Output method and device, electronic equipment and storage medium
By analyzing network security databases and characteristic information, the network security situation level can be predicted, thus solving the problem of losses caused by network security incidents and achieving early prevention and loss reduction.
Patent Information
- Application Number
- CN202211656734.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-22
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2042-12-22
AI Technical Summary
In existing technologies, after a cybersecurity incident occurs, network data has been damaged, causing serious losses to the relevant personnel.
By analyzing the network security database within the target network, data on network security events whose probability values meet certain conditions are obtained, and combined with target characteristic information, the security status level of the target network is predicted.
Early detection of cybersecurity incidents allows for preventative measures and minimizes losses.
Smart Images

Figure CN116192450B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the network security technical field, and particularly relates to an output method and device, electronic equipment and storage medium. BACKGROUND
[0002] At present, the developed network technology brings convenience to people, but also brings some security risks to people. For example, network security events often occur, the network security events attack the network to damage network data, leak network data, etc., thereby causing different degrees of loss to relevant personnel.
[0003] In the prior art, when a network security event occurs in the network, an alarm is sent, thereby attracting the attention of relevant personnel, and the relevant personnel can further take measures to block the network security event.
[0004] It can be seen that in the prior art, when the network security event is detected, the network data has been damaged, thereby causing serious loss to the relevant personnel. SUMMARY
[0005] The embodiment of the present application provides an output method to solve the problem of serious loss of relevant personnel caused by network attacks of network security events in the prior art.
[0006] In order to solve the above technical problems, the embodiment of the present application is implemented as follows:
[0007] The embodiment of the present application provides an output method, which comprises:
[0008] According to the network security database in the network group of the target network, data of at least one type of target network security event in the network security database in the network group is obtained; wherein the occurrence probability value of the target network security event meets a target condition;
[0009] At least one target feature information of the target network is obtained; wherein the target feature information is used to evaluate the security posture of the target network;
[0010] According to the data of each type of network security event in the network security database in the network group, the data of the at least one type of target network security event, and the at least one target feature information of the target network, target information is output; wherein the target information is used to represent the predicted level of the security posture of the target network.
[0011] Optionally, the method according to the network security database in the network group of the target network, the data of at least one type of target network security event in the network security database in the network group comprises:
[0012] According to the network security database in the networking of the target network, at least one type of network security event in at least one target period is determined; wherein, in the target period, the occurrence probability value of the determined network security event is arranged in the first place;
[0013] Based on at least one target time information corresponding to the at least one type of network security event, the occurrence probability value of the at least one type of network security event is adjusted;
[0014] According to at least one target intention information corresponding to the at least one type of network security event, the occurrence probability value of the at least one type of network security event is adjusted;
[0015] The occurrence probability value of the at least one type of network security event is arranged in descending order;
[0016] The data of the network security event corresponding to the occurrence probability value arranged in the top N is obtained as the data of the target network security event, and N is a positive integer.
[0017] Optionally, the at least one target feature information of the target network comprises:
[0018] The first target feature information, the second target feature information and the third target feature information of the target network are obtained;
[0019] The first target feature information is used to indicate the vulnerability risk existing in the target network;
[0020] The second target feature information is used to indicate the attack risk existing in the target network;
[0021] The third target feature information is used to indicate the asset and work task risk existing in the target network.
[0022] Optionally, the target information is output according to the data of each type of network security event in the network security database in the networking, the data of the at least one type of target network security event, and the at least one target feature information of the target network, comprising:
[0023] According to the data of each type of network security event in the network security database in the networking, at least one weight value corresponding to the at least one target feature information is obtained; wherein, the weight value is used to indicate the total influence degree of the target feature information in the each type of network security event;
[0024] According to data of the at least one type of target network security event, at least one index corresponding to the at least one target feature information is acquired; wherein the index is used to represent a total influence degree of the target feature information in the at least one type of target network security event;
[0025] According to the at least one index and the at least one weight value corresponding thereto, the target information is outputted.
[0026] Embodiments of the present application further provide an output device, the device comprising:
[0027] A first acquisition module is configured to acquire data of at least one type of target network security event in a network security database in a target network according to the network security database in the target network; wherein an occurrence probability value of the target network security event satisfies a target condition;
[0028] A second acquisition module is configured to acquire at least one target feature information of the target network; wherein the target feature information is used to evaluate a security posture of the target network;
[0029] An output module is configured to output target information according to data of each type of network security event in the network security database in the target network, data of the at least one type of target network security event, and at least one target feature information of the target network; wherein the target information is used to represent a predicted level of the security posture of the target network.
