A network security assessment method, system, device and storage medium

By obtaining hardware and traffic information of nodes in the network topology, calculating accessibility, and evaluating asset situations, threat situations and vulnerability situations, the problem of low efficiency and accuracy of network security assessment in the existing technology is solved, and a more efficient network security situation assessment is achieved.

CN116566635BActive Publication Date: 2025-08-26XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210111950.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-29
Publication Date
2025-08-26
Estimated Expiration
2042-01-29

AI Technical Summary

Technical Problem

Existing cybersecurity assessment methods are analyzed based on the dimensional characteristics of intrusion attacks only, resulting in low efficiency and low accuracy.

Method used

By obtaining hardware information and traffic information of each node in the network topology, the accessibility of the nodes is determined, and the asset situation, threat situation and vulnerability situation are calculated based on this, and the network security situation is comprehensively evaluated.

Benefits of technology

It improves the accuracy and efficiency of network security situation evaluation and reduces the dimension of network perception characteristics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566635B_ABST
    Figure CN116566635B_ABST
Patent Text Reader

Abstract

The present application discloses a network security assessment method to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment. The method includes: obtaining the network topology structure of the network to be assessed, and obtaining the hardware information and traffic information of each node in the network topology structure; respectively determining the accessibility corresponding to each node in the network topology structure; determining the asset situation of the network to be assessed based on the hardware information and accessibility of each node; determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node; determining the vulnerability situation of the network to be assessed based on the traffic information and corresponding accessibility of each node; evaluating the security situation of the network to be assessed based on the asset situation, threat situation and vulnerability situation to obtain an assessment result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a network security assessment method, system, device, and storage medium. Background Art

[0002] With the rapid development of computer network technology, the number of network users has increased, the scale of networks has grown, and network security incidents have increased accordingly. Rapidly detecting network security incidents has become a crucial issue for network technicians. Currently, single-point detection is a common method for monitoring network attacks. However, due to its drawbacks such as a single data source and a lack of effective coordination mechanisms, it cannot effectively respond to intelligent and complex network attacks. Therefore, a single firewall or network intrusion detection system cannot meet the requirements of modern network information security.

[0003] Network security situation assessment can reflect the network security status in an overall and dynamic manner, and evaluate and warn the development trend of network security. Therefore, it has become a research hotspot in the current network security field.

[0004] However, due to the growth of network scale, cybersecurity incidents are characterized by four key characteristics: large volume, diverse types, low value, and rapid processing. These characteristics necessitate comprehensive analysis of multiple network security factors, such as system vulnerabilities, port status, intrusion attacks, and accessibility, encompassing a wide range of high-dimensional network situational awareness features, rather than simply focusing on intrusion attacks alone.

[0005] Therefore, how to evaluate and analyze the network security situation in order to efficiently and quickly evaluate and judge the network security has become an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0006] The embodiment of the present application provides a network security assessment method to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment.

[0007] The embodiment of the present application also provides a network security assessment system to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment.

[0008] The embodiment of the present application also provides a network security assessment device to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment.

[0009] The embodiment of the present application also provides a computer-readable storage medium to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment.

[0010] The embodiments of this application adopt the following technical solutions:

[0011] A network security assessment method comprises: obtaining a network topology structure of a network to be assessed, and obtaining hardware information and traffic information of each node in the network topology structure within a preset time period; respectively determining the accessibility corresponding to each node in the network topology structure; determining the asset situation of the network to be assessed based on the hardware information and corresponding accessibility of each node within the preset time period; determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within the preset time period; determining the vulnerability situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within the preset time period; and assessing the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation to obtain an assessment result.

[0012] A network security assessment system comprises: a topology acquisition unit for acquiring the network topology of a network to be assessed, and acquiring the hardware information and traffic information of each node in the network topology within a preset time period; an accessibility determination unit for respectively determining the accessibility corresponding to each node in the network topology; an asset situation determination unit for determining the asset situation of the network to be assessed based on the hardware information and corresponding accessibility of each node within a preset time period; a threat situation determination unit for determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; a vulnerability situation determination unit for determining the vulnerability situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; and a security assessment unit for assessing the security situation of the network to be assessed based on the asset situation, the threat situation and the vulnerability situation to obtain an assessment result.

[0013] A network security assessment device, comprising:

[0014] A processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to perform the following operations: obtain a network topology structure of a network to be evaluated, and obtain hardware information and traffic information of each node in the network topology structure within a preset time period; respectively determine the accessibility corresponding to each node in the network topology structure; determine the asset situation of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; determine the threat situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; determine the vulnerability situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; evaluate the security situation of the network to be evaluated based on the asset situation, the threat situation, and the vulnerability situation to obtain an evaluation result.

