Safety assessment methods, devices, electronic equipment and storage media
By employing a multi-dimensional security assessment method, data on organizational entities across cloud, network, endpoint, application, and data security dimensions is obtained, and security risk index values are calculated. This addresses the issues of high labor costs and inaccurate scoring in existing technologies, achieving a more comprehensive security risk assessment and lower labor costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-30
- Publication Date
- 2026-04-03
AI Technical Summary
Existing cybersecurity assessment methods suffer from high labor costs and the scoring results fail to accurately reflect the security status.
By acquiring security data from organizational entities across multiple security assessment dimensions, including cloud security, network security, endpoint security, application security, and data security, corresponding security risk indicator values are calculated to conduct multi-dimensional security risk analysis.
It enables more comprehensive and accurate security risk assessments, reduces labor costs, and helps security analysts better understand the overall security risk situation of an organization.
Smart Images

Figure CN118509225B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a security assessment method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the rapid development of information technology, information networks are widely used in daily life. Consequently, various network security issues are also impacting the development of these industries.
[0003] In real-world applications, network regulatory bodies and enterprises typically need to understand the current network security situation and conduct targeted assessments. Currently, assessments are generally conducted through manual analysis or simpler, single-dimensional analysis. However, both of these methods suffer from high labor costs or the inability of the assessment results to accurately reflect the security status. Summary of the Invention
[0004] The purpose of this application is to provide a security assessment method, apparatus, electronic device, and storage medium to improve the problems of high labor costs or inaccurate reflection of security status in existing assessment methods.
[0005] In a first aspect, embodiments of this application provide a security assessment method, the method comprising:
[0006] Obtain security data for organizational entities across multiple security assessment dimensions, wherein the multiple security assessment dimensions include at least two of the following: cloud security dimension, network security dimension, endpoint security dimension, application security dimension, and data security dimension;
[0007] Based on the security data corresponding to each security assessment dimension, obtain the security risk indicator value for the corresponding security assessment dimension;
[0008] The security risk situation of the organization entity is analyzed based on the security risk index value corresponding to each security assessment dimension.
[0009] In the above implementation process, by acquiring security data corresponding to the organization's entity under multiple security assessment dimensions, and based on this security data, the security risk index values of the corresponding security assessment dimensions are obtained to achieve the analysis of the organization's entity's security risk status. The multiple security assessment dimensions include at least two of the following: cloud security dimension, network security dimension, endpoint security dimension, application security dimension, and data security dimension. In this way, the organization's entity can be analyzed from multiple aspects from these security dimensions, achieving a more comprehensive and accurate security risk assessment, so as to more accurately reflect the security status of the organization's entity, and with lower manual costs.
[0010] Optionally, the multiple security assessment dimensions include a cloud security dimension, and the security risk indicators corresponding to the cloud security dimension include at least one of cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. Obtaining the security data corresponding to the organizational entity under the multiple security assessment dimensions includes:
[0011] Obtain security data corresponding to at least one of the following indicators: cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators;
[0012] And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes:
[0013] Based on the security data corresponding to each of the cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators, obtain the risk indicator value corresponding to each indicator;
[0014] Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the cloud security dimension is determined.
[0015] In the above implementation process, under the cloud security dimension, corresponding indicator values are obtained from at least one of the following indicators: cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. In this way, the risk status of an organization under the cloud security dimension can be more accurately assessed from multiple indicators.
[0016] Optionally, the security data corresponding to the cloud security product configuration indicators includes at least one of the following: website application-level intrusion prevention system (WAF) configuration ratio, security audit configuration status, and bastion host access ratio.
[0017] And / or, the security data corresponding to the cloud security configuration risk indicators includes at least one of the following: high-risk access control situation, high-risk data security situation, and high-risk protection status situation;
[0018] And / or, the security data corresponding to the cloud host vulnerability index includes the vulnerability status of the host and middleware;
[0019] And / or, the security data corresponding to the cloud host alarm indicators includes at least one of cloud host alarm status and alarm processing rate.
[0020] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0021] Optionally, the multiple security assessment dimensions include a network security dimension, and the security risk indicators corresponding to the network security dimension include at least one of network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. Obtaining the security data corresponding to the organizational entity under the multiple security assessment dimensions includes:
[0022] Obtain security data corresponding to at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators;
[0023] And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes:
[0024] Based on the security data corresponding to each of the network security risk indicators, network security operation and maintenance indicators and network boundary indicators, obtain the risk indicator value corresponding to each indicator;
[0025] Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the network security dimension is determined.
[0026] In the above implementation process, under the network security dimension, corresponding indicator values are obtained from at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. In this way, the risk situation of an organization entity under the network security dimension can be more accurately assessed from multiple indicators.
[0027] Optionally, the security data corresponding to the network security risk indicators includes at least one of network security incidents and potential dangers, and the timely repair rate of network security vulnerabilities;
[0028] And / or, the security data corresponding to the network boundary indicators includes unauthorized external network connections and / or the offline status and policy configuration status of boundary devices.
[0029] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0030] Optionally, the multiple security assessment dimensions include an endpoint security dimension, and the security risk indicators corresponding to the endpoint security dimension include at least one of endpoint protection capability indicators and endpoint virus status indicators. Obtaining the security data corresponding to the organizational entity under the multiple security assessment dimensions includes:
[0031] Obtain security data corresponding to at least one of the terminal protection capability indicators and the terminal virus status indicators;
[0032] And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes:
[0033] Based on the security data corresponding to each of the terminal protection capability indicators and the terminal virus status indicators, obtain the risk indicator value corresponding to each indicator;
[0034] Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the terminal security dimension is determined.
[0035] In the above implementation process, under the endpoint security dimension, the corresponding indicator value is obtained from at least one of the endpoint protection capability indicators and endpoint virus status indicators, so that the risk status of the organization entity under the endpoint security dimension can be more accurately assessed from multiple indicators.
[0036] Optionally, the multiple security assessment dimensions include an application security dimension, and the security risk indicators corresponding to the application security dimension include at least one of the following: graded protection security assessment rate indicator, security testing indicator, threat indicator, application remediation indicator, supply chain security indicator, and security operation and maintenance indicator. Obtaining the security data corresponding to the organizational entity under the multiple security assessment dimensions includes:
[0037] Obtain security data corresponding to at least one of the following indicators: the graded protection security assessment rate indicator, the security testing indicator, the threat indicator, the application rectification indicator, the supply chain security indicator, and the security operation and maintenance indicator;
[0038] And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes:
[0039] Based on the security data corresponding to each of the following indicators: the security assessment rate of graded protection, the security test indicator, the threat indicator, the application rectification indicator, the supply chain security indicator, and the security operation and maintenance indicator, obtain the risk indicator value corresponding to each indicator;
[0040] Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the application security dimension is determined.
[0041] In the above implementation process, under the application security dimension, corresponding indicator values are obtained from at least one of the following indicators: graded protection security assessment rate, security testing indicators, threat indicators, application rectification indicators, supply chain security indicators, and security operation and maintenance indicators. In this way, the risk situation of an organization under the application security dimension can be more accurately assessed from multiple indicators.
[0042] Optionally, the security data corresponding to the graded protection security assessment rate index includes at least one of the graded protection classification and filing rate, graded protection assessment pass rate, and security assessment rate;
[0043] And / or, the security data corresponding to the threat indicators includes at least one of high-risk port data, high-risk vulnerability data, high-risk external connection data, and weak password data;
[0044] And / or, the security data corresponding to the supply chain security indicators include construction-related supply chain security data and / or operation and maintenance-related supply chain security data.
[0045] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0046] Optionally, the multiple security assessment dimensions include a data security dimension, and the security risk indicators corresponding to the data security dimension include at least one of data element protection indicators, password security indicators, and access control indicators. Obtaining the security data corresponding to the organizational entity under the multiple security assessment dimensions includes:
[0047] Obtain security data corresponding to at least one of the data element protection indicators, the password security indicators, and the access control indicators;
[0048] And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes:
[0049] Based on the security data corresponding to each of the data element protection indicators, the password security indicators, and the access control indicators, obtain the risk indicator value corresponding to each indicator;
[0050] Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the data security dimension is determined.
[0051] In the above implementation process, under the data security dimension, corresponding indicator values are obtained from at least one of the data element protection indicators, password security indicators, and access control indicators. In this way, the risk situation of an organization entity under the data security dimension can be more accurately assessed from multiple indicators.
[0052] Optionally, the step of analyzing the security risk status of the organizational entity based on the security risk index values corresponding to each security assessment dimension includes:
[0053] Determine the target security assessment dimension corresponding to the security risk index values that are below a set threshold;
[0054] Analyze the security risks of the organization entity in the target security assessment dimension.
