Information security risk quantification method based on risk hazard and asset structure decomposition
By using a method for quantifying information security risks based on risk severity and asset structure decomposition, and generating a weighted supermatrix using network analysis, the problem of incomplete risk assessment in traditional assessment methods is solved, enabling scientific, reasonable, and comprehensive risk assessment and management of information-based business operations.
Patent Information
- Application Number
- CN202411115020.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2044-08-14
AI Technical Summary
Traditional information security risk assessment methods lack correlation analysis of risk factors, resulting in incomplete and difficult-to-quantify assessment results, which cannot effectively identify and respond to complex and ever-changing information security threats.
An information security risk quantification method based on risk severity and asset structure decomposition is adopted. A weighted supermatrix is generated through network analysis to calculate the hazard quantification value and weight of each vulnerability on each underlying asset, and to comprehensively assess the overall information security risk.
It enables scientific, reasonable, and comprehensive risk assessment of information-based business operations, quantifies risk values, asset risk values, and vulnerability risk coefficients, and improves the efficiency of information security management and the ability to cope with complex environments.
Smart Images

Figure CN119106429B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of information security, in particular to an information security risk quantification method based on risk hazard and asset structure decomposition. BACKGROUND
[0002] With the high-speed iteration and development of information technology and its application, information technology has penetrated into all aspects of economic and social development. The information level of business fields, to some extent, represents the advancement of productivity and the efficiency of management level, and directly determines market competitiveness. The informationization of business logic is accompanied by the improvement of electronic degree and the accumulation of business data. Under the joint action of complex external environment and internal technical management defects, the vulnerability of information business is highlighted. Even if the security technology capability and management level are continuously optimized and improved, information security still faces all-round threats and hidden dangers, which leads to complex and variable security risks of information business and assets, affects the continuous output and delivery capability of business implementation and production manufacturing, and is not conducive to the stability and security of business development, and even may lead to disastrous consequences. Ensuring information security is a common problem faced by organizations. Information security risk assessment is the key work and fundamental basis for information security protection and management, and is an important link of information risk management. Through information security risk assessment, risks are identified at each stage of information system planning, design, implementation, operation and maintenance, and appropriate measures are taken to analyze risk factors comprehensively, guide the construction of information system security management system, and develop comprehensive and targeted security strategies and rectification measures, to provide scientific basis and decision support for preventing, resolving and controlling information security risks and ensuring information security level.
[0003] The traditional security risk assessment method mainly adopts a qualitative assessment method, combines the estimated security event occurrence and event loss, and performs security risk assessment. In the risk assessment, the traditional method only identifies and grades risk elements, integrates and calculates to form a risk assessment result, and does not comprehensively consider the distribution characteristics of risk and its hazards, the correlation properties of asset structure, etc. The risk assessment lacks correlation analysis and system consideration, and therefore the risk assessment result is not systematic and comprehensive. SUMMARY
[0004] The present disclosure provides an information security risk quantification method based on risk hazard and asset structure decomposition to obtain a systematic and comprehensive risk assessment result.
[0005] In a first aspect, the present disclosure provides an information security risk quantification method based on risk hazard and asset structure decomposition, comprising:
[0006] The vulnerability of the business information asset system is quantified based on the probability value and the influence value of each information security risk generated by each underlying asset, and the quantified value of the harm of each information security risk generated by each underlying asset is calculated, wherein the asset structure of the business information asset system includes multiple asset categories and underlying assets under each asset category.
[0007] The at least two asset categories and the underlying assets corresponding to the two asset categories are merged, a weighted hypermatrix of the merged underlying assets is generated by using a network analysis method, and the weight of each underlying asset is solved based on the weighted hypermatrix.
[0008] The overall information security risk value of the business information asset system is calculated based on the quantified value of the harm and the weight.
[0009] In some embodiments, the information security risk quantification method further includes:
[0010] The probability value of each information security risk generated by each underlying asset of each vulnerability faced by the business information asset system is calculated by using a first calculation formula.
[0011] The influence value of each information security risk generated by each underlying asset of each vulnerability faced by the business information asset system is calculated by using a second calculation formula.
[0012] The first calculation formula is as follows:
[0013]
[0014] In the formula, pr(i)(j)(p) represents the probability value of the pth information security risk generated by the ith vulnerability on the jth underlying asset, the interval is [0, 1], r h (i)(j)(p) represents the number of votes of the pth information security risk generated by the ith vulnerability on the jth underlying asset, n a represents the number of first assessors;
[0015] The second calculation formula is as follows:
[0016]
[0017] In the formula, ef(i)(j)(p) represents the influence of the pth information security risk on the jth underlying asset in the case that the pth information security risk is generated by the ith vulnerability on the jth underlying asset, ef(i)(j)(p)(a) represents the influence value of the information security risk given by the a th assessor in the case that the pth information security risk is generated by the ith vulnerability on the jth underlying asset, and L represents the number of second assessors.
[0018] In some embodiments, a third calculation formula is used to calculate a quantified value of the damage of each information security risk caused by each vulnerability on each underlying asset;
[0019] The third calculation formula is as follows:
[0020] rc(i)(j)(p)=ef(i)(j)(p)×pr(i)(j)(p)
[0021] In the formula, rc(i)(j)(p) represents a quantified value of the damage of the pth information security risk caused by the ith vulnerability on the jth underlying asset, ef(i)(j)(p) represents an impact of the pth information security risk on the jth underlying asset in the case that the ith vulnerability causes the pth information security risk on the jth underlying asset, and pr(i)(j)(p) represents a probability value of the ith vulnerability causing the pth information security risk on the jth underlying asset.
[0022] In some embodiments, the asset categories include technical stack assets, organization management assets, and technical management assets; the merging of at least two asset categories and the underlying assets corresponding to the two asset categories uses a network analysis method to generate a weighted super matrix of the merged underlying assets, including:
[0023] The organization management assets and the technical management assets are merged, and the underlying assets under the organization management assets and the technical management assets are also merged;
[0024] Each underlying asset in the merged organization management assets and the technical management assets is taken as a criterion to form a judgment matrix and calculate a corresponding weight vector, an initial super matrix is obtained, column vectors corresponding to the merged part of the initial super matrix are split and restored into column vectors of the corresponding part before the merging and are normalized, and a final super matrix is obtained
[0025] The technical stack assets, the organization management assets, and the technical management assets are taken as criteria to form judgment matrices and calculate corresponding weight vectors, and a weighted matrix is obtained.
[0026] Each element in the weighted matrix is multiplied by a block representing a domination relationship between underlying assets under each category of assets in the super matrix to form a weighted super matrix.
[0027] In some embodiments, each underlying asset in the merged organization management assets and the technical management assets is taken as a criterion to form a judgment matrix and calculate a corresponding weight vector, an initial super matrix is obtained, column vectors corresponding to the merged part of the initial super matrix are split and restored into column vectors of the corresponding part before the merging and are normalized, and a final super matrix is obtained, including:
[0028] For each underlying asset in the technology stack asset, a judgment matrix of the underlying assets dominated by the underlying asset is formed with the underlying asset as the criterion, a corresponding weight vector is calculated based on the judgment matrix, and the weight vector is taken as a column vector of the first m rows of the super matrix, where m represents the number of underlying assets in the technology stack asset;
[0029] For the underlying assets under the merged organization management asset and the technology management asset, a judgment matrix of the underlying assets dominated by the underlying asset is formed with the underlying asset as the criterion, a corresponding weight vector is calculated based on the judgment matrix, the weight vector is split and restored into two column vectors according to the partition boundary of the underlying assets corresponding to the organization management asset and the technology management asset, the two column vectors correspond to the two parts before the merging respectively, the two column vectors are normalized respectively, and the normalized column vectors are taken as the column vectors of the m+1 th row to the m+n th row of the super matrix and the column vectors of the m+n+1 th row to the m+n+q th row of the super matrix respectively, where n represents the number of underlying assets in the organization management asset, and q represents the number of underlying assets in the technology management asset.
[0030] In some embodiments, solving the weight of each underlying asset based on the weighted super matrix comprises:
[0031] iteratively calculating the WHMA N N-1 ×WHMA;
[0032] The termination condition of the iterative calculation is as follows:
[0033]
[0034] wherein, WHMA represents the weighted super matrix, i represents the row index of the WHMA n , j represents the column index of the WHMA N , WHMA N ij represents the i th row and the j th column element of the WHMA N , max represents the maximum value of a vector, min represents the minimum value of a vector, cov represents a threshold value, and N represents the current iteration number;
[0035] taking the median of each row of the WHMA N to form the WHMA N a row median column vector RMC, each element in the row median column vector RMC being a weight of a corresponding underlying asset, summing and normalizing the row median column vector RMC, the normalized row median column vector being denoted as MC, the first m elements in the row median column vector MC sequentially representing weights of corresponding underlying assets in the technology stack assets, the (m+1)th element to the (m+n)th element sequentially representing weights of corresponding underlying assets in the organization management assets, and the (m+n+1)th element to the (m+n+q)th element sequentially representing weights of corresponding underlying assets in the technology management assets.
