A cloud-edge-end power internet of things vulnerability hazard assessment method and system
By employing the entropy weight method and multi-dimensional assessment, and combining vulnerability type, time impact, and network asset risk, the accuracy and reliability issues of vulnerability assessment in cloud-edge-device power Internet of Things systems in existing technologies have been resolved, achieving a more objective and comprehensive assessment of the severity of vulnerabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-07
- Publication Date
- 2026-03-17
AI Technical Summary
Existing vulnerability assessment methods cannot accurately assess the vulnerability severity of cloud-edge-device power Internet of Things systems, and they ignore the changes in the speed of vulnerability exploitation with social development and the impact of time factors, resulting in poor assessment accuracy and reliability.
The entropy weight method is used to calculate the weights of influencing factors and exploitability factors. Combining vulnerability type, time impact, and network asset risk, the severity level of the vulnerability is comprehensively assessed through basic characteristic assessment, time impact assessment, and network asset risk assessment.
It improves the accuracy and reliability of vulnerability assessment, reduces subjectivity, ensures that the assessment results are consistent with the actual situation, and comprehensively considers the harm of vulnerabilities to the cloud-edge-device power Internet of Things system.
Smart Images

Figure CN118784353B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of Internet of Things (IoT) security technology, and specifically relates to a vulnerability assessment method and system for cloud-edge-device power IoT. Background Technology
[0002] Vulnerability assessment technology involves in-depth analysis of identified vulnerabilities to determine their threat level and potential impact on system security. The assessment process considers factors such as the difficulty of exploiting the vulnerability, the privileges an attacker might gain, and the potential consequences of vulnerability exploitation. Its purpose is to help enterprises or organizations improve system security and reliability, and reduce potential losses caused by vulnerability exploitation.
[0003] Currently, the most common vulnerability assessment technology uses the Common Vulnerability Scoring System (CVSS) for vulnerability severity assessment. Other methods include vulnerability assessment based on the Analytic Hierarchy Process (AHP) and fuzzy comprehensive evaluation. Domestic and international vulnerability databases (NVD and CNVD) use the basic scoring group of CVSS as the assessment standard for severity levels. However, due to its universality, this method cannot comprehensively reflect the severity of vulnerabilities in all system environments, and its assessment method is too singular and fixed, resulting in low accuracy. The AHP-based vulnerability assessment method can systematically analyze complex targets, but its analysis process relies heavily on expert experience, leading to a high degree of subjectivity in the assessment results. Furthermore, the fuzzy comprehensive evaluation method may affect the discriminative power of the assessment results if it does not fully consider the information content of the evaluation object's indicators. In addition, traditional methods do not consider the impact of the time factor of vulnerability disclosure on the system, ignoring the phenomenon that the speed of vulnerability exploitation increases with social development, which makes the method less scientific and accurate.
[0004] The cloud-edge-device power IoT system is a power system network architecture primarily composed of a distribution network cloud platform, edge IoT agents, and intelligent power distribution equipment. The cloud, edge, and device components each have their own roles and work in close coordination. If one device is attacked, the other two may also be affected, leading to significant losses. Currently, the vulnerability assessment methods mentioned above are not well-suited for cloud-edge-device power IoT systems, exhibiting poor accuracy and reliability in assessment. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a vulnerability assessment method and system for cloud-edge-device power IoT, which comprehensively evaluates the severity level of target vulnerabilities in the cloud-edge-device power IoT system.
[0006] To solve the above-mentioned technical problems, the present invention adopts the following technical solution.
[0007] This invention first discloses a vulnerability assessment method for cloud-edge-device power Internet of Things (IoT), which includes the following steps:
[0008] Step S110: Determine the impact factor score and exploitability factor score of the target vulnerability based on the vulnerability type of the target vulnerability, calculate the weight of the impact factor and exploitability factor using the entropy weight method, and determine the basic characteristic evaluation value of the target vulnerability based on the impact factor score, exploitability factor score and corresponding weight.
