Method, device and equipment for determining network security risk and storage medium

By acquiring topology and device parameters from communication networks, and combining vulnerability assessments and attack logs, the system automatically evaluates network stability, threats, and losses, solving the problems of low efficiency and high cost in existing technologies, and enabling accurate risk assessment and real-time maintenance of complex networks.

CN118802239BActive Publication Date: 2026-04-28CHINA MOBILE GROUP ZHEJIANG +3
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GROUP ZHEJIANG
Filing Date
2023-12-14
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing technologies are inefficient, costly, and difficult to accurately assess the impact of internal vulnerabilities and external attacks on complex networks when conducting network security risk assessments in communication networks. This results in complex network risk analysis and makes it difficult to achieve automated risk assessment and effective network maintenance.

Method used

By acquiring the topology, node parameters, and vulnerability severity assessments of devices in the communication network, and combining these with network attack logs and security levels, the system automatically assesses the network's stability, threat level, and potential losses, comprehensively determines the network risk value, and then makes informed decisions.

Benefits of technology

It enables automated, real-time assessment of network security risks in complex communication networks, reduces operation and maintenance costs, supports network maintenance and risk management, and avoids risk assessment bias caused by changes in network scale.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802239B_ABST
    Figure CN118802239B_ABST
Patent Text Reader

Abstract

The embodiment of the specification discloses a method and device for determining network security risk, equipment and storage medium, belonging to the technical field of network security, which can automatically determine network risk and network risk warning. The method comprises the following steps: acquiring node parameters of each device in the topological connection structure of the communication network and evaluation values of various vulnerability severity; determining the stability of the first target device under security monitoring based on the maximum evaluation value of each first target device and associated device to obtain the stability of the communication network; determining the threat value of the second target device based on the network attack log of each second target device to obtain the threat value of the communication network; determining the loss value of the third target device based on the security level of each third target device and associated device to determine the loss value of the communication network; determining the network risk value of the communication network based on the specified parameter index of the communication network; and performing decision processing based on the network risk value of the communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of network security technology, and in particular to a method, apparatus, device, and storage medium for determining network security risks. Background Technology

[0002] In communication networks, common devices include switches, routers, base stations, fiber optic transceivers, terminal equipment, network boundary devices, and application servers. The hardware devices in operator communication networks are diverse, numerous, and of varying sizes. The software products supporting this hardware, such as operating system kernels, libraries, programs running within the system, and protocols used, are extremely broad. Neither software nor hardware is perfect, and each device is susceptible to intrusion and attack. Vulnerability exploiters' actions, such as eavesdropping and damaging equipment, pose security risks to communication networks. Timely network maintenance can significantly reduce network risks and prevent large-scale losses; therefore, identifying network security risks is fundamental to effective network maintenance.

[0003] Currently, manual assessment methods such as vulnerability detection tools and code auditing allow analysts to write test cases for specific devices and software, conduct detection, auditing, and scoring, and estimate the risks associated with those devices and software based on experience. However, manual assessment is inefficient and costly in operator communication networks. Furthermore, the reality of multiple vulnerabilities and devices coexisting, including diverse vulnerability types, device types, and vulnerability distribution, makes network risk assessment and analysis overly complex, posing significant challenges to this work. Summary of the Invention

[0004] The purpose of the embodiments in this specification is to provide a method, apparatus, device, and storage medium for determining network security risks, so as to avoid the difficulty in determining the impact of the actual internal and external conditions of the communication network on the current risk loss of the communication network due to the scale of the communication network and changes in the scale. In this way, it can realize automated risk assessment and handling applications for communication networks, reduce operation and maintenance costs, support real-time network risk assessment applications, and provide a basis for carrying out network maintenance.

[0005] To achieve the above objectives, the embodiments in this specification adopt the following solutions:

[0006] Firstly, a method for determining cybersecurity risks is provided, the method comprising:

[0007] Obtain the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device;

[0008] Based on the maximum evaluation value of each first target device and the maximum evaluation value of each corresponding associated device in the communication network, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network.

[0009] Based on the network attack logs of each second target device in the communication network, the threat value of the second target device is determined to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network.

[0010] Based on the security level of each third target device and the security level of each corresponding associated device in the communication network, the loss value of the third target device is determined to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0011] Based on specified parameter indicators of the communication network, the network risk value of the communication network is determined. The specified parameter indicators include the node parameters, as well as the stability, threat value, and loss value of the communication network.

[0012] Decision-making is performed based on the network risk value of the communication network.

[0013] Secondly, a network risk processing device is provided, the network risk processing device comprising:

[0014] The acquisition module is used to acquire the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device.

[0015] The stability assessment module is used to determine the stability of the first target device under security monitoring based on the maximum assessment value of each first target device and the maximum assessment value of each corresponding associated device in the communication network, so as to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network.

[0016] The threat assessment module is used to determine the threat value of the second target device based on the network attack logs of each second target device in the communication network to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network.

[0017] The loss assessment module is used to determine the loss value of each third target device in the communication network based on the security level of each third target device and the security level of each corresponding associated device, and to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0018] The risk determination module is used to determine the network risk value of the communication network based on specified parameter indicators of the communication network. The specified parameter indicators include the node parameters, as well as the stability, threat value, and loss value of the communication network.

[0019] The decision processing module is used to perform decision processing based on the network risk value of the communication network.

[0020] Thirdly, an electronic device is provided, the electronic device comprising:

[0021] At least one processor;

[0022] A memory connected to the at least one processor;

[0023] The memory stores instructions that can be executed by the at least one processor, and the at least one processor implements the aforementioned method by executing the instructions stored in the memory.

