Method and system for constructing knowledge graph for network security risk assessment
By constructing a knowledge graph that supports forward, reverse and bidirectional relationships in network security risk assessment, the problem of single relationship direction in existing technologies is solved, and more flexible and accurate user retrieval and display effects are achieved.
Patent Information
- Application Number
- CN202310139651.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2043-02-20
AI Technical Summary
In network security risk assessment, the existing knowledge graph displays the relationship between objects in a single direction and cannot effectively reflect bidirectional or reverse relationships, resulting in insufficient integration with network security-related application systems.
Provides a knowledge graph for network security risk assessment, supports the display of forward, reverse and bidirectional association relationships, automatically switches the direction of association relationships based on user search needs, and constructs 3D or planar relationship graphs to display associated data.
The combination of knowledge graphs and network security-related application systems has been optimized, which has improved the accuracy and flexibility of user retrieval and met the search needs of different users.
Smart Images

Figure CN116167441B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of knowledge graphs, and in particular to knowledge graphs and construction methods for network security risk assessment. Background Art
[0002] Cybersecurity risk assessment refers to the process of scientifically evaluating the confidentiality, integrity, controllability, availability and other security attributes of a network system based on relevant information security technologies and management standards. It involves the vulnerability of the network system, cybersecurity threats and the actual impact of the vulnerability being exploited by threat actors, and determines the cybersecurity risk level based on the potential impact of security incidents.
[0003] A knowledge graph is essentially a large-scale knowledge base that uses graph data structures and other technologies to describe objective facts and their relationships. The cybersecurity knowledge graph aggregates data related to cybersecurity risk assessments, including laws, standards, policies, institutions, and individuals, into knowledge, and organizes the relationships within this knowledge into a graph. It intelligently matches user search queries to user data, and intelligently recommends specific knowledge data based on user attributes and behavior.
[0004] However, in the formed knowledge graph, there is a problem with the direction of the relationship between objects when displaying the relationship. The direction of the relationship in the existing knowledge graph is usually displayed in a single direction, but when the knowledge graph is applied to network risk assessment, the relationship between objects is sometimes reverse or bidirectional, resulting in deficiencies in the integration of knowledge graphs with network security-related application systems. Summary of the Invention
[0005] In order to optimize the combination of knowledge graphs and network security related application systems, this application provides a knowledge graph for network security risk assessment and a construction method.
[0006] First, the knowledge graph for cybersecurity risk assessment provided in this application adopts the following technical solutions:
[0007] A knowledge graph for network security risk assessment includes a first object, a second object, and a knowledge graph association relationship displayed on a visualization interface. The knowledge graph association relationship displays the association direction between the first object and the second object. The knowledge graph association relationship includes a forward association relationship and a reverse association relationship. The forward association relationship and the reverse association relationship display opposite relationship directions, and the forward association relationship and the reverse association relationship can be switched between.
[0008] By adopting the above technical solution, the first object and the second object can display a positive correlation relationship, a reverse correlation relationship, and a bidirectional correlation relationship. The effect of the correlation direction can be switched according to the user's search needs to optimize the combination of the knowledge graph and network security related application systems.
[0009] In a second aspect, this application provides a method for constructing a knowledge graph for network security risk assessment, which is used to construct the above-mentioned knowledge graph for network security risk assessment, using the following technical solutions:
[0010] A method for constructing a knowledge graph for network security risk assessment includes: classifying and associating the acquired first data to obtain the first object, the second object and the knowledge graph association relationship; responding to a knowledge graph association relationship selection instruction, constructing a knowledge graph based on the first object, the second object, the knowledge graph association relationship and a preset knowledge graph construction model; responding to a user search instruction, judging the display relationship between the first object and the second object based on the user's attribute information and behavior information, and pushing the knowledge graph association relationship between the first object and the second object on a visual interface.