[0030] Optionally, the first acquisition module comprises:
[0031] A determination unit is configured to determine at least one type of network security event in at least one target period according to a network security database in a target network; wherein in the target period, an occurrence probability value of the determined network security event is arranged in the first place;
[0032] A first adjustment unit is configured to adjust the occurrence probability value of the at least one type of network security event based on at least one target time information corresponding to the at least one type of network security event;
[0033] A second adjustment unit is configured to adjust the occurrence probability value of the at least one type of network security event according to at least one target intention information corresponding to the at least one type of network security event;
[0034] An arrangement unit is configured to arrange the occurrence probability value of the at least one type of network security event in descending order;
[0035] The first obtaining unit is configured to obtain data of network security events corresponding to the top N probability values, as the data of the target network security event, N being a positive integer.
[0036] Optionally, the second obtaining module comprises:
[0037] The second obtaining unit is configured to obtain the first target feature information, the second target feature information and the third target feature information of the target network.
[0038] The first target feature information is configured to represent a vulnerability risk existing in the target network.
[0039] The second target feature information is configured to represent an attack risk existing in the target network.
[0040] The third target feature information is configured to represent an asset and work task risk existing in the target network.
[0041] Optionally, the output module comprises:
[0042] The third obtaining unit is configured to obtain at least one weight value corresponding to the at least one target feature information according to data of various network security events in the network security database in the group network, the weight value being configured to represent a total influence degree of the target feature information in the various network security events.
[0043] The fourth obtaining unit is configured to obtain at least one index corresponding to the at least one target feature information according to data of the at least one type of target network security event, the index being configured to represent a total influence degree of the target feature information in the at least one type of target network security event.
[0044] The output unit is configured to output the target information according to the at least one index and the at least one weight value corresponding thereto.
[0045] The embodiment of the present application further provides an electronic device, which comprises a memory, a processor and a computer program stored in the memory and capable of running on the processor, and the computer program is executed by the processor to implement the output method as described above.
[0046] The embodiment of the present application further provides a readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the output method as described above.
[0047] Thus, in the embodiments of the present application, the networking-in-network security database of the target network is utilized to obtain data of at least one type of target network security event whose occurrence probability value meets a target condition based on the occurrence probability values of various types of network security events in the database, and further, in combination with the data in the networking-in-network security database and at least one target feature information in the target network for evaluating the security posture of the target network, target information is output, the target information being used to represent a predicted level of the security posture of the target network. It can be seen that, based on the embodiments of the present application, by analyzing the historical data of network security events and the data of the network itself, the level of the security posture of the target network can be predicted, so that relevant personnel can understand whether the security posture of the target network is stable based on the prediction result, so as to perceive the occurrence of network security events in advance, and then take corresponding measures in advance, so as to protect important network data, and then reduce the loss to the minimum, so as to avoid the generation of serious loss.
[0048] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the content of the specification can be implemented, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0050] Figure 1 Flowchart of the output method of the embodiments of the present application;
[0051] Figure 2 One of the explanatory diagrams of the output method of the embodiments of the present application;
[0052] Figure 3 The second of the explanatory diagrams of the output method of the embodiments of the present application;
[0053] Figure 4 Block diagram of the output device of the embodiments of the present application;
[0054] Figure 5 Block diagram of the electronic device of the embodiments of the present application. DETAILED DESCRIPTION
[0055] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described, obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative work are within the protection scope of the present application.
[0056] In the present application, an output method is provided for predicting the output of network security posture. In the present application, based on the major network security events found in the network, scientific theories, methods and experience are used to predict the development trend and harm situation, in the prediction process, the potential and possible attack path is analyzed, the influence of network vulnerability on the attack path is analyzed, the attack mode is analyzed, the confusion behavior and deception behavior of the attacker are analyzed. Based on this,
[0057] Referring to Figure 1 , a step flowchart of the output method of an embodiment of the present application is shown, the method is applied to an electronic device, as Figure 1 shown, the output method can include the following steps:
[0058] Step 110: According to the networking network security database of the target network, the data of at least one type of target network security event in the networking network security database is obtained; wherein the occurrence probability value of the target network security event meets the target condition.
[0059] In this step, the target network is the network whose security posture is to be predicted.
[0060] Optionally, the target network is an enterprise network.
[0061] In the networking network security database, a large number of network security event data has occurred, in this step, the networking network security database is used as historical reference data, through data analysis, at least one type of network security event that may occur is predicted, so that the predicted network security event is used as the target network security event.
[0062] Optionally, the target condition is that the occurrence probability value is greater than a certain threshold value; optionally, the target condition is that the larger value in the occurrence probability values of several network security events.
[0063] Step 120: Obtain at least one target feature information of the target network; wherein the target feature information is used to evaluate the security posture of the target network.
[0064] In this step, based on one dimension, a target feature information is determined according to the specific needs of the enterprise network.
