A network security evaluation method

By employing a linear boundary assessment model in cybersecurity assessment and utilizing feature thresholds to evaluate cybersecurity data, the inaccuracy problem caused by the reliance on expert experience in traditional methods is solved, achieving more accurate security risk assessment and efficient data classification.

CN118869331BActive Publication Date: 2026-01-23CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411142594.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-19
Publication Date
2026-01-23
Estimated Expiration
2044-08-19

AI Technical Summary

Technical Problem

Existing cybersecurity assessment methods rely on expert experience, resulting in poor accuracy of assessment results that fail to accurately reflect the true state of cybersecurity.

Method used

A linear boundary assessment model is adopted, which evaluates network security data through feature thresholds to achieve linear data partitioning, avoid the influence of human factors, and improve the accuracy of assessment results.

Benefits of technology

The linear boundary assessment model can effectively avoid the influence of human factors, improve the accuracy and classification ability of safety risk assessment results, and is suitable for rapid classification of large-scale datasets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118869331B_ABST
    Figure CN118869331B_ABST
Patent Text Reader

Abstract

The application discloses a network security evaluation method, which comprises the following steps: obtaining target network security data of a system network; inputting the target network security data into an evaluation model, evaluating the target network security data through a feature threshold in the evaluation model, obtaining an evaluation result, and the feature threshold of the evaluation model is a linear boundary, which is used for linearly dividing the target network security data to obtain network security classifications of different categories of the target network security data. According to the application, the input target network security data is linearly divided through the feature threshold, different network security classifications to which the target network security data belongs are determined, and through the automatic evaluation process, the accuracy and objectivity of the network security evaluation result are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security technology, and in particular relates to a network security assessment method, apparatus, device, computer storage medium, and program product. Background Technology

[0002] With the evolution and development of information and communication technologies, network information security has evolved from simply keeping information confidential to assessing the integrity and availability of information, and further to encompassing fundamental theories and implementation technologies related to "attack, prevention, detection, control, management, and evaluation." To manage and safeguard network information security, it is necessary to conduct security risk assessments of network information.

[0003] There are many existing traditional safety risk assessment methods, but these methods rely on the experience of experts to determine the relevant parameters of the assessment model, which is easily affected by subjective human factors, resulting in poor accuracy of the safety risk assessment results. Summary of the Invention

[0004] This application provides a network security assessment method, apparatus, device, computer storage medium, and program product to address the problem of poor accuracy in the assessment results of existing security risk assessment methods.

[0005] In a first aspect, embodiments of this application provide a network security assessment method, the method comprising:

[0006] Obtain target network security data from the system network;

[0007] The target network security data is input into the evaluation model, and the target network security data is evaluated by the feature thresholds in the evaluation model to obtain the evaluation results. The feature thresholds of the evaluation model are linear boundaries, which are used to linearly divide the target network security data to obtain different categories of network security classification of the target network security data.

[0008] Secondly, embodiments of this application provide a network security assessment device, which includes:

[0009] The acquisition module is used to acquire target network security data of the system network;

[0010] The detection module is used to input target network security data into the evaluation model, evaluate the target network security data through the feature thresholds in the evaluation model, and obtain the evaluation results. The feature thresholds of the evaluation model are linear boundaries, which are used to linearly divide the target network security data to obtain different categories of network security classification of the target network security data.

[0011] Thirdly, embodiments of this application provide a terminal device, the device including: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the network security assessment method as described in the first aspect.

[0012] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the network security assessment method as described in the first aspect.

[0013] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the network security assessment method as described in the first aspect.

[0014] This application provides a network security assessment method, apparatus, device, computer storage medium, and program product. First, target network security data of the system network is acquired. The target network security data is then input into an assessment model, and the model's feature thresholds are used to evaluate the data, yielding assessment results. The feature thresholds of the assessment model are linear boundaries, used to linearly divide the target network security data, resulting in different network security classifications. By setting the feature thresholds of the assessment model as linear boundaries, different categories of data points can be divided in different dimensional feature spaces, improving the model's classification ability. The assessment results are obtained by inputting the data to be detected into the assessment model, and the model's feature thresholds are trained using known assessment data, eliminating the need for manual parameter setting and effectively avoiding the influence of human factors, thus improving the accuracy of security risk assessment results. Attached Figure Description

[0015] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 This is a schematic diagram of a system architecture that can implement the network security assessment method provided in the embodiments of this application;

[0017] Figure 2 This is a flowchart illustrating the network security assessment method provided in the embodiments of this application;

[0018] Figure 3 This is a schematic diagram of data points in a two-dimensional space provided in the embodiments of this application.

