A network security supervision platform based on network security operation
Through the network security supervision platform, multi-level data of the network operation system is obtained and evaluated, and early warning response signals are generated, which solves the problem of insufficient in-depth analysis of exposure in the existing technology, and achieves more comprehensive risk assessment and more efficient security maintenance.
Patent Information
- Application Number
- CN202510006104.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-01-03
AI Technical Summary
In the prior art, insufficient in-depth analysis of the exposure of network operating systems leads to incomplete risk assessment and vulnerability to attacks. The security team has a high error rate when judging protection priorities, which reduces maintenance efficiency.
Provide a network security supervision platform, which obtains asset operation, business operation and offline management data through the network operation data acquisition module, uses the exposure depth evaluation module to evaluate the system's exposure depth at multiple levels, and generates an early warning response signal.
Comprehensively evaluate the depth of multi-level exposure of network systems, reduce attack risks, and improve the judgment accuracy and maintenance efficiency of security teams.
Smart Images

Figure CN119420573B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security monitoring platform based on network security operation. Background Art
[0002] In the digital age, the internet has become an integral part of human life. Industries across all walks of life rely on it for daily operations and communication. However, with the rapid development and widespread adoption of network technology, cybersecurity issues have become increasingly prominent, becoming a global concern. Therefore, strengthening cybersecurity regulation is particularly important and necessary.
[0003] Prior art, such as the invention patent application with announcement number CN114021154B, discloses a network security risk assessment system, which includes a server and a client. The server includes a service module, an asset assessment standard module, an asset identification module, an asset valuation and ranking module, a risk assessment module a, an assessment result display module, an existing security means analysis module, and a risk assessment module b. The asset valuation and ranking module is used to assign values to assets according to their importance and to sort them. The risk assessment module a is used to perform risk assessment on assets selected by the user. The existing security means analysis module is used to analyze and count the internal security means set on the existing network. The risk assessment module b is used to combine existing security means to derive the risk level of a specific asset. The client includes a login module and a display module. The invention can perform risk assessment on specific assets according to customer needs, greatly reducing the information risk management budget and having a wide range of applications.
[0004] Existing technology, such as the network security risk assessment system disclosed in patent application number CN113225358B, includes a server and client using a client-server architecture, as well as an agent installed on the target system. The server includes an assessment engine service module, a vulnerability library, historical assessment records, a fusion assessment module, and an identity authentication module. The client includes a login module, a scan configuration module, a feedback processing module, and an assessment result library. The agent on the target system includes an information collection module, a machine learning module, a machine learning update module, an anomaly detection module, and an asset scanning module. This invention provides a more comprehensive and objective assessment of network security risks.
[0005] Combining the above solutions, it can be found that there is rarely any analysis of the depth of exposure of the network operation system in the existing technology. The depth of exposure of the designated operation system at the asset operation level, business operation level and offline management level is highly correlated with the vulnerability of the designated operation system to attacks. The neglect of this level in the existing technology leads to incomplete risk assessment. The designated operation system is vulnerable to network attacks from the asset operation level, business operation level or offline management level, which reduces the network security of the designated operation system, thereby increasing the error rate of the subsequent security team in judging which levels need priority protection, reducing the maintenance efficiency of the designated operation system, and increasing the network risk of the designated operation system to a certain extent. Summary of the Invention
[0006] The purpose of the present invention is to provide a network security monitoring platform based on network security operation, which solves the problems existing in the background technology.
[0007] In order to solve the above technical problems, the present invention adopts the following technical solution: The present invention provides a network security supervision platform based on network security operation, including: a network operation data acquisition module, used to obtain network operation data from a designated operation system, wherein the network operation data includes asset operation data, business operation data, and obtains offline management data.
[0008] The exposure depth assessment module is used to assess the exposure depth of a specified operating system at the asset operation level, business operation level, and offline management level.
[0009] The exposed surface processing module is used to generate early warning response signals for the specified operating system.
[0010] The beneficial effect of the present invention is that the present invention obtains relevant data of the specified operating system in the network operation data acquisition module, laying a data foundation for the subsequent evaluation of the exposure depth of the specified operating system at the asset operation level, business operation level and offline management level.
