Banking threat modeling platform construction method, equipment and readable storage medium
By designing a banking threat modeling platform, generating questionnaires and analyzing risk scenarios, and retrieving security baselines for threat modeling, we solved the security testing challenges of banking software in an Internet environment, achieved automation and integration with project management platforms, and improved the efficiency and accuracy of security testing.
Patent Information
- Application Number
- CN202310797609.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-30
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-06-30
AI Technical Summary
Existing banking software is difficult to effectively conduct threat modeling in an Internet environment, making security testing difficult to ensure and lacking automation and integration with project management platforms.
Design a banking threat modeling platform that generates questionnaires by receiving project parameters, analyzes risk scenarios, retrieves security baselines from the security database, performs threat modeling, and generates assessment reports. It supports questionnaire editing and data analysis to implement an automated threat modeling process.
It improves the automation level of threat modeling, facilitates integration into existing project management platforms, improves the efficiency and accuracy of security testing, and forms a closed loop of design-implementation-verification.
Smart Images

Figure CN117077189B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer and information security technology, and in particular relates to a banking threat modeling platform construction method, equipment and readable storage medium. Background Art
[0002] With the continuous integration of the internet and the banking industry, the demand for banking software is becoming increasingly diverse, and delivery cycles are becoming increasingly tight. Furthermore, due to the highly open nature of the internet, any software deployed there is inevitably exposed to the risk of data leakage or unknown attacks. Once hackers exploit vulnerabilities to attack systems, they can cause significant financial losses. In this context, relying solely on pre-release security testing to ensure the security of banking software is often difficult.
[0003] Threat modeling is a structured method for analyzing application security, which can be used to identify, quantify and reduce application security risks. The design stage is an important stage for the overall design of the software system based on the results of the demand analysis. Compared with considering security requirements after the system is developed, completing the construction of the overall security plan in the design stage gives both developers and security personnel greater flexibility to eliminate security threats in advance, which helps to reduce the cost of development and subsequent maintenance. Potential threats are eliminated through security design, and security testing and verification are carried out in the testing phase to form a design-implementation-verification closed loop. In view of the above, the present application discloses a method for building a banking threat modeling platform, which can effectively improve the automation level of threat modeling and facilitate access to existing project management platforms. Summary of the Invention
[0004] The purpose of the present invention is to address the deficiencies of the existing technology and provide a banking threat modeling platform construction method, device and readable storage medium.
[0005] The purpose of the present invention is achieved through the following technical solutions:
[0006] According to a first aspect of this specification, a method for constructing a banking threat modeling platform is provided, comprising:
[0007] Receive the parameters of the project to be evaluated and generate a questionnaire;
[0008] Based on the questionnaire, analyze risk scenarios and extract functional templates; analyze potential system attack threats and retrieve relevant security baselines from the security database;
[0009] Perform threat modeling based on the current security baseline and return modeling results and modeling reports.
[0010] Furthermore, the security database of the threat modeling platform pre-stores a threat modeling requirement questionnaire template and the correspondence between the questionnaire function template and the security baseline, and can dynamically configure the correspondence between questionnaire questions => function template => risk operation => attack threat => security baseline.
[0011] Furthermore, a user's requirement security assessment request for the system version waiting for requirement clarification is received through the API gateway, and project parameter information is carried in the URL; the requirement security assessment request is transmitted to the threat modeling platform in HTTP Get mode, and the parameters are encrypted using the md5 algorithm.
[0012] Furthermore, the threat modeling platform includes a questionnaire generation module for generating a questionnaire task for project risk threat modeling based on the received project parameter information. The security questions in the questionnaire are divided into four categories: basic questions about the associated system, general security questions, scenario-based security questions, and security test estimation questions. Different versions of each project require new threat modeling.
[0013] The basic issues of the associated systems focus on whether the system applications are open to the Internet, which are divided into Internet systems and intranet systems. The selection of this issue is related to the risk baseline setting of this threat modeling.
[0014] The general security issues mentioned above condense the information security requirements in the banking field into question items;
[0015] The scenario-based security issues mentioned above classify the system according to the usage scenarios and users;
[0016] The security test pre-assessment questions are used to count the low-risk test points in the security test. If the results of the project questionnaire statistics only involve the options in these security test pre-assessment questions, the security test risk weight of the system will be reduced when the security test is conducted in the security test link.