[0024] Fourthly, a machine-readable storage medium is provided, storing machine instructions that, when executed on a machine, cause the machine to perform the aforementioned method.

[0025] In the embodiments of this specification, the scale of the communication network is variable, and the communication connections between devices are not constant. The obtained node degree can reflect the current number of connections of the device in the communication network, providing a basis for determining risks based on the network scale, rather than using path analysis or node hierarchy analysis between nodes in a fixed topology diagram. Furthermore, due to differences in device network roles, hardware and software, the actual vulnerabilities of the devices are different. The obtained evaluation value can reflect the magnitude of the impact of vulnerabilities of the devices in the communication network, providing a basis for determining risks in complex network realities.

[0026] In the embodiments of this specification, since the risk of a device to the network in a communication network is manifested in the impact of the device on connected devices, the stability of the first target device and the stability of the communication network can be determined based on the distribution of monitoring vulnerabilities of the first target device under security monitoring in the communication network by using the maximum evaluation value among connected devices. This allows for the automatic assessment of the degree of vulnerability impact within the communication network, rather than using vulnerability evaluation values ​​to describe the vulnerability risk of local devices, and eliminates the need to construct empirical values ​​for vulnerability exploitation behavior of each device.

[0027] In the embodiments of this specification, the network attacks on the communication network are random. The impact of the network attack on the devices in the communication network is reflected in the devices affected by the attack. The threat value of the devices and the network is determined by the network attack log of the second target device. This can automatically assess the degree of impact of external attacks on the communication network, rather than specifying the use of specific software / hardware types and levels of equipment experience to represent the impact of the network attack.

[0028] In the embodiments of this specification, there is a static mapping relationship between the security level of each device in the communication network and the magnitude of the loss value of each device when a risk event occurs. The higher the security level, the greater the loss value, thereby providing a static benchmark and reference for the actual vulnerability impact degree inside the complex communication network (vulnerability distribution) and the actual attack impact degree outside (attack behavior) as assessed above.

[0029] In the embodiments of this specification, based on the loss value of the communication network, and taking into account both the actual vulnerability impact within the complex communication network (vulnerability distribution) and the actual attack impact externally (attack behavior), a network risk value is obtained within the actual network scale (number of connections that node parameters can carry and node scale information). This avoids deviations from the actual network risk caused by using fixed scale, experience values, and fixed path experience. Thus, the network risk value is used for decision-making and risk management applications.

[0030] Other features and advantages of the embodiments described herein will be described in detail in the following detailed description section. Attached Figure Description

[0031] The accompanying drawings, which are included to provide a further understanding of this specification and form part of this specification, illustrate exemplary embodiments and are used to explain this specification, but do not constitute an undue limitation thereof. In the drawings:

[0032] Figure 1 This is a schematic diagram of the topology of an exemplary communication network according to an embodiment of this specification.

[0033] Figure 2 This diagram illustrates the main steps of an exemplary method for determining network security risks according to an embodiment of this specification.

[0034] Figure 3 This is a schematic diagram illustrating an exemplary risk monitoring server application scenario as described in this specification.

[0035] Figure 4 This is a schematic diagram of an exemplary device module according to an embodiment of this specification;

[0036] Figure 5 This is a schematic diagram of an exemplary electronic device module according to an embodiment of this specification. Detailed Implementation

[0037] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this document.

[0038] As mentioned earlier, network risks in communication networks are often addressed by maintenance personnel writing scripts for specific devices and software. However, this method is time-consuming and labor-intensive, and it is difficult to obtain a description of the network risk situation of the entire communication network, or the required cost is unacceptable.

[0039] In some possible examples, a security assessment scheme could be attempted. This scheme utilizes network dependencies and determines the state values ​​of nodes in the network graph of the information network by using a preset attack success probability. The preset attack success probability is determined based on the total number of vulnerabilities, vulnerability exploitation rate, and the probability of an attacker exploiting a vulnerability knowing its principles, combined with network hierarchy, (empirically) commonly attacked devices, theoretical dependencies, and path information. Then, using the state values ​​of nodes in the information network, the state values ​​of nodes in the power network graph are determined, and the security risk assessment value of the power network is obtained using the state values ​​of the nodes in the power network graph. However, firstly, the information network mapped to the power network often does not change significantly; the node paths and node hierarchy in the network graph can be fixed, and the vulnerability distribution and attack behavior are not affected by changes in network size. The network situation is relatively simple and difficult to apply to complex communication networks. Second, the security risk assessment values ​​for power networks, derived from the number of vulnerabilities in specific-level devices within information networks and empirical risk assessment probabilities, and employing theoretical dependencies, network layers, paths, and experience with attacks on specific-level devices, are empirical and do not consider the actual defensive capabilities of devices or the impact of actual attacks on devices on network risk. This makes it difficult to determine the actual extent of internal vulnerabilities and the impact of external attacks. Third, the loss values ​​of nodes in a power network's network diagram are determined by the state values ​​and importance of nodes in an information network's network diagram. However, when studying complex communication networks in isolation, it is difficult to use the state values ​​of other networks to represent the actual loss values ​​of the communication network; therefore, this approach is also difficult to apply to complex communication networks.

[0040] Therefore, the embodiments in this specification provide a scheme for determining network security risks and mitigating those risks. This avoids the significant deviation from the actual network risk situation caused by directly describing device risks using empirical values ​​alone. It enables the automated determination of actual network risks in complex communication networks and can be applied to the communication networks of operators and large-scale equipment, without requiring additional network-aided assessments. It should be understood that the method provided in this specification can be executed by a device with computing, instruction processing, and communication capabilities, such as a server or electronic device.