[0019] Figure 4 This is a schematic diagram of the network security assessment device provided in the embodiments of this application;

[0020] Figure 5 This is a schematic diagram of the structure of the terminal device provided in the embodiments of this application. Detailed Implementation

[0021] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0022] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0023] Current cybersecurity assessment methods primarily employ fault tree analysis (FPA), analytic hierarchy process (AHP), fuzzy comprehensive evaluation, and assessment methods based on Dexterity and Data Security (DS) evidence theory. However, these traditional methods rely heavily on expert experience, determining the parameters of the assessment model based on expert judgment. This results in poor model performance and susceptibility to human influence. For example, while FPA can clearly demonstrate the causes and paths of system failures, it requires substantial amounts of accurate data. AHP, in constructing relation matrices and weight vectors, struggles to directly compare the importance of cybersecurity risk factors, thus requiring human judgment to provide the necessary data. This leads to subjective and inaccurate cybersecurity assessment results that fail to accurately reflect the true state of cybersecurity.

[0024] The following section first provides an example of a system framework that can be applied to the network security assessment method provided in the embodiments of this application.

[0025] like Figure 1As shown, the system may include an evaluation model building module, a vulnerability scanning module, and a risk analysis module.

[0026] The assessment model construction module includes a risk data acquisition unit, a risk data processing unit, and an assessment model construction unit; the vulnerability scanning module includes a vulnerability scanning unit and a vulnerability exploitation testing unit; the risk analysis module includes a threat analysis unit, a vulnerability analysis unit, a comprehensive risk analysis unit, and a risk assessment unit. The risk data acquisition unit collects existing risk data, the risk data processing unit processes the collected risk data, and the assessment model construction module constructs a security assessment model from the processed risk data. The vulnerability scanning unit scans the network system for vulnerabilities, tests the detected vulnerabilities using the vulnerability exploitation testing module, and then analyzes the test data using the risk analysis module. Specifically, the threat analysis unit analyzes the current threat situation, including known and potential threats; the vulnerability analysis unit analyzes vulnerabilities existing in the system, including vulnerabilities and configuration errors; the comprehensive risk analysis unit comprehensively considers threats, vulnerabilities, and other factors to analyze and assess the overall risk of the system; and the risk assessment unit assesses and quantifies the risk level of the system based on the comprehensive risk analysis results.

[0027] To address the shortcomings of existing technologies, this application provides a network security assessment method. First, known network security data is acquired, and a network security assessment model is established based on this data. The linear boundary of the network security assessment model is optimized by setting the feature threshold of the assessment model as the linear boundary. This allows different categories of data points to be divided in different dimensional feature spaces, improving the model's classification ability. The method maximizes the shortest distance between the network security data and the linear boundary in the spatial representation of the linear boundary. Second, target network security data to be assessed is collected. The target network security data is then dimensionality-reduced using a covariance formula to reduce data complexity, improve computational efficiency, and retain the main features of the data, facilitating better understanding and processing of the target network security data. The dimensionality-reduced target network security data is input into the assessment model, and linearly divided according to the linear boundary in the assessment model to obtain different categories of network security classifications. Specifically, during the linear division of the target network security data, mapping the data to a high-dimensional space makes the originally linearly inseparable target network security data linearly separable, improving the accuracy and efficiency of classification. The distance between each target network security data and the linear boundary in a high-dimensional space is calculated based on the relationship between the weight vector, bias term, mapping data, and distance. Network security is then classified based on the calculated distance. This eliminates the need for manually setting relevant parameters, effectively avoiding the influence of human factors and improving the accuracy of security risk assessment results.

[0028] The network security assessment method provided in the embodiments of the present invention will be described below.

[0029] Figure 2 A flowchart illustrating a network security assessment method provided in one embodiment of this application is shown. Figure 2 As shown, the method may include the following steps: S201 to S202.

[0030] S201, Obtain target network security data of the system network.

[0031] In some embodiments, the system network may include chips, system hardware, system physical environment, and system software.

[0032] In some embodiments, the target network security data for the chip may include chip side-channel data; the target network security data for the system hardware may include device authentication records and hardware detection records; the target security data for the system physical environment may include physical access control records and environmental monitoring data; and the target network security data for the system software may include vulnerability scanning records, malicious code analysis data, and user authentication records.

