matrix hit map.
[0031] A network security capability evaluation device, the device comprising:
[0032] The first acquisition unit is used to acquire basic data of each security event among multiple security events from the network security protection system. The basic data is used to characterize the event occurrence status.
[0033] The second acquisition unit is used to acquire the configuration parameters of each security event, the configuration parameters including relevant configuration parameters for the event occurrence state;
[0034] The calculation unit is used to obtain an evaluation value of the target security event based on the basic data and configuration parameters of the target security event; the evaluation value of the target security event is used to characterize the capability level of defending against the target security event; the target security event is any one of a plurality of security events;
[0035] The first determining unit is used to obtain a network security capability evaluation value based on the evaluation values of multiple security events.
[0036] A network security capability evaluation device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the network security capability evaluation method described above.
[0037] A computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the network security capability evaluation method described above.
[0038] Therefore, the embodiments of this application have the following beneficial effects:
[0039] This application embodiment obtains basic data and configuration parameters for each security event among multiple security events intercepted by the network security protection system. Based on the basic data and configuration parameters of each security event, an evaluation value for each security event can be calculated. The evaluation value of a security event can characterize the current capability level for defending against that security event. By using the evaluation values of multiple security events, an overall network security capability evaluation value can be obtained, thereby effectively evaluating the current network security capability. Attached Figure Description
[0040] Figure 1 A schematic diagram illustrating an exemplary application scenario provided in this application embodiment;
[0041] Figure 2 A flowchart illustrating a network security capability evaluation method provided in this application embodiment;
[0042] Figure 3 A schematic diagram of the attack matrix defense capability coverage map and the attack matrix hit map provided in the embodiments of this application;
[0043] Figure 4 This is a schematic diagram of a network security capability evaluation device provided in an embodiment of this application. Detailed Implementation
[0044] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the embodiments of this application will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0045] To facilitate understanding and explanation of the technical solutions provided in the embodiments of this application, the background technology of the embodiments of this application will be described first below.
[0046] To achieve cybersecurity, enterprises are now building more sophisticated internal security analysis systems and deploying various network security protection systems, such as firewalls, antivirus software, and intrusion detection systems (IDS). However, despite these internal security analysis systems, enterprises currently lack effective methods to evaluate their current network security capabilities.
[0047] Based on this, embodiments of this application provide a method, apparatus, and device for evaluating network security capabilities. This involves acquiring basic data and configuration parameters for each security event among multiple security events intercepted by a network security protection system. Based on the basic data and configuration parameters of each security event, an evaluation value can be calculated for each security event. The evaluation value of a security event characterizes the current capability level for defending against that security event. By using the evaluation values of multiple security events, an overall network security capability evaluation value can be obtained, thereby effectively evaluating the current network security capability.
[0048] To facilitate understanding of the network security capability evaluation method provided in the embodiments of this application, the following is combined with... Figure 1 The example scenario is shown below. See also... Figure 1 As shown in the figure, this figure is a schematic diagram of an exemplary application scenario provided in the embodiments of this application.
[0049] The network security capability evaluation method provided in this application embodiment can be applied to a security analysis system 101. The security analysis system 101 obtains basic data for each security event from multiple security events reported by various network security protection systems 102. Simultaneously, the security analysis system 101 can also obtain the configuration parameters for each security event. Therefore, based on the basic data and configuration parameters of each security event, the security analysis system 101 can calculate the evaluation value for each security event. Through the evaluation values of each security event, the overall network security capability evaluation value can be obtained, thereby effectively evaluating the current network security capability.
[0050] Those skilled in the art will understand that Figure 1 The schematic diagram shown is merely one example in which embodiments of this application can be implemented. The scope of application of the embodiments of this application is not limited by any aspect of this framework.
[0051] To facilitate understanding of this application, the following description, in conjunction with the accompanying drawings, illustrates a network security capability evaluation method provided by an embodiment of this application.
[0052] See Figure 2 As shown, this figure is a flowchart of a network security capability evaluation method provided in an embodiment of this application. Figure 2 As shown, the method may include S201-S204:
[0053] S201: Obtain basic data for each of multiple security events from the network security protection system. The basic data is used to characterize the state of the event.