[0065] The target feature information is used for evaluating the security posture of the target network, and is also referred to as an evaluation element.
[0066] Optionally, the target feature information has an impact on the occurrence probability of the network security event, and / or the target feature information has an impact on the damage degree of the network data under the attack of the network security event, so that the impact factors are considered, and the predicted security posture of the target network is more accurate.
[0067] It should be noted that the target feature information has an impact on the occurrence of the network security event, which is not limited to the target network security event, but also the non-target network security event.
[0068] Step 130: output target information according to the data of various network security events in the network security database in the networking, the data of at least one type of target network security event, and at least one target feature information of the target network; wherein the target information is used to represent the level of the predicted security posture of the target network.
[0069] Optionally, the target information is a number used to represent the level, the larger the number, the higher the level, and the more unstable the security posture of the target network, that is, the greater the possibility of future network security events; on the contrary, the smaller the number, the lower the level, and the more stable the security posture.
[0070] The application scenario is, for example, a number is output at a fixed time every day, and the number becomes larger and larger with the progress of time, such as 3, 4, and 5, so that relevant personnel can determine that the security posture of the target network is becoming more and more unstable based on the trend of the number, so that corresponding measures can be taken to stop loss in time.
[0071] In the above scenario, relevant personnel can determine the security posture of the target network based on the trend of the output target information without waiting for the number corresponding to the target information to be greater than a threshold value, and then taking measures to stop loss as soon as possible.
[0072] The application scenario is, for example, a number is output at a fixed time, the number is large, such as 7, and the distance to the threshold value 8 is close, so that relevant personnel can determine that the security posture of the target network is unstable based on the size of the number, so that corresponding measures can be taken to stop loss in time.
[0073] In the above scenario, relevant personnel can determine the security posture of the target network based on the size of the number of the output target information.
[0074] In more application scenarios, the application of the target information is not limited by the present application.
[0075] Thus, in the embodiments of the present application, by using the in-network security database of the target network, based on the occurrence probability values of various network security events in the database, data of at least one type of target network security event meeting a target condition is obtained, and further, in combination with the data in the in-network security database and at least one target feature information in the target network for evaluating the security posture of the target network, target information is output, and the target information is used to represent the level of the predicted security posture of the target network. It can be seen that, based on the embodiments of the present application, by analyzing the historical data of network security events and the data of the network itself, the level of the security posture of the target network can be predicted, so that relevant personnel can understand whether the security posture of the target network is stable based on the prediction result, so as to perceive the occurrence of network security events in advance, and then take corresponding measures in advance to protect important network data, thereby reducing the loss to the minimum, so as to avoid serious loss.
[0076] In the step flow of the output method of another embodiment of the present application, step 110 includes:
[0077] Sub-step A1: determining at least one type of network security event in at least one target period according to the in-network security database of the target network; wherein in the target period, the occurrence probability value of the determined network security event is arranged in the first place.
[0078] In this step, in combination with the Pareto method, a Pareto optimal solution set is obtained in the in-network security database, and the Pareto optimal solution set includes data of at least one type of network security event.
[0079] Optionally, in the Pareto optimal solution set, at least one occurrence probability value is sequentially sorted in descending order of occurrence probability value, and correspondingly, at least one type of network security event is correspondingly sorted.
[0080] Optionally, in the process of obtaining the Pareto optimal solution set, a target function f is used to map an n-dimensional decision space Ω to a k-dimensional target space. Generally, the target function needs to include all optimization objectives of the optimization problem, and the decision space needs to cover all of the variable space.
[0081] Wherein, the target function refers to: min f(x) = (f1(x), f2(x), …, fk(x)), x∈Ω. k (x)).
[0082] Further, in the Pareto dominance process, for two decision vectors x and y, if f(x) is not greater than f(y) on any objective and is less than f(y) on at least one objective, then x dominates y, or y is dominated by x, and is denoted as f(x)くf(y); if x and y exist a mutual domination relationship, then x and y can be compared; if f(x) and f(y) are equal on all objectives, then x and y are equivalent; if x and y are neither mutually dominated nor equivalent, then x and y cannot be compared.
[0083] The Pareto dominance defines the relationship between the objective functions obtained by two different decision vectors, so that the advantages and disadvantages between the two decision vectors can be conveniently compared. If x dominates y, it indicates that x is stronger than y in the evaluation of all objective functions; on the contrary, it indicates that y is stronger than x in the evaluation of all objective functions.
[0084] Therefore, if the decision vector x is not dominated by any vector in the decision space, then x is a Pareto optimal solution, and the set of all Pareto optimal solutions constitutes a Pareto optimal solution set, also known as a non-inferior solution set.
