A network security early warning processing method and electronic equipment
Patent Information
- Application Number
- CN202310761990.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-26
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2043-06-26
AI Technical Summary
[0004]本申请提供一种网络安全预警处理方法及电子设备,用以解决网络安全预警准确度不高的问题
[0038]本申请提供的网络安全预警处理方法及电子设备,通过网络中各节点自身情况以及各节点受攻击之后的影响情况对网络安全进行检测,通过这两方面可以准确地描述当前网络被攻击的可能性,进而对网络安全进行预警处理。
Smart Images

Figure CN116743469B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a network security early warning processing method and electronic device. Background Technology
[0002] With the development of the internet and the rapid growth of computer networks, the network has brought tremendous convenience to people. However, it has also brought security issues. Network security has become one of the most important factors for enterprises. To protect and ensure network security, the importance of network security equipment is becoming increasingly prominent. Therefore, there is an urgent need to adopt an effective method for early warning of network security vulnerabilities.
[0003] Most existing cybersecurity early warning methods quantify cyber threats in specific scenarios to identify them and then issue warnings. However, the accuracy of cybersecurity early warnings in existing technologies is not high, thus cybersecurity risks still exist. Summary of the Invention
[0004] This application provides a network security early warning processing method and electronic device to solve the problem of low accuracy in network security early warning.
[0005] On the one hand, this application provides a network security early warning processing method, including:
[0006] Determine the vulnerability of each node in the network, whereby the vulnerability represents the degree to which the node is susceptible to attack;
[0007] Obtain vulnerability information and historical attack information for each node, and determine the attack impact value based on the vulnerability information and the historical attack information;
[0008] Determine the number of associated devices for each node;
[0009] Based on the vulnerability of each node in the network, the impact of attacks, and the number of related devices, the security prediction value of the network is determined.
[0010] Network security early warning processing is carried out based on the security prediction values.
[0011] Furthermore, determining the vulnerability of each node in the network includes:
[0012] Obtain device information for each node, wherein the device information includes at least one of the following: device type, vulnerability information, device security level, and system operation information;
[0013] The vulnerability of a node is determined based on the device information of each node.
[0014] Furthermore, the vulnerability includes: type vulnerability, vulnerability vulnerability, security impact, and operational vulnerability; determining the vulnerability of each node based on its device information includes:
[0015] Based on the device information, determine the type vulnerability, vulnerability level, security impact level, and operational vulnerability, respectively.
[0016] The vulnerability of a node is determined by summing the products of the type vulnerability, the vulnerability itself, the security impact, and the operational vulnerability.
[0017] Furthermore, determining the type of vulnerability based on the device information includes:
[0018] Determine the device type of each node and obtain the correspondence between the device type and the type vulnerability;
[0019] The type vulnerability of each node is determined based on the correspondence.
[0020] Furthermore, determining the vulnerability of each node based on its device information includes:
[0021] Determine the security level of each vulnerability and its corresponding vulnerability vulnerability in the vulnerability information of each node;
[0022] The vulnerability of a node is determined based on the vulnerability of each security vulnerability in each node.
[0023] Furthermore, determining the security impact of each node based on its device information includes:
[0024] Determine the security level of each node and obtain the correspondence between the security level and the security impact.
[0025] The security impact of each node's security level is determined based on the aforementioned correspondence.
[0026] Furthermore, determining the operational vulnerability of each node based on its device information includes:
[0027] Determine the number of ports, the number of open ports, the maximum maximum number of connections, the average traffic, and the total number of services;
[0028] The operational vulnerability is determined by multiplying the quotient of dividing the number of ports by the number of open ports, the maximum value of the maximum number of connections, the average traffic, and the sum of the weights corresponding to each service.
[0029] Furthermore, determining the attack impact value based on the vulnerability information and the historical attack information includes:
[0030] Determine the security level of each vulnerability in the vulnerability information of each node;
[0031] The attack impact value for each node is determined by dividing the product of the actual attack impact value and the threat level value corresponding to the highest security level vulnerability.
[0032] Furthermore, determining the network's security prediction value based on the vulnerability of each node in the network, the attack impact value, and the number of related devices includes:
[0033] Determine the product of the vulnerability of each node, the attack impact value, and the number of devices;
[0034] The sum of the products of each node is determined as the security prediction value of the network.
