A method, system, device and storage medium for information system risk assessment
By acquiring and analyzing basic and associated risk information of target network assets in information systems, and combining vulnerability, threat, protection, and location parameters, the impact between target network assets and associated network assets was assessed. This solved the problem of inaccurate risk assessment in existing technologies and achieved higher assessment accuracy.
Patent Information
- Application Number
- CN202411132528.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-19
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2044-08-19
AI Technical Summary
Existing information system risk assessment methods cannot effectively unify the analysis and processing of various test results, resulting in incomplete assessment conclusions and low accuracy of assessment results.
By acquiring basic and associated risk information of the target network assets, and comprehensively considering the risks of the target network assets themselves and the degree of impact with associated network assets, the basic risk value is determined using vulnerability scoring tables, threat level tables, and protection level tables. The associated risk value is determined by access frequency and the risk status of associated network assets, and finally the system risk result is determined.
It provides a more objective and comprehensive assessment of the risks of target network assets, improving the accuracy of risk assessment in information systems.
Smart Images

Figure CN119109626B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of network security, and in particular to a method, system, device and storage medium for risk assessment of information systems. Background Technology
[0002] The fundamental and overarching role of networks and information systems is increasingly important, and economic and social development is becoming more and more reliant on them. However, due to the inherent defects, vulnerabilities, and threats faced by networks and information systems, their operation is objectively subject to potential risks.
[0003] Information system risk assessment is a means of understanding the state of cybersecurity. Through risk assessment, the security threats, vulnerabilities, and risks faced by the assets of the tested object can be evaluated.
[0004] Currently, risk assessment methods typically involve examining the vulnerabilities, asset value, and threats of each asset within an information system, then calculating the quantified risk value of each asset using a weighted summation method. These quantified risk values are then weighted and summed to obtain the quantified risk value of the entire information system. Alternatively, based on the "weakest link theory," the maximum risk value among all assets is taken as the quantified risk value of the information system. However, current risk assessment methods cannot effectively and uniformly analyze and process various detection results, leading to incomplete risk assessment conclusions and low accuracy. Summary of the Invention
[0005] To improve the accuracy of information system risk assessment, this application provides an information system risk assessment method, system, device, and storage medium.
[0006] In a first aspect of this application, an information system risk assessment method is provided. The method includes:
[0007] Obtain basic risk information and associated risk information of the target network asset. The basic risk information is used to reflect the risk status of the target network asset, and the associated risk information is used to reflect the impact of associated network assets on the target network asset. Associated network assets refer to network assets that are related to the target network asset.
[0008] Analyze basic risk information to determine basic risk values;
[0009] Analyze associated risk information and determine associated risk values;
[0010] Determine the asset risk outcome corresponding to the base risk value and the associated risk value;
[0011] Determine the system risk result corresponding to the asset risk result. The system risk result is used to reflect the risk status of the information system in which the target network asset is located. The information system includes multiple target network assets.
[0012] As can be seen from the above technical solutions, based on the obtained basic risk information and related risk information, the risks of each target network asset are determined by comprehensively considering both the risk of the target network asset itself and the degree of influence between the target network asset and related network assets. This provides a more objective and comprehensive assessment of the risks of the target network assets, thereby improving the accuracy of risk assessment for information systems composed of target network assets.
[0013] In one possible implementation, the basic risk information includes the vulnerability status, threat status, protection status, and location parameters of the target network asset, with the location parameters reflecting the impact of the target network asset's location on its security.
[0014] Analyze basic risk information to determine basic risk values, including:
[0015] Based on the vulnerability scoring table and the vulnerability details, the vulnerability score is determined. The vulnerability scoring table is used to reflect the degree of impact of different vulnerabilities on the target network assets.
[0016] Threat scores are determined based on the threat level table and the threat situation. The threat level table is used to reflect the degree of impact of different threats on target network assets.
[0017] Based on the protection level table and the protection status, the protection score is determined. The protection level table is used to reflect the protection effect of different protection devices on the target network assets.
[0018] The basic risk value is determined based on the vulnerability score, threat score, protection score, and location parameters.
[0019] In one possible implementation, the base risk value is determined as follows:
[0020]
[0021] Among them, M single The base risk score is represented by WP, the vulnerability score by AP, the threat score by SP, and the protection score by M. location Indicates positional parameters.