[0041] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.

[0042] One embodiment of this specification provides a method for determining network security risks, which can be applied to a network security risk monitoring server. This monitoring server can be configured with a program that, when executed, implements the aforementioned method for determining network security risks. The monitoring server can acquire data from the communication network in real-time, periodically, or non-periodically (based on monitoring requests), and process the data to output decision-making results. These results may include alarm messages, risk mitigation instructions, and identifiers of risky devices in the communication network. The server can be a device within the communication network, such as a gateway server or a terminal device used for monitoring; alternatively, the server can be one or more external servers. Please refer to... Figure 1 The communication network may include servers 1-2, gateway devices 1-3, terminal devices 1-2, etc. Figure 1 This can be a schematic diagram of the topology of the communication network. External servers can obtain data from the communication network through authorized interfaces. External servers can be physical servers, server instances, or container instances with communication capabilities. The hardware of the instance can be a resource instance in a server cluster, consisting of processor resources and memory resources, with computing and instruction processing functions, such as a cloud server.

[0043] In the embodiments of this specification, the aforementioned method for determining network security risks should be referred to in conjunction with... Figure 2 It can include:

[0044] S1, obtain the node parameters of each device in the communication network topology and the assessment values ​​of the severity of various vulnerabilities of each device.

[0045] In some possible implementations, the communication network can be a target network composed of various actually active online devices, and there can be communication connections between the devices in the target network. The aforementioned step S1 may include:

[0046] S101, Identify a device within the communication network that has a communication connection / uses (communication) resources.

[0047] For example, a base station allocates time and frequency resources to a terminal device. The terminal device may be transmitting data, or it may be camped within the base station cell (capable of communication) without transmitting user data. Both the base station and the terminal device can be devices within the target network. Another example is a gateway device allocating routing tables to each terminal device, with the terminal device's identifier appearing in the gateway device's online device list. Both the gateway device and the terminal device can be devices within the target network. Yet another example is the transmission of data packets indicating active online status between devices, where at least one device can report online device data to a monitoring server or act as a monitoring server. The devices listed in the online device data can all be devices within the target network. Furthermore, the size of the target network can vary; for example, devices originally part of the communication network can go offline, and / or devices not currently part of the communication network can join, rather than using a communication network composed of devices of a theoretical size.

[0048] In some possible examples, the actual online activity of devices in a communication network can be determined based on network identifiers and specified network segments, thereby improving data collection efficiency and ensuring security. Within a specified network segment, a configured server belonging to that segment (e.g., a private / internal network) can scan / collect data from online devices and / or determine the network identifiers of devices in data packets reported by internal network devices to identify the currently active online devices within that specified network segment. This process can be repeated segment by segment to determine the active devices in the network.

[0049] In some possible implementations, step S1 may further include:

[0050] S102 can map currently active devices in the communication network to nodes in the topology connection structure.

[0051] For example, the topology connection structure can be a network topology graph, which can be a graph representing the nodes corresponding to each device in the communication network and the connections between the nodes. One device can correspond to one node, that is, a point in the network topology graph. If two devices in the communication network have a communication connection / are able to communicate (one device uses resources allocated by the other device), then in the network topology graph, there can be an edge between the two points corresponding to those two devices.

[0052] In some possible implementations, after obtaining the topology connection structure, the aforementioned step S1 may further include:

[0053] S103 can obtain the degree (number) of the nodes corresponding to each device and the total number of nodes in the topology connection structure.

[0054] The degree of a node can be referred to as node degree, and the aforementioned node parameter can be a mapping value between this node degree and the total number of nodes. In the aforementioned topology, the node degree of the target node can be the number of nodes that are directly connected to the target node by an edge, which can be used to represent the current scale of connections for each node. This provides a basis for determining the network size coefficient using the node degree of each node and the total number of nodes. The network size coefficient can be used to represent the current actual size of the communication network and to describe the impact of network size on the risk and loss of the communication network.

[0055] In some possible implementations, step S1 may further include:

[0056] S104, obtain the assessment values ​​of the severity of various vulnerabilities of each of the aforementioned devices.

[0057] For example, software and hardware parameter information of each device in a communication network can be obtained, and combined with a maintained vulnerability information list, a standardized vulnerability assessment system can be used to obtain an assessment value for the severity of various vulnerabilities on each device. The vulnerability assessment system can preferably be a Common Vulnerability Scoring System (CVSS), an industry-open standard that measures vulnerability severity and can be used to compare vulnerability severity. Information on various vulnerabilities on each device can be input into CVSS (based on metric-based scoring and score fusion). CVSS can output the final score for each vulnerability, thereby obtaining the corresponding CVSS value or assessment value for the vulnerability. For example, the maximum value can be 10, and the minimum can be 0. Vulnerabilities with scores of 7-10 are generally considered relatively severe, those with scores between 4 and 6.9 are considered medium-level vulnerabilities, and those between 0 and 3.9 are considered low-level vulnerabilities. The assessment value can be combined with a security value representing the device's security monitoring and defensive behavior to jointly represent the device's stability, thus describing the vulnerability risk based on the device's defensive capabilities, rather than describing the device's vulnerability risk solely with the assessment value. In addition to the aforementioned CVSS value, a known vulnerability catalog and vulnerability level can also be used to map the vulnerability level to an assessment value of the severity of various vulnerabilities on the device.

