Network risk prediction method and device, processor and electronic device
By building a directed network graph and using graph neural network to output device risk values, the problem of low accuracy of network security risk prediction in the prior art is solved, and more accurate security risk prediction and effective security event handling are achieved.
Patent Information
- Application Number
- CN202211734945.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-30
AI Technical Summary
In the prior art, the accuracy of predicting whether the network has security risks is low, making it difficult for users to effectively handle security incidents and prevent subsequent attacks.
By building a directed graph of the network, obtain the risk matrix and weight values, and input it into the graph neural network, output the risk values of each device, and make security risk prediction based on these risk values.
Improves the accuracy of predicting whether there is a security risk in the network, helping users to handle security incidents more effectively and prevent potential attacks.
Smart Images

Figure CN116070382B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network risk prediction method and device, a processor, and an electronic device. Background Art
[0002] At present, there are more and more security protection devices, and a large number of security events are generated every day. However, most of the data may be false alarms and noise data, which causes the information that users need to pay attention to to be drowned. Users have no idea where to start with the alarms of daily security protection systems, and do not know how to deal with them. Moreover, after a security incident occurs, it affects the equipment, the scope of the impact, the severity of the consequences, and what other assets the attacker may attack. How to do a good job of protection for similar security incidents and avoid them in advance. This series of problems will lead to low accuracy in predicting whether there are security risks in the network.
[0003] With regard to the problem of low accuracy in predicting whether a network has security risks in related technologies, no effective solution has been proposed so far. Summary of the invention
[0004] The main purpose of the present application is to provide a network risk prediction method and device, a processor and an electronic device to solve the problem of low accuracy in predicting whether a network has security risks in the related art.
[0005] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for predicting network risks is provided. The method comprises: obtaining a network directed graph, wherein the network directed graph comprises at least a plurality of nodes and a plurality of edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network to be predicted for security risks; obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; inputting the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into a graph neural network, and outputting the risk value corresponding to each device in the target network; and predicting the security risks of the target network according to the risk value corresponding to each device in the target network.
[0006] Furthermore, based on the risk value corresponding to each device in the target network, security risk prediction for the target network includes: determining whether the risk value corresponding to each device in the target network is a preset value; if the risk value corresponding to each device in the target network is the preset value, determining that there is no security risk in the target network; if the risk value corresponding to each device in the target network is not the preset value, determining that there is a security risk in the target network.
[0007] Furthermore, obtaining a network directed graph includes: obtaining multiple devices in the target network; determining access relationships between the multiple devices in the target network; and determining the network directed graph based on the multiple devices in the target network and the access relationships between the multiple devices in the target network.
[0008] Furthermore, before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, the method also includes: obtaining the vulnerability information of each device in the network directed graph; determining whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph, then calculating the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph.
[0009] Furthermore, obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph includes: transforming the network directed graph to obtain the risk matrix corresponding to the network directed graph; calculating the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; determining the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; adjusting the initial weight value corresponding to each edge in the network directed graph based on the degree of influence of a security incident occurring in the target device in the network directed graph on other devices in the network directed graph, to obtain the weight value corresponding to each edge in the network directed graph.
[0010] Furthermore, based on the vulnerability information of each device in the network directed graph, determining whether there is a correlation and exploitation among the vulnerabilities of multiple devices in the network directed graph includes: obtaining a network security knowledge graph; and based on the network security knowledge graph and the vulnerability information of each device in the network directed graph, determining whether there is a correlation and exploitation among the vulnerabilities of multiple devices in the network directed graph.
[0011] Furthermore, obtaining the network security knowledge graph includes: obtaining multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of adopting each attack method; determining the network security knowledge graph based on the multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of adopting each attack method.
[0012] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a network risk prediction device is provided. The device includes: a first acquisition unit, used to acquire a network directed graph, wherein the network directed graph includes at least a plurality of nodes and a plurality of edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network to be predicted for security risk; a second acquisition unit, used to acquire the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph; a first processing unit, used to input the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into a graph neural network, and output the risk value corresponding to each device in the target network; a first prediction unit, used to predict the security risk of the target network according to the risk value corresponding to each device in the target network.
[0013] Furthermore, the first prediction unit includes: a first judgment module, used to judge whether the risk values corresponding to each device in the target network are all preset values; a first determination module, used to determine that there is no security risk in the target network if the risk values corresponding to each device in the target network are all preset values; and a second determination module, used to determine that there is a security risk in the target network if the risk values corresponding to each device in the target network are not all preset values.