[0055] In the above implementation process, a target security assessment dimension with a security risk index value less than a set threshold is determined. This allows for targeted risk analysis of organizational entities in the target security assessment dimension, enabling security analysts to take targeted protective measures for the organizational entities.
[0056] Optionally, after analyzing the security risk situation of the organizational entity in the target security assessment dimension, the analysis further includes:
[0057] Analyze the reasons for the loss of points in the aforementioned target security assessment dimensions;
[0058] Based on the reasons for the loss of points, corresponding processing recommendations are determined, and these recommendations are used to instruct the organization entity to take appropriate security measures.
[0059] In the above implementation process, corresponding handling suggestions are determined based on the reasons for the loss of points. This makes it easier for security analysts to carry out security protection based on the handling suggestions, thereby improving the user experience for security analysts.
[0060] Optionally, after analyzing the security risk situation of the organizational entity based on the security risk index values corresponding to each security assessment dimension, the method further includes:
[0061] Obtain the historical security risk information of the organization entity;
[0062] Based on the historical security risk situation and the current security risk situation, obtain the risk change trend of the organization entity.
[0063] In the above implementation process, by obtaining the risk change trend of the organizational entity, it is easier to analyze the overall risk change of the organizational entity, and thus more accurately grasp the risk situation of the organizational entity.
[0064] Secondly, embodiments of this application provide a security assessment device, the device comprising:
[0065] The data acquisition module is used to acquire security data corresponding to organizational entities under multiple security assessment dimensions, wherein the multiple security assessment dimensions include at least two of cloud security dimension, network security dimension, endpoint security dimension, application security dimension and data security dimension;
[0066] The indicator value acquisition module is used to obtain the security risk indicator value of the corresponding security assessment dimension based on the security data corresponding to each security assessment dimension.
[0067] The risk analysis module is used to analyze the security risk status of the organization entity based on the security risk index values corresponding to each security assessment dimension.
[0068] Thirdly, embodiments of this application provide an electronic device, including a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps of the method provided in the first aspect above are performed.
[0069] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the steps of the method provided in the first aspect above.
[0070] Fifthly, embodiments of this application provide a computer program product, including computer program instructions, which, when read and executed by a processor, perform the steps of the method provided in the first aspect above.
[0071] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing embodiments of this application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0072] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0073] Figure 1 A flowchart illustrating a security assessment method provided in this application embodiment;
[0074] Figure 2 This is a schematic diagram of the structure of a neural network model provided in an embodiment of this application;
[0075] Figure 3 This application provides a schematic diagram of the business logic of a security assessment system.
[0076] Figure 4 A structural block diagram of a security assessment system provided in this application embodiment;
[0077] Figure 5 A structural block diagram of a safety assessment device provided in an embodiment of this application;
[0078] Figure 6 This is a schematic diagram of the structure of an electronic device for performing a security assessment method, provided as an embodiment of this application. Detailed Implementation
[0079] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0080] It should be noted that the terms "system" and "network" in the embodiments of this invention can be used interchangeably. "Multiple" refers to two or more; therefore, in the embodiments of this invention, "multiple" can also be understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / ", unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0081] This application provides a security assessment method. This method acquires security data corresponding to an organization entity under multiple security assessment dimensions, and obtains security risk index values for the corresponding security assessment dimensions based on this security data, so as to analyze the security risk situation of the organization entity. The multiple security assessment dimensions include at least two of cloud security dimension, network security dimension, endpoint security dimension, application security dimension, and data security dimension. In this way, the organization entity can be analyzed from multiple security dimensions, achieving a more comprehensive and accurate security risk assessment, and with lower labor costs. This helps security analysts to control the overall security risk situation of the organization entity from multiple dimensions, making it easier for security analysts to carry out security protection work.
[0082] Please refer to Figure 1 , Figure 1 A flowchart of a security assessment method provided in this application embodiment, the method including the following steps:
[0083] Step S110: Obtain security data for organizational entities across multiple security assessment dimensions.
[0084] The organizational entity can refer to a company, unit, department, institution, enterprise, etc. Taking a unit as an example, the organizational entity mentioned in this application can refer to a unit that needs to undergo a security assessment.
[0085] Security data can refer to information used to assess security risks. In this solution, security data refers to the security data of the organization under multiple security assessment dimensions. These multiple security assessment dimensions may include at least two of the following: cloud security, network security, endpoint security, application security, and data security. In other words, multiple security assessment dimensions include at least two of the following five dimensions: cloud, network, endpoint, application, and data.
[0086] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing applications. It uses a large number of clients in a network to monitor abnormal software behavior, obtain the latest information on Trojans and malicious programs on the Internet, push it to the server for automatic analysis and processing, and then distribute solutions for viruses and Trojans to each client.
[0087] Network security: The ability to prevent attacks, intrusions, interference, damage, and unauthorized use of the network, as well as accidents, by taking necessary measures to ensure the network operates stably and reliably, and to guarantee the integrity, confidentiality, and availability of data.
[0088] Endpoint security: Protects user devices from malicious threats and cyberattacks. It emphasizes the security of all networked devices, ensuring they meet the standards defined by the security policy, and protecting the network from viruses and Trojans.
[0089] Application security: Ensuring the security of application usage processes and results, that is, eliminating potential risks such as leakage and theft of computational and transmitted data during the use of applications or tools through other security tools or strategies.
[0090] Data security refers to taking necessary measures to ensure that data is effectively protected and legally used, as well as having the ability to guarantee a continuous state of security.
[0091] Security data for each dimension can be obtained from different sources. For example, security data for the cloud security dimension can be obtained from the organization's cloud devices, such as security logs stored on these devices. Security data for the network security dimension can be obtained from the organization's network traffic, such as alarm logs and threat data. Security data for the endpoint security dimension can be obtained from the organization's endpoint devices, such as logs and operational data generated on these devices. Security data for the application security dimension can be obtained from the organization's various applications, such as network traffic and log information for each application. Security data for the data security dimension can be obtained from the organization's database, such as password and permission data stored in the database. All of this security data can be used for security risk assessment. Understandably, in practical applications, security data may also include other data, which will not be detailed here.
[0092] It should be understood that the entity executing the security assessment method in this application embodiment can be a security assessment system. This security assessment system can be a system installed in the equipment of a third-party risk assessment agency, or a system installed in the equipment of an organizational entity. If it is a system installed in the equipment of a third-party assessment agency, the aforementioned security data can be obtained from the organizational entity when an assessment is required, or it can be pre-stored in a storage medium, and then the third-party assessment agency can retrieve it from the storage medium and directly call the corresponding security data when an assessment is required.
[0093] Alternatively, if there are many organizations that need to participate in the assessment, and each organization has a different assessment cycle, these organizations can periodically or in real time compile their own security data, package it, and upload it to a shared file system, or they can upload it to a third-party assessment agency. The uploaded security data can be tagged with the respective organization's tags. When security analysts have a security assessment requirement for a particular organization, they can trigger the security assessment operation for that organization in the third-party assessment agency's security assessment system. At this time, the third-party assessment agency can obtain the organization's security data based on the organization's tags for subsequent assessment.
[0094] If the security assessment system is installed in the organization's own security assessment equipment, the security assessment equipment can collect and store security data periodically or in real time. When the organization's security analysts need to conduct a security assessment, they can log in to the security assessment system and then call the corresponding security data for subsequent assessment.
[0095] Step S120: Based on the security data corresponding to each security assessment dimension, obtain the security risk indicator value for the corresponding security assessment dimension.
[0096] For each security assessment dimension, the corresponding security risk indicator value can be obtained. For example, for the cloud security dimension, the corresponding security risk indicator value can be obtained. In this way, the security risk indicator values under each security assessment dimension can be obtained, thereby enabling the security assessment of organizational entities from each security assessment dimension.
[0097] Each security risk indicator value can be used to indicate the security risk situation under the corresponding security assessment dimension. For example, if the security risk indicator value of the cloud security dimension is low, it means that the security risk under the cloud security dimension is relatively large, and subsequent cloud protection needs to be strengthened.
[0098] The security data corresponding to each security assessment dimension can be used to evaluate the risk status of an organizational entity under that security assessment dimension. Therefore, the security data can be converted into corresponding security risk indicator values to reflect the risk status of an organizational entity under each security assessment dimension.
[0099] Step S130: Analyze the security risk situation of the organization's entities based on the security risk index values corresponding to each security assessment dimension.
