A zero-trust access control system based on network security posture assessment

The zero-trust access control system, which assesses network security situation, dynamically adjusts user access permissions, addressing the shortcomings of traditional network security models in complex network environments. It achieves quantitative assessment and dynamic adjustment of user permissions, balancing resource protection and normal access.

CN118138295BActive Publication Date: 2025-12-16CHINESE PEOPLES LIBERATION ARMY UNIT 91977 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410222238.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-28
Publication Date
2025-12-16
Estimated Expiration
2044-02-28

AI Technical Summary

Technical Problem

Traditional 'boundary'-based cybersecurity models struggle to effectively address threats in complex network environments, and existing zero-trust security systems lack clear methods for assessing cybersecurity posture, resulting in limited user access permission settings and impacting normal use.

Method used

A zero-trust access control system based on network security situation assessment is adopted. Through user terminals, network security database, situation assessment module, access permission decision center and execution point, identity authentication and continuous assessment are carried out, and user access permissions are dynamically adjusted, including blocking, allowing, continuing assessment and other permissions between allowing and blocking.

Benefits of technology

It enables dynamic adjustment of user access permissions based on binary decision results, protecting resources from attacks while ensuring normal user access, and provides a decision-making basis for network security situation assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118138295B_ABST
    Figure CN118138295B_ABST
Patent Text Reader

Abstract

The application discloses a kind of zero trust access control system and method based on network security posture assessment, the method includes using the user terminal to the user is authenticated, obtains identity authentication information, and the identity authentication information is sent to network security database and is stored;With access permission decision center, according to the resource access application of user terminal, security posture assessment instruction is sent to network security posture assessment module;With network security posture assessment module, according to the security posture assessment instruction, the security assessment of current network is carried out, and security assessment information is obtained;With access permission decision center, according to the security assessment information, the access permission of user is determined, and the access permission of user is sent to access permission controller and network security posture assessment module;With access permission execution point, under the control of access permission controller, according to the access permission of user, user access control is carried out.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a zero-trust access control system and method based on network security posture assessment. BACKGROUND

[0002] With the continuous development of cloud technology, mobile Internet, big data and other technologies, the network structure is becoming increasingly complex, and user terminals access through wireless public networks, making the originally clear network boundary gradually blurred. The protection of the system network has been extended to the user terminal. At the same time, the attack means for the network is also constantly upgrading and changing, so that the traditional network security model based on "border" can no longer effectively cope with the threat.

[0003] The traditional network security model based on "border" divides the network into trusted and untrusted areas according to the location of the network, and uses gateways and other means to form a network boundary and isolate the network. Users in the trusted area access resources in the trusted area network, and must pass security checks and be granted access rights under certain rules, and use VPN to access remotely. For the case of small network size and small user quantity, this network security model has good performance. However, with the continuous expansion of network size and the increasing complexity of network structure, the number of users has increased dramatically, and the network boundary has become blurred, making the traditional network security model based on "border" no longer applicable.

[0004] In view of the current blurred network boundary, a zero-trust security model is proposed and has become a new generation of security technology system. The protection object of the zero-trust security model is no longer the security boundary of the network, but every resource being accessed, and its basic idea is "never trust, continuously verify". In the zero-trust security model system, network location no longer determines access rights, and all access subjects need to pass identity authentication and authorization before access is allowed. The system realizes identity and access management of access entities through enhanced authentication and dynamic trust evaluation, and ensures the legitimacy of entity identity.

[0005] However, at present, the network security system based on the zero-trust security model mostly adopts a binary decision result form, i.e. allowing access or blocking access. Since the scope of this permission setting is small, it will affect the normal use of users to some extent. In addition, most of the current research and invention lack a specific and explicit evaluation method to quantify network security risks or trust in users, which is an important basis for determining user access rights. SUMMARY

[0006] The technical problem to be solved by the present application is to provide a zero-trust access control system and method based on network security posture assessment to cope with the problem of small dynamic setting range of access permission caused by binary decision results, and to quantify the network environment and the security situation of the user for the determination of user access permission, based on the assessment of the network security posture, to determine the access permission of the user to the resource, including the allowed access, blocked access under the binary decision result framework, and the newly added permission or action between the allowed and blocked, such as continuous evaluation, read-only access, allowed access and recording, etc.

[0007] To solve the above technical problems, the first aspect of the embodiment of the present application discloses a zero-trust access control system based on network security posture assessment, the system comprising a user terminal, a network security database, a network security posture assessment module, an access permission decision center, an access permission manager, and an access permission execution point.

[0008] The user terminal is data-connected with the network security database and the access permission decision center, and is used for authenticating the user and sending the authentication result to the network security database for storage.

[0009] The access permission decision center is data-connected with the network security posture assessment module and the access permission controller, and is used for receiving the access application of the user terminal and sending a security posture assessment instruction to the network security posture assessment module.

[0010] The network security posture assessment module is data-connected with the network security database, and is used for reading the related data in the network security database, analyzing and quantifying the security access situation under the current network environment, and obtaining security assessment information.

[0011] The access permission decision center is data-connected with the access permission controller, and is used for determining the access permission of the user to the resource according to the security assessment information, and uploading the access permission of the user to the resource to the network security database.