[0017] Furthermore, the threat modeling platform includes a relationship retrieval module for obtaining the function templates checked in the questionnaire results, and obtaining the security baseline set corresponding to the current questionnaire based on the correspondence between the questionnaire function templates and the security baselines in the security database.
[0018] Furthermore, the threat modeling platform includes a threat modeling module for performing threat analysis and classification based on the threat modeling risk operations corresponding to the questionnaire results, comprehensively collecting all possible attack threats, matching the security baseline content corresponding to the current questionnaire results, and obtaining threat modeling results. Specifically, the following steps are included:
[0019] (1) Define the expected loss of the attack threat;
[0020] (2) Scan the questionnaire results and generate a threat modeling tree; the first-level node of the threat modeling tree represents the name of the modeling project, the second-level node represents the functional template involved in the project system selected by the user, the third-level node represents the risk operation involved in the functional template, the fourth-level node represents the attack threat faced by the requirement, and the fifth-level node represents the security baseline corresponding to the attack threat;
[0021] (3) Obtain the security baseline content corresponding to the attack threat, including: security baseline name, operational risk points, security requirements, security design recommendations, security test cases, threat types, and associated regulatory standards, and temporarily store them in memory;
[0022] (4) Merge the security baseline contents associated with the system;
[0023] (5) Define the path of the threat modeling tree as the set of nodes from the root node to the third-level node;
[0024] (6) Define the risk value of a risk operation as the sum of the expected losses of all attack threats associated with the risk operation;
[0025] (7) Traverse all paths of the threat modeling tree, calculate the risk values of all risk operations of the system, fill in the system risk quantification table and temporarily store it in memory.
[0026] Furthermore, the threat modeling platform integrates the security baseline content into an assessment report based on the threat modeling results, which specifically includes the following steps:
[0027] (1) Extract the "Security Requirements Assessment Report" template, "Security Design Report" template, and "Security Test Case" template from the security database, and fill in the first chapter of the template with the project parameter information, questionnaire check results, and the regulatory standards involved;
[0028] (2) Fill in the system risk quantification table in Chapter 2 of the template;
[0029] (3) Summarize the security baseline content and fill it into Chapter 3;
[0030] (4) The data transmission module calls the project management platform interface to automatically transmit the generated assessment report back, and the log module records the entire threat modeling process and stores it in the security log library.
[0031] Furthermore, the threat modeling platform includes a questionnaire editing module, which is used to add, delete, and modify the questionnaire questions and the functional templates of each question, as well as the functional templates, risk operations, and corresponding security baseline content associated with each question option. After submission, the questionnaire interface can be updated by restarting the service.
[0032] Furthermore, the threat modeling platform includes a data analysis module for scanning the questionnaire results in the security database, generating statistical analysis charts, and recording the user's supplementary answers to each question. Specifically, the following steps are included:
[0033] (1) The backend records the project parameter information for threat modeling implementation, generates a histogram of the number of projects in each development department, a statistical line chart of the number of threat modeling projects, a pie chart of internal and external network statistics, and a line chart of the distribution of questionnaire generation time, so that security managers can intuitively understand the status of threat modeling questionnaire generation;
[0034] (2) The background records the supplementary answers to each questionnaire question and counts the number of times the answers appear. Security managers regularly adjust the questionnaire question options based on the content of the supplementary answers.
[0035] Furthermore, the threat modeling platform includes a security verification module for verifying the threat modeling results in the security testing phase to achieve a closed loop of demand security management and control, which specifically includes the following steps:
[0036] (1) Pull the security test function template data submitted by the project team on the test process control platform, referred to as submitted test data;
[0037] (2) Compare the questionnaire results with the test data;
[0038] (3) Calculate the metric indexes X, Y, and Z of the development department modeling results:
[0039] (3.1) Calculate the result matching degree X, which is used to measure the coverage of the questionnaire content on the actual test system function points, and to show the matching degree between the questionnaire results and the test function template submitted by the project manager;
[0040] (3.2) Calculate the result matching degree Y, which is used to measure the effectiveness of the questionnaire content check function template in the actual test, and show the degree of matching between the function template used by the actual tester and the questionnaire results;
[0041] (3.3) Calculate the safety design realization degree Z, which shows the implementation of the "Safety Design Report" by the project team during the coding process;
[0042] (4) Obtain the parameter information corresponding to the project, combine the measurement indexes X, Y, and Z to give the security assessment performance of this project version and store it in the security database; if the performance value is lower than the threshold, it is considered that the project team did not conduct threat modeling based on the actual situation of the project during the requirements phase, or did not pay attention to the contents of the "Security Design Report" in the subsequent development process.