[0015] A computer-readable storage medium stores one or more programs, which, when executed by an electronic device including multiple application programs, enable the electronic device to perform the following operations: obtain a network topology structure of a network to be evaluated, and obtain hardware information and traffic information of each node in the network topology structure within a preset time period; respectively determine the accessibility corresponding to each node in the network topology structure; determine the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; determine the threat status of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; determine the vulnerability status of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; evaluate the security status of the network to be evaluated based on the asset status, the threat status and the vulnerability status to obtain an evaluation result.

[0016] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects:

[0017] By adopting the network security assessment method provided in the embodiment of the present application, when a network security assessment is required, the network topology of the network to be assessed can be obtained, and the hardware information and traffic information of each node in the network topology within a preset time period can be obtained, and then the accessibility corresponding to each node, as well as the asset situation, threat situation and vulnerability situation of the network to be assessed can be determined respectively based on the obtained topology, the hardware information and traffic information of each node in the topology, and the asset situation, threat situation and vulnerability situation of the network to be assessed, and the security situation of the network to be assessed can be evaluated based on the asset situation, threat situation and vulnerability situation to obtain an assessment result. By adopting the network completeness assessment method provided in the present application, the accessibility of each node can be calculated based on the network topology and the relevant information of each node, and then the asset situation, threat situation and vulnerability situation of the network can be evaluated based on the accessibility of each node, and then the analysis and evaluation of the network security situation can be completed based on the above network situation characteristics, which reduces the dimension of the network perception characteristics required in the process of network security situation assessment and greatly improves the accuracy and efficiency of network security situation assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0019] Figure 1 A schematic diagram of a specific process of a network security assessment method provided in an embodiment of the present application;

[0020] Figure 2 A schematic diagram of a specific structure of a network topology diagram provided in an embodiment of the present application;

[0021] Figure 3 A schematic diagram of the specific structure of a network security assessment system provided in an embodiment of the present application;

[0022] Figure 4 A schematic diagram of the specific structure of a network security assessment device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0023] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0024] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0025] The embodiments of the present application provide a network security assessment method to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment.

[0026] The execution entity of the network security assessment method provided in the embodiments of the present application may be, but is not limited to, at least one of a network security assessment server, a network risk management server, and a network security server; in addition, the execution entity of the method may also be the application (Application, APP) itself running on these security servers.

[0027] For ease of description, the following describes an implementation of the method using a network security assessment server as an example. It should be understood that using a network security assessment server as the execution subject of the method is merely an example and should not be construed as limiting the method.

[0028] The specific implementation flow diagram of the network security assessment method provided in this application is as follows Figure 1 As shown, it mainly includes the following steps:

[0029] Step 11: obtaining a network topology of the network to be evaluated, and obtaining hardware information and traffic information of each node in the network topology within a preset time period;

[0030] The network topology is a topology graph constructed by all nodes in the network to be evaluated. That is, a node in the network corresponds to a point in the network topology graph. If two nodes can communicate, there is a line connecting the corresponding points of the two nodes in the network topology graph. This line is called an edge in the topology graph. Figure 2 shown.

[0031] In the embodiment of the present application, while obtaining the network topology structure of the network to be evaluated, the node type of each node in the topology structure is also obtained at the same time.

[0032] The type information is determined when the network node is deployed. The types of the node include but are not limited to the following: terminal, server, and switch.

[0033] In the embodiment of the present application, the node hardware information that needs to be obtained is mainly content related to the node hardware, such as: port number, port status, CPU usage, memory usage, vulnerability list, etc.

[0034] The port state is the current switch state of the port. If a port is open, the current port state of the port can be recorded as 1, and if a port is closed, the current port state of the port can be recorded as 0. In the embodiment of the present application, as long as a port has been 1 (i.e., open state) within a preset time period, the port state of the port within the preset time period is 1.

[0035] It should be noted that the vulnerability list of the node in the embodiment of the present application records: node vulnerabilities caused by the current operating system or hardware configuration of the node. The vulnerability list generally records the vulnerability type (such as DDOS attack) and the port number corresponding to the vulnerability.

[0036] Vulnerabilities exist objectively on node devices and are irrelevant to whether they are vulnerable to attacks. A list of vulnerabilities can be obtained from official vulnerability information released by operating systems and other organizations.

[0037] In one embodiment, the traffic information to be obtained is data related to the data transmission of the node, and may include, for example, data packet information and network information.