[0036] In some embodiments, an overall information security risk value of the business information asset system is calculated based on the weight and the quantified value of the harm, using a fourth calculation formula as follows:
[0037]
[0038] wherein Rw represents the overall information security risk value of the business information asset system, taking a value in the interval [0, 1], and the greater the overall information security risk value, the greater the risk; MC(j) represents the weight of the jth underlying asset; rc(i)(j)(p) represents the quantified value of harm of the pth information security risk caused by the ith vulnerability on the jth underlying asset; and rkn(i)(j) represents the number of information security risks caused by the ith vulnerability on the jth underlying asset.
[0039] In some embodiments, the information security risk quantification method further comprises:
[0040] A fifth calculation formula is used to calculate a risk coefficient of each information security risk of the business information asset system based on the quantified value of harm and the weight;
[0041] The fifth calculation formula is as follows:
[0042]
[0043] wherein Rc(p) represents the risk coefficient of the pth information security risk, taking a value in the interval [0, 1], and the greater the risk coefficient, the greater the destructive power of the information security risk on the business information asset system; MC(j) represents the weight of the jth underlying asset; and rc(i)(j)(p) represents the quantified value of harm of the pth information security risk caused by the ith vulnerability on the jth underlying asset.
[0044] In some embodiments, the information security risk quantification method further comprises:
[0045] A sixth calculation formula is used to calculate a risk coefficient of each vulnerability of the business information asset system based on the quantified value of harm and the weight;
[0046] The sixth calculation formula is as follows:
[0047]
[0048] wherein Rv(i) represents a risk coefficient of the i-th vulnerability, the risk coefficient is in the interval [0, 1], and the greater the risk coefficient indicates the greater the destructive power of the vulnerability on the business information asset system; MC(j) represents the weight of the j-th underlying asset; rc(i)(j)(p) represents the harm quantization value of the p-th information security risk generated by the i-th vulnerability on the j-th underlying asset; and rkn(i)(j) represents the number of information security risks generated by the i-th vulnerability on the j-th underlying asset.
[0049] In some embodiments, the information security risk quantization method further comprises:
[0050] The risk value of each underlying asset of the business information asset system is calculated based on the harm quantization value and the weight by using a seventh calculation formula;
[0051] The seventh calculation formula is as follows:
[0052]
[0053] wherein Ra(j) represents the risk value of the j-th underlying asset, the risk value is in the interval [0, 1], and the greater the risk value indicates the greater the risk harm of the asset; MC(j) represents the weight of the j-th underlying asset; rc(i)(j)(p) represents the harm quantization value of the p-th information security risk generated by the i-th vulnerability on the j-th underlying asset; and rkn(i)(j) represents the number of information security risks generated by the i-th vulnerability on the j-th underlying asset.
[0054] In a second aspect, the disclosure provides an information security risk quantization device based on risk harm and asset structure decomposition, comprising:
[0055] A harm quantization module is configured to calculate the harm quantization value of each information security risk generated by each vulnerability on each underlying asset based on the probability value and the impact value of each information security risk generated by each vulnerability on each underlying asset in a business information asset system, wherein the asset structure in the business information asset system comprises a plurality of asset categories and underlying assets under each asset category.
[0056] A weight solving module is configured to combine at least two asset categories and the underlying assets corresponding to the two asset categories, generate a weighted hypermatrix of the combined underlying assets by using a network analysis method, and solve the weight of each underlying asset based on the weighted hypermatrix.
[0057] a risk calculation module configured to calculate an overall information security risk value of the information technology asset system based on the quantified value of the hazard and the weight.
[0058] In a third aspect, the present disclosure provides a computer device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method of the first aspect.
[0059] In a fourth aspect, the present disclosure provides a computer readable storage medium, having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method of the first aspect.
[0060] In a fifth aspect, the present disclosure provides a computer program product, comprising computer programs / instructions, wherein the computer programs, when executed by a processor, implement the steps of the method of the first aspect.
[0061] The scheme provided by the present disclosure comprehensively considers the asset system structure and the vulnerability risk distribution structure, flexibly utilizes the analytic network process (ANP) to perform asset correlation importance analysis, and performs comprehensive information security risk assessment and analysis of the system, so as to quantify the risk value of the overall information technology business, the risk value of the asset, the risk coefficient of the vulnerability, and the risk coefficient of the risk. The method is scientific and reasonable, has high technical advancement and reliability, is complete in system, and has high practical value. The method solves the problems in the related art, such as lack of system in the risk assessment method, lack of correlation analysis of system asset elements, difficulty in quantifying the risk assessment result, dispersion and independence of the analysis elements, difficulty in integrated analysis, large number of judgment matrices in the super matrix in the ANP algorithm, high complexity of the characteristic vector solving calculation, quantification of the vulnerability hazard degree, quantification of the risk hazard degree, and quantification of the specified asset risk value. The method is beneficial to information technology construction safety management and improves the information technology business safety management efficiency, and can effectively cope with the complex and changeable information security environment. BRIEF DESCRIPTION OF DRAWINGS
[0062] In the following, the present disclosure will be described in more detail based on embodiments and with reference to the accompanying drawings:
[0063] Figure 1 A flowchart of the information security risk quantification method based on risk hazard and asset structure decomposition provided by the embodiments of the present disclosure is shown in the following figure:
[0064] Figure 2 An element structure diagram of the information security risk quantification analysis and evaluation based on risk hazard and asset structure decomposition provided by the embodiments of the present disclosure is shown in the following figure:
[0065] Figure 3 An information security risk diagram caused by vulnerability provided by the embodiments of the present disclosure is shown in the following figure:
[0066] Figure 4 A business informatization-oriented asset decomposition schematic diagram provided by an embodiment of the present disclosure;
[0067] Figure 5 An application example schematic diagram provided by an embodiment of the present disclosure;
[0068] In the drawings, the same components are designated by the same reference numerals, and the drawings are not drawn according to the actual scale. DETAILED DESCRIPTION
[0069] In order to enable personnel in the art to better understand the technical solutions of the present disclosure, and to fully understand and implement the implementation process of the present disclosure how to apply technical means to solve technical problems and achieve corresponding technical effects, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, not all. The embodiments of the present disclosure and various features in the embodiments can be combined with each other without conflict, and the technical solutions formed thereby are all within the protection scope of the present disclosure. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative labor should be within the protection scope of the present disclosure.
[0070] In information security risk assessment, due to the complex relationship of mutual interlacing influence and mutual condition between assets, the traditional assessment method has limited risk assessment quantization means, and the granularity is relatively coarse, and the complex correlation between assets is not considered. Therefore, the assessment method has limitations. The scheme provided by the present disclosure comprehensively considers the asset system structure and the vulnerability risk distribution structure, flexibly uses the network analysis method (Analytic Network Process, ANP for short) to analyze the asset correlation importance, and performs comprehensive information security risk assessment and analysis of the system, so as to quantify the risk value of the overall information business, the risk value of the asset, the dangerous coefficient of the vulnerability and the dangerous coefficient of the risk. The method is scientific and reasonable, has high technical advancement and reliability, and has a complete estimation system and high practical value.
[0071] In the scheme of the present disclosure, the asset system structure and the vulnerability risk distribution structure are comprehensively considered, the network analysis method (Analytic Network Process, ANP for short) is flexibly used to analyze the asset correlation importance, and the comprehensive information security risk assessment and analysis of the system are performed, so as to quantify the risk value of the overall information business, the risk value of the asset, the dangerous coefficient of the vulnerability and the dangerous coefficient of the risk. The method is scientific and reasonable, has high technical advancement and reliability, and has a complete estimation system and high practical value.
[0072] The following introduces the relationship symbol expression system between the elements (nodes) involved in the method:
[0073] The following is the relationship symbol expression convention between nodes in the application of ANP process.
[0074] Bidirectional association: nodes v1, …, vn are dependent on each other, denoted by (v1, …, vn), and abbreviated as (vi | i ∈ {1, …, n}).
[0075] One-way association: node v1 dominates v2, denoted by <v1, v2>.
[0076] Set: nodes v1, …, vn form a set, denoted by {v1, …, vn}, abbreviated as {vi | i ∈ {1, …, n}}, and the corresponding set can also be obtained by using a function. The elements in the set can be represented by bidirectional association or one-way association according to the actual logical relationship. The elements in the set can also have no dependent relationship.
[0077] The following is an example of composite association. This example is for a two-layer case, and the multi-layer case can be extended accordingly:
[0078] 1) {v1, (v2, …, vn)} represents that v2, …, vn are dependent on each other, and v1 and (v2, …, vn) form a set. It is mainly used for the structure representation of ANP and does not involve the weight quantification between v1 and {v2, …, vn}.
[0079] 2) <v1, {v2, …, vn}> represents the relationship that the upper node v1 dominates the lower node set {v2, …, vn}, abbreviated as <v1, {vi | i ∈ {2, …, n}}>. It is mainly used for the structure representation of ANP and involves the weight quantification between v1 and {v2, …, vn}.