[0009] Step S120: Determine the time impact assessment value of the target vulnerability based on the average time of its exploitation and the number of days since its disclosure.
[0010] Step S130: Obtain the data value of the cloud server, the computing resource value of the edge server, and the device utilization rate of the terminal device. Combine the deployment quantity and business value of each device in the cloud-edge-terminal system to calculate the value of the cloud server, the value of the edge server, and the value of the terminal. Based on the bidirectional penetration attack graph and the values of the cloud server, the edge server, and the terminal, determine the network asset risk assessment value of the target vulnerability.
[0011] Step S140: Based on the basic characteristic assessment value, time impact assessment value, and network asset risk assessment value, assess the severity level of the target vulnerability.
[0012] The present invention further includes the following preferred embodiments:
[0013] The determination of the impact factor score and exploitability factor score of the target vulnerability further includes:
[0014] The impact factor scores of the target vulnerability are determined based on confidentiality, integrity, and availability.
[0015] The exploitability factor score of the target vulnerability is determined based on the attack path, attack complexity, and identity authentication.
[0016] The calculation of the weights of influencing factors and availability factors using the entropy weight method further includes:
[0017] The collected sample dataset is normalized:
[0018]
[0019] In the formula, x m Let be the feature value of the m-th factor in the sample data, max be the maximum value of the sample data, and min be the minimum value of the sample data;
[0020] Based on the normalized dataset, calculate the information entropy of influencing factors and availability factors:
[0021]
[0022] e j Let P be the information entropy of the j-th factor in the sample data, n be the number of sample data, and P be the information entropy of the j-th factor. i,j The probability of the i-th sample occurring under the j-th factor in the sample data:
[0023]
[0024] Based on the information entropy of influencing factors and availability factors, calculate the evaluation weights of influencing factors and availability factors:
[0025]
[0026] In the formula, w j e represents the evaluation weight of the j-th factor among the influencing factors and the availability factors. i e j The information entropy is defined as the influencing factors and the available factors.
[0027] The determination of the time impact assessment value of the target vulnerability further includes:
[0028] Calculate the impact of time on the assessment value:
[0029]
[0030] Where d is the number of days since the target vulnerability was disclosed, and t is the average time it takes for the collected vulnerability to be exploited.
[0031] The determination of the network asset risk assessment value of the target vulnerability further includes:
[0032] Calculate the Network Asset Risk Assessment Value (NAV):
[0033]
[0034] In the formula, P C P represents the probability of cloud server risks occurring. E P represents the probability of edge server risk occurring. T E1 represents the probability of an endpoint risk occurring. This probability is the success rate of an attacker attacking the primary target, i.e., the probability that the device containing the vulnerability will be at risk due to the target vulnerability. E2 represents an event where an endpoint penetrates and attacks an edge server, E3 represents an event where an edge server penetrates and attacks a cloud server, and E4 represents an event where an edge server penetrates and attacks an endpoint.
[0035] This invention also discloses a vulnerability assessment system for cloud-edge-device power IoT that utilizes the aforementioned vulnerability assessment method, comprising:
[0036] The basic characteristic assessment module is used to determine the impact factor score and exploitability factor score of the target vulnerability based on the vulnerability type of the target vulnerability, calculate the weight of the impact factor and exploitability factor using the entropy weight method, and determine the basic characteristic assessment value of the target vulnerability based on the impact factor score, exploitability factor score and corresponding weight.
[0037] The time impact assessment module is used to determine the time impact assessment value of the target vulnerability based on the average time of the exploitation of the target vulnerability and the number of days since the target vulnerability was disclosed.
[0038] The network asset risk assessment module is used to obtain the data value of cloud servers, the computing resource value of edge servers, and the device utilization rate of terminal devices. It calculates the value of cloud servers, edge servers, and terminals by combining the deployment quantity and business value of each device in the cloud-edge-terminal system. Based on the bidirectional penetration attack graph and the values of cloud servers, edge servers, and terminals, it determines the network asset risk assessment value of the target vulnerability.
