A method for network security threat assessment
The Beautiful Soup crawling tool and proxy IP pool policy capture network security incident data, combine threat frequency, number of vulnerabilities and data breach to calculate threat values, normalized processing and dynamic adjustment, solving the real-time and intuitive problems of network security threat assessment, and achieving comprehensive, accurate and dynamic assessment of network threats.
Patent Information
- Application Number
- CN202411324466.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-09-23
AI Technical Summary
The existing technology is difficult to dynamically evaluate network security threats in real time, and the evaluation results are not intuitive.
The Beautiful Soup crawler tool is used to combine the proxy IP pool strategy to capture network security incident data, calculate threat value, vulnerability value and loss value through threat frequency, number of vulnerabilities and data breach degree, and normalize it, dynamically adjust the evaluation time interval, introduce time interval ratio and adjustment coefficient, and set threat level evaluation standards.
It has achieved stable and continuous data collection, quantitative consistency and comparability of evaluation results, can reflect changes in network security threats in real time, and provides a basis for formulating targeted security prevention measures.
Smart Images

Figure CN119094228B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a network security threat assessment method. Background Art
[0002] With the rapid development of the Internet, network security threats have become increasingly severe, and network attack methods have emerged in an endless stream, ranging from traditional hacker attacks and malicious software propagation to new types of phishing and ransomware, etc., bringing huge challenges to the information security of enterprises and individual users. To ensure network security, network security threat assessment has become a crucial task. Network security threat assessment aims to comprehensively identify, quantify, and evaluate potential security threats through scientific methods and processes, providing effective security decision-making support for organizations.
[0003] However, traditional threat assessment methods often rely on static data analysis and expert experience judgment, and it is difficult to reflect the changes in the network security situation in real time and dynamically. Therefore, this application proposes a comprehensive network security threat assessment method, which ensures comprehensive coverage and accurate assessment of network security threats through multi-step and multi-dimensional analysis and evaluation. Specifically, this method includes multiple links such as threat identification and analysis, threat assessment, and formulating security measures and strategies. Through these steps, organizations can not only comprehensively understand their own network security status, but also formulate targeted preventive measures to improve the overall security level. Summary of the Invention
[0004] This application solves the problems in the prior art that it is difficult to evaluate network security threats in real time and dynamically and the intuitiveness of the evaluation results is insufficient by providing a network security threat assessment method.
[0005] This application provides a network security threat assessment method, including:
[0006] S101, scraping network security event data: Using the Beautiful Soup crawler tool to scrape network security event data, and adopting the proxy IP pool strategy to deal with the anti-crawler mechanism to achieve stable and continuous data collection;
[0007] S102, determining network security threat scenarios: Based on the scraped data, combined with the threats faced by the network, determine the existing network security threat scenarios;
[0008] S103, calculating the threat value, vulnerability value, and loss value of the network security threat scenario: By statistically analyzing the number of occurrences of the threat scenario within a specific time period and comparing it with the total number of observations, the threat frequency is obtained, and according to the mapping table between the threat frequency and the threat value, the threat frequency is converted into a specific threat value;
[0009] By carefully counting and analyzing the number of vulnerabilities in the network, the total number of vulnerabilities is obtained, and according to the vulnerability number and vulnerability value mapping table, the vulnerability data is converted into specific vulnerability values;
[0010] By making a detailed judgment on the severity of data leakage, and according to the data leakage degree and loss value mapping table, different data leakage degree intervals are mapped to specific loss values;
[0011] S104, Normalize the threat value, vulnerability value and loss value: Normalize the threat value, vulnerability value and loss value through the formula
[0012]
[0013] for normalization to ensure the consistency and comparability of the evaluation results;
[0014] S105, Calculate the threat assessment value of the threat scenario: Calculate the threat assessment value according to the formula with the normalized threat value, vulnerability value and loss value to reflect the security threat status of the network;
[0015] In addition, by dynamically adjusting the time interval of the next evaluation according to the change of network security threats, and introducing the concept of time interval ratio TR, the original apparent threat assessment value is calculated ; Map the original apparent threat assessment value to the range of 1 - 100 to obtain the apparent threat assessment value; at the same time, by calculating the difference value between the apparent threat assessment value and the normalized threat assessment value, and setting the threat level assessment standard accordingly, the current threat level can be more intuitively understood;
[0016] S106, Application of the evaluation result: According to the obtained level of network security threats, the security threat status of the network can be more intuitively understood, providing an important basis for formulating targeted security prevention measures.
[0017] Preferably, for the normalization process, the normalization formula
[0018]
[0019] is used to convert the three key indicators of threat value (T), vulnerability value (V) and loss value (L) into a unified magnitude, making the threat assessment results more accurate and reliable, and avoiding calculation deviations caused by magnitude differences.
[0020] Preferably, the calculation formula for the threat assessment value is: , where k is a adjustment coefficient, which plays a crucial role in threat assessment, used to adjust the scale of the threat assessment value to ensure that the evaluation results can accurately reflect the actual security threat status.