[0080] 3) {<v1, S1>, … <vn, Sn>} represents that the upper nodes v1, …, vn respectively dominate the lower node sets S1, … Sn, abbreviated as {<vi, Si> | i ∈ {1, …, n}}. It is mainly used for the structure representation of ANP and involves the weight quantification between the nodes in vi and Si.
[0081] The nodes or node sets (nodes or functions in the set are enclosed in {}) separated by "," in the above "<>" are referred to as parts. From left to right, the left part is the upper part of the right part, and the right part is the lower part of the left part. In the ANP method, a bidirectional association can be decomposed into several unidirectional associations. Since the nodes in the network relationship are mostly composed of bidirectional associations and unidirectional associations, the unidirectional relationship can be directly applied to the Analytic Hierarchy Process (AHP) to quantify the weight of the model, and the bidirectional association can be decomposed into unidirectional association, so that the AHP method can be used to determine the weighted supermatrix in the ANP method. In addition, in the above symbol representation, the left part and the right part separated by "," in "<>" are the positions that need to determine the relevant weights. "() " is finally decoupled into multiple "<>" representations. "{}" is only used for the structure representation of the hierarchy or network. The present application uses "<>", "()" and "{}" to construct the asset structure representation, and represents and decomposes the association relationship between assets.
[0082] The related principles of the analytic hierarchy process (AHP) are introduced below:
[0083] 1) Judgment matrix
[0084] The elements of the judgment matrix represent that the upper node is the target or criterion, and in terms of the relationship, the lower node of the row number and the lower node of the column number are important to the upper node. The judgment matrix elements use the 1-9 scale method, and the meanings of 1-9 and their reciprocals are listed in the table.
[0085] Table 1 1-9 scale method of judgment matrix elements
[0086]
[0087] 2) Calculate weight
[0088] First, normalize the judgment matrix by column (divide each element by the sum of its column), then add each column of the normalized matrix (sum by row), and finally divide each element in the resulting vector by n to obtain the weight vector.
[0089]
[0090] In the formula, w i is the weight of the ith index or requirement.
[0091] 3) Calculate the maximum eigenvalue of the judgment matrix
[0092] The maximum eigenvalue of the judgment matrix is calculated as follows:
[0093]
[0094] where λ max is the maximum eigenvalue of the judgment matrix.
[0095] 4) Consistency check
[0096] In order to check the logical rationality, the judgment matrix needs to be checked for consistency.
[0097] The checking steps are as follows:
[0098] 4.1) Calculate the consistency index CI:
[0099]
[0100] where λ max is the maximum eigenvalue of the judgment matrix, and n is the order of the matrix.
[0101] 4.2) Calculate the consistency ratio CR:
[0102]
[0103] where RI is the average random consistency index, which can be obtained by looking up the table.
[0104] 4.3) Consistency judgment:
[0105] When CR<0.1, it is considered that the consistency of the judgment matrix is acceptable.
[0106] When CR≥0.1, the judgment matrix does not meet the consistency requirement, and the judgment matrix needs to be modified, the CR is recalculated and judged until the consistency requirement of the matrix is met, and the weight calculated in 2) is accepted.
[0107] In the scheme of the disclosure, the informationization business information security risk assessment is divided into two dimensions: first, the business informationization asset system (business informationization asset system) is decomposed to obtain different types of informationization assets, and the network association relationship is formed by combining the dependency relationship between the decomposed elements, so as to determine the weight of each asset. Second, the vulnerability risk hazard structure decomposition, that is, the hazard of different risks that each vulnerability may cause is quantified, and the corresponding hazard is mapped to different assets. In this way, by integrating the hazard of each risk of each vulnerability and the importance of the asset corresponding to the risk, the information security risk assessment result of the overall informationization business is formed, that is, the information security risk value of the overall informationization business. At the same time, through the data collection of the model, the risk hazard degree, the vulnerability hazard degree, and the asset risk value can be analyzed in multiple dimensions.
[0108] Example One
[0109] Figure 1 A flowchart of a risk quantification method based on risk hazard and asset structure decomposition is shown as follows. Figure 1 The risk quantification method based on risk hazard and asset structure decomposition provided in the embodiment includes the following steps.
[0110] In step S11, the probability value and the impact value of each information security risk caused by each vulnerability on each underlying asset are calculated based on each vulnerability faced by the business information asset system, and the hazard quantification value of each information security risk caused by each vulnerability on each underlying asset is calculated, wherein the asset structure in the business information asset system includes a plurality of asset categories and underlying assets under each asset category.
[0111] In the embodiment, the factor structure of the risk quantification analysis and evaluation based on risk hazard and asset structure decomposition can be shown as follows. Figure 2 The method of the embodiment performs information security risk quantification analysis and evaluation based on vulnerability risk hazard and asset structure decomposition, and forms the factor structure of information security risk evaluation by decomposing the business information asset system B and the vulnerability information security risk hazard. The information security risk hazard of the vulnerability V refers to the risk damage capability of various risks that the vulnerability can cause on assets of a certain importance level, i.e., the damage capability of a specified risk caused by a specified vulnerability on a specified asset is evaluated by the security measures taken by the vulnerability, the threats faced by the vulnerability, the difficulty of the vulnerability being exploited, the impact of the risk caused by the vulnerability on the asset, and other factors. The asset weight in the business information system reflects the importance of the underlying asset, and these weights are quantified by the ANP method. As shown in the following table, the place marked with √ shows the correlation distribution of the risk formed by a vulnerability in all assets. The logic of risk analysis and evaluation of the method is that the risk value is related to the asset importance and the hazard of various risks caused by the vulnerability on the asset, the hazard of various risks caused by each vulnerability on each asset is integrated, and the asset importance is combined to obtain the quantification result of risk evaluation and analysis. Figure 2
[0112] Before step S11, the probability value of each information security risk caused by each vulnerability on each underlying asset and the impact value of each information security risk caused by each vulnerability on each underlying asset faced by the business information asset system are calculated, and then the hazard quantification value of each information security risk caused by each vulnerability on each underlying asset is calculated. Therefore, the information security risk quantification method of the embodiment further includes the following steps.
[0113] The first calculation formula is used to calculate the probability value of each information security risk caused by each vulnerability of the business information asset system on each underlying asset.
[0114] The second calculation formula is used to calculate the impact value of each information security risk caused by each vulnerability of the business information asset system on each underlying asset.
[0115] The vulnerability V has a probability of generating a corresponding risk for different underlying assets according to factors such as security measures taken, threats faced, and ease of exploitation, and then quantifies the harm of each risk by combining the impact of the risk on the underlying asset. Fixing the ith vulnerability and the jth underlying asset, the vulnerability can generate different risks, and fixing the pth risk, there is a probability of generating the pth risk. In some embodiments, this probability can be generated by obtaining the statistical voting of the evaluators on the occurrence of the pth risk. It should be understood that the risk referred to here is an information security risk.
[0116] The first calculation formula is as follows:
[0117]
[0118] In the formula, pr(i)(j)(p) represents the probability value of the pth information security risk generated by the ith vulnerability on the jth underlying asset, the interval is [0, 1], and it is an estimated value; r h (i)(j)(p) represents the number of votes for the pth information security risk generated by the ith vulnerability on the jth underlying asset, n a represents the number of first evaluators;
[0119] In some embodiments, the impact of the risk on the asset can be quantified as a continuous variable in the interval [0, 1] according to the evaluation of the evaluators, 0 is no impact, and 1 is the maximum impact. If the pth risk generated by the ith vulnerability on the jth underlying asset, the impact on the jth underlying asset is recorded as ef(i)(j)(p), and the value is in the interval [0, 1].
[0120] The second calculation formula is as follows:
[0121]
[0122] In the formula, ef(i)(j)(p) represents the impact of the pth information security risk on the jth underlying asset in the case of the pth information security risk generated by the ith vulnerability on the jth underlying asset, ef(i)(j)(p)(a) represents the impact value of the information security risk given by the ath evaluator in the case of the pth information security risk generated by the ith vulnerability on the jth underlying asset, and L represents the number of second evaluators.
[0123] The impact value of the risk can be taken from the following table.
[0124] Table 2 Risk Impact Value Table
[0125] Risk Impact Value Meaning 5 Risk has a major impact on the asset 4 Risk has a large impact on the asset 3 Risk has a general impact on the asset 2 Risk has a small impact on the asset 1 Risk has a weak impact on the asset 0 Risk has no impact on the asset
[0126] In some embodiments, a third calculation formula can be further employed to calculate the quantified value of the harm of each information security risk caused by each vulnerability on each underlying asset;
[0127] The third calculation formula is as follows:
[0128] rc(i)(j)(p) = ef(i)(j)(p) x pr(i)(j)(p)
[0129] In the formula, rc(i)(j)(p) represents the quantified value of the harm of the pth information security risk caused by the ith vulnerability on the jth underlying asset, ef(i)(j)(p) represents the impact of the pth information security risk on the jth underlying asset in the case that the ith vulnerability causes the pth information security risk on the jth underlying asset, and pr(i)(j)(p) represents the probability value of the ith vulnerability causing the pth information security risk on the jth underlying asset.