[0022] In one possible implementation, the associated risk information includes the access frequency of the associated network assets and the risk status of the associated network assets;
[0023] Analyze associated risk information and determine associated risk values, including:
[0024] Determine the access score corresponding to the access frequency. The access score is used to reflect the degree of connection between the associated network assets and the target network assets.
[0025] The associated risk value is determined based on the access score and the risk status of the associated network assets.
[0026] In one possible implementation, determining the access score corresponding to the access frequency includes:
[0027] Obtain the standard access frequency, which represents the maximum value of the stable access frequency between the target network asset and its associated network assets during operation;
[0028] When the access frequency is greater than the standard access frequency, the maximum access score will be used as the access score.
[0029] When the access frequency is less than or equal to the standard access frequency, the access score is determined based on the ratio of the access frequency to the standard access frequency.
[0030] In one possible implementation, the systematic risk outcome corresponding to the asset risk outcome is determined, including:
[0031] Obtain the range of risk outcomes for multiple assets;
[0032] When the range is within the range range, the average of the risk outcomes of multiple assets is taken as the systematic risk outcome;
[0033] When the range exceeds the range range, the systematic risk result is determined based on the maximum and minimum values in the asset risk result.
[0034] In one possible implementation, the systematic risk outcome corresponding to the asset risk outcome is determined, including:
[0035] The maximum or average of multiple asset risk outcomes is taken as the systematic risk outcome.
[0036] In a second aspect of this application, an information system risk assessment system is provided. The system includes:
[0037] The data acquisition module is used to acquire basic risk information and related risk information of the target network asset. The basic risk information reflects the risk status of the target network asset, and the related risk information reflects the impact of related network assets on the target network asset. Related network assets refer to network assets that are related to the target network asset.
[0038] The basic risk determination module is used to analyze basic risk information and determine the basic risk value;
[0039] The associated risk determination module is used to analyze associated risk information and determine associated risk values;
[0040] The asset risk determination module is used to determine the asset risk outcome corresponding to the basic risk value and the associated risk value;
[0041] The system risk determination module is used to determine the system risk result corresponding to the asset risk result. The system risk result is used to reflect the risk status of the information system in which the target network asset is located. The information system includes multiple target network assets.
[0042] In a third aspect of this application, an electronic device is provided. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described above.
[0043] In a fourth aspect of this application, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method according to the first aspect of this application.
[0044] In summary, this application includes at least one beneficial technical effect:
[0045] Based on the acquired basic and related risk information, the risks of each target network asset are determined by comprehensively considering both the risks inherent in the target network asset itself and the degree of influence between the target network asset and related network assets. This approach provides a more objective and comprehensive assessment of the risks of target network assets, thereby improving the accuracy of risk assessment for information systems composed of target network assets. Attached Figure Description
[0046] Figure 1 This is a flowchart illustrating the information system risk assessment method provided in this application.
[0047] Figure 2 This is a schematic diagram of the information system risk assessment system provided in this application.
[0048] Figure 3 This is a schematic diagram of the structure of the electronic device provided in this application.
[0049] In the diagram, 201 is the data acquisition module; 202 is the basic risk determination module; 203 is the associated risk determination module; 204 is the asset risk determination module; 205 is the system risk determination module; 301 is the CPU; 302 is the ROM; 303 is the RAM; 304 is the I / O interface; 305 is the input section; 306 is the output section; 307 is the storage section; 308 is the communication section; 309 is the driver; and 310 is the removable medium. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0051] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0052] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.
[0053] This application provides an information system risk assessment method, and the main process of the above method is described below.
[0054] like Figure 1 As shown:
[0055] Step S101: Obtain basic risk information and associated risk information of the target network asset.