[0012] The access permission controller is data-connected with the access permission execution point, and is used for controlling the access permission execution point.

[0013] The access permission execution point is used for connecting the data transmission between the user and the resource or blocking the access of the user to the resource according to the access permission of the user to the resource, and uploading the user access situation to the network security database.

[0014] As an optional implementation, in the first aspect of the embodiment of the present application, the network security database comprises user identity management data, user behavior log data, user access record data, user access permission decision result data, system activity log data, system vulnerability and patch management data, terminal detection and response data, and intrusion detection data;

[0015] The network security database is configured to provide input data for the network security posture assessment module, save records of identity authentication from user terminals, and receive and record results of the access permission decision center and user access conditions uploaded by the access permission execution point in real time.

[0016] As an optional implementation, in the first aspect of the embodiment of the present application, the network security posture assessment module comprises a network security data auditing unit and a security posture assessment unit.

[0017] The network security data auditing unit is connected with the network security database, configured to collect relevant security data in the network security database, identify the security state of the current network, and detect existing or potential network security threats.

[0018] The security posture assessment unit is connected with the network security data auditing unit, configured to determine the network security posture condition information from multiple sources according to the detection results of the network security data auditing unit, obtain security assessment information, and provide the information to the access permission decision center.

[0019] For the user who has completed identity authentication, the network security posture assessment module continuously assesses the user periodically, so that the access permission decision center adjusts the access permission of the user in time.

[0020] As an optional implementation, in the first aspect of the embodiment of the present application, the access permission decision center is configured to periodically and continuously receive the security assessment information provided by the network security posture assessment module according to the resource access request of the user terminal, and determine or adjust the access permission of the user to the resource by using a predefined security access strategy.

[0021] The access permission of the user to the resource comprises blocking access, allowing access, continuing access, allowing and recording, allowing and reviewing, allowing and isolating, and allowing and limiting.

[0022] The access permission decision center uploads its decision results to the network security database in real time for saving, so as to adjust the access permission of the user who has completed identity authentication in time.

[0023] As an optional implementation, in the first aspect of the embodiment of the present application, the access permission execution point is blocked between the user and the resource, and the user can access the resource with specified permission only when the user is authenticated and granted the access permission;

[0024] In the process of user accessing the resource, the access permission execution point transmits data through various communication protocols, and uploads and records the access content and access time of the user to the network security database, and the transmission of the data is protected by using national secret SSL.

[0025] The second aspect of the embodiment of the present application discloses a zero-trust access control method based on network security situation assessment, and the method comprises the following steps:

[0026] S1, using the user terminal, responding to the resource access application of the user, performing identity authentication on the user to obtain identity authentication information, and sending the identity authentication information to the network security database for storage;

[0027] S2, using the access permission decision center, sending a security situation assessment instruction to the network security situation assessment module according to the access application of the user terminal;

[0028] S3, using the network security situation assessment module, performing security assessment on the current network according to the security situation assessment instruction to obtain security assessment information;

[0029] S4, using the access permission decision center, determining the access permission of the user according to the security assessment information, and sending the access permission of the user to the access permission controller and the network security situation assessment module;

[0030] S5, the access permission execution point, under the control of the access permission controller, performs user access control according to the access permission of the user; the access control comprises data transmission between the user and the resource or blocking the user access.

[0031] As an optional implementation, in the second aspect of the embodiment of the present application, the network security situation assessment module is used to perform security assessment on the current network according to the security situation assessment instruction to obtain security assessment information, which comprises the following steps:

[0032] S31, using the network security data auditing unit, collecting security data from the network security database; the security data comprises user information, terminal information and network environment information;

[0033] S32, performing index decomposition on the security data to obtain a network security index system;

[0034] S33, processing the network security index system by using a preset quantitative evaluation model of the network security index to obtain security evaluation information.

[0035] As an optional implementation, in the second aspect of the embodiment of the present application, the network security index system comprises a first-level index, a second-level index and a third-level index.

[0036] The first-level index comprises a user behavior risk, a terminal system risk and a network environment risk.

[0037] The second-level index comprises a multi-person surrounding behavior, a rule violation access behavior, a disabled security mode, a screenshot monitoring, a screen recording monitoring, a vulnerability check list, a patch check list, a configuration check list, an IDS alarm and an EDR alarm.

[0038] The third-level index comprises a surrounding risk score, a rule violation access score, a disabled security score, a screenshot score, a screen recording score, a vulnerability risk score, a patch risk score, a configuration risk score, an alarm level score and an EDR score.

[0039] As an optional implementation, in the second aspect of the embodiment of the present application, the processing of the network security index system by using a preset quantitative evaluation model of the network security index to obtain security evaluation information comprises:

[0040] S331, processing the surrounding risk score, the rule violation access score, the disabled security score, the screenshot score and the screen recording score to obtain a user behavior risk overall score.

[0041] S332, processing the vulnerability risk score, the patch risk score and the configuration risk score to obtain a user terminal system overall risk score.

[0042] S333, processing the alarm level score and the EDR score to obtain a network environment risk overall score.

[0043] S334, processing the user behavior risk overall score, the user terminal system overall risk score and the network environment risk overall score to obtain security evaluation information.

