A vulnerability risk assessment method and apparatus
By constructing vulnerability attack graphs and fuzzy vulnerability game models, the problem of assessing the correlation between vulnerabilities and the relationship between attack and defense constraints was solved, thus improving the accuracy of vulnerability risk assessment.
Patent Information
- Application Number
- CN202410498941.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2044-04-24
AI Technical Summary
Existing vulnerability scanning tools cannot effectively consider the correlation between vulnerabilities and the mutual constraints between attackers and defenders, resulting in inaccurate vulnerability risk assessments.
By constructing a vulnerability attack graph and determining the attack payoff under the Nash equilibrium state based on a fuzzy vulnerability game model, and combining vulnerability importance, propagation loss and cumulative probability, the initial payoff is represented by a triangular fuzzy number for defuzzification, and the attack payoff under the Nash equilibrium state is solved to achieve vulnerability risk assessment of the target vulnerability.
It enables quantitative analysis of the cumulative probability and risk parameters of vulnerabilities, thereby improving the accuracy of vulnerability risk assessment.
Smart Images

Figure CN118381640B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data processing, in particular to a vulnerability risk assessment method and device. BACKGROUND
[0002] In recent years, network security has attracted more and more attention due to frequent network security incidents. The root cause of network attack incidents is the existence of information system vulnerability (or vulnerability). Vulnerability refers to the defects in the specific implementation of hardware, software, protocol or system security policy, which can enable attackers to access or damage the system without authorization.
[0003] Although the vulnerability scanning tools (such as Nessus, X-can, etc.) developed in recent years can find vulnerabilities in the system, they are all isolated analysis of vulnerability vulnerability, without considering the correlation between vulnerabilities and without considering the mutual restraint relationship between attack and defense, and cannot provide accurate vulnerability risk assessment strategy. SUMMARY
[0004] Therefore, the purpose of the present application is to provide a vulnerability risk assessment method and device, which quantitatively analyzes the cumulative probability and risk parameters of vulnerabilities to improve the accuracy of vulnerability risk assessment. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a vulnerability risk assessment method, comprising:
[0006] Constructing a vulnerability attack graph based on an attack path of system vulnerabilities;
[0007] For a target vulnerability in the vulnerability attack graph, determining an attack income degree in a Nash equilibrium situation based on a fuzzy vulnerability game model as a vulnerability importance of the target vulnerability;
[0008] Determining a risk parameter of the target vulnerability in combination with the vulnerability importance of the target vulnerability, a vulnerability propagation loss and a vulnerability cumulative probability, the vulnerability cumulative probability being a probability of successfully penetrating the target vulnerability through all paths capable of reaching the target vulnerability from an initial vulnerability in the vulnerability attack graph;
[0009] The determination of the attack income degree in the Nash equilibrium situation based on the fuzzy vulnerability game model as the vulnerability importance of the target vulnerability includes:
[0010] For the target vulnerability in the vulnerability attack graph, an initial income degree is represented by a triangular fuzzy number;
[0011] Defuzzifying the initial income degree to obtain a clear income degree;
[0012] According to the clear benefit degree, a Nash equilibrium of the fuzzy vulnerability game model is solved, and an attack benefit degree in the Nash equilibrium is obtained as the vulnerability importance degree of the target vulnerability.
[0013] Optionally, the triangular fuzzy number is represented by a lower bound, a main value and an upper bound, and is used to indicate the value of the system asset in terms of confidentiality, integrity and availability.
[0014] Optionally, the defuzzification of the initial benefit degree to obtain the clear benefit degree comprises:
[0015] According to the probability vector of the triangular fuzzy number, an expectation of the triangular fuzzy number is determined as the clear benefit degree obtained by the defuzzification of the initial benefit degree.
[0016] Optionally, the risk parameter of the target vulnerability is determined according to the vulnerability importance degree of the target vulnerability, the vulnerability propagation loss and the vulnerability cumulative probability of the target vulnerability, and comprises:
[0017] According to the vulnerability importance degree of the target vulnerability and the vulnerability propagation loss of the target vulnerability, a vulnerability comprehensive loss of the target vulnerability is calculated.
[0018] According to the vulnerability comprehensive loss and the vulnerability cumulative probability of the target vulnerability, a risk parameter of the target vulnerability is determined.
[0019] Optionally, the method further comprises:
[0020] According to the vulnerability cumulative probability of the parent node of the target vulnerability and the logical relationship between the parent nodes, a vulnerability cumulative probability of the target vulnerability is calculated; and / or,
[0021] According to the vulnerability self loss and the inherent probability of the child node of the target vulnerability, a vulnerability propagation loss of the target vulnerability is calculated.
[0022] In a second aspect, an embodiment of the present application further provides a vulnerability risk assessment device, comprising:
[0023] An attack graph construction unit is configured to construct a vulnerability attack graph based on an attack path of a system vulnerability.
[0024] An importance degree determination unit is configured to determine, for a target vulnerability in the vulnerability attack graph, an attack benefit degree in a Nash equilibrium based on a fuzzy vulnerability game model, as a vulnerability importance degree of the target vulnerability.