[0039] The comprehensive assessment module is used to assess the severity level of the target vulnerability based on the basic characteristic assessment value, time impact assessment value, and network asset risk assessment value.
[0040] Accordingly, this application also discloses a terminal, including a processor and a storage medium;
[0041] The storage medium is used to store instructions;
[0042] The processor is configured to operate according to the instructions to perform the steps of the aforementioned cloud-edge-device power Internet of Things vulnerability hazard assessment method.
[0043] Accordingly, this application also discloses a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the aforementioned cloud-edge-device power Internet of Things vulnerability hazard assessment method.
[0044] The beneficial effects of this invention are as follows: Compared with the prior art, this invention provides a vulnerability hazard assessment method and system for cloud-edge-device power IoT. It comprehensively assesses the harm caused by target vulnerabilities to the cloud-edge-device power IoT system from multiple perspectives, considers the correlation between vulnerability type and vulnerability impact factors and exploitability factors, uses the entropy weight method to reduce the subjectivity of the assessment, making the assessment more objective, assesses the time impact of target vulnerabilities based on the average time required for current social vulnerability exploitation, considers the correlation between the duration of vulnerability disclosure and the resulting risk, and analyzes the risk of vulnerabilities to assets based on the respective value characteristics of cloud, edge, and device devices. This effectively improves the completeness and richness of vulnerability assessment methods, and ultimately comprehensively assesses the harm of vulnerabilities to the cloud-edge-device power IoT system. It does not rely excessively on subjective human assessment experience and can ensure that the assessed vulnerability hazard level matches the actual vulnerability situation, thereby significantly improving the accuracy and reliability of cloud-edge-device power IoT vulnerability assessment. Attached Figure Description
[0045] Figure 1 This is a flowchart of the vulnerability assessment method for cloud-edge-device power Internet of Things in this invention.
[0046] Figure 2 This is an exemplary two-way penetration attack diagram of the comprehensive assessment method for vulnerabilities in the cloud-edge-device power Internet of Things in this invention. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0048] The embodiments described in this application are merely some, not all, embodiments of the present invention. Based on the spirit of the present invention, other embodiments obtained by those skilled in the art without inventive effort are all within the protection scope of the present invention.
[0049] To address the shortcomings of existing technologies, this invention proposes a vulnerability hazard assessment method and system for cloud-edge-device power IoT systems. By determining the basic characteristic assessment value, time impact assessment value, and network asset risk assessment value of the target vulnerability, the hazard level of the target vulnerability in the cloud-edge-device power IoT system is comprehensively evaluated. On the one hand, considering the correlation between vulnerability type and vulnerability impact factors and exploitability factors, the entropy weight method is used to assess the basic characteristics of the target vulnerability, reducing the subjectivity of the assessment. On the other hand, considering the correlation between the duration of vulnerability disclosure and the resulting risk, the time impact of the target vulnerability is assessed based on the average time required for current social vulnerability exploitation. Furthermore, based on the respective value characteristics of cloud, edge, and device devices and the two-way penetration attack graph, the risk of the vulnerability to assets is analyzed. Finally, the overall hazard of the vulnerability to the cloud-edge-device power IoT system is comprehensively assessed.
[0050] See Figure 1 As shown, the vulnerability assessment method for cloud-edge-device power Internet of Things disclosed in this invention includes the following steps:
[0051] Step S110: Determine the impact factor score and exploitability factor score of the target vulnerability based on the vulnerability type of the target vulnerability, calculate the weight of the impact factor and exploitability factor using the entropy weight method, and determine the basic characteristic evaluation value of the target vulnerability based on the impact factor score, exploitability factor score and corresponding weight.
[0052] Specifically, based on the method of attack, the type characteristics of the target vulnerability are first determined, and the impact factor score (IS) and exploitability factor score (ES) of the target vulnerability are determined.