[0035] On the other hand, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0036] The memory stores computer-executed instructions;
[0037] The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-9.
[0038] The network security early warning processing method and electronic device provided in this application detect network security by considering the status of each node in the network and the impact of attacks on each node. Through these two aspects, the possibility of the current network being attacked can be accurately described, thereby enabling early warning processing of network security. Attached Figure Description
[0039] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0040] Figure 1 A flowchart illustrating a network security early warning processing method provided in this application;
[0041] Figure 2 A flowchart illustrating a method for determining the vulnerability of each node in a network, as provided in this application;
[0042] Figure 3 This application provides a flowchart illustrating a method for determining the impact value of an attack.
[0043] Figure 4This is a schematic diagram of the structure of an electronic device provided in this application.
[0044] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0045] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0046] The network security early warning processing method and electronic device provided in this application aim to solve the technical problem of low accuracy of network security early warning in the prior art.
[0047] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0048] Figure 1 The flowchart of a network security early warning processing method provided in this application is shown. The method specifically includes the following steps:
[0049] S101. Determine the vulnerability of each node in the network. This vulnerability is used to indicate how easily a node is attacked.
[0050] Vulnerabilities in a computer network system, which are flaws in its design, implementation, operation, and control that could be exploited by attackers to cause security risks, are called vulnerabilities. The presence of vulnerabilities in a network system can lead to network attacks; conversely, the absence of vulnerabilities makes network attacks relatively unlikely. Therefore, node vulnerability indicates how easily a node is attacked. A high node vulnerability score indicates that the node is easily attacked, while a low score indicates that the node is not easily attacked. Each node in a network refers to every device within the network, such as a terminal, server, or switch.
[0051] S102. Obtain vulnerability information and historical attack information for each node, and determine the attack impact value based on the vulnerability information and historical attack information.
[0052] The attack information describes the circumstances under which the device was attacked. This information can be obtained from the logs of security software such as firewalls on the device. Examples include the attacker's IP address, attack type, attack time, attack actions, and vulnerabilities involved.
[0053] A vulnerability is a weakness or flaw in a system. Vulnerabilities may stem from design flaws in application software or operating systems, or from design flaws in business interaction processes. These flaws can be exploited intentionally or unintentionally, causing adverse effects. Therefore, when conducting cybersecurity predictions, it is necessary to obtain vulnerability information and take different countermeasures based on the specific vulnerability information. This vulnerability information can also be obtained from the logs of security software such as firewalls, and may include details such as release date, vulnerability name, suggested remediation, affected platforms, vulnerability ID, and security severity level.
[0054] S103. Determine the number of devices with associated relationships at each node.
[0055] Devices with a communication relationship generally refer to all other devices that communicate with the target device. Since devices with a communication relationship are relatively more vulnerable to attack after the target device is attacked, the number of such devices can generally be used to characterize the potential scope of an attack's impact. The more devices with a communication relationship, the larger the scope of the impact after an attack; conversely, the fewer such devices, the smaller the scope of the impact.
[0056] S104. Determine the network security prediction value based on the vulnerability of each node in the network, the impact of attacks, and the number of related devices.
[0057] Network security prediction values refer to numerical values that represent the network's operational security status, obtained by integrating massive amounts of network security data and applying certain algorithms.
[0058] In this step, the network security prediction value can be obtained as follows: First, determine the product of the vulnerability of each node, the attack impact value, and the number of devices. Then, based on this product value for each node, sum the product values of all nodes to determine the network security prediction value: Predicted value = ∑ i The value of the attack on the i-th device is n * the vulnerability of the i-th device * the attack impact value of the i-th device.
[0059] Where n is the number of other devices that are associated with this device.
[0060] i represents the device identifier. For example, if there are 50 devices in the network, then i ranges from 1 to 50, and the sum of the results for these 50 devices is calculated.
[0061] Understandably, the vulnerability of each node, the impact of an attack, and the number of related devices can also be determined using different weight settings and fusion algorithms based on the specific network environment of the application to determine the predicted values for network security.
[0062] S105. Conduct network security early warning processing based on security prediction values.