[0025] a risk assessment unit, configured to determine a risk parameter of the target vulnerability by combining a vulnerability importance of the target vulnerability, a vulnerability propagation loss of the target vulnerability, and a vulnerability cumulative probability of the target vulnerability, the vulnerability cumulative probability being a probability of successfully penetrating the target vulnerability through all paths capable of reaching the target vulnerability from an initial vulnerability in the vulnerability attack graph.
[0026] Optionally, the importance determination unit comprises:
[0027] an initial benefit degree representation unit, configured to represent an initial benefit degree of a target vulnerability in the vulnerability attack graph by a triangular fuzzy number.
[0028] a defuzzification unit, configured to defuzzify the initial benefit degree to obtain a clear benefit degree.
[0029] a solving unit, configured to solve a Nash equilibrium of a fuzzy vulnerability game model according to the clear benefit degree to obtain an attack benefit degree in a Nash equilibrium situation as the vulnerability importance of the target vulnerability.
[0030] Optionally, the triangular fuzzy number is represented by a lower bound, a principal value, and an upper bound, and is used to indicate values of system assets in terms of confidentiality, integrity, and availability.
[0031] Optionally, the defuzzification unit comprises:
[0032] a defuzzification sub-unit, configured to determine an expectation of the triangular fuzzy number according to a probability vector of the triangular fuzzy number as the clear benefit degree obtained by defuzzifying the initial benefit degree.
[0033] Optionally, the risk assessment unit comprises:
[0034] a comprehensive loss determination unit, configured to calculate a vulnerability comprehensive loss of the target vulnerability according to the vulnerability importance of the target vulnerability and the vulnerability propagation loss of the target vulnerability.
[0035] a risk assessment sub-unit, configured to determine the risk parameter of the target vulnerability according to the vulnerability comprehensive loss and the vulnerability cumulative probability of the target vulnerability.
[0036] Optionally, the apparatus further comprises:
[0037] a cumulative probability calculation unit, configured to calculate the vulnerability cumulative probability of the target vulnerability according to vulnerability cumulative probabilities of parent nodes of the target vulnerability and logical relationships between the parent nodes; and / or
[0038] a propagation loss calculation unit, configured to calculate the vulnerability propagation loss of the target vulnerability according to vulnerability self-losses and inherent probabilities of child nodes of the target vulnerability.
[0039] The embodiment of the present application provides a vulnerability risk assessment method and device, a vulnerability attack graph is constructed based on an attack path of a system vulnerability, for a target vulnerability in the vulnerability attack graph, attack income degree in a Nash equilibrium situation is determined based on a fuzzy vulnerability game model, as vulnerability importance of the target vulnerability, in combination with the vulnerability importance of the target vulnerability, vulnerability propagation loss and vulnerability cumulative probability, a risk parameter of the target vulnerability is determined, the vulnerability cumulative probability is a probability of successfully penetrating the target vulnerability through all routes capable of reaching the target vulnerability from an initial vulnerability in the vulnerability attack graph, the attack graph can associate and comprehensively analyze the vulnerabilities in the network, the game theory can consider the restriction relationship of the attack and defense sides, in the process of determining the vulnerability importance of the target vulnerability, the initial income degree can be represented by a triangular fuzzy number, the initial income degree is de-fuzzified and solved to obtain the attack income degree in the Nash equilibrium situation, therefore, the problem that the attack and defense income degrees are difficult to solve the vulnerability importance due to the uncertainty and fuzziness of the information system can be solved on the basis of analyzing the logical relationship of the vulnerabilities, based on the restriction relationship of the attack and defense, and by de-fuzzifying the fuzzy number, the cumulative probability and the risk parameter of the vulnerability are quantitatively analyzed, and the accuracy of the vulnerability risk assessment is improved. BRIEF DESCRIPTION OF DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0041] Figure 1 A flowchart of a vulnerability risk assessment method provided by the embodiment of the present application is shown;
[0042] Figure 2 Two basic logical relationship diagrams provided by the embodiment of the present application are shown;
[0043] Figure 3 A mixed logical relationship diagram provided by the embodiment of the present application is shown;
[0044] Figure 4 A propagation loss determination diagram provided by the embodiment of the present application is shown;
[0045] Figure 5 A structural block diagram of a vulnerability risk assessment device provided by the embodiment of the present application is shown;
[0046] Figure 6 A structural diagram of a computer device provided by the embodiment of the present application is shown. DETAILED DESCRIPTION
[0047] In order to make the above objectives, features and advantages of the present application more apparent, the specific embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0048] In the following description, a large number of specific details are set forth in order to provide a thorough understanding of the present application, but the present application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of the present application, therefore the present application is not limited to the specific embodiments disclosed below.
[0049] As described in the background, although the vulnerability scanning tools developed in recent years such as Nessus, X-can, etc. can find the vulnerabilities existing in the system, they are all isolated to analyze the vulnerability of the vulnerability, without considering the correlation between the vulnerabilities and the mutual restraint relationship between the attack and defense, and cannot provide accurate vulnerability risk assessment strategy.