[0033] S202, Input the target network security data into the evaluation model, evaluate the target network security data through the feature thresholds in the evaluation model, and obtain the evaluation results. The feature thresholds of the evaluation model are linear boundaries, which are used to linearly divide the target network security data to obtain network security classifications of different categories of the target network security data.

[0034] In some embodiments, network security classification may include threat classification and vulnerability classification. Threat classification may include threat source classification, threat subject classification, threat type, threat object, threat timing, and threat frequency. Vulnerability classification may include physical environment vulnerability, network structure vulnerability, host system vulnerability, database vulnerability, application middleware vulnerability, and security management vulnerability.

[0035] This application provides a network security assessment method. First, target network security data of the system network is acquired. The target network security data is then input into an assessment model, and the target network security data is assessed using feature thresholds in the assessment model to obtain assessment results. The feature thresholds of the assessment model are linear boundaries, used to linearly divide the target network security data, resulting in different network security classifications of the target network security data. By setting the feature thresholds of the assessment model as linear boundaries, different categories of data points can be divided in feature spaces of different dimensions, improving the model's classification ability. The assessment results are obtained by inputting the data to be detected into the assessment model, and the feature thresholds of the assessment model are trained using known assessment data, eliminating the need for manual parameter setting. This effectively avoids the influence of human factors and improves the accuracy of security risk assessment results.

[0036] In some embodiments, the target network security data is network security data of the chip-side channel. Obtaining the target network security data of the system network includes:

[0037] Obtain the parameter fingerprint of the chip's side channel; the parameter fingerprint is feature data.

[0038] Based on the parameter fingerprint, simulation of the chip circuit is performed to obtain multi-dimensional side channel signal data;

[0039] The multidimensional side channel signal data is reduced in dimensionality by calculating the covariance matrix, and the reduced multidimensional side channel signal data is used as the network security data of the target network.

[0040] By acquiring the parameter fingerprints of the chip side channels and performing simulations based on the chip circuits, the obtained data becomes more realistic and reliable. By performing dimensionality reduction processing on the multi-dimensional side channel signal data, highly characteristic multi-dimensional side channel signal data can be obtained, improving the accuracy and reliability of network security analysis.

[0041] In some embodiments, when multidimensional side-channel signal data is obtained by simulating the chip circuit based on the parameter fingerprint, circuit simulation is performed using Monte Carlo analysis.

[0042] In some embodiments, the linear boundary includes a weight vector and a bias term. Target cybersecurity data is input into the evaluation model, and the target cybersecurity data is evaluated using feature thresholds in the evaluation model to obtain the evaluation result, including:

[0043] The target network security data is input into the evaluation model, and the target network security data is mapped to a high-dimensional space according to a preset function to obtain the mapping data of the target network security data in the high-dimensional space. The high-dimensional space is the space in which the target network security data is linearly separable.

[0044] The distance between each target network security data and the linear boundary in high-dimensional space is calculated based on the relationship between the weight vector, bias term, mapping data and distance.

[0045] Based on the distance of the target network security data to the linear boundary and the preset classification range, the target network security data is assigned to the target network security category, and the evaluation result is obtained. The target network security category is the network security category corresponding to the classification range to which the distance of the target network security data to the linear boundary belongs.

[0046] By mapping target cybersecurity data to a high-dimensional space to make it linearly separable, the classification problem is simplified compared to the low-dimensional space that cannot be linearly divided. It has high computational efficiency, is suitable for processing large-scale datasets, and can quickly classify data, improving the accuracy and reliability of classification.

[0047] In some embodiments, the evaluation model includes multiple evaluation sub-models, each corresponding to a network security classification, which divides the target network security data into positive and negative categories. For example, the network security classification corresponding to the evaluation sub-model is whether the chip circuit of the network system has redundant circuits. The target network security data is divided into positive categories, which can be chip circuits without redundant circuits, and negative categories, which can be chip circuits with redundant circuits.

[0048] In some embodiments, network security is assessed based on the classification results of target network security data. When the number of target network security data classified as negative exceeds a set threshold, the system network is considered to have a risk corresponding to the negative network security classification. For example, if the negative category of target network security data is "chip circuit with redundant circuits" and the number of target network security data classified as negative exceeds a set threshold, the chip circuit is considered to have a risk of redundant circuits.

[0049] In some embodiments, the relationship between the weight vector, bias term, mapping data, and distance may include:

[0050]

[0051] Where D is the distance, w is the weight vector, b is the bias term, and w T x is the transpose of the weight vector. i Let ||w|| be the mapping data, and ||w|| be the norm of the weight vector.