[0053] For example, in this embodiment, the calculation method of the CVSS basic scoring group is used to calculate the impact factor score and exploitability factor score of the target vulnerability. The weight scores of the relevant scoring items are shown in Table 1:
[0054] Scoring Indicators Scoring Items Weight score Confidentiality (C) None, Part, All 0.0、0.275、0.660 Integrity (I) None, Part, All 0.0、0.275、0.660 Availability (A) None, Part, All 0.0、0.275、0.660 Attack Pathway (AV) Local, neighboring, remote 0.395、0.646、1 Attack complexity (AC) High, Medium, Low 0.35、0.61、0.71 Identity Authentication (AU) Multiple times, single time, none 0.45、0.56、0.704
[0055] Table 1
[0056] Among them, confidentiality (C), integrity (I), and availability (A) are the scoring indicators for the impact factors of the target vulnerability. Confidentiality is used to measure the potential impact on the confidentiality of information after the vulnerability is exploited; integrity is used to measure the potential impact on the accuracy and consistency of data or systems after the vulnerability is exploited; and availability is used to measure the potential impact on the normal operation and access of systems or information after the vulnerability is exploited.
[0057] Attack path (AV), attack complexity (AC), and authentication (AU) are scoring metrics for exploitability factors of a target vulnerability. Attack path reflects the entry point or medium through which an attacker exploits the vulnerability; attack complexity measures the skill level, resources, time, and effort required for an attacker to successfully exploit the vulnerability; and authentication describes the level of identity verification required by an attacker before exploiting the vulnerability.
[0058] The formulas for calculating the Influence Factor Score (IS) and the Availability Factor Score (ES) are as follows:
[0059] IS=10.41×(1-(1-C)×(1-I)×(1-A))
[0060] ES = 20 × AV × AC × AU
[0061] Furthermore, a dataset of relevant vulnerability samples is collected based on the aforementioned type characteristics, including evaluation values of the impact factors and exploitability factors of the vulnerability samples. The weights of the impact factors and exploitability factors are calculated using the entropy weight method on the dataset of relevant vulnerability samples, specifically including:
[0062] For each vulnerability in the collected sample dataset, its impact factor score and exploitability factor score are calculated, and the dataset is normalized using the max-min method. The normalization formula is as follows:
[0063]
[0064] In the formula, x m Let be the feature value of the m-th factor in the sample data, max be the maximum value of the sample data, and min be the minimum value of the sample data;
[0065] Furthermore, based on the normalized dataset, the information entropy of influencing factors and availability factors is calculated. The formula for calculating information entropy is:
[0066]
[0067] In the formula, e j Let P be the information entropy of the j-th factor in the sample data, n be the number of sample data, and P be the information entropy of the j-th factor. i,j The probability of the i-th sample occurring under the j-th factor in the sample data is calculated using the following formula:
[0068]
[0069] Based on the information entropy of influencing factors and availability factors, calculate the evaluation weights of influencing factors and availability factors:
[0070]
[0071] In the formula, w j For the evaluation weight of factor j, which is the factor of influencing factors and availability factors, e i e j The information entropy is defined as the influencing factors and the available factors.
[0072] Furthermore, based on the impact factor assessment weights (w1) and exploitability factor assessment weights (w2), as well as the impact factor score (IS) and exploitability factor score (ES) of the target vulnerability, the vulnerability basic characteristic assessment value (BS) is calculated:
[0073] BS = w1 × IS + w2 × ES;
[0074] Step S120: Determine the time impact assessment value of the target vulnerability based on the average time of its exploitation and the number of days since its disclosure.
[0075] Specifically, by statistical analysis, the average time t required for a current social vulnerability to be exploited and the number of days d since the target vulnerability was disclosed are obtained. The Time Impact Assessment (TS) is calculated, and the larger the value, the greater the risk of the vulnerability being exploited.