[0050] The inventors have found that the attack graph is a directed graph showing the attack sequence and attack effect that the attacker may launch, which is composed of vertices and directed edges, can correlate the vulnerabilities in the network to comprehensively analyze the security of the network, and further discover the potential threats existing in the network, and can more accurately and effectively evaluate the security of the network; game theory is a method and theory for making effective decisions in a confrontation environment, which can consider the restraint relationship between the attack and defense. However, the vulnerability risk analysis methods based on attack graph and game theory do not consider the existence of system fuzziness and uncertainty, so that the evaluated vulnerability risk is not close to the actual network.
[0051] Based on the above technical problems, the embodiments of the present application provide a vulnerability risk assessment method and device, an attack graph of vulnerabilities is constructed based on the attack path of system vulnerabilities, for the target vulnerability in the attack graph of vulnerabilities, an attack income degree in Nash equilibrium situation is determined based on a fuzzy vulnerability game model as the vulnerability importance degree of the target vulnerability, and the risk parameter of the target vulnerability is determined by combining the vulnerability importance degree of the target vulnerability, the vulnerability propagation loss and the vulnerability cumulative probability, the vulnerability cumulative probability is the probability of successfully penetrating the target vulnerability through all routes that can reach the target vulnerability from the initial vulnerability in the attack graph of vulnerabilities, the attack graph can correlate the vulnerabilities in the network for comprehensive analysis, and the game theory can consider the restraint relationship between the attack and defense. In the process of determining the vulnerability importance degree of the target vulnerability, the initial income degree can be represented by a triangular fuzzy number, the initial income degree is de-fuzzified and solved to obtain the attack income degree in Nash equilibrium situation, so that the vulnerability importance degree can be determined based on the attack and defense restraint relationship on the basis of analyzing the logical relationship of the vulnerabilities, and the problem that the attack and defense income degree is difficult to solve the vulnerability importance degree due to the uncertainty and fuzziness of the information system is solved by de-fuzzifying the fuzzy number, thereby the cumulative probability and risk parameter of the vulnerability are quantitatively analyzed, and the accuracy of vulnerability risk assessment is improved.
[0052] For ease of understanding, the vulnerability risk assessment method and device provided by the embodiments of the present application are described in detail below with reference to the drawings.
[0053] Reference Figure 1 As shown in the figure, a flowchart of a vulnerability risk assessment method provided by the embodiments of the present application, which can include the following steps.
[0054] S101, constructing a vulnerability attack graph based on the attack path of system vulnerabilities.
[0055] There is a complex association relationship between the vulnerabilities of a network system. An attacker can use a successfully penetrated vulnerability to attack the associated vulnerability nodes until the target node is attacked. Therefore, by analyzing the network topology structure, the system vulnerabilities can be determined, and based on the attack path, a vulnerability attack graph can be constructed.
[0056] The vulnerability node can be defined as n i ={V i , R i , A i , D i , I i}, wherein V i is the vulnerability name, R i is the asset information where the vulnerability is located, A i is the attack means of the attacker, representing the attack space, D i is the defense measure of the defender, representing the defense space, and I i is the vulnerability importance, representing the impact on the system after the vulnerability risk occurs, which is the basis for vulnerability risk assessment. In the following, the vulnerability and the vulnerability node will not be distinguished.
[0057] The vulnerability importance of the vulnerability node is an unknown quantity, which can be calculated through the steps of S102, and then the risk assessment is carried out based on the vulnerability importance.
[0058] The directed graph with vulnerabilities as nodes and attack paths as edges becomes a vulnerability attack graph, which can be represented as VAG={N, L}, wherein N represents the vulnerability set of the system, and L represents the penetration relationship between vulnerabilities. VAG satisfies the constraint: Let Pre(n) be the parent node set of n, then there are two basic logical relationships between the parent nodes, which are "and" relationship and "or" relationship. The parent node is the vulnerability node located in the front side of n in the vulnerability attack graph and connected with n. After penetrating the parent node, the parent node can be used to attack the n node.
[0059] The vulnerability node has an inherent probability representing a probability of successful penetration of the vulnerability node, denoted as P, and the probability value is taken from an "AccessComplexity" attribute value E of a vulnerability causing successful penetration in a Common Vulnerability Scoring System (CVSS) scoring system. The "Access Complexity" field represents the difficulty of an attacker attacking the vulnerability, which can be considered as a probability value of the vulnerability being successfully penetrated.
[0060] The vulnerabilities in the network can be associated through the vulnerability attack graph, and then the security of the network can be comprehensively analyzed to find potential threats existing in the network, so that the security of the network can be more accurately and effectively evaluated.
[0061] In S102, for a target vulnerability in the vulnerability attack graph, an attack revenue degree in a Nash equilibrium situation is determined based on a fuzzy vulnerability game model, as a vulnerability importance degree of the target vulnerability.
[0062] Game theory is a method and theory for making effective decisions in a confrontation environment, and can consider the constraint relationship between the attack and defense sides, so that the determined vulnerability importance degree is in line with the actual situation and is relatively accurate.
[0063] The fuzzy vulnerability game model (FVGM) is a game model at a vulnerability position of the attack and defense sides, which is constructed according to attack and defense behavior strategies, and is a game model at a certain vulnerability node, which can be expressed as FVGM=(P,A,U), wherein:
[0064] (1) P=(P a , P d ) is a participant set, P a is an attacker, and P d is a defender.