[0011] In the exposure depth assessment module, the present invention evaluates the exposure depth of the specified operating system at the asset operation level, business operation level and offline management level through the asset operation data, business operation data and offline management data of the specified operating system, thereby making up for the shortcomings of the existing technology, preventing the specified operating system from being attacked from multiple levels, and providing a more comprehensive risk assessment, thereby improving the network security of the specified operating system.
[0012] The present invention generates an early warning response signal for a designated operating system in an exposed surface processing module, providing support for subsequent security teams to determine which layers require priority protection, thereby avoiding subsequent security teams from making incorrect judgments about which layers require priority protection, improving the maintenance efficiency of designated operating systems, and reducing network risks of designated operating systems to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0014] Figure 1 This is a schematic diagram of the system structure connection of the present invention. DETAILED DESCRIPTION
[0015] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0016] Reference Figure 1 As shown, the present invention provides a network security supervision platform based on network security operation, including: a network operation data acquisition module, an exposure surface depth assessment module, an exposure surface processing module and a web data warehouse.
[0017] It should be noted that the network operation data acquisition module is connected to the exposure surface depth assessment module, the exposure surface depth assessment module is connected to the exposure surface processing module, and the web data warehouse is connected to the exposure surface depth assessment module and the exposure surface processing module respectively.
[0018] The network operation data acquisition module is used to acquire network operation data from a designated operation system, wherein the network operation data includes asset operation data, business operation data, and offline management data.
[0019] The present invention obtains relevant data of a specified operating system in a network operation data acquisition module, laying a data foundation for subsequent evaluation of the exposure depth of the specified operating system at the asset operation level, business operation level and offline management level.
[0020] In a specific embodiment of the present invention, the asset operation data includes characteristic parameters of each network asset, characteristic parameters of each data asset, and characteristic parameters of each physical asset.
[0021] The characteristic parameters of each network asset include the number of each external network device and the number of vulnerabilities of each internal device.
[0022] It should be noted that the external network devices include but are not limited to servers, websites and cloud services, and the internal devices include but are not limited to computers, printers and network storage devices.
[0023] The characteristic parameters of each data asset include the convenient access value and sharing degree of each key data.
[0024] It should be noted that the key data include but are not limited to customer information and financial data.
[0025] The characteristic parameters of each physical asset include a location security value of the office location, a security value of the access control system, a security value of the monitoring system, and a security value of the anti-theft alarm system.
[0026] The business operation data includes the network status security value and logistics protection security value of each supplier.
[0027] The offline management data includes authority allocation feature values, safety training feature values, and competition form feature values.
[0028] In a specific embodiment of the present invention, the convenient access value and sharing degree of each key data are specifically obtained by: obtaining each storage location of each key data from the specified operating system, and obtaining the number of sharing channels corresponding to each storage location from the specified operating system, screening the number of sharing channels of each storage location of each key data of the specified operating system, screening to obtain each high-risk storage location and each low-risk storage location of each key data of the specified operating system, and summarizing to obtain the number of high-risk storage locations of each key data of the specified operating system.
[0029] It should be noted that the screening obtains the high-risk storage locations and low-risk storage locations of the key data of the specified operating system, and compares the number of shared channels of each storage location of the key data of the specified operating system with the preset shared channel convergence number. If the number of shared channels of a storage location is greater than the shared channel convergence number, the storage location is recorded as a high-risk storage location; otherwise, it is recorded as a low-risk storage location, and the high-risk storage locations and low-risk storage locations of the key data of the specified operating system are obtained by screening.
[0030] Summarize the total number of storage locations M for each key data of the specified operating system _i , specify the total number of storage locations for each key data of the running system and the number of high-risk storage locations MI _i Import into convenient access value evaluation model Output the convenient access value α of each key data _i , where M _ ' iis the number of suitable storage locations for the i-th key data stored in the web data warehouse, i is the number of each key data, i = 1, 2, ..., n.
[0031] Obtain the protection characteristic value χ of each transmission of each key data from the specified operating system _im , import it into the sharing evaluation model In the output, the sharing degree of each key data is output, m is the number of each transmission, m = 1, 2, ..., l, χ′ _i It is represented as the required protection characteristic value of the i-th key data stored in the web data warehouse.
[0032] It should be noted that the protection characteristic value is a value of 0-1, which reflects the effectiveness of the protection measures taken by the specified operating system when transmitting key data. For example, if the protection measures taken are stronger, the protection characteristic value will be larger, and if the protection measures taken are poorer, the protection characteristic value will be smaller. The protection characteristic value taken is specifically set by professionals.