[0038] Among them, the data packet information describes the relevant information of each data packet, such as the data packet identifier, data direction (downlink or uplink), the ports involved, the source IP address (only for downlink data, there is no such indicator for uplink data) and the destination IP address (only for uplink data, there is no such indicator for downlink data).

[0039] Network information describes the overall situation during data transmission, such as packet loss rate, maximum number of connections at the same time, and traffic situation.

[0040] Step 12, respectively determining the accessibility corresponding to each node in the network topology structure;

[0041] The accessibility of a node represents the likelihood that the node will be accessed by a user. The user accessibility of any node is related to the type of the node.

[0042] In one embodiment, the accessibility corresponding to each node can be determined specifically according to the following scheme: determine the node class of each node in the network topology structure, and determine whether the node type of each node is a terminal; when the node type is determined to be a terminal, determine the accessibility corresponding to the node to be 1; when the node type is determined to be a non-terminal, determine all links with the node as the starting point and the node with the node type as the terminal as the end point, calculate the accessibility corresponding to the link respectively, and determine the accessibility corresponding to the node based on the accessibility corresponding to the link.

[0043] Specifically, when it is determined that the type of the node is a terminal, the accessibility corresponding to the node=1.

[0044] If the node type is determined to be non-terminal, such as a server or switch, the accessibility of the node can be determined by following the steps below:

[0045] Sub-step 1201, determining a link starting from the node and ending at the terminal;

[0046] Starting from this node, search along the edge. When a point is found as the terminal, this link is a confirmed link. Figure 2 For example, assuming that in the topology, nodes A, B, C, and D are non-terminals, and the remaining nodes E, F, G, and H are terminals. Assuming that the accessibility of non-terminal node A needs to be determined, the links starting from node A and ending at the terminal can be found in the graph, including: link ABCG, link AH, link ACG, link ABDE, and link ABDF, a total of five links.

[0047] Sub-step 1202, respectively calculating the accessibility corresponding to each link obtained by executing sub-step 1;

[0048] In the embodiment of the present application, the accessibility corresponding to each link can be calculated by the following formula [1]:

[0049]

[0050] Wherein, j represents the identifier of the non-terminal node in the link, D j Represents the ratio of the node j to the number of other nodes in the link.

[0051] Sub-step 1203, obtaining a first link with the greatest accessibility and a second link with the least edges;

[0052] Still Figure 2 , the link with the least edges is link AH, which only contains one edge.

[0053] Sub-step 1204: when the first link and the obtained second link are the same link, determining the accessibility of the first link as the accessibility corresponding to the node;

[0054] In sub-step 1205, when the first link is different from the obtained second link, the comprehensive value of each link can be calculated according to the following formula [2], and the maximum value of the comprehensive value of the link is used as the accessibility of the node:

[0055] Comprehensive value = max{link accessibility, (1 / number of edges contained in the link)} [2]

[0056] Step 13: Determine the asset status of the network to be evaluated based on the hardware information of each node within a preset time period obtained by executing step 11 and the accessibility of each node obtained by executing step 12;

[0057] In the embodiment of the present application, the asset status of the network to be evaluated can be calculated by the following formula [3]:

[0058] A=∑ i w i ×A i [3]

[0059] Among them, i is the node identifier of the node contained in the network to be evaluated, w i is the accessibility of node i, A i is the asset value of node i.

[0060] It should be noted that, in the embodiment of the present application, the asset value A of node i i The following formula [4] can be used to calculate the node i based on the number of ports, port status, CPU usage, memory usage, and vulnerability list in the hardware information of the node i:

[0061]

[0062] in, Indicates the maximum CPU usage of the node within a preset time period; Indicates the average CPU usage of the node within a preset time period; Indicates the minimum CPU usage of the node within a preset time period; Indicates the maximum memory usage of the node within a preset time period; Indicates the average memory usage of the node within a preset time period; Indicates the minimum memory usage of the node within the preset time period; because the vulnerability list records the vulnerability type (such as DDOS attack) and the corresponding port number, there may be a situation where the same vulnerability type corresponds to multiple ports, or the same port may correspond to multiple vulnerability types, so Indicates the number of different types of vulnerabilities in the vulnerability list. Indicates the maximum number of vulnerabilities of the same type in the vulnerability list; Indicates the number of ports. Indicates the number of ports in status 1.

[0063] Step 14: determining the threat situation of the network to be assessed based on the traffic information of each node within a preset time period obtained by executing step 11 and the accessibility corresponding to each node obtained by executing step 12;

[0064] In the embodiment of the present application, the threat situation of the network to be evaluated can be calculated by the following formula [5]:

[0065] R=∑ i w i ×R i [5]

[0066] Among them, w i is the accessibility of node i, R i is the threat value of node i.

