A method, device and application product for evaluating network security health

By acquiring and analyzing vulnerability log data from network systems and using an assessment model to calculate a network security health index, the problem of inaccurate assessment of non-compliance risks in existing technologies has been solved. This has enabled more accurate risk assessment and timely remediation recommendations, thereby improving network security assessment and response capabilities.

CN116471086BActive Publication Date: 2026-03-24BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-19
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies cannot accurately identify non-compliance risks, do not consider other interfering factors affecting cybersecurity, and lack remediation suggestions and methods for risk events.

Method used

By acquiring vulnerability log data from application systems and operating systems, and using an assessment model to calculate a cybersecurity health index, the system provides risk values ​​and remediation recommendations, taking into account factors such as asset value and threat frequency.

Benefits of technology

It improves the accuracy of cybersecurity health index calculation, provides targeted risk remediation suggestions, and enhances the objectivity and response efficiency of cybersecurity assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116471086B_ABST
    Figure CN116471086B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method, device and application product for evaluating network security health condition, the method comprising: obtaining to-be-evaluated data, wherein the to-be-evaluated data is obtained based on target log data, and the target log data at least includes application system WEB vulnerability log information and operating system vulnerability log information; obtaining a network security health index value according to an evaluation model and the to-be-evaluated data; and providing alarm information if the network security health index value is located in an alarm range. Embodiments of the present application aim to solve the following technical problems: solving the determination of non-compliance risks, proposing that the calculation of health index by interference factors participating in the calculation of health index is more accurate, and providing repair suggestions and methods based on health index to risks affecting the change of health index.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity, and specifically, embodiments of this application relate to a method, apparatus, and application product for assessing cybersecurity health status. Background Technology

[0002] In recent years, with the deepening integration of digitalization, networking, and various industries, and the continuous development of network technology, cybersecurity issues have become increasingly complex. Cybersecurity experts are attempting to employ a range of technologies to protect networks from attacks, but these technologies are insufficient to safeguard against the diverse threats facing networks. Therefore, cybersecurity health index assessment has become an important indicator for identifying the degree of threat a network faces.

[0003] While related technologies offer some methods for determining the health status of cybersecurity, these solutions suffer from the following technical problems: the calculation methods tend to be based on compliance judgments, failing to assess non-compliance risks; they do not consider other interfering factors affecting cybersecurity, resulting in inaccurate results; and they do not provide remediation suggestions and methods for risk events that impact the index. Summary of the Invention

[0004] The purpose of this application is to provide a method, apparatus, and application product for assessing the health status of network security. The embodiments of this application aim to solve the following technical problems: solving the determination of non-compliance risks, proposing interference factors involved in the calculation of the health index to make the calculation of the health index more accurate, and providing remediation suggestions and methods for risks affecting changes in the health index based on the health index prompts.

[0005] In a first aspect, embodiments of this application provide a method for assessing network security health status. The method includes: acquiring data to be assessed, wherein the data to be assessed is obtained based on target log data, and the target log data includes at least application system WEB vulnerability log information and operating system vulnerability log information; acquiring a network security health index value according to an assessment model and the data to be assessed; and providing alarm information if the network security health index value is within the alarm range.

[0006] Some embodiments of this application resolve the determination of non-compliance risks by collecting vulnerability data corresponding to non-compliance risks.

[0007] In some embodiments, obtaining the data to be evaluated includes: accessing network traffic of the managed network, collecting network traffic data of multiple protocols, application system WEB vulnerability data, and operating system vulnerability data to obtain initial log data; and formatting the initial log data to obtain the data to be evaluated.

[0008] Some embodiments of this application also require formatting of the collected data to facilitate data processing.

[0009] In some embodiments, obtaining the cybersecurity health index value based on the assessment model and the data to be assessed includes: performing quantitative analysis on the target elements that affect the quantitative analysis based on the data to be assessed and the user's own asset data to obtain the probability value of risk occurrence and the impact value of risk occurrence.

[0010] Some embodiments of this application determine the risk value of various assets based on the probability of risk occurrence and the impact value of risk occurrence, thereby improving the accuracy of security assessment of various assets.

[0011] In some embodiments, the target elements include: the cost of the protective measures, asset value, business impact, threat frequency, effectiveness of the protective measures, or vulnerability exploitation potential.

[0012] Some embodiments of this application use multiple elements to determine the risk value of each asset, thereby improving the accuracy of risk value assessment.