[0043] According to a second aspect of this specification, a banking threat modeling platform construction device is provided, comprising: a memory, a processor, and a computer program; wherein the computer program is stored in the memory and is configured to be executed by the processor to implement the method described in the first aspect.
[0044] According to a third aspect of this specification, a computer-readable storage medium is provided, storing a computer program, wherein when the computer program is executed by a processor, the method described in the first aspect is implemented.
[0045] The beneficial effects of the present invention are: the present invention designs a banking threat modeling platform construction method, which is based on platform construction and can effectively improve the automation level of threat modeling, while facilitating access to existing project management platforms. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 This is an overall flow chart of a banking threat modeling platform construction method provided by an exemplary embodiment of the present application;
[0047] Figure 2 is an architectural diagram of a threat modeling platform provided by an exemplary embodiment of the present application;
[0048] Figure 3 This is a schematic diagram of a banking project management process provided by an exemplary embodiment of the present application;
[0049] Figure 4 This is a tree diagram of threat modeling provided by an exemplary embodiment of the present application;
[0050] Figure 5 This is a flowchart of the specific steps of a method for building a banking threat modeling platform provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0051] In order to better understand the technical solution of the present application, the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0052] It should be clear that the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0053] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. The singular forms "a", "an", "the" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise.
[0054] like Figure 1 FIG. 1 is a flowchart of a method for constructing a banking threat modeling platform according to an embodiment of the present invention, comprising the following steps:
[0055] S10, receiving the parameters of the project to be evaluated and generating a questionnaire;
[0056] S20: Based on the questionnaire, analyze risk scenarios and extract functional templates; analyze potential system attack threats and retrieve relevant security baselines from the security database;
[0057] S30: Perform threat modeling based on the current security baseline and send back the modeling results and modeling report.
[0058] Specifically, Figure 2 This is the architecture diagram of the threat modeling platform. Figure 5 The following is a flowchart of the specific steps of the banking threat modeling platform construction method. Figure 2 and Figure 5 Describe in detail the specific implementation process of this application.
[0059] S100, Figure 2 The API gateway shown in the figure receives a user's request for a security assessment of a system version awaiting clarification. The URL carries parameters such as the project number, version number, project name, project manager's name, expected production version, and operator ID. The security assessment request is transmitted to the threat modeling platform via HTTP GET. The parameters are securely encrypted using the MD5 algorithm to effectively prevent tampering during the process.
[0060] S200, a threat modeling requirements questionnaire template for the banking industry is pre-stored in the security database. Figure 2 The questionnaire generation module shown in the figure combines the parameter information obtained in step S100 to generate a questionnaire task for risk threat modeling of the project, and displays the project parameter information on the questionnaire homepage. The security questions in the questionnaire are divided into four categories: basic questions about the associated system, general security questions, scenario-based security questions, and security test estimation questions. Different versions of each project require new threat modeling. Specifically:
[0061] S201, basic issues related to the system, focuses on whether the system application is open to the Internet. It is divided into Internet system and Intranet system. The selection of this issue is related to the risk baseline setting of this threat modeling.
[0062] S202, general security issues, condenses information security requirements in the banking industry, such as regulatory requirements and industry compliance requirements, into question items, such as whether the current production version involves the addition or modification of functions such as login, registration, upload, and download, and whether third-party components are used.
[0063] S203, scenario-based security issues, classify the system according to usage scenarios and users, such as financial business scenarios (whether it involves the addition or modification of functions such as refunds, loans, and investment and financial management), online banking business scenarios (whether it involves the addition or modification of functions such as account opening, binding, reporting loss, and certificates), etc.