[0067] It should be noted that, in the embodiment of the present application, the threat value R of node i is i It can be determined as follows:

[0068] Sub-step 1401, respectively obtaining data packet information of each node within a preset time period;

[0069] Among them, the data packet information includes: data packet identification, data direction (downlink or uplink), involved ports, source IP address (only for downlink data, no such indicator for uplink data) or destination IP address (only for uplink data, no such indicator for downlink data).

[0070] Sub-step 1402: clustering the uplink traffic data obtained by executing sub-step 1401 to obtain at least one uplink traffic data class;

[0071] Specifically, the uplink data packets are sorted in the order of arrival time to obtain an uplink data sequence. The arrival time difference between each uplink data in the uplink data sequence and the previous uplink data is calculated: Δt i 上 .

[0072] Classify the uplink traffic data and obtain the uplink traffic data to form a set φ i 上 Specifically, traffic data can be classified according to the following scheme:

[0073] a. From φ i 上 Choose any one element as the center of a class and mark it as classified;

[0074] b. Select an unclassified φ in turn i 上 For example, element x, the degree of belonging between element x and the already attributed elements y is calculated according to the following formula [6]:

[0075]

[0076] Among them, it can be calculated according to the following formula [7]

[0077]

[0078] Among them, ΔT represents the Δt in all uplink data packets i 上 The mean of .

[0079] If the port corresponding to element x is the same as the port corresponding to element y, a can be determined according to the following formula [8]:

[0080]

[0081] in, The number of vulnerability types corresponding to the port corresponding to element x in the vulnerability list.

[0082] If the port corresponding to the vulnerability list element x is different from the port corresponding to the vulnerability list element y, a can be determined according to the following formula [9]:

[0083]

[0084] in, The number of vulnerability types corresponding to the port corresponding to element y in the vulnerability list.

[0085] IP i xy is the source address similarity between element x and element y, which is calculated as follows:

[0086] An IP address is divided into four decimal digits. For example, in the case of 120.244.110.131, starting from the leftmost decimal digit of the source address, the values ​​of element x and element y are compared in sequence to see if they are the same. The position of the first different decimal digit is found.

[0087] For example, if the source IP address of element x is 120.244.110.131 and the source IP address of element y is 120.244.110.100, the first different decimal number is on the far right.

[0088] Taking AAA.BBB.CCC.DDD as an example, if the first different decimal digit is on the right (that is, the position of DDD), then IP i xy =1-absolute value of the difference between two different numbers / 255.

[0089] If the first different decimal number is the second from the right (i.e., the position of CCC), then IP i xy =(1-absolute value of the difference between two different numbers / 255) / 2.

[0090] If the first different decimal number is the second from the left (i.e., the position of BBB), then IP i xy =(1-absolute value of the difference between two different numbers / 255) / 4.

[0091] If the first different decimal digit is on the left (that is, the position of AAA), then IP i xy =(1-absolute value of the difference between two different numbers / 255) / 8.

[0092] At this point, φ will be calculated i 上 The degree of belonging between each unclassified element and each classified element.

[0093] c. Find the maximum degree of attribution among all degrees of attribution, and classify the unclassified elements in the maximum degree of attribution into the class of the corresponding classified elements.

[0094] d. Find the minimum degree of attribution among all degrees of attribution, determine the unclassified elements in the minimum degree of attribution as a new class, and mark them as classified.

[0095] e. Repeat steps b-d above until φ i 上 All elements in are classified.

[0096] Sub-step 1403, clustering the downlink traffic data obtained by executing sub-step 1401 to obtain at least one downlink traffic data class;

[0097] The clustering method for downstream traffic data is the same as that for upstream traffic data, except that the source IP is changed to the destination IP. Therefore, the clustering method for downstream traffic data will not be described in detail here.

[0098] Sub-step 1404, determine the threat value of the node according to the following formula

[10] :

[0099] Ri=U1 / U+D1 / D

[10]

[0100] Among them, U1 represents the number of elements of the uplink traffic data class with the largest number of elements, U represents the total amount of uplink traffic data, D1 represents the number of elements of the downlink traffic data class with the largest number of elements, and D represents the total amount of downlink traffic data.

[0101] Step 15: Determine the vulnerability status of the network to be evaluated based on the traffic information of each node within a preset time period obtained by executing step 11 and the accessibility corresponding to each node obtained by executing step 12;

[0102] In the embodiment of the present application, the vulnerability status of the network to be evaluated can be calculated by the following formula

[11] :

[0103] L=∑ i w i ×L i

[11]

[0104] Among them, w i is the accessibility of node i, L i is the vulnerability value of node i.