[0013] In some embodiments, obtaining the cybersecurity health index value based on the assessment model and the data to be assessed includes: obtaining the risk value of each asset; obtaining the total risk value based on the risk value of each asset and the weight value of each asset; and using the total risk value as the cybersecurity health index value.

[0014] Some embodiments of this application can determine the overall security of assets in a network system by determining the risk values ​​of all assets and then weighting and summing them.

[0015] In some embodiments, obtaining the risk value of each asset includes: obtaining the impact of a security threat to the first asset on the business; obtaining the probability of a security incident occurring by exploiting the vulnerability of the first asset, and obtaining the true probability value of the incident; and obtaining the risk value of the first asset based on the impact and the true probability value.

[0016] Some embodiments of this application require determining the impact of security threats on business operations and the probability of such events when determining the risk value of each asset, thereby improving the accuracy and objectivity of risk value acquisition.

[0017] In some embodiments, obtaining the impact of a security threat to the first asset on the business includes: obtaining the loss value after the corresponding event occurs based on the asset value and vulnerability level of the first asset; and calculating a total loss value based on the loss value, wherein the total loss value is used to characterize the impact on the business.

[0018] Some embodiments of this application provide a way to quantify the impact of a security threat on a business, improving the accuracy and objectivity of the calculation of this value.

[0019] In some embodiments, obtaining the probability of a security incident occurring due to the vulnerability of the first asset, and obtaining the true probability value of the incident, includes: obtaining the true probability value of the incident through a first function, wherein the first function further includes a base value and a correction function value, the correction function value is related to the risk source, and the base value is determined by the frequency and vulnerability of the corresponding incident.

[0020] Some embodiments of this application improve the accuracy of calculating the true probability value of an event by using correction values.

[0021] In some embodiments, the method further includes: associating target events affecting the health index with the system's own security knowledge base through keywords, associating experts who are good at handling the target events through the knowledge base, and assigning association tags; when the administrator receives the alarm information, obtaining the association tags, and providing relevant information based on the association tags.

[0022] Some embodiments of this application provide relevant handling measures and personnel information based on associated tags, thereby increasing the probability of responding to alarm events.

[0023] Secondly, some embodiments of this application provide an apparatus for assessing network security health status. The apparatus includes: a data acquisition module configured to acquire data to be assessed, wherein the data to be assessed is obtained based on target log data, and the target log data includes at least application system web vulnerability log information and operating system vulnerability log information; a network security health index value acquisition module configured to acquire a network security health index value according to an assessment model and the data to be assessed; and a notification module configured to provide alarm information if the network security health index value is within an alarm range.

[0024] Thirdly, some embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.

[0025] Fourthly, some embodiments of this application provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method as described in any embodiment of the first aspect. Attached Figure Description

[0026] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0027] Figure 1 This is one of the system architecture diagrams provided in the embodiments of this application for assessing network security health status;

[0028] Figure 2 A flowchart illustrating a method for assessing network security health status provided in this application embodiment;

[0029] Figure 3 This is the second system architecture diagram for assessing network security health status provided in the embodiments of this application;

[0030] Figure 4 A block diagram of the apparatus for assessing network security health provided in the embodiments of this application;

[0031] Figure 5 This is a schematic diagram of the electronic device provided in the embodiments of this application. Detailed Implementation

[0032] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0033] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0034] Some embodiments of this application relate to a method for calculating a network security health index, used to index and quantify the degree of threat to network assets. The method is characterized by using deep learning technology to extract features from a large amount of network security threat data, analyzing the data that impacts the network, and then constructing an analysis model based on these features to preliminarily determine the degree of threat to the network based on factors such as attack and weight.

[0035] Please refer to Figure 1 , Figure 1 A system for assessing network security health status is provided in some embodiments of this application. The system includes: multiple terminals (e.g., Figure 1The first terminal device 101 and the second terminal device 102), the first server 103 that provides services, and the assessment server 200 that assesses the network security monitoring status.

[0036] Multiple terminals connect to the first server 103 via network 100 and obtain relevant services provided by the first server 103 through the connection.

[0037] Some embodiments of this application complete the security assessment of various assets (e.g., terminal devices or servers) in the network 100 by acquiring various network data generated in the network 100 through the assessment server 200.

[0038] It should be noted that, Figure 1 This is merely an example to illustrate a system architecture; those skilled in the art can design different architectures according to actual needs. Figure 1 The system architecture.