[0021] Preferably, the time interval for the next evaluation will be dynamically adjusted based on the calculated threat change amplitude RC and the determined adjustment coefficients α and β, and the time interval for the next network security threat evaluation will be dynamically adjusted; the specific adjustment formula is as follows:
[0022]
[0023] wherein, is the preset basic time interval; when RC is positive, it indicates that the threat evaluation value decreases and the actual threat increases. Therefore, by to achieve the need to shorten the evaluation time interval to respond to threats more quickly; on the contrary, when RC is negative, it indicates that the threat evaluation value increases and the actual threat decreases. Therefore, by to appropriately extend the evaluation time interval to save resources.
[0024] Preferably, the threat change amplitude RC is calculated by the formula:
[0025]
[0026] to quantify the change of the threat; wherein, is the previous threat evaluation value, the current threat evaluation value; in this formula, if the threat evaluation value becomes smaller (i.e., ), then RC is a positive number, indicating that the threat evaluation value has decreased compared to the previous evaluation; if the threat evaluation value becomes larger (i.e., ), then RC is a negative number, indicating that the threat evaluation value has increased compared to the previous evaluation; if the threat evaluation value remains unchanged, then RC is equal to 0; therefore, through the above formula, the change direction and amplitude of the threat evaluation value can be intuitively reflected.
[0027] Preferably, for the determined adjustment coefficients α and β, when the threat increases, the value of α needs to be set as a relatively large positive number to ensure that the time interval can be significantly shortened so as to quickly respond to the threat; when the threat decreases, the time interval can be appropriately extended to save resources, and the value of β needs to be set as a relatively small positive number or a value close to 0, so that while ensuring resource efficiency, the response delay caused by too long a time interval can be avoided.
[0028] Preferably, the introduction time interval ratio TR is constructed by calculating the ratio of the basic time interval of this evaluation to the actual time interval between the previous evaluation time node, and adjusting it in combination with the adjustment coefficient γ, so as to construct a quantitative standard to reflect the execution frequency of the evaluation work and its sensitivity to adapt to threat changes. The formula is:
[0029]
[0030] Among them, t is the time stamp of this evaluation, is the time stamp of the previous evaluation, is the basic time interval, and γ is a regulation coefficient, whose function is to control the influence degree of the change of the time interval on the threat evaluation value.
[0031] Preferably, the original apparent threat evaluation value , integrating the two key elements of the threat change range and the time interval ratio, is calculated by using the formula
[0032]
[0033] ; By comprehensively considering the change range of the threat and the evaluation frequency, it provides a comprehensive evaluation of the threat dynamics.
[0034] Preferably, mapping the original apparent threat evaluation value to the range of 1-100, and normalizing the original apparent threat evaluation value to 0-100 by using the linear mapping method. The specific calculation formula is as follows: , where is the apparent threat evaluation value, is the minimum value of the original apparent threat evaluation value, is the maximum value of the original apparent threat evaluation value.
[0035] Preferably, by calculating the difference value between the apparent threat evaluation value and the normalized threat evaluation value, and setting the threat level evaluation standard accordingly, through the formula:
[0036]
[0037] to provide a more intuitive and quantitative index to capture the subtle changes in the threat level. Among them, D represents the difference value between the two; according to the difference value obtained by the formula, it is divided into three threat levels: when the difference value is within 0 to 20%, it is set as the low threat level; when the difference value is between 20% and 50%, it is set as the medium threat level; when the difference value exceeds 50%, it is set as the high threat level; in addition, when the apparent threat evaluation value is exactly equal to the threat evaluation value, that is, the difference value is 0%, it is set as a specific threat level, that is, the stable level.
[0038] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0039] By adopting the Beautiful Soup crawler tool and combining it with the proxy IP pool strategy, a stable and continuous collection effect of network security event data is achieved. At the same time, by carefully counting and analyzing the threat frequency, the number of vulnerabilities, and the degree of data leakage, these key metrics are transformed into specific threat values, vulnerability values, and loss values, realizing the quantitative assessment of network security threat scenarios. Further, by normalizing the threat values, vulnerability values, and loss values, the consistency and comparability of the evaluation results are ensured. Finally, the threat assessment value is calculated by combining the normalized evaluation values with the adjustment coefficient, and by dynamically adjusting the evaluation time interval and introducing the time interval ratio, the evaluation results can reflect the changes in network security threats in real time. Through this series of innovative steps and methods, this network security threat assessment method realizes a comprehensive, accurate, and dynamic assessment of the network threat situation, providing an important basis for formulating targeted security prevention measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 It is a flowchart of a network security threat assessment method in an embodiment of the present invention;
[0041] Figure 2 It is a mapping table of example threat frequency and threat value of a network security threat assessment method in an embodiment of the present invention;
[0042] Figure 3 It is a mapping table of example number of vulnerabilities and vulnerability value of a network security threat assessment method in an embodiment of the present invention;
[0043] Figure 4 It is a mapping table of example degree of data leakage and loss value of a network security threat assessment method in an embodiment of the present invention;
[0044] Figure 5 It is a flowchart of dynamically adjusting the time interval of the next evaluation in an embodiment of the present invention;
[0045] Figure 6 It is a flowchart of calculating the original apparent threat assessment value and mapping it to the range of 1-100 in an embodiment of the present invention;
[0046] Figure 7 It is a flowchart of setting the threat level assessment standard in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] To facilitate the understanding of the present invention, the present application will be described more comprehensively with reference to the relevant drawings; the preferred embodiments of the present invention are shown in the drawings, however, the present invention can be implemented in many different forms and is not limited to the embodiments described herein; on the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.