[0076] The time impact assessment value ranges from (0, 10), and its calculation expression is as follows:
[0077]
[0078] In the formula, d is the number of days since the target vulnerability was disclosed, and t is the average time it takes for the vulnerability to be exploited. The above expression has the following characteristics: when the number of days d is the same as the average time t is used, that is, when d = t, the calculated time impact assessment value TS is 5.
[0079] Step S130: Obtain the data value of the cloud server, the computing resource value of the edge server, and the device utilization rate of the terminal device. Combine the deployment quantity and business value of each device in the cloud-edge-terminal system to calculate the value of the cloud server, the value of the edge server, and the value of the terminal. Based on the bidirectional penetration attack graph and the values of the cloud server, the edge server, and the terminal, determine the network asset risk assessment value of the target vulnerability.
[0080] Specifically, in order to assess the value risks and potential penetration hazards of network assets in the cloud-edge-device power Internet of Things (IoT) system, statistics are first used to obtain information on the network assets of the cloud-edge-device power IoT system, including indicators such as the number of deployments and business value. Combining the characteristics of the cloud, edge, and device, the cloud server value (CV), edge server value (EV), and terminal value (TV) of the system are quantitatively evaluated. The higher the value, the greater the risk of vulnerabilities being exploited.
[0081] For example, in addition to indicators such as the number of cloud-edge-device deployments and business value, considering that cloud servers are responsible for data analysis and storage, data value is used as one of the indicators for evaluating cloud server value; considering that edge servers are responsible for the initial filtering, analysis, and storage of local data, and for coordinating terminal devices, computing resource value is used as one of the indicators for evaluating edge server value; considering that terminal devices interact with users and provide corresponding services, device utilization rate is used as one of the indicators for evaluating terminal value; the evaluation values are distributed between 1 and 5 points (5 points being the highest and 1 point the lowest), and the higher the score of a single item, the higher the value and importance of that indicator in the device; the relevant evaluation indicator options and evaluation values are shown in Tables 2, 3, and 4:
[0082]
[0083]
[0084] Table 2
[0085]
[0086] Table 3
[0087]
[0088]
[0089] Table 4
[0090] In this example, an additive method is used to calculate the system's cloud server value (CV), edge server value (EV), and terminal value (TV).
[0091] Furthermore, based on the structural characteristics of the cloud-edge-device power Internet of Things system, a two-way penetration attack graph is drawn; for example, such as... Figure 2The bidirectional penetration attack graph shown represents the penetration attack path of a vulnerability into a system. An attacker may successfully launch an attack on a device through the vulnerability and then penetrate and attack an adjacent device through the path in the attack graph. Alternatively, after successfully penetrating an adjacent device, the attacker may further penetrate and attack a higher-level device. The probability of a penetration attack occurring along each path in the bidirectional penetration attack graph is obtained.
[0092] Furthermore, based on the cloud server value (CV), edge server value (EV), and terminal value (TV), and combined with the aforementioned two-way penetration attack graph, the network asset risk assessment value (NAV) is calculated comprehensively.
[0093] The expression for Network Asset Risk Assessment Value (NAV) is:
[0094]
[0095] In the formula, P C P represents the probability of cloud server risks occurring. E P represents the probability of edge server risk occurring. T E1 represents the probability of an endpoint risk occurring. This probability is the success rate of an attacker attacking the primary target, i.e., the probability that the device containing the vulnerability will be at risk due to the target vulnerability. E2 represents an event where an endpoint penetrates and attacks an edge server, E3 represents an event where an edge server penetrates and attacks a cloud server, and E4 represents an event where an edge server penetrates and attacks an endpoint.
[0096] Step S140: Based on the basic characteristic assessment value, time impact assessment value, and network asset risk assessment value, assess the severity level of the target vulnerability.
[0097] Specifically, based on the basic characteristic assessment value, basic characteristic assessment weight, time impact assessment value, time impact assessment weight, network asset risk assessment value, and network asset risk assessment weight of the target vulnerability, the comprehensive hazard level of the target vulnerability in the cloud-edge-device power Internet of Things system is determined.