[0044] As an optional implementation, in the second aspect of the embodiment of the present application, the processing of the vulnerability risk score, the patch risk score and the configuration risk score to obtain a user terminal system overall risk score comprises:

[0045] S3321, processing the vulnerability risk score by using a vulnerability risk evaluation model to obtain a system vulnerability overall risk score.

[0046] The vulnerability risk assessment model is:

[0047]

[0048] S3322, processing the patch risk score by using the patch risk assessment model to obtain a system patch management overall risk score;

[0049] The patch risk assessment model is:

[0050]

[0051] S3323, processing the configuration risk score by using the configuration risk assessment model to obtain a system security configuration overall risk score;

[0052] The configuration risk assessment model is:

[0053]

[0054] S3324, processing the system vulnerability overall risk score, the system patch management overall risk score and the system security configuration overall risk score by using a user terminal system overall risk score model to obtain a user terminal system overall risk score;

[0055] The user terminal system overall risk score model is:

[0056] R T = ω v × risk v + ω p × risk p + ω c × risk c

[0057] In the formula, R T is the user terminal system overall risk score, risk v is the system vulnerability overall risk score, risk p is the system patch management overall risk score, risk c is the system security configuration overall risk score, v(i) is the check result of the i-th to-be-checked vulnerability item in the preset vulnerability check list, including the existence or non-existence of the vulnerability, p(j) is the installation situation of the j-th patch in the preset patch management list, including whether the patch has been installed according to the requirement or not, c(k) is the security configuration situation of the k-th item in the preset security configuration list, including whether the configuration is compliant or not, ω v is the weight of the system vulnerability overall risk score, ω p is the weight of the system patch management overall risk score, and ωc weight of the overall risk score of system security, ω v + ω p + ω c = 1.

[0058] Compared with the prior art, the embodiment of the application has the following beneficial effects:

[0059] The application provides a zero-trust access control system and method based on network security posture assessment, which increases access permissions between allowed access and blocked access on the basis of binary decision result forms, and uses a network security posture assessment method to provide decision basis for user permission determination, periodically and continuously monitors the authenticated user, and evaluates the risk of user access or the trust level of the user, so as to timely and dynamically adjust the access permission of the user to the resource. Based on this, the resource is protected from attack, and the normal access of the user to the resource is also taken into account. BRIEF DESCRIPTION OF DRAWINGS

[0060] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.

[0061] Figure 1 is a structural schematic diagram of a zero-trust access control system based on network security posture assessment disclosed by the embodiment of the application;

[0062] Figure 2 is a flowchart of a zero-trust access control method based on network security posture assessment disclosed by the embodiment of the application;

[0063] Figure 3 is a flowchart of another zero-trust access control method based on network security posture assessment disclosed by the embodiment of the application. DETAILED DESCRIPTION

[0064] In order to enable those skilled in the art to better understand the application scheme, the technical solutions in the embodiments of the application will be described clearly and completely in conjunction with the drawings of the embodiments of the application. Obviously, the described embodiments are only some of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the application.

[0065] The terms "first", "second", and the like in the description and in the claims of the present application and in the above-described drawings mean for distinguishing different objects, not for describing a particular sequential order. Furthermore, the terms "comprises", "comprising", "has", "having", "includes", "including", and the like are to be construed open- ended, allowing for instances where there are equivalents. For example, a process, method, article, or apparatus that comprises, has, includes or the like a list of steps or elements is not necessarily limited to only those particular steps or elements but can include other not listed steps or elements, and vice versa.

[0066] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in an embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive of one another. It is expressly understood that any of the embodiments described herein can be incorporated in to other embodiments.

[0067] The application discloses a zero-trust access control system and method based on network security posture assessment, and the method comprises the following steps: authenticating a user by using a user terminal to obtain identity authentication information, and sending the identity authentication information to a network security database for storage; sending a security posture assessment instruction to a network security posture assessment module according to a resource access application of the user terminal by using an access permission decision center; performing security assessment on the current network according to the security posture assessment instruction by using the network security posture assessment module to obtain security assessment information; determining the access permission of the user according to the security assessment information by using the access permission decision center, and sending the access permission of the user to an access permission controller and the network security posture assessment module; and performing user access control according to the access permission of the user under the control of the access permission controller by using an access permission execution point. The following will be described in detail.

[0068] Embodiment one

[0069] Please refer to Figure 1 , Figure 1 is a structural schematic diagram of a zero-trust access control system based on network security posture assessment disclosed by the embodiment of the application. Wherein, Figure 1 The zero-trust access control system based on network security posture assessment described in the embodiment of the application is applied to the field of network security, and the access permission of a user to a resource is determined based on the assessment of the network security posture. The embodiment of the application is not limited. As shown in the figure, Figure 1 The zero-trust access control system based on network security posture assessment can comprise a user terminal, a network security database, a network security posture assessment module, an access permission decision center, an access permission manager, and an access permission execution point.