[0039] The following is combined Figure 2 and Figure 3 This application provides exemplary methods for assessing cybersecurity health status, including some embodiments thereof.

[0040] like Figure 2 As shown in the embodiment of this application, a method for assessing network security health status is provided. The method includes: S101, obtaining data to be assessed, wherein the data to be assessed is obtained based on target log data, and the target log data includes at least application system WEB vulnerability log information and operating system vulnerability log information; S102, obtaining a network security health index value according to an assessment model and the data to be assessed; S103, if the network security health index value is within the alarm range, providing alarm information.

[0041] In other words, some embodiments of this application resolve the determination of non-compliance risks by collecting vulnerability data corresponding to non-compliance risks.

[0042] The implementation process of the above steps is illustrated below.

[0043] In some embodiments of this application, S101 includes, for example,: accessing the network traffic of the managed network, collecting network traffic data of multiple protocols, application system WEB vulnerability data, and operating system vulnerability data to obtain initial log data; and formatting the initial log data to obtain the data to be evaluated.

[0044] For example, such as Figure 3As shown, in some embodiments of this application, a data collector accesses the network traffic of the managed business network to obtain non-compliant log data such as network traffic data of various protocols, application system web vulnerabilities, and operating system vulnerabilities; data specification standards are defined for different types of data, through... Figure 3 The data standardization engine standardizes the collected data to facilitate subsequent assessments of the business system's security and health index. The standardized data is then categorized and stored... Figure 3 The data storage is used for index evaluation. Some embodiments of this application include an index evaluation engine comprising: event self-hazard assessment, associated threat information assessment, and target impact weight assessment. For example, in some embodiments of this application, these three aspects are all important factors affecting the final risk assessment result, mainly: the threat of the event itself, its association with other confirmed threats leading to its potential threat, and the weight of the risk's impact on the target (asset) (importance, confidentiality, integrity, availability, etc.). All three aspects of threat assessment will affect the final index evaluation.

[0045] Some embodiments of this application also require formatting of the collected data to facilitate data processing.

[0046] In some embodiments of this application, the step S102, which involves obtaining a cybersecurity health index value based on an evaluation model and the data to be evaluated, includes: performing quantitative analysis on target elements that influence the quantitative analysis based on the data to be evaluated and the user's own asset data, to obtain the probability value of risk occurrence and the impact value of risk occurrence. For example, the target elements include: the cost of protective measures, asset value, business impact, threat frequency, effectiveness of protective measures, or vulnerability exploitation probability.

[0047] Some embodiments of this application determine the risk value of various assets based on the probability of risk occurrence and the impact of risk occurrence, thereby improving the accuracy of security assessments for various assets. Some embodiments of this application determine the risk value of each asset using multiple elements, further improving the accuracy of risk value assessment.

[0048] The following example illustrates a method for calculating risk values.

[0049] The first step involves using some embodiments of this application. Figure 3 The evaluation model established by the index evaluation engine evaluates the collected and standardized data to derive the cybersecurity health index. The specific evaluation method is as follows:

[0050] a) Use quantitative analysis methods to describe the true probability of risk occurrence and its impact using numerical values. Utilizing collected data and internal asset data, analyze the elements influencing quantification, including the cost of protective measures, asset value, business impact, threat frequency, effectiveness of protective measures, and vulnerability exploitation potential. This includes the following steps:

[0051] 1) Based on the risk calculation paradigm: Risk value = (a, T, V) = (L(T, V), F(, Va)) is calculated, where R represents the security risk calculation function, a represents the asset, T represents the threat, V represents the vulnerability, Ia represents the asset value affected by the security incident, Va represents the severity of the vulnerability, L represents the probability that the threat will exploit the vulnerability of the asset to cause a security incident, and F represents the loss caused after the security incident occurs.

[0052] 2) The true probability of an event is calculated as follows: True probability of event = (Event frequency, Vulnerability) = L(T,V)

[0053] 3) The loss after the event is: Loss after the event = (Asset value, Vulnerability level) = (Ia, Va)

[0054] 4) Calculate the risk value: Risk value = (True probability of the event, Loss after the event occurs) = R(L(T,V),F(,Va))

[0055] 5) Risk is calculated using matrix and multiplication methods, and is measured by factors such as assets, events, and vulnerabilities that affect risk factors.