[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this invention belongs; the terms used in the description of the present invention herein are for the purpose of describing specific embodiments only and are not intended to limit the present invention; the term "and / or" used herein includes any and all combinations of one or more of the related listed items.
[0049] Aiming at the problems that the network security threat assessment method in the prior art is difficult to adjust in real time and dynamically, and the intuitiveness of the assessment result is insufficient, this application uses the crawler tool Beautiful Soup to efficiently capture data, and adopts the proxy IP pool strategy to deal with the anti-crawler mechanism, thereby realizing stable and continuous data collection; at the same time, the normalization processing and dynamic adjustment strategy are introduced to quantitatively evaluate the threat value, vulnerability value and loss value, and optimize the assessment result through the adjustment coefficient, thereby realizing the intuitiveness and accuracy of the assessment result, and providing strong decision-making support for the management level.
[0050] Example 1: As Figure 1 shown, a network security threat assessment method includes the following steps:
[0051] S101, capturing network security event data: In order to effectively collect public network security event data and ensure the stability, efficiency, ease of use and excellent scalability of the capture tool, the crawler tool BeautifulSoup is selected. This tool can capture the required network security event data from major security websites and vulnerability bulletin platforms.
[0052] Among them, during the capture process, special attention should be paid to dealing with the anti-crawler mechanism, and the proxy IP pool strategy is adopted to effectively avoid the IP being blocked. The management and maintenance of the proxy IP pool are crucial, including regularly updating the IP list, real-time monitoring of the availability and response speed of the IP, and timely removing unavailable or slow-responsive IPs to ensure the continuous and stable operation of the crawler tool.
[0053] S102, determining the network security threat scenario: Based on the captured network security event data, further combined with the threats faced by the network, to determine the possible network security threat scenarios. First, retrieve and access the captured data, and use data analysis techniques to deeply explore the data to identify different threat types, such as DDoS attacks, SQL injections, zero-day vulnerability exploitations, etc.
[0054] Secondly, compare and correlate the identified threats with known cybersecurity threat scenarios. In this process, utilize a professional threat intelligence library or a known threat database and, through an algorithm based on signature matching, search for threat scenarios similar to the analysis results. For threats that cannot be matched, consider them as new threats and conduct a detailed analysis of them, including their sources, attack methods, possible scope of impact, etc., to ensure that the description of each threat scenario is both specific and comprehensive.
[0055] S103. Calculate the threat value, vulnerability value, and loss value of the cybersecurity threat scenario: After determining the cybersecurity threat scenario, to more comprehensively evaluate its potential threat, calculate its threat value, vulnerability value, and loss value according to the selected evaluation metrics.
[0056] First, the calculation of the threat value is based on the threat frequency. The threat frequency, that is, the frequency of occurrence of the threat scenario, is an important basis for evaluating its potential threat. By statistically analyzing the number of occurrences of the threat scenario within a specific time period and comparing it with the total number of observations, the threat frequency is obtained, that is, the proportion of the number of occurrences of the threat scenario to the total number of observations. To more intuitively evaluate the potential threat of the threat scenario, based on historical data and the evaluation of potential threats, a mapping table between threat frequency and threat value is formulated, and according to the mapping table, the threat frequency is converted into a specific threat value. Specifically, a lower threat frequency corresponds to a lower threat value, indicating that the potential threat of this threat scenario is relatively small; while a higher threat frequency corresponds to a higher threat value, indicating that the potential threat of this threat scenario is relatively large. As an example, reference can be made to Figure 2 the mapping table between threat frequency and threat value shown.
[0057] Secondly, select the number of vulnerabilities as the key metric for evaluating network security vulnerability. Vulnerabilities, that is, security defects existing in the network, the number of which directly reflects the likelihood of the network being attacked and is an important basis for evaluating vulnerability. By carefully statistically analyzing the number of vulnerabilities in the network, the total number of vulnerabilities is obtained, and according to the preset mapping table between the number of vulnerabilities and the vulnerability value, the vulnerability data is converted into a specific vulnerability value. Specifically, a smaller total number of vulnerabilities corresponds to a lower vulnerability value, indicating that the network is relatively secure; while a larger total number of vulnerabilities corresponds to a higher vulnerability value, indicating that there are relatively large security risks in the network. As an example, reference can be made to Figure 3 the mapping table between the number of vulnerabilities and the vulnerability value shown.