[0054] To improve network security, various network security protection systems are typically deployed within the internal network, such as firewalls, antivirus systems, and Intrusion Detection Systems (IDS). These systems intercept and handle security incidents. Multiple security incidents are common, and each incident can occur multiple times. The network security protection system can report the basic data of each intercepted security incident to the security analysis system. This basic data characterizes the occurrence status of each security incident.
[0055] In one possible implementation, the basic data for each security event includes the number of times the event has been handled, the number of times it has been unhandled, and the attack stage to which it belongs. That is, the number of times the event has been handled, the number of times it has been unhandled, and the attack stage to which it belongs can all characterize the event occurrence status of the security event.
[0056] A network security protection system can handle security incidents, meaning it has the capability to defend against them. Conversely, a network security protection system may fail to handle intercepted security incidents, meaning it lacks the capability to defend against them. For the same security incident occurring multiple times, the system may handle only a portion of the incidents. Therefore, the basic data for a security incident includes the number of times the incident was handled and the number of times it was not handled. For example, if a security incident involves a Trojan virus and occurs 100 times, with 90 instances of the incident being handled and 10 instances being unhandled.
[0057] Simultaneously, network security protection systems can also report the attack phase of a security incident. According to the adversarial tactics and technology knowledge base initiated by the cybersecurity company MITRE, security incidents can be divided into 14 attack phases, including reconnaissance, resource development, initial access, execution, presence, privilege escalation, protection escape, credential acquisition, discovery, lateral movement, data collection, remote control, data leakage, and impact. Security incidents at different attack phases have different levels of danger.
[0058] S202: Obtain the configuration parameters for each security event, including relevant configuration parameters for the event occurrence status.
[0059] Each security event also has pre-configured configuration parameters, which may include relevant configuration parameters for the event occurrence status. These configuration parameters can be manually configured according to the actual situation.
[0060] In one possible implementation, the configuration parameters for each security event include the counting frequency of the event's handled state, the counting frequency of the event's unhandled state, the risk level weight, and the weight of the attack phase to which it belongs. In other words, these configuration parameters are all related to the event's occurrence state.
[0061] The counting frequency for handled events indicates how many times a handled event can be counted, while the counting frequency for unhandled events indicates how many unhandled events can be counted. For example, a counting frequency of 10,000 for handled events means that 10,000 handled events are required to be counted, while a counting frequency of 1 for unhandled events means that 1 unhandled event is required to be counted. Because unhandled events have a greater impact on evaluating security capabilities, their counting frequency is usually lower than that of handled events.
[0062] The risk level of a security incident and the danger level of its attack stage differ. Therefore, different security incidents can have their own corresponding risk level weights and attack stage weights set separately. The risk level weights and attack stage weights of a security incident can be set according to actual circumstances, and the embodiments of this application do not limit their values.
[0063] S203: Based on the basic data and configuration parameters of the target security event, obtain the evaluation value of the target security event; the evaluation value of the target security event is used to characterize the level of ability to defend against the target security event; the target security event is any one of multiple security events.
[0064] By selecting any one of multiple security events as the target security event, and based on its basic data and configuration parameters, an evaluation value can be calculated for that target security event. The evaluation value of the target security event characterizes the ability level of various network security protection systems deployed in the current network to defend against that target security event. For example, the lower the evaluation value of the target security event, the stronger its ability to defend against that target security event.
[0065] Each security event is selected as the target security event, and the evaluation value of each security event can be calculated.
[0066] The specific implementation method of obtaining the evaluation value of the target security event based on the basic data and configuration parameters of the target security event will be described in detail in subsequent embodiments, and will not be repeated here.
[0067] S204: Obtain a cybersecurity capability evaluation value based on the evaluation values of multiple security events.
[0068] By evaluating multiple security incidents, a comprehensive network security capability assessment value can be obtained, which evaluates the current network security capabilities.
[0069] Based on the descriptions in S201-S204, this embodiment of the application obtains basic data of each security event among multiple security events intercepted by the network security protection system and obtains configuration parameters for each security event. Based on the basic data and configuration parameters of each security event, an evaluation value for each security event can be calculated. The evaluation value of a security event can characterize the current capability level for defending against that security event. Through the evaluation values of multiple security events, an overall network security capability evaluation value can be obtained, thereby effectively evaluating the current network security capability.
[0070] In one possible implementation, the specific implementation of S203 obtaining the evaluation value of the target security event based on the basic data and configuration parameters of the target security event may include the following steps:
[0071] A1: Calculate the coefficient of the event handling status of the target security event based on the number of times the event has been handled and the counting frequency of the handled status.
