A computer network engineering security control system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-20
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]针对上述方案,至少存在如下技术问题:1、上述方案缺乏了对企业内部和外部攻击面的详细划分和影响评估,会导致无法全面评估企业面临的实际安全威胁和风险,在工控网络安全健康指数评估中,仅依赖合规指数和风险指数进行综合评估,而缺乏考虑攻击面分析的具体细节,如互联网接入点的漏洞数量、合作伙伴连接风险指数、员工设备的安全合规率以及内部网络漏洞修复的平均时间,使得评估结果与实际情况存在偏差,无法准确反映企业网络的真实安全状态
Smart Images

Figure CN119276622B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network engineering security technology, and specifically to a computer network engineering security control system. Background Technology
[0002] As businesses expand and network boundaries become blurred, the attack surface also expands. External attack surfaces include internet access points and partner connections, while internal attack surfaces include employee devices and internal networks. Traditional network security defenses struggle to comprehensively cover these attack surfaces. Therefore, a security control system capable of comprehensively analyzing and evaluating the attack surface is needed to effectively identify and mitigate potential security risks.
[0003] Existing technologies, such as the invention patent application with publication number CN109495502A, disclose a method and apparatus for assessing the network security health index of industrial control systems. The method includes: acquiring compliance index parameters of host terminals, compliance index parameters of network boundaries and communication networks, vulnerability risk index parameters of assets, threat risk index parameters of assets, and business value score parameters of assets in a network system; calculating a network security compliance index based on the compliance index parameters of host terminals and the compliance index parameters of network boundaries and communication networks; calculating a network security risk index based on the vulnerability risk index parameters of assets, the threat risk index parameters of assets, and the business value score parameters of assets; calculating a network security health index based on the network security compliance index and the network security risk index; and determining the network security level based on a preset network security level range and the network security health index.
[0004] The above solutions have at least the following technical problems: 1. The above solutions lack detailed division and impact assessment of internal and external attack surfaces, which leads to the inability to comprehensively assess the actual security threats and risks faced by the enterprise. In the assessment of the industrial control network security health index, only compliance index and risk index are relied upon for comprehensive assessment, without considering specific details of attack surface analysis, such as the number of vulnerabilities in Internet access points, the risk index of partner connections, the security compliance rate of employee devices, and the average time for internal network vulnerability repair. This results in a deviation between the assessment results and the actual situation, and cannot accurately reflect the true security status of the enterprise network.
[0005] 2. The above solution lacks a detailed assessment of the complexity of the network architecture, which will lead to an inability to accurately assess the security risks of the network architecture itself. The complexity of the network architecture directly affects the security performance of the network architecture itself. Without a detailed scoring and comprehensive assessment of technical complexity, logical complexity and interconnection complexity, it is impossible to accurately determine whether the network architecture meets the engineering security requirements. This will lead to a lack of scientific basis for enterprises to optimize and upgrade, misjudgment of the security status of the network architecture, and thus an inability to effectively improve the overall security level.
[0006] 3. The above solution lacks detailed calculation and assessment of the risk index of each threat event, which will lead to the inability to accurately identify high-risk threats. The risk index of a threat event directly affects the priority of the enterprise's response measures and resource allocation. If there is a lack of detailed assessment of the probability of occurrence and the scope of impact of a threat event, it will be impossible to accurately determine which threat events pose the greatest risk to the enterprise, which will lead to a lack of focus in the enterprise's security investment and an inability to effectively prevent and respond to key threats. Summary of the Invention
[0007] The purpose of this invention is to provide a computer network engineering security control system that solves the problems existing in the background technology.
[0008] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: The present invention provides a computer network engineering security control system, including: an attack surface analysis module, used to divide the attack surface impact of a specified company into external attack surface impact and internal attack surface impact, and then calculate the comprehensive attack surface evaluation coefficient corresponding to the attack surface of the specified company.
[0009] The network architecture security assessment module is used to assess whether the network architecture pattern corresponding to the specified company's network architecture meets the network engineering security requirements.