[0033] It should also be noted that the required protection characteristic value of each key data is specifically determined by the staff of the designated operating system based on the key data. For example, the required protection characteristic value of financial data is greater than the required protection characteristic value of customer information.
[0034] In a specific embodiment of the present invention, the location security value of the office location is obtained by obtaining the characteristic parameter δ of each meteorological data of the office location of the designated operating system from the meteorological management center. _p , and import it into the meteorological safety value assessment model Output the weather safety value X of the office location _1 , p is the number of each meteorological data, p=1,2,...,q,δ _ ' p is the suitable characteristic parameter interval of the pth meteorological data of the office location stored in the web data warehouse.
[0035] The threat value of the office location of the designated operating system is obtained from the public management center, and combined with the meteorological safety value of the office location of the designated operating system, the location safety value of the office location of the designated operating system is obtained through analysis.
[0036] It should be noted that the threat value of the office location is a value of 0-1, which reflects the public security effect of the office location of the designated operating system. For example, if the number of public security cases at the office location of the designated operating system is small, the smaller the threat value of the office location is; if the number of public security cases at the office location of the designated operating system is large, the greater the threat value of the office location is. The threat value of the office location is obtained by homogenizing the number of public security cases at the office location of the designated operating system with the number of public security cases at other locations.
[0037] It should also be noted that the specific analysis method of the location security value of the office location of the designated operating system is: the threat value and meteorological safety value of the office location of the designated operating system are averaged to obtain the location security value of the office location of the designated operating system.
[0038] In a specific embodiment of the present invention, the security value of the access control system, the security value of the monitoring system and the security value of the anti-theft alarm system are obtained by: obtaining the duration T of each fault of the access control system from the designated operating system _1j , event keyword set A _j , after processing, the security value of the access control system is obtained Where C is the total number of failures of the access control system, C′, T′, and A′ are the allowed number of failures, allowed failure duration, and risk event keyword set of the access control system stored in the web data warehouse, respectively, and j is the number of each failure, j = 1, 2, ..., k.
[0039] The volume V, average frame rate Z, average throughput U, and average delay time TI of the monitoring system's coverage are obtained from the specified operating system, and the security value of the monitoring system is obtained after processing. Where V', Z', U', and TI' represent the volume of the office location of the specified operating system stored in the web data warehouse, the required frame rate, required throughput, and allowed delay time of the monitoring system, respectively.
[0040] It should be noted that the required frame rate, required throughput and allowed delay duration of the monitoring system are determined by multiplying the volume of the office location where the designated operating system is located by the required frame rate, required throughput and allowed delay duration of the monitoring system corresponding to the unit volume stored in the web data warehouse to obtain the required frame rate, required throughput and allowed delay duration of the monitoring system.
[0041] Obtain the false alarm rate WI and detection rate JI of the anti-theft alarm system from the specified running system, and obtain the security value of the anti-theft alarm system after processing. Where WI' and JI' represent the required false alarm rate and required detection rate of the anti-theft alarm system of the specified running system stored in the web data warehouse, respectively.
[0042] It should be noted that in order to ensure the safe and stable operation of the anti-theft alarm system, the anti-theft alarm system is usually tested. For example, in a simulated actual environment, by arranging various scenarios that may cause false alarms, the response of the anti-theft alarm system is obtained to evaluate its false alarm rate and detection rate, and upload them to the designated operating system.
[0043] The false alarm rate specifically refers to the proportion of alarms triggered by non-security tags.
[0044] The detection rate is specifically obtained by averaging the number of alarms when a unit number of valid tags passes through different positions in the detection area in different directions.
[0045] It should also be noted that the required false alarm rate and required detection rate of the anti-theft alarm system of the designated operating system are specifically uploaded by the staff of the designated operating system. For example, in order to improve the anti-theft alarm performance of the designated operating system, the required false alarm rate is lowered and the required detection rate is increased.
[0046] In a specific embodiment of the present invention, the network status security value and logistics protection security value of each supplier are obtained by: obtaining the audit weight value Q of each supplier from the designated operation system. _h And crawl the security incident reports of each supplier from the public network security emergency response center, and extract the keyword set E of each security incident of each supplier _hb and the number of associated devices S _hb , after processing, the network status security value μ of each supplier is obtained _1h , h is the number of each supplier, h=1,2,...,g, b is the number of each security incident, b=1,2,...,d.
