A network security assessment system
By building a network risk data set and model update mechanism based on sensitive types differentiation, the problem of insufficient targeting of the existing network security assessment model is solved, and higher adaptability and accuracy are achieved, adapting to the security risk characteristics in different fields, and ensuring the effectiveness and timeliness of the assessment model.
Patent Information
- Application Number
- CN202411076578.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-07
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2044-08-07
AI Technical Summary
The existing network security assessment model is not targeted and cannot fully consider the differences in risk assessment sensitivity involved in different units or enterprises or fields due to the nature of their business, resulting in insufficient assessment accuracy.
A network risk data set based on differentiation of sensitive types is constructed, a model and risk label library is identified through sensitive types, a sub-security model is generated and joint training is carried out, and a differentiated network security evaluation model is established based on the analysis of the attribute law values and correlation degree of risk subjects, and a model update mechanism is introduced to adapt to the dynamic changes of the system.
It improves the adaptability and accuracy of the network security assessment model, can better adapt to the security risk characteristics of different attribute fields, promptly respond to the latest security risk characteristics of the system, reduce invalid updates, and improve the stability and efficiency of the assessment system.
Smart Images

Figure CN119071026B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data processing, and in particular to a network security evaluation system. Background Art
[0002] With the rapid development of computer technology, information networks have become a vital component of social development and are crucial for individuals, businesses, and organizations. Network security is about ensuring that the hardware, software, and data within network systems are protected from accidental or malicious damage, alteration, or leakage, ensuring continuous, reliable, and normal operation of network systems and uninterrupted network services.
[0003] The existing traditional network security protection system consists of network firewalls, identity authentication, and other methods. These protection methods are normalized and lack targetedness, leading to network security risks. To address this shortcoming, the invention patent application number 202310551165.7 discloses a network security intelligent assessment method and system. The method uses a network risk label library to train multi-party network risk data to obtain a security analysis model, and then jointly trains the model parameters of multiple models to obtain a network security analysis model. This pre-trained model is used to perform network security assessments on the target system.
[0004] However, although a pre-built network risk label library is used to jointly train the parameters of the model for multi-party security risk data to improve the generalization ability of the model, the network security assessment of all fields or units and enterprises is evaluated using a "one-size-fits-all" network security analysis model. This inevitably has certain defects and fails to fully consider the differences in risk assessment sensitivity due to the nature of their business in different units and enterprises or fields (the focus of risk level, that is, different units and enterprises have different business content attributes, for example, the network security system in the hospital field focuses more on the business content of medical data and patient information). In order to differentiate different network risk data, the use of a "one-size-fits-all" security analysis model is bound to lack targetedness and model assessment accuracy. Summary of the Invention
[0005] In response to the technical problems existing in the prior art, the present invention provides a network security assessment system, which improves the pertinence and differentiation of the assessment results of the assessment model based on differentiated network risk data of sensitive types.
[0006] The technical solution of the present invention to solve the above technical problems is as follows:
[0007] A network security assessment system, comprising:
[0008] Risk tag library building blocks for:
[0009] S101: Collect historical network risk data from various attribute fields and input it into a pre-trained sensitive type recognition model to obtain several network risk data sets with sensitive key labels.
[0010] S102: Constructing a corresponding risk label library based on each network risk dataset and its sensitive key labels, including: analyzing the network security event type, risk subject attributes, and influencing factors in each network risk dataset to construct a risk label library for the network risk dataset;
[0011] The network security model generation module includes a data source division unit and a model group construction unit. The data source division unit is used to:
[0012] B1. Based on the region to which the IP address of each piece of network risk data in each network risk data set belongs, divide all network risk data into data sources to obtain several data source network risk data groups;
[0013] B2. Based on the network risk data group of each data source, perform cluster analysis on the network risk data using the corresponding risk tag library to obtain network risk cluster data;
[0014] The model group building unit is used to:
[0015] C1. Input the network risk cluster data corresponding to each data source network risk data group of the network risk dataset as a training set into the network structure for training to obtain a sub-security model;
[0016] C2. Combine several sub-security models into a risk model group, conduct joint training on the risk model group, and obtain a network security assessment model corresponding to sensitive key labels;
[0017] Cybersecurity Assessment Module for:
[0018] S201, based on the sensitive type identification model, obtain the sensitive key labels of the system to be evaluated;
[0019] S202: Based on the sensitive key tags of the system to be evaluated, the corresponding network security evaluation model is retrieved every preset evaluation period to perform network security evaluation.
[0020] Preferably, the sensitive type identification model is used to identify the sensitive type of network risk data, where the sensitive type includes the nature of the business and the degree of sensitivity. The sensitive key label of the network risk data is determined as follows:
[0021] Among the at least one identified sensitive type, determine the most sensitive business nature and its corresponding sensitivity as the sensitive key label of the corresponding network risk data;
[0022] The network risk dataset is composed of network risk data with the same sensitive key labels. The network risk dataset and the risk label library have a one-to-one relationship, and each risk label library is assigned a sensitive key label.
[0023] Preferably, the analysis obtains the network security event type, risk subject attributes, and impact factors in each network risk dataset, and constructs a risk label library for the network risk dataset, specifically including:
[0024] A1. Extract cybersecurity event types based on different cybersecurity events in the network risk dataset;
[0025] A2. Based on the type of cybersecurity incident, extract the risk subject attributes of the corresponding network risk data. Perform network quality simulation based on the cybersecurity incident type and risk subject attributes to generate impact factors. Risk subject attributes include internal and external risks.