[0070] The user terminal is connected with the network security database and the access permission decision center, and is configured to perform identity authentication on a user and send a result of the authentication to the network security database for storage;

[0071] The access permission decision center is connected with the network security situation assessment module and the access permission controller, and is configured to receive an access application of the user terminal and send a security situation assessment instruction to the network security situation assessment module;

[0072] The network security situation assessment module is connected with the network security database, and is configured to read relevant data in the network security database, analyze and quantify a security access situation under a current network environment, and obtain security assessment information;

[0073] The access permission decision center is connected with the access permission controller, and is configured to determine an access permission of a user to a resource according to the security assessment information and upload the access permission of the user to the resource to the network security database;

[0074] The access permission controller is connected with the access permission execution point, and is configured to control the access permission execution point;

[0075] The access permission execution point is configured to connect data transmission between a user and a resource or block an access of the user to the resource according to the access permission of the user to the resource, and upload a user access situation to the network security database.

[0076] Optionally, the network security database comprises user identity management data, user behavior log data, user access situation record data, user access permission decision result data, system activity log data, system vulnerability and patch management data, terminal detection and response data, and intrusion detection data;

[0077] The network security database is configured to provide input data for the network security situation assessment module, save a record of identity authentication from a user terminal, and receive and record a result of the access permission decision center and a user access situation uploaded by the access permission execution point in real time.

[0078] Optionally, the network security situation assessment module comprises a network security data auditing unit and a security situation assessment unit;

[0079] The network security data auditing unit is connected with the network security database, and is configured to collect relevant security data in the network security database, identify a security state of a current network, and detect an existing or potential network security threat;

[0080] The security posture assessment unit is in data connection with the network security data auditing unit, and is configured to judge the multi-source network security posture situation information according to the identification detection result of the network security data auditing unit, obtain security assessment information, and provide the security assessment information to the access permission decision center;

[0081] The network security posture assessment module periodically and continuously assesses the user who has completed the identity authentication, so that the access permission decision center timely adjusts the access permission of the user.

[0082] Optionally, the access permission decision center is configured to periodically and continuously receive the security assessment information provided by the network security posture assessment module according to the resource access request of the user terminal, and determine or adjust the access permission of the user to the resource by using a pre-defined security access strategy.

[0083] The access permission of the user to the resource includes blocking access, allowing access, continuing access, allowing and recording, allowing and reviewing, allowing and isolating, and allowing and limiting.

[0084] The access permission decision center uploads the decision result to the network security database in real time for storage, so as to timely adjust the access permission of the user who has completed the identity authentication.

[0085] Optionally, the access permission execution point is blocked between the user and the resource, and the user can access the resource with specified permission only when the user is authenticated and granted the access permission.

[0086] In the process of the user accessing the resource, the access permission execution point transmits data by using a plurality of communication protocols, and uploads and records the access content and access time of the user to the network security database, and the data transmission is protected by using a national secret SSL.

[0087] It can be seen that the application provides a zero-trust access control system and method based on network security posture assessment, which increases the access permission between the allowed access and the blocked access on the basis of the binary decision result form, uses the network security posture assessment method to provide a decision basis for the determination of the user permission, periodically and continuously monitors the user who has completed the identity authentication, assesses the risk of the user access or the trust level of the user, and timely and dynamically adjusts the access permission of the user to the resource. Based on this, the resource is protected from being attacked, and the normal access of the user to the resource is also taken into account.

[0088] Embodiment Two

[0089] Please refer to Figure 2 , Figure 2 is a flowchart of a zero-trust access control method based on network security posture assessment disclosed by the embodiments of the application. In the flowchart, Figure 2The described network security posture assessment-based zero-trust access control method is applied to the field of network security, determines the access permission of a user to a resource based on the assessment of the network security posture, and is not limited by the embodiments of the application. Figure 2 The network security posture assessment-based zero-trust access control method can include the following steps.

[0090] S1, using the user terminal, responding to the resource access application of a user, performing identity authentication on the user to obtain identity authentication information, and sending the identity authentication information to the network security database for storage;

[0091] S2, using the access permission decision center, sending a security posture assessment instruction to the network security posture assessment module according to the resource access application of the user terminal;

[0092] S3, using the network security posture assessment module, performing security assessment on the current network according to the security posture assessment instruction to obtain security assessment information;

[0093] S4, using the access permission decision center, determining the access permission of the user according to the security assessment information, and sending the access permission of the user to the access permission controller and the network security posture assessment module;

[0094] S5, using the access permission execution point, performing user access control according to the access permission of the user under the control of the access permission controller; the access control includes data transmission between the user and the resource or blocking the user access.

[0095] Optionally, the network security posture assessment module uses the security posture assessment instruction to perform security assessment on the current network to obtain security assessment information, which includes the following steps.

[0096] S31, using the network security data auditing unit to collect security data from the network security database; the security data includes user information, terminal information, and network environment information;

[0097] S32, performing index decomposition on the security data to obtain a network security index system;

[0098] S33, using a preset network security index quantification evaluation model to process the network security index system to obtain security assessment information.

[0099] Optionally, the network security index system includes a first-level index, a second-level index, and a third-level index.

[0100] The first-level index includes user behavior risk, terminal system risk, and network environment risk.