[0014] Furthermore, the first acquisition unit includes: a first acquisition module, used to acquire multiple devices in the target network; a third determination module, used to determine the access relationship between the multiple devices in the target network; and a fourth determination module, used to determine the network directed graph based on the multiple devices in the target network and the access relationship between the multiple devices in the target network.
[0015] Furthermore, the device also includes: a third acquisition unit, used to obtain the vulnerability information of each device in the network directed graph before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph and the weight value corresponding to each edge in the network directed graph; a first determination unit, used to determine whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; and a first calculation unit, used to calculate the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph.
[0016] Furthermore, the second acquisition unit includes: a first processing module, used to transform the network directed graph to obtain a risk matrix corresponding to the network directed graph; a first calculation module, used to calculate the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; a fifth determination module, used to determine the degree of impact of a security incident occurring in the target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in the target device in the network directed graph indicates that the target device is under attack; a first adjustment module, used to adjust the initial weight value corresponding to each edge in the network directed graph based on the degree of impact of a security incident occurring in the target device in the network directed graph on other devices in the network directed graph, to obtain the weight value corresponding to each edge in the network directed graph.
[0017] Furthermore, the first determination unit includes: a second acquisition module for acquiring a network security knowledge graph; and a sixth determination module for determining whether there is a correlation and exploitation between the vulnerabilities of multiple devices in the network directed graph based on the network security knowledge graph and the vulnerability information of each device in the network directed graph.
[0018] Furthermore, the second acquisition module includes: a first acquisition sub-module, used to obtain a variety of attack devices that may be used to attack the network, the availability of the multiple attack devices and the consequences of using each attack device; a first determination sub-module, used to determine the network security knowledge graph based on the multiple attack devices that may be used to attack the network, the availability of the multiple attack devices and the consequences of using each attack device.
[0019] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a processor is provided, wherein the processor is used to run a program, wherein the program executes any one of the above-mentioned network risk prediction methods when running.
[0020] In order to achieve the above-mentioned purpose, according to another aspect of the present application, an electronic device is provided, which includes one or more processors and a memory, and the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the above-mentioned network risk prediction methods.
[0021] Through the present application, the following steps are adopted: obtaining a network directed graph, wherein the network directed graph includes at least multiple nodes and multiple edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network for security risk prediction; obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; inputting the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into a graph neural network, and outputting the risk value corresponding to each device in the target network; predicting the security risk of the target network based on the risk value corresponding to each device in the target network, thereby solving the problem of low accuracy in predicting whether a network has a security risk in the related art. A network directed graph is constructed for the target network for security risk prediction, and the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are obtained. The risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are input into the graph neural network, and the risk value corresponding to each device in the target network is output. Based on the risk value corresponding to each device in the target network, security risk prediction is performed on the target network, thereby achieving the effect of improving the accuracy of predicting whether the network has security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0023] Figure 1 is a flow chart of a network risk prediction method provided according to an embodiment of the present application;
[0024] Figure 2 is a schematic diagram of a network security knowledge graph constructed in an embodiment of the present application;
[0025] Figure 3 is a flowchart of an optional network risk prediction method provided according to an embodiment of the present application;
[0026] Figure 4is a schematic diagram of a network risk prediction device provided according to an embodiment of the present application;
[0027] Figure 5 is a schematic diagram of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0029] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between this system and the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain relevant information after receiving the consent information fed back by the aforementioned user or organization.
[0032] For the convenience of description, some nouns or terms involved in the embodiments of the present application are explained below:
[0033] Directed graph: represents the relationship between objects.
[0034] Graph Neural Network: Graph Neural Network (GNN) is a general term for algorithms that use neural networks to learn graph structured data, extract and discover features and patterns in graph structured data, and meet the needs of graph learning tasks such as clustering, classification, prediction, segmentation, and generation.
[0035] The present invention is described below in conjunction with preferred implementation steps. Figure 1 is a flow chart of a network risk prediction method provided in an embodiment of the present application, such as Figure 1 As shown, the method comprises the following steps:
[0036] Step S101, obtaining a network directed graph, wherein the network directed graph includes at least multiple nodes and multiple edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network for which security risk prediction is to be performed.
[0037] For example, a network directed graph corresponding to the network to be subjected to security risk prediction may be constructed according to the access relationship between multiple devices in the network.
[0038] Step S102, obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph.
[0039] For example, the constructed network directed graph is converted into a risk matrix, and the weight value corresponding to each node in the network directed graph and the weight value corresponding to each edge in the network directed graph are obtained.