[0098] Among them, the weight of network asset risk assessment is greater than the weight of basic characteristic assessment, which is greater than the weight of time impact assessment.
[0099] For example, in this instance, the Basic Characteristics Assessment Value (BS) ranges from (0, 10), the Time Impact Assessment Value (TS) ranges from (0, 10), and the Network Asset Risk Assessment Value (NAV) ranges from (0, 45). The Comprehensive Hazard Score (CAS) of the target vulnerability in the cloud-edge-device power IoT system is calculated based on the weighted values of the above scores, and its specific expression is as follows:
[0100]
[0101] In this example, the Comprehensive Severity Score (CAS) ranges from (0 to 10). The higher the score, the more severe the vulnerability. The vulnerability severity can be qualitatively assessed based on the mapping relationship between the Comprehensive Severity Score (CAS) and the Comprehensive Severity Score in Table 5, which is used to describe the severity of the vulnerability.
[0102] Comprehensive Hazard Score (CAS) Overall Hazard Level (0,4) Low risk [4,7) Medium risk [7,9) High risk [9,10] Serious risks
[0103] Table 5
[0104] The beneficial effects of this invention are as follows: Compared with the prior art, this invention provides a vulnerability hazard assessment method and system for cloud-edge-device power IoT. It comprehensively assesses the harm caused by target vulnerabilities to the cloud-edge-device power IoT system from multiple perspectives, considers the correlation between vulnerability type and vulnerability impact factors and exploitability factors, uses the entropy weight method to reduce the subjectivity of the assessment, making the assessment more objective, assesses the time impact of target vulnerabilities based on the average time required for current social vulnerability exploitation, considers the correlation between the duration of vulnerability disclosure and the resulting risk, and analyzes the risk of vulnerabilities to assets based on the respective value characteristics of cloud, edge, and device devices. This effectively improves the completeness and richness of vulnerability assessment methods, and ultimately comprehensively assesses the harm of vulnerabilities to the cloud-edge-device power IoT system. It does not rely excessively on subjective human assessment experience and can ensure that the assessed vulnerability hazard level matches the actual vulnerability situation, thereby significantly improving the accuracy and reliability of cloud-edge-device power IoT vulnerability assessment.
[0105] This invention can be a system, method, and / or computer program product. This invention also discloses a cloud-edge-device power IoT vulnerability assessment system based on the aforementioned cloud-edge-device power IoT vulnerability assessment method, comprising:
[0106] The basic characteristic assessment module is used to determine the impact factor score and exploitability factor score of the target vulnerability based on the vulnerability type of the target vulnerability, calculate the weight of the impact factor and exploitability factor using the entropy weight method, and determine the basic characteristic assessment value of the target vulnerability based on the impact factor score, exploitability factor score and corresponding weight.
[0107] The time impact assessment module is used to determine the time impact assessment value of the target vulnerability based on the average time of the exploitation of the target vulnerability and the number of days since the target vulnerability was disclosed.
[0108] The network asset risk assessment module is used to obtain the data value of cloud servers, the computing resource value of edge servers, and the device utilization rate of terminal devices. It calculates the value of cloud servers, edge servers, and terminals by combining the deployment quantity and business value of each device in the cloud-edge-terminal system. Based on the bidirectional penetration attack graph and the values of cloud servers, edge servers, and terminals, it determines the network asset risk assessment value of the target vulnerability.
[0109] The comprehensive assessment module is used to assess the severity level of the target vulnerability based on the basic characteristic assessment value, time impact assessment value, and network asset risk assessment value.
[0110] Based on the spirit of this invention, those skilled in the art will readily conceive of a computer program product derived from the aforementioned cloud-edge-device power IoT vulnerability assessment method. The computer program product may include a computer-readable storage medium on which computer-readable program instructions are loaded to cause a processor to implement various aspects of this disclosure. That is, this application also includes a terminal comprising a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the aforementioned cloud-edge-device power IoT vulnerability assessment method.