[0100] After obtaining the security risk index values corresponding to each security assessment dimension, the security risk situation of an organization under each security assessment dimension can be analyzed. For example, if the security risk index value of the cloud security dimension is low, it can be analyzed that the organization's protection in cloud security is relatively weak, and the security risk in this aspect is relatively large. This allows for analysis of the organization's risk situation in a certain aspect. Alternatively, from an overall perspective, if the security risk index values corresponding to each security assessment dimension are all low, it indicates that the organization's overall risk is relatively high, and overall security protection needs to be strengthened.
[0101] In other implementations, when assessing the overall risk of an organization, the security risk index values corresponding to each security assessment dimension can be summed, weighted, averaged, or weighted summed and then averaged. The calculated total index value can be used to assess the overall risk of the organization. For example, the calculated total index value can be directly used as the security risk status of the organization. Alternatively, the security risk index values corresponding to each security assessment dimension can be directly used as the security risk status of the organization. In other implementations, the security risk level of the organization can be assessed based on the obtained total index value. If the total index value is greater than a set threshold, its security risk level is considered low; if the total index value is less than or equal to the set threshold, its security risk level is considered high. Subsequently, the obtained security risk level information can be output to security analysts so that they can understand the security risk status of the organization and improve the defense system accordingly.
[0102] Understandably, the security risk situation of an organization can be characterized by different information, not limited to the total indicator value, the security risk indicator value or security risk level corresponding to each security assessment dimension, etc., as mentioned above. In practical applications, the security risk indicator values corresponding to each security assessment dimension can be flexibly converted into corresponding information to characterize the security risk situation of the organization.
[0103] In the above implementation process, by acquiring security data corresponding to the organization's entity under multiple security assessment dimensions, and based on this security data, the security risk index values of the corresponding security assessment dimensions are obtained to achieve the analysis of the organization's entity's security risk status. The multiple security assessment dimensions include at least two of the following: cloud security dimension, network security dimension, endpoint security dimension, application security dimension, and data security dimension. In this way, the organization's entity can be analyzed from multiple aspects from these security dimensions, achieving a more comprehensive and accurate security risk assessment, so as to more accurately reflect the security status of the organization's entity, and with lower manual costs.
[0104] Based on the above embodiments, if multiple security assessment dimensions include a cloud security dimension, the security risk indicators corresponding to the cloud security dimension may include at least one of cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. In other words, under the cloud security dimension, security risk assessment can be performed using these indicators. Therefore, when obtaining security data under this dimension, security data corresponding to at least one of the following indicators can be obtained: cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators.
[0105] In obtaining security risk indicator values for the cloud security dimension, the risk indicator value corresponding to each indicator can be obtained based on the security data corresponding to each indicator among at least one of the cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. Then, based on the risk indicator values corresponding to each indicator, the security risk indicator value corresponding to the cloud security dimension can be determined.
[0106] As an example, suppose the risk indicator value corresponding to the cloud security product configuration indicator is a1, the risk indicator value corresponding to the cloud security configuration risk indicator is a2, the risk indicator value corresponding to the cloud host vulnerability indicator is a3, and the risk indicator value corresponding to the cloud host alarm indicator is a4. Then, the security risk indicator value A corresponding to the cloud security dimension is A = w1*a1 + w2*a2 + w3*a3 + w4*a4, where wi represents the weight of each indicator, which can be set according to actual experience, and i = 1, 2, 3, 4.
[0107] In other implementations, the security risk indicator value A corresponding to the cloud security dimension can be the average of the risk indicator values corresponding to each indicator, or the average value after weighted summation. The specific calculation formula can be flexibly set according to actual needs.
[0108] In the above implementation process, under the cloud security dimension, corresponding indicator values are obtained from at least one of the following indicators: cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. In this way, the risk status of an organization under the cloud security dimension can be more accurately assessed from multiple indicators.
[0109] Based on the above embodiments, the security data corresponding to the cloud security product configuration indicators includes at least one of the following: the configuration ratio of the website application-level intrusion prevention system (WAF), the configuration status of security audit, and the access ratio of the bastion host; and / or, the security data corresponding to the cloud security configuration risk indicators includes at least one of the following: high-risk access control status, high-risk data security status, and high-risk protection status; and / or, the security data corresponding to the cloud host vulnerability indicators includes the vulnerability status of the host and middleware; and / or, the security data corresponding to the cloud host alarm indicators includes at least one of the following: cloud host alarm status and alarm processing rate.
[0110] Here, the safety data corresponding to each indicator and the calculation formula for the risk index value of each indicator are shown in the table below:
[0111]
[0112] Understandably, the security data corresponding to each of the above secondary indicators are the tertiary indicators in the table above. Each tertiary indicator can be calculated using the corresponding data. For example, the WAF configuration ratio can be obtained by the number of security gateways configured and the number that should be configured. The security audit configuration can be obtained based on the number of security audit configurations and the number that should be configured. The bastion host access ratio can be obtained based on the number of cloud hosts connected to the bastion host and the total number of hosts.
[0113] High-risk access control situations can be identified by the number of high-risk access control situations, high-risk data security situations can be identified by the number of high-risk data security situations, and high-risk protection situations can be identified by the number of high-risk protection situations.
[0114] Vulnerability information for hosts and middleware can be obtained based on the number of vulnerabilities. Cloud host alert information can be obtained based on the number of alerts, and the alert handling rate can be obtained based on the number of alerts processed and the number of alerts pending.
[0115] The table above shows the calculation formula for each tertiary indicator. Based on these formulas, the indicator value for each tertiary indicator can be obtained. However, in practical applications, the specific calculation formula can be flexibly set and is not limited to the formulas given above. Each secondary indicator in the table corresponds to at least one tertiary indicator. When calculating the indicator value for each secondary indicator, the indicator values of the corresponding tertiary indicators can be weighted, summed, or averaged to obtain the indicator value for each secondary indicator. Then, by weighting, summing, or averaging the indicator values of all secondary indicators, the security risk indicator value corresponding to the cloud security dimension can be obtained.
[0116] For example, the corresponding indicator value for the security product configuration indicator in the secondary indicators can be equal to (WAF configuration ratio * m1 + security audit configuration status * m2 + bastion host access ratio * m3), where m1 / m2 / m3 are the weights corresponding to the tertiary indicators, and their weights can be flexibly set according to actual experience.
[0117] Understandably, the safety data corresponding to the above indicators can include more data in practical applications, as long as it can reflect the risk situation of the corresponding indicators.
[0118] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0119] Based on the above embodiments, multiple security assessment dimensions include a network security dimension. The security risk indicators corresponding to the network security dimension include at least one of network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. In other words, under the network security dimension, security risk assessment can be performed using these indicators. Therefore, when obtaining security data under this dimension, security data corresponding to at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators can be obtained.
[0120] In obtaining security risk indicator values for the network security dimension, the risk indicator value corresponding to each indicator can be obtained based on the security data corresponding to each indicator among at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. Then, based on the risk indicator value corresponding to each indicator, the security risk indicator value corresponding to the network security dimension can be determined.
[0121] As an example, suppose the risk index value corresponding to the network security risk index is b1, the risk index value corresponding to the network security operation and maintenance index is b2, and the risk index value corresponding to the network boundary index is b3. Then the security risk index value B corresponding to the network security dimension is B = w1*b1 + w2*b2 + w3*b3, where wi represents the weight of each index, which can be set according to actual experience, i = 1, 2, 3.
[0122] In other implementations, the security risk indicator value B corresponding to the network security dimension can be the average of the risk indicator values corresponding to each indicator, or the average value after weighted summation. The specific calculation formula can be flexibly set according to actual needs.
[0123] In the above implementation process, under the network security dimension, corresponding indicator values are obtained from at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. In this way, the risk situation of an organization entity under the network security dimension can be more accurately assessed from multiple indicators.
[0124] Based on the above embodiments, the security data corresponding to the network security risk indicators includes at least one of network security incidents and potential dangers, and the timely repair rate of network security vulnerabilities; and / or, the security data corresponding to the network boundary indicators includes network unauthorized external connections and / or the offline status and policy configuration status of boundary devices.
[0125] Here, the safety data corresponding to each indicator and the calculation formula for the risk index value of each indicator are shown in the table below:
[0126]
[0127] Understandably, the security data corresponding to each of the above secondary indicators are the tertiary indicators in the table above. Each tertiary indicator can be calculated using its corresponding data. For example, the number of cybersecurity incidents and potential threats can be obtained based on the number of medium- and high-risk threats and the number of cybersecurity incidents. The timely remediation rate of cybersecurity vulnerabilities can be obtained based on the number of vulnerabilities remediated within a set time and the total number of vulnerabilities. The security data corresponding to cybersecurity operation and maintenance indicators can include the types of operation and maintenance completed, and the corresponding indicator values can be obtained based on the types of operation and maintenance completed.