[0040] Step S103, input the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and output the risk value corresponding to each device in the target network.
[0041] For example, the converted risk matrix, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph can be input into the graph neural network, and then the risk value corresponding to each device in the network to be predicted for security risks can be obtained.
[0042] Step S104: predicting the security risk of the target network according to the risk value corresponding to each device in the target network.
[0043] For example, based on the risk value corresponding to each device in the network to be predicted for security risk output by the graph neural network, it is predicted whether there is a security risk in the network.
[0044] Through the above steps S101 to S104, a network directed graph is constructed for the target network to be subjected to security risk prediction, and the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are obtained. Then, the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are input into the graph neural network, and the risk value corresponding to each device in the target network is output. Based on the risk value corresponding to each device in the target network, a security risk prediction is performed on the target network, thereby achieving the effect of improving the accuracy of predicting whether the network has security risks.
[0045] In order to quickly and accurately determine the network security knowledge graph, in the network risk prediction method provided in the embodiment of the present application, the network security knowledge graph can also be determined by the following steps: obtaining multiple attack methods that may be used to attack the network, the availability of multiple attack methods, and the consequences of using each attack method; determining the network security knowledge graph based on the multiple attack methods that may be used to attack the network, the availability of multiple attack methods, and the consequences of using each attack method.
[0046] For example, Figure 2 is a schematic diagram of the network security knowledge graph constructed in the embodiment of the present application, such as Figure 2 As shown, we can rely on the professional knowledge accumulation of security experts to collect and build a network security attack knowledge graph. We can build a knowledge graph based on the attack type and attack method as entities and the mutual exploitability of attack methods as relationships. We can also build a knowledge graph based on the preconditions of the attack method (such as vulnerabilities) and the impact or threat it produces as the attributes of the entity. Figure 2 The consequence indicates the possible consequences of using the attack method, and exploit indicates what kind of vulnerability the attack method exploits.
[0047] Through the above solution, a network security knowledge graph can be constructed quickly and accurately.
[0048] In order to quickly and accurately determine the network directed graph, in the network risk prediction method provided in the embodiment of the present application, the network directed graph can also be determined by the following steps: obtaining multiple devices in the target network; determining the access relationship between the multiple devices in the target network; determining the network directed graph based on the multiple devices in the target network and the access relationship between the multiple devices in the target network.
[0049] For example, you can import network device policies to build user network topology and a network directed graph, which represents the access relationship between multiple devices in the network.
[0050] Through the above scheme, a network directed graph can be constructed quickly and accurately.
[0051] In order to quickly and accurately calculate the initial weight value corresponding to each edge in a network directed graph, in the network risk prediction method provided in the embodiment of the present application, the initial weight value corresponding to each edge in the network directed graph can also be calculated by the following steps: obtaining the vulnerability information of each device in the network directed graph; determining whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph, then calculating the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between the multiple devices in the network directed graph.
[0052] For example, when combining the edge weight calculation of the vulnerability directed graph, the user asset vulnerability information can be prepared, and the asset vulnerability information is shown in Table 1. Then, according to the asset exposure, asset vulnerability level, utilization difficulty, and impact results, the threat value of the vulnerability is calculated and input into the constructed network directed graph. The threat value is used as the weight value of the node edge. The larger the weight value, the higher the threat value. The calculation formula is as follows:
[0053]
[0054] Table 1
[0055]
[0056]
[0057] Through the above scheme, the initial weight value corresponding to each edge in the network directed graph can be calculated quickly and accurately.
[0058] In order to quickly and accurately obtain the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, in the network risk prediction method provided in the embodiment of the present application, the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph can also be obtained through the following steps: transforming the network directed graph to obtain the risk matrix corresponding to the network directed graph; calculating the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; determining the degree of impact of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; adjusting the initial weight value corresponding to each edge in the network directed graph based on the degree of impact of a security incident occurring in the target device in the network directed graph on other devices in the network directed graph to obtain the weight value corresponding to each edge in the network directed graph.
[0059] For example, the network directed graph can be converted into a risk matrix first, and then the weight value corresponding to each node in the network directed graph can be calculated based on the vulnerability information. Then, the initial weight value corresponding to each edge in the network directed graph can be adjusted to obtain the weight value corresponding to each edge in the network directed graph.