[0047] It should be noted that the review and confirmation value of each supplier is specifically a value of 0 or 1, which reflects whether the designated operating system conducts a security review of the supplier. If a security review is conducted on the supplier, the review and confirmation value is 1, otherwise, the review and confirmation value is 0.
[0048] It should be noted that the specific calculation formula for the network status security value of each supplier is: Where E', S' _h are the network risk event keyword set stored in the web data warehouse and the total number of devices of the hth supplier.
[0049] Obtain the historical logistics delivery data of each supplier from the designated operation system, where the historical logistics delivery data includes the cargo tracking characteristic value R of each logistics delivery. _2hf , safe packaging characteristic value B _2hfand the proportion of goods mispayment BI _2hf , after processing, the logistics protection safety value μ of each supplier is obtained _2h , f is the number of each logistics delivery, f = 1, 2, ..., t.
[0050] The specific calculation formula of the logistics protection safety value is:
[0051] It should be noted that when the designated operating system establishes a cooperative relationship with a supplier, the supplier is usually required to provide capital verification data, which includes historical logistics delivery data and is uploaded by the supplier to the designated operating system.
[0052] It should also be noted that the cargo tracking characteristic value, specifically a value of 0 or 1, reflects whether the supplier adopts a cargo tracking system during the logistics delivery process. If a cargo tracking system is adopted, the cargo tracking characteristic value is 1, otherwise, the cargo tracking characteristic value is 0. The security packaging characteristic value is specifically a value of 0 or 1, reflecting whether the supplier securely packages the goods during the logistics delivery process. If the goods are securely packaged, the security packaging characteristic value is 1, otherwise, the cargo tracking characteristic value is 0. The cargo mispayment ratio includes the total number of tampered, lost or stolen goods divided by the total number of goods.
[0053] It should be noted again that if the supplier adopts a cargo tracking system or safely packages the goods during the logistics delivery process, it means that the supplier has better protective measures during the logistics delivery process, avoiding the risks of business interruption and information leakage for the enterprise to which the designated operating system belongs, thereby reducing the exposure of the enterprise to which the designated operating system belongs. Therefore, it is necessary to analyze the characteristic values of cargo tracking and safe packaging of the supplier during the logistics delivery process.
[0054] In a specific embodiment of the present invention, the authority allocation characteristic value, security training characteristic value and competition form characteristic value are specifically obtained by: obtaining the corresponding allocation authority level of each employee of each functional level from the designated operating system, combining the initial allocation authority level corresponding to each functional level stored in the web data warehouse, and determining the authority allocation characteristic value of the designated operating system.
[0055] It should be noted that the specific method for determining the authority allocation characteristic value of the specified operating system is as follows: the allocated authority level of each employee of each functional level of the specified operating system is compared with the initial allocated authority level. If the allocated authority level of an employee is consistent with the initial allocated authority level, the authority allocation characteristic value of the employee is recorded as H; otherwise, it is recorded as H', where H>H'. The authority allocation characteristic value of each employee of each functional level is obtained, and the average is processed to obtain the authority allocation characteristic value of the specified operating system.
[0056] It should be noted that during the work process of a designated operating system, it is usually necessary to set permission levels for employees to ensure the security of employees when using the designated operating system. However, in actual use, in order to facilitate work, other permission levels are often opened to employees. If they are not closed, it will affect the security of employees using the designated operating system and increase the risk of leakage. Therefore, it is necessary to compare and analyze the assigned permission levels of each employee at each functional level of the designated operation.
[0057] The type and time of each security training session are obtained from the specified operating system. If the type of a security training session is network security, the security training session is recorded as network security training. The network security training sessions are screened and the time of each network security training session is obtained. The frequency of network security training for the specified operating system is calculated and divided by the frequency of appropriate network security training stored in the web data warehouse to obtain the security training characteristic value for the specified operating system.
[0058] Obtain each competing enterprise from the designated operating system, and crawl the number of risky behaviors of each competing enterprise from the public network security emergency response center. Summarize the total number of risky behaviors of competing enterprises in the designated operating system, and divide it by the total number of allowed risky behaviors of the designated operating system stored in the web data warehouse to obtain the ratio of the number of risky behaviors of competing enterprises in the designated operating system to the number of allowed risky behaviors. The ratio is then inverted to obtain the competitive morphology characteristic value of the designated operating system.