[0064] S204, security test pre-assessment questions, statistics of some low-risk test points in security testing, such as whether the current production version involves terminal hardware modification, counter system optimization, browser compatibility modification, etc. If the results of the project questionnaire statistics only involve the options in these security test pre-assessment questions, it means that the security risk of this project's change and production is relatively low, then Figure 3 When security testing is performed in the security testing link shown, the security testing risk weight of the system will be reduced, manual security testing will no longer be performed, and testing efficiency will be improved.
[0065] S300, after obtaining the questionnaire results, Figure 2 The relationship retrieval module shown in the figure exports a questionnaire result, obtains the selected function template, and then obtains the security baseline set corresponding to the current questionnaire based on the correspondence between the questionnaire function template and the security baseline. The correspondence between the questionnaire function template and the security baseline is pre-built in the security database as part of the platform functionality.
[0066] Specifically, the functional template of each questionnaire question is associated with one or more risk operations, and each risk operation is associated with one or more attack threats. The background obtains its unique corresponding security baseline through the attack threats.
[0067] The security baseline content includes the above-mentioned correspondence and the associated data of this attack threat. The associated data includes the security baseline name, operational risk points, security requirements, security design recommendations, security test cases, threat types, and associated regulatory standards.
[0068] Specifically, the security database is pre-configured with the above correspondence of “questionnaire question => function template => risk operation => attack threat => security baseline”, and can be dynamically configured.
[0069] S400, Figure 2 The threat modeling module shown in FIG performs threat modeling risk operations based on the questionnaire results, performs threat analysis and classification based on the STRIDE model, comprehensively collects all possible attack threats, and matches the security baseline content corresponding to the current questionnaire results. Specifically, step S400 includes:
[0070] S401, defining the expected loss L of the attack threat described in step S300:
[0071]
[0072] Among them, F represents the impact factor after the attack threat is quantified. This represents the mean probability of the attack threat occurring. Specifically, a probabilistic impact method is used to quantitatively analyze attack threats. The impact factor parameter is a predefined value for the attack threat, representing an internal asset of the organization. The probability parameter is a fixed-value vulnerability probability score derived from the CNVD database, combining parameters such as attack vector, attack path, confidentiality, and availability. This value is directly obtained and calculated when the questionnaire generates the report, and is maintained daily by security personnel.
[0073] S402, scanning the questionnaire results and generating a threat modeling tree.
[0074] Figure 4 The following diagram shows a threat modeling tree. For example, consider a scenario where a user selects a change in the new version involving login functionality. The first-level nodes represent the name of the modeling project; the second-level nodes represent the functional templates selected by the user for this project system, including login; the third-level nodes represent the risky operations associated with these functional templates, such as login requirements involving SMS verification codes and user input; the fourth-level nodes represent the attack threats faced by these requirements, such as potential attack threats such as SMS verification code requirements involving arbitrary phone number registration and SMS bombing; and the fifth-level nodes represent the security baselines corresponding to these attack threats.
[0075] S403: Obtain security baseline content corresponding to the attack threat.
[0076] Taking the login function as an example, the contents associated with a security baseline include: security baseline name (client passwords should not be displayed in plain text), operational risk points (information leakage risk), security requirements (client application software should not display bank card passwords and online payment transaction passwords in plain text), security design recommendations (when entering authentication information such as account login passwords, bank card payment passwords, and online payment transaction passwords, the client application software should use methods such as replacing the original text in the input box, character-by-character encryption, character encryption, keyboard eavesdropping prevention, customizing the soft keyboard, or other methods to ensure that attack tests cannot obtain the plain text of the input information as a passing standard), security test cases (entering bank card passwords or online payment transaction passwords through the client application software to check whether the client displays the plain text), threat type (identity authentication security - personal financial information), and associated regulatory standards ("Mobile Financial Client Application Software Security Management Specifications"). These are temporarily stored in memory.
[0077] S404: Merge the security baseline contents associated with the system and import them into the threat modeling module.
[0078] S405, Definition Figure 4 The path R of the threat modeling tree shown is a set of nodes from the root node to the third-level nodes.
[0079] S406: Define the risk value W(R) of the risk operation as the sum of the expected losses of all attack threats associated with the risk operation:
[0080]
[0081] Among them, n represents the total number of attack threats corresponding to a risk operation node, L i The expected loss of the attack threat calculated in step 401.
[0082] S407: traverse all paths of the threat modeling tree, calculate the risk values of all risk operations of the system, fill in the system risk quantification table shown in Table 1, and temporarily store it in the memory.
