A method for early warning of security vulnerability risks of an information system based on big data
By establishing an indicator database, integrating a vulnerability database, and conducting data cleaning and big data analysis, the problem of the inability to detect security vulnerabilities in information systems in a timely manner has been solved, enabling accurate vulnerability detection and timely early warning, thereby improving the security of information systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- POWERCHINA HEBEI ELECTRIC POWER SURVEY & DESIGN INST CO LTD
- Filing Date
- 2024-03-11
- Publication Date
- 2026-07-24
AI Technical Summary
Existing technologies are unable to promptly screen and repair a large number of security vulnerabilities in information systems, leading to increased security risks.
By establishing an indicator database, integrating third-party vulnerability databases, performing data cleaning and preprocessing, conducting big data analysis and mining, assessing and classifying vulnerabilities, triggering early warning mechanisms, and providing remediation suggestions, we can achieve accurate detection and timely early warning of security vulnerabilities in information systems.
It enables accurate detection and assessment of potential vulnerabilities in information systems, provides timely security risk warnings and remediation suggestions, improves enterprises' ability to perceive potential threats, reduces losses caused by security risks, and optimizes the allocation of security resources.
Smart Images

Figure CN118194290B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security, and in particular to a method for early warning of information system security vulnerabilities based on big data. Background Technology
[0002] With the rapid development and widespread application of information technology, information systems have become the information infrastructure of enterprises. As the scale and complexity of these systems increase, numerous information systems with different architectures and types exist within enterprises. However, this also brings with it a growing number of security risks, with thousands of information security vulnerabilities being reported every month. These vulnerabilities cannot be promptly identified and patched manually. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a method for early warning of information system security vulnerabilities based on big data. By collecting, storing and analyzing third-party vulnerability databases, it can accurately detect and assess potential vulnerabilities in various aspects such as business systems, networks and applications, as well as provide timely security risk warnings and remediation suggestions.
[0004] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is: a method for early warning of information system security vulnerabilities based on big data, comprising the following steps:
[0005] Step S1: Establish an indicator database for all levels and types of information systems, network devices, and application software within the enterprise, and collect system security-related data;
[0006] Step S2: Integrate security intelligence and third-party vulnerability databases on the Internet to obtain the latest security vulnerability information and classify and store it.
[0007] Step S3: Clean and preprocess the keywords in the security vulnerability information;
[0008] Step S4, Big Data Analysis and Mining: Utilize big data analysis and mining techniques to analyze and mine the cleaned and preprocessed data;
[0009] Step S5, Security Vulnerability Assessment and Classification: Combining professional security knowledge and industry standards, assess and classify the discovered security vulnerabilities, determine their degree of danger and potential risk impact, and issue a real-time security risk report;
[0010] Step S6, Warning Triggering and Notification: Based on the set warning information security risk threshold, when a high-risk security vulnerability is detected in the system, the warning mechanism is triggered;
[0011] Step S7: Establish a security decision support system: Provide reasonable security decision recommendations based on early warning information and real-time security risk reports.
[0012] A further improvement of the technical solution of the present invention is that: the system security-related data in step S1 includes log files, network traffic, intermediate files and configuration information, and the system descriptions in the security-related data are classified and categorized, and decomposed into several system keywords according to the system security index data.
[0013] A further improvement to the technical solution of this invention lies in the following: Step S3, which involves cleaning and preprocessing the descriptions of various security vulnerabilities in the security vulnerability information, specifically includes removing invalid data, converting the data format, and removing duplicate data. The cleaned data is then decomposed into several security vulnerability keywords, and a relevance weight level is defined for each security vulnerability keyword: WL1, WL2, WL3...WL n .