[0059] It should be noted that the total number of risky behaviors allowed for the designated operating system is specifically uploaded by the staff of the designated operating system. For example, in order to avoid attacks on the designated operating system by competing enterprises, the total number of risky behaviors allowed for the designated operating system will be lowered.
[0060] The exposure depth assessment module is used to assess the exposure depth of a specified operating system at the asset operation level, business operation level, and offline management level.
[0061] In the exposure depth assessment module, the present invention evaluates the exposure depth of the specified operating system at the asset operation level, business operation level and offline management level through the asset operation data, business operation data and offline management data of the specified operating system, thereby making up for the shortcomings of the existing technology, preventing the specified operating system from being attacked from multiple levels, and providing a more comprehensive risk assessment, thereby improving the network security of the specified operating system.
[0062] In a specific embodiment of the present invention, the exposure depth of the designated operating system at the asset operation level, business operation level, and offline management level is evaluated by a specific evaluation method: based on the characteristic parameters of each network asset, each data asset, and each physical asset in the asset operation data of the designated operating system, the exposure depth model of the asset operation level is processed to output the exposure depth of the designated operating system at the asset operation level.
[0063] Based on the network status security value and logistics protection security value of each supplier in the business operation data of the specified operation system, the exposure depth model at the business operation level Processing, output the exposure depth of the specified operating system at the business operation level
[0064] Based on the characteristic value of authority allocation in offline management data of a specified operating system Safety training characteristic value and competitive morphological eigenvalues Exposure depth model at the management level below the warp line Processing, output the exposure depth of the specified operating system at the asset operation level
[0065] In a specific embodiment of the present invention, the asset operation level exposure depth model is specifically: ,
[0066] In the formula They are respectively represented as the characteristic parameters of the rth network asset, the vth data asset, and the xth physical asset. They are respectively represented as the security feature parameter interval of the rth network asset, the security feature parameter interval of the vth data asset, and the security feature parameter interval of the xth physical asset stored in the web data warehouse, where r is the number of each network asset, r = 1, 2, ..., w, v is the number of each data asset, v = 1, 2, ..., u, and x is the number of each physical asset, x = 1, 2, ..., y.
[0067] The exposed surface processing module is used to generate an early warning response signal for a designated operating system.
[0068] The present invention generates an early warning response signal for a designated operating system in an exposed surface processing module, providing support for subsequent security teams to determine which layers require priority protection, thereby avoiding subsequent security teams from making incorrect judgments about which layers require priority protection, improving the maintenance efficiency of designated operating systems, and reducing network risks of designated operating systems to a certain extent.
[0069] In a specific embodiment of the present invention, the generation of the early warning response signal of the designated operating system is specifically performed as follows: based on the exposure depth of the designated operating system at the asset operation level, business operation level and offline management level, if Then an early warning response signal is generated for the specified operating system at the asset operation level.
[0070] like Then an early warning response signal is generated for the designated operating system at the business operation level.
[0071] like An early warning response signal is generated for the designated operating system at the offline management level.
[0072] described They are respectively represented by the exposure depth convergence value of the specified operating system stored in the web data warehouse at the asset operation level, the exposure depth convergence value at the business operation level, and the exposure depth convergence value at the offline management level.
[0073] The early warning response signal of the specified operating system is obtained through aggregation.
[0074] The above contents are merely examples and explanations of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should all fall within the scope of protection of the present invention.