[0058] Finally, the degree of data leakage is used as an evaluation indicator to determine the loss value. Data leakage is a common and serious consequence in cybersecurity incidents, and its degree is directly related to the exposure scope of sensitive information and the potential threat of abuse. To accurately evaluate the loss value, it is necessary to make a detailed judgment based on the severity of data leakage and refer to the pre-set mapping table of data leakage degree and loss value. This mapping table is formulated based on the analysis of historical data leakage incidents and their consequences. It maps different data leakage degree intervals to specific loss values, thereby accurately quantifying the actual losses that a threat scenario may cause. Specifically, if the degree of data leakage is low, only involving the leakage of a small amount of non-sensitive information, it corresponds to a lower loss value, indicating that the actual loss is relatively small; conversely, if the degree of data leakage is severe, involving the leakage of a large amount of sensitive or core information, it corresponds to a higher loss value, indicating that the potential actual loss is large. As an example, reference can be made to Figure 4 the mapping table of data leakage degree and loss value shown.
[0059] To visually display the mapping relationships between threat frequency and threat value, vulnerability quantity and vulnerability value, and data leakage degree and loss value, as Figure 5 shown as an example, each mapping table includes a header and some assumed numerical values. This figure is only for reference, and the interval of specific mapping relationship numerical values is set according to the actual situation.
[0060] S104, Normalize the threat value, vulnerability value, and loss value: In cybersecurity threat assessment, since the magnitudes of the threat value (T), vulnerability value (V), and loss value (L) may vary greatly, directly multiplying them may lead to an overly large range of assessment results, making it difficult to effectively evaluate the size of the actual threat. Therefore, normalizing these three values can ensure the consistency and comparability of threat assessment.
[0061] Set a normalization interval for each evaluation indicator (i.e., T, V, L), usually choosing between 0 and 1 as the common range after normalization for all indicators. The reason for choosing 0 to 1 as the normalization interval is that this interval provides a dimensionless and relatively unified measurement standard. Compared with other intervals (such as 0 to 100), the interval from 0 to 1 is more compact and can more intuitively reflect the relative magnitudes between indicators. At the same time, it enables indicators of different magnitudes and units to be compared and calculated on the same scale, thereby greatly improving the consistency and comparability of threat assessment.
[0062] Based on historical data or industry standards, determine the maximum and minimum values of each indicator as the reference benchmarks for normalization. The calculation formula for normalization is:
[0063]
[0064] S105. Calculate the threat assessment value of the network security threat scenario: Through normalization, obtain the normalized value T' of the threat value T, the normalized value V' of the vulnerability value V, and the normalized value L' of the loss value L. The threat assessment formula is: , where R is the threat assessment value, and k is a tuning coefficient. The tuning coefficient k plays a crucial role in threat assessment and is used to adjust the scale of the threat assessment value to ensure that the assessment result can accurately reflect the actual security threat situation. The selection of the k value is based on a detailed study and understanding of historical network security events, combined with the threat assessment value at that time and the consequences of actual security events. By comparing the threat assessment results with actual security events under different k values, the most appropriate k value is deduced.
[0065] For example, taking the network security threat assessment of an enterprise as an example, the original threat value (T) is 360, the vulnerability value (V) is 16, and the loss value (L) is 166. Direct multiplication of these values may result in an overly large result, making it difficult to intuitively understand. According to historical data, the range of the threat value T is determined to be [0, 500], the range of the vulnerability value V is [0, 50], and the range of the loss value L is [0, 500]. These ranges will serve as the basis for normalization.
[0066] The normalized value of the threat value T is calculated as follows:
[0067]
[0068] The normalized value of the vulnerability value V is calculated as follows:
[0069]
[0070] The normalized value of the loss value L is calculated as follows:
[0071]
[0072] Use the normalized values to calculate the threat assessment value, and the formula remains the same: . Assume that after analysis, the tuning coefficient k is determined to be 1, then R = 1 * (0.72 * 0.32 * 0.332) ≈ 0.077. Through normalization, the obtained threat assessment value R is between 0 and 1, which more intuitively reflects the security threat situation of the network and makes it easier to understand the threat level.
[0073] S106. Application of the assessment result: Through the threat assessment value after normalization, it is possible to more intuitively understand the security threat situation of the network, providing an important basis for formulating targeted security prevention measures.
[0074] The technical solutions in the above embodiments of the present application at least have the following technical effects or advantages:
[0075] This application uses a crawler tool and a proxy IP pool to achieve the effect of efficiently, stably, and continuously collecting public network security event data. Based on the crawled network security event data, combined with the threats faced by the network, possible network security threat scenarios are determined. By calculating the threat value, vulnerability value, and loss value of the network security threat scenario and normalizing them, the threat assessment result is made more accurate and reliable, avoiding calculation biases caused by magnitude differences, and being able to intuitively reflect the network security threat situation. By calculating the network security threat assessment value, the overall level and severity of the network security threats faced can be comprehensively reflected.