[0060] Moreover, the initial weight value corresponding to each edge in the network directed graph can be adjusted to take into account the vulnerability association and exploitation between nodes and the mutual influence of security incident risks between nodes. According to the asset vulnerability and the constructed network security knowledge graph, each node entity in the graph is calculated to see whether there is an attack vulnerability association and exploitation with all nodes reachable by the entity, and the edge weights of the two nodes are adjusted as the attention coefficient between the nodes.
[0061] Through the above scheme, the weight value corresponding to each edge in the network directed graph can be adjusted quickly and accurately, thereby improving the accuracy of the weight value corresponding to each edge in the network directed graph.
[0062] In order to quickly and accurately determine whether the vulnerabilities between multiple devices in a network directed graph are associated and exploited, in the network risk prediction method provided in the embodiment of the present application, it is also possible to determine whether the vulnerabilities between multiple devices in the network directed graph are associated and exploited through the following steps: obtaining a network security knowledge graph; and determining whether the vulnerabilities between multiple devices in the network directed graph are associated and exploited based on the network security knowledge graph and the vulnerability information of each device in the network directed graph.
[0063] For example, based on the asset vulnerability and the constructed network security knowledge graph, it is possible to calculate whether there is an attack vulnerability associated with all nodes reachable from the entity.
[0064] Through the above solution, it is possible to quickly and accurately determine whether there is a correlation between the vulnerabilities of multiple devices in the network directed graph.
[0065] In order to quickly and accurately predict the security risks of the target network, in the network risk prediction method provided in the embodiment of the present application, the security risks of the target network can also be predicted through the following steps: determine whether the risk values corresponding to each device in the target network are all preset values; if the risk values corresponding to each device in the target network are all preset values, it is determined that there is no security risk in the target network; if the risk values corresponding to each device in the target network are not all preset values, it is determined that there is a security risk in the target network.
[0066] For example, the above preset value may be zero. That is, if the risk value of each device in the network is zero, it means that there is no security risk in the network, and if there is a device in the network whose risk value is not zero, it means that there is a security risk in the network.
[0067] Through the above solution, it is possible to quickly and accurately determine whether there are security risks in the network.
[0068] For example, Figure 3 is a flowchart of an optional network risk prediction method provided in an embodiment of the present application, such as Figure 3 As shown, the optional network risk prediction method includes the following steps:
[0069] Step 1: Cybersecurity knowledge graph construction:
[0070] Relying on the professional knowledge accumulation of security experts, we collect and build a network security attack knowledge graph. We build a knowledge graph based on the attack type and attack method as entities and the mutual exploitability of attack methods as relationships. We also build the preconditions of attack methods (such as vulnerabilities) and the impact or threat they produce as attributes of entities.
[0071] Step 2: Construct a network directed graph:
[0072] Import network device policies to build user network topology and construct a network directed graph.
[0073] Step 3: Calculate the edge weights of the vulnerability directed graph:
[0074] Prepare user asset vulnerability information, calculate the threat value of the vulnerability based on asset exposure, asset vulnerability level, difficulty of use, and impact results, input it into the directed graph constructed in step 2, and use the threat value as the weight value of the node edge. The larger the weight value, the higher the threat value.
[0075]
[0076] Step 4: Edge weight adjustment:
[0077] Considering the vulnerability association and exploitation between nodes, and the mutual influence of security incident risks between nodes, we calculate the attack vulnerability association and exploitation of all nodes reachable by each node entity in the graph according to the asset vulnerability and the network security knowledge graph prepared in step 1, and adjust the edge weights of the two nodes as the attention coefficient between the nodes.
[0078] Step 5: Network graph embedding model construction:
[0079] An embedding model based on autoencoder is used to extract the attribute features of network graph nodes. Multiple network attribute matrices corresponding to the nodes are taken as input. Each network attribute matrix undergoes a series of decoding and encoding operations. At the same time, in order to extract the topological structure information of the opportunity network, a hidden layer for integrating the original features in the encoding stage and a hidden layer for decomposing the embedded features in the decoding stage are added. Finally, an embedding matrix composed of node attribute embedding vectors is obtained as the output of the model.
[0080] Node threat attribute matrix:
[0081] R=(r1,r2,…,rn)
[0082] Encoder encoding part:
[0083]
[0084]
[0085]
[0086] Among them, f is the activation function, Q is the weight matrix, c is the bias matrix, l is the total number of encoder layers, and y i is the attribute matrix after the encoder conversion, r1, r2, …, rn are the node threat attribute values.
[0087] Output matrix:
[0088] S=(s1,s2,…,sn)
[0089] Among them, s1, s2, …, sn are node attribute embedding vectors.