[0105] It should be noted that, in the embodiment of the present application, the vulnerability value L of node i is i It can be determined as follows:

[0106] According to the traffic information of node i in the preset time period, the packet loss rate, maximum number of connections and traffic situation of node i in the preset time period are obtained.

[0107] The vulnerability value of node i is calculated according to the following formula

[12] :

[0108] L i = Packet loss rate × maximum number of connections × average traffic situation × e^Q

[12]

[0109] Where Q represents the product of the maximum losses caused by attacks of the corresponding vulnerability types on each port with status 1.

[0110] Step 16: Evaluate the security situation of the network to be evaluated based on the asset situation, threat situation, and vulnerability situation of the network to be evaluated calculated by executing steps 13 to 15 to obtain an evaluation result.

[0111] In the embodiment of the present application, the security situation of the network to be evaluated can be calculated according to the following formula

[13] :

[0112] S=A×R×L

[13]

[0113] Wherein, S represents the security situation of the network to be evaluated, A represents the asset situation of the network to be evaluated, R represents the threat situation of the network to be evaluated, and L represents the vulnerability situation of the network to be evaluated.

[0114] By adopting the network security assessment method provided in the embodiment of the present application, when a network security assessment is required, the network topology of the network to be assessed can be obtained, and the hardware information and traffic information of each node in the network topology within a preset time period can be obtained, and then the accessibility corresponding to each node, as well as the asset situation, threat situation and vulnerability situation of the network to be assessed can be determined respectively based on the obtained topology, the hardware information and traffic information of each node in the topology, and the asset situation, threat situation and vulnerability situation of the network to be assessed, and the security situation of the network to be assessed can be evaluated based on the asset situation, threat situation and vulnerability situation to obtain an assessment result. By adopting the network completeness assessment method provided in the present application, the accessibility of each node can be calculated based on the network topology and the relevant information of each node, and then the asset situation, threat situation and vulnerability situation of the network can be evaluated based on the accessibility of each node, and then the analysis and evaluation of the network security situation can be completed based on the above network situation characteristics, which reduces the dimension of the network perception characteristics required in the process of network security situation assessment and greatly improves the accuracy and efficiency of network security situation assessment.

[0115] In one embodiment, the present application also provides a network security assessment system to solve the problem that the existing network security assessment method only analyzes the intrusion attack dimension when conducting network security situation assessment, resulting in low efficiency and low accuracy of the existing network security assessment. The specific structural diagram of the network security assessment system is shown in FIG. Figure 3 As shown, it includes: a topology acquisition unit 31, an accessibility determination unit 32, an asset situation determination unit 33, a threat situation determination unit 34, a vulnerability situation determination unit 35 and a security assessment unit 36.

[0116] The topology acquisition unit 31 is configured to acquire the network topology of the network to be evaluated, and to acquire the hardware information and traffic information of each node in the network topology within a preset time period;

[0117] an accessibility determination unit 32, configured to respectively determine the accessibility corresponding to each node in the network topology structure;

[0118] An asset status determination unit 33 is configured to determine the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period;

[0119] A threat situation determination unit 34 is configured to determine the threat situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period;

[0120] A vulnerability situation determination unit 35 is configured to determine the vulnerability situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period;

[0121] The security assessment unit 36 ​​is configured to assess the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation to obtain an assessment result.

[0122] In one embodiment, the topology structure acquisition unit 31 is specifically configured to acquire the network topology structure of the network to be evaluated; and determine the node type of each node in the network topology structure.

[0123] In one embodiment, the accessibility determination unit 32 is specifically used to: determine the node class of each node in the network topology structure, and determine whether the node type of each node is a terminal; when the node type is determined to be a terminal, determine the accessibility corresponding to the node to be 1; when the node type is determined to be a non-terminal, determine all links that start from the node and end at a node with a terminal node type, calculate the accessibility corresponding to the link respectively, and determine the accessibility corresponding to the node based on the accessibility corresponding to the link.

[0124] In one embodiment, the accessibility determination unit 32 is specifically configured to calculate the accessibility corresponding to the link according to the following formula:

[0125]

[0126] Wherein, j represents the identifier of the non-terminal node in the link, D j represents the ratio of the number of node j to the number of other nodes in the link; obtain the first link with the greatest accessibility and the second link with the least edges; when the first link and the second link are the same link, the accessibility of the first link is determined as the accessibility corresponding to the node; when the first link and the second link are different, the comprehensive value of each link is calculated according to the following formula:

[0127] Link comprehensive value = max{link accessibility, (1 / number of edges included in the link)}

[0128] The maximum value of the link comprehensive value is taken as the accessibility of the node.