[0011] By adopting the above technical solution, the first object and the second object can be displayed with a positive correlation, a reverse correlation, and a bidirectional correlation. According to the user's search needs, the correlation can be automatically judged and switched to optimize the combination of the knowledge graph and network security-related application systems.
[0012] Preferably, the classification and association of the acquired first data to obtain the association relationship between the first object, the second object and the knowledge graph includes: performing data processing on the acquired first data to obtain the second data; and associating and binding the first object and the second object in the second data.
[0013] Preferably, the associating and binding of the first object and the second object in the second data includes: performing forward associating and binding of the first object and the second object; and performing reverse associating and binding of the first object and the second object.
[0014] Preferably, in response to the knowledge graph association relationship selection instruction, a model is constructed based on the first object, the second object, the knowledge graph association relationship and the preset knowledge graph, and the construction of the knowledge graph includes: matching the second data with the project field; constructing a model based on the preset knowledge graph, and associating and displaying the matched second data through the knowledge graph.
[0015] Preferably, the first data obtained is classified and associated to obtain the association relationship between the first object, the second object and the knowledge graph, and the first data is obtained in a manner including a manual acquisition method and an automatic acquisition method.
[0016] Preferably, the knowledge graph is a 3D relationship graph or a plane relationship graph to display the relationship data information in the preset association relationship library, and the relationship data information includes the association data generated by the forward association and the association data generated by the reverse association.
[0017] On the third aspect, the present application discloses a system for constructing a knowledge graph for network security risk assessment, which adopts the above-mentioned method for constructing a knowledge graph for network security risk assessment, including: a data acquisition module, used to classify and associate the acquired first data, and obtain the first object, the second object and the knowledge graph association relationship; a knowledge graph construction module, used to respond to a knowledge graph association relationship selection instruction, and construct a knowledge graph based on the first object, the second object, the knowledge graph association relationship and a preset knowledge graph construction model; a retrieval module, used to respond to a user retrieval instruction, judge the display relationship between the first object and the second object according to the user's attribute information and behavior information, and push the knowledge graph association relationship between the first object and the second object on a visual interface.
[0018] By adopting the above technical solution, the original data source is obtained through the data acquisition module, and a knowledge graph that can match the network security risk assessment system and platform is constructed through the knowledge graph construction module. The user's search instructions are obtained through the retrieval module to determine whether the display relationship between the first object and the second object is a positive relationship or a reverse relationship, and displayed on the knowledge graph.
[0019] In a fourth aspect, the present application discloses a terminal device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the processor loads and executes the computer program, the above-mentioned method for constructing a knowledge graph for network security risk assessment is adopted.
[0020] By adopting the above technical solution, a computer program is generated through the above-mentioned method of constructing a knowledge graph for network security risk assessment, and stored in a memory to be loaded and executed by a processor. Thus, a terminal device is manufactured based on the memory and the processor, which is convenient for users to use.
[0021] In a fourth aspect, the present application discloses a computer-readable storage medium, which adopts the following technical solution: a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the above-mentioned method for constructing a knowledge graph for network security risk assessment is adopted.
[0022] By adopting the above technical solution, a computer program is generated through the above-mentioned method of constructing a knowledge graph for network security risk assessment, and stored in a computer-readable storage medium to be loaded and executed by a processor. The computer-readable storage medium facilitates the readability and storage of the computer program. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is a method flow chart of steps S1-S3 in the knowledge graph and construction method of network security risk assessment in an embodiment of the present application.
[0024] Figure 2 It is a method flow chart of steps S10-S11 in the knowledge graph and construction method of network security risk assessment in an embodiment of the present application.
[0025] Figure 3 It is a method flow chart of steps S110-S111 in the knowledge graph and construction method of network security risk assessment in an embodiment of the present application.
[0026] Figure 4 It is a method flow chart of steps S20-S21 in the knowledge graph and construction method of network security risk assessment in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The following is combined with Figure 1-4 This application is described in further detail.