[0085] Correspondingly, x is a Pareto optimal solution, which means that x is a class of network security events with the maximum probability value in a target period. Based on this, at least one class of network security events can be obtained based on at least one target period.
[0086] It should be noted that if the two classes of network security events with the maximum probability value obtained in two target periods are the same class, they can be combined into one class of network security events; further, the larger probability value can be retained to avoid false prediction of the security situation.
[0087] Optionally, the target period is one day.
[0088] Sub-step A2: Adjusting the occurrence probability value of the at least one class of network security events based on the at least one target time information corresponding to the at least one class of network security events.
[0089] In this step, the occurrence probability value of the at least one class of network security events is adjusted by using a compound attack prediction method of CTPN (Colored Time Petri Net).
[0090] It should be noted that CTPN is a colored timed Petri net (Petri net is a mathematical representation of discrete parallel systems), which adds time logic to the traditional colored Petri net and introduces a time threshold into the transition firing sequence of CPTN. CTPN is composed of a nine-tuple, in the format of CTPN(∑, P, D, A, N, C, G, E, I), and the meanings of the parameters in the nine-tuple are as follows:
[0091] ∑ = {c i | i = 1, 2, …, Nc} is a color set, non-empty finite;
[0092] P = {p i | i = 1, 2, …, N p} is a state set, finite set;
[0093] D = {d i | i = 1, 2, …, N d} is a transition set, finite set;
[0094] A is a finite set, and P∩D = P∩A = D∩A;
[0095] N is a node function, and N: F→P×T∪T×P;
[0096] C is a color function, and C: F→∑;
[0097] Type(G() = Boolean) G is a guard function, and
[0098]
[0099] Type(E(a) = C(p(a)) Ms; where p is the a-linked place;
[0100] E is an arc function, and
[0101] I is an initialization function, and
[0102] D is fired only when the transition set D satisfies both the firing condition of the colored Petri net and the logical formula. The attack process of the composite attack prediction mode based on the CTPN is shown in Figure 2 .
[0103] When receiving the alarm information, it is identified and converted into the form of IntentAlert, and the transition intent corresponds to the logical relationship of the composite attack. When both the condition and the time requirement of the transition are satisfied, D is activated, and the alarm information belonging to the intent is saved in R(D). After D is activated, the arc place operation function is used to assign different types of properties corresponding to the IntentAlert in the place, and store the current state of the system. Different IntentAlerts in D also save the color corresponding property values in P of D.
[0104] The composite attack prediction mode of the CTPN adds the time threshold attribute to the traditional Petri network by improving the traditional Petri network, models the attack scene of the composite attack by the colored timed Petri network, establishes an attack scene graph, and associates the alarm information. The real-time detection of the composite attack behavior is realized, and a part of new attack scenes can be predicted according to the detection result. The mode can predict the composite attack situation as a good composite attack detection mode.
[0105] Correspondingly, the target time information is the time threshold in the foregoing content. It can be understood as a time peak value of the corresponding type of network security event in the historical event, for example, nine o'clock in the morning.
[0106] Therefore, based on this step, the occurrence probability value of the network security event in the Pareto optimal solution set is adjusted, so that the occurrence probability value is more accurate; further, based on the adjusted occurrence probability value, the at least one occurrence probability value is reordered, and the at least one type of network security event is reordered accordingly.
[0107] Based on this step, it is difficult to accurately predict the mutation peak value of the network security event data based on the traditional time sequence prediction mode, and it is also difficult to predict the important change identifier of the network situation. When the composite attack prediction mode of the CTPN is used to predict the non-stationary time sequence data, the data can be converted into a relatively stable time sequence data without losing the original information, so that the mutation peak value of the network security event data can be accurately predicted.
[0108] Substep A3: Adjusting the occurrence probability value of the at least one type of network security event according to the at least one target intention information corresponding to the at least one type of network security event.
[0109] Generally, in the complete composite attack process of a network security event, the motivation of each attack step is limited, but the way to achieve the attack intention is various. Attackers can have multiple ways to choose to achieve the same attack effect, and the attack methods between different stages can be arbitrarily combined. Because the attack intention is more easily summarized and easier to grasp than the attack behavior, it is more operational and reasonable to abstract the attack intention first and then judge the specific attack behavior of the specific attack intention.
[0110] Using a cybersecurity incident as an example, the attack process of a complex attack can be divided into multiple attack stages. Although the attack stages differ, the attack intent is the same. If the attack intent hidden within each attack stage is extracted, and the steps in each stage that achieve the same attack intent are taken as the set corresponding to the attack intent, then compared to the diverse attack behaviors, the number of attack intents is relatively small, and these attack intents do not change within a certain period of time. Therefore, this embodiment uses a small number of attack intents to represent the attack scenario.