[0056] Specifically, the aforementioned basic risk information reflects the risk status of the target network asset, and the aforementioned associated risk information reflects the impact of associated network assets on the target network asset. The associated network assets refer to network assets related to the target network asset. The aforementioned basic risk information includes the vulnerability status, threat status, protection status, and location parameters of the target network asset. The vulnerability status of the target network asset includes, but is not limited to, the number of vulnerabilities, the severity level of vulnerabilities, and the location of vulnerabilities. The threat status includes, but is not limited to, the number of dangerous accesses to the target network asset in a recent period, the severity level of dangerous access, and the frequency of dangerous access. The aforementioned "recent period" is set based on the actual usage of the target network asset or based on the user's experience, and is not limited thereto. The aforementioned protection status includes the monitoring, interception, and remediation of threats by the protection devices in the target network asset. The aforementioned location parameters reflect the impact of the location of the target network asset on its security. The aforementioned associated risk information includes the access frequency corresponding to the associated network asset and the risk status of the associated network asset. In the example provided in this application, the risk status of the associated network asset is represented by the basic risk value of the associated network asset. In other embodiments, other data can be used to reflect the risk status of the associated network asset, and is not limited thereto.
[0057] Step S102: Analyze the basic risk information and determine the basic risk value.
[0058] Specifically, based on the vulnerability scoring table and the aforementioned vulnerability information, vulnerability scores are determined. The vulnerability scoring table reflects the impact of different vulnerabilities on the aforementioned target network assets. Based on the threat level table and the aforementioned threat information, threat scores are determined. The threat level table reflects the impact of different threats on the aforementioned target network assets. Based on the protection level table and the aforementioned protection information, protection scores are determined. The protection level table reflects the effectiveness of different protection devices in protecting the aforementioned target network assets. Based on the aforementioned vulnerability scores, threat scores, protection scores, and location parameters, a basic risk value is determined.
[0059] The aforementioned basic risk value is determined in the following way:
[0060]
[0061] Among them, M single The above represents the basic risk value, WP represents the vulnerability score, AP represents the threat score, SP represents the protection score, and M represents the protection score. location This indicates the positional parameters mentioned above.
[0062] In a specific example, a target network asset has m vulnerabilities, each with a vulnerability score of w1, w2, w3, ..., w... m This yields a one-dimensional vector (w1, w2, w3, ..., w m Let A be a vector. Construct another one-dimensional vector (v1, v2, v3, ..., v...). m ), denoted as vector B, where v i It is w i The corresponding weights. From this, the vulnerability score (WP) of the target network asset can be obtained:
[0063]
[0064] Among them, w i v represents the vulnerability score of the i-th vulnerability. i This represents the weight corresponding to the i-th vulnerability. For example, the weight of w mentioned above... i and v iThe corresponding relationship, i.e., the vulnerability scoring table mentioned above, can be obtained from one or more of the following: Common Vulnerabilities & Exposures (CVE), China National Vulnerability Database (CNVD), and China National Vulnerability Database of Information Security (CNNVD). It can also be set and adjusted according to the actual situation; there are no restrictions on this. For example, v 外 >v 内 This indicates that vulnerabilities existing on the internal network have a lower weight than vulnerabilities existing on the public network, because vulnerabilities on the external network have a greater impact than those on the internal network. In the example provided in this application, w i ∈(0,10), v i ∈(0,1), WP∈(0,10). In other implementations, the range of vulnerability scores and weights can be adjusted according to the actual situation, and there is no limitation on this.
[0065] The threat profile of a target network asset primarily refers to the network attacks it has suffered over a period of time, which are mainly obtained through security monitoring equipment. For example, threats can be categorized into four levels: severe, high-risk, medium-risk, and low-risk, each assigned a different weight. i Then the threat score (AP) of the target network asset can be obtained:
[0066]
[0067] Among them, a i It is a threat weight, a max It is the highest weight of the threat.
[0068] In the example provided in this application, a i ∈(0,10), AP∈(0,10), the threat registration table includes the threat level and the corresponding weight. The above threat level table can be set by security business experts according to the actual threat situation, for example, a 严重 =10, a 高危 =8, a 中危 =6, a 低危 =4. In other implementations, a threat registration form can also be obtained by analyzing the historical impact range of different threats, and this is not limited.
[0069] Understandably, to reduce the risk of attacks or threats to network assets, users deploy security devices on these assets. The more types of security devices available, the more comprehensive the risks that can be monitored and remediated. Based on classifying security devices by function, the highest security coefficient for a given function is used as the overall security coefficient for that function, resulting in a security device score (SP).