[0026] A3. Combine the network security event type, risk subject attributes, impact factors, and sensitive key tags into a risk label. Each network risk dataset includes at least one risk label, and each risk label corresponds to at least one piece of network risk data.
[0027] A4. Based on all risk labels obtained from the analysis of the network risk dataset, a risk label library corresponding to the network risk dataset is constructed.
[0028] Preferably, the model group construction unit establishes a connection with the network security assessment module, and C2 specifically includes:
[0029] D1. Obtain all network risk data and risk subject attributes of the system to be evaluated within a historical time window. Obtain the risk subject attribute distribution value for each window unit within the historical time window. Based on the variation in the risk subject attribute distribution value, obtain the risk subject attribute regularity value of the system to be evaluated.
[0030] D2. Based on the network risk data group of each data source, obtain each network security data and its risk subject attributes, and calculate the risk subject attribute regularity value of each data source;
[0031] D3. Obtain the correlation values between the system to be evaluated and the risk subject attribute regularity values of each data source network risk data group, and sort the sub-security models corresponding to all data source network risk data groups in descending order according to the correlation values;
[0032] D4. Based on the pre-set correlation threshold, the risk model group is divided into a primary model group and a secondary model group. The primary model group has a greater influence on the generated network security assessment model than the secondary model group.
[0033] Preferably, the risk subject attribute distribution value of each window unit is specifically: the risk subject attribute of all network risk data in the window unit is the ratio of the number of internal risk to external risk;
[0034] The risk subject attribute regularity value of the system to be evaluated is obtained according to the variation range of the risk subject attribute distribution value. Specifically, the risk subject attribute regularity value of the system to be evaluated is obtained by obtaining the risk subject attribute distribution value of each window unit in the historical time window and calculating the risk subject attribute regularity value of the system to be evaluated according to the following formula:
[0035]
[0036] Among them, v is the regular value of the risk subject attribute, N is the total number of window units in the historical time window, k i is the risk subject attribute distribution value of the i-th window unit, k i-1 is the risk subject attribute distribution value of the i-1th window unit.
[0037] Preferably, the model group construction unit further includes a model updating unit, and the network security assessment module is further configured to: when the system to be assessed is about to enter a new assessment cycle, determine whether the network security risk information of the previous assessment cycle meets a preset condition; if so, generate a first trigger signal and transmit it to the model group construction unit; the model group construction unit receives the first trigger signal and controls the model updating unit to work, specifically for: executing steps D1 to D4, updating the risk subject attribute regularity value of the system to be assessed and the primary model group and secondary model group;
[0038] When the system to be evaluated reaches the next evaluation cycle, determining whether the evaluation result of the previous evaluation cycle meets the preset conditions specifically includes:
[0039] E1. Based on the cybersecurity risk information of the system to be evaluated in the previous evaluation cycle, execute step D1 to update the risk subject attribute regularity value of the system to be evaluated, replacing the original risk subject attribute regularity value;
[0040] E2. Obtain the difference rate between the current risk subject attribute regularity value and the original risk subject attribute regularity value. The difference rate is set as the ratio of the absolute value of the difference between the two and the original risk subject attribute regularity value. If the difference rate is greater than the preset difference threshold, it is determined that the network security risk information of the previous assessment cycle meets the preset conditions.
[0041] Preferably, the model group construction unit further includes an update span monitoring unit, which is connected to the model update unit and is specifically configured to:
[0042] S301, when the current evaluation cycle of the system to be evaluated ends, obtaining a position span value of the risk model group based on the risk model group of the current network security evaluation model and the risk model group of the previous evaluation cycle;
[0043] S302: When the position span value is greater than a preset span threshold, a second trigger signal is generated and sent to the model updating module.
[0044] Preferably, obtaining the position span value of the risk model group based on the risk model group of the current network security assessment model and the risk model group of the previous assessment cycle specifically includes:
[0045] Each sub-safety model in the risk model group is assigned a unique position code, which is set to (a, b), where a is the group class, which includes the main model group and the secondary model group, and b is the position number of the sub-safety model in the group class.
[0046] Based on the change in the position number of each sub-security model in the current risk model group and the position number of each sub-security model in the risk model group of the previous assessment cycle, the number of sub-security models whose group class has been promoted from a secondary model group to a primary model group and the position change value corresponding to the sub-security model whose position number has been reduced are obtained, and the position span value is calculated according to the following formula:
[0047]
[0048] Among them, H is the position span value, M is the total number of all sub-safety models in the main model group and the secondary model group in the risk model group, m is the number of sub-safety models whose group class is promoted from the secondary model group to the main model group, J is the total number of sub-safety models with reduced position numbers, ΔLj is the position change value of the j-th sub-safety model in the sub-safety model with reduced position numbers, and α is the weight factor of the influence of the number of group class promotions on the position span value.
[0049] Preferably, upon receiving the second trigger signal, the model updating unit is specifically configured to:
[0050] F1. Obtain all sensitive types of the system to be evaluated, analyze them with sensitive key labels in other risk label libraries, and obtain cross-sensitive key labels of the system to be evaluated;
[0051] The system to be evaluated obtains at least one sensitive type based on the sensitive type identification model, and matches it with sensitive key labels in other risk label libraries according to its business nature. Sensitive key labels with the same business nature and a higher sensitivity than the sensitive key labels of the system to be evaluated are determined as cross-sensitive key labels.