[0101] The secondary indicators include multi-person watching behavior, illegal access behavior, disabling security mode, screenshot monitoring, screen recording monitoring, vulnerability check list, patch check list, configuration check list, IDS alarm and EDR alarm;

[0102] The tertiary indicators include watching risk score, illegal access score, disabling security score, screenshot score, screen recording score, vulnerability risk score, patch risk score, configuration risk score, alarm level score and EDR score.

[0103] Optionally, the network security indicator system is processed by using the quantitative evaluation model of the preset network security indicator to obtain security evaluation information, including:

[0104] S331, the watching risk score, the illegal access score, the disabling security score, the screenshot score and the screen recording score are processed to obtain a user behavior risk overall score;

[0105] S332, the vulnerability risk score, the patch risk score and the configuration risk score are processed to obtain a user terminal system overall risk score;

[0106] S333, the alarm level score and the EDR score are processed to obtain a network environment risk overall score;

[0107] S334, the user behavior risk overall score, the user terminal system overall risk score and the network environment risk overall score are processed to obtain security evaluation information.

[0108] Optionally, the vulnerability risk score, the patch risk score and the configuration risk score are processed to obtain a user terminal system overall risk score, including:

[0109] S3321, the vulnerability risk score is processed by using a vulnerability risk evaluation model to obtain a system vulnerability overall risk score;

[0110] The vulnerability risk evaluation model is:

[0111]

[0112] S3322, the patch risk score is processed by using a patch risk evaluation model to obtain a system patch management overall risk score;

[0113] The patch risk evaluation model is:

[0114]

[0115] S3323, processing the configuration risk score by using the configuration risk assessment model to obtain a system security configuration overall risk score;

[0116] The configuration risk assessment model is:

[0117]

[0118] S3324, processing the system vulnerability overall risk score, the system patch management overall risk score and the system security configuration overall risk score by using a user terminal system overall risk score model to obtain a user terminal system overall risk score;

[0119] The user terminal system overall risk score model is:

[0120] R T = ω v × risk v + ω p × risk p + ω c × risk c

[0121] In the formula, R T is the user terminal system overall risk score, risk v is the system vulnerability overall risk score, risk p is the system patch management overall risk score, risk c is the system security configuration overall risk score, v(i) is the checking result of the ith to-be-checked vulnerability item in the preset vulnerability checking list, including the existence or non-existence of the vulnerability, p(j) is the installation situation of the jth patch in the preset patch management list, including whether the patch is installed according to the requirement or not, c(k) is the situation of the kth item security configuration in the preset security configuration list, including whether the configuration is compliant or not, ω v is the weight of the system vulnerability overall risk score, ω p is the weight of the system patch management overall risk score, ω c is the weight of the system security configuration overall risk score, and the weight can be calculated according to actual data, which is not limited by the present application, ω v + ω p + ω c = 1.

[0122] It can be seen that the application provides a zero-trust access control system and method based on network security posture assessment. On the basis of a binary decision result form, access permissions between allowed access and blocked access are added, and the method of network security posture assessment is used to provide a decision basis for the determination of user permissions. For users who have been authenticated, periodic continuous monitoring is performed, and the risk of user access or the trust level of the user is evaluated, so as to timely and dynamically adjust the access permissions of the user to the resources. Based on this, the resources are protected from attacks, and normal access of the user to the resources is also taken into account.

[0123] Embodiment three

[0124] Please refer to Figure 3 , Figure 3 is another flowchart of a zero-trust access control method based on network security posture assessment according to an embodiment of the application. Among them, Figure 3 The zero-trust access control method based on network security posture assessment described above is applied to the field of network security, and the access permissions of the user to the resources are determined based on the evaluation of the network security posture. The embodiments of the application are not limited. As shown in Figure 3 The technical scheme of the zero-trust access control method based on network security posture assessment is: implementing zero-trust access control for data, computing, services, applications and other resources, and constructing a zero-trust access control system, including an access permission decision center, an access permission manager, an access permission execution point, a network security posture assessment module, a network security database, and a user terminal and resources. The network security posture assessment module reads related data in the network security database, analyzes and evaluates and quantifies the security access situation under the current network environment, such as the trust evaluation of the user or the risk evaluation of the user access. The access permission decision center determines the access permissions of the user to the resources according to the security access situation under the current network environment quantified by the network security posture assessment module, and the access permission controller controls the access permission execution point based on the result, connects the data transmission between the user and the resources according to the specified access permissions, or blocks the access of the user to the resources.

[0125] The network security database is the basis of the zero-trust access control, and is an input data source for analyzing, evaluating and quantifying the security access in the current network environment. The database includes user identity management, user behavior logs, user access records, user access permission decision results, system activity logs, system vulnerability and patch management, endpoint detection and response (EDR), intrusion detection system (IDS) and other data. In the zero-trust access control system based on network security situation assessment proposed in the present application, the network security situation assessment module is provided with input data, records of identity authentication from user terminals, and real-time reception and recording of the results of the access permission decision center and the user access situation uploaded by the access permission execution point.