[0028] The present application discloses a knowledge graph and construction method for network security risk assessment.
[0029] S1: Classify and associate the acquired first data to obtain the association relationship between the first object, the second object and the knowledge graph;
[0030] S10: Processing the acquired first data to obtain second data;
[0031] The first data acquisition method includes manual acquisition method and automatic acquisition method. Among them, the first data refers to knowledge data. Based on network security-related laws, regulations, policies and standards, institutional personnel and product information, etc., it is committed to network security risk assessment. These knowledge data are used as the basis for classifying and grading each network security assessment matter. For example, according to the assessment steps such as grading and filing, and the knowledge types such as laws, regulations, policies and standards, designated knowledge data can be corresponding to different matters.
[0032] The manual acquisition method is manual input, and the automatic acquisition method is crawling through the web crawler. The knowledge data obtained through the above two channels is cleaned and integrated to remove duplicate data that appears after merging different data sources, and obtain higher-quality second data;
[0033] S11: Associating and binding the first object and the second object in the second data;
[0034] S110: Perform forward association binding on the first object and the second object;
[0035] In this application, the first object is data A, and the second object is data B. After data A is put into the database, the name and attribute information of data A are recorded. After data B is put into the database, the record name and attribute information of data B are recorded. Forward association binding is to match the name of data A with the attributes of data B and other data. After the match is successful, an association relationship is created and stored in the association relationship library.
[0036] S111: Perform reverse association binding on the first object and the second object;
[0037] Specifically, each attribute information of data A is used to match the name information of data B and other data until a match is found. After a successful match, a relationship is created in the relationship library. The reverse association will require the title of the associated data to be associated with the title of other data.
[0038] Through forward association and reverse association, all associated data are associated and bound.
[0039] S2: In response to the knowledge graph association relationship selection instruction, construct a knowledge graph based on the first object, the second object, the knowledge graph association relationship and a preset knowledge graph construction model;
[0040] S20: Match the second data with the project field;
[0041] Specifically, the second data's title and attribute information is matched against the project domain. Project domains here include, but are not limited to, cybersecurity risk assessment and its sub-domains, such as cybersecurity multi-level protection, critical information infrastructure security protection, commercial cryptography security assessment, data security protection, and personal information protection. Through aggregation processing, relevant project domains aggregate related second data and bind the associated relationships.
[0042] S21: Build a model based on a preset knowledge graph, and associate and display the matched second data through the knowledge graph;
[0043] The matched second data is used to build a model through a knowledge graph to construct a knowledge graph to obtain a knowledge graph for network security risk assessment.
[0044] The data generated by the network security knowledge graph is embedded into the network security assessment related platform. For example, the network security knowledge data and graph are embedded into the network security level protection comprehensive management platform to provide assessment basis, such as the basis, templates and process diagrams for the prescribed actions and processes such as security level registration. In addition, a general version of the network security level protection assessment operation manual is also provided to support the knowledge data required in the network security risk assessment process.
[0045] S3: In response to a user search instruction, push the knowledge graph association relationship between the first object and the second object on a visual interface based on the user's attribute information and behavior information;
[0046] Among them, the knowledge graph of network security risk assessment includes: a first object, a second object and a knowledge graph association relationship displayed on a visual interface, the knowledge graph association relationship displays the association direction between the first object and the second object, the knowledge graph association relationship includes a forward association relationship and a reverse association relationship, the forward association relationship and the reverse association relationship display opposite relationship directions, and the forward association relationship and the reverse association relationship can be switched between.
[0047] The knowledge graph is a 3D relationship diagram or a flat relationship diagram, which mainly displays the data information of the relationships in the association relationship library, including the associated data generated by forward associations and the associated data generated by reverse associations. The association has a direction line and can be displayed separately according to the inclusion and inclusion relationships of the data attributes, but only one type of association can be displayed at the same time.
[0048] To facilitate related queries and other attribute information of the data, the data format can be displayed through components such as echarts and 3d-force-graph.