[0052] F2. Obtain all data source network risk data groups corresponding to the cross-sensitive key tags, and execute step D3 to obtain a sorted list of the corresponding data source network risk data groups and the associated values of the risk subject attribute regularity values of each data source network risk data group;
[0053] F3. If the correlation value reaches the correlation threshold, execute step F4; otherwise, terminate the response of the model updating unit to the second trigger signal;
[0054] F4. Determine the sub-security model corresponding to the data source network data group that reaches the association threshold as a supplementary model group;
[0055] F5. Add the supplementary model group to the risk model group, update the risk model group, and obtain a new network security assessment model.
[0056] Preferably, the risk label library construction module is used to construct a risk label library for each sensitive key label. The risk label library construction module is connected to the model updating unit. The risk label library construction module is also used to receive the cross-sensitive key labels of the system to be evaluated generated by the model updating unit, specifically for:
[0057] Generate a guided route for the risk tag library based on the attribute domain, sensitive key label, and cross-sensitive key label of the system to be evaluated: sensitive key label-attribute domain-cross-sensitive key label;
[0058] Among all risk tag libraries, the risk tag library of sensitive key tags in the guidance route and the risk tag library of cross-sensitive key tags are located. The former is directed to the latter and a guidance tag is attached for guidance linking. The guidance tag is an attribute field.
[0059] The beneficial effects of the present invention are:
[0060] The introduction of a sensitive type identification model and a differentiated risk label library enables differentiated processing of sensitive type-based network risk databases in different attribute fields. Furthermore, by constructing a joint training model between sub-security models for different data sources within a specific sensitive type, a network security assessment model is derived, improving the model's adaptability and accuracy. The resulting network security assessment model can better adapt to the specific needs of different attribute fields for the sensitivity of security risks, improving the model's generalization and practicality, and addressing the lack of targetedness in traditional network security assessments.
[0061] By introducing regular values of risk subject attributes and analyzing the correlation between different data sources and the system to be evaluated, the training effect of the network security assessment model can be specifically adjusted according to the unique security risk characteristics of the system to be evaluated. By analyzing the changes in risk data within the historical time window, the dynamic changes in the security risks of the system to be evaluated can be captured, ensuring that the assessment model can promptly respond to the latest security risk characteristics of the system to be evaluated.
[0062] By periodically monitoring the system to be evaluated and introducing a model update unit, the difference rate of the risk subject attribute regularity value is used as the trigger condition of the model update unit. When the security risk characteristics of the system to be evaluated change significantly, the historical parameters can be updated in a timely manner, so that the network security assessment model has the effectiveness and assessment value over time. At the same time, the update mechanism of the model update unit only works when the first trigger signal is received, which reduces invalid model updates and resource waste, and helps to improve the stability and efficiency of the assessment system.
[0063] By monitoring the position span value of the risk model group, the risk model group of the previous and subsequent evaluation cycles can be updated in a timely manner when the structure changes significantly; by analyzing the cross-sensitive key labels of the system to be evaluated, a supplementary model group is introduced, which further expands the coverage of the model and improves the model's ability to identify potential risks; based on the cross-sensitive key labels generated by the model update unit, the risk label library is improved, and a guided route for constructing the risk label library is introduced, making the system architecture of the risk label library more complete and regular, facilitating network security staff to perform visual analysis, and facilitating subsequent network security mining and analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Figure 1 A schematic diagram of the structure of a network security assessment system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0065] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0066] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the described features. In the description of this application, "plurality" means two or more, unless otherwise specifically specified.
[0067] In the description of this application, the term "for example" is used to mean "used as an example, illustration or explanation". Any embodiment described as "for example" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any person skilled in the art to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art will recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes will not be elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in this application.
[0068] Example 1: Figure 1 It is a structural diagram of a network security assessment system according to an embodiment of the present invention.
[0069] like Figure 1 As shown, a network security assessment system includes: a risk label library construction module, a network security model generation module, and a network security assessment module.
[0070] In some embodiments, the risk tag library construction module is specifically used to:
[0071] S101 collects historical network risk data from various attribute fields and inputs it into a pre-trained sensitive type recognition model to obtain several network risk data sets with sensitive key labels.
[0072] Specifically, attribute fields may include but are not limited to finance, retail, and healthcare. A large amount of historical network risk data is collected from these attribute fields. Based on the business nature of network security involved in the pre-labeled attribute fields (which can be set as data transaction, data storage, data access, data upgrade, etc., and different business natures can be obtained by analyzing the data related to network security in the specific attribute fields), sensitivity (the sensitivity of business nature in different attribute fields is different, that is, for the acceptability standard when judging security risks, the higher the sensitivity, the lower the security risk acceptance standard, and the more likely it is to trigger security risks), and the corresponding network risk data, the network structure is trained to obtain a sensitive type recognition model. The sensitive type recognition model has been trained according to the business nature and sensitivity corresponding to the network risk data in each attribute field, and is used to identify the sensitive type of network risk data. The sensitive type consists of the business nature and the corresponding sensitivity. The sensitive key label of the network risk data is determined as follows:
[0073] Among the at least one identified sensitive type, the business property with the highest sensitivity and its corresponding sensitivity are determined as sensitive key labels corresponding to the network risk data.
[0074] Furthermore, network risk data with the same sensitive key labels are used to form a network risk dataset.
[0075] Sensitivity types are determined by both the nature of the business and the corresponding sensitivity level, which ranges from high to medium to low. For example, in the financial sector, data transactions may be considered highly sensitive because they directly involve the flow of funds. Therefore, when using this type of cyber risk data as model training data, expert experience can be used to assign it a high sensitivity level. This means that in the financial sector, cyber risk data with data transactions as its business nature is highly sensitive. Therefore, cyber risk data with both high sensitivity and data transactions as its business nature is classified as a cyber risk dataset with the key sensitivity label "Data Transactions - Highly Sensitive." Using this sensitivity type identification model, cyber risk data with attributes in sectors like finance and retail is classified as "Data Transactions - Highly Sensitive."