Claims
1. A network security supervision platform based on network security operation, characterized in that: include: The network operation data acquisition module is used to obtain network operation data from the specified operation system, where the network operation data includes asset operation data, business operation data, and offline management data; The asset operation data includes characteristic parameters of each network asset, characteristic parameters of each data asset, and characteristic parameters of each physical asset; The characteristic parameters of each network asset include the number of each external network device and the number of vulnerabilities of each internal device; The characteristic parameters of each data asset include the convenient access value and sharing degree of each key data; The characteristic parameters of each physical asset include the location security value of the office location, the security value of the access control system, the security value of the monitoring system, and the security value of the anti-theft alarm system; The business operation data includes the network status security value and logistics protection security value of each supplier; The offline management data includes authority allocation feature values, safety training feature values, and competition form feature values; The convenient access value and sharing degree of each key data are obtained in the following specific methods: Obtain each storage location of each key data from the designated operating system, and obtain the number of shared channels corresponding to each storage location from the designated operating system, filter the number of shared channels for each storage location of each key data of the designated operating system, filter out each high-risk storage location and each low-risk storage location of each key data of the designated operating system, and summarize to obtain the number of high-risk storage locations of each key data of the designated operating system; Summarize the total number of storage locations M for each key data of the specified operating system _i , specify the total number of storage locations for each key data of the running system and the number of high-risk storage locations MI _i Import into convenient access value evaluation model Output the convenient access value α of each key data _i , where M′ _i is the number of suitable storage locations for the i-th key data stored in the web data warehouse, i is the number of each key data, i = 1, 2, ..., n; Obtain the protection characteristic value χ of each transmission of each key data from the specified operating system _im , import it into the sharing evaluation model In the output, the sharing degree of each key data is output, m is the number of each transmission, m = 1, 2, ..., l, χ′ _i It is represented by the required protection characteristic value of the i-th key data stored in the web data warehouse; The specific method for obtaining the security value of the access control system, the security value of the monitoring system, and the security value of the anti-theft alarm system is as follows: Obtain the duration T of each fault of the access control system from the specified operating system _1j , event keyword set A _j , after processing, the security value of the access control system is obtained Where C is the total number of failures of the access control system, C′, T′, and A′ are the allowed number of failures, allowed failure duration, and risk event keyword set of the access control system stored in the web data warehouse, respectively. j is the number of each failure, j = 1, 2, ..., k. The volume V, average frame rate Z, average throughput U, and average delay time TI of the monitoring system's coverage are obtained from the specified operating system, and the security value of the monitoring system is obtained after processing. Where V', Z', U', and TI' represent the volume of the office location of the specified operating system stored in the web data warehouse, the required frame rate, required throughput, and allowed delay of the monitoring system, respectively; Obtain the false alarm rate WI and detection rate JI of the anti-theft alarm system from the specified running system, and obtain the security value of the anti-theft alarm system after processing. Where WI' and JI' represent the required false alarm rate and required detection rate of the anti-theft alarm system of the specified running system stored in the web data warehouse, respectively; The exposure depth assessment module is used to assess the exposure depth of a specified operating system at the asset operation level, business operation level, and offline management level; The exposed surface processing module is used to generate early warning response signals for the specified operating system.
2. A network security monitoring platform based on network security operation according to claim 1, characterized in that: The location security value of the office location is obtained in the following manner: Obtain the characteristic parameters δ of each meteorological data of the office location where the designated operation system is located from the meteorological management center _p , and import it into the meteorological safety value assessment model Output the weather safety value X of the office location _1 , p is the number of each meteorological data, p=1,2,...,q,δ′ _p is the suitable characteristic parameter interval of the pth meteorological data of the office location stored in the web data warehouse; The threat value of the office location of the designated operating system is obtained from the public management center, and combined with the meteorological safety value of the office location of the designated operating system, the location safety value of the office location of the designated operating system is obtained through analysis.
3. A network security monitoring platform based on network security operation according to claim 1, characterized in that: The specific method for obtaining the network status security value and logistics protection security value of each supplier is as follows: Obtain the audit weight Q of each supplier from the designated operating system _h , and crawl to obtain the security incident reports of each supplier, and extract the keyword set E of each security incident of each supplier _hb and the number of associated devices S _hb , after processing, the network status security value μ of each supplier is obtained _1h , h is the number of each supplier, h = 1, 2, ..., g, b is the number of each security incident, b = 1, 2, ..., d; The review and confirmation value of each supplier is specifically a value of 0 or 1, which reflects whether the designated operating system has conducted a security review on the supplier. If the supplier is subject to a security review, the review and confirmation value is 1, otherwise, the review and confirmation value is 0; Obtain the historical logistics delivery data of each supplier from the designated operation system, where the historical logistics delivery data includes the cargo tracking characteristic value R of each logistics delivery. _2hf , safe packaging characteristic value B _2hf and the proportion of goods mispayment BI _2hf , after processing, the logistics protection safety value μ of each supplier is obtained _2h , f is the number of each logistics delivery, f = 1, 2, ..., t; The cargo tracking characteristic value is specifically a value of 0 or 1, reflecting whether the supplier adopts a cargo tracking system during the logistics delivery process. If a cargo tracking system is adopted, the cargo tracking characteristic value is 1, otherwise, the cargo tracking characteristic value is 0. The security packaging characteristic value is specifically a value of 0 or 1, reflecting whether the supplier securely packages the goods during the logistics delivery process. If the goods are securely packaged, the security packaging characteristic value is 1, otherwise, the cargo tracking characteristic value is 0. The cargo mispayment ratio includes the total number of tampered, lost or stolen goods divided by the total number of goods.