[0010] The network architecture optimization module is used to evaluate the optimization process of the network architecture of a specified company when the network architecture mode corresponding to the specified company's network architecture does not meet the network engineering security requirements.
[0011] The early warning terminal is used to issue early warnings when the network architecture mode corresponding to the network architecture within a specified company does not meet the network engineering security requirements or when the network architecture mode used by the specified company needs to be optimized and upgraded.
[0012] The beneficial effects of this invention are as follows: 1. The computer network engineering security control system provided by this invention, in the process of external attack surface impact classification, uses vulnerability scanning tools to perform vulnerability scanning on network devices connected to the Internet for a set time period, which helps to discover and count the number of vulnerabilities in Internet access points in a timely manner, thereby effectively reducing potential security risks caused by failure to discover vulnerabilities in a timely manner. In the process of internal attack surface impact classification, using device management software to scan and detect employee devices helps to ensure that employee devices meet the security standards set by the company, improve the security compliance rate of employee devices, and reduce the security risks caused by substandard devices in the internal network.
[0013] 2. This invention, through the calculation of a comprehensive attack surface evaluation coefficient, combines the impact of external and internal attack surfaces, which is beneficial for comprehensively assessing the overall security status of a designated company. This provides a scientific basis for subsequent network architecture security assessment and optimization. During the network architecture pattern assessment process, by evaluating whether the network architecture pattern corresponding to the network architecture within the designated company meets the network engineering security requirements, it is beneficial for identifying security vulnerabilities in the existing network architecture, timely discovering and warning of potential security risks. By combining the comprehensive score of network architecture complexity with the comprehensive attack surface evaluation coefficient through the security risk assessment coefficient, it is beneficial for quantifying the security risks of the network architecture.
[0014] 3. In the network architecture optimization process, the embodiments of the present invention evaluate the optimization process of the network architecture of a designated company, which is conducive to formulating reasonable optimization and upgrade plans based on the current security risk assessment coefficient, thereby improving the security and stability of the network architecture. By assessing the threat event risk index, the probability of occurrence and the scope of impact of each threat event in the network architecture can be obtained, which is conducive to identifying high-risk threat events, formulating targeted optimization and upgrade measures, and reducing the overall risk level of the network architecture. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a schematic diagram of the system structure connection of the present invention. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] Please see Figure 1 As shown, the present invention provides a computer network engineering security control system, which includes: an attack surface analysis module, a network architecture security assessment module, a network architecture optimization module, an early warning terminal, and a database.
[0019] The attack surface analysis module is connected to the network architecture security assessment module and the database, the network architecture security assessment module is connected to the network architecture optimization module and the database, and the network architecture optimization module is connected to the early warning terminal and the database.
[0020] The attack surface analysis module is used to divide the attack surface impact of a specified company into external attack surface impact and internal attack surface impact, and then calculate the comprehensive attack surface evaluation coefficient of the specified company's attack surface.
[0021] In a specific embodiment, the attack surface impact corresponding to the designated company is divided into external attack surface impact and internal attack surface impact. The specific process is as follows: A1. External attack surface impact includes the number of Internet access point vulnerabilities and the partner connection risk index, while internal attack surface impact includes the employee device security compliance rate and the average time for internal network vulnerability remediation.
[0022] A2. Use vulnerability scanning tools to scan network devices connected to the Internet for a set time period, and then count the number of vulnerabilities scanned within the set time period. By evaluating the security management system, authentication method and data transmission process of the designated company's corresponding partners, the security assessment score, connection method security score and data transmission monitoring score of the designated company's corresponding partners are obtained. The security assessment score, connection method security score and data transmission monitoring score are denoted as sf, cn and sc, respectively. The connection risk index k of the designated company's corresponding external attack surface is obtained by calculating k = sf*ι1 + cn*ι2 + sc*ι3, where ι1, ι2 and ι3 represent the weight factors corresponding to the set security assessment score, connection method security score and data transmission monitoring score, respectively.