[0052] In some embodiments, when the distance is positive, the target network security data is classified as positive; when the distance is negative, the target network security data is classified as negative. The positive and negative classes of network security classification are selected according to actual needs.

[0053] In some embodiments, the chip circuit is simulated based on the parameter fingerprint to obtain multi-dimensional side-channel signal data, including:

[0054] Obtain the known target parameter fingerprint range of the chip;

[0055] Filter the parameter fingerprints that fall within the target parameter fingerprint range to obtain the target parameter fingerprint;

[0056] Circuit simulation is performed based on the target parameter fingerprint and the known chip circuit to obtain multi-dimensional side channel signal data.

[0057] By obtaining the target parameter fingerprint range of a known chip and filtering the parameter fingerprints, we can ensure that the parameter fingerprints used in the simulation process are highly reliable, thereby improving the accuracy and reliability of circuit simulation. Simulation based on known chip circuits can realize the simulation of specific chips, which helps to conduct comprehensive analysis and evaluation of chip circuits.

[0058] In some embodiments, the method further includes, before inputting the target cybersecurity data into the evaluation model:

[0059] Acquire known cybersecurity assessment data, which includes cybersecurity data and corresponding cybersecurity classifications;

[0060] Based on network security data and corresponding network security classifications, a target linear boundary is selected by optimizing the preset linear boundary, and a network security assessment model is established. The target linear boundary enables the network security data to be linearly divided according to the network security classification, and maximizes the shortest distance between the network security data and the linear boundary in space.

[0061] By optimizing the selection of target linear boundaries, more accurate classification of cybersecurity data can be achieved. Data closer to the classification boundary is more likely to be misidentified. By maximizing the shortest distance between cybersecurity data and the linear boundary in space, the model's ability to detect cybersecurity data can be improved, thus enhancing the model's robustness.

[0062] In one example, when network security data is network traffic data, the corresponding network security classification is malicious traffic and normal traffic. The preset linear boundary is optimized based on the network security traffic data so that malicious traffic and normal traffic are on opposite sides of the linear boundary, and the shortest distance between malicious traffic and normal data and the linear boundary is maximized within the space where the linear boundary is located.

[0063] In some embodiments, a network security assessment model is established by optimizing a preset linear boundary based on network security data and corresponding network security classifications to select a target linear boundary, including:

[0064] Based on a preset function, network security data is mapped to a high-dimensional space to obtain the mapping data of network security data in the high-dimensional space, which is the space in which network security data is linearly separable;

[0065] Constraints are determined based on the relationship between the mapping data, the corresponding cybersecurity classification, the weight vector, and the bias value. The linear boundary of the security assessment model is optimized with the goal of minimizing the norm of the weight vector, resulting in a cybersecurity assessment model where the norm is the square root of the sum of squares of the elements within the weight vector.

[0066] By mapping cybersecurity data to a high-dimensional space, the data becomes linearly separable, enhancing the effectiveness and accuracy of classification. The norm represents the size or length of the weight vector. By minimizing the norm of the weight vector, the complexity of the model can be effectively controlled, the risk of overfitting can be reduced, and the generalization ability of the model can be improved.

[0067] In some embodiments, the relationship between the mapping data, the corresponding evaluation category, the weight vector, and the bias value is as follows:

[0068] The weight vector is multiplied by the feature vector of the mapped data and then summed with the bias value to obtain the summation result.

[0069] The summation result is multiplied by the evaluation label corresponding to the mapped data to obtain the multiplication result. The evaluation label is the value corresponding to the preset evaluation category, and the multiplication result is greater than or equal to one.

[0070] The summation result is actually the distance from the mapped data to the linear boundary. When the distance is positive, the sample is classified as positive, and when the distance is negative, the sample is classified as negative. The evaluation label of the positive class is set to a positive number, and the evaluation label of the negative class is set to a negative number. Multiplying the summation result by the evaluation label makes the result positive, which can ensure that the mapped data is classified into the correct category. The multiplication result is greater than or equal to one, which can ensure that the mapped data has a certain gap with the linear boundary, increasing the generalization ability of the model.

[0071] In one example, the relationship between the mapped data, the corresponding evaluation categories, the weight vector, and the bias values ​​includes:

[0072]

[0073] Among them, y i For evaluating the categories, w is the weight vector and b is the bias value. This is the mapped data.

[0074] In some embodiments, before optimizing and selecting a target linear boundary based on network security data and corresponding network security classifications to establish a network security assessment model, the method further includes:

[0075] The correlation probability is calculated based on the relationship between the assessment characteristics and assessment categories of cybersecurity data, and cybersecurity data with a correlation probability greater than a set threshold is selected as new cybersecurity data.