[0070]
[0071] Among them, s ij This represents the weight of a certain type of security device under a specific function, s ij The larger the value, the more effective the safety protection equipment. It is the highest weight among similar devices. It is the cumulative product of the scores of devices of class m. In the example provided in this application, s ij ∈(0,1), SP∈(0,1), the protection level table is set by the security business experts according to the actual situation of the equipment, and there are no restrictions on it.
[0072] For example, consider security devices a, b, and c. Security device a can protect against both a1 and b1 threats, security device b can protect against both b1 and c1 threats, and security device c can protect against both c1 and d1 threats. Based on the function "protect against a1 threats," security devices a and b belong to the same category. Considering the actual protection capabilities of security devices a and b against a1 threats, we assign a weight of 0.6 to security device a and a weight of 0.4 to security device b. Therefore, the weight corresponding to the function "protect against a1 threats" is 0.6, because 0.6 > 0.4. Similarly, the weights corresponding to other functions can be determined, which will not be elaborated upon here.
[0073] Step S103: Analyze the associated risk information and determine the associated risk value.
[0074] Specifically, an access score corresponding to the aforementioned access frequency is determined, which reflects the degree of connection between the aforementioned related network assets and the aforementioned target network assets; based on the aforementioned access score and the risk status of the aforementioned related network assets, a connection risk value is determined.
[0075] It is understood that since most information systems consist of multiple network assets, these network assets are connected to other related network assets. If the related network assets all have significant risks, the risk value of the corresponding target network asset will also increase accordingly. The higher the risk of the related network assets and the closer the connection, the greater the associated risk value of the target network asset.
[0076] Furthermore, determining the access score corresponding to the aforementioned access frequency includes:
[0077] A standard access frequency is obtained, which represents the maximum value of the stable access frequency between the target network asset and the associated network asset during operation. When the access frequency is greater than the standard access frequency, the maximum access score is used as the access score. When the access frequency is less than or equal to the standard access frequency, the access score is determined based on the ratio of the access frequency to the standard access frequency. The standard access frequency is determined based on the historical access frequencies between the target network asset and the associated network asset. For example, historical access frequencies include 60 times / minute, 58 times / minute, 63 times / minute, 67 times / minute, 56 times / minute, and 51 times / minute. The maximum value of 67 times / minute is selected, therefore the standard access frequency is 67 times / minute.
[0078] In a specific example
[0079]
[0080] Where p represents the score of access frequency between the target network asset and related network assets, f represents the number of accesses between network assets per unit time, and M... i This indicates the risk status of associated network assets, i.e., the actual risk value of the associated network assets, where n represents the number of associated network assets. The number of accesses per unit of time is the standard access frequency f. max This can be configured and adjusted by security business experts according to actual circumstances, and there are no restrictions on this. In the example provided in this application, f max =50, p∈(0,1), M net ∈(0,10), the unit time is 1 minute. In other implementations, it can be adjusted according to the actual situation, and is not limited here.
[0081] Step S104: Determine the asset risk outcome corresponding to the base risk value and the associated risk value.
[0082] Specifically, in determining the basic risk value M single and associated risk value M net In this case, the asset risk outcome N∈(0,10), where N represents the asset risk outcome. The range of N values corresponds to the range of basic risk values and associated risk values, and can be adjusted according to the actual situation.
[0083] Step S105: Determine the systemic risk outcome corresponding to the asset risk outcome.
[0084] Specifically, the aforementioned system risk results are used to reflect the risk status of the information system in which the aforementioned target network assets reside, and the information system includes multiple of the aforementioned target network assets. Based on the asset risk results of each target network asset in the information system, the system risk result of the information system is determined.
[0085] In the first implementation, the maximum value of the multiple asset risk outcomes is taken as the system risk outcome. Where, N system N represents the system risk outcome of an information system. i This represents the asset risk outcome of the i-th target network asset in the information system.
[0086] In the second implementation, the average of the multiple asset risk outcomes is taken as the systemic risk outcome. Where, N system N represents the system risk outcome of an information system. i This represents the asset risk outcome of the i-th target network asset in the information system.
[0087] In the third implementation, the range of multiple asset risk results is obtained; when the range is within the range range, the average value of the multiple asset risk results is taken as the systematic risk result; when the range exceeds the range range, the systematic risk result is determined based on the maximum and minimum values of the asset risk results.