[0129] In one embodiment, the asset status determination unit 33 is specifically configured to: obtain the number of ports, port status, CPU usage, memory usage, and vulnerability list of the node within a preset time period based on the hardware information of the node within a preset time period;

[0130] The asset value of the node is determined according to the following formula:

[0131]

[0132] in, Indicates the maximum CPU usage of the node within the preset time period. Indicates the average CPU usage of the node within a preset time period. Indicates the minimum CPU usage of the node within the preset time period. Indicates the maximum value of the node's memory usage within the preset time period. Indicates the average memory usage of the node within the preset time period, Indicates the minimum memory usage of the node within the preset time period. Indicates the number of different types of vulnerabilities in the vulnerability list. Indicates the maximum number of vulnerabilities of the same type in the vulnerability list. Indicates the number of ports. Indicates the number of ports in state 1;

[0133] The asset status of the network to be evaluated is calculated according to the following formula:

[0134] A=∑ i w i ×A i

[0135] Wherein, i is the node identifier of the node included in the network to be evaluated, w i is the accessibility corresponding to node i, A i is the asset value of node i.

[0136] In one embodiment, the threat situation determination unit 34 is specifically configured to: obtain uplink traffic data and downlink traffic data of each node within a preset time period;

[0137] Clustering the uplink traffic data to obtain at least one uplink traffic data class;

[0138] Clustering the downlink traffic data to obtain at least one downlink traffic data class;

[0139] The threat value of the node is determined according to the following formula:

[0140] Ri=U1 / U+D1 / D

[0141] Among them, U1 represents the number of elements of the uplink traffic data class with the largest number of elements, U represents the total amount of uplink traffic data, D1 represents the number of elements of the downlink traffic data class with the largest number of elements, and D represents the total amount of downlink traffic data;

[0142] The threat situation of the network to be assessed is calculated according to the following formula:

[0143] R=∑ i w i ×R i

[0144] Among them, w i is the accessibility of node i, R i is the threat value of node i.

[0145] In one embodiment, the vulnerability situation determination unit 35 is specifically configured to: obtain the packet loss rate, the maximum number of connections, and the traffic situation of the node within a preset time period based on the traffic information of the node within a preset time period;

[0146] The vulnerability value of the node is determined according to the following formula:

[0147] L i =Packet loss rate × maximum number of connections × average traffic situation × e^Q

[0148] Where Q represents the product of the maximum losses caused by attacks of the corresponding vulnerability type on each port with status 1;

[0149] The vulnerability status of the network to be assessed is calculated according to the following formula:

[0150] L=∑ i w i ×L i

[0151] Among them, w i is the accessibility of node i, L i is the vulnerability value of node i.

[0152] In one embodiment, the security assessment unit 36 ​​is specifically configured to determine the security situation of the network to be assessed according to the following formula:

[0153] S=A×R×L

[0154] Wherein, S represents the security situation of the network to be evaluated, A represents the asset situation of the network to be evaluated, R represents the threat situation of the network to be evaluated, and L represents the vulnerability situation of the network to be evaluated.

[0155] By adopting the network security assessment system provided by the embodiment of the present application, when a network security assessment is required, the network topology of the network to be assessed can be obtained, and the hardware information and traffic information of each node in the network topology within a preset time period can be obtained, and then the accessibility corresponding to each node, as well as the asset situation, threat situation and vulnerability situation of the network to be assessed, can be determined respectively based on the obtained topology, the hardware information and traffic information of each node in the topology, and the asset situation, threat situation and vulnerability situation of the network to be assessed. Based on the asset situation, threat situation and vulnerability situation, the security situation of the network to be assessed is evaluated to obtain an assessment result. By adopting the network completeness assessment method provided by the present application, the accessibility of each node can be calculated based on the network topology and the relevant information of each node, and then the asset situation, threat situation and vulnerability situation of the network can be evaluated based on the accessibility of each node. Then, based on the above network situation characteristics, the analysis and evaluation of the network security situation can be completed, which reduces the dimension of the network perception characteristics required in the process of network security situation assessment and greatly improves the accuracy and efficiency of network security situation assessment.

[0156] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 4 At the hardware level, the electronic device includes a processor and, optionally, an internal bus, a network interface, and memory. The memory may include internal memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for its services.

[0157] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0158] The memory is used to store programs. Specifically, the program may include program code, which includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor.