[0083] Table 1 System risk quantification table provided by an exemplary embodiment of the present application
[0084]
[0085] S500: Based on the modeling results of the above steps, the security baseline content is automatically integrated to form an assessment report. Specifically, step S500 includes:
[0086] S501: Extract the "Security Requirements Assessment Report" template, "Security Design Report" template, and "Security Test Case" template from the security database, and fill in the first chapter of the template with the parameter information described in step S100, the selected results of the questionnaire, and the relevant regulatory standards;
[0087] S502, filling the system risk quantification table described in step S407 into Chapter 2 of the template;
[0088] S503, extract the security baseline content described in step S403, summarize it and fill it into Chapter 3.
[0089] S600, based on the evaluation report generated in step S500, Figure 2 The data transmission module shown in calls the project management platform interface to automatically return the evaluation report.
[0090] Specifically, the log module records the entire threat modeling process and stores it in the security log library.
[0091] S700, the threat modeling platform described in this application also includes Figure 2 In the questionnaire editing module shown in the figure, you can add, delete, and modify the questionnaire questions and the function templates of each question in the background. You can also configure the function templates, risk operations, and corresponding security baseline content associated with each question option. After submission, restart the service to update the questionnaire interface.
[0092] S800, the threat modeling platform described in this application also includes Figure 2The data analysis module shown in the figure has two major functions: first, scanning the questionnaire results in the security database and generating statistical analysis charts; second, recording the user's supplementary answers to each question; specifically:
[0093] S801, the background records the parameter information of the projects implementing threat modeling, generates a histogram of the number of projects in each development department, a statistical line chart of the number of threat modeling projects, a pie chart of internal and external network statistics, a line chart of the distribution of questionnaire generation time, etc., so that security management personnel can intuitively understand the threat modeling questionnaire generation status.
[0094] S802: The background records the supplementary answers to each questionnaire question and counts the number of occurrences of the answers. The security management personnel regularly adjust the questionnaire question options based on the content of the supplementary answers.
[0095] S900, in Figure 3 In the safety test phase shown, Figure 2 The security verification module of the platform shown verifies the threat modeling results.
[0096] Specifically, Figure 2 The log module shown in the figure scans and stores the results of each questionnaire, generates a "creation time" parameter for each questionnaire, and obtains the project status and version launch time from the test process control platform. Before the project version is launched, a security test application is submitted to the test process control platform and the function template selected in the questionnaire results is reused.
[0097] Verify threat modeling results through the following steps to achieve a closed-loop demand security management and control:
[0098] Step a: Pull the security test function template data submitted by the project team on the test process management platform, referred to as submitted test data;
[0099] Step b: Compare the questionnaire results with the test data;
[0100] Step c: Calculate the metric indexes X, Y, and Z of the development department modeling results:
[0101] Step c.1: Calculate the result matching degree X, 0<X≤1, to measure the coverage of the questionnaire content on the actual test system function points, and to show the degree of match between the questionnaire results and the test function template submitted by the project manager. The formula is as follows:
[0102]
[0103] The parameters p and q represent the number of function templates that have been checked in the questionnaire results corresponding to the current project version and the number of function templates actually submitted by the project manager in the security testing phase, respectively.
[0104] Step c.2: Calculate the result matching degree Y, 0<Y≤1, to measure the effectiveness of the questionnaire content check function template in the actual test, and to show the degree of match between the function template used by the actual tester and the questionnaire results. The formula is as follows:
[0105]
[0106] The parameters r and s represent the number of functional templates actually used by the tester in the security testing phase and the number of functional templates checked in the questionnaire corresponding to the project, respectively;
[0107] Step c.2: Calculate the safety design implementation degree Z, 0<Z≤1, which reflects the implementation of the "Safety Design Report" by the project team during the coding process; the formula is as follows:
[0108]
[0109] Among them, the parameter n i ,φ i ,η i Respectively indicate the current project version Figure 3 The number of vulnerabilities of type i detected in the security test phase, the vulnerability level, and the corresponding risk value of this vulnerability are shown in the figure. k is the number of vulnerability types detected, and m is the total number of risky operations. The vulnerability level and vulnerability risk value are derived from the vulnerability list of the internal system maintenance component. They are predefined values and belong to the internal assets of the organization. W(R) j The risk value of the j-th risk operation in the questionnaire results under the current project version calculated in step S406;
[0110] Step d: Obtain the parameter information corresponding to the project, combine the measurement indexes X, Y, and Z to calculate the security assessment performance sum of this project version and store it in the security database; the formula is as follows:
[0111] sum=αX+βY+γZ
[0112] Among them, α, β, and γ are weight coefficients preset according to the project implementation safety criteria.