[0065] (2) A=(A a , A d ) is an action space of the attack and defense sides, A a represents an action space of the attacker, A d represents an action space of the defender, and A is a specific behavior set selected by the attack and defense sides in the game.
[0066] (3) U=(f a , f d ) represents a revenue degree of the participants P a and P d , which depends on specific behaviors of the attack and defense sides, and cannot be accurately measured, and is represented as a fuzzy number, so the formula is a fuzzy revenue function. Wherein f a is an attack revenue degree, and f dTo defend the yield degree. The above attack yield degree and defense yield degree are unknown quantities, which can be determined in the following way.
[0067] In the vulnerability attack and defense game scenario, the attack yield has various forms, including tangible and intangible yields. It can be the sense of achievement after a successful attack, or the commercial data obtained through the attack to obtain more commercial benefits, which is often difficult to measure with precise numerical values.
[0068] In the embodiments of the present application, for the target vulnerability in the vulnerability attack graph, the initial yield degree can be represented by a triangular fuzzy number, and the clear yield degree can be obtained by de-fuzzification of the initial yield degree. The Nash equilibrium of the fuzzy vulnerability model is solved according to the clear yield degree, and the attack yield degree in the Nash equilibrium situation is obtained as the vulnerability importance of the target vulnerability. Such vulnerability importance quantitative analysis process not only fully considers the constraint relationship between attack and defense, but also solves the problem of difficult quantification of attack and defense yield due to the uncertainty and fuzziness of the information system, so that the solved vulnerability importance is more reasonable to reflect the risk of the vulnerability.
[0069] Specifically, the attack and defense yield (loss caused by attack behavior) can be described by a triangular fuzzy number, that is, used to represent the attack yield degree and the defense yield degree. Define M=(s, m, u) as a triangular fuzzy number, and its membership function μ M (x): R→[0, 1] can be represented as:
[0070]
[0071] In the vulnerability game scenario, the upper and lower bounds u and s of the triangular fuzzy number M represent the maximum and minimum possible values of the yield obtained by the attack and defense sides, and the main value m of M represents the most likely value. Where s, m and u represent the values of system assets in terms of confidentiality, integrity and availability, and M is a fuzzy number as the initial yield degree.
[0072] In actual operation, the yield obtained by the attack and defense sides is essentially obtained by damaging the security properties of the system, so the degree of damage to the security properties of the system can represent the yield of the attack and defense sides. In this paper, the aforementioned triangular fuzzy number is determined according to the security properties of the system, for example, R=(r C , r I , r A ) represents the values of system assets in terms of confidentiality, integrity and availability, and is used as the aforementioned triangular fuzzy number M. P=(p c , p i , p a ) represents the degree of preference of the attacker for the security properties of the system, and is used as the probability vector of the triangular function, where 0≤p c , pi , p a ≤ 1, p c +p i +p a = 1, then the system loss (SL) can be expressed as: SL = p c · r c +p i · r I +p a · r A .
[0073] Therefore, the initial profit degree is de-fuzzified to obtain the clear profit degree, which can be realized based on fuzzy probability and expectation. Specifically, the probability vector of a triangular fuzzy number M = (s, m, u) can be expressed as p = (p s , p m , p u ), wherein p s +p m +p u = 1, p s , p m , p u are all greater than 0, and the expectation EM = p s × s + p m × m + p u × u of the triangular fuzzy number. Thus, based on the degree of preference of the attacker for the security characteristics of the system, the loss caused by the attack is described using a triangular fuzzy number, which is reasonable and has high accuracy.
[0074] Assuming that SP is the total value of the system, SL is the system loss, AC is the attack cost, and DC is the defense cost, then the attack profit degree f a and the defense profit degree f d are respectively:
[0075] f a = SL - AC, f d = SP - SL - DC.
[0076] In the determination process of the probability vector of the triangular fuzzy number M, the main value m of the triangular fuzzy number M can be taken as a boundary, and the first probability p m corresponding to the main value, the second probability p s corresponding to the lower bound, and the third probability p u corresponding to the upper bound of the triangular fuzzy number are determined under the condition of equal probability.to obtain a probability vector comprising the first probability, the second probability and the third probability. Then, according to the deviation degree m-s of the lower limit of M, the probability that the attacker's income is the main value m is N times the probability of the lower bound s, and according to the deviation degree m-u of the upper limit of M, the probability that the attacker's income is the main value m is K times the probability of the upper bound, then the probability vector can be expressed as:
[0077]
[0078] In this way, the probability vector p of the triangular fuzzy number can be determined, and the expectation EM of the triangular fuzzy number can be determined.
[0079] That is, the expectation of the triangular fuzzy number can be determined according to the probability vector of the triangular fuzzy number, as the clear income degree obtained by de-fuzzifying the initial income degree, that is, the clear income degree EM, as SL in the foregoing formula, and then f a and f d .
[0080] After determining the attack income degree and the defense income degree, the attack income degree of each attack strategy and the defense income degree of each defense strategy can be determined, and a game income degree matrix based on the FVGM model is formed. In the vulnerability game, both the attacker and the defender tend to choose the strategy that maximizes their own income degree, and finally reach Nash equilibrium. Nash equilibrium is a concept of solution in game theory, which refers to a strategy combination that satisfies the following properties: any player will not improve their own income by changing their own strategy alone. Based on the FVGM model, the maximum income of both parties is obtained by solving the Nash equilibrium of the FVGM model according to the income degree matrix, that is, solving the mixed strategy Nash equilibrium, and completing the vulnerability importance quantification.