[0128] Information on unauthorized external connections can be obtained based on the number of unauthorized connections. Information on the offline status of border devices and policy configuration can be obtained based on the number of times the border firewall goes offline or the number of times policies are fully configured.
[0129] The table above shows the calculation formula for each tertiary indicator. Based on these formulas, the indicator value for each tertiary indicator can be obtained. However, in practical applications, the specific calculation formula can be flexibly set and is not limited to the formulas given above. Each secondary indicator in the table corresponds to at least one tertiary indicator. When calculating the indicator value for each secondary indicator, the indicator values of the corresponding tertiary indicators can be weighted, summed, or averaged to obtain the indicator value for each secondary indicator. Then, by weighting, summing, or averaging the indicator values of all secondary indicators, the security risk indicator value corresponding to the cybersecurity dimension can be obtained.
[0130] For example, for the cybersecurity risk indicator in the secondary indicators, its corresponding indicator value can be equal to (cybersecurity incidents and potential dangers * m1 + timely cybersecurity vulnerability repair rate * m2), where m1 / m2 is the weight of the tertiary indicator, and its weight can be flexibly set according to actual experience.
[0131] Understandably, the safety data corresponding to the above indicators can include more data in practical applications, as long as it can reflect the risk situation of the corresponding indicators.
[0132] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0133] Based on the above embodiments, multiple security assessment dimensions include a terminal security dimension. The security risk indicators corresponding to the terminal security dimension include at least one of terminal protection capability indicators and terminal virus status indicators. In other words, under the terminal security dimension, security risk assessment can be performed using these indicators. Therefore, when obtaining security data under this dimension, security data corresponding to at least one of the terminal protection capability indicators and terminal virus status indicators can be obtained.
[0134] In the method of obtaining security risk indicator values for the terminal security dimension, the risk indicator value corresponding to each indicator can be obtained based on the security data corresponding to each indicator among at least one of the terminal protection capability indicators and the terminal virus status indicators. Then, based on the risk indicator value corresponding to each indicator, the security risk indicator value corresponding to the terminal security dimension can be determined.
[0135] As an example, assuming the risk index value corresponding to the endpoint protection capability index is c1 and the risk index value corresponding to the endpoint virus situation index is c2, then the security risk index value corresponding to the endpoint security dimension is C = w1*c1 + w2*c2, where w1 represents the weight of each index, which can be set according to actual experience, and i = 1, 2.
[0136] In other implementations, the security risk index value C corresponding to the terminal security dimension can be the average value of the risk index values corresponding to each index, or the average value after weighted summation. The specific calculation formula can be flexibly set according to actual needs.
[0137] In the above implementation process, under the endpoint security dimension, the corresponding indicator value is obtained from at least one of the endpoint protection capability indicators and endpoint virus status indicators, so that the risk status of the organization entity under the endpoint security dimension can be more accurately assessed from multiple indicators.
[0138] Based on the above embodiments, the security data corresponding to the endpoint protection capability index may include the endpoint security protection installation rate, which can be obtained based on the number of endpoints with installed protection software and the total number of endpoints. The security data corresponding to the endpoint virus status index may include the endpoint virus-free rate, which can be obtained based on the number of endpoints that have not been infected by viruses and the total number of endpoints.
[0139] Here, the safety data corresponding to each indicator and the calculation formula for the risk index value of each indicator are shown in the table below:
[0140]
[0141] The table above shows the calculation formula for each tertiary indicator. Based on these formulas, the indicator value for each tertiary indicator can be obtained. However, in practical applications, the specific calculation formula can be flexibly set and is not limited to the formulas given above. Each secondary indicator in the table corresponds to at least one tertiary indicator. When calculating the indicator value for each secondary indicator, the indicator values of the corresponding tertiary indicators can be weighted, summed, or averaged to obtain the indicator value for each secondary indicator. Then, by weighting, summing, or averaging the indicator values of all secondary indicators, the security risk indicator value corresponding to the terminal security dimension can be obtained.
[0142] For example, the endpoint protection capability indicator in the secondary indicators can be equal to the endpoint security protection installation rate, which is equal to the number of endpoints with installed protection software divided by the total number of endpoints.
[0143] Understandably, the safety data corresponding to the above indicators can include more data in practical applications, as long as it can reflect the risk situation of the corresponding indicators.
[0144] Based on the above embodiments, multiple security assessment dimensions include an application security dimension. The security risk indicators corresponding to the application security dimension include at least one of the following: the graded protection security assessment rate indicator, security testing indicators, threat indicators, application remediation indicators, supply chain security indicators, and security operation and maintenance indicators. In other words, under the application security dimension, security risk assessment can be conducted using these indicators. Therefore, when obtaining security data under this dimension, security data corresponding to at least one of the graded protection security assessment rate indicator, security testing indicators, threat indicators, application remediation indicators, supply chain security indicators, and security operation and maintenance indicators can be obtained.
[0145] In obtaining the security risk indicator values for the application security dimension, the risk indicator value corresponding to each indicator can be obtained based on the security data corresponding to each indicator among at least one of the following indicators: security assessment rate of graded protection, security testing indicators, threat indicators, application rectification indicators, supply chain security indicators, and security operation and maintenance indicators. Then, the security risk indicator value corresponding to the application security dimension can be determined based on the risk indicator value corresponding to each indicator.
[0146] As an example, suppose the risk index value corresponding to the security level protection assessment rate is d1, the risk index value corresponding to the security testing index is d2, the risk index value corresponding to the threat index is d3, the risk index value corresponding to the application rectification index is d4, the risk index value corresponding to the supply chain security index is d5, and the risk index value corresponding to the security operation and maintenance index is d6. Then, the security risk index value corresponding to the application security dimension is D = w1*d1 + w2*d2 + w3*d3 + w4*d4 + w5*d5 + w6*d6, where wi represents the weight of each index, which can be set according to actual experience, i = 1, 2, 3, 4, 5, 6.
[0147] In other implementations, the security risk index value D corresponding to the security dimension can be the average of the risk index values corresponding to each index, or the average value after weighted summation. The specific calculation formula can be flexibly set according to actual needs.
[0148] In the above implementation process, under the application security dimension, corresponding indicator values are obtained from at least one of the following indicators: graded protection security assessment rate, security testing indicators, threat indicators, application rectification indicators, supply chain security indicators, and security operation and maintenance indicators. In this way, the risk situation of an organization under the application security dimension can be more accurately assessed from multiple indicators.
[0149] Based on the above embodiments, the security data corresponding to the graded protection security assessment rate index includes at least one of the following: graded protection classification and filing rate, graded protection assessment pass rate, and security assessment rate. The graded protection classification and filing rate is used to characterize whether an application has been classified and filed for graded protection. The security assessment rate is used to characterize the information on the application of domestic cryptography in government information systems at or above the graded protection level for cybersecurity. And / or, the security data corresponding to the threat index includes at least one of the following: high-risk port data, high-risk vulnerability data, high-risk external connection data, and weak password data. And / or, the security data corresponding to the supply chain security index includes construction-related supply chain security data and / or operation and maintenance-related supply chain security data.
[0150] Here, the safety data corresponding to each indicator and the calculation formula for the risk index value of each indicator are shown in the table below:
[0151]
[0152]
[0153] Understandably, the security data corresponding to each of the above secondary indicators are the tertiary indicators in the table above. Each tertiary indicator can be calculated using the corresponding data. For example, the graded protection filing rate can be obtained based on the number of information systems that have been filed and the total number of information systems that should be filed. The graded protection assessment pass rate can be obtained based on the number of information systems that have been assessed as good at level 3 or above and the total number of information systems that have been graded as level 3 or above. The security assessment rate can be obtained based on the number of information systems that have conducted security assessments and the total number of information systems that should conduct security assessments.
[0154] Security testing metrics can be obtained based on the proportion of security tests conducted before deployment.
[0155] High-risk port data can be obtained based on the number of high-risk ports, high-risk vulnerability data can be obtained based on the number of high-risk vulnerabilities, high-risk external connection data can be obtained based on the number of high-risk external connections, and weak password data can be obtained based on the number of times weak passwords have been discovered.
[0156] The rectification indicators can be obtained based on the number of timely rectifications reported within a set time period and the total number of reports.
[0157] Security data for the construction supply chain can be obtained based on the average score of each construction supply chain vendor, while security data for the operation and maintenance supply chain can be obtained based on the average score of each operation and maintenance supply chain vendor.