[0076] Embodiment 2: In Embodiment 1, it was elaborated in detail how to crawl network security event data, determine network security threat scenarios, and calculate the threat value, vulnerability value, and loss value of the threat scenarios, and then obtain the network security threat assessment value. To further optimize this assessment process and enable it to be dynamically adjusted according to the actual situation, this embodiment designs a strategy for calculating the time interval of the next threat assessment based on the magnitude of the previous threat assessment value, so as to improve the flexibility and response speed of network security threat assessment.
[0077] As Figure 6 shown, the embodiment of this application is optimized on the basis of Embodiment 1, and specifically includes the following steps:
[0078] S201, define the threat change range RC: To more precisely adjust the time interval of the next assessment according to the changes in network security threats, a calculation formula needs to be defined to calculate the threat change range RC. This formula will be based on the previous threat assessment value and the current threat assessment value to quantify the changes in threats. The calculation formula is as follows:
[0079]
[0080] In this formula, if the threat assessment value becomes smaller (i.e., ), then RC is a positive number, indicating that the threat assessment value has decreased compared to the previous assessment; if the threat assessment value becomes larger (i.e., ), then RC is a negative number, indicating that the threat assessment value has increased compared to the previous assessment; if the threat assessment value remains unchanged, then RC is equal to 0. Therefore, through the above formula, the change direction and magnitude of the threat assessment value can be intuitively reflected.
[0081] S202, determine the adjustment coefficients α and β: To more finely control the adjustment of the time interval, two adjustment coefficients α and β are introduced.
[0082] When the threat increases, a faster response is needed to address potential threats. Therefore, the value of α is usually set to a relatively large positive number to ensure that the time interval can be significantly shortened, enabling a prompt response to threats. The specific value of α is determined through historical data analysis, expert evaluation, or simulation tests to ensure its effectiveness and accuracy in actual situations.
[0083] When the threat decreases, the time interval can be appropriately extended to save resources. However, to maintain a certain evaluation frequency and ensure timely detection of new threats, the value of β is usually set to a relatively small positive number or a value close to 0. Thus, while ensuring resource efficiency, the response delay caused by an overly long time interval can be avoided. The specific value of β is also determined through historical data analysis, expert evaluation, and simulation tests to ensure that it can achieve the best results under different threat levels.
[0084] S203, Dynamically adjust the time interval for the next evaluation: Based on the calculated threat change amplitude RC and the determined adjustment coefficients α and β, dynamically adjust the time interval for the next network security threat evaluation. Through the formula:
[0085]
[0086] It can intuitively reflect the change direction and amplitude of the threat evaluation value, where, is the preset base time interval. When RC is positive, it indicates that the threat evaluation value decreases and the actual threat increases. Therefore, is used to shorten the evaluation time interval as needed to respond to threats more quickly. On the contrary, when RC is negative, it means that the threat evaluation value increases and the actual threat decreases. Therefore, is used to appropriately extend the evaluation time interval to save resources.
[0087] Assume the base time interval days, adjustment coefficient α = 0.5, β = 0.25, and the previous threat evaluation value .
[0088] When the current threat evaluation value becomes , since the threat evaluation value becomes smaller and the actual threat increases, RC is positive, , days, indicating that when a decrease in the threat evaluation value is detected, the time interval for the next evaluation will be correspondingly shortened.
[0089] When the current threat evaluation value becomes , RC will be a negative number, , then days, indicating that when an increase in the threat evaluation value is detected, the time interval for the next detection will be correspondingly shortened.
[0090] When the threat assessment value remains unchanged, i.e., at this time, , and days, indicating that when the detected threat assessment value remains unchanged, the time interval for the next assessment remains the same.
[0091] S204. Process outliers or extreme cases: When dealing with outliers or extreme cases, it is necessary to set the maximum value and the minimum value of RC. Because when the value of RC is extremely large or small, the current time interval adjustment strategy may no longer be effective. To determine these limit values, the RC distribution in historical data can be analyzed, and reasonable thresholds can be selected to ensure that the adjustment of the time interval is within a reasonable range. Specifically, when at this time, process according to ; when at this time, process according to . This can prevent the time interval adjustment from being too large or too small caused by extreme cases, thereby ensuring the stability and effectiveness of the evaluation strategy.
[0092] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages:
[0093] By adopting the calculation formula of the threat change amplitude RC and combining the adjustment coefficients α and β, the present application realizes adjusting the time interval for the next assessment according to the dynamic changes of network security threats, thereby improving the timeliness of threat response and the efficiency of resource use. At the same time, by dealing with outliers or extreme cases, the stability and effectiveness of the evaluation strategy are ensured.