[0090] Step 6: Use GNN graph neural network for risk assessment ranking:
[0091] The feature matrix composed of the attribute embedding vectors generated in step 5 is used as the input of the node risk assessment model, and the risk degree sequence RV composed of the node risk values is RV = {RV1, RV2, RV3, ..., RV n} as the output of the model.
[0092] Considering the vulnerability associations between nodes and the mutual influence of risks between nodes, the graph attention network GAT uses the association between nodes to perform convolution operations on adjacent nodes. By introducing the inter-node attention coefficient generated in step 4, the attention coefficient between the node and its neighbors is normalized by the softmax function to obtain the inter-node attention factor. Finally, the attention factor is used to perform weighted summation on the dynamic attribute embedding vector of the node to obtain a new node dynamic attribute embedding matrix that integrates domain information:
[0093] S'={s'1, s'2, s'3,...,s' n}
[0094] And use it as the input of the output layer, perform dimensionality reduction transformation on the updated node dynamic embedding vector, and obtain the asset risk urgency sequence composed of network node risk values:
[0095] RV={RV1,RV2,RV3,…,RV n}
[0096] Through the method provided in the embodiment of the present application, for example, the impact assessment on the intranet after the user's local area network suffers a network attack is performed as follows:
[0097] 1. Data preparation stage
[0098] (1) Collect intranet configuration information, import router and switch configuration information, and establish a network topology directed graph.
[0099] (2) Prepare all vulnerability information of network environment assets and perform standardized processing.
[0100] (3) Input vulnerability information and security events, calculate through the formulas in steps 3 and 4, and adjust the weight values.
[0101] (4) Graph embedding outputs attribute vector matrix.
[0102] 2. Application phase
[0103] (1) Output the network node risk assessment result matrix through the graph neural network and rank them according to risk.
[0104] (2) The higher the asset risk value, the greater the risk of attack.
[0105] Therefore, a directed graph is constructed according to the network topology, and the threat value is calculated as the edge weight of the directed graph by introducing information such as asset vulnerability, the difficulty of exploitable vulnerabilities, and the degree of vulnerability harm. The edge weights in the directed graph can be recalculated and adjusted by utilizing the exploitable correlation between vulnerabilities and the risk impact of adjacent nodes after a security incident occurs in an asset. The autoencoder graph embedding technology is used to combine the customer network topology information and the node threat attribute information to output an attribute matrix containing topological relationships. The weights of the mutual influence relationship between the directed graph nodes are calculated as the attention coefficient, and a graph neural network is constructed to perform weighted aggregation of the node attribute embedding vectors according to the relationship between nodes, which can realize the fusion of neighborhood information between nodes to calculate the risk value.
[0106] In summary, the network risk prediction method provided in the embodiment of the present application obtains a network directed graph, wherein the network directed graph includes at least multiple nodes and multiple edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network for security risk prediction; obtains the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph; inputs the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and outputs the risk value corresponding to each device in the target network; performs security risk prediction on the target network based on the risk value corresponding to each device in the target network, thereby solving the problem of low accuracy in predicting whether a network has a security risk in the related art. A network directed graph is constructed for the target network for security risk prediction, and the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are obtained. The risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are input into the graph neural network, and the risk value corresponding to each device in the target network is output. Based on the risk value corresponding to each device in the target network, security risk prediction is performed on the target network, thereby achieving the effect of improving the accuracy of predicting whether the network has security risks.
[0107] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0108] The embodiment of the present application also provides a network risk prediction device. It should be noted that the network risk prediction device of the embodiment of the present application can be used to execute the network risk prediction method provided by the embodiment of the present application. The network risk prediction device provided by the embodiment of the present application is introduced below.
[0109] Figure 4 Schematic diagram of a risk prediction device for a network according to an embodiment of the present application. Figure 4 As shown, the device includes: a first acquisition unit 401, a second acquisition unit 402, a first processing unit 403 and a first prediction unit 404.
[0110] Specifically, the first acquisition unit 401 is used to acquire a network directed graph, wherein the network directed graph includes at least a plurality of nodes and a plurality of edges, each node is used to represent each device in the target network, and each edge is used to represent an access relationship between multiple devices in the target network, and the target network is a network for which security risk prediction is to be performed;
[0111] The second acquisition unit 402 is used to acquire the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph;
[0112] The first processing unit 403 is used to input the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and output the risk value corresponding to each device in the target network;
[0113] The first prediction unit 404 is used to predict the security risk of the target network according to the risk value corresponding to each device in the target network.