[0158] Security operation and maintenance metrics can be obtained based on the number of applications with routine security operation and maintenance and the total number of applications.
[0159] The table above shows the calculation formula for each tertiary indicator. Based on these formulas, the indicator value for each tertiary indicator can be obtained. However, in practical applications, the specific calculation formula can be flexibly set and is not limited to the formulas given above. Each secondary indicator in the table corresponds to at least one tertiary indicator. When calculating the indicator value for each secondary indicator, the indicator values of the corresponding tertiary indicators can be weighted, summed, or averaged to obtain the indicator value for each secondary indicator. Then, by weighting, summing, or averaging the indicator values of all secondary indicators, the security risk indicator value corresponding to the application security dimension can be obtained.
[0160] For example, the confidentiality assessment rate of the graded protection system in the secondary indicators can be equal to (graded protection system classification and filing rate * m1 + graded protection system assessment pass rate * m2 + confidentiality assessment rate * m3), where m1 / m2 / m3 are the weights of the tertiary indicators, and their weights can be flexibly set according to actual experience.
[0161] Understandably, the safety data corresponding to the above indicators can include more data in practical applications, as long as it can reflect the risk situation of the corresponding indicators.
[0162] In the above implementation process, the security data corresponding to each indicator is obtained to calculate the corresponding indicator value, which can improve the accuracy of the evaluation of each indicator.
[0163] Based on the above embodiments, multiple security assessment dimensions include a data security dimension. The security risk indicators corresponding to the data security dimension include at least one of data element protection indicators, password security indicators, and access control indicators. In other words, under the data security dimension, security risk assessment can be performed using these indicators. Therefore, when obtaining security data under this dimension, security data corresponding to at least one of the data element protection indicators, password security indicators, and access control indicators can be obtained.
[0164] In obtaining the security risk indicator values for the data security dimension, the risk indicator value corresponding to each indicator can be obtained based on the security data corresponding to each indicator among at least one of the data element protection indicators, password security indicators, and access control indicators. Then, the security risk indicator value corresponding to the data security dimension can be determined based on the risk indicator value corresponding to each indicator.
[0165] As an example, suppose the risk index value corresponding to the data element protection index is e1, the risk index value corresponding to the password security index is e2, and the risk index value corresponding to the access control index is e3. Then the security risk index value E corresponding to the data security dimension is E = w1*e1 + w2*e2 + w3*e3, where wi represents the weight of each index, which can be set according to actual experience, i = 1, 2, 3.
[0166] In other implementations, the security risk index value E corresponding to the data security dimension can be the average of the risk index values corresponding to each index, or the average value after weighted summation. The specific calculation formula can be flexibly set according to actual needs.
[0167] In the above implementation process, under the data security dimension, corresponding indicator values are obtained from at least one of the data element protection indicators, password security indicators, and access control indicators. In this way, the risk situation of an organization entity under the data security dimension can be more accurately assessed from multiple indicators.
[0168] Based on the above embodiments, the security data corresponding to the data element protection indicator may include the public data classification and grading ratio, which can be obtained based on the number of applications that have completed the data classification and grading ratio and the total number of applications. The security data corresponding to the password security indicator may include data lifecycle protection, which can be obtained based on the number of applications that have completed data lifecycle protection and the total number of applications. The security data corresponding to the access control indicator may include database access control data and desktop cloud access control data. Database access control data can be obtained based on the number of applications that have connected to database access control and the total number of applications. Desktop cloud access control data can be obtained based on the number of applications that have connected to desktop cloud access control and the total number of applications.
[0169] Here, the safety data corresponding to each indicator and the calculation formula for the risk index value of each indicator are shown in the table below:
[0170]
[0171] Understandably, the security data corresponding to each of the above secondary indicators are the tertiary indicators in the table above. Each tertiary indicator can be calculated using its corresponding data. The table above shows the calculation formula for each tertiary indicator. Based on this formula, the indicator value for each tertiary indicator can be obtained. Of course, in practical applications, the specific calculation formula can be flexibly set and is not limited to the formula given above. Each secondary indicator in the table above corresponds to at least one tertiary indicator. When calculating the indicator value of each secondary indicator, the indicator values of the corresponding tertiary indicators can be weighted, summed, or averaged to obtain the indicator value for each secondary indicator. Then, by weighting, summing, or averaging the indicator values of each secondary indicator, the security risk indicator value corresponding to the data security dimension can be obtained.
[0172] For example, for the permission control indicator in the secondary indicators, its corresponding indicator value can be equal to (database permission control data * m1 + desktop cloud permission control data * m2), where m1 / m2 is the weight corresponding to the tertiary indicator, and its weight can be flexibly set according to actual experience.
[0173] Understandably, the safety data corresponding to the above indicators can include more data in practical applications, as long as it can reflect the risk situation of the corresponding indicators.
[0174] Based on the above embodiments, when analyzing the security risks of an organizational entity, the target security assessment dimension corresponding to the security risk index value that is less than a set threshold can be determined first, and then the security risk of the organizational entity in the target security assessment dimension can be analyzed.
[0175] Understandably, a security assessment system can provide a display function. After obtaining the security risk indicator values for each security assessment dimension, it can display these values to help security analysts understand the risk situation under each dimension. Alternatively, the system can display the security risk indicator values for each dimension in ascending order, allowing security analysts to quickly focus on the dimensions with lower values and thus concentrate their attention on the risks associated with those dimensions.
[0176] In other implementations, the values of the secondary and tertiary indicators (as shown in the tables above) in each security assessment dimension can also be displayed together during the presentation, so that security analysts can have a detailed understanding of the risk situation of each indicator.
[0177] In other implementations, the security assessment system can directly determine the target security assessment dimension based on the security risk index value that is less than a set threshold, or it can select a preset number of security risk index values with smaller values from the security risk index values and determine the target security assessment dimension corresponding to the security risk index value. For example, if there are a total of 5 security risk index values, the security assessment dimension corresponding to the 3 security risk index values with smaller values can be selected as the target security assessment dimension.
[0178] After determining the target security assessment dimensions, the security risk of an organization within these dimensions can be analyzed. This analysis involves obtaining the corresponding values for each secondary and tertiary indicator within the target security assessment dimensions. By identifying the secondary and tertiary indicators with lower values, it's possible to determine where the organization's protection is weak. For example, if the target security assessment includes a data security dimension, and the secondary indicator for data element protection within this dimension has a low value, as shown in the table above, a low value indicates a low proportion of public data classification and grading, meaning fewer applications have completed data classification and grading. This suggests that the organization's protection in this area is weak, and the risk in this area is significant.
[0179] In the above implementation process, a target security assessment dimension with a security risk index value less than a set threshold is determined. This allows for targeted risk analysis of organizational entities in the target security assessment dimension, enabling security analysts to take targeted protective measures for the organizational entities.
[0180] Based on the above embodiments, after analyzing the security risks of the organization entity in the target security assessment dimension, it is also possible to analyze the reasons for the loss of points in the target security assessment dimension, determine the corresponding processing suggestions based on the reasons for the loss of points, and use the processing suggestions to instruct the organization entity to carry out corresponding security protection.
[0181] In the specific implementation process, a rule base corresponding to the reasons for score deductions and corresponding handling suggestions can be established in advance. The reasons for score deductions in the target security assessment dimensions can be analyzed based on the information in the tables mentioned above. For example, under the data security dimension, if the index value of the data element protection indicator is low, the reason for the score deduction can be analyzed as the number of applications that have completed data classification and grading. The corresponding handling suggestion could be to increase the data classification and grading of applications. In other words, the corresponding reasons for score deductions can be determined by the index value of the target security assessment dimension, and then the corresponding handling suggestions can be found from the rule base.
[0182] In some implementations, corresponding processing suggestions can also be obtained through neural network models. For example, an initial knowledge base can be constructed, including an indicator base, a base for reasons for failing to score, and a base for processing suggestions. The base for reasons for failing to score can be classified according to the problem and its severity. The recommended processing measures in the indicator base and the base for processing suggestions can be initialized first, and then the neural network model can be trained through a supervised learning mechanism to build a connection between the base for reasons for failing to score and the base for processing suggestions.
[0183] During model training, a supervised learning mechanism is used, employing the daily assessment processes and handling suggestions of security service experts as input sources to strengthen the correlation between various issues and handling suggestions. Security service experts evaluate and correct the issues based on the model's suggestions, and then, based on their operation logs, appropriate labels are assigned to form trainable input parameters. This process is iterated repeatedly.