[0111] It should be noted that attack intent refers to the purpose that an attacker intends to achieve by engaging in malicious behavior. A single-step attack refers to an attack A that cannot be directly achieved, but can be divided into several sub-attacks, each of which cannot be further decomposed and can uniquely correspond to attack A. See also... Figure 3 A composite attack refers to an attack where the attacker cannot directly perform the final operation on the final target T, but in order to achieve the goal, the attack can be divided into several steps (T1, T2, T3, T4, T5). Each step is called a single-step attack. Each single-step attack not only has its own local target, but also has a certain causal relationship with other single-step attacks, and together they achieve the final attack target T.
[0112] Correspondingly, the target intent information refers to the attack intent mentioned above. This can be understood as the attack intent during complex attack actions in corresponding types of cybersecurity incidents in historical events.
[0113] Based on the above, in this step, an intent-based composite attack prediction method is adopted to adjust the probability value of at least one type of network security incident.
[0114] It should be noted that the intent-based composite attack prediction method predicts attack behavior through a "graph" data structure. First, an attack logic graph is defined, where G is a six-tuple with the format G = {V(G), E(G), RR(G), W(G), H(G), L(G)}. The specific meaning of each parameter is as follows:
[0115] V(G) = {v1, v2, ... v} n} represents the set of vertices (vertices:attack type = 1:1);
[0116] E(G) = {e1, e2, ... e} n} is the set of directed edges (vertex pairs: directed edges = 1:1);
[0117] R(G)={R(v1), R(v2),…R(v n The ratio of elements in R(G) to elements in V(G) is 1:1.
[0118] w(G) = {w1, w2,... w n}, which is a vertex weight value (an element in W(G): an element in V(G) = 1:1) ;
[0119] H(G) = {h1, h2,... h n}, which is a relationship between vertices (an element in H(G): an element in E(G) = 1:1) ;
[0120] L(G) = {l1, l2,... l n}, which is a set of truth value expressions, representing the relationship of edges pointing to the same vertex (an element in L(G): an element in V(G) = 1:1).
[0121] The intention-based composite attack prediction mode extends the original directed graph with attributes, describes the logical relationship between different attack types, and predicts the next step of the attack event according to the logical relationship. The limitation of this mode is that the parameter setting of attack effectiveness lacks standardization, and it is difficult to determine the matching degree of the composite attack.
[0122] Therefore, the intention-based composite attack prediction mode, combined with the composite attack prediction mode of CTPN, can improve the accuracy of composite attack prediction, and make up for the above-mentioned shortcomings of the intention-based composite attack prediction mode.
[0123] Therefore, based on this step, the occurrence probability values of the network security events in the Pareto optimal solution set are adjusted again, so that the occurrence probability values are more accurate; further, based on the adjusted occurrence probability values, at least one occurrence probability value is reordered, and correspondingly, at least one type of network security event is reordered.
[0124] Sub-step A4: obtaining the data of the network security events corresponding to the occurrence probability values arranged in the first N, as the data of the target network security event, N being a positive integer.
[0125] In this step, based on the ordering of each type of network security event in the Pareto optimal solution set, the first N types of network security events are obtained as the target network security events, so as to obtain the data of the target network security events.
[0126] In this embodiment, the network security database data in the access group is accessed, and the Pareto optimal solution set is obtained by combining the Pareto method; the composite attack prediction mode of CTPN is combined with the intention-based composite attack prediction mode to adjust the accuracy of the Pareto optimal solution set, so that the accuracy of the predicted possible target network security events is higher.
[0127] In the step flow of the output method of another embodiment of the present application, step 120 comprises:
[0128] Sub-step B1: obtaining first target feature information, second target feature information and third target feature information of the target network.
[0129] The first target feature information is used to represent a vulnerability risk existing in the target network.
[0130] Correspondingly, the first target feature information is a vulnerability evaluation element.
[0131] The vulnerability evaluation element in the enterprise network mainly considers the vulnerability situation of the asset, i.e., the vulnerability situation of the network itself in the absence of attacks, including how much attack the network itself can withstand, how many attacks and how much damage and loss the attacks will bring to the network, etc.
[0132] The second target feature information is used to represent an attack risk existing in the target network.
[0133] Correspondingly, the second target feature information is an attack risk evaluation element.
[0134] The attack risk evaluation element in the enterprise network mainly considers the influence of network attacks on the network. Network attacks exist in the form of network alarms and are generated by correlation analysis of events collected by multiple security devices, and can include a hierarchical structure of attack risk evaluation elements corresponding to various network attacks.
[0135] The third target feature information is used to represent an asset and work task risk existing in the target network.
[0136] Correspondingly, the third target feature information is an asset and work task evaluation element.