[0114] In summary, the network risk prediction device provided in the embodiment of the present application obtains a network directed graph through a first acquisition unit 401, wherein the network directed graph includes at least multiple nodes and multiple edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network for security risk prediction; the second acquisition unit 402 obtains the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph; the first processing unit 403 inputs the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and outputs the risk value corresponding to each device in the target network; the first prediction unit 404 performs security risk prediction on the target network based on the risk value corresponding to each device in the target network, thereby solving the problem of low accuracy in predicting whether a network has a security risk in the related art. A network directed graph is constructed for the target network for security risk prediction, and the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are obtained. The risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph are input into the graph neural network, and the risk value corresponding to each device in the target network is output. Based on the risk value corresponding to each device in the target network, security risk prediction is performed on the target network, thereby achieving the effect of improving the accuracy of predicting whether the network has security risks.
[0115] Optionally, in the risk prediction device for the network provided in the embodiment of the present application, the first prediction unit includes: a first judgment module, used to judge whether the risk values corresponding to each device in the target network are all preset values; a first determination module, used to determine that there is no security risk in the target network if the risk values corresponding to each device in the target network are all preset values; and a second determination module, used to determine that there is a security risk in the target network if the risk values corresponding to each device in the target network are not all preset values.
[0116] Optionally, in the network risk prediction device provided in an embodiment of the present application, the first acquisition unit includes: a first acquisition module, used to acquire multiple devices in the target network; a third determination module, used to determine the access relationship between the multiple devices in the target network; and a fourth determination module, used to determine the network directed graph based on the multiple devices in the target network and the access relationship between the multiple devices in the target network.
[0117] Optionally, in the network risk prediction device provided in the embodiment of the present application, the device also includes: a third acquisition unit, used to obtain the vulnerability information of each device in the network directed graph before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph; a first determination unit, used to determine whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; and a first calculation unit, used to calculate the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph.
[0118] Optionally, in the network risk prediction device provided in the embodiment of the present application, the second acquisition unit includes: a first processing module, used to transform the network directed graph to obtain a risk matrix corresponding to the network directed graph; a first calculation module, used to calculate the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; a fifth determination module, used to determine the degree of impact of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; a first adjustment module, used to adjust the initial weight value corresponding to each edge in the network directed graph based on the degree of impact of a security incident occurring in the target device in the network directed graph on other devices in the network directed graph, to obtain the weight value corresponding to each edge in the network directed graph.
[0119] Optionally, in the network risk prediction device provided in the embodiment of the present application, the first determination unit includes: a second acquisition module, used to obtain a network security knowledge graph; a sixth determination module, used to determine whether there is a correlation and exploitation between the vulnerabilities of multiple devices in the network directed graph based on the network security knowledge graph and the vulnerability information of each device in the network directed graph.
[0120] Optionally, in the network risk prediction device provided in the embodiment of the present application, the second acquisition module includes: a first acquisition sub-module, used to obtain a variety of attack devices that may be used to attack the network, the availability of the multiple attack devices, and the consequences of using each attack device; a first determination sub-module, used to determine the network security knowledge graph based on the multiple attack devices that may be used to attack the network, the availability of the multiple attack devices, and the consequences of using each attack device.
[0121] The network risk prediction device includes a processor and a memory. The above-mentioned first acquisition unit 401, second acquisition unit 402, first processing unit 403 and first prediction unit 404 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize corresponding functions.
[0122] The processor contains a kernel, which calls the corresponding program unit from the memory. One or more kernels can be set, and the accuracy of predicting whether there is a security risk in the network can be improved by adjusting the kernel parameters.
[0123] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0124] An embodiment of the present invention provides a computer-readable storage medium on which a program is stored. When the program is executed by a processor, the risk prediction method of the network is implemented.
[0125] An embodiment of the present invention provides a processor, which is used to run a program, wherein the risk prediction method of the network is executed when the program is running.
[0126] like Figure 5As shown, an embodiment of the present invention provides an electronic device, the device includes a processor, a memory, and a program stored in the memory and executable on the processor, and the processor implements the following steps when executing the program: obtaining a network directed graph, wherein the network directed graph includes at least a plurality of nodes and a plurality of edges, each node is used to represent each device in a target network, and each edge is used to represent an access relationship between a plurality of devices in the target network, and the target network is a network for which security risk prediction is to be performed; obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; inputting the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into a graph neural network, and outputting a risk value corresponding to each device in the target network; and performing security risk prediction on the target network based on the risk value corresponding to each device in the target network.