[0081] Specifically, for FVGM, let the attacker and the defender choose strategies with probability vectors F a ={p a1 ,p a2 ,…,p am1} and F d ={p d1 ,p d2 ,…,p dm2}, respectively. If there exist and satisfying the following conditions:
[0082]
[0083]
[0084] then and are determined as the most mixed strategies of the attacker and the defender, A Nash equilibrium is formed. In the equilibrium situation, the payoff of both the attacker and the defender reaches the maximum simultaneously, and the payoffs are:
[0085]
[0086]
[0087] In determining the attack payoff in the Nash equilibrium situation, it is taken as the vulnerability importance of the target vulnerability, which is used to represent the influence of the target vulnerability on the system after the occurrence of the risk. The vulnerability importance is represented as The vulnerability importance of all vulnerabilities in the system can be represented by an importance vector: I = [I(1), I(2), …, I(n)].
[0088] In S103, the risk parameter of the target vulnerability is determined in combination with the vulnerability importance of the target vulnerability, the vulnerability propagation loss, and the vulnerability cumulative probability.
[0089] In the embodiments of the present application, after the vulnerability importance of the target vulnerability is determined, the vulnerability importance of the target vulnerability can be taken as the vulnerability self-loss, i.e., the loss caused by the penetration of the target vulnerability itself. In combination with the vulnerability propagation loss and the vulnerability cumulative probability, the risk parameter of the target vulnerability can be determined, wherein the vulnerability propagation loss is the loss caused by the penetration of a vulnerability directly associated with the target vulnerability by the attacker using a broken vulnerability, i.e., the loss caused by the attack on the vulnerability directly associated with the target vulnerability by the attacker through the target vulnerability, and the vulnerability cumulative probability represents the probability that the attacker successfully penetrates the target vulnerability through all paths capable of reaching the target vulnerability node starting from the initial vulnerability node.
[0090] Specifically, the comprehensive loss of the target vulnerability can be determined based on the vulnerability importance of the target vulnerability and the vulnerability propagation loss, and then the risk parameter of the target vulnerability can be determined according to the comprehensive loss of the target vulnerability and the vulnerability cumulative probability. The comprehensive loss of the target vulnerability can be the sum of the vulnerability importance and the vulnerability propagation loss, and the risk parameter of the target vulnerability can be the product of the comprehensive loss and the vulnerability cumulative probability.
[0091] The vulnerability importance (i.e., the vulnerability self-loss) of the target vulnerability, the vulnerability propagation loss, and the comprehensive loss of the target vulnerability can be represented as L s , L o , and L w , respectively. L w = L s + L o , the risk parameter of the vulnerability is represented as R, and the vulnerability cumulative probability is represented as P. Therefore, R = L w × P.
[0092] The loss of all vulnerabilities in the information system constitutes a loss vector, wherein the vulnerability self-loss vector is represented as V(Ls )=[L s (1),L s (2),…,L s The vulnerability propagation loss vector is represented as V(L(n)]. o )=[L o (1),L o (2),…,L o (n)], then the comprehensive loss vector is represented as V(L w )=V(L s )+V(L o The risk vector composed of the risk parameters of all vulnerabilities in the information system can be represented as V(R)=[R(1),R(2),…,R(n)].
[0093] The following section introduces how to determine the cumulative probability of a vulnerability. Specifically, the cumulative probability of a target vulnerability can be calculated by considering the cumulative probability of the target vulnerability's parent nodes and the logical relationships between the parent nodes.
[0094] As defined in the vulnerability attack graph, vulnerabilities exhibit both penetration and logical relationships. Penetration relationships are represented by directed edges, while logical relationships have two basic types: AND and OR. (Reference) Figure 2 The diagram illustrates two basic logical relationships provided in this application embodiment. Figure a represents an "AND" relationship, and Figure b represents an "OR" relationship. Taking the V3 vulnerability as the target vulnerability, V1 and V2 are the parent nodes of the target vulnerability. When the logical relationship between V1 and V2 is an "AND" relationship, it means that to target the V3 vulnerability, it is necessary to successfully penetrate both parent nodes V1 and V2 simultaneously. The inherent probabilities of V1, V2, and V3 are denoted as p1, p2, and p3, and the cumulative probability of the vulnerabilities of V1, V2, and V3 is denoted as p. v1 p v2 and p v3 Then pv3 = p v1 p v2 p3; When the logical relationship between V1 and V2 is "OR", it means that for the target vulnerability V3, it is possible to successfully penetrate the parent node V1 or successfully penetrate the parent node V2. The inherent probabilities of V1, V2, and V3 are denoted as p1, p2, and p3, respectively, and the cumulative probability of the vulnerabilities in V1, V2, and V3 is denoted as p. v1 p v2 and p v3 Then p v3 =(p v1 +p v2 -p v1 p v2 )p3.