[0049] This application can also provide users with accurate, relevant and customer-desired knowledge graph-related data through manual knowledge retrieval and customer attributes, operation behaviors, etc.
[0050] The implementation principle of the method for constructing a knowledge graph for network security risk assessment in the embodiment of the present application is: to enable the first object and the second object to display a positive correlation relationship, a reverse correlation relationship, and a bidirectional correlation relationship, and to automatically judge and switch the correlation relationship according to the user's search needs to optimize the combination of the knowledge graph and the network security-related application system.
[0051] The present application also discloses a system for constructing a knowledge graph for network security risk assessment, which uses the method for constructing a knowledge graph for network security risk assessment in the above embodiment, including:
[0052] A data acquisition module, configured to classify and associate the acquired first data to obtain an association relationship between the first object, the second object, and the knowledge graph;
[0053] A knowledge graph construction module, configured to construct a knowledge graph based on the first object, the second object, the knowledge graph association relationship, and a preset knowledge graph construction model in response to a knowledge graph association relationship selection instruction;
[0054] The retrieval module is used to respond to the user's retrieval instruction and push the knowledge graph association relationship between the first object and the second object on the visual interface based on the user's attribute information and behavior information.
[0055] The implementation principle of the system for constructing a knowledge graph for network security risk assessment in the embodiment of the present application is as follows: the original data source is obtained through the data acquisition module, a knowledge graph that can match the network security risk assessment system and platform is constructed through the knowledge graph construction module, and the user's search instructions are obtained through the retrieval module to determine whether the display relationship between the first object and the second object is a positive relationship or a reverse relationship, and displayed on the knowledge graph.
[0056] An embodiment of the present application also discloses a terminal device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein the processor adopts the method for constructing a knowledge graph for network security risk assessment of the above embodiment when executing the computer program.
[0057] Among them, the terminal device can be a computer device such as a desktop computer, a laptop computer or a cloud server, and the terminal device includes but is not limited to a processor and a memory. For example, the terminal device can also include input and output devices, network access devices and buses, etc.
[0058] Among them, the processor can adopt a central processing unit (CPU). Of course, according to actual usage, other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. can also be adopted. The general-purpose processor can adopt a microprocessor or any conventional processor, etc., and this application does not impose any restrictions on this.
[0059] Among them, the memory can be an internal storage unit of the terminal device, such as the hard disk or memory of the terminal device, or it can be an external storage device of the terminal device, such as a plug-in hard disk, smart memory card (SMC), secure digital card (SD) or flash memory card (FC) equipped on the terminal device, etc., and the memory can also be a combination of the internal storage unit and the external storage device of the terminal device. The memory is used to store computer programs and other programs and data required by the terminal device. The memory can also be used to temporarily store data that has been output or is to be output. This application does not impose any restrictions on this.
[0060] Among them, through this terminal device, the method for constructing the knowledge graph of network security risk assessment in the above embodiment is stored in the memory of the terminal device, and is loaded and executed on the processor of the terminal device for user convenience.
[0061] An embodiment of the present application further discloses a computer-readable storage medium, and the computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the method for constructing a knowledge graph for network security risk assessment of the above embodiment is adopted.
[0062] Among them, the computer program can be stored in a computer-readable medium, the computer program includes computer program code, the computer program code can be in the form of source code, object code, executable file or certain middleware, etc. The computer-readable medium includes any entity or device that can carry computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that computer-readable medium includes but is not limited to the above-mentioned components.
[0063] Among them, through this computer-readable storage medium, the method for constructing the knowledge graph of network security risk assessment in the above-mentioned embodiment is stored in the computer-readable storage medium, and is loaded and executed on the processor to facilitate the storage and application of the method for constructing the knowledge graph of network security risk assessment.
[0064] The above are all preferred embodiments of the present application and are not intended to limit the scope of protection of this application. Unless otherwise specified, any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features. In other words, unless otherwise specified, each feature is merely an example of a series of equivalent or similar features.