4. A network security monitoring platform based on network security operation according to claim 1, characterized in that: The specific method for obtaining the authority allocation characteristic value, security training characteristic value and competition form characteristic value is as follows: Obtain the assigned authority level corresponding to each employee of each functional level from the designated operating system, and determine the authority allocation characteristic value of the designated operating system by combining the initial assigned authority level corresponding to each functional level stored in the web data warehouse; Obtain the type and time of each security training session from the specified operating system. If the type of a security training session is network security, record the security training session as network security training. Filter each network security training session and obtain the time of each network security training session. Calculate the frequency of network security training for the specified operating system and divide it by the frequency of appropriate network security training sessions stored in the web data warehouse to obtain a security training feature value for the specified operating system. Obtain each competing enterprise from the designated operating system, crawl and obtain the number of risky behaviors of each competing enterprise, summarize the total number of risky behaviors of the competing enterprises in the designated operating system, and divide it by the total number of allowed risky behaviors of the designated operating system stored in the web data warehouse to obtain the ratio of the number of risky behaviors of the competing enterprises in the designated operating system to the number of allowed risky behaviors, and invert it to obtain the competition morphology characteristic value of the designated operating system.
5. A network security monitoring platform based on network security operation according to claim 1, characterized in that: The assessment specifies the depth of exposure of the operating system at the asset operation level, business operation level, and offline management level. The specific assessment method is as follows: Based on the characteristic parameters of each network asset, each data asset and each physical asset in the asset operation data of the specified operation system, the exposure depth model of the asset operation layer is processed to output the exposure depth θ(1) of the specified operation system at the asset operation layer. Based on the network status security value and logistics protection security value of each supplier in the business operation data of the specified operation system, the exposure depth model of the business operation layer is processed to output the exposure depth θ(2) of the specified operation system at the business operation layer; Based on the authority allocation feature value, security training feature value and competition morphology feature value in the offline management data of the specified operating system, the exposure depth model of the offline management level is processed to output the exposure depth θ(3) of the specified operating system at the asset operation level.
6. A network security monitoring platform based on network security operation according to claim 5, characterized in that: The asset operation level exposure depth model is specifically as follows: In the formula They are respectively represented as the characteristic parameters of the rth network asset, the vth data asset, and the xth physical asset. They are respectively represented as the security feature parameter interval of the rth network asset, the security feature parameter interval of the vth data asset, and the security feature parameter interval of the xth physical asset stored in the web data warehouse, where r is the number of each network asset, r = 1, 2, ..., w, v is the number of each data asset, v = 1, 2, ..., u, and x is the number of each physical asset, x = 1, 2, ..., y.
7. A network security monitoring platform based on network security operation according to claim 5, characterized in that: The specific generation method of the early warning response signal of the specified operating system is as follows: Based on the exposure depth of the designated operating system at the asset operation level, business operation level, and offline management level, if θ(1)≥θ(1)′, then an early warning response signal of the designated operating system at the asset operation level is generated; If θ(2)≥θ(2)′, then an early warning response signal of the designated operation system at the business operation level is generated; If θ(3)≥θ(3)′, then an early warning response signal is generated at the offline management level of the designated operating system; The θ(1)′, θ(2)′, and θ(3)′ respectively represent the exposure depth convergence value of the specified operating system at the asset operation level, the exposure depth convergence value at the business operation level, and the exposure depth convergence value at the offline management level stored in the web data warehouse; The early warning response signal of the specified operating system is obtained through aggregation.
Citation Information
Patent Citations
Cybersecurity Risk Assessment System
CN113225358B
A network security risk assessment system
CN114021154B
Network security risk detection method and device, electronic equipment and storage medium
CN113114647A
Network security index assessment method
CN118869341A