[0063] After obtaining the network security prediction value, it can be compared with a pre-set threshold, which can be an empirical value for different types of networks. If the obtained security prediction value is greater than the threshold, it indicates that the network security is under greater threat and the network is insecure. In this case, an alarm should be triggered to alert the network to the current security risk.
[0064] Alarms can be issued via sound or by sending alerts to the system's central processing platform to alert users of network security risks. Furthermore, targeted warnings and protective measures can be implemented based on the vulnerability of each node and the number of its associated nodes. For example, for nodes with high vulnerability and a large number of associated nodes, traffic data can be collected and analyzed, and protective measures can be upgraded for those nodes.
[0065] The network security early warning and processing method proposed in this proposal detects network security by examining the individual status of each node and the impact of an attack on that node. The individual status of a node describes its vulnerability, while the impact of an attack on a node describes the overall impact of the attack on the network. By analyzing these two aspects, the probability of the current network being attacked can be accurately described, thereby predicting the current network security posture. This proposed solution can predict the security posture of any network and is therefore universally applicable.
[0066] Figure 2 This application provides a method for determining the vulnerability of each node in a network. The vulnerability of a node is determined by further analyzing its type vulnerability, vulnerability to vulnerabilities, security impact, and operational vulnerability. The specific determination method includes the following steps:
[0067] S201. Obtain device information for each node, including at least one of the following: device type, vulnerability information, device security level, and system operation information.
[0068] A node's vulnerability is used to indicate whether a node is susceptible to attack. A device's vulnerability is related to the device's own vulnerabilities and its condition. Therefore, it is necessary to obtain device information first.
[0069] The device information includes at least one of the following: device type, vulnerability information, device security level, and system operation information. The following is a detailed explanation of the various pieces of information included in the device information:
[0070] Device type describes the purpose of a device, such as terminal, server, switch, etc. This type is determined when the device is deployed.
[0071] Vulnerability information describes vulnerabilities in a device's operating system or other software, and this information can be obtained through web crawlers.
[0072] A device's security level describes its security positioning and is determined during deployment. For example, if a device stores confidential data, its security level is high; if it's located on a public network and only relays ordinary data, its security level is low. The device's security level is determined during deployment based on its intended use, and can be modified if the intended use changes subsequently.
[0073] System operation information describes the current operating status of the device, such as the number of device ports, the status of each port, the number of services, the service type, and network information (such as packet loss rate, maximum number of connections at the same time, and traffic status).
[0074] After obtaining the aforementioned device information, the vulnerability of each node can be determined based on that information. Node vulnerability can be further categorized into four aspects: type vulnerability, vulnerability level, security impact, and operational vulnerability.
[0075] S202. Determine the type vulnerability of the node based on the correspondence between device type and type vulnerability.
[0076] In this step, the correspondence between device type and type vulnerability is determined through a set correspondence table. This table records the vulnerability corresponding to each device type, and the type vulnerability of each node can be determined based on this table.
[0077] This vulnerability is an empirical value determined by experienced security experts to the extent to which each type of device is vulnerable to attack. The higher the value, the more susceptible the device is to attack.
[0078] For example, the correspondence between device type and type vulnerability is shown in Table 1 (it should be noted that Table 1 is only an example, and the specific implementation can be determined according to the actual situation).
[0079] Table 1
[0080] terminal 0.6 server 0.6 switch 0.5
[0081] S203. Determine the vulnerability of the node based on the vulnerability information.
[0082] In this step, the specific method for determining the vulnerability of a node is as follows:
[0083] First, it is necessary to determine the security level of each vulnerability in the vulnerability information and its corresponding vulnerability vulnerability.
[0084] A vulnerability is a flaw, whether intentional or unintentional, that occurs in the process of requirement setting, design, implementation, configuration, and operation of a computer information system. Based on the severity of the flaw, vulnerabilities can be classified into different security levels, such as "Critical," "Important," "Warning," and "Caution," with the severity decreasing sequentially from "Critical" to "Caution."
[0085] When the security level corresponding to the vulnerability information is the lower level of "Warning" and "Note", then the corresponding vulnerability vulnerability value is set to 1.