[0058] In the embodiments of this specification, stability can be used to assess the actual vulnerability risk within the communication network, threat values ​​can be used to assess the impact of attacks (behaviors) outside the communication network, and loss values ​​can be used to assess the degree of damage to the communication network. The steps of determining stability, threat values, and loss values ​​can be synchronous or asynchronous. A target device can represent any device in the communication network, and a first target device, a second target device, and a third target device can represent a device in different determination steps. The first target device, the second target device, and the third target device can be the same target device or different devices being traversed. Regarding the aforementioned stability, the stability of a device can be the extent to which the device is affected by vulnerabilities and their distribution in the communication network under a security monitoring environment (security-monitored). The stability of the communication network can be the extent to which the current network environment of the security-monitored device is affected by the risk of vulnerability distribution. The aforementioned method for determining network security risks may further include:

[0059] S2, based on the maximum evaluation value of each first target device in the communication network and the maximum evaluation value of each corresponding associated device, determine the stability of the first target device under security monitoring to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability is used to evaluate the degree of impact of vulnerabilities within the communication network.

[0060] In some possible implementations, devices in the communication network can have communication connections with each other or devices can communicate with other devices. Any device can have at least one associated device, which can be a device connected to that device by an edge. For example, please refer to... Figure 1 When the first target device is gateway device 1, all associated devices corresponding to the first target device may include server 1, terminal device 1, and gateway device 2, but not terminal device 2, gateway device 3, or server 2. Any one of these devices can be the aforementioned first target device. From the corresponding evaluation values ​​of the first target device and its associated devices, the maximum evaluation value for each device can be determined. The vulnerability corresponding to the maximum evaluation value can be the most risky vulnerability among multiple vulnerabilities distributed on the device. Based on the relationship between the maximum evaluation values ​​or the difference between the maximum evaluation values, the stability of the first target device under security monitoring is obtained. The aforementioned step S2 may include:

[0061] S201, based on the maximum evaluation values ​​of the first target device and its corresponding associated device in the communication network, determine the relative stability of the first target device under security monitoring relative to the associated device, wherein the relative stability is used to evaluate the degree to which the first target device is affected by vulnerabilities in the communication network.

[0062] In some possible examples, both the first target device and its corresponding associated devices can be security-monitored devices with (basic) network security defense capabilities and the ability to perform network security defense actions. For example, both the first target device and its corresponding associated devices may be configured with one or more security monitoring components, which could include firewall services / components or security scanning components. For instance, a firewall service can restrict data transmission through a device's programs or ports, provide data transmission policies for those programs or ports, and provide statistics on patched and unpatched vulnerabilities. The maximum evaluation value of a first target device can be compared to the maximum evaluation value of an associated device. When the maximum evaluation value of the first target device is greater than or equal to the maximum evaluation value of the associated device, it indicates that within the security-monitored (network) internal environment, the vulnerability impact on the first target device is more strongly influenced by the vulnerabilities corresponding to its own maximum evaluation value. Conversely, when the maximum evaluation value of the first target device is less than or equal to the maximum evaluation value of the associated device, it indicates that within the security-monitored internal environment, the vulnerability impact on the first target device is jointly influenced by the vulnerabilities corresponding to its own and the associated device's maximum evaluation values, thus representing the relative stability of the security-monitored first target device.

[0063] In some preferred examples, a first target device can be denoted as device i1 (representing the i1th device in the network, which can be a positive integer), and an associated device can be selected from all associated devices corresponding to the first target device, which can be denoted as device j1 (representing the j1th device among all associated devices, which can be a positive integer). The aforementioned step S201 may include:

[0064] S211, if the maximum evaluation value of device i1 (which can be denoted as...) The value is greater than or equal to the maximum evaluation value of device j1 (denoted as ). In a securely monitored internal environment, the relative stability of device i1 is...

[0065] in, It can be the security value of device i1 in a security-monitored environment. The security value of device j1 relative to the security monitoring environment The proportion, that is

[0066] Any device within a communication network can be equipped with a security monitoring component or provide data on its current security status (a score for the device can be obtained from the security monitoring component deployed on the monitoring server). For example, the current security status of device i1 (e.g., the number of patched and unpatched vulnerabilities, the number of unknown / suspicious programs, abnormal port traffic, etc.) can be evaluated using a security monitoring component to obtain a score. In addition, multiple security monitoring components can be deployed on device i1. The average score of the outputs of multiple security monitoring components can be used as the score of device i1 to describe the current security status of device i1.

[0067] The scoring values ​​of each device within a communication network can be statistically analyzed to represent the security value of devices in a monitored environment. For example, by determining the mean μ, median M, and standard deviation σ of the scoring values ​​of all devices within the communication network, the security value of device i1 can be determined. The aforementioned step S201 may also include:

[0068] S212, if device i1's Less than device j1 In a security-monitored internal environment, the relative stability of device i1...

[0069] The relative stability of device i1 and all associated devices can be determined by referring to the method used to determine the relative stability of device i1 and device j1, in order to determine the stability of device i1 in a security-monitored internal environment. The aforementioned step S2 may further include:

[0070] S202, Based on the relative stability of the first target device relative to all associated devices, determine the stability of the first target device.

[0071] For example, the stability of device i1 It can be the sum of the relative stability of device i1 and each associated device. It can be the node degree of device i1 in the node parameters of the communication network, thereby determining the actual impact of distributed vulnerabilities on the device in the internal network environment under security monitoring, based on the current connection scale of the device.

[0072] The stability of each device in the communication network can be determined by referring to the method used to determine the stability of device i1, thereby statistically obtaining the stability of the communication network. The aforementioned step S2 may further include:

[0073] S203, Based on the stability of each first target device in the communication network, determine the stability of the communication network.