[0076] S102: Based on each network risk dataset and its sensitive key labels, a corresponding risk label library is constructed.
[0077] Among them, the network risk data set includes a number of network risk data, and each piece of network risk data includes but is not limited to network security events and risk assessment information.
[0078] Specifically, the network risk dataset and risk label library present a one-to-one relationship, and each risk label library is assigned a sensitive key label.
[0079] Specifically, step S102 includes: analyzing the network security event types, risk subject attributes, and influencing factors in the network risk dataset, and constructing a risk label library for the network risk dataset, specifically including:
[0080] A1. Based on different network security events in the network risk dataset, network security event types are extracted, including network environment risks, access behavior risks, operating system risks, and application device risks.
[0081] A2. Based on the type of network security incident, extract the risk subject attributes of the corresponding network risk data, perform network quality simulation based on the network security incident type and risk subject attributes, and generate impact factors.
[0082] Among them, each network security incident type includes internal risks and external risks, so the corresponding network risk data is analyzed to obtain the risk subject attributes corresponding to the network security incident type. The risk subject attributes include internal risks and external risks.
[0083] A3. The network security event type, risk subject attributes, impact factors, and sensitive key tags are combined into a risk label. Each network risk data set includes at least one risk label, and each risk label corresponds to at least one piece of network risk data.
[0084] A4. Based on all risk labels obtained from the analysis of the network risk dataset, a risk label library corresponding to the network risk dataset is constructed.
[0085] In some embodiments, the network security model generation module includes a data source division unit and a model group construction unit. The data source division unit is specifically configured to:
[0086] B1. Based on each network risk data set, obtain the region to which the IP address of each piece of network risk data belongs, divide the data sources of all network risk data according to the region to which the IP address belongs, and obtain several data source network risk data groups.
[0087] B2. Based on the network risk data group of each data source, use the corresponding risk label library to label and classify the network risk data therein, and perform cluster analysis based on the label classification results to obtain network risk cluster data.
[0088] Therefore, through label classification and cluster analysis, network risk data with similar characteristics can be clustered together, which helps to reduce the complexity of subsequent models and improve training efficiency. The model can learn the characteristic patterns of the network risk cluster data more quickly.
[0089] The model group building unit is specifically used to:
[0090] C1. Based on the network risk cluster data corresponding to each data source network risk data group, risk labels are annotated on them. The annotated network risk cluster data is input as a training set into the preset network structure for training to obtain a sub-security model. Each data source network risk data group corresponds to a sub-security model.
[0091] C2. Combine several sub-security models of the network risk dataset into a risk model group, jointly train the risk model group, and optimize the model parameters to obtain a network security assessment model corresponding to the sensitive key label, so as to more accurately assess the network risks of different regions or enterprises under the sensitive key label.
[0092] The joint training process enables different sub-security models to learn from each other and share knowledge, thereby improving the generalization and accuracy of the overall model. In addition, by optimizing model parameters, the risk of overfitting can be further reduced and the model stability can be improved.
[0093] In some embodiments, the network security assessment module is specifically configured to:
[0094] S201: Obtain historical network risk data of the system to be evaluated, input it into a pre-trained sensitive type recognition model, and obtain sensitive key labels of the system to be evaluated.
[0095] S202: According to the sensitive key tags of the system to be evaluated, the corresponding network security evaluation model is retrieved, and a network security evaluation is performed on the system every preset evaluation period to obtain network security risk information of the system to be evaluated.
[0096] Among them, different attribute fields have different focuses or standards for the assessment of network security risks, that is, different risk sensitivity types. By introducing sensitive type identification models and differentiated risk label libraries, network security assessments can more accurately match the actual security risk status of the system to be assessed, thereby improving the pertinence and accuracy of the assessment.
[0097] Therefore, the introduction of sensitive type identification model and differentiated risk label library realizes differentiated processing of network risk database based on sensitive types in different attribute fields; and by constructing joint training between sub-security models for different data sources in specific sensitive types, a network security assessment model is obtained, which improves the adaptability and accuracy of the model; through differentiated processing and targeted assessment, the accuracy of network security assessment is significantly improved, and the generated network security assessment model can better adapt to the specific needs of different attribute fields for the sensitivity of security risks, improve the generalization ability and practicality of the model, and solve the defect of insufficient targeting of traditional network security assessment.
[0098] Example 2: In Example 1, based on the network risk data set under the same sensitive key label as the system to be evaluated, sub-security models of different data sources are divided. Then, the security risk characteristics of the systems applicable to different sub-security models must also be different. Although the joint training of the model group achieves the relative comprehensiveness of the model, it lacks the specificity of the system to be evaluated.
[0099] In some embodiments, the model group building unit establishes a connection with the network security assessment module, and step C2 specifically includes:
[0100] D1. Obtain all network risk data and risk subject attributes of the system to be evaluated within a historical time window. Obtain the risk subject attribute distribution value for each window unit within the historical time window. Based on the magnitude of the risk subject attribute distribution value, obtain the risk subject attribute regularity value of the system to be evaluated.
[0101] Among them, the historical time window can be set to the past month, the window unit can be set to every 24 hours, and the risk subject attribute distribution value of each window unit is specifically: the risk subject attribute of all network risk data in the window unit is the ratio of the number of internal risks to the number of external risks.