[0086] When the security level in the vulnerability information includes higher security levels such as "critical" and "important," it is necessary to determine the threat level of each vulnerability. For vulnerabilities with security levels of "important" and "critical," the threat level is set to a value greater than 1. This value is an empirical value preset based on attack scenarios. Each vulnerability is susceptible to different attacks; therefore, the threat level setting will vary depending on the attack. Based on the vulnerabilities, the possible attacks can be obtained, and the sum of the threat levels corresponding to all possible attacks is taken as W1. At this point, vulnerability vulnerability = log(the sum of the threat levels W1 of all vulnerabilities with security levels of "important" and "critical").
[0087] Then, the vulnerability of each node is determined based on the vulnerability of each security vulnerability.
[0088] The vulnerability level of a node varies depending on the security level of the vulnerability. If the security level of each vulnerability in the vulnerability information is only "Warning" and "Caution", then the current vulnerability threat level of this node is considered to be low, and there is no need to determine the specific threat level value. The vulnerability value of this node is the value of 1 corresponding to each low-level security vulnerability.
[0089] If any vulnerability information contains vulnerabilities with security levels of "urgent" and "important", then the vulnerability vulnerability value of that node is the value calculated based on the threat level corresponding to the vulnerability with the higher security level.
[0090] The higher the vulnerability value, the more vulnerable the node is.
[0091] S204. Determine the safety impact of this node based on the equipment safety level.
[0092] This step, which determines the degree of safety impact, specifically includes the following:
[0093] Determine the security level of each node and obtain the correspondence between the security level and the security impact. Based on the correspondence, determine the security impact corresponding to the security level of each node.
[0094] This method is similar to the method for determining type vulnerability, also using a pre-defined mapping table between security levels and security impact. Different security levels are pre-set based on experience to indicate the degree of impact after an attack; the higher the security level, the greater the impact after an attack. By looking up the mapping table using the device's security level, the security impact of that node can be determined.
[0095] The security impact rating characterizes the consequences of attacks on devices with different security levels. The higher the value, the more severe the consequences of the attack.
[0096] S205. Determine the operational vulnerability of this node based on system operation information.
[0097] Specifically, first determine the system operating information, which includes the number of ports, the number of open ports, the maximum number of connections, the average traffic, and the total number of services.
[0098] The operational vulnerability is then determined by multiplying the quotient (the number of ports divided by the number of open ports) with the sum of the maximum number of connections, average traffic, and the weights corresponding to each service. For ease of representation, each piece of information is replaced with a letter to obtain the operational vulnerability.
[0099]
[0100] N3 represents the total number of ports on the node device. The number of ports varies depending on the device type.
[0101] N1 represents the number of ports opened by the node device; the number of ports opened varies between different devices.
[0102] N4 represents the maximum number of connections. The maximum number of connections for each port changes dynamically over a period of time. The maximum number of connections is the peak value over a period of time. The maximum number of connections for each open port is also different within the same time period. Therefore, the maximum number of connections here is the maximum value of the number of connections for all open ports over a period of time.
[0103] N2 is the average flow rate over a period of time.
[0104] N5 represents the total number of services corresponding to this node, j is the service identifier, and W2j Let j be the weight corresponding to the j-th service. For example, if the total number of services is 20, then the value of j ranges from 1 to 20. In this case, the weights corresponding to these 20 services need to be summed.
[0105] S206. Determine the vulnerability of this node.
[0106] After determining the vulnerabilities of the above four parts, the vulnerability of the node can be determined by combining the vulnerabilities of each part: type vulnerability + vulnerability vulnerability + security impact * operational vulnerability.
[0107] The method for determining node vulnerability provided in this embodiment obtains device information and, based on this information, determines the node's vulnerability by considering four aspects: type vulnerability, vulnerability severity, security impact, and operational vulnerability. This allows for a more comprehensive and accurate calculation of node vulnerability, thereby ensuring the accuracy of network security predictions.
[0108] Figure 3 A flowchart illustrating a method for determining the impact value of an attack, as provided in this application, specifically includes the following steps:
[0109] S301. Determine the security level of each vulnerability in the vulnerability information of each node.