[0056] 6) The matrix method is mainly applicable to situations where two element values ​​determine one element value. First, a two-dimensional calculation matrix needs to be determined. The element values ​​within the matrix are determined mathematically based on the specific circumstances and the increasing nature of the function. Then, the values ​​of the two elements are compared within the matrix; the intersection of the rows and columns represents the determined calculation result. See Table 1 below for details:

[0057] Table 1

[0058]

[0059] The risk index calculation example is shown in Table 2 below:

[0060] Table 2

[0061]

[0062]

[0063] The risk levels are divided into 5 levels, as shown in Table 3 below:

[0064] Table 3 Risk Registration Reference Table

[0065] Risk Value 1~70 70~80 80~90 90~100 100~125 Risk level 1 2 3 4 5

[0066] The multiplication method is applicable when two or more feature values ​​determine one feature value. That is, z = f(x,y), and the function f can be determined using the multiplication method.

[0067] When F is an increment function This can be done by direct multiplication, or by multiplying and then taking the modulus, etc., such as:

[0068] or

[0069] or

[0070] or

[0071]

[0072] z = f(x, y) = xy

[0073] b) Link events affecting the health index with the system's own security knowledge base using keywords. Also, link experts skilled in handling such security incidents through the knowledge base and add associated tags.

[0074] The second step is to monitor the assessed cybersecurity health index and issue a warning if the index exceeds a certain range. The specific warning logic is as follows:

[0075] a) Using a health status score of 125 as the base, set thresholds. A health index range of ≥101 and ≤125 indicates an "Excellent" health status. A health index range of ≥90 and ≤100 indicates a "Good" health status. A health index range of ≥80 and <90 indicates a "Average" health status. A health index range of ≥70 and <80 indicates a "Poor" health status. A health index <70 indicates a "Dangerous" health status.

[0076] (b) When the health index is indicated as "Fair," a text message reminder will be sent daily. When the health index is indicated as "Poor," a text message reminder will be sent every 12 hours. When the health index is indicated as "Dangerous," a text message reminder will be sent every 3 hours.

[0077] Thirdly, when administrators receive health index alerts, they can view detailed information about risk events affecting the health index through the system. The system needs to display remediation suggestions, methods, and emergency response expert information linked by the correlation analysis engine to promptly eliminate dangers and maintain network health and security. 。

[0078] In some embodiments of this application, S102 includes, for example,: obtaining the risk value of each asset; obtaining a total risk value based on the risk value of each asset and the weight value of each asset; and using the total risk value as the cybersecurity health index value.

[0079] Some embodiments of this application can determine the overall security of assets in a network system by determining the risk values ​​of all assets and then weighting and summing them.

[0080] For example, in some embodiments of this application, obtaining the risk value of each asset includes: obtaining the impact of a security threat to the first asset on the business; obtaining the probability of a security incident occurring by exploiting the vulnerability of the first asset, and obtaining the true probability value of the incident; and obtaining the risk value of the first asset based on the impact and the true probability value.

[0081] Some embodiments of this application require determining the impact of security threats on business operations and the probability of such events when determining the risk value of each asset, thereby improving the accuracy and objectivity of risk value acquisition.

[0082] For example, in some embodiments of this application, obtaining the impact of a security threat on the business after the first asset is threatened includes: obtaining the loss value after the corresponding event occurs based on the asset value and vulnerability level of the first asset; calculating the total loss value based on the loss value, wherein the total loss value is used to characterize the impact on the business.

[0083] Some embodiments of this application provide a way to quantify the impact of a security threat on a business, improving the accuracy and objectivity of the calculation of this value.

[0084] For example, in some embodiments of this application, obtaining the probability of a security incident occurring due to the vulnerability of the first asset and obtaining the true probability value of the incident includes: obtaining the true probability value of the incident through a first function, wherein the first function further includes a base value and a correction function value, the correction function value is related to the risk source, and the base value is determined by the frequency of occurrence and vulnerability of the corresponding incident.

[0085] Some embodiments of this application improve the accuracy of calculating the true probability value of an event by using correction values.

[0086] To facilitate timely processing of alarm information, in some embodiments of this application, the method further includes: associating target events affecting the health index with the system's own security knowledge base using keywords, and associating experts skilled in handling the target events with the knowledge base and assigning association tags; when the administrator receives the alarm information, they obtain the association tags and provide relevant information based on the association tags. Some embodiments of this application provide relevant handling measures and personnel information based on the association tags, thereby improving the probability of responding to alarm events.

[0087] The following example illustrates some embodiments of the methods for assessing network security health in this application.