[0023] Device management software is used to scan and inspect the devices of all employees within the designated company to determine whether each device complies with the company's security standards. This yields the total number of employee devices and the number of devices that meet the company's security standards. The employee device security compliance rate is calculated by dividing the number of devices that meet the security standards by the total number of employee devices. Based on the number of vulnerabilities scanned by the designated company within a set time period, the total time spent fixing vulnerabilities within that time period is retrieved from the database. The average time spent fixing vulnerabilities is calculated by dividing the total time spent by the number of vulnerabilities.
[0024] It should be noted that vulnerability scanning tools include Nessus and OpenVAS, network devices include routers and firewalls, and device management software automatically detects the security status of each employee's devices, such as the installation status of antivirus software and the status of operating system updates. The specific process for obtaining the security assessment score, connection method security score, and data transmission monitoring score for the designated company's corresponding partner is as follows: For example, if a partner organizes a security training seminar once a month, covering network attack types and prevention methods, and conducts a vulnerability scan once a week, developing and implementing a remediation plan within 48 hours of discovering a vulnerability, with a maximum score of 100 points, then based on the partner's corresponding employee access control, training management, and vulnerability management, security access control is set to 40 points, security training to 30 points, and vulnerability management to 30 points. The average of the scores for security access control, security training, and vulnerability management is the security assessment score. The process for obtaining the connection method security score and data transmission monitoring score is the same as that for obtaining the security assessment score, and will not be elaborated further here.
[0025] It should also be noted that the values of ι1, ι2, and ι3 are all greater than 0 and less than 1. For example, the importance of identity authentication methods and data transmission processes in preventing data leakage and protecting sensitive information is higher than that of the security management system. The security management system, on the other hand, affects the implementation and continuous improvement of the overall security strategy. Based on historical data and expert opinions, the weight factor for data transmission monitoring score is set to 0.4. This is because data leakage during data transmission can lead to the exposure of sensitive information, the leakage of trade secrets, and the infringement of customer privacy. The weight factor for identity authentication methods is set to 0.35, and the weight factor for the security management system is set to 0.25.
[0026] In a specific embodiment, the calculation of the comprehensive attack surface evaluation coefficient corresponding to the attack surface of the specified company is carried out as follows: The maximum number of internet access point vulnerabilities, the range of preset partner connection risk indices, and the shortest and longest repair times for internal network vulnerabilities of the specified company are retrieved from the database before the network architecture attack surface analysis is performed. The maximum value of the maximum number of internet access point vulnerabilities, the maximum value of the preset partner connection risk index range, and the shortest and longest repair times for internal network vulnerabilities are denoted as N. max k max T min and T max Through the calculation formula:
[0027] The comprehensive attack surface evaluation coefficient FS corresponding to the attack surface of the specified company is obtained, where N, yg, and T represent the number of Internet access point vulnerabilities, employee device security compliance rate, and average time to fix internal network vulnerabilities, respectively, and μ1, μ2, μ3, and μ4 represent the weight factors corresponding to the set number of Internet access point vulnerabilities, the weight factors corresponding to the partner connection risk index, the weight factors corresponding to the employee device security compliance rate, and the weight factors corresponding to the average time to fix internal network vulnerabilities, respectively.
[0028] It should be noted that the values of μ1, μ2, μ3, and μ4 are all greater than 0 and less than 1.
[0029] It is also necessary to clarify the contribution of external and internal attack surface impacts to network architecture security risks. Since Internet access point vulnerabilities are direct entry points for external attacks, a high weighting factor is assigned, such as 0.3. The partner connection risk index reflects the security status of external partners and is assigned a reasonable weight, such as 0.25. The employee device security compliance rate reflects the security awareness and operational standards of internal employees and is assigned an appropriate weight, such as 0.2. The average time to repair internal network vulnerabilities directly affects the efficiency of security incident repair and is assigned a weight of 0.25. This ensures that the weighting factors of external and internal attack surface impacts objectively reflect their influence on the overall attack surface assessment.