[0094] Embodiment 3: In order to further improve the accuracy and intuitiveness of network security threat assessment, a new evaluation index - apparent threat assessment value is introduced in this embodiment on the existing basis, and combined with the dynamic adjustment of the basic time interval strategy to enhance the real-time response ability to network security threats.
[0095] As Figure 7 shown, the embodiments of the present application are optimized to a certain extent on the basis of Embodiment 2, specifically including the following steps:
[0096] S301. Record the threat assessment value and timestamp: After each network security threat assessment is completed, in order to ensure traceability and analysis of historical threat changes, record the threat assessment value obtained from this assessment, and synchronously mark the exact time corresponding to this assessment, that is, the timestamp.
[0097] S302. Calculate the time interval ratio TR: To more precisely measure the relationship between the evaluation frequency and the dynamic changes of threats, the concept of the time interval ratio is introduced. This indicator constructs a quantitative standard by calculating the ratio of the actual time interval between the base time interval of this evaluation and the time node of the previous evaluation, and adjusting it with the adjustment coefficient γ, so as to reflect the execution frequency of the evaluation work and its sensitivity to adapting to threat changes. The formula is:
[0098]
[0099] where t is the time stamp of this evaluation, is the time stamp of the previous evaluation, is the base time interval, that is, the preset evaluation frequency. As an adjustment coefficient, γ is used to control the influence degree of the time interval change on the threat evaluation value. The selection of γ is based on the statistical analysis of historical evaluation data, and at the same time, the considerations of response speed and security monitoring accuracy need to be balanced. Generally, a larger γ value is more sensitive to the change of the time interval, while a smaller γ value is the opposite. This sensitivity adjustment can better adapt to the rhythm of threat changes and improve the accuracy of evaluation.
[0100] The time interval ratio TR can intuitively reflect the close relationship between the evaluation frequency and the dynamic changes of threats. When the threat level changes, the ideal evaluation frequency should be able to adjust accordingly to more accurately capture the dynamics of threats. By calculating the time interval ratio, the adaptability of the evaluation frequency can be quantified, so as to better understand whether the evaluation work can respond to threat changes in a timely and effective manner.
[0101] Specifically, when the threat level increases, the evaluation frequency should increase accordingly to monitor and evaluate threats more frequently. At this time, the value of the time interval ratio TR will be relatively small, indicating that the actual evaluation frequency is higher than the base time interval and is more sensitive to threat changes. On the contrary, when the threat level decreases, it is necessary to appropriately reduce the evaluation frequency to save resources. At this time, the value of the time interval ratio TR will be relatively large, indicating that the actual evaluation frequency is lower than the base time interval.
[0102] S303. Calculate the original apparent threat evaluation value : In the actual network security environment, the threat level is not only affected by the current threat evaluation value, but also closely related to its change range and evaluation frequency. Therefore, a single threat evaluation value often cannot comprehensively reflect the actual situation of threats. To more comprehensively evaluate threats, the two key elements of the threat change range RC and the time interval ratio TR are integrated, and the formula:
[0103]
[0104] is used to calculate the original apparent threat evaluation value It comprehensively considers the change range and evaluation frequency of threats, thus providing a comprehensive evaluation of threats. The time interval ratio TR reflects the adaptability of the evaluation frequency to threat changes, that is, the timeliness of evaluation. The threat change range RC measures the fluctuation degree of the threat level. Whether the threat increases or decreases, |RC| can ensure that this change is correctly reflected in the evaluation value.
[0105] S304, determine the minimum and maximum original apparent threat evaluation values: Usually, when both the threat evaluation value R and the time interval ratio TR are close to the minimum value, the original apparent threat evaluation value will obtain its minimum value. However, considering that it is unlikely for R to be 0 in actual situations, a minimum value of the original apparent threat evaluation value can be determined based on the minimum R value and the minimum reasonable TR value in historical data . Similarly, when both the threat evaluation value R and the time interval ratio TR are close to the maximum value, and the threat change range RC is also large, the original apparent threat evaluation value will obtain its maximum value .
[0106] S305, map the original apparent threat evaluation value to the range of 1 - 100: In order to map the original apparent threat evaluation value to the range of 0 - 100, a linear mapping method is used to normalize it to 0 - 100. The specific calculation formula is as follows:
[0107]
[0108] where, is the apparent threat evaluation value. By mapping the original apparent threat evaluation value to the range of 1 - 100, the evaluation result is made more intuitive and understandable, improving the accuracy and real-time response ability of network security threat evaluation.