[0130] Based on the above calculation formula, the quantified value of the harm of each information security risk is calculated by changing p, j, and i respectively.
[0131] In step S12, at least two asset categories and the underlying assets corresponding to the two asset categories are merged, a weighted hypermatrix of the merged underlying assets is generated by employing the network analysis method, and the weight of each underlying asset is solved based on the weighted hypermatrix.
[0132] As Figure 4As shown, the evaluation entity of the business informationization B in the embodiment is decomposed into three dimensions (asset categories) of technology stack T, organization management O and technology management M, that is, the asset categories include technology stack assets, organization management assets and technology management assets, which can be simplified as {B, (T, O, M)}, wherein the technology stack includes system hardware, software and other assets, the organization management includes environment management, operation management, system development management, operation and maintenance management, business continuity management and other assets, and the technology management includes security policy, organization security, asset classification and control, compliance application management and other assets. The related processes of the technology stack, the organization management and the technology management are converted from verticalization to flat structure. The relationship between the technology stack and the underlying assets subordinate thereto is represented as {T, (T1, …, Tm)}, and m is the number of underlying assets of the technology stack. The relationship between the organization management and the underlying assets subordinate thereto is represented as {O, (O1, …, On)}, and n is the number of underlying assets of the organization management. The relationship between the technology management and the underlying assets subordinate thereto is represented as {M, (M1, …, Mq)}, and q is the number of underlying assets of the organization management. Figure 4 The correlation structure of the assets facing the business informationization is used to obtain the weight symbol system, which includes:
[0133] 1) (T, O, M) 2)
[0135] {<Ai, RE(Ai)>|i∈{1,…,m+n+q}}={<T1,RE(T1)>,…,<Tm,RE(Tm)>,<O1,RE(O1)>,…,<On,RE(On)>,<M1,RE(M1)>,…,<Mq,RE(Mq)>}
[0136] Wherein, Ai represents the i-th underlying asset, Ai,…,Am are T1,…,Tm respectively; Am+1,…,Am+n are O1,…,On respectively; Am+n+1,…,Am+n+q are M1,…,Mq respectively. m is the number of underlying assets of the technology stack, n is the number of underlying assets of the organization management, and q is the number of underlying assets of the organization management. RE is a function for obtaining a set of underlying assets dominated by a certain underlying asset, and the output is a set of underlying assets that can be dominated by the corresponding underlying asset. For example, RE(Ai) represents a set of underlying assets dominated by Ai, which includes Ai itself. The weight quantization process is as follows:
[0137] The above-mentioned merging of at least two asset categories and the underlying assets corresponding to the two asset categories generates a weighted super-matrix of the merged underlying assets by using the network analysis method, which can include:
[0138] Step S12a, merging the organization management assets and the technology management assets, and simultaneously merging the underlying assets under the organization management assets and the technology management assets.
[0139] To reduce the time complexity and space complexity of ANP calculation, the embodiment adopts the method of merging elements, reduces the generation of judgment matrix, and then reduces the number of times of solving the weight through the eigenvalue method of the matrix, and reduces the solving complexity. Here, logically merge O and M, denoted as OM = O U M, and logically merge the underlying assets, denoted as OMi representing the i-th underlying asset corresponding to OM, OMi, …, OMn are O1, …, On respectively;
[0140] OMn+1, …, OMn+q are M1, …, Mq respectively. T is not merged. In this way, according to the ANP method, the variables T, O, M, the correlation relationship of the asset elements is generated, and the number of judgment matrices formed is originally 3(m+n+q). After merging the judgment matrix, the number of judgment matrices is 2(m+n+q), thereby reducing the number of times of decomposing and solving the weight of the judgment matrix, and reducing the space complexity and time complexity.
[0141] Step S12b, respectively taking each underlying asset in the merged organization management asset and technology management asset as the criterion, forming a judgment matrix and calculating the corresponding weight vector, obtaining an initial super matrix, splitting and restoring the column vectors corresponding to the merged part of the initial super matrix into the column vectors of the corresponding part before merging and normalizing, and obtaining a final super matrix.
[0142] Denote TOM = T U O U M, take T1, …, Tm, O1, …, On, M1, …, Mq as criteria respectively, form a judgment matrix, that is, decompose {<Ai, RE(Ai)>|i∈{1,…,m+n+q}} one by one to form the corresponding judgment matrix. Further, respectively taking each underlying asset in the merged organization management asset and technology management asset as the criterion, forming a judgment matrix and calculating the corresponding weight vector, obtaining an initial super matrix, splitting and restoring the column vectors corresponding to the merged part of the initial super matrix into the column vectors of the corresponding part before merging and normalizing, and obtaining a final super matrix, including:
[0143] For each underlying asset in the technology stack asset, respectively taking each underlying asset as the criterion to form a judgment matrix of the underlying assets dominated by the underlying asset, calculating the corresponding weight vector based on the judgment matrix as the column vector of the first m rows of the super matrix, and m represents the number of underlying assets in the technology stack asset;
[0144] For the underlying assets under the merged organization management assets and technology management assets, a judgment matrix of the underlying assets dominated by each underlying asset is formed as a criterion, a corresponding weight vector is calculated based on the judgment matrix, the weight vector is split and restored into two column vectors according to the segmentation boundary of the underlying assets corresponding to the organization management assets and the technology management assets, the two column vectors correspond to the two parts before merging respectively, and the two column vectors are normalized respectively as the column vectors of the m+1th row to the m+nth row and the column vectors of the m+n+1th row to the m+n+qth row of the super matrix, n represents the number of underlying assets in the organization management assets, and q represents the number of underlying assets in the technology management assets.
[0145] In some specific embodiments, the generation of the super matrix is as follows:
[0146] For each Ai, According to the method of 1-9 scale of the judgment matrix elements in the analytic hierarchy process introduced above, a judgment matrix JMi of the factors dominated by Ai is formed as a criterion, len(RE(Ai)) represents the number of elements in RE(Ai), each judgment matrix is a len(RE(Ai)) order square matrix, and a corresponding len(RE(Ai))×1 weight vector WVi is calculated based on JMi, for the elements Ti in T that cannot be dominated by Ai, 0 is inserted at the corresponding position of WVi according to the position of Ti in T, so that WVi becomes an m×1 column vector. If Ai cannot dominate all elements in T, the corresponding WVi is an m×1 column vector with all elements being 0. WVi corresponding to Ai is respectively a column vector of the first m rows of the super matrix HMA.
[0147] For each Ai, According to the method of 1-9 scale of the judgment matrix elements in the analytic hierarchy process introduced above, a judgment matrix JMi of the factors dominated by Ai is formed as a criterion, len(RE(Ai)) represents the number of elements in RE(Ai), each judgment matrix is a len(RE(Ai)) order square matrix, and a corresponding len(RE(Ai))×1 weight vector WVi is calculated based on JMi, for the elements Ti in T that cannot be dominated by Ai, 0 is inserted at the corresponding position of WVi according to the position of Ti in T, so that WVi becomes an m×1 column vector. If Ai cannot dominate all elements in T, the corresponding WVi is an m×1 column vector with all elements being 0. WVi corresponding to Ai is respectively a column vector of the first m rows of the super matrix HMA.
[0147] For each Ai, According to the method of 1-9 scale of the judgment matrix elements in the analytic hierarchy process introduced above, a judgment matrix JMi of the factors dominated by Ai is formed as a criterion, len(RE(Ai)) represents the number of elements in RE(Ai), each judgment matrix is a len(RE(Ai)) order square matrix, and a corresponding len(RE(Ai))×1 weight vector WVi is calculated based on JMi, for the elements Ti in T that cannot be dominated by Ai, 0 is inserted at the corresponding position of WVi according to the position of Ti in T, so that WVi becomes an m×1 column vector. If Ai cannot dominate all elements in T, the corresponding WVi is an m×1 column vector with all elements being 0. WVi corresponding to Ai is respectively a column vector of the first m rows of the super matrix HMA.
[0147] For each Ai, According to the method of 1-9 scale of the judgment matrix elements in the analytic hierarchy process introduced above, a judgment matrix JMi of the factors dominated by Ai is formed as a criterion, len(RE(Ai)) represents the number of elements in RE(Ai), each judgment matrix is a len(RE(Ai)) order square matrix, and a corresponding len(RE(Ai))×1 weight vector WVi is calculated based on JMi, for the elements Ti in T that cannot be dominated by Ai, 0 is inserted at the corresponding position of WVi according to the position of Ti in T, so that WVi becomes an m×1 column vector. If Ai cannot dominate all elements in T, the corresponding WVi is an m×1 column vector with all elements being 0. WVi corresponding to Ai is respectively a column vector of the first m rows of the super matrix HMA.