[0074] The stability *st* of the communication network can be obtained by averaging the stability of each first target device. It is understood that the relative stability and stability mentioned above can be expressed numerically, and the calculation formula can be preferred, but not the only limited calculation method. For example, to suit testing and usage effects, linear relationships, fine-tuning values, etc., can be used for adjustment.

[0075] In the embodiments of this specification, network attack logs of devices in a communication network can be used for external threat analysis. The threat value of a device can be the extent to which the device is affected by network attacks, and the threat value of the communication network can be the extent to which the device's current network environment is affected by network attacks. The aforementioned method for determining network security risks also includes:

[0076] S3, based on the network attack logs of each second target device in the communication network, determine the threat value of the second target device to obtain the threat value of the communication network. The threat value is used to assess the degree of impact of attacks outside the communication network.

[0077] In some possible implementations, network attack logs can be provided by security monitoring components on the device or by the device's system services. Network attack logs can include attack records, timestamps, log identifiers, etc. Attack records can include source port, source network address, access path, parameters carried in the request, etc.

[0078] In some possible examples, the characteristics of an external attack can be described by a vulnerability attack event, and the aforementioned step S3 may include:

[0079] S301, based on the network attack logs of the second target device in the communication network, predict the probability of occurrence of each vulnerability attack event of the second target device.

[0080] For example, each vulnerability attack event can correspond to a vulnerability. Each vulnerability attack event can carry information about attack characteristics and the attack time (the timestamp when the attack characteristics occur). Attack characteristics can include the attack source network address, access path, request frequency, etc. If a vulnerability attack event occurs, it can be considered a network attack behavior with the attack characteristics of one vulnerability attack event. The number of vulnerability attack events with the same attack characteristics can be counted to determine the number of network attack behaviors with the same attack characteristics, i.e., the total number of attacks. Simultaneously, the number of network attack behaviors with various attack characteristics can also be counted, i.e., the total number of attacks. Furthermore, the probability P of a vulnerability attack event with attack characteristic x occurring on the second target device at time t can be predicted. x :

[0081]

[0082] In this formula, Px Let n be the probability of (re)occurrence. x Let t be the total number of attacks with attack characteristic x, N be the total number of attacks, and t be the total number of attacks. x (1) is the time since the most recent attack on attack x. The average time difference is the average time difference between two consecutive network attack events with the same attack feature x. For example, the first time difference between the target attack time and the previous attack time with the same attack feature x, and the second time difference between the target attack time and the next attack time with the same attack feature x. The average time difference is determined by the first time difference and the second time difference. The maximum probability of occurrence can be determined from the probability of occurrence of vulnerability attack events based on each attack characteristic, and combined with the aforementioned evaluation value to determine the threat value of the device. Step S3 may further include:

[0083] S302, Based on the assessment value of the maximum probability of occurrence and the corresponding vulnerability severity, determine the threat value of the second target device.

[0084] For example, the threat value of a second target device i2. It could be:

[0085]

[0086] In this formula, max x P x CVSS represents the maximum probability of occurrence among the attack features in the attack feature set X (x∈X) of the network attack behavior against the second target device i2. max The CVSS value of the vulnerability corresponding to the network attack behavior with the highest probability of occurrence. Step S3 may further include:

[0087] S303, Based on the threat values ​​of each second target device, determine the threat value of the communication network.

[0088] For example, the average threat value of each second target device can be taken to obtain the threat value of the communication network. It is understood that the aforementioned exemplary method for determining the threat value is preferred, but not the only limited method. The formula can be numerically adjusted and linearly transformed based on testing and usage results. Alternatively, a numerical table can be used, and a numerical granularity suitable for the product application can be selected to cover the possible inputs and outputs of each calculation formula. The result of the corresponding calculation formula can be obtained by querying the table. If no value is found, the corresponding calculation formula can be called for calculation. All calculation formulas in this embodiment can be implemented in this manner.

[0089] In the embodiments of this specification, loss values ​​can be described between devices by employing security levels. The aforementioned method for determining network security risks may further include:

[0090] S4, based on the security level of each third target device in the communication network and the security level of each corresponding associated device, determine the loss value of the third target device to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0091] In some possible implementations, the security level can be set in the configuration file / parameters of the third target device, or it can be a default static value or adjusted / set by security personnel. After the device joins the communication network, it can remain static or be modified through the configuration file / parameters. The device's loss value can be the degree to which device data or services performed by the device are damaged due to an actual risk event. The communication network's loss value can be the degree to which services or communications are damaged due to an actual risk event. Actual risk events can include events such as attackers successfully intruding into the device or attacks that successfully exploit vulnerabilities. The security level can be used to represent the security / confidentiality level of the data stored by the device or the tasks processed by the device. For example, if the stored data of a third target device involves confidential data, the security level of the third target device can be 10; if it does not involve confidential data and processes ordinary tasks, the security level can be 1. The loss value of the third target device can be jointly determined using the security levels of the third target device and its corresponding associated devices. The aforementioned step S4 can include:

[0092] S401, Based on the highest security level among all associated devices in the communication network, determine the loss value of the third target device.

[0093] For example, the loss value of a third target device i3 It could be:

[0094]

[0095] In this formula, The security level for the third target device i3. It can be the security level of the j2th associated device among all associated devices. This can be the highest security level among the security level set J (j2∈J) of all associated devices. Step S4 may further include:

[0096] S402, determine the loss value and corresponding node degree of each device in the communication network, and determine the maximum loss value and maximum node degree.