[0030] The network architecture security assessment module is used to assess whether the network architecture pattern corresponding to the specified company's network architecture meets the network engineering security requirements.
[0031] In a specific embodiment, the evaluation process for whether the network architecture pattern corresponding to the specified company's network architecture meets the network engineering security requirements is as follows: Based on the comprehensive attack surface evaluation coefficient corresponding to the specified company's attack surface and the comprehensive score of the network architecture complexity corresponding to the network architecture used by the specified company, the security risk evaluation coefficient corresponding to the network architecture used by the specified company is calculated. The security risk evaluation coefficient includes values of 0 and 1. When the security risk evaluation coefficient is 0, it indicates that the network architecture pattern corresponding to the specified company's network architecture does not meet the network engineering security requirements. When the security risk evaluation coefficient is 1, it indicates that the network architecture pattern corresponding to the specified company's network architecture meets the network engineering security requirements.
[0032] In a specific embodiment, the calculation of the security risk assessment coefficient corresponding to the network architecture of the specified company is carried out in the following specific assessment process: the network architecture complexity corresponding to the network architecture used by the specified company is obtained from the database, the network architecture complexity is divided into technical complexity, logical complexity and interconnection complexity, and according to the preset scoring criteria, the technical complexity score, logical complexity score and interconnection complexity score are obtained, and then the comprehensive score of the network architecture complexity corresponding to the network architecture used by the specified company is calculated.
[0033] Substitute the comprehensive network architecture complexity score and comprehensive attack surface evaluation coefficient into the security risk assessment expression: The security risk assessment coefficient α corresponding to the network architecture of the specified company is obtained, where FS and FD represent the comprehensive attack surface assessment coefficient and the comprehensive network architecture complexity score, respectively; λ1 and λ2 represent the weight factors corresponding to the set comprehensive attack surface assessment coefficient and the comprehensive network architecture complexity score, respectively; and P represents the security risk assessment coefficient range.
[0034] It should be noted that the values of λ1 and λ2 are both greater than 0 and less than 1. The setting process of λ1 and λ2 is the same as that of μ1, μ2, μ3 and μ4, and will not be described in detail here.
[0035] It should also be noted that the security risk assessment coefficient range P is obtained from the database. P serves as the basis for assessing whether the network architecture pattern corresponding to the specified company's network architecture meets the network engineering security requirements. When the value range of P is (20, 30),
[0036] When the value of (FS*λ1+FD*λ2) is 25, it indicates that the network architecture mode corresponding to the specified company's network architecture meets the network engineering security requirements.
[0037] It should also be noted that, for example, if a designated company's network architecture uses multiple advanced network technologies, including software-defined networking (SDN) and virtual private networks (VPNs), the level of technological advancement is scored based on industry standards and actual application. If the company's SDN technology is industry-leading and effectively improves network flexibility and manageability, a high score is given. If the designated company uses multiple different types of network equipment, including routers and switches from different brands, the management difficulty will increase accordingly, and the score will decrease. Assuming that, according to the preset scoring criteria, technological advancement accounts for 0.4, technological diversity accounts for 0.3, and management difficulty accounts for 0.3, and combining the scoring criteria and expert opinions, if the company scores 80 points for technological advancement, 70 points for technological diversity, and 60 points for management difficulty, then the technological complexity score = 80 × 0.4 + 70 × 0.3 + 60 × 0.3 = 71 points. The process for obtaining the logical complexity score and the interconnection complexity score is the same as that for the technological complexity score, and will not be elaborated further here.
[0038] In a specific embodiment, the calculation yields a comprehensive network architecture complexity score corresponding to the network architecture used by the specified company. The specific calculation process is as follows: substituting the technical complexity score, logical complexity score, and interconnection complexity score into the calculation formula. The network architecture complexity score (FD) corresponding to the network architecture used by the specified company is obtained, where a, b, and c represent the technical complexity score, logical complexity score, and interconnection complexity score, respectively. These are respectively represented as the set technical complexity scoring weight factor, logical complexity scoring weight factor, and interconnection complexity scoring weight factor.