[0126] The network security situation assessment module is the pre-decision station of the zero-trust access control, and completes the evaluation and quantification of the security access in the current network environment, thereby providing a direct basis for determining the user access permission. The module includes two units of network security data auditing and security situation assessment. The network security data auditing unit is the input part of the network security situation assessment module, and is connected with the network security database. Its function is to collect relevant security data in the network security database, identify the security state of the current network and detect existing or potential network security threats. The security situation assessment unit real-time quantifies and fuses the multi-source network security situation information based on the identification and detection results of the network security data auditing unit, and converts it into a trust evaluation of the user or a risk assessment of the user access, to provide for the access permission decision center. For the user who has completed identity authentication, the network security situation assessment module continuously evaluates it periodically, so that the access permission decision center can adjust the access permission of the user in a timely manner.

[0127] The access permission decision center is the decision core of the zero-trust access control, and directly determines the access permission of the user to the resource. The access permission decision center periodically and continuously receives the user trust evaluation or the risk assessment of the user access provided by the network security situation assessment module for the resource access request from the user terminal, and determines or adjusts the access permission of the user by using a pre-defined security access strategy. The access permission of the user to the resource includes blocking access, allowing access, continuing access, allowing and recording, allowing and reviewing, allowing and isolating, allowing and limiting, etc. The access permission decision center uploads its decision results to the network security database in real time for saving, so as to adjust the access permission of the user who has completed identity authentication in a timely manner.

[0128] The access permission execution point is the only channel for the user to access the resource, and under the control of the access permission controller, the data transmission between the user and the resource is connected or the user's access to the resource is blocked according to the user access permission given by the access permission decision center. The access permission execution point blocks between the user and the resource, so that the resource is hidden behind the access permission execution point, and only when the user is authenticated and granted access permission can the user access the resource with specified permission, thereby reducing the risk of resource attacks. In the process of user accessing the resource, the access permission execution point transmits data through various communication protocols, and uploads and records the user's access content and access time to the network security database, and the data transmission adopts national secret SSL for protection.

[0129] For the resource access application from the user terminal, under the zero-trust access control system based on network security situation assessment proposed in the application, the steps of access control are as follows:

[0130] Step 1: The user terminal proposes a resource access application and performs identity authentication, and after the authentication is completed, the user identity authentication situation is uploaded to the network security database for recording.

[0131] Step 2: The access permission decision center receives the access application from the user terminal, and sends a security situation assessment instruction to the network security situation assessment module.

[0132] Step 3: The network security situation assessment module collects relevant network security related data from the network security database through the network security data audit unit, and analyzes and identifies the current network security state, detects existing or potential network security threats. Further, the security situation assessment group unit estimates the security access situation under the current network environment.

[0133] Step 4: The access permission decision center determines or adjusts the user's access permission according to the evaluation result of the network security situation assessment module according to the pre-defined security access strategy, and issues the user's access permission to the access permission controller and uploads it to the network security situation assessment module for recording.

[0134] Step 5: The access permission execution point connects the data transmission between the user and the resource or blocks the user's access under the control of the access permission controller according to the user access permission given by the access permission decision center, and uploads the user's access to the resource to the network security situation assessment module for recording.

[0135] Step 6: The user ends the access to the resource, ending the access control process, otherwise go to step 3.

[0136] In the above access control, the network security posture assessment carried out around the user mainly depends on the construction of the index system and the design of the quantification method. For the quantification of the security access situation in the current network environment, the present application takes the risk of user access as an example to specifically develop the construction of the index system and the design of the quantification method.

[0137] (1) Network security index system

[0138] The subjects associated with the security data collected by the network security data auditing unit of the network security posture assessment module from the network security database mainly include three categories, including users, terminals and network environments. The present application takes the three subjects as dimensions, adopts the analytic hierarchy process (AHP) to start from the three dimensions, decomposes the security state of the three subjects by indexes, and forms an extensible network security index system, and the specific content is shown in Table 1.

[0139] Table 1 Network security index system

[0140]

[0141] In the aspect of user behavior security, the present application decomposes the first-level index into five second-level indexes including onlookers, rule violation access, disabled security mode, etc. according to the typical rule violation behaviors of the user in the access to resources.

[0142] In the aspect of terminal system security, the present application sets the second-level indexes around the system vulnerabilities, patches and configuration. Taking the terminal system vulnerabilities as an example, a vulnerability check list can be preset, the user terminal is checked for vulnerabilities by a vulnerability scanner, and the security index quantification evaluation method is adopted to quantitatively score, so as to form the corresponding risk severity score for each vulnerability item in the list.

[0143] In the aspect of network environment security, the present application associates the alarm events of the IDS system and the EDR system with the user terminal, so as to form the corresponding risk score. Of course, since the scoring mechanisms of different external systems may be different, for a specific external system, the scoring mechanism needs to be converted.

[0144] (2) Security index quantification evaluation method

[0145] For the risk assessment of user access in the current network environment, the network security index system proposed in the application involves the index types including user behavior risk, terminal security risk and network environment risk. Among them, the terminal security risk is mainly caused by terminal software problems, such as defects existing in terminal software, security configuration of software and abuse of software functions. For the above three terminal software problems, the application quantifies them by using the commonly used standard evaluation methods, namely Common Vulnerability Scoring System (CVSS), Common Misuse Scoring System (CMSS) and Common Configuration Scoring System (CCSS), and the simple introduction of their functions is shown in Table 2. The three evaluation methods all use the same theoretical basis and evaluate the severity of the corresponding terminal software problems by using the same evaluation dimensions, and the quantification results have consistency in the grade division and value range, and the specific conditions are shown in Table 3.