[0014] A further improvement to the technical solution of the present invention is that: in step S4, potential security vulnerabilities and attack patterns are identified by analyzing and mining security vulnerability keywords;
[0015] Each system keyword is matched with a security vulnerability keyword. If a match is found, the value is 1; otherwise, it is 0, forming a matching vector M, namely M1, M2...Mn. Each security vulnerability keyword has a relevance weight level set manually. The weight levels include direct relevance, strong relevance, medium relevance, and weak relevance. Except for direct relevance, each relevance is predefined with a weight value from 0 to 1, thus obtaining the relevance vector W of the vulnerability report, namely W1, W2...Wn. The matching vector M and the relevance vector W are mapped one-to-one.
[0016] A further improvement to the technical solution of this invention lies in: in step S5, a security vulnerability risk model is established. For weight levels that are directly related, if the value of the matching vector M corresponding to that item is 1, it is matched and directly identified as having a security risk; for weight levels other than those that are directly related, the magnitude of the vector difference is calculated and compared with the magnitude of the benchmark vector.
[0017] Vector difference magnitude:
[0018] Benchmark vector magnitude:
[0019] Among them, M i For the vector matching of the i-th security vulnerability keyword, W i Let be the relevance vector of the i-th security vulnerability keyword, and n be the total number of security vulnerability keywords.
[0020] Modulus ratio: S = Md / Mv. The smaller the modulus ratio, the higher the correlation. It is divided into several levels according to the modulus Mv of the benchmark vector to solve the judgment jitter problem when n is too small, which leads to insufficient sampling.
[0021] A further improvement of the technical solution of the present invention is that: the warning information in step S6 includes the vulnerability type, vulnerability risk level and the systems or services that may be affected; the warning mechanism is to quickly notify relevant personnel of the corresponding warning information through built-in system messages, emails, and SMS messages to ensure timely security response and repair.
[0022] A further improvement of the technical solution of the present invention is that the security decision recommendations in step S7 involve system configuration optimization, vulnerability repair and security policy adjustment.
[0023] The technological advancements achieved by this invention due to the adoption of the above technical solutions are as follows:
[0024] 1. This invention collects, stores, and analyzes third-party vulnerability databases to accurately detect and assess potential vulnerabilities in various aspects of business systems, networks, and applications, as well as provide timely security risk warnings and remediation suggestions. When a new vulnerability is discovered, it can be integrated into the vulnerability database. The system can be automatically checked to see if the vulnerability exists. If the vulnerability exceeds the security threshold, a warning message can be sent to the administrator.
[0025] 2. This invention, through big data analysis and mining techniques, can uncover patterns and correlations hidden behind massive amounts of data, further identifying potential security threats and abnormal behaviors. Based on these findings, real-time monitoring, risk assessment, and security early warning of the system can be achieved. This provides important basis and reference for information system security decisions. It not only improves enterprises' ability to perceive potential security threats and reduces losses caused by security risks, but also helps enterprises and institutions formulate reasonable security decisions and optimize the allocation of security resources.
[0026] 4. This invention can promptly detect potential security vulnerabilities: By utilizing big data analysis and mining techniques, this method can quickly analyze massive amounts of security-related data to identify potential security vulnerabilities and abnormal behaviors. Automated vulnerability scanning tools can be used to periodically scan systems and applications to find known security vulnerabilities. When vulnerabilities exceeding warning thresholds are detected, the system can automatically generate warnings, which helps in real-time monitoring and timely detection of potential security threats within the system.
[0027] 5. This invention improves the accuracy of security vulnerability assessment: By combining big data analysis with security knowledge and industry standards, this method can accurately assess the severity and impact of security vulnerabilities. This helps to prioritize the handling and remediation of high-risk security vulnerabilities, minimizing the risk of attacks on information systems;
[0028] 6. This invention provides real-time security risk warnings: Based on big data, warning triggering and notifications can monitor vulnerability intelligence and system status in real time, and trigger warning mechanisms according to set security risk thresholds. Timely warnings can help identify and address potential security risks in the system early, reducing the scope of losses and impacts. By collecting and analyzing security data from various systems, a security situation map can be generated, providing the company with a comprehensive overview and warnings of its security status.