[0148] The method for generating a hypermatrix based on the merging and segmentation of the logical boundary of elements can reduce the generation of judgment matrices, thereby reducing the number of times of solving the weight by the eigenvalue method, and reducing the complexity of subsequent weight solving. The ANP (Analytic Network Process) method is used in the asset decomposition of risk assessment modeling, and the hypermatrix generation method based on the merging and segmentation of the logical boundary of elements is creatively used, which effectively reduces the time complexity and space complexity of ANP.
[0149] In step S12c, judgment matrices are formed and corresponding weight vectors are calculated respectively taking the technical stack asset, the organization management asset and the technical management asset as criteria, and a weighted matrix is obtained.
[0150] Taking T, O and M as criteria respectively, judgment matrices are formed, that is, (T, O, M) is decomposed one by one to form corresponding judgment matrices: (T, O, M) is decomposed into {<T, {T, O, M}>, <O, {O, T, M}>, <M, {M, T, O}>}, three 3x3 judgment matrices are formed according to the method of 1-9 scale of judgment matrix elements in the analytic hierarchy process introduced above, and three 3x1 weight vectors are calculated as column vectors of the 3x3 weighted matrix WM.
[0151] In step S12d, each element in the weighted matrix is multiplied by the block representing the domination relationship between the bottom layer assets under each type of asset in the hypermatrix to form a weighted hypermatrix. The domination relationship between the bottom layer assets under each type of asset includes the domination relationship between the bottom layer assets under the same type of asset and the domination relationship between the bottom layer assets under different types of assets.
[0152] The hypermatrix HMA is divided into nine blocks corresponding to <T, T>, <T, O>, <T, M>, <O, T>, <O, O>, <O, M>, <M, T>, <M, O> and <M, M> respectively. Each element of the weighted matrix WM obtained above is multiplied by the block of the hypermatrix HMA to form a weighted hypermatrix WHMA.
[0153] Further, the weight of each bottom layer asset is solved based on the weighted hypermatrix, including:
[0154] Iterative calculation of WHMA N = WHMA N-1 x WHMA;
[0155] The termination condition of the iterative calculation is as follows:
[0156]
[0157] where WHMA represents the weighted hypermatrix, and i represents the WHMAN row index of WHMA N column index of WHMA N ij element of the i-th row and j-th column of WHMA N max indicates the maximum value of the orientation vector, min indicates the minimum value of the orientation vector, and cov indicates a threshold value;
[0158] WHMA N median of each row, forming a WHMA N row median column vector RMC, each element in the row median column vector RMC is the weight of the corresponding underlying asset, the row median column vector RMC is normalized by summation, and the normalized row median column vector is denoted as MC. The first m elements in the row median column vector MC represent the weights of the corresponding underlying assets in the technology stack assets in turn, the m+1th element to the m+nth element represent the weights of the corresponding underlying assets in the organization management assets in turn, and the m+n+1th element to the m+n+qth element represent the weights of the corresponding underlying assets in the technology management assets in turn.
[0159] The above iterative calculation is performed until the difference between each column vector in WHMA N becomes smaller, and ideally, each column vector is consistent, so that the corresponding elements of the column vector are the weights of the underlying assets, and the solution is completed. The threshold value cov is set to constrain the column vectors of WHMA N to approximately converge to be consistent.
[0160] It should be understood that the formation of the above judgment matrix needs to be completed by multiple experts in collaboration and through consistency test.
[0161] Step S13, calculating the overall information security risk value of the business information asset system based on the quantified value of the hazard and the weight.
[0162] In some specific embodiments, the overall information security risk value of the business information asset system is calculated based on the quantified value of the hazard and the weight, and the following fourth calculation formula is used:
[0163]
[0164] wherein Rw represents the overall information security risk value of the business information asset system, which is in the interval [0, 1], and the larger the overall information security risk value, the greater the risk; MC(j) represents the weight of the jth underlying asset; rc(i)(j)(p) represents the quantified value of the hazard of the pth information security risk produced by the ith vulnerability on the jth underlying asset, and rkn(i)(j) represents the number of information security risks produced by the ith vulnerability on the jth underlying asset.
[0165] In some embodiments, the method can further calculate a risk coefficient of each information security risk of the business information asset system, a risk coefficient of each vulnerability, and a risk value of each underlying asset, to further realize the information security risk analysis and evaluation.
[0166] Specifically, the method can further include:
[0167] adopting a fifth calculation formula to calculate a risk coefficient of each information security risk of the business information asset system based on the harm quantization value and the weight;
[0168] The fifth calculation formula is as follows:
[0169]
[0170] wherein Rc(p) represents the risk coefficient of the pth information security risk, which is in the interval [0, 1], and the greater the risk coefficient is, the greater the destructive power of the information security risk to the business information asset system is; MC(j) represents the weight of the jth underlying asset; and rc(i)(j)(p) represents the harm quantization value of the pth information security risk caused by the ith vulnerability on the jth underlying asset.
[0171] adopting a sixth calculation formula to calculate a risk coefficient of each vulnerability of the business information asset system based on the harm quantization value and the weight;
[0172] The sixth calculation formula is as follows:
[0173]
[0174] wherein Rv(i) represents the risk coefficient of the ith vulnerability, which is in the interval [0, 1], and the greater the risk coefficient is, the greater the destructive power of the vulnerability to the business information asset system is; MC(j) represents the weight of the jth underlying asset; rc(i)(j)(p) represents the harm quantization value of the pth information security risk caused by the ith vulnerability on the jth underlying asset; and rkn(i)(j) represents the number of information security risks caused by the ith vulnerability on the jth underlying asset.
[0175] adopting a seventh calculation formula to calculate a risk value of each underlying asset of the business information asset system based on the harm quantization value and the weight;
[0176] The seventh calculation formula is as follows:
[0177]
[0178] Wherein, Ra(j) represents the risk value of the jth underlying asset, taking value in the interval [0, 1], the greater the risk value, the greater the risk harm suffered by the asset; MC(j) represents the weight of the jth underlying asset; rc(i)(j)(p) represents the harm quantification value of the pth information security risk produced by the ith vulnerability on the jth underlying asset; rkn(i)(j) represents the quantity of the information security risk produced by the ith vulnerability on the jth underlying asset.
[0179] Further, the method of the embodiment can further include:
[0180] The above risk coefficients and risk values are sorted respectively to obtain an information security risk quantification report based on risk harm and asset structure decomposition, realizing data processing of information security risk information based on risk harm and asset structure decomposition, so as to further analyze the assets, vulnerabilities and risks. The information security risk information includes at least one of the overall information security risk value of the business information asset system, the risk coefficient of each information security risk, the risk coefficient of each vulnerability, and the risk value of each underlying asset.
[0181] The method comprehensively considers the asset system structure and the vulnerability risk distribution structure, flexibly utilizes the analytic network process (ANP) for asset correlation importance analysis, and performs comprehensive information security risk evaluation and analysis of the system, so as to quantify the risk value of the overall informationization business, the risk value of the asset, the risk coefficient of the vulnerability and the risk coefficient of the risk. The method is scientific and reasonable, has high technical advancement and reliability, and is complete and practical.
[0182] Specifically, the problems of the related art, such as the lack of systematic risk assessment method, the lack of systematic asset element correlation analysis, the difficulty in quantifying the risk assessment result, the dispersion and independence of the analysis elements, the difficulty in integrated analysis, the large number of judgment matrices in the super matrix in the ANP algorithm, the high complexity of the characteristic vector solving calculation, the vulnerability hazard degree quantization problem, the risk hazard degree quantization, and the specified asset risk value quantization problem, are solved. It is conducive to information construction safety management, improves information business safety management efficiency, can effectively respond to complex and variable information security environment, and further promotes the continuous output and delivery capability of business implementation and production manufacturing, is conducive to the stability and safety of business development, can be applied to the identification of risks in each stage of planning, design, implementation, operation and maintenance, and abandonment of information systems, guides the construction of information system safety management system, supports the development of comprehensive and targeted safety strategies and rectification measures, provides scientific basis and decision support for preventing, resolving and controlling information security risks, and guarantees information security level, improves the comprehensive system of information security risk assessment, supports different granularity risk assessment and analysis, promotes the improvement of information security risk analysis and evaluation ability in fine granularity and multi-dimension, and helps fine-grained decision-making and multi-dimensional decision-making.
[0183] Example Two
[0184] Corresponding to the first embodiment, the present embodiment provides an information security risk quantization device based on risk hazard and asset structure decomposition, comprising:
[0185] A hazard quantization module is configured to calculate a hazard quantization value of each vulnerability on each bottom layer asset based on a probability value and an impact value of each information security risk caused by each vulnerability on each bottom layer asset in a business information asset system, wherein the asset structure in the business information asset system comprises a plurality of asset categories and bottom layer assets under each asset category.