[0102] Among them, according to the change range of the risk subject attribute distribution value, the risk subject attribute regularity value of the system to be evaluated is obtained. Specifically, the risk subject attribute distribution value of each window unit in the historical time window is obtained, and the risk subject attribute regularity value of the system to be evaluated is calculated according to the following formula:
[0103]
[0104] Among them, v is the regular value of the risk subject attribute, N is the total number of window units in the historical time window, k i is the risk subject attribute distribution value of the i-th window unit, k i-1 is the risk subject attribute distribution value of the i-1th window unit.
[0105] Therefore, by analyzing the risk data of the system to be evaluated over a period of time, the dynamic change pattern of its risk subject attributes is found and quantified as the risk subject attribute regularity value, which may reflect the system's unique security vulnerabilities, common attack modes or operating habits, etc. It can also reflect the common characteristics between different systems that are vulnerable to external attacks.
[0106] D2. Based on the network risk data group of each data source, obtain each network security data and its risk subject attributes, and calculate the risk subject attribute regularity value of each data source.
[0107] Similarly, the method for obtaining the risk subject attribute regularity value of each data source refers to the content of step D1, and the present invention will not elaborate on this.
[0108] D3. Obtain the association value between the system to be evaluated and the risk subject attribute regularity value of each data source network risk data group, and sort all data source network risk data groups (i.e., the corresponding sub-security models) in descending order according to the association value.
[0109] The correlation value between the risk subject attribute regularity value of the system to be evaluated and each data source network risk group is specifically: the reciprocal of the absolute value of the difference between the risk subject attribute regularity value of the system to be evaluated and each data source network risk group.
[0110] Therefore, in order to understand the network risk characteristics of different data sources (i.e., different regions or enterprises) and the system to be evaluated, the correlation degree is used to roughly determine which data source sub-security models are more relevant or representative for the system to be evaluated.
[0111] D4. Based on the pre-set correlation threshold, the risk model group is divided into a primary model group and a secondary model group. The primary model group has a greater influence on the generated network security assessment model than the secondary model group.
[0112] Specifically, the sub-security models with correlation values greater than the correlation threshold are combined into the main model group, otherwise, they are combined into the secondary model group. By setting the correlation threshold, it can be ensured that only the data sources that are highly relevant to the system to be evaluated (i.e., the main model group) occupy a dominant position in the model training. Although the secondary model group also participates in the training, its influence weight is lower, thereby ensuring the comprehensiveness of the model while improving its pertinence. It should be noted that the main model and the secondary model are adaptively set for the training influence weight value of the generated network security assessment model, so that the influence weight value of the main model group on the generated network security assessment model is greater than that of the secondary model group.
[0113] Therefore, by introducing the regular values of risk subject attributes and the correlation analysis between different data sources and the system to be evaluated, the training effect of the network security assessment model can be adjusted according to the unique security risk characteristics of the system to be evaluated, thereby improving the adaptability and accuracy of the model; by analyzing the changes in risk data within the historical time window, the dynamic changes in the security risks of the system to be evaluated can be captured, ensuring that the assessment model can respond to the latest security risk characteristics of the system to be evaluated in a timely manner; the main model group and the secondary model group are divided according to the correlation, and joint training is carried out according to their preset influence weight values, which can conduct differentiated assessments based on the characteristics of different systems to be evaluated, avoiding a "one-size-fits-all" assessment method.
[0114] Therefore, the analysis of the short-term network risk data of the system to be evaluated and the mechanism for setting up primary and secondary model groups ensure that the model evaluation results can effectively reflect the latest security risk characteristics of the system to be evaluated, improving the timeliness of the evaluation. During the joint training of multiple model groups, the correlation analysis with the system to be evaluated is used to customize the model group specifically for the system to be evaluated. Each model group has a different influence weight in the security assessment process of the network security assessment model, achieving differentiated and targeted network security assessments between different systems. The dynamic changes in the network security risk of the system to be evaluated are taken into account. As security risk data increases over time, its risk patterns will also change accordingly. The primary and secondary model groups are set according to these patterns to improve the accuracy and timeliness of the evaluation.
[0115] Example 3: Since the network security assessment of a system is a long-term process, if a fixed model group is used for the assessment, as the network environment continues to change and network threats continue to emerge, the security risk characteristics of the system to be assessed are also constantly changing. If the assessment model cannot adapt to these changes in a timely manner, it will lead to inaccurate and delayed assessment results.
[0116] In some embodiments, the model group construction unit also includes a model updating unit, and the network security assessment module is also used to: when the system to be assessed is about to enter a new assessment cycle, determine whether the network security risk information of the previous assessment cycle meets the preset conditions; if so, generate a first trigger signal and transmit it to the model group construction unit; the model group construction unit receives the first trigger signal to control the model updating unit to work, specifically for: executing steps D1 to D4, updating the risk subject attribute regularity values and the main model group and secondary model group of the system to be assessed.
[0117] It should be noted that historical network risk data is updated in real time, so the network risk data set, risk tag library, and network risk data group of each data source need to be updated regularly to ensure the timeliness of the data.
[0118] In some embodiments, when the system to be evaluated reaches the next evaluation cycle, determining whether the evaluation result of the previous evaluation cycle meets the preset conditions specifically includes:
[0119] E1. Based on the network security risk information of the system to be evaluated in the previous evaluation cycle, execute step D1 to update the risk subject attribute regularity value of the system to be evaluated, replacing the original risk subject attribute regularity value.