[0095] The logical relationship between the vulnerabilities also has a mixed (MIX) relationship, which can be based on this to increase an auxiliary node to decompose the MIX relationship into "and" relationship and "or" relationship, and then determine the vulnerability cumulative probability. Referring to Figure 3 Fig. a shows a mixed logical relationship diagram provided by an embodiment of the application, and Fig. b shows a decomposition diagram of the mixed relationship. Taking V4 vulnerability as a target vulnerability, V1, V2 and V3 are parent nodes of the target vulnerability, the logical relationship between V3 and V2 is "and" relationship, the logical relationship between V1 and V2 is "or" relationship, and the logical relationship between V1 and V3 is "or" relationship, which embodies a complex relationship. Then an auxiliary node s can be added as a parent node of V4, which is also a child node of V3 and V2, and the inherent probability p is 1. The inherent probabilities of V1, V2, V3 and V4 are denoted as p1, p2, p3 and p4, and the vulnerability cumulative probabilities of V1, V2, V3 and V4 are denoted as p v1 , p v2 , p v3 and p v4 . For the auxiliary node s, the parent nodes V3 and V2 need to be successfully penetrated at the same time, so the vulnerability cumulative probability p s of the auxiliary node can be determined as p v3 p v2 . For the target vulnerability V4, the parent node V1 can be successfully penetrated, or the parent node s can be successfully penetrated, so p v4 = (p v1 +p s -p v1 p s )p4.
[0096] Based on the above method, the vulnerability cumulative probability of all vulnerabilities can be calculated step by step from the initial node trigger using the breadth-first method.
[0097] In the process of calculating the vulnerability propagation loss, the vulnerability propagation loss of the target vulnerability can be calculated according to the vulnerability itself loss and inherent probability of the child nodes of the target vulnerability. Referring to Figure 4 Fig. shows a propagation loss determination diagram provided by an embodiment of the application, where V d and V e are child nodes of V c , the inherent probabilities of V c , V d and V e are denoted as p c , p d and p e , the vulnerability itself loss can be denoted as L s (c), L s (d) and L s (e), and the target vulnerability Vc The vulnerability propagation loss is represented as L o (c) = L s (d) p d + L s (e) p e .
[0098] That is, in combination with the logical relationship between the vulnerabilities in the vulnerability attack graph and the inherent probability defined by the CVSS system, the cumulative probability of the vulnerabilities can be quantitatively analyzed on the basis of analyzing the logical relationship of the vulnerabilities, and then the vulnerability risk is evaluated on the basis of the vulnerability importance and the cumulative probability, the quantitative vulnerability itself loss and the propagation loss are completed. The evaluation result can be used to identify the key vulnerabilities and help the administrator to focus on defense.
[0099] The embodiment of the application provides a vulnerability risk assessment method, constructs a vulnerability attack graph based on an attack path of system vulnerabilities, determines an attack income degree in a Nash equilibrium situation as a vulnerability importance of a target vulnerability based on a fuzzy vulnerability game model for the target vulnerability in the vulnerability attack graph, and determines a risk parameter of the target vulnerability in combination with the vulnerability importance of the target vulnerability, a vulnerability propagation loss and a vulnerability cumulative probability. The vulnerability cumulative probability is a probability of successfully penetrating the target vulnerability through all routes capable of reaching the target vulnerability starting from an initial vulnerability in the vulnerability attack graph. The attack graph can associate and comprehensively analyze the vulnerabilities in the network, the game theory can consider the restriction relationship between the attack and defense, the initial income degree can be represented by a triangular fuzzy number in the process of determining the vulnerability importance of the target vulnerability, the initial income degree is de-fuzzified and solved to obtain the attack income degree in the Nash equilibrium situation, so that the cumulative probability of the vulnerabilities and the risk parameter can be quantitatively analyzed on the basis of analyzing the logical relationship of the vulnerabilities, based on the restriction relationship between the attack and defense, and the problem that the attack and defense income degree is difficult to solve the vulnerability importance due to the uncertainty and fuzziness of the information system is solved by de-fuzzifying the fuzzy number, thereby improving the accuracy of the vulnerability risk assessment.
[0100] Based on the above vulnerability risk assessment method, the embodiment of the application further provides a vulnerability risk assessment device, as shown in Figure 5 The structure block diagram of the vulnerability risk assessment device provided by the embodiment of the application can include:
[0101] The attack graph construction unit 110 is configured to construct a vulnerability attack graph based on an attack path of system vulnerabilities.
[0102] The importance determination unit 120 is configured to determine an attack income degree in a Nash equilibrium situation as a vulnerability importance of a target vulnerability based on a fuzzy vulnerability game model for the target vulnerability in the vulnerability attack graph.
[0103] The risk assessment unit 130 is configured to determine a risk parameter of the target vulnerability by combining a vulnerability importance of the target vulnerability, a vulnerability propagation loss of the target vulnerability, and a vulnerability cumulative probability, the vulnerability cumulative probability being a probability of successfully penetrating the target vulnerability through all paths capable of reaching the target vulnerability from an initial vulnerability in the vulnerability attack graph.
[0104] Optionally, the importance determination unit 120 comprises:
[0105] The initial benefit degree representation unit is configured to represent an initial benefit degree of a target vulnerability in the vulnerability attack graph by a triangular fuzzy number.
[0106] The defuzzification unit is configured to defuzzify the initial benefit degree to obtain a clear benefit degree.