[0137] The asset and work task evaluation element in the enterprise network is mainly selected from the perspectives of hardware capability, security protection capability and actual load, and needs to consider whether the services carried by the network can run healthily, and whether the various node devices constituting the network can work normally and provide services to users in time. In order to simplify the evaluation process, the enterprise network does not describe the work task in detail, and the asset and work task evaluation element is mainly divided into two aspects of disaster tolerance and smoothness, and can include a hierarchical structure of asset and work task evaluation elements.
[0138] In this embodiment, the influence degree of the target network itself on the occurrence of network security events is analyzed from three dimensions of the vulnerability evaluation element, the attack risk evaluation element and the asset and work task evaluation element, so that the predicted security posture of the target network is combined with the actual situation, and the prediction result is more accurate.
[0139] In the step flow of the output method of another embodiment of the present application, step 130 comprises:
[0140] Sub-step C1: obtaining at least one weight value corresponding to at least one target feature information according to the data of various network security events in the network security database in the network group; wherein the weight value is used to represent the total influence degree of the target feature information in various network security events.
[0141] In this step, after determining the network security situation assessment elements, each assessment element needs to be quantified to obtain the weight value through quantification.
[0142] Among them, there are many quantification algorithms, and in the selection of specific quantification algorithms, the needs of relevant personnel and the characteristics of the target network can be selected. The following will illustrate the quantification algorithm in the situation assessment through an example.
[0143] Taking network deception type network security events as an example, network deception type network security events have four indicators: target assets, harmfulness, event number, and clearability. Assuming that in the unit assessment period set by the relevant personnel, the original value vectors of the target assets, harmfulness, and clearability of the three indicators are respectively:
[0144] A(t)={A1,A2,…,A n};
[0145] B(t)={B1,B2,…,B n};
[0146] C(t)={C1,C2,…,C n};
[0147] n represents the event number.
[0148] Among them, the target assets, harmfulness, event number, and clearability can be obtained through the event data of this type of network security event in the network security database in the network group, and the target assets, harmfulness, and clearability are related to the specific content in the assessment elements.
[0149] First, calculate the four attribute values of the network deception type network security events in this time period.
[0150] Event number: n;
[0151] Target assets:
[0152] Harmfulness:
[0153] Clearability:
[0154] Secondly, the attribute values are quantified. For the number of events, the threshold method can be used, and for other attributes, the maximum value method or the minimum value method can be used.
[0155] Furthermore, the aforementioned quantization algorithm can be applied to any type of cybersecurity incident.
[0156] Furthermore, after quantifying each assessment element based on various cybersecurity incidents, the Analytic Hierarchy Process (AHP) is used to determine the weight value corresponding to each assessment element.
[0157] The overall network security is the result of the combined effect of various security indicators, and the weight of each indicator and its sub-indicators on system security varies. Based on the principle of the Analytic Hierarchy Process (AHP), the network security indicator system includes a total network security index, network security indices for each dimension (such as vulnerability index, attack risk index, asset and task index), and influencing factors for each dimension (secondary indicators, tertiary indicators, etc.). The secondary and tertiary indicators include the target assets and risk indicators mentioned in the previous example. The influence weight of each target element at each level relative to a certain element at the previous level is obtained by expert evaluation. Then, a weighted sum method is used to merge the final weights of each sub-target on the overall target.
[0158] Therefore, the weight values corresponding to each evaluation element can be obtained. For example, the weight values of vulnerability evaluation elements, attack risk evaluation elements, and asset and task evaluation elements.
[0159] The weight values of vulnerability assessment elements are used to represent the overall weight of the impact of vulnerability assessment elements in various cybersecurity incidents.
[0160] The weight values of attack risk assessment elements are used to represent the overall weight of the impact of attack risk assessment elements in various types of cybersecurity incidents.
[0161] The weight values of the asset and task assessment elements are used to represent the overall weight of the asset and task assessment elements in various cybersecurity incidents.
[0162] Sub-step C2: Based on data from at least one type of target cybersecurity incidents, obtain at least one index corresponding to at least one target feature information; wherein the index is used to represent the total influence of the target feature information in at least one type of target cybersecurity incidents.
[0163] In this step, the index corresponding to each evaluation element is obtained. Unlike the weight value, the index is determined based on the comprehensive situation of various target cybersecurity incidents, that is, based on possible cybersecurity incidents.
[0164] Optionally, the quantification algorithm of the previous step is used to obtain the index corresponding to each evaluation element.
[0165] Sub-step C3: outputting the target information according to the at least one index and the one-to-one corresponding at least one weight value.
[0166] Optionally, the selected evaluation elements include three, see the formula:
[0167] IC=W F *IF+W V *IV+W R *IR
[0168] Wherein, IC is used to represent the network security total index, i.e. the target information, W F , W V , W R respectively used to represent the weight value corresponding to the three evaluation elements, satisfying ∑W=1; IF, IV, IR respectively used to represent the index corresponding to the three evaluation elements.