[0088] Based on network security situation awareness products, this paper describes the application of a network security health index assessment method proposed in some embodiments of this application in network security situation awareness products, thereby improving the network security health assessment business capabilities. The specific process is as follows:

[0089] 1. Access network traffic, business system web vulnerabilities, and system vulnerabilities of the managed business network through a data receiver. Specifically, this includes: non-compliant log data such as network traffic data of various protocols, application system web vulnerabilities, and operating system vulnerabilities.

[0090] 2. Define data specification standards for different types of data, and standardize the collected data through a data standardization engine to facilitate subsequent evaluation of the security and health index of the business system.

[0091] 3. Standardize and classify data and store it in a data storage device.

[0092] 4. For a specific asset information 'a', the risk value calculation formula above is simplified to: Ra = Ra(a, V, T) = Ra = (, g(Va, T)), where a represents the asset, Ra represents the risk, Va represents the vulnerability, T represents the threat, Ia represents the impact of a security threat on the business (also known as the importance of the asset), the future is simplified by the damage function F(Ia, Va) of the security event, and g represents the probability of a security event occurring by exploiting the asset vulnerability (also known as the true probability of the event).

[0093] 5. In assessment practice, threats from different sources have varying impacts. For example, the same threat posed by a nation-state, a hostile force, an external hacker, and an internal hacker will have different risks. Therefore, a correction function g2 is introduced into the calculation of the g function: Where S represents the threat source, s(S) represents the severity of the threat source, and g1 can be a summation function (calculating all vulnerability values ​​of the asset and all threat values ​​associated with the asset, and then summing them). Let be a Boolean function used to characterize whether an asset is threatened, where 'a' is the asset and 'T' is the threat. Its value range is as follows:

[0094] 1. The attack source is within China and is on a whitelist.

[0095] 2. The attack originated within China and was an unusual access method.

[0096] 3. The attack source is identified through threat intelligence.

[0097] 4. The attack originated from overseas or domestic hacker groups.

[0098] 5. The source of the attack is an enemy force.

[0099] Wherein, g2 is a correction function (for example, the function can be in the form of a logarithmic function, a step function, etc., and is used here to correct the threat value according to different threat sources). If there is a possibility that the system may cause a major security incident by subjective threat sources such as countries, hostile forces, external hackers, internal hackers, and legitimate users using Trojan attacks, password cracking, etc., then a correction value related to the corresponding threat and vulnerability is given; otherwise, the value is 0.

[0100] 6. Calculate the true probability of an event = g(threat, asset vulnerability) = g1(threat, asset vulnerability) + g2(threat, asset vulnerability).

[0101] Function g1 calculates all vulnerability values ​​of the asset and all threat values ​​associated with the asset, and then sums them.

[0102] Function g2 calculates the Trojan vulnerability value and password security value of the asset by multiplying them by the Trojan and password threat values ​​associated with the asset, and then sums them. If there is an attack from a subjective threat source such as a country, hostile forces, or hackers, the result is the product of the function value related to the threat source and the sum; otherwise, it is 0.

[0103] 7. Calculate the risk value based on the importance of the asset and the likelihood of a security incident.

[0104] Risk value = Ra (asset importance, probability of a security incident occurring)

[0105] 8. The total risk of the system being evaluated is the weighted sum of the risk values ​​of all assets. Let the weighted value of asset a be h(a), representing the degree of influence of the risk of asset a on the overall risk of the system being evaluated. Let the total risk of the system being evaluated be:

[0106] Rsum = a R a (a,V,T)h(a)

[0107] 9. Link events affecting the health index to the system's own security knowledge base using keywords. Also, link experts skilled in handling such security incidents to the knowledge base and add associated tags.

[0108] 10. Based on the risk values ​​calculated above, determine the risk level as shown in the table below.

[0109]

[0110] 11. When an administrator receives a health index alert, they can view the risk events affecting the health index in detail through the system. The system needs to display repair suggestions, methods, and emergency response expert information based on the correlation analysis engine to eliminate dangers in a timely manner and maintain network health and security.

[0111] Please refer to Figure 4 , Figure 4 This application illustrates an apparatus for assessing network security health, and it should be understood that this apparatus is similar to the one described above. Figure 2 Corresponding to the method embodiments, it can execute the various steps involved in the above method embodiments. The specific functions of the device can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here. The device includes at least one software function module that can be stored in the memory or embedded in the device's operating system in the form of software or firmware. The device for assessing network security health status includes: a data acquisition module 401 to be assessed, a network security health index value acquisition module 402, and a prompting module 403.