[0097] For example, the maximum loss value can be the largest of the loss values ​​of all devices in the communication network, which can be achieved by maxing out the maximum loss value. i loss i Determined, loss i This can represent the loss value of device i in a communication network. The maximum node degree can be the largest of the node degrees of all devices in the communication network, which can be expressed by maxing out the maximum value. i de i Confirmed, de i This can represent the node degree of device i in the communication network. The aforementioned step S4 may further include:

[0098] S403, determine the loss value of the communication network based on the ratio of the maximum loss value to the maximum node degree.

[0099] For example, the loss value l of the communication network can be written as:

[0100]

[0101] Understandably, the expression for the loss value can also be adjusted. For example, weighting coefficients corresponding to different time periods can be selected, and the loss value obtained can be weighted using the corresponding weighting coefficients in each time period to further match the characteristics of actual communication network equipment products and application scenarios.

[0102] In the embodiments of this specification, specified parameter indicators can be used to comprehensively determine the current network risk value by integrating the aforementioned node parameters, stability, threat value, and loss value of the communication network. The network risk value of the communication network can be the magnitude of the loss value relative to the communication network, representing the combined network risk magnitude formed by the impact of the actual internal vulnerability distribution (internal defense behavior) and the actual external attack behavior within the current connection and device scale of the communication network. The aforementioned method for determining network security risk may further include:

[0103] S5. Based on specified parameter indicators of the communication network, determine the network risk value of the communication network. The specified parameter indicators include the node parameters, the stability of the communication network, the threat value of the communication network, and the loss value of the communication network.

[0104] In some possible implementations, the specified parameter indicator can be the current set of network monitoring values. The specified parameter indicator may also include the aforementioned network size coefficient, which can be represented by the node degree and total number of nodes in the node parameters, and can be obtained before step S5. The aforementioned method for determining network security risks may also include:

[0105] T1 determines the maximum node degree based on the node degree corresponding to each device in the communication network.

[0106] For example, the maximum node degree can be expressed as the aforementioned max. i de i .

[0107] T2, based on the maximum node degree and the total number of nodes in the topology, determines the network size coefficient.

[0108] For example, the network size coefficient α can be written as:

[0109]

[0110] In this formula, n node This could be the total number of nodes. In other possible examples, the average node degree could also be used. Total number of nodes n node Represents the network size coefficient, i.e. Using the specified parameter indicators at this time, the aforementioned step S5 may include:

[0111] S501, based on the product of the network scale coefficient, stability, threat value and loss value of the communication network, the network risk value of the communication network is obtained.

[0112] In addition, the network risk value can be fine-tuned by using weighting coefficients corresponding to different time periods to meet the requirements of risk alarm, handling margin, and product application scenario characteristics. The aforementioned step S5 can also include:

[0113] S502, the network risk value of the communication network is obtained by weighting the product of the network scale coefficient, stability, threat value and loss value of the communication network and the weight coefficient corresponding to the current time period.

[0114] In the embodiments of this specification, after the risk value reflected in the current actual situation of the communication network is obtained, the aforementioned method for determining network security risks may further include:

[0115] S6, make a decision based on the network risk value of the communication network.

[0116] In some possible implementations, such as Figure 3 The monitoring server obtains data from the communication network through the network's data interface (which can use authorized open ports and specified interface protocols). Figure 3(The example shown is for illustrative purposes only and does not limit the number or physical structure of servers.) The aforementioned method for determining network security risks can be executed to obtain a network risk value. Decision processing can be a device operation performed by the device that determined the risk value, such as an operation performed by the monitoring server. This could include alarm operations, sending alarm messages, etc. The alarm messages can be received by user devices operated by designated personnel to automatically implement current network risk warnings.

[0117] This specification also provides a network risk handling method, which can be applied to the aforementioned monitoring server. This network risk handling method may include:

[0118] P1, obtain the network risk value of the communication network in the aforementioned embodiments;

[0119] P2, if the network risk value of the communication network is greater than the risk threshold, an alarm operation will be triggered.

[0120] In some possible implementations, the alarm operation can involve a monitoring server sending an alarm message to the device of a designated person. This alarm message can carry information such as the communication network's identifier (region code, telephone / data service symbol, etc.) and the network risk value, thus enabling network risk alarm applications based on the current risk value of the communication network. It should be noted that in the process of determining the network risk value, in some possible scenarios, devices such as terminal devices or user devices that do not belong to operators or enterprises with large-scale network support equipment can be excluded. This further improves the efficiency of data processing (carrying information such as defensive and offensive behaviors) and allows for a better understanding of the actual current network risk situation on the business support surface.

[0121] In this embodiment, based on the scale of device connections and network size, the stability of the (communication) network is assessed by evaluating the vulnerability distribution represented by the vulnerability assessment value between devices and the internal defense behavior under security monitoring. The network threat value is assessed by evaluating external attack behavior. The actual degree of internal and external influence on the network is assessed by using the various physical behaviors that occur. The network loss value is assessed by evaluating the security level between devices. The degree of damage to the network due to actual influence is assessed by evaluating the configuration files / parameters between devices. Finally, the current network risk value is obtained by comprehensively using specified index parameters. Thus, based on the actual monitoring information such as device configuration, actual attack and defense behavior between devices, and device and connection scale, automated network risk assessment is performed. This enables the server to automatically determine the actual network risk without the need for other network auxiliary assessments and supports real-time network risk monitoring / handling applications.

[0122] One embodiment of this specification provides a network risk handling device under the same inventive concept as the foregoing embodiments, such as... Figure 4The network risk handling device 400 may include:

[0123] The acquisition module 401 is used to acquire the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device.

[0124] The stability assessment module 402 is used to determine the stability of the first target device under security monitoring based on the maximum assessment value of each first target device and the maximum assessment value of each corresponding associated device in the communication network, so as to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology connection structure. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network.