[0088] For example, an information system contains 10 target network assets with asset risk values of 1, 2, 3, 4, 5, 6, 7, 8, 9, and 9. The range is set to 0-4, and the current range is 9-1=8, which is outside this range. In this case, the system compares the location parameters of the target network asset corresponding to the maximum and minimum values. If the location parameter of the target network asset corresponding to the maximum value is greater than the location parameter of the target network asset corresponding to the minimum value, then... If the location parameter of the target network asset corresponding to the maximum value is less than or equal to the location parameter of the target network asset corresponding to the minimum value, the average of the asset risk results after removing the maximum and minimum values is used as the systematic risk result. For example, if the asset risk values corresponding to 10 target network assets are 6, 4, 5, 4, 5, 7, 7, 8, 7, and 6, then the current range is 8 - 4 = 4, which is within the range. Therefore... In the example provided in this application, N system ∈(0,10), in other embodiments, N system The range of values corresponds to the range of values for the basic risk value and the associated risk value, and can be adjusted according to the actual situation.
[0089] This application considers four aspects—vulnerability, threat, protection, and location—to determine the risks of the target network assets themselves. It then combines the degree of influence between the target network assets and related network assets to comprehensively determine the risks of each target network asset. This approach provides a more objective and comprehensive assessment of network asset risks, thereby improving the accuracy of risk assessment for information systems composed of target network assets.
[0090] This application provides an information system risk assessment system, referring to... Figure 2 The information system risk assessment system includes:
[0091] The data acquisition module 201 is used to acquire basic risk information and related risk information of the target network asset. The basic risk information reflects the risk status of the target network asset, and the related risk information reflects the impact of related network assets on the target network asset. Related network assets refer to network assets that are related to the target network asset.
[0092] The basic risk determination module 202 is used to analyze basic risk information and determine the basic risk value.
[0093] The associated risk determination module 203 is used to analyze associated risk information and determine the associated risk value.
[0094] The asset risk determination module 204 is used to determine the asset risk outcome corresponding to the basic risk value and the associated risk value.
[0095] The system risk determination module 205 is used to determine the system risk result corresponding to the asset risk result. The system risk result is used to reflect the risk status of the information system where the target network asset is located. The information system includes multiple target network assets.
[0096] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the described module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0097] This application discloses an electronic device. (Refer to...) Figure 3The electronic device includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 302 or programs loaded from storage section 307 into random access memory (RAM) 303. RAM 303 also stores various programs and data required for system operation. The CPU 301, ROM 302, and RAM 303 are interconnected via a bus. An input / output (I / O) interface 304 is also connected to the bus.
[0098] The following components are connected to I / O interface 304: an input section 305 including a keyboard, mouse, etc.; an output section 306 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 307 including a hard disk, etc.; and a communication section 308 including a network interface card such as a local area network (LAN) card, modem, etc. The communication section 308 performs communication processing via a network such as the Internet. A drive 309 is also connected to I / O interface 304 as needed. A removable medium 310, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 309 as needed so that computer programs read from it can be installed into storage section 307 as needed.
[0099] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 1 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a machine-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 308, and / or installed from removable medium 310. When the computer program is executed by central processing unit (CPU) 301, it performs the functions defined in the apparatus of this application.
[0100] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.
[0101] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing application concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions claimed in this application.
Claims
1. A method for risk assessment of an information system, characterized in that, include: Acquire basic risk information and associated risk information of the target network asset. The basic risk information is used to reflect the risk status of the target network asset, and the associated risk information is used to reflect the impact of associated network assets on the target network asset. The associated risk information includes the access frequency and risk status of the associated network asset. The associated network asset refers to a network asset that is related to the target network asset. Analyze the basic risk information to determine the basic risk value. The basic risk information includes the vulnerability status, threat status, protection status, and location parameters of the target network asset. The vulnerability status includes the number, severity level, and location of vulnerabilities. The threat status includes the number, severity level, and frequency of dangerous accesses to the target network asset. The protection status includes the monitoring, interception, and remediation status of the protection devices on the target network asset. The location parameters reflect the impact of the target network asset's location on its security, including: determining a vulnerability score based on a vulnerability scoring table and the vulnerability status (the vulnerability scoring table reflects the impact of different vulnerabilities on the target network asset); determining a threat score based on a threat level table and the threat status (the threat level table reflects the impact of different threats on the target network asset); determining a protection score based on a protection level table and the protection status (the protection level table reflects the protection effectiveness of different protection devices on the target network asset); and determining the basic risk value based on the vulnerability score, threat score, protection score, and location parameters, using the following method: Among them, M single The base risk value is represented by WP, the vulnerability score by WP, the threat score by AP, and the protection score by SP. location Indicates the position parameter; Analyze the associated risk information to determine the associated risk value; Determine the asset risk outcome corresponding to the base risk value and the associated risk value; Determine the system risk result corresponding to the asset risk result. The system risk result is used to reflect the risk status of the information system in which the target network asset is located. The information system includes multiple target network assets.