[0127] When the processor executes the program, the following steps are also implemented: based on the risk value corresponding to each device in the target network, security risk prediction for the target network includes: judging whether the risk value corresponding to each device in the target network is a preset value; if the risk value corresponding to each device in the target network is the preset value, determining that there is no security risk in the target network; if the risk value corresponding to each device in the target network is not the preset value, determining that there is a security risk in the target network.
[0128] When the processor executes the program, the following steps are also implemented: obtaining a network directed graph includes: obtaining multiple devices in the target network; determining the access relationship between the multiple devices in the target network; and determining the network directed graph based on the access relationship between the multiple devices in the target network and the multiple devices in the target network.
[0129] When the processor executes the program, the following steps are also implemented: before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, the method also includes: obtaining the vulnerability information of each device in the network directed graph; determining whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph, then calculating the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph.
[0130] When the processor executes the program, the following steps are also implemented: obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, including: transforming the network directed graph to obtain the risk matrix corresponding to the network directed graph; calculating the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; determining the degree of influence of a security incident on other devices in the network directed graph after a target device in the network directed graph has a security incident, wherein a security incident on the target device in the network directed graph indicates that the target device has been attacked; adjusting the initial weight value corresponding to each edge in the network directed graph based on the degree of influence of a security incident on other devices in the network directed graph after a security incident on the target device in the network directed graph has a security incident, and obtaining the weight value corresponding to each edge in the network directed graph.
[0131] When the processor executes the program, the following steps are also implemented: based on the vulnerability information of each device in the network directed graph, determining whether there is a correlation and utilization between the vulnerabilities of multiple devices in the network directed graph, including: obtaining a network security knowledge graph; based on the network security knowledge graph and the vulnerability information of each device in the network directed graph, determining whether there is a correlation and utilization between the vulnerabilities of multiple devices in the network directed graph.
[0132] When the processor executes the program, the following steps are also implemented: Obtaining a network security knowledge graph includes: obtaining multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of using each attack method; determining the network security knowledge graph based on the multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of using each attack method.
[0133] The devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0134] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program that initializes the following method steps: obtaining a network directed graph, wherein the network directed graph includes at least multiple nodes and multiple edges, each node is used to represent each device in the target network, and each edge is used to represent the access relationship between multiple devices in the target network, and the target network is a network for security risk prediction; obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; inputting the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into a graph neural network, and outputting the risk value corresponding to each device in the target network; and performing security risk prediction on the target network based on the risk value corresponding to each device in the target network.
[0135] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: based on the risk value corresponding to each device in the target network, predicting the security risk of the target network includes: judging whether the risk value corresponding to each device in the target network is a preset value; if the risk value corresponding to each device in the target network is the preset value, determining that there is no security risk in the target network; if the risk value corresponding to each device in the target network is not the preset value, determining that there is a security risk in the target network.
[0136] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: obtaining a network directed graph includes: obtaining multiple devices in the target network; determining the access relationship between the multiple devices in the target network; determining the network directed graph based on the multiple devices in the target network and the access relationship between the multiple devices in the target network.
[0137] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, the method also includes: obtaining the vulnerability information of each device in the network directed graph; determining whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph, then calculating the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph.
[0138] When executed on a data processing device, it is also suitable for executing a program that initializes the following method steps: obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, including: transforming the network directed graph to obtain the risk matrix corresponding to the network directed graph; calculating the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; determining the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; adjusting the initial weight value corresponding to each edge in the network directed graph based on the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, to obtain the weight value corresponding to each edge in the network directed graph.
[0139] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: determining whether there is a correlation and utilization between the vulnerabilities of multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph, including: obtaining a network security knowledge graph; determining whether there is a correlation and utilization between the vulnerabilities of multiple devices in the network directed graph based on the network security knowledge graph and the vulnerability information of each device in the network directed graph.
[0140] When executed on a data processing device, it is also suitable for executing a program that is initialized with the following method steps: obtaining a network security knowledge graph including: obtaining multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of using each attack method; determining the network security knowledge graph based on the multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of using each attack method.