[0072] Target security events include both handled and unhandled states. Understandably, if the number of unhandled states is not zero, it indicates that a target security event has not been addressed, potentially impacting current network security. Therefore, it's necessary to calculate the coefficients for both the handled and unhandled states of the target security event. Based on the number of handled states and the counting frequency of handled states, the coefficient for the handled state is calculated. The handled state of the target security event serves as a means to evaluate the ability to defend against it.
[0073] In one possible implementation, the specific implementation of step A1, which calculates the coefficient of the event's handled state based on the number of times the event has been handled and the counting frequency of the handled state, may include:
[0074] Divide the number of times the target security event has been handled by the count frequency of the handled state and round down to obtain the coefficient of the target security event's handled state.
[0075] For example, if the target security event is a Trojan virus, the number of events handled is 90, the count frequency of handled events is 10000, and floor(90 / 10000) = 0, where floor is a floor function that rounds down, the coefficient of the event handling status of the target security event is 0.
[0076] A2: Calculate the coefficient of the unhandled state of the target security event based on the number of times the unhandled state occurs and the counting frequency of the unhandled state.
[0077] Similarly, based on the number of times the target security event is in an unhandled state and the counting frequency of the unhandled state, the coefficient of the target security event's unhandled state is calculated. The ability to defend against the target security event is evaluated from another perspective through the unhandled state of the target security event.
[0078] In one possible implementation, step A2, which calculates the coefficient of the unhandled state of the target security event based on the number of times the unhandled state occurs and the counting frequency of the unhandled state, may specifically include:
[0079] Divide the number of times the target security event is in an unhandled state by the counting frequency of unhandled states and round down to obtain the coefficient of the unhandled state of the target security event.
[0080] For example, if the target security event is a Trojan virus, the number of unhandled events is 10, the counting frequency of unhandled events is 1, and floor(10 / 1) = 10, where floor is a floor function that rounds down to the nearest integer, the coefficient of the unhandled status of the target security event is 10.
[0081] A3: Add the coefficient of the target security event's "handled" status to the coefficient of the target security event's "unhandled" status, and then multiply by the risk level weight of the target security event and the weight of its attack stage to obtain the evaluation value of the target security event.
[0082] The ability to defend against a target security incident is assessed by adding the coefficient for the incident's "handled" status to the coefficient for its "unhandled" status, based on the incident's handling status. This assessment is then multiplied by the incident's risk level weight and the weight of its attack phase to obtain the incident's evaluation value.
[0083] For example, if the target security incident is a Trojan virus, the coefficient for the "handled" status of the target security incident is 0, and the coefficient for the "unhandled" status is 10. The risk level of the target security incident is "high," and the risk level weight for "high" is 1. The attack stage of the target security incident is the "data outreach" stage, and the weight of the "data outreach" stage is 1. Then the evaluation value of the target security incident is (0+10)*1*1=10.
[0084] As an example, the evaluation value of a target security event can be calculated using the following formula:
[0085]
[0086] Where the i-th security event is the target security event, k is the event handling status value of the target security event, k=1 indicates the event has been handled, and k=2 indicates the event has not been handled. Let k=1 and k=2 respectively. When k=1, f represents the number of times an event has been handled, indicating the target security incident's status. k The coefficient of the event handling status of the target security event is calculated based on the counting frequency of the event handling status. When k=2, f represents the number of times an event remains unresolved, indicating a target security incident. k The coefficient of the unhandled state of the target security event is calculated by counting the frequency of the unhandled state of the target security event.
[0087] The coefficients for the handled and unhandled states of the target security event are summed and multiplied by r. i Multiply by p i This yields the evaluation value of the target security event. Where r... i p represents the risk level weight of the target security event. i This represents the weight of the attack phase to which the target security event belongs. Through the above calculation process, the lower the evaluation value of the target security event, the stronger the ability to defend against that target security event.
[0088] In this embodiment of the application, by utilizing relevant data on the status of the target security event as handled, relevant data on the status as unhandled, risk level weights, and the weights of the attack phase to which it belongs, the current ability to defend against the target security event can be comprehensively evaluated, and an evaluation value of the target security event can be obtained.
[0089] In one possible implementation, a network security capability evaluation value is obtained based on the evaluation values of multiple security events, including:
[0090] The minimum value between the sum of the evaluation values of multiple security events and a preset value is determined as the network security capability evaluation value.