[0112] The data to be evaluated acquisition module is configured to acquire data to be evaluated, wherein the data to be evaluated is obtained based on target log data, and the target log data includes at least application system WEB vulnerability log information and operating system vulnerability log information.

[0113] The cybersecurity health index value acquisition module is configured to acquire the cybersecurity health index value based on the assessment model and the data to be assessed.

[0114] The alert module is configured to provide an alert if the network security health index value is within the alert range.

[0115] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.

[0116] Some embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the methods described in any of the embodiments included in the above-described method for assessing network security health status.

[0117] like Figure 5 As shown, some embodiments of this application provide an electronic device 500, including a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520, wherein when the processor 520 reads and executes the program via a bus 530, it can implement the methods described in any of the embodiments of the above-described method for assessing network security health status.

[0118] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.

[0119] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code used to implement some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of the embodiments of this disclosure can be used to execute the instructions in the memory 510 to implement… Figure 2 The method shown. Memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory well known to those skilled in the art.

[0120] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0121] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0122] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0123] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0124] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0125] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for assessing the health status of cybersecurity, characterized in that, The method includes: Obtain the data to be evaluated, wherein the data to be evaluated is obtained based on the target log data, and the target log data includes at least application system WEB vulnerability log information and operating system vulnerability log information; The cybersecurity health index value is obtained based on the assessment model and the data to be assessed. If the network security health index value is within the alarm range, an alarm message will be provided; The process of obtaining the cybersecurity health index value based on the evaluation model and the data to be evaluated includes: Obtain the risk value of each asset; derive the total risk value based on the risk value and weight of each asset; and use the total risk value as the cybersecurity health index value. The process of obtaining the risk value of each asset includes: obtaining the impact of a security threat to the first asset on the business; obtaining the probability of a security incident occurring by exploiting the vulnerability of the first asset, and obtaining the true probability value of the incident; and obtaining the risk value of the first asset based on the impact and the true probability value. The process of obtaining the impact of a security threat to the first asset on the business includes: obtaining the loss value after the corresponding event occurs based on the asset value and vulnerability level of the first asset; and calculating the total loss value based on the loss value, wherein the total loss value is used to characterize the impact on the business. The step of obtaining the probability of a security incident occurring due to the vulnerability of the first asset, and obtaining the true probability value of the incident, includes: obtaining the true probability value of the incident through a first function, wherein the first function further includes a base value and a correction function value, the correction function value is related to the risk source, and the base value is determined by the frequency of occurrence and vulnerability of the corresponding incident; The method further includes: associating target events affecting the health index with the system's own security knowledge base through keywords, associating experts who are good at handling the target events through the knowledge base, and adding association tags; when the administrator receives the alarm information, he obtains the association tags and provides relevant information based on the association tags.

2. The method as described in claim 1, characterized in that, The acquisition of the data to be evaluated includes: Access the network traffic of the managed network, collect network traffic data of various protocols, application system WEB vulnerability data, and operating system vulnerability data to obtain initial log data; The initial log data is formatted to obtain the data to be evaluated.

3. The method as described in claim 1, characterized in that, The process of obtaining the cybersecurity health index value based on the evaluation model and the data to be evaluated includes: Based on the data to be evaluated and the company's own asset data, quantitative analysis is performed on the target elements that affect the quantitative analysis to obtain the probability value of risk occurrence and the impact value of risk occurrence.

4. The method as described in claim 3, characterized in that, The target elements include: the cost of the protective measures, asset value, business impact, threat frequency, effectiveness of the protective measures, or the possibility of vulnerability exploitation.

5. An apparatus for assessing the health status of cybersecurity, characterized in that, The apparatus is used to perform the method as described in claim 1, comprising: The data to be evaluated acquisition module is configured to acquire data to be evaluated, wherein the data to be evaluated is obtained based on target log data, and the target log data includes at least application system WEB vulnerability log information and operating system vulnerability log information; The cybersecurity health index value acquisition module is configured to acquire a cybersecurity health index value based on the assessment model and the data to be assessed. The alert module is configured to provide an alert if the network security health index value is within the alert range.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it can implement the method as described in any one of claims 1-4.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it can implement the method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Method and apparatus for evaluating security health index of industrial control network

    CN109495502A

  • Network security risk assessment method and device, computer equipment and storage medium

    CN115643107A