2. The information system risk assessment method according to claim 1, characterized in that, The associated risk information includes the access frequency of the associated network assets and the risk status of the associated network assets. The analysis of the associated risk information to determine the associated risk value includes: Determine an access score corresponding to the access frequency, the access score being used to reflect the degree of association between the associated network asset and the target network asset; Based on the access score and the risk status of the associated network assets, the associated risk value is determined.
3. The information system risk assessment method according to claim 2, characterized in that, The determination of the access score corresponding to the access frequency includes: Obtain the standard access frequency, which represents the maximum value of the stable operating access frequency between the target network asset and the associated network asset; When the access frequency is greater than the standard access frequency, the maximum value of the access score is taken as the access score; When the access frequency is less than or equal to the standard access frequency, the access score is determined based on the ratio of the access frequency to the standard access frequency.
4. The information system risk assessment method according to claim 1, characterized in that, The determination of the systemic risk outcome corresponding to the asset risk outcome includes: Obtain the range from multiple asset risk outcomes; When the range is within the range range, the average of the multiple asset risk results is taken as the systematic risk result; When the range exceeds the range range, the system risk result is determined based on the maximum and minimum values in the asset risk results.
5. The information system risk assessment method according to claim 1, characterized in that, The determination of the systemic risk outcome corresponding to the asset risk outcome includes: The maximum or average of the multiple asset risk outcomes is taken as the system risk outcome.
6. An information system risk assessment system, characterized in that, include: The data acquisition module is used to acquire basic risk information and associated risk information of the target network asset. The basic risk information is used to reflect the risk status of the target network asset, and the associated risk information is used to reflect the impact of associated network assets on the target network asset. The associated risk information includes the access frequency and risk status of the associated network asset. The associated network asset refers to a network asset that is related to the target network asset. The basic risk determination module is used to analyze the basic risk information and determine the basic risk value. The basic risk information includes the vulnerability status, threat status, protection status, and location parameters of the target network asset. The vulnerability status includes the number, severity level, and location of vulnerabilities. The threat status includes the number, severity level, and frequency of dangerous accesses to the target network asset. The protection status includes the monitoring, interception, and remediation status of the protection devices on the target network asset regarding threats. The location parameters reflect the impact of the target network asset's location on its security, including: determining a vulnerability score based on a vulnerability scoring table and the vulnerability status (the vulnerability scoring table reflects the impact of different vulnerabilities on the target network asset); determining a threat score based on a threat level table and the threat status (the threat level table reflects the impact of different threats on the target network asset); determining a protection score based on a protection level table and the protection status (the protection level table reflects the protection effectiveness of different protection devices on the target network asset); and determining the basic risk value based on the vulnerability score, threat score, protection score, and location parameters, using the following method: Among them, M single The base risk value is represented by WP, the vulnerability score by WP, the threat score by AP, and the protection score by SP. location Indicates the position parameter; The associated risk determination module is used to analyze the associated risk information and determine the associated risk value; The asset risk determination module is used to determine the asset risk outcome corresponding to the basic risk value and the associated risk value; The system risk determination module is used to determine the system risk result corresponding to the asset risk result. The system risk result is used to reflect the risk status of the information system in which the target network asset is located. The information system includes multiple target network assets.
7. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer program is stored that can be loaded by a processor and executed as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Information system risk assessment method and device and computer readable storage medium
CN114154873A
Calculating quantitative asset risk
US20130247205A1