[0184] The neural network model can be a backpropagation (BP) neural network, the structure of which is as follows: Figure 2 As shown, its hidden layers can be set to 3 layers. The specific number of layers can be flexibly set according to actual needs. The input layer is the reason for the loss of points, and the output layer is the processing suggestion.
[0185] In the above implementation process, corresponding handling suggestions are determined based on the reasons for the loss of points. This makes it easier for security analysts to carry out security protection based on the handling suggestions, thereby improving the user experience for security analysts.
[0186] Building upon the above embodiments, if the security assessment system is used by a regulatory body to monitor the security risks of multiple organizational entities, then for each organizational entity, the security risk indicator value corresponding to each security assessment dimension can be obtained using the method described above. Assuming each organizational entity has the aforementioned five security assessment dimensions, the security risk indicator values for these five dimensions can be calculated accordingly for each entity, such as through weighted summation or averaging, to obtain a total indicator value. Thus, each organizational entity corresponds to a total indicator value. The security assessment system can then display either the total indicator value for each organizational entity or the security risk indicator values corresponding to the five security assessment dimensions for each organizational entity. This allows security analysts within the regulatory body to intuitively view the risk situation of each organizational entity.
[0187] Alternatively, if a regulatory authority wants to understand the overall risk of multiple organizations under its supervision, it can calculate the total index values of the multiple organizations accordingly, such as by weighted summation or averaging, to obtain an overall assessment value. This overall assessment value can be used to indicate the overall risk of multiple organizations. For example, if the overall assessment value is low, it indicates that the risks of these organizations are relatively high, and further security protection for the regulated organizations needs to be strengthened.
[0188] Based on the above embodiments, the logic for security assessment of each organizational entity can be as follows: Figure 3 As shown, the risk situation of an organization is analyzed from the dimensions of cloud security, network security, endpoint security, application security, and data security. The corresponding indicator values are obtained by conducting a security index assessment to reflect the risk situation of the organization from various aspects.
[0189] Regarding data sources, different types and focuses of data from various security vendors can be provided and uniformly integrated within the security assessment system. Based on business objectives, a multi-level indicator system is dynamically established, with each indicator having a dynamically configurable calculation formula. Baseline values for the indicators can be dynamically configured according to their business numerical values and meanings. Based on multiple data sources, indicator calculation formulas, and baseline values, the score for each indicator is quantitatively calculated. Multiple indicators are weighted and calculated to obtain the total indicator value.
[0190] It can also automatically update multiple data sources periodically and adjust the calculation formulas, baseline values, and weights of indicators periodically to automatically obtain indicator values for different periods. Furthermore, it can display time-dimensional trends using line charts to reflect changes in the organization's security protection effectiveness over a period of time.
[0191] For each type of indicator and each indicator's deduction items, immediate and clear prompts are provided. In addition, by accumulating historical knowledge, the reasons for deductions for each indicator are analyzed, and handling suggestions are provided, which are automatically sent to the relevant responsible persons via instant messaging methods (such as SMS, email, etc.).
[0192] To help security analysts understand the risk situation of various organizational entities, the overall indicator value, the security risk indicator value of each security assessment dimension, the trend change of the indicator value, the reasons for the failure and the improvement measures (i.e., handling suggestions) can also be output.
[0193] In some implementations, in order to intuitively see the changes in the risk of an organizational entity, the historical security risk of the organizational entity can be obtained, and then the risk change trend of the organizational entity can be obtained based on the historical security risk and the currently obtained security risk.
[0194] The historical security risk information here can be obtained from security assessments of the organization over a historical period. This historical security risk information can include the security risk indicator values of various security assessment dimensions obtained by the organization over the historical period and / or the total indicator values obtained. For example, the security assessment system can conduct security assessments of the organization every month or week, and then store the various indicator values obtained from the assessment for trend analysis.
[0195] Risk change trends can characterize the changes in an organization's risk over a period of time. For example, a trend chart can be generated by comparing the total indicator values from historical security risk data with the currently obtained total indicator values over time. This trend chart can be provided to security analysts, allowing them to visually observe the changes in the organization's total indicator values. If the total indicator value is continuously decreasing, it indicates that the organization's risk is gradually increasing, requiring further strengthening of protective measures. Alternatively, trend charts can be generated for the indicator values of each security assessment dimension. This allows them to see the changes in the organization's risk under each security assessment dimension, enabling security analysts to take targeted protective measures.
[0196] In the above implementation process, by obtaining the risk change trend of the organizational entity, it is easier to analyze the overall risk change of the organizational entity, and thus more accurately grasp the risk situation of the organizational entity.
[0197] The overall architecture of the security assessment system can be as follows: Figure 4 As shown, it includes several modules: basic support, indicator maintenance, task management, indicator calculation, processing suggestion provision, and visualization.
[0198] The basic support module includes a data source (used to store various security data), a security index indicator system (i.e., the indicators in the tables in the above embodiments), a database of reasons for failure, and a database of processing suggestions.
[0199] The indicator maintenance module is used to maintain the indicator system and indicator calculation logic. The indicator system maintenance refers to the maintenance and explanation of the first-level indicators, second-level indicators, third-level indicators, data sources and calculation formulas. The indicator calculation logic includes the calculation of indicator values and benchmark values, the upper limit of scores using "+, -, ×, ÷", or the judgment of "≥, <, >, ≤, =, ≠".
[0200] The task management module supports automatic or manual creation of security index assessment tasks and maintenance of task content. Automatic task creation means the security assessment system can automatically initiate security assessment tasks for organizational entities at regular intervals, such as automatically creating tasks at the end of the month. These newly created tasks can reference relevant data used in the previous assessment, such as the security assessment dimensions and indicators used in the previous assessment. Automatically created tasks allow for modification of relevant information within a certain period, and the corresponding assessment task can be automatically issued when the assessment time arrives.
[0201] Manual task creation refers to security analysts initiating security assessment tasks on organizational entities themselves. Manual task creation supports the selection of organizational entities (i.e., custom selection of organizational entities to be assessed), setting of excellent, good, fair, and poor levels, selection of indicators (i.e., selection of indicators corresponding to each security assessment dimension), setting of the weight of each indicator, and issuing the task.
[0202] The indicator calculation module is used to calculate indicators for a specific organizational entity. It calculates the indicator value of each indicator and the total indicator value through data source docking or manual maintenance. For example, for indicators that can automatically obtain data sources, the score can be automatically calculated by using multiple data sources connected to each indicator and its underlying calculation formula. For indicators that cannot be docked with data sources, the score can be automatically calculated by organizing, maintaining or adjusting the current indicator value offline.
[0203] The specific algorithm is as follows:
[0204] Step 1: Start the scheduled task. The offline computing engine will obtain the security data corresponding to each indicator in 5-minute, hourly, daily, weekly, and monthly dimensions.
[0205] Step 2: Initialize the classification and calculation formula of each indicator x, fax(x), and weight w;
[0206] Step 3: Calculate the score of each unit sum(xi*wi*fax(x)) according to the five dimensions of cloud-network-terminal-data-application (c). Some indicators may need to be maintained manually. Fax needs to be obtained from alarm logs and business processing database according to the statistical period based on the definition of each indicator. Indicators with low scores will be tagged.
[0207] Step 4: Calculate the security index score for each unit u sum(ci*xi*wi*fax(x)), where ci represents the weight of the corresponding dimension;
[0208] Step 5: Calculate the current total security index sum(ui*ci*xi*wi*fax(x)), which is the comprehensive index value of each unit.
[0209] Here, the output can be displayed at different time granularities.
[0210] The handling suggestion module can analyze the problems existing in an organization's entities for each indicator, using an indicator library, a library of reasons for failure, and a library of handling suggestions, combined with a neural network model. It can also identify the reasons for failure based on the indicator values and the correlation between attacks across several dimensions, providing targeted handling suggestions to assist security analysts in taking appropriate measures.
[0211] For example, during an attack, security analysts noticed low scores on endpoints, data, and applications based on metrics. Further analysis revealed that the attackers phished clients via email, implanted malware, and then sent important files out. Tracing the source also revealed that the attackers had performed multiple scans before the attack. Analyzing the entire attack chain showed that the attackers simultaneously targeted endpoints, applications, and data, with the data being the primary objective.