[0159] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, forming a data synchronization device at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:

[0160] Obtain a network topology structure of the network to be evaluated, and obtain hardware information and traffic information of each node in the network topology structure within a preset time period; respectively determine the accessibility corresponding to each node in the network topology structure; determine the asset situation of the network to be evaluated based on the hardware information and corresponding accessibility of each node within the preset time period; determine the threat situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within the preset time period; determine the vulnerability situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within the preset time period; evaluate the security situation of the network to be evaluated based on the asset situation, the threat situation and the vulnerability situation to obtain an evaluation result.

[0161] The above application Figure 4The methods performed by electronic devices for network security assessment disclosed in the illustrated embodiments can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be performed by hardware integrated logic circuits in the processor or by software instructions. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0162] Of course, in addition to software implementation, the electronic device of this application does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0163] The embodiment of the present application also provides a computer-readable storage medium, which stores one or more programs, wherein the one or more programs include instructions, which, when executed by a portable electronic device including multiple application programs, can enable the portable electronic device to execute Figure 1 The method of the embodiment shown is specifically used to perform the following operations:

[0164] Obtain a network topology structure of the network to be evaluated, and obtain hardware information and traffic information of each node in the network topology structure within a preset time period; respectively determine the accessibility corresponding to each node in the network topology structure; determine the asset situation of the network to be evaluated based on the hardware information and corresponding accessibility of each node within the preset time period; determine the threat situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within the preset time period; determine the vulnerability situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within the preset time period; evaluate the security situation of the network to be evaluated based on the asset situation, the threat situation and the vulnerability situation to obtain an evaluation result.

[0165] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0166] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0167] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0168] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0169] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0170] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0171] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0172] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0173] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0174] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A network security assessment method, characterized in that: include: Obtaining a network topology structure of the network to be evaluated, and obtaining hardware information and traffic information of each node in the network topology structure within a preset time period; Determining the accessibility of each node in the network topology structure; Determining the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; Determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Determining the vulnerability status of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Assessing the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation to obtain an assessment result; Determining the accessibility of each node in the network topology structure respectively includes: Determining a node type of each node in the network topology; Determining whether the node type of each node is a terminal; When it is determined that the node type is a terminal, the accessibility corresponding to the node is determined to be 1; When it is determined that the node type is non-terminal, all links with the node as the starting point and the node with the node type as the terminal as the end point are determined, and the accessibility corresponding to the links is calculated respectively. Based on the accessibility corresponding to the links, the accessibility corresponding to the node is determined.

2. The method according to claim 1, characterized in that Calculating the accessibility corresponding to the link, and determining the accessibility corresponding to the node based on the accessibility corresponding to the link, specifically including: The accessibility of the link is calculated according to the following formula: Wherein, j represents the identifier of the non-terminal node in the link, D j represents the ratio of the number of the node j to the number of other nodes in the link; Obtain the first link with the greatest accessibility and the second link with the least edges; When the first link and the second link are the same link, determining the accessibility of the first link as the accessibility corresponding to the node; When the first link and the second link are different, the comprehensive value of each link is calculated according to the following formula: Link comprehensive value = max{link accessibility, (1 / number of edges contained in the link)} The maximum value of the link comprehensive value is taken as the accessibility of the node.

3. The method according to claim 1, characterized in that Determining the asset status of the network to be evaluated based on the hardware information of each node within a preset time period and the corresponding accessibility specifically includes: According to the hardware information of the node within the preset time period, obtain the number of ports, port status, CPU usage, memory usage and vulnerability list of the node within the preset time period; The asset value of the node is determined according to the following formula: in, Indicates the maximum CPU usage of the node within the preset time period. Indicates the average CPU usage of the node within a preset time period. Indicates the minimum CPU usage of the node within the preset time period. Indicates the maximum memory usage of the node within the preset time period. Indicates the average memory usage of the node within the preset time period, Indicates the minimum value of the node's memory usage within the preset time period. Indicates the number of different types of vulnerabilities in the vulnerability list. Indicates the maximum number of vulnerabilities of the same type in the vulnerability list. Indicates the number of ports. Indicates the number of ports in state 1; The asset status of the network to be evaluated is calculated according to the following formula: Wherein, i is the node identifier of the node included in the network to be evaluated, w i is the accessibility corresponding to node i, A i is the asset value of node i.

4. The method according to claim 1, wherein Determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period specifically includes: Obtain the uplink traffic data and downlink traffic data of each node within a preset time period respectively; Clustering the uplink traffic data to obtain at least one uplink traffic data class; Clustering the downlink traffic data to obtain at least one downlink traffic data class; The threat value of the node is determined according to the following formula: Ri=U1 / U+D1 / D Among them, U1 represents the number of elements of the uplink traffic data class with the largest number of elements, U represents the total amount of uplink traffic data, D1 represents the number of elements of the downlink traffic data class with the largest number of elements, and D represents the total amount of downlink traffic data; The threat situation of the network to be assessed is calculated according to the following formula: Among them, w i is the accessibility of node i, R i is the threat value of node i.