[0076] By calculating the association probability and setting a threshold, data points that are not strongly related to the evaluation category can be removed, and only data that are highly related to the evaluation category can be focused on. This reduces the amount of computation and improves the efficiency of model training and the accuracy of model classification.

[0077] In some embodiments, the relationship between the assessment characteristics and assessment categories of cybersecurity data is as follows:

[0078]

[0079] Where A is the evaluation feature, B is the evaluation category, P(B|A) is the probability of being evaluated as evaluation category B when evaluation feature A is present, P(A|B) is the probability of having evaluation feature A when evaluation category B is present, P(B) is the probability of evaluation category B, and P(A) is the probability of having evaluation feature A.

[0080] In some embodiments, the multidimensional side channel data is reduced in dimensionality by calculating the covariance matrix to obtain multidimensional side channel signal data, including:

[0081] Calculate the mean eigenvalue of the corresponding feature of the multidimensional side channel signal data and subtract the mean eigenvalue of each feature from the eigenvalue of that feature to obtain the target feature value;

[0082] A covariance matrix is ​​constructed based on the target eigenvalues, where each element of the covariance matrix represents the covariance between two eigenvalues.

[0083] Eigenvalue decomposition of the covariance matrix yields multiple eigenvalues ​​and corresponding eigenvectors;

[0084] Select the eigenvectors corresponding to eigenvalues ​​exceeding a set threshold as column vectors to construct the projection matrix;

[0085] The multidimensional side channel signal data is projected onto the target feature space through a projection matrix to obtain the dimensionality-reduced multidimensional side channel signal data.

[0086] By setting the covariance matrix, the linear correlation between data features is quantified. The larger the eigenvalue corresponding to the eigenvector, the more important the eigenvector is. Filtering eigenvectors corresponding to eigenvalues ​​exceeding the set threshold can remove redundant information, which helps to improve the accuracy of classification, reduce the number of features, and reduce the complexity and computational cost of the model.

[0087] The actual purpose of dimensionality reduction is to rotate the coordinate axes so that the projections of each data point on the new coordinate axes are dispersed. The more dispersed the data points are, the more information the data carries. The amount of information is defined by variance.

[0088] In one example, such as Figure 3 As shown in the figure, the points are randomly generated data points with certain correlations in a two-dimensional space. When the data points are projected onto the dashed line position, they contain more information than when they are projected onto the x-axis or y-axis.

[0089] In some embodiments, the covariance matrix can be represented as:

[0090] XX T =QDQ T

[0091] Among them, XX T Let X be the covariance matrix of the target eigenvalues, and let X be the data matrix constructed from the target eigenvalues. T Let X be the transpose of X, Q be an orthogonal matrix formed by the eigenvectors of the covariance matrix, and D be a diagonal matrix whose diagonal lines are the eigenvalues ​​of the covariance matrix. T Let Q be the transpose of Q.

[0092] In some embodiments, the feature vectors corresponding to feature values ​​exceeding a set threshold are selected as column vectors to construct a projection matrix, that is, the first k columns of matrix Q are selected as projection matrix P, where k is a preset value, and the data matrix Y = PX in the target feature space is used.

[0093] In some embodiments, before simulating the chip circuit based on the parameter fingerprint to obtain the multi-dimensional side-channel signal data, the method further includes:

[0094] Calculate the distance between each parameter fingerprint and other parameter fingerprints in the feature space;

[0095] Calculate the average distance of each parameter fingerprint to a set number of neighboring parameter fingerprints;

[0096] Remove parameter fingerprints whose average distance is greater than a set threshold.

[0097] By removing parameter fingerprints whose average distance is greater than a set threshold, outliers or noisy data that differ significantly from other parameter fingerprints can be removed, thereby improving data quality and reliability.

[0098] In some embodiments, before simulating the chip circuit based on the parameter fingerprint to obtain the multi-dimensional side-channel signal data, the method further includes:

[0099] When a feature value of a parameter fingerprint is missing, the missing feature value is replaced with the mean or a fixed value of that feature.

[0100] By replacing missing feature values ​​with the mean or a fixed value of the feature, the continuity of the simulation process and the integrity of the data can be guaranteed, avoiding simulation interruptions or deviations caused by missing data.