[0212] For example, ransomware attacks primarily employ brute-force attacks, unauthorized operations, phishing emails, vulnerability exploitation, and vulnerability scanning. Once a ransomware attack is launched, attackers will conduct extensive scans of the client's network. This will result in a low score for the "network" security indicator in the security assessment. After obtaining user / password information, attackers will compromise the terminal or server, leading to a low score for the "terminal" related indicator in the security assessment. Once inside the server, attackers will encrypt sensitive data to carry out ransomware attacks, resulting in a very low score for the "data" related indicator in the security assessment. Therefore, by examining the indicators across various dimensions, ransomware attacks involve three dimensions: "network," "terminal," and "data." Conversely, security analysts can also trace parts of the attack process through the analysis of indicator scores. By analyzing the correlation between "cloud-network-terminal-data-application" indicators, better overall defense measures can be provided.
[0213] The visualization module visually represents security risks, including security risk indicator values, overall indicator values, risk trends, handling suggestions, and reasons for score deductions for each security assessment dimension. During display, the overall indicator value and risk level (good, excellent, average, poor) are centered for easy viewing by security analysts. The primary indicators—cloud security, network security, endpoint security, application security, and data security—can rotate around the central display, showing their scores / maximum values. When rotating a primary indicator, the scores / maximum values of its secondary indicators are also displayed synchronously. Regarding trend representation, when interacting with the overall indicator value, or the values of a specific primary or secondary indicator, a line graph can be used to reflect the trend of the score over a certain period, illustrating the risk situation during the process. For providing suggestions to aid decision-making, the module visually displays low-scoring items (i.e., indicators with low scores), the reasons for the low scores, and systematically presents overall and detailed handling suggestions.
[0214] Please refer to Figure 5 , Figure 5 This is a structural block diagram of a security assessment device 200 provided in an embodiment of this application. The device 200 may be a module, program segment, or code on an electronic device. It should be understood that this device 200 is similar to the one described above. Figure 1 The method implementation corresponds to this and can be executed. Figure 1 The various steps involved in the method embodiment and the specific functions of the device 200 can be found in the description above. To avoid repetition, detailed descriptions are omitted here.
[0215] Optionally, the device 200 includes:
[0216] The data acquisition module 210 is used to acquire security data corresponding to organizational entities under multiple security assessment dimensions, wherein the multiple security assessment dimensions include at least two of cloud security dimension, network security dimension, terminal security dimension, application security dimension and data security dimension;
[0217] The indicator value acquisition module 220 is used to acquire the security risk indicator value of the corresponding security assessment dimension based on the security data corresponding to each security assessment dimension.
[0218] The risk analysis module 230 is used to analyze the security risk status of the organization entity based on the security risk index values corresponding to each security assessment dimension.
[0219] Optionally, the multiple security assessment dimensions include a cloud security dimension, and the security risk indicators corresponding to the cloud security dimension include at least one of cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. The data acquisition module 210 is used to acquire security data corresponding to at least one of the cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators.
[0220] And / or, the indicator value acquisition module 220 is used to acquire the risk indicator value corresponding to each indicator based on the security data corresponding to each indicator among at least one of the cloud security product configuration indicators, the cloud security configuration risk indicators, the cloud host vulnerability indicators, and the cloud host alarm indicators; and to determine the security risk indicator value corresponding to the cloud security dimension based on the risk indicator value corresponding to each indicator.
[0221] Optionally, the security data corresponding to the cloud security product configuration indicators includes at least one of the following: website application-level intrusion prevention system (WAF) configuration ratio, security audit configuration status, and bastion host access ratio.
[0222] And / or, the security data corresponding to the cloud security configuration risk indicators includes at least one of the following: high-risk access control situation, high-risk data security situation, and high-risk protection status situation;
[0223] And / or, the security data corresponding to the cloud host vulnerability index includes the vulnerability status of the host and middleware;
[0224] And / or, the security data corresponding to the cloud host alarm indicators includes at least one of cloud host alarm status and alarm processing rate.
[0225] Optionally, the plurality of security assessment dimensions include a network security dimension, and the security risk indicators corresponding to the network security dimension include at least one of network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. The data acquisition module 210 is used to acquire security data corresponding to at least one of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators.
[0226] And / or, the indicator value acquisition module 220 is used to acquire the risk indicator value corresponding to each indicator based on the security data corresponding to each indicator among at least one of the network security risk indicators, the network security operation and maintenance indicators, and the network boundary indicators; and to determine the security risk indicator value corresponding to the network security dimension based on the risk indicator value corresponding to each indicator.
[0227] Optionally, the security data corresponding to the network security risk indicators includes at least one of network security incidents and potential dangers, and the timely repair rate of network security vulnerabilities;
[0228] And / or, the security data corresponding to the network boundary indicators includes unauthorized external network connections and / or the offline status and policy configuration status of boundary devices.
[0229] Optionally, the plurality of security assessment dimensions include a terminal security dimension, and the security risk indicators corresponding to the terminal security dimension include at least one of terminal protection capability indicators and terminal virus status indicators. The data acquisition module 210 is used to acquire security data corresponding to at least one of the terminal protection capability indicators and terminal virus status indicators.
[0230] And / or, the indicator value acquisition module 220 is used to acquire the risk indicator value corresponding to each indicator based on the security data corresponding to each indicator in at least one of the terminal protection capability indicators and the terminal virus status indicators; and to determine the security risk indicator value corresponding to the terminal security dimension based on the risk indicator value corresponding to each indicator.
[0231] Optionally, the multiple security assessment dimensions include an application security dimension, and the security risk indicators corresponding to the application security dimension include at least one of the following: graded protection security assessment rate indicator, security testing indicator, threat indicator, application rectification indicator, supply chain security indicator, and security operation and maintenance indicator. The data acquisition module 210 is used to acquire security data corresponding to at least one of the following indicators: graded protection security assessment rate indicator, security testing indicator, threat indicator, application rectification indicator, supply chain security indicator, and security operation and maintenance indicator.
[0232] And / or, the indicator value acquisition module 220 is used to acquire the risk indicator value corresponding to each indicator based on the security data corresponding to each indicator among at least one of the graded protection security assessment rate indicator, the security test indicator, the threat indicator, the application rectification indicator, the supply chain security indicator, and the security operation and maintenance indicator; and to determine the security risk indicator value corresponding to the application security dimension based on the risk indicator value corresponding to each indicator.
[0233] Optionally, the security data corresponding to the graded protection security assessment rate index includes at least one of the graded protection classification and filing rate, graded protection assessment pass rate, and security assessment rate;
[0234] And / or, the security data corresponding to the threat indicators includes at least one of high-risk port data, high-risk vulnerability data, high-risk external connection data, and weak password data;
[0235] And / or, the security data corresponding to the supply chain security indicators include construction-related supply chain security data and / or operation and maintenance-related supply chain security data.
[0236] Optionally, the plurality of security assessment dimensions include a data security dimension, and the security risk indicators corresponding to the data security dimension include at least one of data element protection indicators, password security indicators, and access control indicators. The data acquisition module 210 is used to acquire security data corresponding to at least one of the data element protection indicators, password security indicators, and access control indicators.
[0237] And / or, the indicator value acquisition module 220 is used to acquire the risk indicator value corresponding to each indicator based on the security data corresponding to each indicator among at least one of the data element protection indicators, the password security indicators, and the access control indicators; and to determine the security risk indicator value corresponding to the data security dimension based on the risk indicator value corresponding to each indicator.
[0238] Optionally, the risk analysis module 230 is used to determine the target security assessment dimension corresponding to the security risk index value that is less than a set threshold among the security risk index values; and to analyze the security risk situation of the organization entity in the target security assessment dimension.
[0239] Optionally, the device 200 further includes:
[0240] The processing suggestion module is used to analyze the reasons for the loss of points in the target security assessment dimension; and to determine the corresponding processing suggestions based on the reasons for the loss of points. The processing suggestions are used to instruct the organization entity to carry out corresponding security protection.
[0241] Optionally, the device 200 further includes:
[0242] The trend analysis module is used to obtain the historical security risk information of the organization entity; and to obtain the risk change trend of the organization entity based on the historical security risk information and the currently obtained security risk information.
[0243] It should be noted that those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0244] Please refer to Figure 6 , Figure 6This is a schematic diagram of an electronic device for performing a security assessment method, provided in an embodiment of this application. The electronic device may include: at least one processor 310, such as a CPU; at least one communication interface 320; at least one memory 330; and at least one communication bus 340. The communication bus 340 is used to establish communication between these components. In this embodiment, the communication interface 320 is used for signaling or data communication with other node devices. The memory 330 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 330 may also be at least one storage device located remotely from the aforementioned processor. The memory 330 stores computer-readable instructions. When these computer-readable instructions are executed by the processor 310, the electronic device performs the aforementioned... Figure 1 The method and process are shown.
[0245] Understandable. Figure 6 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 6 The more or fewer components shown, or having the same Figure 6 The different configurations shown. Figure 6 The components shown can be implemented using hardware, software, or a combination thereof.