[0029] 7. This invention provides effective remediation suggestions and optimization decisions: This method can provide detailed remediation suggestions for each discovered security vulnerability, including patches, configuration modifications, etc. This helps to speed up the security vulnerability remediation process and provides targeted optimization decisions to reduce the probability of the system being attacked. Attached Figure Description
[0030] Figure 1 This is a flowchart of the information system security vulnerability risk warning based on big data according to the present invention. Detailed Implementation
[0031] The present invention will be further described in detail below with reference to embodiments:
[0032] like Figure 1 As shown, a method for early warning of information system security vulnerabilities based on big data includes the following steps:
[0033] S1. Establish an indicator database for all levels and types of information systems, network devices, and application software within the enterprise, collect system security-related data, including log files, network traffic, intermediate files, and configuration information, classify and categorize the system descriptions in the security-related data, and decompose the system security indicator data into several system keywords.
[0034] S2. Integrate security intelligence and third-party vulnerability databases on the Internet to obtain the latest security vulnerability information and classify and store it.
[0035] S3. Clean and preprocess the collected raw data, including removing invalid data, converting data formats, and removing duplicate data. This ensures data quality and consistency, preparing for subsequent analysis and data mining. The cleaned data is then broken down into several security vulnerability keywords, and a relevance weight level is defined for each keyword: WL1, WL2, WL3...WL n .
[0036] S4. Big Data Analysis and Mining: Utilizing big data analysis and mining techniques, the cleaned and preprocessed data is analyzed and mined. Each system keyword is matched with a security vulnerability keyword; a match is assigned a value of 1, otherwise 0, forming a matching vector M, denoted as M1, M2...Mn. Each security vulnerability keyword has a manually assigned relevance weight level, including direct relevance, strong relevance, moderate relevance, and weak relevance. Except for direct relevance, each relevance is predefined with a weight value between 0 and 1, resulting in a vulnerability report relevance vector W, denoted as W1, W2...Wn. A one-to-one correspondence is established between the matching vector M and the relevance vector W.
[0037] Corresponding process:
[0038]
[0039] S5. Security Vulnerability Assessment and Classification: Combining professional security knowledge and industry standards, assess and classify discovered security vulnerabilities, determine their severity and potential impact, and generate real-time security risk reports. Establish a security vulnerability risk model. For items with weight levels that are directly relevant, if the corresponding matching vector M has a value of 1, it is considered a match and directly identified as having a security risk. For weight levels other than directly relevant, calculate the vector difference magnitude and the benchmark vector magnitude:
[0040] Vector difference magnitude:
[0041] Benchmark vector magnitude:
[0042] Among them, M i For the vector matching of the i-th security vulnerability keyword, W i Let be the relevance vector of the i-th security vulnerability keyword, and n be the total number of security vulnerability keywords.
[0043] Modulus ratio: S = Md / Mv. The smaller the modulus ratio, the higher the correlation. It is divided into several levels according to the modulus Mv of the benchmark vector to solve the judgment jitter problem when n is too small, which leads to insufficient sampling.
[0044] S6. Early Warning Triggering and Notification: Based on set security risk thresholds, an early warning mechanism is triggered when a high-risk security vulnerability is detected in the system. The early warning information includes the vulnerability type, vulnerability severity level, and potentially affected systems or services. Corresponding early warning information is promptly notified to relevant personnel via built-in system messages, emails, SMS, etc., ensuring timely security response and remediation. Big data-driven early warning triggering and notification enables real-time monitoring of vulnerability intelligence and system status, triggering the early warning mechanism according to set security risk thresholds. Timely early warnings help identify and address potential security risks in the system early, reducing the scope of losses and impacts.
[0045] S7. Establish a security decision support system: Based on early warning information and real-time security risk reports, provide reasonable security decision suggestions on existing security control measures. These suggestions involve system configuration optimization, vulnerability remediation, and security policy adjustments to improve the overall security of information systems and networks. This invention can provide effective remediation suggestions and optimization decisions: This method can provide detailed remediation suggestions for each discovered security vulnerability, including patches, configuration modifications, etc. This helps to accelerate the security vulnerability remediation process and provide targeted optimization decisions to reduce the probability of the system being attacked.