[0039] It should be noted that, The values of are all greater than 0 and less than 1. The setting process is the same as that for μ1, μ2, μ3, and μ4, so it will not be described in detail here.
[0040] This invention, through the calculation of a comprehensive attack surface evaluation coefficient, combines the impact of external and internal attack surfaces to comprehensively assess the overall security status of a designated company. This provides a scientific basis for subsequent network architecture security assessment and optimization. During the network architecture pattern assessment process, by evaluating whether the network architecture pattern corresponding to the network architecture within the designated company meets network engineering security requirements, it is beneficial to identify security vulnerabilities in the existing network architecture, promptly discover and warn of potential security risks. By combining the comprehensive score of network architecture complexity with the comprehensive attack surface evaluation coefficient through the security risk assessment coefficient, it is beneficial to quantify the security risks of the network architecture.
[0041] The network architecture optimization module is used to evaluate the optimization process of the network architecture of a specified company when the network architecture mode corresponding to the specified company's network architecture does not meet the network engineering security requirements.
[0042] In a specific embodiment, the process of evaluating the optimization of the network architecture of a designated company is as follows: When the network architecture mode corresponding to the network architecture of the designated company does not meet the network engineering security requirements, the value corresponding to (FS*λ1+FD*λ2) in the security risk level evaluation expression is obtained. When (FS*λ1+FD*λ2) is greater than the upper boundary value corresponding to the security risk evaluation coefficient interval P, it indicates that the network architecture mode used by the designated company needs to be optimized and downgraded. When (FS*λ1+FD*λ2) is less than the lower boundary value corresponding to the security risk evaluation coefficient interval P, it indicates that the network architecture mode used by the designated company needs to be optimized and upgraded. When the network architecture mode used by the designated company needs to be optimized and upgraded, the risk index corresponding to each threat event in the network architecture is evaluated, and then an optimization and upgrade plan is formulated to achieve the purpose of network architecture optimization and upgrade.
[0043] It should be noted that when the network architecture used by a company needs to be optimized and downgraded, for example, after a security risk assessment, a company finds that it has too many VPN channels and that there are security risks. By optimizing and downgrading, some channels are closed, simplifying the network architecture and reducing potential security risks.
[0044] In a specific embodiment, the process of evaluating the risk index corresponding to each threat event in the network architecture is as follows: Obtain the probability of occurrence and the post-occurrence impact assessment value corresponding to each threat event in the network architecture used by the specified company, and calculate the risk index using the formula FP. i =R i *I i The risk index FP corresponding to each threat event in the network architecture is obtained. i Let i be the number corresponding to each threat event, i = 1, 2, ..., n, and n be the total number of threat events, where n is a positive integer. i I i These represent the probability of occurrence and the estimated impact range of the i-th threat event in the network architecture used by the specified company, respectively.
[0045] It should be noted that the attack surface refers to the sum of all entry points or pathways that can be exploited in a system, including public ports, potentially compromised software defects, and manipulated configuration items. A threat event, on the other hand, refers to a specific malicious act or event that exploits certain weaknesses in the attack surface to attack or cause damage. The attack surface is a potential attack channel, while a threat event is an actual attack or threat that occurs through the attack surface.
[0046] In a specific embodiment, the process of obtaining the probability of occurrence and the assessment value of the impact range of each threat event in the network architecture used by the specified company is as follows: obtain the probability of occurrence and the assessment value of the impact range of each historical threat event when the specified company uses the same network architecture from the database, and use the probability of occurrence and the assessment value of the impact range of each historical threat event as the probability of occurrence and the assessment value of the impact range of each historical threat event in the network architecture used by the specified company.