[0186] A weight solving module is configured to combine at least two asset categories and the bottom layer assets corresponding to the two asset categories, generate a weighted super matrix of the combined bottom layer assets by using a network analysis method, and solve the weight of each bottom layer asset based on the weighted super matrix.
[0187] A risk calculation module is configured to calculate the overall information security risk value of the business information asset system based on the hazard quantization value and the weight.
[0188] In the present embodiment, the element structure of the information security risk quantization analysis and evaluation based on risk hazard and asset structure decomposition can be as follows Figure 2The method of the embodiment is based on the information security risk quantitative analysis and evaluation of the vulnerability risk hazard and asset structure decomposition. The business information asset system B and the vulnerability information security risk hazard are decomposed to form the element structure of the information security risk evaluation. The information security risk hazard of the vulnerability V refers to the risk damage ability of various risks that the vulnerability can produce on the asset with a certain importance degree. That is, on the specified asset, the evaluator assesses the damage ability of the specified risk produced by the specified vulnerability by the security measures taken by the vulnerability, the threats faced by the vulnerability, the difficulty of the vulnerability being exploited, the impact of the risk on the asset after the vulnerability is exploited, and other factors. The asset weight in the business information system reflects the importance of the underlying asset, and these weights are quantified by the ANP method. For example Figure 2 As shown, the place marked with √ is the correlation distribution of the risk formed by a vulnerability in all assets. The logic of the risk analysis and evaluation of the method is that the risk value is related to the asset importance and the vulnerability hazard of various risks produced thereon. The hazard of each risk of each vulnerability on each asset is integrated, and the asset importance is combined to obtain the quantitative result of the risk evaluation and analysis.
[0189] In the embodiment, the first calculation formula is used to calculate the probability value of each information security risk produced by each vulnerability on each underlying asset; and the second calculation formula is used to calculate the impact value of each information security risk produced by each vulnerability on each underlying asset.
[0190] The first calculation formula is as follows:
[0191]
[0192] In the formula, pr(i)(j)(p) represents the probability value of the ith vulnerability producing the pth information security risk on the jth underlying asset, the interval is [0, 1], and it is an estimated value; r h (i)(j)(p) represents the number of votes of the ith vulnerability producing the pth information security risk on the jth underlying asset, n a represents the number of the first evaluators;
[0193] The second calculation formula is as follows:
[0194]
[0195] In the formula, ef(i)(j)(p) represents the impact of the pth information security risk on the jth underlying asset in the case that the ith vulnerability produces the pth information security risk on the jth underlying asset, ef(i)(j)(p)(a) represents the impact value of the information security risk given by the ath assessor in the case that the ith vulnerability produces the pth information security risk on the jth underlying asset, and L represents the number of the second assessors.
[0196] The impact value of the risk can be taken from the following table.
[0197] Table 2 Risk Impact Value Table
[0198] Risk Impact Value Meaning 5 Risk has a major impact on the asset 4 Risk has a large impact on the asset 3 Risk has a general impact on the asset 2 Risk has a small impact on the asset 1 Risk has a weak impact on the asset 0 Risk has no impact on the asset
[0199] In some embodiments, a third calculation formula can be further used to calculate the quantified value of the harm of each information security risk produced by each vulnerability on each underlying asset.
[0200] The third calculation formula is as follows:
[0201] rc(i)(j)(p) = ef(i)(j)(p) x pr(i)(j)(p)
[0202] In the formula, rc(i)(j)(p) represents the quantified value of the harm of the pth information security risk produced by the ith vulnerability on the jth underlying asset, ef(i)(j)(p) represents the impact of the pth information security risk on the jth underlying asset in the case that the ith vulnerability produces the pth information security risk on the jth underlying asset, and pr(i)(j)(p) represents the probability value of the pth information security risk produced by the ith vulnerability on the jth underlying asset.
[0203] Based on the above calculation formula, the quantified value of the harm of each information security risk is calculated by changing p, j, and i respectively.
[0204] The above merging of at least two asset categories and the underlying assets corresponding to the two asset categories, and the generation of the weighted super matrix of the merged underlying assets using the network analysis method can include:
[0205] merge the organization management assets and the technology management assets, and merge underlying assets under the merged organization management assets and the technology management assets; take each underlying asset in the technology stack assets, the merged organization management assets and the technology management assets as a criterion respectively to form a judgment matrix and calculate a corresponding weight vector, obtain an initial super matrix, split and restore column vectors corresponding to the merged part of the initial super matrix into column vectors of the corresponding part before merging and normalize to obtain a final super matrix; take the technology stack assets, the organization management assets and the technology management assets as criteria respectively to form a judgment matrix and calculate a corresponding weight vector, obtain a weighted matrix; and multiply each element in the weighted matrix with a block in the super matrix representing the dominance relationship between underlying assets under each type of assets to form a weighted super matrix.
[0206] For each underlying asset in the technology stack assets, a judgment matrix of underlying assets dominated by each underlying asset is formed respectively based on each underlying asset as a criterion, a corresponding weight vector is calculated based on the judgment matrix, and the weight vector is taken as a column vector of the first m rows of the super matrix, m representing the number of underlying assets in the technology stack assets;
[0207] For underlying assets under the merged organization management assets and the technology management assets, a judgment matrix of underlying assets dominated by each underlying asset is formed respectively based on each underlying asset as a criterion, a corresponding weight vector is calculated based on the judgment matrix, and the weight vector is split and restored into two column vectors according to the division boundary of the underlying assets corresponding to the organization management assets and the technology management assets, the two column vectors correspond to the two parts before merging respectively, and the two column vectors are normalized respectively to be taken as column vectors of the m+1th row to the m+nth row and the m+n+1th row to the m+n+qth row of the super matrix, n representing the number of underlying assets in the organization management assets, and q representing the number of underlying assets in the technology management assets.
[0208] Take T, O and M as criteria respectively to form judgment matrices, that is, decompose (T, O, M) one by one to form corresponding judgment matrices: decompose (T, O, M) into {<T, {T, O, M}>, <O, {O, T, M}>, <M, {M, T, O}>}, form three 3x3 judgment matrices respectively according to the method of 1-9 scale of judgment matrix elements in the analytic hierarchy process introduced above, and calculate three 3x1 weight vectors respectively as column vectors of the 3x3 weighted matrix WM.
[0209] The super matrix HMA is divided into nine blocks corresponding to <T, T>, <T, O>, <T, M>, <O, T>, <O, O>, <O, M>, <M, T>, <M, O>, <M, M> respectively. Multiply each element of the weighted matrix WM obtained above with a block of the super matrix HMA to form a weighted super matrix WHMA.
[0210] Further, the weight of each underlying asset is solved based on the weighted hypermatrix, including:
[0211] The iterative calculation of the WHMA is as follows: N = WHMA N-1 × WHMA
[0212] The termination condition of the iterative calculation is as follows:
[0213]
[0214] wherein WHMA represents the weighted hypermatrix, i represents the row index of the WHMA N , j represents the column index of the WHMA N , WHMA N ij represents the element of the i-th row and the j-th column of the WHMA N , max represents the maximum value of a vector, min represents the minimum value of a vector, and cov represents a threshold value.
[0215] The median of each row of the WHMA N is taken to form a row median column vector RMC of the WHMA N , each element in the row median column vector RMC is the weight of the corresponding underlying asset, the row median column vector RMC is summed and normalized, and the normalized row median column vector is denoted as MC. The first m elements in the row median column vector MC represent the weights of the corresponding underlying assets in the technology stack assets in turn, the m+1th element to the m+nth element represent the weights of the corresponding underlying assets in the organization management assets in turn, and the m+n+1th element to the m+n+qth element represent the weights of the corresponding underlying assets in the technology management assets in turn.
[0216] The above iterative calculation is performed until the difference between each column vector in the WHMA N becomes narrow, and ideally each column vector is consistent, so that the corresponding elements of the column vector are the weights of the respective underlying assets, and the solving is completed. The threshold value cov is set to constrain the column vectors of the WHMA N to approximately converge to be consistent.
[0217] It should be understood that the formation of the above judgment matrix needs to be completed by multiple experts (evaluators) in collaboration and through consistency verification.
[0218] In some specific embodiments, the overall information security risk value of the business informationization asset system is calculated based on the hazard quantification value and the weight, and the following fourth calculation formula is adopted:
[0219]
[0220] wherein Rw represents the overall information security risk value of the business information asset system, taking a value in the interval [0, 1], and the greater the overall information security risk value, the greater the risk; MC(j) represents the weight of the jth bottom layer asset; rc(i)(j)(p) represents the harm quantization value of the pth information security risk generated by the ith vulnerability on the jth bottom layer asset; and rkn(i)(j) represents the quantity of information security risks generated by the ith vulnerability on the jth bottom layer asset.
[0221] In some embodiments, the risk coefficient of each information security risk of the business information asset system, the risk coefficient of each vulnerability, and the risk value of each bottom layer asset can also be calculated to further realize information security risk analysis and evaluation.