[0107] The solving unit is configured to solve a Nash equilibrium of a fuzzy vulnerability game model according to the clear benefit degree to obtain an attack benefit degree in a Nash equilibrium situation as the vulnerability importance of the target vulnerability.
[0108] Optionally, the triangular fuzzy number is represented by a lower bound, a principal value, and an upper bound, and is used to indicate values of system assets in terms of confidentiality, integrity, and availability.
[0109] Optionally, the defuzzification unit comprises:
[0110] The defuzzification sub-unit is configured to determine an expectation of the triangular fuzzy number according to a probability vector of the triangular fuzzy number as the clear benefit degree obtained by defuzzifying the initial benefit degree.
[0111] Optionally, the risk assessment unit comprises:
[0112] The comprehensive loss determination unit is configured to calculate a vulnerability comprehensive loss of the target vulnerability according to the vulnerability importance of the target vulnerability and the vulnerability propagation loss of the target vulnerability.
[0113] The risk assessment sub-unit is configured to determine the risk parameter of the target vulnerability according to the vulnerability comprehensive loss and a vulnerability cumulative probability of the target vulnerability.
[0114] Optionally, the apparatus further comprises:
[0115] The cumulative probability calculation unit is configured to calculate the vulnerability cumulative probability of the target vulnerability according to vulnerability cumulative probabilities of parent nodes of the target vulnerability and logical relationships between the parent nodes; and / or
[0116] The propagation loss calculation unit is configured to calculate the vulnerability propagation loss of the target vulnerability according to vulnerability self-losses and inherent probabilities of child nodes of the target vulnerability.
[0117] The embodiment of the present application provides a vulnerability risk assessment device, a vulnerability attack graph is constructed based on an attack path of a system vulnerability, for a target vulnerability in the vulnerability attack graph, attack income degrees in a Nash equilibrium situation are determined based on a fuzzy vulnerability game model, as vulnerability importance degrees of the target vulnerability, in combination with the vulnerability importance degrees of the target vulnerability, vulnerability propagation loss and vulnerability cumulative probability, risk parameters of the target vulnerability are determined, the vulnerability cumulative probability is a probability of successfully penetrating the target vulnerability through all routes capable of reaching the target vulnerability from an initial vulnerability in the vulnerability attack graph, the attack graph can correlate and comprehensively analyze the vulnerabilities in the network, the game theory can consider the restriction relationship of the attack and defense sides, in the process of determining the vulnerability importance degrees of the target vulnerability, the initial income degrees can be represented by triangular fuzzy numbers, the initial income degrees are de-fuzzied and solved to obtain the attack income degrees in the Nash equilibrium situation, therefore, on the basis of analyzing the logical relationship of the vulnerabilities, the attack and defense restriction relationship is considered, and the problem that the attack and defense income degrees are difficult to solve the vulnerability importance degrees due to the uncertainty and fuzziness of the information system is solved by de-fuzzifying the fuzzy numbers, so that the cumulative probability and the risk parameters of the vulnerabilities are quantitatively analyzed, and the accuracy of the vulnerability risk assessment is improved.
[0118] In another aspect, the embodiment of the present application provides a computer device, referring to Figure 6 The diagram shows a structure diagram of a computer device provided by the embodiment of the present application, as Figure 6 The device includes a processor 310 and a memory 320:
[0119] The memory 310 is used for storing program codes and transmitting the program codes to the processor;
[0120] The processor 320 is used for executing the vulnerability risk assessment method provided by the above-mentioned embodiment according to the instructions in the program codes.
[0121] The computer device can include a terminal device or a server, and the vulnerability risk assessment device mentioned above can be configured in the computer device.
[0122] In another aspect, the embodiment of the present application further provides a storage medium, the storage medium is used for storing a computer program, and the computer program is used for executing the vulnerability risk assessment method provided by the above-mentioned embodiment.
[0123] In addition, the embodiment of the present application further provides a computer program product including instructions, when the computer program product runs on a computer, the computer program product makes the computer execute the vulnerability risk assessment method provided by the above-mentioned embodiment.
[0124] Those skilled in the art can understand that all or part of the steps of the foregoing method embodiments can be completed by program instruction hardware, and the foregoing program can be stored in a computer readable storage medium. When the program is executed, the program performs steps including the foregoing method embodiments. The foregoing storage medium can be at least one of the following: a read-only memory (English: Read-only Memory, ROM), a RAM, a magnetic disk or an optical disk, and various media capable of storing program codes.
[0125] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, they are described more simply, and the relevant parts can be referred to the part of the method embodiments.
[0126] The above only describes the preferred embodiments of the present application. Although the preferred embodiments of the present application are disclosed as above, the present application is not intended to be limited to the above. Any person skilled in the art can make many possible changes and modifications to the technical solutions of the present application or modify equivalent embodiments with equivalent changes without departing from the scope of the technical solutions of the present application. Therefore, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present application, without departing from the scope of the technical solutions of the present application, still belongs to the protection scope of the technical solutions of the present application.