Claims
1. A method for constructing a knowledge graph for network security risk assessment, which is used to construct a knowledge graph for network security risk assessment, and is characterized by: include: The knowledge graph for network security risk assessment includes: a first object, a second object, and a knowledge graph association relationship displayed on a visual interface, wherein the knowledge graph association relationship displays the association direction between the first object and the second object, and the knowledge graph association relationship includes a forward association relationship and a reverse association relationship, wherein the forward association relationship and the reverse association relationship display opposite relationship directions, and the forward association relationship and the reverse association relationship can be switched between; Classifying and associating the acquired first data to obtain an association relationship between the first object, the second object, and the knowledge graph; In response to the knowledge graph association relationship selection instruction, construct a knowledge graph based on the first object, the second object, the knowledge graph association relationship, and a preset knowledge graph construction model; In response to a user search instruction, determining a display relationship between a first object and a second object based on the user's attribute information and behavior information, and pushing the knowledge graph association relationship between the first object and the second object on a visual interface; The classifying and associating the acquired first data to obtain the association relationship between the first object, the second object, and the knowledge graph includes: performing data processing on the acquired first data to obtain second data; Associating and binding the first object and the second object in the second data; Associating and binding the first object with the second object in the second data includes: Perform forward association binding on the first object and the second object. The first object is data A, and the second object is data B. After data A is stored in the database, the name and attribute relationship of data A are recorded. After data B is stored in the database, the record name and attribute information of data B are recorded. Forward association binding is to match the name of data A with the attributes of data B and other data. After a successful match, an association relationship is created and stored in the association relationship database. Perform a reverse association binding between the first object and the second object. Use each attribute of data A to match the name of data B and other data until a match is found. If a match is found, a relationship is created in the relationship database. The reverse association will associate the title of the associated data with the title of other data. The step of constructing a knowledge graph based on the first object, the second object, the knowledge graph association relationship, and a preset knowledge graph in response to the knowledge graph association relationship selection instruction includes: Matching the second data with the project field based on the title information and attribute information of the second data. The project field includes the network security risk assessment field and its sub-fields. Through aggregation processing, the relevant project fields will aggregate the relevant second data and bind the association relationship. Building a model based on the preset knowledge graph, and displaying the matched second data in association with the knowledge graph; The first data is classified and associated to obtain the association relationship between the first object, the second object and the knowledge graph, wherein the first data is obtained in a manual acquisition method and an automatic acquisition method; The knowledge graph is a 3D relationship graph or a plane relationship graph to display the relationship data information in the preset association relationship library, and the relationship data information includes the association data generated by the forward association and the association data generated by the reverse association.
2. A knowledge graph construction system for network security risk assessment, characterized by: The method for constructing a knowledge graph for network security risk assessment according to claim 1 comprises: A data acquisition module, configured to classify and associate the acquired first data to obtain an association relationship between the first object, the second object, and the knowledge graph; A knowledge graph construction module, configured to construct a knowledge graph based on the first object, the second object, the knowledge graph association relationship, and a preset knowledge graph construction model in response to a knowledge graph association relationship selection instruction; The retrieval module is used to respond to the user's retrieval instruction, determine the display relationship between the first object and the second object based on the user's attribute information and behavior information, and push the knowledge graph association relationship between the first object and the second object on the visualization interface.
3. A terminal device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor loads and executes the computer program, it adopts the method for constructing the knowledge graph for network security risk assessment described in claim 1.
4. A computer-readable storage medium having a computer program stored therein, characterized in that: When the computer program is loaded and executed by the processor, the method for constructing a knowledge graph for network security risk assessment described in claim 1 is adopted.
Citation Information
Patent Citations
An assessment method for calculating the information security risk of a network product
CN109948911A
Knowledge graph construction method and device, terminal and storage medium
CN110928984A