[0222] Specifically, the fifth calculation formula can be used to calculate the risk coefficient of each information security risk of the business information asset system based on the harm quantization value and the weight.
[0223] The fifth calculation formula is as follows:
[0224]
[0225] wherein Rc(p) represents the risk coefficient of the pth information security risk, taking a value in the interval [0, 1], and the greater the risk coefficient, the greater the destructive power of the information security risk on the business information asset system; MC(j) represents the weight of the jth bottom layer asset; and rc(i)(j)(p) represents the harm quantization value of the pth information security risk generated by the ith vulnerability on the jth bottom layer asset.
[0226] The sixth calculation formula can be used to calculate the risk coefficient of each vulnerability of the business information asset system based on the harm quantization value and the weight.
[0227] The sixth calculation formula is as follows:
[0228]
[0229] wherein Rv(i) represents the risk coefficient of the ith vulnerability, taking a value in the interval [0, 1], and the greater the risk coefficient, the greater the destructive power of the vulnerability on the business information asset system; MC(j) represents the weight of the jth bottom layer asset; rc(i)(j)(p) represents the harm quantization value of the pth information security risk generated by the ith vulnerability on the jth bottom layer asset; and rkn(i)(j) represents the quantity of information security risks generated by the ith vulnerability on the jth bottom layer asset.
[0230] The seventh calculation formula can be used to calculate the risk value of each bottom layer asset of the business information asset system based on the harm quantization value and the weight.
[0231] The seventh calculation formula is as follows:
[0232]
[0233] wherein Ra(j) represents a risk value of the jth underlying asset, which is in the interval [0, 1], and the greater the risk value, the greater the risk harm suffered by the asset; MC(j) represents a weight of the jth underlying asset; rc(i)(j)(p) represents a harm quantification value of the pth information security risk generated by the ith vulnerability on the jth underlying asset; and rkn(i)(j) represents a quantity of information security risks generated by the ith vulnerability on the jth underlying asset.
[0234] Further, the apparatus of the embodiment can further include:
[0235] The report generation module is configured to sort the above risk coefficients and risk values respectively to obtain an information security risk quantification report based on risk harm and asset structure decomposition, and to realize data processing of information security risk information based on risk harm and asset structure decomposition, so as to further analyze the assets, vulnerabilities, and risks. The information security risk information includes at least one of a whole information security risk value of the business information asset system, a risk coefficient of each information security risk, a risk coefficient of each vulnerability, and a risk value of each underlying asset.
[0236] The apparatus of the embodiment has all the beneficial effects of the method of the first embodiment, which will not be repeated here.
[0237] Example Three
[0238] The embodiment provides a computer device, which includes a memory, a processor, and a computer program stored in the memory. The processor executes the computer program to realize the steps of the method of the first embodiment.
[0239] Example Four
[0240] The embodiment provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to realize the steps of the method of the first embodiment.
[0241] Example Five
[0242] The embodiment provides a computer program product, which includes a computer program / instruction. The computer program is executed by a processor to realize the steps of the method of the first embodiment.
[0243] The processor can include, but is not limited to, one or more processors or microprocessors, etc. Each processor can be an application specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a controller, a microcontroller, a microprocessor, or other electronic elements for executing the methods in the above-described embodiments.
[0244] The computer-readable storage medium can be implemented by any type of volatile or nonvolatile storage devices or a combination thereof, and can include, but is not limited to, for example, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (such as a hard disk, a floppy disk, a solid state disk, a removable disk, a CD-ROM, a DVD-ROM, a Blu-ray disk, etc.).
[0245] The computer-readable storage medium can also store at least one computer executable program / instruction, such as computer readable instructions. The computer-readable storage medium includes, but is not limited to, for example, volatile memory and / or non-volatile memory. The volatile memory can include, for example, random access memory (RAM) and / or cache memory, etc. The computer-readable storage medium can include, for example, read-only memory (ROM), a hard disk, a flash memory, etc. For example, the non-transitory computer-readable storage medium can be connected to a computing device, such as a computer, and then, in the case where the computing device executes the computer readable instructions stored on the computer-readable storage medium, the various methods described above can be performed.
[0246] In addition, the computer device can also include, but is not limited to, a data bus, an input / output (I / O) bus, a display, and an input / output device (e.g., a keyboard, a mouse, a speaker, etc.), etc.
[0247] The processor can communicate with an external device via a wired or wireless network through the I / O bus.
[0248] In one embodiment, the at least one computer-executable instruction can also be compiled or composed into a software product / computer program product, wherein the one or more computer-executable instructions perform the steps of the functions and / or methods in the embodiments described in the present technology when executed by a processor.
[0249] Example Six
[0250] The present embodiment provides an application example of the foregoing method, as shown in Figure 5 .
[0251] The information security risk quantification method in the foregoing embodiment is implemented as a software system.
[0252] The following information is submitted and displayed at the front end of the software:
[0253] Experts decompose assets in the business informatization asset system according to the (T, M, O) mode, submit (T, M, O) and the comparative scale relationship of the underlying assets thereof;
[0254] The vulnerabilities faced by the informatization assets discovered by the evaluators and the risks added by the evaluators due to the vulnerabilities, wherein the risks are mainly proposed by the evaluators in combination with the protection measures of the vulnerabilities, the threats faced, the asset characteristics, and the like;
[0255] The pth risk is fixed, and the evaluators vote on the occurrence of the pth risk, wherein the vulnerability can produce different risks under the condition that the ith vulnerability and the jth underlying asset are fixed;
[0256] The risk impact value of the pth risk produced by the ith vulnerability on the jth underlying asset submitted by the ath evaluator; and
[0257] After the asset weight and all the risk quantification calculations are completed, i, j, and p are set.
[0258] The submitted information is obtained by the back end and is processed.
[0259] The back end performs the following information processing:
[0260] 1) Calculate the probability of the pth risk produced by the ith vulnerability on the jth underlying asset;
[0261] 2) Calculate the impact of the pth risk produced by the ith vulnerability on the jth underlying asset;
[0262] 3) Calculate the quantification value of the pth risk produced by the ith vulnerability on the jth underlying asset;
[0263] If not, the assessment personnel is fed back to continue adding risks, submitting votes and submitting risk impact values through the front end.
[0264] While the information processing steps of 1) to 3) are performed, 4) to 7) are also performed:
[0265] 4) generating a hypermatrix by using a hypermatrix generation method based on element logical boundary merging and splitting;
[0266] 5) generating a weighted matrix;
[0267] 6) generating a weighted hypermatrix;
[0268] 7) solving the underlying asset weight;
[0269] In the execution process of 4) to 7), the corresponding results are stored synchronously, and it is judged whether the weight calculation is completed. If not, the experts are fed back to continue submitting the comparative scale relationship through the front end.
[0270] If the harm quantification calculation and weight calculation of all risks corresponding to all vulnerabilities are completed, the overall information security risk value of business informatization is calculated, the risk value of the jth underlying asset is calculated according to the front-end input j, the risk coefficient of the ith vulnerability is calculated according to the front-end input i, and the risk coefficient of the pth risk is calculated according to the front-end input p.
[0271] It should be noted that the terms "first", "second", and the like in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0272] It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that described herein.
[0273] In the embodiments provided by the present disclosure, it should be understood that the disclosed apparatus and method can also be implemented in other manners. The embodiments described above are merely exemplary for describing the present disclosure. For example, the flowchart and block diagram in the accompanying drawings show the possible implementation architectures, functions and operation of the apparatus, method and computer program product according to the embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a segment or a portion of code which comprises one or more executable instructions for implementing the specified logic function. It should also be noted that in some alternative implementations, the functions shown in the blocks can occur in a different order than that shown in the figure. For example, two blocks shown in succession can in fact be executed substantially concurrently or in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by dedicated hardware-based systems which perform the specified functions or acts, or can be implemented by a combination of dedicated hardware-based systems and computer instructions.
[0274] It should be noted that, in the present disclosure, the terms "comprising", "containing" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but also includes other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, the element limited by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.
[0275] Although the embodiments disclosed by the present disclosure are as described above, the above description is only for the purpose of facilitating the understanding of the present disclosure, and is not intended to limit the present disclosure. Any person skilled in the art, without departing from the spirit and scope of the present disclosure, can make any modifications and changes in the implementation form and details, but the patent protection scope of the present disclosure shall be subject to the scope defined by the appended claims.