[0091] In practical applications, the evaluation value of network security capabilities can be determined within a preset range, such as 0-100, where 0 indicates high security defense capability and 100 indicates low security defense capability.
[0092] The sum of the evaluation values of multiple security events is compared with a preset value, and the smaller value is taken as the network security capability evaluation value. The preset value is the maximum value within a preset range, such as 100. This embodiment of the application does not limit the value of the preset value. When the sum of the evaluation values of multiple security events is less than the preset value, the sum of the evaluation values of multiple security events is the network security capability evaluation value; when the sum of the evaluation values of multiple security events is greater than or equal to the preset value, the preset value is the network security capability evaluation value.
[0093] As an example, the cybersecurity capability evaluation value T can be calculated using the following formula:
[0094]
[0095] in, The evaluation value of the i-th security event is calculated. The evaluation values of the m security events are summed. The sum is compared with the preset value of 100. The minimum value between the two is taken as the network security capability evaluation value T.
[0096] This application embodiment utilizes the evaluation values of multiple security events to ultimately obtain a network security capability evaluation value.
[0097] In addition, the embodiments of this application can also more intuitively display the attack stages that the internal network can defend against and the attack stages where security incidents cannot be handled.
[0098] In one possible implementation, based on the above embodiments, the method provided in this application may further include:
[0099] The attack phase to which each security incident belongs is identified as the first target phase.
[0100] The attack phases belonging to the first target phase in the attack matrix are marked first, and an attack matrix defense capability coverage map is generated.
[0101] In this embodiment, obtaining the attack stage of a security event from the network security protection system indicates that the system can intercept the event, meaning it has the capability to defend against it. These attack stages can then be marked in the attack matrix to generate an attack matrix defense capability coverage map. This map represents which attack stages the internal network currently defends against. The attack matrix is built based on the attack stages.
[0102] In practical applications, each attack phase can be further subdivided into multiple defensive techniques. Within the attack matrix, the defensive techniques corresponding to security events can be marked as the first marker, generating an attack matrix defense capability coverage map. See also... Figure 3As shown, the attack matrix includes 14 attack phases, each corresponding to multiple defense techniques. For example, the execution phase corresponds to defense techniques T41, T42, and T43, while the data outreach phase corresponds to defense techniques T131, T132, and T133. For instance, if the attack phase of a security incident is data outreach, specifically corresponding to defense techniques T131 and T132, then T131 and T132 within the data outreach phase can be marked as the first step (as shown by the left diagonal line in the figure), generating an attack matrix defense capability coverage map.
[0103] In one possible implementation, based on the above embodiments, the method provided in this application may further include:
[0104] The attack phase that the network security protection system can defend against is identified as the second target phase.
[0105] The attack phases belonging to the second target phase in the attack matrix are marked as first, and an attack matrix defense capability coverage map is generated.
[0106] In this embodiment, the attack phases that the network security protection system can defend against can also be obtained from the functional description of the network security protection system itself. These attack phases are then marked to generate an attack matrix defense capability coverage map. In other words, an attack matrix defense capability coverage map is generated based on the theoretically defendable attack phases of the network security protection system.
[0107] In one possible implementation, based on the above embodiments, the method provided in this application may further include:
[0108] Security events with a non-zero number of unresolved events are classified as the third target phase of the attack.
[0109] A second mark is applied to the attack phases belonging to the third target phase in the attack matrix to generate an attack matrix hit map.
[0110] If the number of times an unresolved security event occurs is not zero, it indicates that these security events were not successfully defended against. A second label is then applied to the attack phase to which these security events belong, generating an attack matrix hit map. The attack matrix hit map represents which attack phases the current internal network has failed to defend against.
[0111] Specifically, within the attack matrix, the defensive techniques corresponding to undefended security events can be a second-order marker, generating an attack matrix hit map. See also... Figure 3 As shown, for example, if a security incident that could not be successfully defended belongs to the data collection phase of the attack, specifically, corresponding to the T111 defense technology, the T111 in the data collection phase can be marked a second time (as shown by the right diagonal line in the figure) to generate an attack matrix hit map.
[0112] In this embodiment of the application, the attack matrix defense capability coverage map and the attack matrix hit map can be used to subjectively display the attack stages that the current network can defend against and the attack stages that have not been successfully defended against, making it more convenient for users to view.