[0113] If the sum value is lower than the threshold, it is considered that the project team did not conduct threat modeling based on the actual project situation during the requirements phase, or did not pay attention to the contents of the "Security Design Report" during the subsequent development process. Points will be deducted as appropriate in the year-end evaluation.
[0114] In one embodiment, a banking threat modeling platform construction device is proposed, including a memory, a processor, and a computer program; wherein the computer program is stored in the memory and is configured to be executed by the processor to implement the above-mentioned banking threat modeling platform construction method.
[0115] In one embodiment, a storage medium storing computer-readable instructions is provided. When executed by one or more processors, the computer-readable instructions cause the one or more processors to perform the steps of the method for building a banking threat modeling platform described in each of the above embodiments. The storage medium may be a non-volatile storage medium.
[0116] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0117] The above description is merely a preferred embodiment of one or more embodiments of this specification and is not intended to limit one or more embodiments of this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of this specification shall be included in the scope of protection of one or more embodiments of this specification.
Claims
1. A banking threat modeling platform construction method, characterized by: It includes: Receiving the parameters of the project to be evaluated and generating a questionnaire; Analyzing risk scenarios based on the questionnaire content and refining function templates; Analyzing potential attack threats to the system and retrieving associated security baselines in the security database; Performing threat modeling based on the current security baseline and sending back the modeling results and modeling reports; The threat modeling platform includes a threat modeling module, which is used to perform threat analysis and classification based on the threat modeling risk operations corresponding to the questionnaire results, comprehensively collect all possible attack threats, match the security baseline content corresponding to the current questionnaire results, obtain the threat modeling results, and verify the implementation of the report. Specifically, it includes the following steps: (1) Defining the expected loss of attack threats; (2) Scanning the questionnaire results and generating a threat modeling tree; the first-layer nodes of the threat modeling tree represent the name of the modeling project this time, the second-layer nodes represent the function templates involved in the system selected by the user for this project, the third-layer nodes represent the risk operations involved in the function templates, the fourth-layer nodes represent the attack threats faced by the requirements, and the fifth-layer nodes represent the security baselines corresponding to the attack threats; (3) Obtaining the security baseline content corresponding to the attack threats, including: security baseline name, operation risk points, security requirement content, security design suggestions, security test cases, threat types, associated regulatory standards, and temporarily storing them in memory; (4) Merging the security baseline content associated with the system; (5) Defining the path of the threat modeling tree as the node set from the root node to the third-layer nodes; (6) Defining the risk value of a risk operation as the accumulation of the expected losses of all attack threats associated with the risk operation; (7) Traversing all paths of the threat modeling tree, calculating the risk values of all risk operations of the system, filling them into the system risk quantification table and temporarily storing them in memory; (8) Using the security verification module to verify the threat modeling results in the security test link to achieve a closed-loop of demand security control. Specifically, it includes the following steps: (8.1) Pulling the security test function template data submitted by the project team on the test process control platform, simply referred to as the data submitted for testing; (8.2) Comparing the questionnaire results and the data submitted for testing; (8.3) Calculating the modeling result measurement indices X, Y, Z of the development department: (8.3.1) Calculating the result matching degree X, 0 < X ≤ 1, which is used to measure the coverage of the questionnaire content for the actual test system function points, and represents the matching degree between the questionnaire results and the test function templates submitted by the project manager; the formula is as follows: Among them, the parameters p and q respectively represent the number of function templates that have been selected in the questionnaire results corresponding to the current project version that conform to the actual test function templates, and the number of function templates actually submitted by the project manager in the security test link; (8.3.2) Calculating the result matching degree Y, 0 < Y ≤ 1, which is used to measure the effectiveness of the function templates selected in the questionnaire content in the actual test, and represents the matching degree between the function templates actually used by the actual testers and the questionnaire results; the formula is as follows: Among them, the parameters r and s respectively represent the number of function templates actually used by the testers in the security test link and the number of function templates selected in the questionnaire corresponding to this project; (8.3.3) Calculate the implementation degree Z of security design, where 0 < Z ≤ 1, which represents the implementation of the "Security Design Report" by the