[0141] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0142] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0143] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0144] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0145] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0146] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0147] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0148] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0149] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0150] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A network risk prediction method, characterized in that: include: Obtain a network directed graph, wherein the network directed graph includes at least a plurality of nodes and a plurality of edges, each node is used to represent each device in a target network, and each edge is used to represent an access relationship between multiple devices in the target network, and the target network is a network for which security risk prediction is to be performed; Obtaining a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; Inputting the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and outputting the risk value corresponding to each device in the target network; Predicting the security risk of the target network according to the risk value corresponding to each device in the target network; Wherein, before obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph, the method further includes: obtaining vulnerability information of each device in the network directed graph; determining whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph, then calculating the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph; Obtaining the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph includes: transforming the network directed graph to obtain the risk matrix corresponding to the network directed graph; calculating the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; determining the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; adjusting the initial weight value corresponding to each edge in the network directed graph based on the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph to obtain the weight value corresponding to each edge in the network directed graph.
2. The method according to claim 1, characterized in that: Predicting the security risk of the target network according to the risk value corresponding to each device in the target network includes: Determine whether the risk value corresponding to each device in the target network is a preset value; If the risk value corresponding to each device in the target network is the preset value, it is determined that there is no security risk in the target network; If the risk value corresponding to each device in the target network is not the preset value, it is determined that there is a security risk in the target network.
3. The method according to claim 1, characterized in that Obtaining a network directed graph includes: Acquire multiple devices in the target network; Determining access relationships between multiple devices in the target network; The network directed graph is determined according to a plurality of devices in the target network and access relationships between the plurality of devices in the target network.
4. The method according to claim 1, characterized in that Determining whether there is a correlation between the vulnerabilities of multiple devices in the network directed graph according to the vulnerability information of each device in the network directed graph comprises: Obtain network security knowledge graph; Based on the network security knowledge graph and the vulnerability information of each device in the network directed graph, it is determined whether there is a correlation and exploitation between the vulnerabilities of multiple devices in the network directed graph.
5. The method according to claim 4, characterized in that Obtaining the network security knowledge graph includes: Obtain multiple attack methods that may be used to attack the network, the exploitability of the multiple attack methods, and the consequences of using each attack method; The network security knowledge graph is determined based on multiple attack methods that may be used to attack the network, the availability of the multiple attack methods, and the consequences of using each attack method.
6. A network risk prediction device, characterized in that: include: A first acquisition unit is used to acquire a network directed graph, wherein the network directed graph includes at least a plurality of nodes and a plurality of edges, each node is used to represent each device in a target network, and each edge is used to represent an access relationship between multiple devices in the target network, and the target network is a network for which security risk prediction is to be performed; A second acquisition unit is used to acquire a risk matrix corresponding to the network directed graph, a weight value corresponding to each node in the network directed graph, and a weight value corresponding to each edge in the network directed graph; A first processing unit is used to input the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph into the graph neural network, and output the risk value corresponding to each device in the target network; A first prediction unit, configured to perform security risk prediction on the target network according to a risk value corresponding to each device in the target network; The risk prediction device for a network also includes: a third acquisition unit, which is used to acquire vulnerability information of each device in the network directed graph before acquiring the risk matrix corresponding to the network directed graph, the weight value corresponding to each node in the network directed graph, and the weight value corresponding to each edge in the network directed graph; a first determination unit, which is used to determine whether there is associated utilization of the vulnerabilities between multiple devices in the network directed graph based on the vulnerability information of each device in the network directed graph; and a first calculation unit, which is used to calculate the initial weight value corresponding to each edge in the network directed graph based on the degree of associated utilization of the vulnerabilities between multiple devices in the network directed graph if there is associated utilization of the vulnerabilities between multiple devices in the network directed graph; The second acquisition unit includes: a first processing module, which is used to transform the network directed graph to obtain a risk matrix corresponding to the network directed graph; a first calculation module, which is used to calculate the weight value corresponding to each node in the network directed graph based on the vulnerability information of each device in the network directed graph; a fifth determination module, which is used to determine the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, wherein a security incident occurring in a target device in the network directed graph indicates that the target device is under attack; a first adjustment module, which is used to adjust the initial weight value corresponding to each edge in the network directed graph based on the degree of influence of a security incident occurring in a target device in the network directed graph on other devices in the network directed graph, to obtain the weight value corresponding to each edge in the network directed graph.
7. A processor, characterized in that: The processor is used to run a program, wherein the program executes the network risk prediction method described in any one of claims 1 to 5 when running.
8. An electronic device, characterized in that: It includes one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the network risk prediction method described in any one of claims 1 to 5.
Citation Information
Patent Citations
Network security equipment knowledge reasoning method, device and system and storage medium
CN113254674A
Event occurrence probability prediction method and device, electronic equipment and storage medium
CN114118583A