[0146] Table 2 Function of CVSS, CMSS and CCSS

[0147]

[0148] Table 3 Evaluation quantization grade division and corresponding value range of CVSS, CMSS and CCSS

[0149]

[0150]

[0151] Based on this, the application considers the influence of each index factor in the user behavior risk and the network environment risk from the three angles of confidentiality, integrity and availability, maps the corresponding risk score calculation to CVSS, CMSS and CCSS, so as to unify the evaluation perspective and dimension of the quantification calculation of the whole network security index system, and the specific settings are shown in Table 4.

[0152] Table 4 Quantitative evaluation method of network security index

[0153]

[0154] When the evaluation and quantification of all indexes in the network security index system are completed, the user behavior risk, terminal system risk and network environment risk can be comprehensively evaluated and quantified. Since the quantification calculation of the whole network security index system proposed in the application is unified in the evaluation perspective and dimension, it lays a foundation for the fusion calculation of multiple indexes.

[0155] The present application takes the evaluation and quantification of terminal system risk as an example, and gives the process of multi-index fusion calculation of the security access situation in the network security situation evaluation module under the current network environment. Specifically as follows

[0156]

[0157] R T =ω v ×risk v +ω p ×risk p +ω c ×risk c

[0158] In the formula, risk v is the overall risk score of the user terminal system on the system vulnerability, v(i) is the check result of the i-th to-be-checked vulnerability item in the preset vulnerability check list, i.e. the vulnerability exists or does not exist. risk p is the overall risk score of the user terminal system on the system patch management, such as the risk brought by the failure of a patch to be installed as required, p(j) is the installation situation of the j-th patch in the preset patch management list, i.e. the patch has been installed as required or not installed as required. risk c is the overall risk score of the user terminal system on the system security configuration, such as the risk brought by the failure of the user terminal system to perform a certain security configuration as required, c(k) is the security configuration situation of the k-th item in the preset security configuration list, i.e. the configuration is compliant or not compliant. R T is the overall risk score of the user terminal system, ω v , ω p , ω c are the fusion weights of the above-mentioned three sub-security indexes, and the sum of the three weight values is 1. In the actual application background, the values of ω v , ω p , ω c can be adjusted to adapt to the requirement differences of different application backgrounds on system vulnerability, patch management and security configuration.

[0159] Therefore, the above method is used to complete the evaluation and quantification of user behavior risk, terminal system risk and network environment risk, and similar methods are used to fuse and calculate the quantification results of the three types of risks, to obtain the risk evaluation of user access under the current network environment.

[0160] The apparatus embodiments described above are only illustrative, wherein the modules illustrated as separate components can or can not be physically separated, and the components illustrated as modules can or can not be physical modules, i.e., can be located in one place or distributed to multiple network modules. Part or all of the modules can be selected to achieve the purposes of the embodiments according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0161] Through the specific description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage, a magnetic tape storage, or any other computer readable medium that can be used to carry or store data.