[0120] E2. Obtain the difference rate between the current risk subject attribute regularity value and the original risk subject attribute regularity value. The difference rate is set as the ratio of the absolute value of the difference between the two and the original risk subject attribute regularity value. If the difference rate is greater than the preset difference threshold, it is determined that the network security risk information of the previous assessment cycle meets the preset conditions.
[0121] Among them, the preset difference threshold is a value set based on experience or experiments, which is used to determine whether the change in the security risk characteristics of the system to be evaluated is significant to the extent that the model needs to be updated. If the difference rate exceeds this threshold, it means that the security risk characteristics of the system to be evaluated have changed significantly, and at this time it is necessary to trigger the model update unit to respond to the first trigger signal to work.
[0122] Therefore, by periodically monitoring the system to be evaluated, introducing a model update unit, and using the difference rate of the regular values of the risk subject attributes as the trigger condition of the model update unit, the historical parameters can be updated in time when the security risk characteristics of the system to be evaluated change significantly, so that the network security assessment model has effectiveness and assessment value as time changes, improving the dynamic adaptability of the model and the accuracy of the assessment; at the same time, the update mechanism of the model update unit only works when the first trigger signal is received, reducing invalid model updates and resource waste, and helping to improve the stability and efficiency of the assessment system.
[0123] Example 4: Different systems may contain other sensitive data types in addition to key sensitive network risk data. While limiting the focus to a single key sensitive data type can identify most key risks, some subtle or difficult-to-detect risks may be overlooked. To ensure comprehensive network security assessments, corresponding assessment models with broader coverage and higher accuracy are required. Furthermore, as the risk tag library continues to expand and become more complex, improving the update efficiency of the model update unit has become a pressing issue.
[0124] In some embodiments, the model group construction unit further includes an update span monitoring unit, which is connected to the model update unit and is specifically configured to:
[0125] S301 : When the current evaluation cycle of the system to be evaluated ends, a position span value of the risk model group is obtained based on the risk model group of the current network security evaluation model and the risk model group of the previous evaluation cycle.
[0126] Specifically, based on the risk model group of the current network security assessment model and the risk model group of the previous assessment cycle, the position span value of the risk model group is obtained, including:
[0127] Each sub-safety model in the risk model group is assigned a unique position code, set to (a, b), where a is the group class, which includes the main model group and the secondary model group, and b is the position number of the sub-safety model in the group class (arranged in descending order, for example, 1, 2, 3...n);
[0128] Based on the change in the position number of each sub-security model in the current risk model group and the position number of each sub-security model in the risk model group of the previous assessment cycle, the number of sub-security models whose group class has been promoted from the secondary model group to the primary model group and the position change value (the difference between the previous and next position numbers) corresponding to the sub-security model whose position number has been reduced are obtained. The position span value is calculated according to the following formula:
[0129]
[0130] Among them, H is the position span value, M is the total number of all sub-safety models in the main model group and the secondary model group in the risk model group, m is the number of sub-safety models whose group class is promoted from the secondary model group to the main model group, J is the total number of sub-safety models with reduced position numbers, ΔLj is the position change value of the j-th sub-safety model in the sub-safety model with reduced position numbers, and α is the weight factor of the influence of the number of group class promotions on the position span value.
[0131] S302: When the position span value is greater than a preset span threshold, a second trigger signal is generated and sent to the model updating module.
[0132] In some embodiments, upon receiving the second trigger signal, the model updating unit is specifically configured to:
[0133] F1. Obtain all sensitive types of the system to be evaluated, analyze them with the sensitive key labels of other risk label libraries, and obtain the cross-sensitive key labels of the system to be evaluated.
[0134] Specifically, the system to be evaluated obtains at least one sensitive type based on the sensitive type identification model, matches it with the sensitive key labels in other risk label libraries according to its business nature, and determines the sensitive key labels with the same business nature and greater sensitivity than the sensitive key labels of the system to be evaluated as cross-sensitive key labels.
[0135] For example, the system to be evaluated is a hospital system. The sensitive type identification model is used to obtain two sensitive types, namely "data storage-highly sensitive" and "data transaction-moderately sensitive". The determined sensitive key label is "data storage-highly sensitive". It is matched with the sensitive key labels of other risk label libraries and it is found that there is a sensitive key label with "data transaction-highly sensitive". It may be a system in the financial field. Due to the same business nature and its sensitivity is higher than the sensitivity of the corresponding business nature of the system to be evaluated, "data transaction-highly sensitive" is used as the cross-sensitive key label of the system to be evaluated.
[0136] F2. Obtain all data source network risk data groups corresponding to the cross-sensitive key tags, execute step D3, and obtain a sorted list of the corresponding data source network risk data groups and an associated value of the risk subject attribute regularity value of each data source network risk data group.
[0137] F3. If the correlation value reaches the correlation threshold, execute step F4; otherwise, terminate the response of the model updating unit to the second trigger signal.
[0138] F4. Determine the sub-security model corresponding to the data source network data group that reaches the association threshold as a supplementary model group.
[0139] F5. Add the supplementary model group to the risk model group, update the risk model group, and obtain a new network security assessment model, so that the influence weight values of the main model group, secondary model group, and supplementary model group gradually decrease, and the main model group > secondary model group > supplementary model group.
[0140] Therefore, by adding a supplementary model group, we can analyze and obtain the range of other risk data that may exist in the system to be evaluated, so as to expand the coverage of the network security assessment model in a targeted manner, help to explore the potential risks that the system to be evaluated may face, and improve the comprehensiveness and accuracy of the model.