[0047] It should be noted that the impact assessment value is a comprehensive measure of the potential impact of a threat event on the company. The unit of the impact assessment value is not uniform and may include, but is not limited to, the number of users, the amount of economic loss, and the service interruption time. For example, the impact assessment value of a server outage caused by a virus attack is in "hours", indicating that the server outage lasts for 24 hours, while the impact assessment value of a data breach is in "number of users", indicating that the number of affected users is 500.
[0048] In one specific embodiment, the process of formulating the optimization and upgrade plan is as follows: In one specific embodiment, the risk index corresponding to each threat event in the network architecture is compared with each risk index interval stored in the database. Each risk index interval corresponds to a risk level, which includes high-risk security domains, medium-risk security domains, and low-risk security domains. If the risk index corresponding to a certain threat event belongs to a certain risk index interval, it indicates that the risk level of the security domain corresponding to the occurrence of the threat event is the risk level corresponding to the risk index interval. In this way, the risk level of the security domain corresponding to each threat event is analyzed, and the optimization and upgrade measures corresponding to each risk level are determined, thereby completing the division of the risk level corresponding to each security domain and realizing the optimization and upgrade of the network architecture.
[0049] It should be noted that the optimization and upgrade measures include, but are not limited to, strengthening basic security configurations in low-risk security domains, implementing medium-intensity security protections in medium-risk security domains, and adopting advanced security measures in high-risk security domains, such as adding access control lists, deploying intrusion detection systems, real-time monitoring, and automatic response systems.
[0050] In the network architecture optimization process, this invention evaluates the optimization process of a designated company's network architecture. This facilitates the development of reasonable optimization and upgrade plans based on the current security risk assessment coefficients, thereby improving the security and stability of the network architecture. By assessing the threat event risk index, the invention obtains the probability of occurrence and impact range of each threat event in the network architecture. This helps identify high-risk threat events, develop targeted optimization and upgrade measures, and reduce the overall risk level of the network architecture.
[0051] The early warning terminal is used to issue early warnings when the network architecture mode corresponding to the network architecture within a specified company does not meet the network engineering security requirements or when the network architecture mode used by the specified company needs to be optimized and upgraded.
[0052] The database stores the total time spent fixing vulnerabilities within a specified time period. It also stores the maximum number of internet access point vulnerabilities pre-set by the company before conducting attack surface analysis of the network architecture, the pre-set range of partner connection risk indices, the shortest and longest fix times for internal network vulnerabilities, the network architecture complexity corresponding to the network architecture used by the company, the probability of occurrence of each historical threat event and the impact range assessment value after each historical threat event when the company uses the same network architecture, and the risk index ranges.
[0053] This invention provides a computer network engineering security control system. In the process of external attack surface impact assessment, by using vulnerability scanning tools to perform vulnerability scans on network devices connected to the Internet for a set time period, it is beneficial to discover and count the number of vulnerabilities in Internet access points in a timely manner, thereby effectively reducing potential security risks caused by the failure to discover vulnerabilities in a timely manner. In the process of internal attack surface impact assessment, by using device management software to scan and detect employee devices, it is beneficial to ensure that employee devices meet the security standards set by the company, improve the security compliance rate of employee devices, and reduce the security risks caused by substandard devices in the internal network.
[0054] The above description is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined in this specification, they should all fall within the protection scope of the present invention.