[0125] Threat assessment module 403 is used to determine the threat value of the second target device based on the network attack logs of each second target device in the communication network to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network.

[0126] The loss assessment module 404 is used to determine the loss value of the third target device based on the security level of each third target device in the communication network and the security level of each corresponding associated device, so as to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0127] The risk determination module 405 is used to determine the network risk value of the communication network based on specified parameter indicators of the communication network, wherein the specified parameter indicators include node parameters, stability, threat value and loss value;

[0128] The decision processing module 406 is used to perform decision processing based on the network risk value of the communication network.

[0129] Optionally, based on the maximum evaluation value of each first target device in the communication network and the maximum evaluation value of each corresponding associated device, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network, including:

[0130] Based on the maximum evaluation values ​​of the first target device and its corresponding associated device in the communication network, the relative stability of the first target device under security monitoring relative to the associated device is determined. The relative stability is used to evaluate the degree to which the first target device is affected by vulnerabilities in the communication network.

[0131] The stability of the first target device is determined based on its relative stability with respect to all associated devices.

[0132] The stability of the communication network is determined based on the stability of each first target device in the communication network.

[0133] Optionally, based on the network attack logs of each second target device in the communication network, the threat value of the second target device is determined to obtain the threat value of the communication network, including:

[0134] Based on the network attack logs of the second target device in the communication network, predict the probability of occurrence of each vulnerability attack event of the second target device;

[0135] Based on the assessment values ​​of the maximum probability of occurrence and the corresponding vulnerability severity, the threat value of the second target device is determined;

[0136] The threat value of the communication network is determined based on the threat value of each second target device.

[0137] Optionally, based on the security level of each third target device in the communication network and the security level of each corresponding associated device, the loss value of the third target device is determined to determine the loss value of the communication network, including:

[0138] Based on the highest security level among all associated devices in the communication network, the loss value of the third target device is determined.

[0139] Determine the loss value and corresponding node degree of each device in the communication network, and determine the maximum loss value and maximum node degree;

[0140] The loss value of the communication network is determined based on the ratio of the maximum loss value to the maximum node degree.

[0141] Optionally, the specified parameter index may also include: network size coefficient;

[0142] The acquisition module 401 is also used to: acquire network size coefficients.

[0143] Optionally, obtain the network size coefficient, including:

[0144] The maximum node degree is determined based on the node degree corresponding to each device in the communication network.

[0145] The network size coefficient is determined based on the maximum node degree and the total number of nodes in the topology.

[0146] Optionally, based on specified parameter indicators of the communication network, the network risk value of the communication network is determined, including:

[0147] The network risk value of the communication network is obtained by multiplying the network size coefficient, stability, threat value, and loss value of the communication network.

[0148] One embodiment of this specification provides an electronic device under the same inventive concept as the foregoing embodiments. This electronic device may include: at least one processor; and a memory connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the at least one processor implements the methods in the foregoing embodiments by executing the instructions stored in the memory. Please refer to... Figure 5 An exemplary electronic device is provided, the internal structure of which can be shown in the following diagram. Figure 5 As shown, the device can be a server, industrial control computer, user equipment, gateway device, terminal device, microcontroller, etc. This electronic device includes a processor A01, a network interface A02, and a memory connected via a bus. The processor A01 provides computing, instruction processing, and control capabilities. The memory includes a main memory A03 and a non-volatile storage medium A04. The non-volatile storage medium A04 stores an operating system B01 and a computer program B02. The main memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 stored in the non-volatile storage medium A04. The network interface A02 is used for communication with a network. When the computer program B02 is executed by the processor A01, it implements the methods described in the foregoing embodiments.

[0149] In one embodiment of this specification, when the computer program B02 is executed by the processor A01, the method implemented may include:

[0150] Obtain the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device;

[0151] Based on the maximum evaluation value of each first target device and the maximum evaluation value of each corresponding associated device in the communication network, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network.

[0152] Based on the network attack logs of each second target device in the communication network, the threat value of the second target device is determined to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network.

[0153] Based on the security level of each third target device and the security level of each corresponding associated device in the communication network, the loss value of the third target device is determined to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0154] Based on specified parameter indicators of the communication network, the network risk value of the communication network is determined. The specified parameter indicators include node parameters, stability, threat value, and loss value.

[0155] Decision-making is performed based on the network risk value of the communication network.

[0156] One embodiment of this specification provides a machine-readable storage medium under the same inventive concept as the foregoing embodiments, storing machine instructions that, when executed on a machine, cause the machine to perform the methods in the foregoing embodiments. The machine may include a computer and devices with communication, computing, and instruction processing capabilities.

[0157] In one embodiment of this specification, when the machine instructions are executed on the machine, the method that the machine performs may include:

[0158] Obtain the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device;

[0159] Based on the maximum evaluation value of each first target device and the maximum evaluation value of each corresponding associated device in the communication network, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network.

[0160] Based on the network attack logs of each second target device in the communication network, the threat value of the second target device is determined to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network.

[0161] Based on the security level of each third target device and the security level of each corresponding associated device in the communication network, the loss value of the third target device is determined to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network.

[0162] Based on specified parameter indicators of the communication network, the network risk value of the communication network is determined. The specified parameter indicators include node parameters, stability, threat value, and loss value.

[0163] Decision-making is performed based on the network risk value of the communication network.

[0164] It should be noted that the information collection, analysis, use, transmission, and storage involved in this manual shall be used for legal and reasonable purposes in accordance with the provisions of laws and regulations, and shall not be shared, disclosed, or sold outside of these legal uses, and shall be subject to supervision and management in accordance with the law.