[0101] In some embodiments, before simulating the chip circuit based on the parameter fingerprint to obtain the multi-dimensional side-channel signal data, the method further includes:

[0102] When the parameter fingerprint types are unbalanced, filter the target parameter fingerprints that are adjacent to each minority of parameter fingerprint types by a set number;

[0103] Randomly select a target parameter fingerprint and calculate the difference between the corresponding parameter fingerprint and the target parameter fingerprint;

[0104] Based on the difference and random minority type parameter fingerprints, generate new parameter fingerprints such that the number of majority type parameter fingerprints is the same as the number of minority type parameter fingerprints.

[0105] By generating new parameter fingerprints to expand the minority types, the dataset can be expanded when there is little data without increasing the additional data collection cost, and the average number of majority type fingerprint parameters and minority type parameter fingerprints can be increased.

[0106] In some embodiments, before simulating the chip circuit based on the parameter fingerprint to obtain the multi-dimensional side-channel signal data, the method further includes:

[0107] When the parameter fingerprint types are unbalanced, the majority type parameter fingerprints are randomly selected and discarded, so that the number of the majority type parameter fingerprints is the same as the number of the minority type parameter fingerprints.

[0108] By randomly discarding the majority type of parameter fingerprints, the ratio of majority type parameter fingerprints to minority type parameter fingerprints can be quickly adjusted when the dataset is large and the parameter fingerprint types are unbalanced. This does not require a complex calculation process, is easy to implement, and reduces the consumption of computing resources, thus improving efficiency.

[0109] Figure 4 A schematic diagram of the network security assessment device provided in an embodiment of this application is shown. Figure 4 As shown, the device may include an acquisition module 401 and a detection module 402.

[0110] Module 401 is used to acquire target network security data of the system network;

[0111] The detection module 402 is used to input the target network security data into the evaluation model, evaluate the target network security data through the feature thresholds in the evaluation model, and obtain the evaluation results. The feature thresholds of the evaluation model are linear boundaries, which are used to linearly divide the target network security data to obtain different categories of network security classification of the target network security data.

[0112] In some embodiments, the target network security data is network security data of the chip-side channel, and the acquisition module is further used to acquire the parameter fingerprint of the chip-side channel, wherein the parameter fingerprint is feature data.

[0113] The acquisition module is also used to perform simulation based on the chip circuit according to the parameter fingerprint to obtain multi-dimensional side channel signal data;

[0114] The acquisition module is also used to perform dimensionality reduction processing on the multidimensional side channel signal data by calculating the covariance matrix, and obtain the dimensionality-reduced multidimensional side channel signal data, which is then used as the target network security data.

[0115] In some embodiments, the linear boundary includes a weight vector and a bias term. The detection module is also used to input the target network security data into the evaluation model and map the target network security data to a high-dimensional space according to a preset function to obtain the mapping data of the target network security data in the high-dimensional space. The high-dimensional space is the space in which the target network security data is linearly separable.

[0116] The detection module is also used to calculate the distance between each target network security data and the linear boundary in high-dimensional space based on the relationship between the weight vector, bias term, mapping data and distance;

[0117] The detection module is also used to assign the target network security data to the target network security category based on the distance from the target network security data to the linear boundary and the preset classification range, and obtain the evaluation result. The target network security category is the network security category corresponding to the classification range to which the distance from the target network security data to the linear boundary belongs.

[0118] In some embodiments, the acquisition module is further configured to acquire the known target parameter fingerprint range of the chip;

[0119] The acquisition module is also used to filter parameter fingerprints within the target parameter fingerprint range to obtain the target parameter fingerprint;

[0120] The acquisition module is also used to perform circuit simulation based on the target parameter fingerprint and known chip circuits to obtain multi-dimensional side channel signal data.

[0121] In some embodiments, before inputting the target cybersecurity data into the evaluation model, the acquisition module is also used to acquire known cybersecurity evaluation data, which includes cybersecurity data and corresponding cybersecurity classifications.

[0122] The detection module is also used to optimize and select target linear boundaries based on network security data and corresponding network security classifications, and to establish a network security assessment model. The target linear boundaries enable network security data to be linearly divided according to network security classifications, and maximize the shortest distance between network security data and the linear boundary in space.

[0123] In some embodiments, the detection module is further configured to map network security data to a high-dimensional space according to a preset function, thereby obtaining the mapping data of network security data in the high-dimensional space, wherein the high-dimensional space is a space in which network security data is linearly separable.

[0124] The detection module is also used to determine constraints based on the relationship between the mapping data, the network security classification corresponding to the mapping data, the weight vector, and the bias value. With the goal of minimizing the norm of the weight vector, the linear boundary of the security assessment model is optimized to obtain the network security assessment model. The norm is the square root of the sum of squares of the elements in the weight vector.