Claims
1. A computer network engineering security control system, characterized in that, include: The attack surface analysis module is used to divide the attack surface impact of a specified company into external attack surface impact and internal attack surface impact, and then calculate the comprehensive attack surface evaluation coefficient of the specified company's attack surface. The process of dividing the attack surface impact of a designated company into external attack surface impact and internal attack surface impact is as follows: A1. External attack surface impacts include the number of vulnerabilities in Internet access points and the risk index of partner connections, while internal attack surface impacts include the employee device security compliance rate and the average time to fix internal network vulnerabilities. A2. Use vulnerability scanning tools to perform vulnerability scans on network devices connected to the Internet within a set time period, and then count the number of vulnerabilities scanned within the set time period. By evaluating the security management system, authentication method, and data transmission process of the designated company's corresponding partners, the security assessment score, connection method security score, and data transmission monitoring score of the designated company's corresponding partners are obtained. The security assessment score, connection method security score, and data transmission monitoring score are denoted as sf, cn, and sc, respectively. The connection risk index k of the designated company's corresponding external attack surface is obtained by calculating k = sf*ι1 + cn*ι2 + sc*ι3, where ι1, ι2, and ι3 represent the weight factors corresponding to the set security assessment score, connection method security score, and data transmission monitoring score, respectively. Device management software is used to scan and test the devices of all employees within the designated company to check whether each device meets the security standards set by the designated company. This yields the total number of devices and the number of devices that meet the security standards. The number of devices that meet the security standards is divided by the total number of devices to obtain the employee device security compliance rate. Based on the number of vulnerabilities scanned by the designated company within a set time period, the total time spent fixing the vulnerabilities within the set time period is obtained from the database. The total time spent is divided by the number of vulnerabilities to obtain the average time for fixing internal network vulnerabilities. The comprehensive attack surface evaluation coefficient for the specified company's attack surface is calculated. The specific calculation process is as follows: Retrieve from the database the maximum number of internet access point vulnerabilities, the preset range of partner connection risk index, and the minimum and maximum repair times for internal network vulnerabilities of the specified company before conducting network architecture attack surface analysis. Record the maximum number of internet access point vulnerabilities, the maximum value of the preset range of partner connection risk index, and the minimum and maximum repair times for internal network vulnerabilities as N. max k max T min and T max Through the calculation formula: The comprehensive attack surface evaluation coefficient FS corresponding to the attack surface of the specified company is obtained, where N, yg, and T represent the number of Internet access point vulnerabilities, employee device security compliance rate, and average time to fix internal network vulnerabilities, respectively, and μ1, μ2, μ3, and μ4 represent the weight factors corresponding to the set number of Internet access point vulnerabilities, the weight factors corresponding to the partner connection risk index, the weight factors corresponding to the employee device security compliance rate, and the weight factors corresponding to the average time to fix internal network vulnerabilities, respectively. The network architecture security assessment module is used to assess whether the network architecture pattern corresponding to the network architecture within a specified company meets the network engineering security requirements. The network architecture optimization module is used to evaluate the optimization process of the network architecture of a specified company when the network architecture mode corresponding to the specified company's network architecture does not meet the network engineering security requirements. The early warning terminal is used to issue early warnings when the network architecture mode corresponding to the network architecture within a specified company does not meet the network engineering security requirements or when the network architecture mode used by the specified company needs to be optimized and upgraded.
2. The computer network engineering security control system according to claim 1, characterized in that, The assessment process determines whether the network architecture pattern corresponding to the specified company's internal network architecture meets network engineering security requirements. The specific assessment process is as follows: Based on the comprehensive attack surface evaluation coefficient corresponding to the attack surface of the specified company and the comprehensive network architecture complexity score corresponding to the network architecture used by the specified company, the security risk evaluation coefficient corresponding to the network architecture used by the specified company is calculated. The security risk evaluation coefficient includes values of 0 and 1. When the security risk evaluation coefficient is 0, it means that the network architecture mode corresponding to the network architecture within the specified company does not meet the network engineering security requirements. When the security risk evaluation coefficient is 1, it means that the network architecture mode corresponding to the network architecture within the specified company meets the network engineering security requirements.
3. A computer network engineering security control system according to claim 2, characterized in that, The calculation of the security risk assessment coefficient corresponding to the specified company's network architecture is carried out through the following specific assessment process: The network architecture complexity corresponding to the network architecture used by the specified company is obtained from the database. The network architecture complexity is divided into technical complexity, logical complexity and interconnection complexity. Based on the preset scoring criteria, the technical complexity score, logical complexity score and interconnection complexity score are obtained. Finally, the comprehensive score of the network architecture complexity corresponding to the network architecture used by the specified company is calculated. Substitute the comprehensive network architecture complexity score and comprehensive attack surface evaluation coefficient into the security risk assessment expression: The security risk assessment coefficient α corresponding to the network architecture of the specified company is obtained, where FS and FD represent the comprehensive attack surface assessment coefficient and the comprehensive network architecture complexity score, respectively; λ1 and λ2 represent the weight factors corresponding to the set comprehensive attack surface assessment coefficient and the comprehensive network architecture complexity score, respectively; and P represents the security risk assessment coefficient range.