[0169] In this embodiment, first, the network security situation evaluation elements are quantified to obtain the quantified network security situation, thereby completing the quantitative evaluation of the network security situation.
[0170] In summary, the present application aims at the phenomenon that the composite attack behavior has become the mainstream of current attacks, and will continue to expand in the future for a long period of time, and predicts the composite attack behavior to realize the prediction of the network situation, thereby avoiding more serious losses caused by the composite attack behavior.
[0171] Referring to Figure 4 , a block diagram of an output device of an embodiment of the present application is shown, as Figure 4 shown, the output device can include:
[0172] The first acquisition module 10 is configured to acquire data of at least one type of target network security event in the in-network network security database according to the in-network network security database of the target network; wherein the occurrence probability value of the target network security event satisfies a target condition;
[0173] The second acquisition module 20 is configured to acquire at least one target feature information of the target network; wherein the target feature information is used to evaluate the security situation of the target network;
[0174] The output module 30 is configured to output target information according to the data of each type of network security event in the in-network network security database, the data of at least one type of target network security event, and the at least one target feature information of the target network; wherein the target information is used to represent the level of the predicted security situation of the target network.
[0175] Thus, in the embodiments of the present application, by using the in-network security database of the target network, based on the occurrence probability values of various network security events in the database, data of at least one type of target network security event meeting a target condition is obtained, further, in combination with the data in the in-network security database and at least one target feature information in the target network for evaluating the security posture of the target network, target information is output, and the target information is used to represent the level of the predicted security posture of the target network. It can be seen that, based on the embodiments of the present application, by analyzing the historical data of network security events and the data of the network itself, the level of the security posture of the target network can be predicted, so that relevant personnel can understand whether the security posture of the target network is stable based on the prediction result, so as to perceive the occurrence of network security events in advance, and then take corresponding measures in advance to protect important network data, thereby reducing the loss to the minimum, so as to avoid serious loss.
[0176] Optionally, the first obtaining module 10 comprises:
[0177] The determining unit is configured to determine at least one type of network security event in at least one target period according to the in-network security database of the target network; wherein, in the target period, the occurrence probability value of the determined network security event is arranged in the first place;
[0178] The first adjusting unit is configured to adjust the occurrence probability value of the at least one type of network security event based on at least one target time information corresponding to the at least one type of network security event;
[0179] The second adjusting unit is configured to adjust the occurrence probability value of the at least one type of network security event according to at least one target intention information corresponding to the at least one type of network security event;
[0180] The arranging unit is configured to arrange the occurrence probability values of the at least one type of network security event in descending order;
[0181] The first obtaining unit is configured to obtain data of network security events corresponding to the occurrence probability values arranged in the first N places as data of target network security events, N being a positive integer.
[0182] Optionally, the second obtaining module 20 comprises:
[0183] The second obtaining unit is configured to obtain the first target feature information, the second target feature information and the third target feature information of the target network;
[0184] The first target feature information is used to represent the vulnerability risk existing in the target network;
[0185] The second target feature information is used for indicating an attack risk of the target network;
[0186] The third target feature information is used for indicating an asset and work task risk of the target network.
[0187] Optionally, the output module 30 comprises:
[0188] The third obtaining unit is configured to obtain at least one weight value corresponding to at least one target feature information according to data of various network security events in the network security database in the networking; wherein the weight value is used for indicating a total influence degree of the target feature information in the various network security events.
[0189] The fourth obtaining unit is configured to obtain at least one index corresponding to at least one target feature information according to data of at least one type of target network security event; wherein the index is used for indicating a total influence degree of the target feature information in the at least one type of target network security event.
[0190] The output unit is configured to output the target information according to the at least one index and the at least one weight value corresponding thereto.
[0191] In addition, referring to Figure 5 , a block diagram of an electronic device according to an embodiment of the present application is shown, as shown in Figure 5 The electronic device 100 comprises a memory 102, a processor 101 and a computer program stored in the memory 102 and executable on the processor 101, and the computer program is executed by the processor to implement the output method described above.
[0192] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement various processes of the output method embodiment described above and achieve the same technical effects. To avoid repetition, details are not described herein. The computer readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0193] It should be noted that, in the present document, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element preceded by "comprises... a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0194] Those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) execute the methods described in various embodiments of the present application.
[0195] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above-mentioned specific embodiments, and the above-mentioned specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms under the inspiration of the present application without departing from the scope of the present application and the scope protected by the claims.
[0196] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solutions. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0197] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0198] In the embodiments of the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the described embodiments of the apparatus are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0199] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0200] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can be a physically independent unit, or two or more units can be integrated into a unit.