[0246] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, performs the following... Figure 1 The method process executed by the electronic device in the illustrated method embodiment.
[0247] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can perform the methods provided in the above-described method embodiments, such as including:
[0248] Obtain security data for organizational entities across multiple security assessment dimensions, wherein the multiple security assessment dimensions include at least two of the following: cloud security dimension, network security dimension, endpoint security dimension, application security dimension, and data security dimension;
[0249] Based on the security data corresponding to each security assessment dimension, obtain the security risk indicator value for the corresponding security assessment dimension;
[0250] The security risk situation of the organization entity is analyzed based on the security risk index value corresponding to each security assessment dimension.
[0251] In summary, the embodiments of this application provide a security assessment method, apparatus, electronic device, and storage medium. By acquiring security data corresponding to an organizational entity under multiple security assessment dimensions, and obtaining security risk index values for the corresponding security assessment dimensions based on this security data, the security risk status of the organizational entity can be analyzed. The multiple security assessment dimensions include at least two of cloud security, network security, endpoint security, application security, and data security dimensions. This allows for multi-faceted security risk analysis of the organizational entity from these security dimensions, achieving a more comprehensive and accurate security risk assessment to more accurately reflect the security status of the organizational entity, while also reducing labor costs.
[0252] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0253] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0254] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0255] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0256] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A safety assessment method, characterized in that, The method includes: The system acquires security data for organizational entities across multiple security assessment dimensions, including cloud security, network security, endpoint security, application security, and data security. The cloud security dimension includes security risk indicators such as cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. The network security dimension includes network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. The endpoint security dimension includes endpoint protection capability indicators and endpoint virus status indicators. The application security dimension includes security risk indicators such as the security level protection assessment rate, security testing indicators, threat indicators, application remediation indicators, supply chain security indicators, and security operation and maintenance indicators. The data security dimension includes data element protection indicators, password security indicators, and access control indicators. Based on the security data corresponding to each security assessment dimension, obtain the security risk indicator value for the corresponding security assessment dimension; Analyze the security risk status of the organization entity based on the security risk index values corresponding to each security assessment dimension; The step of obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each indicator in the security risk indicators of each security assessment dimension, obtain the security risk indicator value of the corresponding security assessment dimension.
2. The method according to claim 1, characterized in that, The acquisition of security data for organizational entities across multiple security assessment dimensions includes: Obtain the security data corresponding to each indicator in the cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators; And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each of the cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators, obtain the risk indicator value corresponding to each indicator; Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the cloud security dimension is determined.
3. The method according to claim 2, characterized in that, The security data corresponding to the cloud security product configuration indicators include at least one of the following: website application-level intrusion prevention system (WAF) configuration ratio, security audit configuration status, and bastion host access ratio. And / or, the security data corresponding to the cloud security configuration risk indicators includes at least one of the following: high-risk access control situation, high-risk data security situation, and high-risk protection status situation; And / or, the security data corresponding to the cloud host vulnerability index includes the vulnerability status of the host and middleware; And / or, the security data corresponding to the cloud host alarm indicators includes at least one of cloud host alarm status and alarm processing rate.
4. The method according to claim 1, characterized in that, The acquisition of security data for organizational entities across multiple security assessment dimensions includes: Obtain the security data corresponding to each indicator among the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators; And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each of the network security risk indicators, network security operation and maintenance indicators, and network boundary indicators, obtain the risk indicator value corresponding to each indicator; Based on the risk indicator value corresponding to each indicator, the security risk indicator value corresponding to the network security dimension is determined.
5. The method according to claim 4, characterized in that, The security data corresponding to the network security risk indicators include at least one of the following: network security incidents and potential dangers, and the timely remediation rate of network security vulnerabilities. And / or, the security data corresponding to the network boundary indicators includes unauthorized external network connections and / or the offline status and policy configuration status of boundary devices.
6. The method according to claim 1, characterized in that, The acquisition of security data for organizational entities across multiple security assessment dimensions includes: Obtain the security data corresponding to each indicator in the terminal protection capability index and the terminal virus status index; And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each of the terminal protection capability indicators and the terminal virus status indicators, obtain the risk indicator value corresponding to each indicator; Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the terminal security dimension is determined.
7. The method according to claim 1, characterized in that, The acquisition of security data for organizational entities across multiple security assessment dimensions includes: Obtain the security data corresponding to each indicator among the graded protection security assessment rate indicator, the security test indicator, the threat indicator, the application rectification indicator, the supply chain security indicator, and the security operation and maintenance indicator; And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each of the following indicators: the security assessment rate of graded protection, the security test indicator, the threat indicator, the application rectification indicator, the supply chain security indicator, and the security operation and maintenance indicator, obtain the risk indicator value corresponding to each indicator; Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the application security dimension is determined.
8. The method according to claim 7, characterized in that, The security data corresponding to the graded protection security assessment rate index includes at least one of graded protection classification and filing rate, graded protection assessment pass rate and security assessment rate. And / or, the security data corresponding to the threat indicators includes at least one of high-risk port data, high-risk vulnerability data, high-risk external connection data, and weak password data; And / or, the security data corresponding to the supply chain security indicators include construction-related supply chain security data and / or operation and maintenance-related supply chain security data.
9. The method according to claim 1, characterized in that, The acquisition of security data for organizational entities across multiple security assessment dimensions includes: Obtain the security data corresponding to each indicator among the data element protection indicator, the password security indicator, and the access control indicator; And / or, obtaining the security risk indicator value for each security assessment dimension based on the security data corresponding to each security assessment dimension includes: Based on the security data corresponding to each of the data element protection indicators, the password security indicators, and the access control indicators, obtain the risk indicator value corresponding to each indicator; Based on the risk index value corresponding to each indicator, the security risk index value corresponding to the data security dimension is determined.
10. The method according to any one of claims 1-9, characterized in that, The analysis of the security risk status of the organizational entity based on the security risk index values corresponding to each security assessment dimension includes: Determine the target security assessment dimension corresponding to the security risk index values that are below a set threshold; Analyze the security risks of the organization entity in the target security assessment dimension.
11. The method according to claim 10, characterized in that, After analyzing the security risk situation of the organizational entity in the target security assessment dimension, the analysis also includes: Analyze the reasons for the loss of points in the aforementioned target security assessment dimensions; Based on the reasons for the loss of points, corresponding processing recommendations are determined, and these recommendations are used to instruct the organization entity to take appropriate security measures.
12. The method according to any one of claims 1-9, characterized in that, After analyzing the security risk status of the organizational entity based on the security risk index values corresponding to each security assessment dimension, the process further includes: Obtain the historical security risk information of the organization entity; Based on the historical security risk situation and the current security risk situation, obtain the risk change trend of the organization entity.
13. A safety assessment device, characterized in that, The device includes: The data acquisition module is used to acquire security data corresponding to organizational entities under multiple security assessment dimensions. These multiple security assessment dimensions include cloud security, network security, endpoint security, application security, and data security. The security risk indicators corresponding to the cloud security dimension include cloud security product configuration indicators, cloud security configuration risk indicators, cloud host vulnerability indicators, and cloud host alarm indicators. The security risk indicators corresponding to the network security dimension include network security risk indicators, network security operation and maintenance indicators, and network boundary indicators. The security risk indicators corresponding to the endpoint security dimension include endpoint protection capability indicators and endpoint virus status indicators. The security risk indicators corresponding to the application security dimension include graded protection security assessment rate indicators, security testing indicators, threat indicators, application remediation indicators, supply chain security indicators, and security operation and maintenance indicators. The security risk indicators corresponding to the data security dimension include data element protection indicators, password security indicators, and access control indicators. The indicator value acquisition module is used to obtain the security risk indicator value of the corresponding security assessment dimension based on the security data corresponding to each security assessment dimension. The risk analysis module is used to analyze the security risk status of the organization entity based on the security risk indicator values corresponding to each security assessment dimension. The indicator value acquisition module is used to obtain the security risk indicator value of the corresponding security assessment dimension based on the security data corresponding to each indicator in the security risk indicators of each security assessment dimension.
14. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer-readable instructions that, when executed by the processor, perform the method as described in any one of claims 1-12.
15. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it performs the method as described in any one of claims 1-12.
16. A computer program product, characterized in that, It includes computer program instructions, which, when read and executed by a processor, perform the method as described in any one of claims 1-12.
Citation Information
Patent Citations
Cloud security evaluation system and method
CN109379373A
Network system security evaluation method and device, electronic equipment and medium
CN112702366A
Network security protection security method and system based on unit cell
CN114978584A