[0109] Assume that the previous normalized threat evaluation value is 0.5, the current normalized threat evaluation value is 0.7, the time interval from the previous threat evaluation is 5 days, the base time interval is 3 days, the adjustment coefficient is γ = 0.5, and the maximum and minimum values of the original apparent threat evaluation value are 1 and 0.01 respectively. Calculated according to the formula:
[0110]
[0111] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages:
[0112] By introducing a new evaluation index, the original apparent threat evaluation value, and combining the dynamic adjustment strategy of the time interval ratio, this application achieves a more comprehensive, dynamic, and accurate evaluation of network security threats. The original apparent threat evaluation value integrates two key elements, namely the threat change amplitude and the time interval ratio, comprehensively reflecting the dynamic changes of threats and solving the problem that a single threat evaluation value is difficult to capture the real-time fluctuations of threats. At the same time, recording the threat value and timestamp of each evaluation ensures the traceability of the evaluation results and provides strong support for historical analysis. In addition, by calculating the time interval ratio TR and combining it with the adjustment coefficient γ, the evaluation frequency is flexibly adjusted, improving the sensitivity to threat changes. Finally, normalizing the original apparent threat evaluation value to the range of 0-100 makes the evaluation results more intuitive and understandable, enhancing the accuracy and real-time response ability of network security threat evaluation and providing more reliable security protection for the organization.
[0113] Example 4: In Example 3, the real-time and dynamic nature of network security threat evaluation was further optimized by introducing the concept of apparent threat evaluation value and combining two key elements, the time interval ratio TR and the threat change amplitude RC, to achieve a more comprehensive and dynamic evaluation of network security threats. To further enhance the intuitiveness and practicality of the evaluation, Example 4 will, on the basis of Example 3, focus on optimizing the representation method of threat evaluation results. By calculating the difference between the apparent threat evaluation value and the normalized threat evaluation value and setting the threat level evaluation criteria accordingly, it helps users more intuitively understand the current threat level.
[0114] The embodiments of this application are optimized to a certain extent on the basis of Example 3, specifically including the following steps:
[0115] S401, mapping the threat evaluation value to the range of 1-100: In Example 1, the threat evaluation value has been normalized to a value between 0 and 1 through normalization. To more intuitively represent the threat level, this normalized value is mapped to the range of 0-100. The specific mapping formula is as follows:
[0116]
[0117] Among them, R represents the threat evaluation value after normalization, that is, a value between 0 and 1, and R' is the result after mapping this value to the range of 0-100.
[0118] S402. Calculate the difference value between the apparent threat assessment value and the threat assessment value: To evaluate the change in the threat level, it is necessary to calculate the difference between the apparent threat assessment value and the threat assessment value. This difference can be measured by the absolute difference or the relative difference between the two. However, in this embodiment, the relative difference (expressed as a percentage) is selected to provide a more intuitive and quantitative indicator. The specific formula is as follows:
[0119]
[0120] Where, represents the apparent threat assessment value, R' represents the threat assessment value mapped to the range of 0 - 100, and D represents the difference value between the two.
[0121] By calculating the relative difference, we can more accurately understand how the threat level changes over time, rather than simply relying on the absolute threat assessment value. This approach can more sensitively capture the subtle changes in the threat level and take corresponding security measures in a timely manner to address potential threats.
[0122] S403. Set the threat level assessment criteria: According to the actual needs, different ranges of difference values correspond to different threat levels. When the difference value is within 0 to 20%, it is set as a low threat level. This range means that the change in the threat assessment value is relatively small, which may be caused by some normal fluctuations or minor threat changes. When the difference value is between 20% and 50%, it is set as a medium threat level. This range indicates that the change in the threat assessment value is relatively significant, and there may have been some threat dynamics that need attention. When the difference value exceeds 50%, it is set as a high threat level. This range means that the change in the threat assessment value is very large, which may indicate that the threat level has changed significantly, or there are new and more serious threats. In addition, when the apparent threat assessment value is exactly equal to the threat assessment value, that is, the difference value is 0%, it is set as a specific threat level, namely the stable level. This level indicates that the threat level has not changed, or the change is very small and can be ignored.
[0123] The selection of 20% and 50% as the cut-off points for dividing the low, medium, and high threat levels is based on the analysis of historical threat assessment data and the consideration of the sensitivity to threat changes. Such a division helps to more intuitively reflect the relative changes in the threat level and provides clear guidance for security responses. By setting these threat level assessment criteria, we can better address threat challenges of different severities and ensure the effective maintenance and protection of network security.
[0124] S404. Evaluate the current threat level: According to the calculated difference value, find the corresponding threat level in the set assessment criteria.
[0125] If, when the apparent threat assessment value , mapped to the threat assessment value in the range of 0 - 100 , the difference value . According to the threat level assessment standard, this D value corresponds to the medium threat level.
[0126] The technical solutions in the embodiments of the present application described above have at least the following technical effects or advantages:
[0127] By calculating the difference value, the effect of more accurately reflecting the changes in network security threats is achieved, and the problem that the previous evaluation methods only considered the absolute size of threats and ignored the change trend is solved. The threat level value output by this method is a single numerical value, which can intuitively and quickly judge the threat level according to this value, and then formulate targeted security policies, thereby effectively improving the efficiency and accuracy of network security management.