[0141] In some embodiments, the risk label library construction module is used to construct a risk label library for each sensitive key label, each risk label library corresponds to a network risk data set, and the risk label library construction module is connected to the model updating unit. The risk label library construction module is also used to receive the cross-sensitive key labels of the system to be evaluated generated by the model updating unit, specifically for:
[0142] Generate a guided route for the risk tag library based on the attribute domain, sensitive key label, and cross-sensitive key label of the system to be evaluated: sensitive key label-attribute domain-cross-sensitive key label;
[0143] Among all risk tag libraries, the risk tag library of sensitive key tags in the guidance route and the risk tag library of cross-sensitive key tags are located. The former is directed to the latter and a guidance tag is attached for guidance linking. The guidance tag is an attribute field.
[0144] Therefore, all risk tag libraries in the risk tag library construction module are guided and linked through rich guidance routes, and a large number of historical guidance routes are used to make the system architecture of the risk tag library more complete and regular, which is convenient for network security staff to perform visual analysis and facilitate subsequent network security mining and analysis.
[0145] During the subsequent complete network evaluation process of the system to be evaluated, when the model update unit receives the second trigger signal, it can quickly locate the cross-sensitive associated labels in the guided links in the risk label library based on the attribute fields and sensitive key labels of the system to be evaluated, thereby improving the updating efficiency and evaluation efficiency of the model.
[0146] In summary, by monitoring the position span value of the risk model group, more refined model update trigger conditions are achieved, unnecessary model updates are avoided, and at the same time, it is ensured that the risk model group of the previous and subsequent evaluation cycles can be updated in time when the structure changes significantly; by analyzing the cross-sensitive key labels of the system to be evaluated, a supplementary model group is introduced, which further expands the coverage of the model and improves the model's ability to identify potential risks; based on the cross-sensitive key labels generated by the model update unit, the risk label library is improved, and a guided route for constructing the risk label library is introduced, which improves the efficiency of the use of the risk label library and enables the model update unit to find relevant cross-sensitive key labels more quickly, thereby accelerating the model update process.
[0147] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0148] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0149] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0150] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0152] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0153] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A network security assessment system, characterized in that: The system comprises: Risk tag library building blocks for: S101: Collect historical network risk data from various attribute fields and input it into a pre-trained sensitive type recognition model to obtain several network risk data sets with sensitive key labels. S102: Constructing a corresponding risk label library based on each network risk dataset and its sensitive key labels, including: analyzing the network security event type, risk subject attributes, and influencing factors in each network risk dataset to construct a risk label library for the network risk dataset; The network security model generation module includes a data source division unit and a model group construction unit. The data source division unit is used to: B1. Based on the region to which the IP address of each piece of network risk data in each network risk data set belongs, divide all network risk data into data sources to obtain several data source network risk data groups; B2. Based on the network risk data group of each data source, perform cluster analysis on the network risk data using the corresponding risk tag library to obtain network risk cluster data; The model group building unit is used to: C1. Input the network risk cluster data corresponding to each data source network risk data group of the network risk dataset as a training set into the network structure for training to obtain a sub-security model; C2. Combining several sub-security models into a risk model group, jointly training the risk model group to obtain a network security assessment model corresponding to sensitive key labels; The model group construction unit establishes a connection with the network security assessment module, and the C2 specifically includes: D1. Obtain all network risk data and risk subject attributes of the system to be evaluated within a historical time window. Obtain the risk subject attribute distribution value for each window unit within the historical time window. Based on the variation in the risk subject attribute distribution value, obtain the risk subject attribute regularity value of the system to be evaluated. D2. Based on the network risk data group of each data source, obtain each network security data and its risk subject attributes, and calculate the risk subject attribute regularity value of each data source; D3. Obtain the correlation values between the system to be evaluated and the risk subject attribute regularity values of each data source network risk data group, and sort the sub-security models corresponding to all data source network risk data groups in descending order according to the correlation values; D4. Based on the pre-set correlation threshold, the risk model group is divided into a primary model group and a secondary model group. The primary model group has a greater influence on the generated network security assessment model than the secondary model group. Cybersecurity Assessment Module for: S201, based on the sensitive type identification model, obtain the sensitive key labels of the system to be evaluated; S202: Based on the sensitive key tags of the system to be evaluated, the corresponding network security evaluation model is retrieved every preset evaluation period to perform network security evaluation.
2. The network security assessment system according to claim 1, characterized in that: The sensitive type identification model is used to identify the sensitive type of network risk data. The sensitive type includes the nature of the business and the degree of sensitivity. The sensitive key label of the network risk data is determined as follows: Among the at least one identified sensitive type, determine the most sensitive business nature and its corresponding sensitivity as the sensitive key label of the corresponding network risk data; The network risk dataset is composed of network risk data with the same sensitive key labels. The network risk dataset and the risk label library have a one-to-one relationship, and each risk label library is assigned a sensitive key label.
3. The network security assessment system according to claim 2, characterized in that: The analysis obtains the network security event type, risk subject attributes, and impact factors in each network risk dataset, and constructs a risk label library for the network risk dataset, specifically including: A1. Extract cybersecurity event types based on different cybersecurity events in the network risk dataset; A2. Based on the type of cybersecurity incident, extract the risk subject attributes of the corresponding network risk data. Perform network quality simulation based on the cybersecurity incident type and risk subject attributes to generate impact factors. Risk subject attributes include internal and external risks. A3. Combine the network security event type, risk subject attributes, impact factors, and sensitive key tags into a risk label. Each network risk dataset includes at least one risk label, and each risk label corresponds to at least one piece of network risk data. A4. Based on all risk labels obtained from the analysis of the network risk dataset, a risk label library corresponding to the network risk dataset is constructed.