Claims
1. A vulnerability risk assessment method, characterized by, The method comprises the following steps: constructing a vulnerability attack graph based on an attack path of system vulnerabilities; determining an attack income degree in a Nash equilibrium situation based on a fuzzy vulnerability game model as a vulnerability importance degree of a target vulnerability in the vulnerability attack graph; determining a risk parameter of the target vulnerability by combining the vulnerability importance degree, a vulnerability propagation loss and a vulnerability cumulative probability of the target vulnerability, wherein the vulnerability cumulative probability is a probability of successfully penetrating the target vulnerability through all paths capable of reaching the target vulnerability starting from an initial vulnerability in the vulnerability attack graph; determining an attack income degree in a Nash equilibrium situation based on a fuzzy vulnerability game model as a vulnerability importance degree of a target vulnerability in the vulnerability attack graph, comprising the following steps: representing an initial income degree by a triangular fuzzy number for the target vulnerability in the vulnerability attack graph; de-fuzzifying the initial income degree to obtain a clear income degree; solving a Nash equilibrium of the fuzzy vulnerability game model according to the clear income degree to obtain an attack income degree in a Nash equilibrium situation as the vulnerability importance degree of the target vulnerability.
2. The method of claim 1, wherein, The triangular fuzzy number is represented by a lower bound, a main value and an upper bound, which are used to indicate values of system assets in terms of confidentiality, integrity and availability.
3. The method of claim 2, wherein, The de-fuzzification of the initial income degree to obtain a clear income degree comprises the following steps: determining an expectation of the triangular fuzzy number according to a probability vector of the triangular fuzzy number as the clear income degree obtained by de-fuzzifying the initial income degree.
4. The method according to any one of claims 1 to 3, characterized in that, The determination of the risk parameter of the target vulnerability by combining the vulnerability importance degree, the vulnerability propagation loss and the vulnerability cumulative probability of the target vulnerability comprises the following steps: calculating a vulnerability comprehensive loss of the target vulnerability according to the vulnerability importance degree of the target vulnerability and the vulnerability propagation loss of the target vulnerability; determining the risk parameter of the target vulnerability according to the vulnerability comprehensive loss and the vulnerability cumulative probability of the target vulnerability.
5. The method according to any one of claims 1 to 3, characterized in that, The method further comprises the following steps: calculating the vulnerability cumulative probability of the target vulnerability according to the vulnerability cumulative probability of parent nodes of the target vulnerability and a logical relationship between the parent nodes; and / or calculating the vulnerability propagation loss of the target vulnerability according to a vulnerability self-loss and an inherent probability of child nodes of the target vulnerability.
6. A vulnerability risk assessment apparatus characterized by comprising: The method comprises the following steps: an attack graph construction unit configured to construct a vulnerability attack graph based on an attack path of system vulnerabilities; an importance degree determination unit configured to determine an attack income degree in a Nash equilibrium situation based on a fuzzy vulnerability game model as a vulnerability importance degree of a target vulnerability in the vulnerability attack graph; a risk assessment unit configured to determine a risk parameter of the target vulnerability by combining the vulnerability importance degree, a vulnerability propagation loss and a vulnerability cumulative probability of the target vulnerability, wherein the vulnerability cumulative probability is a probability of successfully penetrating the target vulnerability through all paths capable of reaching the target vulnerability starting from an initial vulnerability in the vulnerability attack graph; the importance degree determination unit comprises the following units: an initial income degree representation unit configured to represent an initial income degree by a triangular fuzzy number for a target vulnerability in the vulnerability attack graph; a de-fuzzification unit configured to de-fuzzify the initial income degree to obtain a clear income degree; The solving unit is configured to solve a Nash equilibrium of the fuzzy vulnerability game model according to the clear profit degree, and obtain an attack profit degree in the Nash equilibrium as the vulnerability importance degree of the target vulnerability.
7. The apparatus of claim 6, wherein, The triangular fuzzy number is represented by a lower bound, a main value and an upper bound, and is used to indicate values of system assets in terms of confidentiality, integrity and availability.
8. The apparatus of claim 7, wherein, The de-fuzzification unit comprises: The de-fuzzification sub-unit is configured to determine an expectation of the triangular fuzzy number according to a probability vector of the triangular fuzzy number, and obtain a clear profit degree by de-fuzzifying the initial profit degree.
9. The device according to any of claims 6-8, characterized in that The risk assessment unit comprises: The comprehensive loss determination unit is configured to calculate a vulnerability comprehensive loss of the target vulnerability according to the vulnerability importance degree of the target vulnerability and a vulnerability propagation loss of the target vulnerability. The risk assessment sub-unit is configured to determine a risk parameter of the target vulnerability according to the vulnerability comprehensive loss and a vulnerability cumulative probability of the target vulnerability.
10. The device of any one of claims 6-8, wherein, The apparatus further comprises: The cumulative probability calculation unit is configured to calculate the vulnerability cumulative probability of the target vulnerability according to vulnerability cumulative probabilities of parent nodes of the target vulnerability and logical relationships between the parent nodes; and / or The propagation loss calculation unit is configured to calculate the vulnerability propagation loss of the target vulnerability according to vulnerability self-losses and inherent probabilities of child nodes of the target vulnerability.
Citation Information
Patent Citations
Wireless sensor network attack defense method and system in fuzzy environment
CN112969180A
Network security defense capability quantitative evaluation method and system based on attack surface
CN117411668A