[0128] The above is only the preferred embodiment of the present invention and is not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A network security threat assessment method, characterized in that, Including: S101, Use the Beautiful Soup crawler tool to capture network security event data, and adopt the proxy IP pool strategy to deal with the anti-crawler mechanism to achieve stable and continuous data collection; S102, Based on the captured data and combined with the threats faced by the network, determine the existing network security threat scenarios; S103, Calculate the threat value, vulnerability value and loss value of the network security threat scenario: By counting and analyzing the number of occurrences of the threat scenario within a specific time period and comparing it with the total number of observations, the threat frequency is obtained, and according to the mapping table between the threat frequency and the threat value, the threat frequency is converted into a specific threat value; By carefully counting and analyzing the number of vulnerabilities in the network, the total number of vulnerabilities is obtained, and according to the mapping table between the number of vulnerabilities and the vulnerability value, the vulnerability data is converted into a specific vulnerability value; By making a detailed judgment on the severity of data leakage and according to the mapping table between the degree of data leakage and the loss value, different data leakage degree intervals are mapped to specific loss values; S104, Normalize the threat value, vulnerability value and loss value; S105, calculate the threat assessment value according to the formula based on the normalized threat value, vulnerability value, and loss value. R is the threat assessment value. is the normalized threat value. is the normalized vulnerability value. is the normalized loss value, and k is the adjustment coefficient. In addition, by dynamically adjusting the time interval of the next assessment according to changes in network security threats, shortening the time interval if the threat assessment value increases to quickly respond to threats, and extending the time interval if the threat assessment value decreases to save resources; and introducing the concept of time interval ratio to calculate the original apparent threat assessment value ; map the original apparent threat assessment value to the range of 1 - 100 to obtain the apparent threat assessment value; at the same time, by calculating the difference value between the apparent threat assessment value and the normalized threat assessment value, and setting the threat level assessment criteria accordingly; The original apparent threat assessment value , integrating the threat change range and the time interval ratio, using the formula: , where RC is the threat change range, is the time interval ratio; S106, According to the obtained level of network security threats, the security threat status of the network can be more intuitively understood, providing an important basis for formulating targeted security prevention measures.
2. The network security threat assessment method according to claim 1, characterized in that, The said normalization process uses the normalization formula Convert the three key indicators of threat value (T), vulnerability value (V), and loss value (L) into a unified magnitude, making the results of threat assessment more accurate and reliable, and avoiding calculation biases caused by magnitude differences.
3. The network security threat assessment method according to claim 1, wherein, The calculation formula for the threat assessment value is as follows: , where k is an adjustment coefficient used to adjust the scale of the threat assessment value to ensure that the assessment result can accurately reflect the actual security threat situation.
4. The network security threat assessment method according to claim 1, characterized in that, The threat change amplitude RC is calculated by the formula: Quantify the change in threat; among them, is the previous threat assessment value, is the current threat assessment value; in this formula, if the threat assessment value becomes smaller (i.e., ), then RC is a positive number, indicating that the threat assessment value has decreased compared to the previous assessment; if the threat assessment value becomes larger (i.e., ), then RC is a negative number, indicating that the threat assessment value has increased compared to the previous assessment; if the threat assessment value remains unchanged, then RC is equal to 0; therefore, through the above formula, the change direction and amplitude of the threat assessment value can be intuitively reflected.
5. The network security threat assessment method according to claim 1, wherein The introduced time interval ratio TR is adjusted by calculating the ratio of the actual time interval between the base time interval of this evaluation and the time node of the previous evaluation and combining with the adjustment coefficient γ, so as to construct a quantitative standard to reflect the execution frequency of the evaluation work and its sensitivity to adapt to threat changes. The formula is: where t is the time stamp of this evaluation, is the time stamp of the previous evaluation, is the basic time interval, and γ is the adjustment coefficient, whose function is to control the influence degree of the change of the time interval on the threat evaluation value.
6. The network security threat assessment method according to claim 1, wherein The original apparent threat assessment value is mapped to the range of 1 - 100. The original apparent threat assessment value is normalized to 0 - 100 by using the method of linear mapping. The specific calculation formula is as follows: , where is the apparent threat assessment value, is the minimum value of the original apparent threat assessment value, is the maximum value of the original apparent threat assessment value.
7. A network security threat assessment method according to claim 1, characterized in that, By calculating the difference value between the apparent threat assessment value and the normalized threat assessment value, and setting the threat level assessment standard accordingly, the formula is: To provide a more intuitive and quantitative indicator to capture minor changes in the threat level, where D represents the difference value between the two; the difference values obtained according to the formula are divided into three threat levels: when the difference value is within 0 to 20%, it is set as a low threat level; when the difference value is between 20% and 50%, it is set as a medium threat level; when the difference value exceeds 50%, it is set as a high threat level; in addition, when the apparent threat assessment value is exactly equal to the threat assessment value, that is, the difference value is 0%, it is set as a specific threat level, namely the stable level.
Citation Information
Patent Citations
Network security risk assessment method, system and device
CN113542279A