[0046] This invention utilizes big data analytics and mining techniques to uncover patterns and correlations hidden behind massive amounts of data, further identifying potential security threats and abnormal behaviors. Based on these findings, real-time monitoring, risk assessment, and security early warning of systems can be achieved. This provides crucial evidence and reference for information system security decisions. It not only enhances enterprises' awareness of potential security threats and reduces losses caused by security risks, but also helps enterprises and institutions formulate reasonable security decisions and optimize security resource allocation.
Claims
1. A method for early warning of information system security vulnerabilities based on big data, characterized in that: Includes the following steps: Step S1: Establish an indicator database for all levels and types of information systems, network devices, and application software within the enterprise, and collect system security-related data. System security-related data includes log files, network traffic, intermediate files, and configuration information. Classify and categorize the system descriptions in the security-related data, and decompose the system security indicator data into several system keywords. Step S2: Integrate security intelligence and third-party vulnerability databases on the Internet to obtain the latest security vulnerability information and classify and store it. Step S3: Clean and preprocess the keywords in the security vulnerability information; specifically, this includes removing invalid data, converting data formats, and removing duplicate data. The cleaned data is then broken down into several security vulnerability keywords, and a relevance weight level is defined for each keyword: WL1, WL2, WL3...WL n ; Step S4, Big Data Analysis and Mining: Utilize big data analysis and mining techniques to analyze and mine the cleaned and preprocessed data; By analyzing and mining security vulnerability keywords, potential security vulnerabilities and attack patterns can be identified. Each system keyword is matched with a security vulnerability keyword. If a match is found, the value is 1; otherwise, it is 0, forming a matching vector M, namely M1, M2...Mn. Each security vulnerability keyword defined in the security vulnerability is manually assigned a relevance weight level, which includes direct relevance, strong relevance, medium relevance, and weak relevance. Except for direct relevance, each relevance is predefined with a weight value from 0 to 1, thus obtaining the relevance vector W of the vulnerability report, namely W1, W2...Wn. The matching vector M and the relevance vector W are mapped one-to-one. Step S5, Security Vulnerability Assessment and Classification: Combining professional security knowledge and industry standards, assess and classify the discovered security vulnerabilities, determine their degree of danger and potential risk impact, and issue a real-time security risk report; A security vulnerability risk model is established. For weight levels that are directly related, if the value of the corresponding matching vector M is 1, it is considered a match and directly identified as having a security risk. For weight levels other than those that are directly related, the risk is assessed by calculating the magnitude of the vector difference and the magnitude of the benchmark vector. Vector difference magnitude: Benchmark vector magnitude: in, For the first A vector of security vulnerability keyword matching. For the first A vector of security vulnerability keyword relevance, where n is the total number of security vulnerability keywords; Length-to-module ratio: The smaller the modulus ratio, the higher the correlation, according to the benchmark vector modulus. It is divided into several levels to solve the problem of judgment jitter when n is too small, resulting in insufficient sampling; Step S6, Warning Triggering and Notification: Based on the set warning information security risk threshold, when a high-risk security vulnerability is detected in the system, the warning mechanism is triggered; Step S7: Establish a security decision support system: Provide reasonable security decision recommendations based on early warning information and real-time security risk reports.
2. The method for early warning of information system security vulnerabilities based on big data according to claim 1, characterized in that: The warning information in step S6 includes the vulnerability type, vulnerability risk level, and potentially affected systems or services. The warning mechanism is to quickly notify relevant personnel of the corresponding warning information through built-in system messages, emails, and SMS messages to ensure timely security response and remediation.
3. The method for early warning of information system security vulnerabilities based on big data according to claim 1, characterized in that: The security decision recommendations in step S7 involve system configuration optimization, vulnerability patching, and security policy adjustment.