[0113] Based on the network security capability evaluation method provided in the above-described method embodiments, this application also provides a network security capability evaluation device, which will be described below with reference to the accompanying drawings.
[0114] See Figure 4 As shown in the figure, this is a schematic diagram of the structure of a network security capability evaluation device provided in an embodiment of this application. Figure 4 As shown, the network security capability evaluation device includes:
[0115] The first acquisition unit 401 is used to acquire basic data of each security event among multiple security events from the network security protection system. The basic data is used to characterize the event occurrence status.
[0116] The second acquisition unit 402 is used to acquire configuration parameters for each security event, the configuration parameters including relevant configuration parameters for the event occurrence state;
[0117] The calculation unit 403 is used to obtain an evaluation value of the target security event based on the basic data and configuration parameters of the target security event; the evaluation value of the target security event is used to characterize the capability level of defending against the target security event; the target security event is any one of a plurality of security events;
[0118] The first determining unit 404 is used to obtain a network security capability evaluation value based on the evaluation values of multiple security events.
[0119] In one possible implementation, the basic data of each security event includes the number of times the event has been handled, the number of times the event has not been handled, and the attack stage to which it belongs. The configuration parameters of each security event include the counting frequency of the handled event, the counting frequency of the unhandled event, the risk level weight, and the weight of the attack stage to which it belongs. The calculation unit includes:
[0120] The first calculation subunit is used to calculate the coefficient of the event handling status of the target security event based on the number of times the event handling status has been handled and the counting frequency of the handling status.
[0121] The second calculation subunit is used to calculate the coefficient of the unhandled state of the target security event based on the number of times the unhandled state of the target security event occurs and the counting frequency of the unhandled state.
[0122] The third calculation subunit is used to add the coefficient of the target security event's unhandled status to the coefficient of the event's handled status, and then multiply it by the risk level weight of the target security event and the weight of the attack stage to which it belongs, to obtain the evaluation value of the target security event.
[0123] In one possible implementation, the first computational subunit is specifically used for:
[0124] The coefficient of the event handling status of the target security event is obtained by dividing the number of times the event has been handled by the counting frequency of the handled status by the integer part of the result.
[0125] The second calculation subunit is specifically used for:
[0126] The coefficient of the unhandled state of the target security event is obtained by dividing the number of times the event is in an unhandled state by the counting frequency of the unhandled state and rounding down.
[0127] In one possible implementation, the first determining unit is specifically used for:
[0128] The minimum value between the sum of the evaluation values of multiple security events and a preset value is determined as the network security capability evaluation value.
[0129] In one possible implementation, the device further includes:
[0130] The second determining unit is used to determine the attack stage to which each of the security events belongs as the first target stage;
[0131] The first generation unit is used to mark the attack phases belonging to the first target phase in the attack matrix and generate an attack matrix defense capability coverage map.
[0132] In one possible implementation, the device further includes:
[0133] The third determining unit is used to determine the attack phase that the network security protection system can defend against as the second target phase;
[0134] The second generation unit is used to mark the attack phases in the attack matrix that belong to the second target phase, and generate an attack matrix defense capability coverage map.
[0135] In one possible implementation, the device further includes:
[0136] The fourth determining unit is used to determine the attack phase to which a security event with a non-zero number of unhandled events belongs as the third target phase;
[0137] The third generation unit is used to perform a second marking on the attack stages belonging to the third target stage in the attack matrix, and generate an attack matrix hit map.
[0138] In addition, this application embodiment also provides a network security capability evaluation device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the network security capability evaluation method as described in any of the above claims.
[0139] In addition, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the network security capability evaluation method as described in any of the preceding claims.
[0140] This application embodiment obtains basic data and configuration parameters for each security event among multiple security events intercepted by the network security protection system. Based on the basic data and configuration parameters of each security event, an evaluation value for each security event can be calculated. The evaluation value of a security event can characterize the current capability level for defending against that security event. By using the evaluation values of multiple security events, an overall network security capability evaluation value can be obtained, thereby effectively evaluating the current network security capability.
[0141] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.