[0111] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0112] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0113] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing state information from the computer-readable program instructions to implement various aspects of this disclosure.
[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A method for vulnerability hazard assessment of cloud-edge-end power internet of things, characterized in that, The method comprises the following steps: Step S110: determining an impact factor score and an exploitability factor score of the target vulnerability based on the vulnerability type of the target vulnerability, calculating the weights of the impact factor and the exploitability factor by using an entropy weight method, and determining a basic characteristic evaluation value of the target vulnerability based on the impact factor score, the exploitability factor score, and the corresponding weights; Step S120: determining a time impact evaluation value of the target vulnerability according to the average time of the target vulnerability being exploited and the number of days from when the target vulnerability was disclosed to exist; Step S130: obtaining data value of a cloud server, computing resource value of an edge server, and device usage rate of a terminal device, calculating cloud server value, edge server value, and terminal value in combination with the deployment quantity of each device of cloud-edge-end and business value, determining a network asset risk evaluation value of the target vulnerability based on a bidirectional penetration attack graph and the cloud server value, the edge server value, and the terminal value; Step S140: evaluating the damage level of the target vulnerability based on the basic characteristic evaluation value, the time impact evaluation value, and the network asset risk evaluation value. 2.The cloud-edge-end power internet of things vulnerability damage assessment method according to claim 1, wherein, The determination of the impact factor score and the exploitability factor score of the target vulnerability further comprises: determining the impact factor score of the target vulnerability based on confidentiality, integrity, and availability; determining the exploitability factor score of the target vulnerability based on attack path, attack complexity, and identity authentication. 3.The vulnerability hazard assessment method of cloud-edge-end power internet of things according to claim 2, characterized in that, The calculation of the weights of the impact factor and the exploitability factor by using the entropy weight method further comprises: performing normalization processing on the collected sample data set; In the formula, x m is the eigenvalue of the mth factor of the sample data, max is the maximum value of the sample data, and min is the minimum value of the sample data. calculating information entropy of the impact factor and the exploitability factor based on the normalized data set; e j is the information entropy of the jth factor of the sample data, n is the number of sample data, P i,j is the probability of the ith sample appearing under the jth factor of the sample data: calculating evaluation weights of the impact factor and the exploitability factor based on the information entropy of the impact factor and the exploitability factor; In the formula, w j is the evaluation weight of the jth factor in the influence factor and the availability factor, e i , e j is the information entropy of the influence factor and the availability factor. 4.The cloud-edge-end power internet of things vulnerability damage assessment method according to claim 3, characterized in that, The determination of the time impact evaluation value of the target vulnerability further comprises: calculating the time impact evaluation value: where d is the number of days from when the target vulnerability was disclosed to exist, and t is the average time of the collected exploited vulnerabilities. 5.The vulnerability hazard assessment method of cloud-edge-end power internet of things according to claim 4, characterized in that, The determination of the network asset risk evaluation value of the target vulnerability further comprises: calculating the network asset risk evaluation value NAV: In the formula, P C is the cloud server risk occurrence probability, P E is the edge server risk occurrence probability, P T is the terminal risk occurrence probability, which is the success probability when the attacker attacks the preferred target, that is, the probability of the device where the vulnerability is located due to the target vulnerability; E1 is an event of penetrating attack on the edge server by the terminal, E2 is an event of penetrating attack on the cloud server by the edge server, E3 is an event of penetrating attack on the edge server by the cloud server, and E4 is an event of penetrating attack on the terminal by the edge server; CV is the cloud server value, EV is the edge server value, and TV is the terminal value. 