[0162] Finally, it should be noted that: the zero-trust access control system and method based on network security posture assessment disclosed by the embodiments of the present application are only the preferred embodiments of the present application, and are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that; the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A zero-trust access control system based on network security situation assessment, characterized in that, The system includes a user terminal, a network security database, a network security situation assessment module, an access permission decision center, an access permission manager, and an access permission execution point; The user terminal is connected to the network security database and the access control decision center for user authentication and to send the authentication result to the network security database for storage. The access control decision center is connected to the network security situation assessment module and the access control controller, and is used to receive access requests from user terminals and send security situation assessment instructions to the network security situation assessment module. The network security situation assessment module is connected to the network security database and is used to read relevant data from the network security database, analyze, assess and quantify the security access situation in the current network environment, and obtain security assessment information. The access control decision center is connected to the access control controller via data connection. Used to determine a user's access permissions to resources based on the security assessment information, and to upload the user's access permissions to resources to the network security database; The access control controller is data-connected to the access control execution point and is used to control the access control execution point; The access permission enforcement point is used to connect data transmission between the user and the resource, or block the user's access to the resource, based on the user's access permissions to the resource, and upload the user's access information to the network security database. The steps of the zero-trust access control method based on network security situation assessment applied to the aforementioned zero-trust access control system based on network security situation assessment include: S1, using the user terminal, in response to the user's resource access request, authenticate the user's identity, obtain identity authentication information, and send the identity authentication information to the network security database for storage; S2, using the access permission decision center, a security situation assessment instruction is sent to the network security situation assessment module according to the resource access request of the user terminal; S3, using the network security situation assessment module, perform a security assessment on the current network according to the security situation assessment instruction to obtain security assessment information, including: S31, using the network security data auditing unit, collect security data from the network security database; the security data includes user information, terminal information, and network environment information; S32, decompose the security data into indicators to obtain a network security indicator system; S33, using a preset quantitative evaluation model for network security indicators, the network security indicator system is processed to obtain security evaluation information, including: S331 processes the risk scores of onlookers, unauthorized access, disabling security, screenshots, and screen recordings to obtain an overall user behavior risk score. S332 processes the vulnerability risk score, patch risk score, and configuration risk score to obtain the overall risk score of the user terminal system, including: S3321, The vulnerability risk score is processed using a vulnerability risk assessment model to obtain an overall system vulnerability risk score; The vulnerability risk assessment model is as follows: S3322, The patch risk score is processed using the patch risk assessment model to obtain the overall risk score of system patch management; The patch risk assessment model is as follows: S3323, The configuration risk score is processed using the configuration risk assessment model to obtain the overall risk score of the system security configuration; The configuration risk assessment model is as follows: S3324, using the overall risk scoring model of the user terminal system, process the overall risk score of the system vulnerability, the overall risk score of the system patch management, and the overall risk score of the system security configuration to obtain the overall risk score of the user terminal system; The overall risk scoring model for the user terminal system is as follows: R T =ω v ×risk v +oh p ×risk p +oh c ×risk c In the formula, R T The overall risk score for the user terminal system, risk v Assess the overall risk of system vulnerabilities, and assign a risk rating. p Assess the overall risk of system patch management. c The system security configuration is assigned an overall risk score, where v(i) is the inspection result of the i-th vulnerability item in the preset vulnerability checklist, including whether the vulnerability exists or not; p(j) is the installation status of the j-th patch in the preset patch management list, including whether the patch is installed as required or not; c(k) is the security configuration status of the k-th item in the preset security configuration list, including whether the configuration is compliant or non-compliant; and ω. v ω is the weight for the overall risk score of system vulnerabilities. p ω is the weight for the overall risk score of system patch management. c To configure the overall risk score weights for system security, ω v +ω p +ω c =1; S333 processes the alarm level score and EDR score to obtain the overall network environment risk score; S334, Process the overall risk score of the user behavior, the overall risk score of the user terminal system, and the overall risk score of the network environment to obtain security assessment information; S4, using the access permission decision center, determine the user's access permissions based on the security assessment information, and send the user's access permissions to the access permission controller and the network security situation assessment module; S5, using the access permission execution point, under the control of the access permission controller, user access control is performed according to the user's access permissions; the access control includes connecting data transmission between the user and the resource, or blocking user access.

2. The zero-trust access control system based on network security situation assessment according to claim 1, characterized in that, The network security database includes user identity management data, user behavior log data, user access record data, user access permission decision result data, system activity log data, system vulnerability and patch management data, terminal detection and response data, and intrusion detection data. The network security database is used to provide input data for the network security situation assessment module, save and record the identity authentication from user terminals, and receive and record the results of the access permission decision center and the user access status uploaded by the access permission execution point in real time.

3. The zero-trust access control system based on network security situation assessment according to claim 1, characterized in that, The network security situation assessment module includes a network security data audit unit and a security situation assessment unit; The network security data auditing unit is connected to the network security database and is used to collect relevant security data from the network security database, identify the current security status of the network, and detect existing or potential network security threats. The security situation assessment unit is connected to the network security data audit unit and is used to judge the network security situation information from multiple sources based on the identification and detection results of the network security data audit unit, obtain security assessment information, and provide it to the access control decision center. For users who have completed identity authentication, the network security situation assessment module conducts periodic and continuous assessments so that the access control decision center can adjust the user's access permissions in a timely manner.

4. The zero-trust access control system based on network security situation assessment according to claim 1, characterized in that, The access permission decision center is used to periodically and continuously receive security assessment information provided by the network security situation assessment module based on the resource access requests of user terminals, and to determine or adjust the user's access permissions to resources using predefined security access policies. The user's access permissions to resources include blocking access, allowing access, continuing access, allowing and logging, allowing and reviewing, allowing and isolating, and allowing and restricting. The access control decision center uploads its decision results to the network security database in real time for storage, so as to adjust the access control of authenticated users in a timely manner.

5. The zero-trust access control system based on network security situation assessment according to claim 1, characterized in that, The access permission execution point is isolated between the user and the resource, and the user can only access the resource with the specified permissions when the user is authenticated and granted access permission. During the process of a user accessing resources, the access permission enforcement point transmits data through various communication protocols and uploads and records the user's access content and access time to the network security database. The data transmission is protected by national cryptographic SSL.

6. The zero-trust access control system based on network security situation assessment according to claim 1, characterized in that, The cybersecurity indicator system includes primary indicators, secondary indicators, and tertiary indicators; The primary indicators include user behavior risk, terminal system risk, and network environment risk. The secondary indicators include multi-person spectating behavior, unauthorized access behavior, disabling security mode, screenshot monitoring, screen recording monitoring, vulnerability checklist, patch checklist, configuration checklist, IDS alarms, and EDR alarms. The three-level indicators include the risk score for onlookers, the score for unauthorized access, the score for disabling security, the score for screenshots, the score for screen recordings, the score for vulnerability risks, the score for patch risks, the score for configuration risks, the score for alarm levels, and the score for EDR.

Citation Information

Patent Citations

  • Zero-trust access permission control system and method based on trusted computing

    CN113901499A

  • Internet of Things access scene identity modeling and access control method

    CN117155609A