[0142] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0143] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0144] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0145] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for evaluating network security capabilities, characterized in that, The method includes: The basic data of each security event among multiple security events is obtained from the network security protection system, and the basic data is used to characterize the event occurrence status. Obtain the configuration parameters for each security event, including relevant configuration parameters for the event occurrence state; Based on the basic data and configuration parameters of the target security event, an evaluation value for the target security event is obtained; the evaluation value of the target security event is used to characterize the level of ability to defend against the target security event; the target security event is any one of a plurality of security events; A network security capability evaluation value is obtained based on the evaluation values of multiple security events. The basic data for each security event includes the number of times the event has been handled, the number of times the event has not been handled, and the attack stage to which it belongs. The configuration parameters for each security event include the counting frequency of the handled event, the counting frequency of the unhandled event, the risk level weight, and the weight of the attack stage to which it belongs. The evaluation value of the target security event is obtained based on its basic data and configuration parameters, including: The coefficient of the event handling status of the target security event is calculated based on the number of times the event has been handled and the counting frequency of the handled status. Calculate the coefficient of the unhandled state of the target security event based on the number of times the unhandled state occurs and the counting frequency of the unhandled state. The evaluation value of the target security event is obtained by adding the coefficient of the event's "handled" status to the coefficient of the event's "unhandled" status, and then multiplying the coefficient by the risk level weight and the weight of the attack stage to which the target security event belongs.
2. The method according to claim 1, characterized in that, The step of calculating the coefficient of the event handling status of the target security event based on the number of times the event has been handled and the counting frequency of the handled status includes: The coefficient of the event handling status of the target security event is obtained by dividing the number of times the event has been handled by the counting frequency of the handled status by the integer part of the result. The step of calculating the coefficient of the unhandled state of the target security event based on the number of times the unhandled state of the target security event occurs and the counting frequency of the unhandled state includes: The coefficient of the unhandled state of the target security event is obtained by dividing the number of times the event is in an unhandled state by the counting frequency of the unhandled state and rounding down.
3. The method according to claim 1, characterized in that, The process of obtaining a network security capability evaluation value based on the evaluation values of multiple security events includes: The minimum value between the sum of the evaluation values of multiple security events and a preset value is determined as the network security capability evaluation value.
4. The method according to claim 1, characterized in that, The method further includes: The attack phase to which each of the aforementioned security events belongs is identified as the first target phase; The attack phases belonging to the first target phase in the attack matrix are marked first, and an attack matrix defense capability coverage map is generated.
5. The method according to claim 1, characterized in that, The method further includes: The attack phase that the network security protection system can defend against is defined as the second target phase; The attack phases belonging to the second target phase in the attack matrix are marked first to generate an attack matrix defense capability coverage map.
6. The method according to claim 1, characterized in that, The method further includes: Security events with a non-zero number of unresolved events are classified as the third target phase of the attack. A second mark is applied to the attack phases belonging to the third target phase in the attack matrix to generate an attack matrix hit map.
7. A network security capability evaluation device, characterized in that, The device includes: The first acquisition unit is used to acquire basic data of each security event among multiple security events from the network security protection system. The basic data is used to characterize the event occurrence status. The second acquisition unit is used to acquire the configuration parameters of each security event, the configuration parameters including relevant configuration parameters for the event occurrence state; The calculation unit is used to obtain an evaluation value of the target security event based on the basic data and configuration parameters of the target security event; the evaluation value of the target security event is used to characterize the capability level of defending against the target security event; the target security event is any one of a plurality of security events; The first determining unit is used to obtain a network security capability evaluation value based on the evaluation values of multiple security events; The basic data for each security event includes the number of times the event has been handled, the number of times the event has not been handled, and the attack stage to which it belongs. The configuration parameters for each security event include the counting frequency of the handled event, the counting frequency of the unhandled event, the risk level weight, and the weight of the attack stage to which it belongs. The calculation unit includes: The first calculation subunit is used to calculate the coefficient of the event handling status of the target security event based on the number of times the event handling status of the target security event has been handled and the counting frequency of the handling status. The second calculation subunit is used to calculate the coefficient of the unhandled state of the target security event based on the number of times the unhandled state of the target security event occurs and the counting frequency of the unhandled state. The third calculation subunit is used to add the coefficient of the target security event's unhandled status to the coefficient of the event's handled status, and then multiply it by the risk level weight of the target security event and the weight of the attack stage to which it belongs, to obtain the evaluation value of the target security event.
8. A network security capability evaluation device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the network security capability evaluation method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to perform the network security capability evaluation method as described in any one of claims 1-6.