Claims
1. A risk hazard-based and asset structure-decomposed information security risk quantification method, characterized in that, The method comprises the following steps: calculating a quantitative value of harm of each vulnerability in each underlying asset of a business information asset system based on a probability value and an impact value of each information security risk caused by each vulnerability in each underlying asset, wherein the asset structure of the business information asset system comprises a plurality of asset categories and underlying assets under each asset category, and the asset categories comprise technical stack assets, organization management assets, and technical management assets; merging the organization management assets and the technical management assets, and merging the underlying assets under the organization management assets and the technical management assets; forming a judgment matrix and calculating a corresponding weight vector based on each underlying asset in the technical stack assets, the merged organization management assets, and the technical management assets as a criterion to obtain an initial super matrix, splitting and restoring the column vectors corresponding to the merged part of the initial super matrix into column vectors of the corresponding part before merging and normalizing to obtain a final super matrix; forming a judgment matrix and calculating a corresponding weight vector based on the technical stack assets, the organization management assets, and the technical management assets as a criterion to obtain a weighted matrix; multiplying each element in the weighted matrix with a block representing a domination relationship between underlying assets under each asset category in the super matrix to form a weighted super matrix, and solving the weight of each underlying asset based on the weighted super matrix; calculating an overall information security risk value of the business information asset system based on the quantitative value of harm and the weight. 2.The information security risk quantification method of claim 1, wherein, The method further comprises the following steps: calculating a probability value of each information security risk caused by each vulnerability in each underlying asset of a business information asset system using a first calculation formula; calculating an impact value of each information security risk caused by each vulnerability in each underlying asset of a business information asset system using a second calculation formula; the first calculation formula is as follows: In the formula, Indicates the first i The vulnerability in the first j The first underlying asset generates the first p The probability value of each information security risk is in the range [0,1]. Indicates the first i The vulnerability in the first j The first underlying asset will generate the first p The number of votes for each information security risk. Indicates the number of the first assessors; the second calculation formula is as follows: In the formula, Indicates the first i The vulnerability in the first j The first underlying asset generated p In the case of information security risks, the first p The information security risk to the first j The impact of the underlying assets Indicates the first i The vulnerability in the first j The first underlying asset generated p In the case of information security risks, the first a The impact value of information security risks given by the assessors This indicates the number of second-assessment personnel. 3.The information security risk quantification method of claim 1, wherein, calculating a quantitative value of harm of each vulnerability in each underlying asset of a business information asset system using a third calculation formula; the third calculation formula is as follows: In the formula, Indicates the first i The vulnerability in the first j The first underlying asset generated p The quantification value of the severity of information security risks. Indicates the first i The vulnerability in the first j The first underlying asset generated p In the case of information security risks, the first p The information security risk to the first j The impact of the underlying assets Indicates the first i The vulnerability in the first j The first underlying asset generates the first p The probability value of an information security risk. 4.The information security risk quantification method of claim 1, wherein, forming a judgment matrix and calculating a corresponding weight vector based on each underlying asset in the technical stack assets, the merged organization management assets, and the technical management assets as a criterion to obtain an initial super matrix, splitting and restoring the column vectors corresponding to the merged part of the initial super matrix into column vectors of the corresponding part before merging and normalizing to obtain a final super matrix, comprising the following steps: for each underlying asset in the technical stack assets, forming a judgment matrix of the underlying assets dominated by each underlying asset based on each underlying asset as a criterion, calculating a corresponding weight vector based on the judgment matrix, and taking the column vectors of the first m rows of the super matrix as the weight vector, wherein m represents the number of underlying assets in the technical stack assets; For the underlying assets under the merged organization management assets and technology management assets, a judgment matrix of the underlying assets dominated by each underlying asset is formed respectively with each underlying asset as a criterion, a corresponding weight vector is calculated based on the judgment matrix, the weight vector is split and restored into two column vectors according to the segmentation boundary of the underlying assets corresponding to the organization management assets and the technology management assets, the two column vectors correspond to the two parts before the merging respectively, and the two column vectors are normalized respectively as the column vectors of the m+1th row to the m+nth row and the column vectors of the m+n+1th row to the m+n+qth row of the super matrix, n represents the number of underlying assets in the organization management assets, and q represents the number of underlying assets in the technology management assets.
5. The information security risk quantification method of claim 1, wherein, The weight of each underlying asset is solved based on the weighted super matrix, including: Iterative calculation of WHMA N = WHMA N-1 x WHMA; The termination condition of the iterative calculation is as follows: Where WHMA represents the weighted hypermatrix, i WHMA N row index, j WHMA N column index, WHMA N ij WHMA N The i Line number j In the column elements, max represents the maximum value of the orientation quantity, and min represents the minimum value of the orientation quantity. cov This represents the threshold, and N represents the current iteration number; Take WHMA N The median of each row, forming WHMA N A row median column vector RMC, each element in the row median column vector RMC is the weight of the corresponding underlying asset, the row median column vector RMC is summed and normalized, and the normalized row median column vector is denoted as MC. The first m elements in the row median column vector MC represent the weights of the corresponding underlying assets in the technology stack assets in turn, the m+1th element to the m+nth element represent the weights of the corresponding underlying assets in the organization management assets in turn, and the m+n+1th element to the m+n+qth element represent the weights of the corresponding underlying assets in the technology management assets in turn.
6. The information security risk quantification method of claim 1, wherein, The overall information security risk value of the business information asset system is calculated based on the harm quantization value and the weight, using the following fourth calculation formula: in, This represents the overall information security risk value of the business information asset system, taking a value in the range [0,1]. The higher the overall information security risk value, the greater the risk. Indicates the first j The weight of each underlying asset; Indicates the first i The vulnerability in the first j The first underlying asset generated p The quantification value of the severity of information security risks. Indicates the first i The vulnerability in the first j The number of information security risks arising from underlying assets.
7. The information security risk quantification method of claim 1, wherein, Further comprising: A risk coefficient of each information security risk of the business information asset system is calculated based on the harm quantization value and the weight, using a fifth calculation formula; The fifth calculation formula is as follows: in, Indicates the first p The risk coefficient of each information security risk takes a value in the range [0,1]. The larger the risk coefficient, the greater the destructive effect of the information security risk on the business information asset system. Indicates the first j The weight of each underlying asset; Indicates the first i The vulnerability in the first j The first underlying asset generated p The quantification of the severity of information security risks. 8.The information security risk quantification method of claim 1, wherein, Further comprising: A risk coefficient of each vulnerability of the business information asset system is calculated based on the harm quantization value and the weight, using a sixth calculation formula; The sixth calculation formula is as follows: wherein, represents the risk coefficient of the i th vulnerability, which is in the interval [0, 1], and the greater the risk coefficient, the greater the destructive power of the vulnerability to the business information asset system; represents the weight of the j th underlying asset; represents the i th vulnerability on the j th underlying asset produces the p th quantitative value of the harm of the information security risk; represents the i th vulnerability on the j th underlying asset produces the number of information security risks. 9.The information security risk quantification method of claim 1, wherein, Further comprising: A risk value of each underlying asset of the business information asset system is calculated based on the harm quantization value and the weight, using a seventh calculation formula; The seventh calculation formula is as follows: in, Indicates the first j The risk value of each underlying asset takes a value in the range [0,1]. The larger the risk value, the greater the risk and harm the asset is subject to. Indicates the first j The weight of each underlying asset; Indicates the first i The vulnerability in the first j The first underlying asset generated p The quantification of the severity of each information security risk; Indicates the first i The vulnerability in the first j The number of information security risks arising from underlying assets.
10. An information security risk quantification device based on risk criticality and asset structure decomposition, characterized by, Including: A harm quantization module is configured to calculate a harm quantization value of each vulnerability in each underlying asset generating each information security risk based on a probability value and an impact value of each vulnerability in each underlying asset generating each information security risk faced by a business information asset system, wherein an asset structure in the business information asset system includes a plurality of asset categories and underlying assets under each asset category, and the asset categories include technology stack assets, organization management assets, and technology management assets; A weight solving module is configured to merge the organization management assets and the technology management assets, and simultaneously merge the underlying assets under the organization management assets and the technology management assets; form a judgment matrix and calculate a corresponding weight vector with each underlying asset in the technology stack assets, the merged organization management assets, and the technology management assets as a criterion to obtain an initial super matrix, split and restore the column vector corresponding to the merged part of the initial super matrix into the column vector of the corresponding part before the merging and perform normalization to obtain a final super matrix; form a judgment matrix and calculate a corresponding weight vector with the technology stack assets, the organization management assets, and the technology management assets as a criterion to obtain a weighted matrix; each element in the weighted matrix is multiplied by a block representing the domination relationship between the underlying assets under each type of asset in the super matrix to form a weighted super matrix, and the weight of each underlying asset is solved based on the weighted super matrix; A risk calculation module is configured to calculate an overall information security risk value of a business information asset system based on the harm quantization value and the weight.
11. A computer device comprising a memory, a processor, and a computer program stored on the memory, wherein the computer program comprises instructions that, when executed by the processor, cause the processor to perform the method of any one of claims 1-10. The processor executes the computer program to implement the steps of the method of any one of claims 1 to 9.
12. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, which when executed by the processor, implements the steps of the method of any one of claims 1 to 9.
13. A computer program product comprising computer programs / instructions, characterized in that, The computer program, which when executed by the processor, implements the steps of the method of any one of claims 1 to 9.
Citation Information
Patent Citations
Risk identification method and device, electronic equipment and storage medium
CN117692169A
Method for identifying and evaluating rail transit operation and maintenance logistics supply chain risk
WO2022041267A1