[0165] In implementation, each step of the above method can be completed by integrated logic circuits in the processor or by instructions in software. The processor may be an integrated circuit chip with signal processing capabilities. It can also be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; or a Digital Signal Processor (DSP), Application Specific Integrated Circuit (ASIC), Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this specification. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this specification can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0166] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0167] In summary, the above description is merely a preferred embodiment of this specification and is not intended to limit the scope of protection of this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.

[0168] The systems or modules described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a computer.

[0169] Machine-readable storage media can be computer storage media and can include permanent and non-permanent, removable and non-removable media. Information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0170] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0171] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A method for determining cybersecurity risks, characterized in that, The method includes: Obtain the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device; Based on the maximum evaluation value of each first target device and the maximum evaluation value of each corresponding associated device in the communication network, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network. Based on the network attack logs of each second target device in the communication network, the threat value of the second target device is determined to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network. Based on the security level of each third target device and the security level of each corresponding associated device in the communication network, the loss value of the third target device is determined to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network. Based on specified parameter indicators of the communication network, the network risk value of the communication network is determined. The specified parameter indicators include the node parameters, as well as the stability, threat value, and loss value of the communication network. Decision-making is performed based on the network risk value of the communication network. The step of determining the stability of the first target devices under security monitoring based on the maximum evaluation value of each first target device in the communication network and the maximum evaluation value of each corresponding associated device, in order to obtain the stability of the communication network, includes: Based on the maximum evaluation values ​​of the first target device and its corresponding associated device in the communication network, the relative stability of the first target device under security monitoring relative to the associated device is determined. The relative stability is used to evaluate the degree to which the first target device is affected by vulnerabilities in the communication network. The stability of the first target device is determined based on its relative stability with respect to all associated devices. The stability of the communication network is determined based on the stability of each first target device in the communication network.

2. The method for determining network security risks according to claim 1, characterized in that, The step of determining the threat value of the second target device based on the network attack logs of each second target device in the communication network to obtain the threat value of the communication network includes: Based on the network attack logs of the second target device in the communication network, predict the probability of occurrence of each vulnerability attack event of the second target device; Based on the assessment values ​​of the maximum probability of occurrence and the corresponding vulnerability severity, the threat value of the second target device is determined; The threat value of the communication network is determined based on the threat value of each second target device.

3. The method for determining network security risks according to claim 1, characterized in that, The step of determining the loss value of the third target device and the loss value of the communication network based on the security level of each third target device and the security level of each corresponding associated device in the communication network includes: Based on the highest security level among all associated devices in the communication network, the loss value of the third target device is determined. Determine the loss value and corresponding node degree of each device in the communication network, and determine the maximum loss value and maximum node degree; The loss value of the communication network is determined based on the ratio of the maximum loss value to the maximum node degree.

4. The method for determining network security risks according to claim 1, characterized in that, The specified parameter indicators also include: network size coefficient; Before determining the network risk value of the communication network based on specified parameter indicators of the communication network, the method further includes: obtaining a network scale coefficient.

5. The method for determining network security risks according to claim 4, characterized in that, The acquisition of network size coefficients includes: The maximum node degree is determined based on the node degree corresponding to each device in the communication network. The network size coefficient is determined based on the maximum node degree and the total number of nodes in the topology.

6. The method for determining network security risks according to claim 4, characterized in that, Determining the network risk value of the communication network based on specified parameter indicators of the communication network includes: The network risk value of the communication network is obtained by multiplying the network size coefficient, stability, threat value, and loss value of the communication network.

7. A network risk handling device, characterized in that, The network risk handling device includes: The acquisition module is used to acquire the node parameters of each device in the communication network in the topology of the communication network and the assessment values ​​of the severity of various vulnerabilities of each device. The stability assessment module is used to determine the stability of the first target device under security monitoring based on the maximum assessment value of each first target device and the maximum assessment value of each corresponding associated device in the communication network, so as to obtain the stability of the communication network. The first target device and the corresponding associated device are connected by an edge in the topology. The stability of the communication network is used to assess the impact of vulnerabilities within the communication network. The threat assessment module is used to determine the threat value of the second target device based on the network attack logs of each second target device in the communication network to obtain the threat value of the communication network. The threat value of the communication network is used to assess the degree of impact of attacks outside the communication network. The loss assessment module is used to determine the loss value of each third target device in the communication network based on the security level of each third target device and the security level of each corresponding associated device, and to determine the loss value of the communication network. The loss value of the communication network is used to assess the degree of damage to the communication network. The risk determination module is used to determine the network risk value of the communication network based on specified parameter indicators of the communication network. The specified parameter indicators include the node parameters, as well as the stability, threat value, and loss value of the communication network. The decision processing module is used to perform decision processing based on the network risk value of the communication network; In the stability assessment module, based on the maximum assessment value of each first target device in the communication network and the maximum assessment value of each corresponding associated device, the stability of the first target device under security monitoring is determined to obtain the stability of the communication network, including: Based on the maximum evaluation values ​​of the first target device and its corresponding associated device in the communication network, the relative stability of the first target device under security monitoring relative to the associated device is determined. The relative stability is used to evaluate the degree to which the first target device is affected by vulnerabilities in the communication network. The stability of the first target device is determined based on its relative stability with respect to all associated devices. The stability of the communication network is determined based on the stability of each first target device in the communication network.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; A memory connected to the at least one processor; The memory stores instructions executable by the at least one processor, which implements the method described in any one of claims 1 to 6 by executing the instructions stored in the memory.

9. A machine-readable storage medium storing machine instructions that, when executed on a machine, cause the machine to perform the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network security risk assessment method, system and device

    CN113542279A