6.A vulnerability hazard assessment system of cloud-edge-end power internet of things, characterized in that, comprises: a basic characteristic evaluation module configured to determine an impact factor score and an exploitability factor score of a target vulnerability based on the vulnerability type of the target vulnerability, calculate the weights of the impact factor and the exploitability factor by using an entropy weight method, and determine a basic characteristic evaluation value of the target vulnerability based on the impact factor score, the exploitability factor score, and the corresponding weights; a time impact evaluation module configured to determine a time impact evaluation value of the target vulnerability according to the average time of the target vulnerability being exploited and the number of days from when the target vulnerability was disclosed to exist; a network asset risk evaluation module configured to determine a network asset risk evaluation value of the target vulnerability based on a bidirectional penetration attack graph and the cloud server value, the edge server value, and the terminal value. The network asset risk assessment module is configured to obtain data value of the cloud server, computing resource value of the edge server, and device usage rate of the terminal device, calculate cloud server value, edge server value, and terminal value in combination with deployment quantity and business value of each device of the cloud-edge-terminal, and determine a network asset risk assessment value of the target vulnerability based on a bidirectional penetration attack graph and the cloud server value, the edge server value, and the terminal value. The comprehensive assessment module is configured to assess a hazard level of the target vulnerability based on the basic characteristic assessment value, the time influence assessment value, and the network asset risk assessment value. 7.The vulnerability hazard assessment system of cloud-edge-end power internet of things according to claim 6, wherein, The basic characteristic assessment module is further configured to: determine an impact factor score of the target vulnerability based on confidentiality, integrity, and availability; determine an exploitability factor score of the target vulnerability based on attack path, attack complexity, and identity authentication. 8.The vulnerability hazard assessment system of cloud-edge-end power internet of things according to claim 7, wherein, The basic characteristic assessment module is further configured to: perform normalization processing on the collected sample data set; In the formula, x m is the eigenvalue of the mth factor of the sample data, max is the maximum value of the sample data, and min is the minimum value of the sample data. calculate information entropy of the impact factor and the exploitability factor based on the normalized data set; e j is the information entropy of the jth factor of the sample data, n is the number of sample data, P i,j is the probability of the ith sample appearing under the jth factor of the sample data: calculate evaluation weights of the impact factor and the exploitability factor based on the information entropy of the impact factor and the exploitability factor. In the formula, w j is the evaluation weight of the jth factor in the influence factor and the availability factor, e i , e j is the information entropy of the influence factor and the availability factor. 9.The vulnerability hazard assessment system of cloud-edge-end power internet of things according to claim 8, wherein, The time influence assessment module is further configured to: calculate the time influence assessment value; where d is a number of days that the target vulnerability has existed since being disclosed, and t is an average time of utilization of the obtained vulnerability. 10.The vulnerability hazard assessment system of cloud-edge-end power internet of things according to claim 9, wherein, The network asset risk assessment module is further configured to: calculate a network asset risk assessment value NAV: In the formula, P C is the cloud server risk occurrence probability, P E is the edge server risk occurrence probability, P T is the terminal risk occurrence probability, which is the success probability when the attacker attacks the preferred target, that is, the probability of the device where the vulnerability is located due to the target vulnerability; E1 is an event of penetrating and attacking the edge server by the terminal, E2 is an event of penetrating and attacking the cloud server by the edge server, E3 is an event of penetrating and attacking the edge server by the cloud server, and E4 is an event of penetrating and attacking the terminal by the edge server. where CV is the cloud server value, EV is the edge server value, and TV is the terminal value.
11. A terminal comprising a processor and a storage medium; characterized in that: the storage medium is configured to store instructions; the processor is configured to operate according to the instructions to perform steps of the vulnerability hazard assessment method of the cloud-edge-terminal power Internet of Things according to any one of claims 1-5.
12. A computer readable storage medium having stored thereon a computer program, characterized in that, The program, when executed by the processor, implements steps of the vulnerability hazard assessment method of the cloud-edge-terminal power Internet of Things according to any one of claims 1-5.
Citation Information
Patent Citations
Vulnerability reference price calculation method, device and equipment based on target assets
CN114331510A
Power distribution network cyber-physical system network attack risk quantitative evaluation method and system
CN117768167A