5. The method according to claim 1, characterized in that Determining the vulnerability status of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period specifically includes: According to the traffic information of the node in the preset time period, the packet loss rate, maximum number of connections and traffic situation of the node in the preset time period are obtained; The vulnerability value of the node is determined according to the following formula: L i =Packet loss rate × maximum number of connections × average traffic situation × e^Q Where Q represents the product of the maximum losses caused by attacks of the corresponding vulnerability type on each port with status 1; The vulnerability status of the network to be assessed is calculated according to the following formula: Among them, w i is the accessibility of node i, L i is the vulnerability value of node i.

6. The method according to claim 1, characterized in that The evaluating the security situation of the network to be evaluated based on the asset value, the threat situation, and the vulnerability situation specifically includes: The security posture of the network to be assessed is determined using the following formula: S=A×R×L Wherein, S represents the security situation of the network to be evaluated, A represents the asset situation of the network to be evaluated, R represents the threat situation of the network to be evaluated, and L represents the vulnerability situation of the network to be evaluated.

7. A network security assessment system, characterized in that: include: A topology acquisition unit is used to acquire the network topology of the network to be evaluated, and to acquire the hardware information and traffic information of each node in the network topology within a preset time period; an accessibility determination unit, configured to respectively determine the accessibility corresponding to each node in the network topology structure; An asset status determination unit, configured to determine the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; A threat situation determination unit, configured to determine the threat situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; A vulnerability situation determination unit, configured to determine the vulnerability situation of the network to be evaluated based on the traffic information and corresponding accessibility of each node within a preset time period; A security assessment unit, configured to assess the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation, and obtain an assessment result; The accessibility determination unit is specifically configured to determine the node type of each node in the network topology structure; Determining whether the node type of each node is a terminal; When it is determined that the node type is a terminal, the accessibility corresponding to the node is determined to be 1; When it is determined that the node type is non-terminal, all links with the node as the starting point and the node with the node type as the terminal as the end point are determined, and the accessibility corresponding to the links is calculated respectively. Based on the accessibility corresponding to the links, the accessibility corresponding to the node is determined.

8. A network security assessment device comprising: processor; as well as a memory arranged to store computer-executable instructions which, when executed, cause the processor to: Obtaining a network topology structure of the network to be evaluated, and obtaining hardware information and traffic information of each node in the network topology structure within a preset time period; Determining the accessibility of each node in the network topology structure; Determining the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; Determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Determining the vulnerability status of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Assessing the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation to obtain an assessment result; Determining the accessibility of each node in the network topology structure respectively includes: Determining a node type of each node in the network topology; Determining whether the node type of each node is a terminal; When it is determined that the node type is a terminal, the accessibility corresponding to the node is determined to be 1; When it is determined that the node type is non-terminal, all links with the node as the starting point and the node with the node type as the terminal as the end point are determined, and the accessibility corresponding to the links is calculated respectively. Based on the accessibility corresponding to the links, the accessibility corresponding to the node is determined.

9. A computer-readable storage medium storing one or more programs that, when executed by an electronic device including a plurality of application programs, causes the electronic device to perform the following operations: Obtaining a network topology structure of the network to be evaluated, and obtaining hardware information and traffic information of each node in the network topology structure within a preset time period; Determining the accessibility of each node in the network topology structure; Determining the asset status of the network to be evaluated based on the hardware information and corresponding accessibility of each node within a preset time period; Determining the threat situation of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Determining the vulnerability status of the network to be assessed based on the traffic information and corresponding accessibility of each node within a preset time period; Assessing the security situation of the network to be assessed based on the asset situation, the threat situation, and the vulnerability situation to obtain an assessment result; Determining the accessibility of each node in the network topology structure respectively includes: Determining a node type of each node in the network topology; Determining whether the node type of each node is a terminal; When it is determined that the node type is a terminal, the accessibility corresponding to the node is determined to be 1; When it is determined that the node type is non-terminal, all links with the node as the starting point and the node with the node type as the terminal as the end point are determined, and the accessibility corresponding to the links is calculated respectively. Based on the accessibility corresponding to the links, the accessibility corresponding to the node is determined.

Citation Information

Patent Citations

  • A Method for Detecting Vulnerability of Large-scale Power Grid Based On Complex Network

    AU2020103195A4