[0110] To determine the security level of a vulnerability, the first step is to obtain attack information about the device. This can be done by checking the logs of security software such as firewalls, which can identify the vulnerabilities involved in each attack. Then, based on the different vulnerabilities, vulnerability information can be obtained for each vulnerability. This vulnerability information can include details such as the vulnerability name, vulnerability number, and security severity level. In this step, it is only necessary to determine the security level of the vulnerability based on the vulnerability information.
[0111] S302. The quotient obtained by dividing the product of the actual impact value of the attack and the threat level value corresponding to the vulnerability at the highest security level is determined as the attack impact value for each node.
[0112] The actual impact of an attack is determined based on the real-world consequences of various attacks on an enterprise. Vulnerabilities come in different types, and their impact on the network varies. The actual impact does not necessarily correspond to the security level of a vulnerability. A high-security vulnerability may have a very low impact on the network due to appropriate security measures. Therefore, the actual impact of an attack needs to be determined based on the specific circumstances.
[0113] Different levels of vulnerabilities pose different degrees of threat to the network. Here, we only need to determine the threat level corresponding to the highest security level vulnerability. After multiplying the threat level values corresponding to all the highest security level vulnerabilities, we can divide the actual impact value by the result to obtain the attack impact value of each node.
[0114] The method for determining security impact value provided in this embodiment determines the security level of a vulnerability and calculates the product of the threat level corresponding to the highest security level vulnerability. The ratio of the actual attack impact value to the value of the product is used as the attack impact value of each node. Since the actual impact of different vulnerabilities on different enterprises is taken into account, the impact of the attack on each node can be determined more accurately, thereby making a more accurate prediction of the overall network security value.
[0115] This application provides an electronic device, including: a processor, and a memory communicatively connected to the processor.
[0116] This memory stores instructions that the computer executes.
[0117] The processor executes computer execution instructions stored in memory to implement the method as described in any one of claims 1-9.
[0118] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0119] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A network security early warning processing method, characterized in that, include: Obtain device information for each node in the network. The device information includes: device type, vulnerability information, device security level used to characterize the severity of the consequences after an attack, and system operation information. The system operation information includes the number of ports, the number of open ports, the maximum number of connections, average traffic, and the total number of services. Based on the device information, the vulnerability of each node in the network is determined; the vulnerability includes type vulnerability, vulnerability vulnerability, security impact, and operational vulnerability, used to indicate the degree to which the node is susceptible to attack; wherein, type vulnerability is determined according to the device type; vulnerability vulnerability is determined according to the vulnerability information; security impact is determined according to the device security level; and operational vulnerability is determined according to the system operation information. The operational vulnerability is the product of the ratio of the number of open ports to the total number of ports, the maximum number of connections, the average traffic, and the sum of the weights corresponding to each service. The vulnerability vulnerability is defined as follows: when the security level of each vulnerability in the vulnerability information is warning or attention, the vulnerability vulnerability is 1; when there are vulnerabilities in the vulnerability information with a security level of critical or important, the vulnerability vulnerability is determined based on the sum of the threat levels of each vulnerability with a security level of critical or important. The vulnerability of a node is the sum of the products of the type vulnerability, the vulnerability vulnerability, the security impact, and the operational vulnerability; Historical attack information of each node is obtained, and the attack impact value of each node is determined based on the vulnerability information and the historical attack information; the attack impact value is the quotient obtained by dividing the product of the actual attack impact value and the threat level value corresponding to the vulnerability with the highest security level. Determine the number of devices with communication associations at each node; The security prediction value of the network is determined based on the vulnerability of each node in the network, the attack impact value, and the number of devices with communication relationships; the security prediction value is the sum of the products of the vulnerability of each node, the attack impact value, and the number of devices. Network security early warning processing is carried out based on the security prediction values.
2. The method according to claim 1, characterized in that, Determining the type vulnerability based on the device type includes: Determine the device type of each node and obtain the correspondence between the device type and the type vulnerability; The type vulnerability of each node is determined based on the correspondence.
3. The method according to claim 1, characterized in that, Determining the security impact degree based on the equipment security level includes: Determine the security level of each node and obtain the correspondence between the security level and the security impact. The security impact of each node's security level is determined based on the aforementioned correspondence.
4. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-3.
Citation Information
Patent Citations
Quantitative calculation method and device for network security vulnerability assessment
CN113660227A