4. The network security assessment system according to claim 3, characterized in that: The risk subject attribute distribution value of each window unit is specifically: the risk subject attribute of all network risk data in the window unit is the ratio of the number of internal risks to the number of external risks; The risk subject attribute regularity value of the system to be evaluated is obtained according to the variation range of the risk subject attribute distribution value. Specifically, the risk subject attribute regularity value of the system to be evaluated is obtained by obtaining the risk subject attribute distribution value of each window unit in the historical time window and calculating the risk subject attribute regularity value of the system to be evaluated according to the following formula: in, is the regularity value of the risk subject attribute, N is the total number of window units in the historical time window, is the risk subject attribute distribution value of the i-th window unit, is the risk subject attribute distribution value of the i-1th window unit.
5. The network security assessment system according to claim 4, characterized in that: The model group construction unit also includes a model updating unit. The network security assessment module is further configured to: when the system to be assessed is about to enter a new assessment cycle, determine whether the network security risk information of the previous assessment cycle meets a preset condition. If so, generate a first trigger signal and transmit it to the model group construction unit. The model group construction unit receives the first trigger signal and controls the model updating unit to work, specifically for: executing steps D1 to D4 to update the risk subject attribute regularity value of the system to be assessed and the primary model group and secondary model group; When the system to be evaluated reaches the next evaluation cycle, determining whether the evaluation result of the previous evaluation cycle meets the preset conditions specifically includes: E1. Based on the cybersecurity risk information of the system to be evaluated in the previous evaluation cycle, execute step D1 to update the risk subject attribute regularity value of the system to be evaluated, replacing the original risk subject attribute regularity value; E2. Obtain the difference rate between the current risk subject attribute regularity value and the original risk subject attribute regularity value. The difference rate is set as the ratio of the absolute value of the difference between the two and the original risk subject attribute regularity value. If the difference rate is greater than the preset difference threshold, it is determined that the network security risk information of the previous assessment cycle meets the preset conditions.
6. The network security assessment system according to claim 5, characterized in that: The model group construction unit further includes an update span monitoring unit, which is connected to the model update unit and is specifically configured to: S301, when the current evaluation cycle of the system to be evaluated ends, obtaining a position span value of the risk model group based on the risk model group of the current network security evaluation model and the risk model group of the previous evaluation cycle; S302: When the position span value is greater than a preset span threshold, a second trigger signal is generated and sent to the model updating module.
7. The network security assessment system according to claim 6, characterized in that: The step of obtaining the position span value of the risk model group based on the risk model group of the current network security assessment model and the risk model group of the previous assessment cycle specifically includes: Each sub-safety model in the risk model group is assigned a unique position code, which is set to (a, b), where a is the group class, which includes the main model group and the secondary model group, and b is the position number of the sub-safety model in the group class. Based on the change in the position number of each sub-security model in the current risk model group and the position number of each sub-security model in the risk model group of the previous assessment cycle, the number of sub-security models whose group class has been promoted from a secondary model group to a primary model group and the position change value corresponding to the sub-security model whose position number has been reduced are obtained, and the position span value is calculated according to the following formula: in, is the position span value, M is the total number of all sub-safety models in the main model group and the secondary model group in the risk model group, m is the number of sub-safety models whose group class is promoted from the secondary model group to the main model group, J is the total number of sub-safety models whose position number is reduced, is the position change value of the j-th sub-security model in the sub-security model with a decreasing position number, Weighting factor for the impact of the amount of boost for the group class on the position span value.
8. The network security assessment system according to claim 6, characterized in that: When the model updating unit receives the second trigger signal, it is specifically configured to: F1. Obtain all sensitive types of the system to be evaluated, analyze them with sensitive key labels in other risk label libraries, and obtain cross-sensitive key labels of the system to be evaluated; The system to be evaluated obtains at least one sensitive type based on the sensitive type identification model, and matches it with sensitive key labels in other risk label libraries according to its business nature. Sensitive key labels with the same business nature and a higher sensitivity than the sensitive key labels of the system to be evaluated are determined as cross-sensitive key labels. F2. Obtain all data source network risk data groups corresponding to the cross-sensitive key tags, and execute step D3 to obtain a sorted list of the corresponding data source network risk data groups and the associated values of the risk subject attribute regularity values of each data source network risk data group; F3. If the correlation value reaches the correlation threshold, execute step F4; otherwise, terminate the response of the model updating unit to the second trigger signal; F4. Determine the sub-security model corresponding to the data source network data group that reaches the association threshold as a supplementary model group; F5. Add the supplementary model group to the risk model group, update the risk model group, and obtain a new network security assessment model.
9. The network security assessment system according to claim 8, characterized in that: The risk label library construction module is used to construct a risk label library for each sensitive key label. The risk label library construction module is connected to the model updating unit. The risk label library construction module is also used to receive the cross-sensitive key labels of the system to be evaluated generated by the model updating unit. Specifically, it is used to: Generate a guided route for the risk tag library based on the attribute domain, sensitive key label, and cross-sensitive key label of the system to be evaluated: sensitive key label-attribute domain-cross-sensitive key label; Among all risk tag libraries, the risk tag library of sensitive key tags in the guidance route and the risk tag library of cross-sensitive key tags are located. The former is directed to the latter and a guidance tag is attached for guidance linking. The guidance tag is an attribute field.
Citation Information
Patent Citations
Data detection method and device, storage medium and computer equipment
CN116361784A
Network security intelligent evaluation method and system
CN116668095A
Rewriting method, rewriting device, electronic equipment and storage medium
CN118133814A