[0125] In some embodiments, the detection module is further configured to multiply the weight vector by the feature vector of the mapped data and sum the result with the bias value to obtain a summation result;

[0126] The detection module is also used to multiply the summation result with the evaluation label corresponding to the mapping data to obtain the multiplication result. The evaluation label is the value corresponding to the preset evaluation category, and the multiplication result is greater than or equal to one.

[0127] In some embodiments, before optimizing and selecting target linear boundaries based on network security data and corresponding network security classifications to establish a network security assessment model, the acquisition module is further used to calculate the correlation probability based on the relationship between the assessment characteristics and assessment categories of network security data, and select network security data with a correlation probability greater than a set threshold as new network security data.

[0128] In some embodiments, the detection module is further configured to calculate the feature mean of the corresponding feature of the multidimensional side channel signal data and subtract the feature mean of the feature from the feature value of each feature to obtain the target feature value;

[0129] The detection module is also used to build a covariance matrix based on the target feature values, where each element of the covariance matrix represents the covariance between two features;

[0130] The detection module is also used to perform eigenvalue decomposition on the covariance matrix to obtain multiple eigenvalues ​​and corresponding eigenvectors;

[0131] The detection module is also used to select the feature vectors corresponding to feature values ​​that exceed a set threshold as column vectors to construct the projection matrix;

[0132] The detection module is also used to project the multidimensional side channel signal data onto the target feature space through a projection matrix to obtain the dimensionality-reduced multidimensional side channel signal data.

[0133] In some embodiments, before obtaining multidimensional side channel signal data by simulating the chip circuit based on the parameter fingerprint, the acquisition module is also used to calculate the distance between each parameter fingerprint and other parameter fingerprints in the feature space.

[0134] The acquisition module is also used to calculate the average distance of each parameter fingerprint to a set number of neighboring parameter fingerprints;

[0135] The acquisition module is also used to remove parameter fingerprints whose average distance is greater than a set threshold.

[0136] Figure 4 The various modules in the device shown can achieve Figure 2 The various steps involved, and the corresponding technical effects achieved, will not be elaborated upon here for the sake of brevity.

[0137] Figure 5 A schematic diagram of the hardware structure of the terminal device provided in an embodiment of this application is shown.

[0138] The terminal device may include a processor 501 and a memory 502 storing computer program instructions.

[0139] Specifically, the processor 501 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0140] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 502 may include removable or non-removable (or fixed) media, or memory 502 may be non-volatile solid-state storage. Memory 502 may be internal or external to the integrated gateway disaster recovery device.

[0141] In one instance, memory 502 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform operations described with reference to the cybersecurity assessment method according to this disclosure.

[0142] The processor 501 reads and executes computer program instructions stored in the memory 502 to achieve... Figure 2 The network security assessment method in the illustrated embodiment.

[0143] In one example, the terminal device may also include a communication interface 503 and a bus 504. Wherein, for example... Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 504 and complete communication with each other.

[0144] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0145] Bus 504 includes hardware, software, or both, that couples components of an end device together. For example, and not as a limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 504 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.

[0146] Furthermore, in conjunction with the network security assessment methods in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the network security assessment methods in the above embodiments.

[0147] This application also provides a computer program product, including a computer program, which, when executed, implements any of the network security assessment methods described in the above embodiments.

[0148] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0149] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or text segments used to perform the required tasks. Programs or text segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Text segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0150] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0151] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0152] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A network security assessment method, characterized in that, The method includes: Obtain target network security data from the system network; The target network security data is input into the evaluation model, and the target network security data is evaluated through the feature thresholds in the evaluation model to obtain the evaluation result. The feature thresholds of the evaluation model are linear boundaries, which are used to linearly divide the target network security data to obtain network security classifications of different categories of the target network security data. The linear boundary includes a weight vector and a bias term. The process of inputting the target network security data into the evaluation model, evaluating the target network security data using feature thresholds in the evaluation model, and obtaining the evaluation result includes: The target network security data is input into the evaluation model, and the target network security data is mapped to a high-dimensional space according to a preset function to obtain the mapping data of the target network security data in the high-dimensional space, wherein the high-dimensional space is a space that makes the target network security data linearly separable. The distance between each target network security data and the linear boundary in the high-dimensional space is calculated based on the relationship between the weight vector, bias term, mapping data and distance. The target network security data is assigned to a target network security category based on the distance from the target network security data to the linear boundary and a preset classification range, and an evaluation result is obtained. The target network security category is the network security category corresponding to the classification range to which the distance from the target network security data to the linear boundary belongs. Before inputting the target cybersecurity data into the evaluation model, the method further includes: Acquire known cybersecurity assessment data, which includes cybersecurity data and corresponding cybersecurity classifications; Based on the network security data and the corresponding network security classification, a target linear boundary is selected by optimizing the preset linear boundary, and a network security assessment model is established. The target linear boundary enables the network security data to be linearly divided according to the network security classification, and maximizes the shortest distance between the network security data and the linear boundary in space.