[0201] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc.
[0202] The above description is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An output method, characterized in that, The method includes: Based on the network security database within the target network, data on at least one type of target network security event is obtained from the network security database within the target network; wherein the probability value of the occurrence of the target network security event satisfies the target condition; Obtain at least one target feature information of the target network; wherein the target feature information is used to assess the security posture of the target network; Based on data from various network security events in the network security database, data from at least one type of target network security event, and at least one target feature information of the target network, target information is output; wherein, the target information is used to represent the predicted security status level of the target network.
2. The method according to claim 1, characterized in that, The step of obtaining data on at least one type of target network security event from the network-wide network security database of the target network includes: Based on the network security database within the target network, at least one type of network security event is determined within at least one target period; wherein, within the target period, the probability value of the determined network security event is ranked first. Based on at least one target time information corresponding to the at least one type of network security incident, the occurrence probability value of the at least one type of network security incident is adjusted; The probability value of the occurrence of the at least one type of network security incident is adjusted based on at least one target intent information corresponding to the at least one type of network security incident. The probability values of the occurrence of the at least one type of network security incident are arranged in descending order; Obtain the data of the network security events corresponding to the top N probability values of occurrence, and use them as the data of the target network security event, where N is a positive integer.
3. The method according to claim 1, characterized in that, The step of obtaining at least one target feature information of the target network includes: Obtain the first target feature information, the second target feature information, and the third target feature information of the target network; The first target feature information is used to indicate the vulnerability risks existing in the target network; The second target feature information is used to indicate the attack risk present in the target network; The third target feature information is used to indicate that the target network has asset and task risks.
4. The method according to claim 1, characterized in that, The step of outputting target information based on data of various network security events in the network security database, data of at least one type of target network security event, and at least one target feature information of the target network includes: Based on the data of various network security events in the network security database, at least one weight value corresponding to the at least one target feature information is obtained; wherein, the weight value is used to represent the total degree of influence of the target feature information in the various network security events; Based on the data of the at least one type of target cybersecurity incidents, at least one index corresponding to the at least one target feature information is obtained; wherein, the index is used to represent the total degree of influence achieved by the target feature information in the at least one type of target cybersecurity incidents; The target information is output based on the at least one index and the corresponding at least one weight value.
5. An output device, characterized in that, The device includes: The first acquisition module is used to acquire data on at least one type of target network security event from the network security database within the target network; wherein the probability value of the occurrence of the target network security event satisfies the target condition. The second acquisition module is used to acquire at least one target feature information of the target network; wherein the target feature information is used to assess the security posture of the target network; The output module is used to output target information based on data of various network security events in the network security database within the network, data of at least one type of target network security event, and at least one target feature information of the target network; wherein the target information is used to represent the predicted security status level of the target network.
6. The apparatus according to claim 5, characterized in that, The first acquisition module includes: The determining unit is configured to determine at least one type of network security event within at least one target period based on the network security database within the target network; wherein, within the target period, the occurrence probability value of the determined network security event is ranked first. The first adjustment unit is used to adjust the occurrence probability value of the at least one type of network security event based on at least one target time information corresponding to the at least one type of network security event. The second adjustment unit is used to adjust the occurrence probability value of the at least one type of network security event based on at least one target intent information corresponding to the at least one type of network security event. The sorting unit is used to sort the occurrence probability values of the at least one type of network security incident in descending order; The first acquisition unit is used to acquire data of network security events corresponding to the occurrence probability values of the top N events, as the data of the target network security event, where N is a positive integer.
7. The apparatus according to claim 5, characterized in that, The second acquisition module includes: The second acquisition unit is used to acquire the first target feature information, the second target feature information, and the third target feature information of the target network. The first target feature information is used to indicate the vulnerability risks existing in the target network; The second target feature information is used to indicate the attack risk present in the target network; The third target feature information is used to indicate that the target network has asset and task risks.
8. The apparatus according to claim 5, characterized in that, The output module includes: The third acquisition unit is used to acquire at least one weight value corresponding to the at least one target feature information based on the data of various network security events in the network security database within the network; wherein, the weight value is used to represent the total degree of influence achieved by the target feature information in the various network security events; The fourth acquisition unit is used to acquire at least one index corresponding to the at least one type of target network security event based on the data of the at least one type of target network security event; wherein the index is used to represent the total degree of influence achieved by the target feature information in the at least one type of target network security event; An output unit is configured to output the target information based on the at least one index and the at least one corresponding weight value.
9. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the output method as described in any one of claims 1 to 4.
10. A readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the output method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Security event early warning method for multi-dimensional stereoscopic network
CN112039862A
Real-time dynamic early warning system and method based on network security situation awareness system
CN115150195A