4. A computer network engineering security control system according to claim 3, characterized in that, The calculation yields a comprehensive score for the network architecture complexity of the network architecture used by the specified company. The specific calculation process is as follows: Substitute the technical complexity score, logical complexity score, and interconnect complexity score into the calculation formula. The network architecture complexity score (FD) corresponding to the network architecture used by the specified company is obtained, where a, b, and c represent the technical complexity score, logical complexity score, and interconnection complexity score, respectively. These are respectively represented as the set technical complexity scoring weight factor, logical complexity scoring weight factor, and interconnection complexity scoring weight factor.
5. A computer network engineering security control system according to claim 4, characterized in that, The evaluation process specifies the optimization process of the company's network architecture. The specific evaluation process is as follows: When the network architecture mode corresponding to the specified company's network architecture does not meet the network engineering security requirements, the value corresponding to (FS*λ1+FD*λ2) in the security risk level assessment expression is obtained. When (FS*λ1+FD*λ2) is greater than the upper limit boundary value corresponding to the security risk assessment coefficient interval P, it indicates that the network architecture mode used by the specified company needs to be optimized and downgraded. When (FS*λ1+FD*λ2) is less than the lower limit boundary value corresponding to the security risk assessment coefficient interval P, it indicates that the network architecture mode used by the specified company needs to be optimized and upgraded. When the network architecture mode used by the specified company needs to be optimized and upgraded, the risk index corresponding to each threat event in the network architecture is evaluated, and then an optimization and upgrade plan is formulated to achieve the purpose of network architecture optimization and upgrade.
6. A computer network engineering security control system according to claim 5, characterized in that, The specific process for evaluating the risk index corresponding to each threat event in the network architecture is as follows: Obtain the probability of occurrence and post-occurrence impact assessment value of each threat event in the network architecture used by the specified company, and calculate it using the formula FP. i =R i *I i The risk index FP corresponding to each threat event in the network architecture is obtained. i Let i be the number corresponding to each threat event, i = 1, 2, ..., n, and n be the total number of threat events, where n is a positive integer. i I i These represent the probability of occurrence and the estimated impact range of the i-th threat event in the network architecture used by the specified company, respectively.
7. A computer network engineering security control system according to claim 6, characterized in that, The specific process for obtaining the probability of occurrence and the assessment of the impact range of each threat event in the network architecture used by the specified company is as follows: Retrieve from the database the occurrence probability and impact range assessment value of each historical threat event when the specified company uses the same network architecture. Use the occurrence probability and impact range assessment value of each historical threat event as the occurrence probability and impact range assessment value of each threat event in the network architecture used by the specified company.
8. A computer network engineering security control system according to claim 7, characterized in that, The specific process for formulating the optimization and upgrade plan is as follows: The risk index corresponding to each threat event in the network architecture is compared with the risk index ranges stored in the database. Each risk index range corresponds to a risk level, including high-risk, medium-risk, and low-risk security domains. If the risk index corresponding to a certain threat event falls within a certain risk index range, it indicates that the risk level of the security domain at the time of the threat event is the same as the risk level corresponding to that risk index range. This analysis is used to determine the risk level of the security domain at the time of each threat event, as well as the optimization and upgrade measures corresponding to each risk level. This process completes the classification of the risk level corresponding to each security domain, thereby achieving the optimization and upgrade of the network architecture.
Citation Information
Patent Citations
Method and apparatus for evaluating security health index of industrial control network
CN109495502A
Intelligent networked automobile network security assessment method
CN118074970A