2. The network security assessment method according to claim 1, characterized in that, The target network security data is the network security data of the chip side channel. The acquisition of the target network security data of the system network includes: Obtain the parameter fingerprint of the chip side channel, wherein the parameter fingerprint is feature data; Based on the parameter fingerprint, simulation of the chip circuit is performed to obtain multi-dimensional side-channel signal data; The multidimensional side channel signal data is reduced in dimensionality by calculating the covariance matrix, and the reduced multidimensional side channel signal data is used as the target network security data.

3. The network security assessment method according to claim 2, characterized in that, The step of simulating the chip circuit based on the parameter fingerprint to obtain multi-dimensional side-channel signal data includes: Obtain the known target parameter fingerprint range of the chip; The target parameter fingerprint is obtained by filtering the parameter fingerprints within the range of the target parameter fingerprint. Circuit simulation is performed based on the target parameter fingerprint and the known chip circuit to obtain multi-dimensional side channel signal data.

4. The network security assessment method according to claim 1, characterized in that, The step of optimizing and selecting a target linear boundary based on the network security data and corresponding network security classification, and establishing a network security assessment model, includes: The network security data is mapped to a high-dimensional space according to a preset function to obtain the mapping data of the network security data in the high-dimensional space, wherein the high-dimensional space is a space in which the network security data is linearly separable. Constraints are determined based on the relationship between the mapping data, the corresponding network security classification, the weight vector, and the bias value. The linear boundary of the security assessment model is optimized with the goal of minimizing the norm of the weight vector, resulting in the network security assessment model. The norm is the square root of the sum of squares of the elements within the weight vector.

5. The network security assessment method according to claim 4, characterized in that, The relationship between the mapping data, the corresponding evaluation category, the weight vector, and the bias value is as follows: The weight vector is multiplied by the feature vector of the mapped data and then summed with the bias value to obtain the summation result. The summation result is multiplied by the evaluation label corresponding to the mapping data to obtain the multiplication result. The evaluation label is the value corresponding to the preset evaluation category, and the multiplication result is greater than or equal to one.

6. The network security assessment method according to claim 1, characterized in that, Before optimizing and selecting the target linear boundary based on the network security data and the corresponding network security classification to establish a network security assessment model, the method further includes: The correlation probability is calculated based on the relationship between the assessment characteristics and assessment categories of cybersecurity data, and cybersecurity data with a correlation probability greater than a set threshold is selected as new cybersecurity data.

7. The network security assessment method according to claim 2, characterized in that, The step of reducing the dimensionality of the multidimensional side channel data by calculating the covariance matrix to obtain multidimensional side channel signal data includes: Calculate the mean eigenvalue of the corresponding feature of the multidimensional side channel signal data and subtract the mean eigenvalue of each feature from the eigenvalue of that feature to obtain the target feature value; A covariance matrix is ​​established based on the target feature values, where each element of the covariance matrix represents the covariance between two features; Eigenvalue decomposition of the covariance matrix yields multiple eigenvalues ​​and corresponding eigenvectors; Select the eigenvectors corresponding to eigenvalues ​​exceeding a set threshold as column vectors to construct the projection matrix; The multidimensional side channel signal data is projected onto the target feature space through a projection matrix to obtain the dimensionality-reduced multidimensional side channel signal data.

8. The network security assessment method according to claim 2, characterized in that, Before performing simulation based on the chip circuit according to the parameter fingerprint to obtain multi-dimensional side-channel signal data, the method further includes: Calculate the distance between each parameter fingerprint and other parameter fingerprints in the feature space; Calculate the average distance of each parameter fingerprint to a set number of neighboring parameter fingerprints; Remove parameter fingerprints whose average distance is greater than a set threshold.

Citation Information

Patent Citations

  • Situation data information processing method based on computer network security

    CN116756225A

  • Metadata classification and grading method and device, equipment and medium

    CN116776237A