project team during the coding process; the formula is as follows: Among them, the parameter n i ,φ i ,η i They represent the number of vulnerabilities of type i detected in the security testing phase of the current project version, the vulnerability level, and the corresponding risk value of this type of vulnerability, k is the number of detected vulnerability types, and m is the total number of risky operations; the vulnerability level and vulnerability risk value are derived from the vulnerability list of the internal system maintenance component, which are predefined values and belong to the internal assets of the organization; W(R) j The risk value of the j-th risk operation in the questionnaire results under the current project version; (8.4) Obtain the parameter information corresponding to the project, and give the security assessment performance sum of this project version in combination with the measurement indices X, Y, and Z, and store it in the security database; the formula is as follows: sum = αX + βY + γZ Where, α, β, and γ are weight coefficients preset according to the project implementation security criteria; If the performance value sum is lower than the threshold, it is considered that the project team did not conduct threat modeling in combination with the actual situation of the project during the requirements phase, or did not attach importance to the content in the "Security Design Report" during the subsequent development process.
2. The banking threat modeling platform construction method according to claim 1 is characterized in that: The security database of the threat modeling platform预先 stores the threat modeling requirements questionnaire template, as well as the corresponding relationship between the questionnaire function template and the security baseline, and dynamically configures the corresponding relationship of questionnaire questions => function template => risk operation => attack threat => security baseline.
3. The banking threat modeling platform construction method according to claim 1 is characterized in that: Receive the security assessment request for the system version waiting for requirements clarification from the user through the API gateway, and carry the project parameter information in the URL; The security assessment request is transferred to the threat modeling platform in the form of an HTTP Get, and the parameters are encrypted by the md5 algorithm.
4. The banking threat modeling platform construction method according to claim 1, characterized in that: The threat modeling platform includes a questionnaire generation module, which is used to generate a questionnaire task for project risk threat modeling in combination with the received project parameter information. The security question items of the questionnaire are divided into four types: basic questions about associated systems, general security questions, scenario-based security questions, and security test pre-assessment questions. Different versions of each project need to conduct threat modeling again; The basic questions about associated systems focus on whether the system application is open to the Internet, and are divided into Internet systems and intranet systems. The selection of this question is related to the risk benchmark setting of this threat modeling; The general security questions condense the information security requirements in the banking industry into question items; The scenario-based security questions classify the system according to the usage scenario and users; The security test pre-assessment questions count the low-risk test points in the security test. If the statistical results of the project questionnaire only involve the option content of these security test pre-assessment questions, the security test risk weight of the system is reduced during the security test in the security test link.
5. The banking threat modeling platform construction method according to claim 1 is characterized in that: The threat modeling platform includes a relationship retrieval module, which is used to obtain the function template checked in the questionnaire result, and obtain the set of security baselines corresponding to the current questionnaire according to the corresponding relationship between the questionnaire function template and the security baseline in the security database.
6. The banking threat modeling platform construction method according to claim 1, characterized in that: The threat modeling platform integrates the security baseline content based on the threat modeling result to form an assessment report, which specifically includes the following steps: (1) Extract the "Security Requirements Assessment Report" template, "Security Design Report" template, and "Security Test Cases" template from the security database, and fill in the project parameter information, questionnaire check results, and the involved regulatory standards in the first chapter of the template; (2) Fill in the system risk quantification table in the second chapter of the template; (3) Summarize the security baseline content and fill it in the third chapter; (4) The data transmission module calls the project management platform interface to automatically transmit the generated assessment report back, and the log module records the entire threat modeling process and stores it in the security log library.
7. A banking threat modeling platform construction device, characterized in that: include: A memory, a processor, and a computer program; wherein the computer program is stored in the memory and configured to be executed by the processor to implement the method according to any one of claims 1 to 6.
8. A computer-readable storage medium, characterized in that A computer program is stored, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Threat modeling demand establishment method and device
CN113885837A
Threat modeling method and device
CN114626069A