A computer network information security protection method
By calculating JAQ, DP, and TZ values through data detection and comprehensive processing modules, and dynamically adjusting network security strategies, the problems of untimely response and incomplete assessment in existing technologies are solved, enabling real-time assessment and rapid response of network security.
Patent Information
- Application Number
- CN202411619138.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-11-13
AI Technical Summary
Existing technologies cannot reflect changes in cybersecurity status in real time, resulting in untimely responses. Security policy adjustments rely on manual judgment and are delayed, neglecting the efficiency of security facilities and threat response time, and the assessment results are not comprehensive enough.
The system uses a data detection and acquisition module to collect network security configuration information, and a data processing module to calculate the basic security assessment value JAQ, dynamic risk assessment value DP, and comprehensive security adjustment value TZ. It dynamically adjusts security policies and combines intrusion prevention systems, firewalls, intrusion detection systems, and other equipment for real-time evaluation and adjustment.
It enables dynamic assessment and real-time adjustment of network security status, improves response speed and defense capabilities, and ensures that the network maintains optimal security status in dynamic environments.
Smart Images

Figure CN119449440B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network security protection technology, specifically to a method for protecting information security in computer networks. Background Technology
[0002] With the popularization of the Internet and the rapid development of technology, network attack methods are constantly being innovated. Hackers use system vulnerabilities, malicious software, and phishing websites to launch attacks on network systems, steal sensitive information, damage data integrity, and even paralyze the entire network. These attacks not only threaten personal privacy and security, but also have a serious impact on the normal operation of enterprises and national information security. In order to cope with complex network security threats and the expanding network application environment, information security protection technologies for computer networks are also constantly evolving, providing strong guarantees for the information security protection of computer networks.
[0003] Existing technologies mostly employ static security assessment methods, which cannot reflect changes in network security status in real time. This leads to untimely responses when facing sudden threats. Furthermore, many assessment methods only consider a single dimension, ignoring the combined impact of security facility efficiency and threat response time, resulting in incomplete assessment results. In addition, adjustments to security policies often rely on manual judgment and experience, lacking a scientific dynamic adjustment mechanism, leading to delayed and ineffective adjustments. Moreover, when formulating and adjusting security policies, the results of recent security audits are often overlooked, making it impossible to promptly address the issues identified in the audits. Summary of the Invention
[0004] The purpose of this invention is to provide a method for protecting information security in computer networks, which solves the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution, and the specific implementation steps are as follows:
[0006] The data detection and acquisition module is used to collect detection data on computer network security configuration information;
[0007] The detection data is fed into the data processing module to obtain the basic safety assessment value JAQ, the dynamic risk assessment value DP, and the comprehensive safety adjustment value TZ.
[0008] By comparing the difference between the comprehensive security adjustment value TZ and the average value of the previous m comprehensive security adjustment values TZ extracted from the data detection and acquisition module, the security areas to be adjusted are determined, including improving intrusion prevention capabilities, optimizing security facility efficiency, and reducing the level of current activity threats.
[0009] The data processing module includes a unit for quantifying the basic network security level, a unit for dynamically assessing network risks, and a unit for guiding comprehensive adjustments.
[0010] Optionally, the equipment used in the data detection and acquisition module includes intrusion prevention systems, firewalls, intrusion detection systems, network performance testing tools, security auditing tools, and monitoring and log analysis tools;
[0011] The data processing module uses equipment including servers and storage devices.
[0012] Optionally, the detection data for the configuration information includes a score based on the deployment, updates, and policy effectiveness of the intrusion prevention system;
[0013] Use monitoring and log analysis tools to analyze and determine the operational efficiency of security devices;
[0014] Detect threat response time WX and average response time PX, and use network performance testing tools to provide response efficiency XX;
[0015] Monitor and detect active threats in the network;
[0016] Security auditing tools are used to conduct regular security audits and record the number and severity of issues found.
[0017] Optionally, the calculation formula for the quantized network basic security level unit is as follows:
[0018] JAQ = [(RF + AS) + XX] 0.5 ;
[0019] XX = WX / PX;
[0020] in:
[0021] JAQ is a basic security assessment value;
[0022] RF stands for Intrusion Prevention Value, which reflects the network's defense capabilities.
[0023] AS stands for Safety Facility Operation Efficiency;
[0024] WX stands for Threat Response Time. WX measures the time interval between when the system detects a threat and when it begins to take response measures.
[0025] PX represents the average response time;
[0026] XX represents response efficiency. XX is used to compare threat response time WX and average response time PX to evaluate the efficiency of the network's response when facing threats.
[0027] Optionally, the specific response time WX and the average response time PX are explained and calculated using the following formulas:
[0028] WX=XS-JS;
[0029] XS is the response time, which reflects the specific point in time when the system begins to respond to a threat.
[0030] JS represents the detection time, reflecting the specific point in time when the threat was detected;
[0031] Assuming June 5, 2024, 15:20:10 is the detection time JS, and June 5, 2024, 15:20:35 is the response time XS, the formula is as follows;
[0032] June 5, 2024, 15:20:35 - June 5, 2024, 15:20:10 = 25, therefore the threat response time WX is 25.
[0033] PX = (WX1 + WX2 + WX3 + ... + WX) n ) / n;
[0034] WX1+WX2+WX3+......WX n The sum of all threat response times (WX);
[0035] n is the total number of responses.
[0036] Optionally, the calculation formula for the dynamic assessment network risk unit is as follows:
[0037] DP = JAQ * [1 + (DW / (JAQ / RF)] 0.5 ))];
[0038] in:
[0039] DP stands for Dynamic Risk Assessment Value;
[0040] DW represents the current active threat intensity value, and DW affects the risk level of the dynamic risk assessment value DP.
[0041] The baseline security assessment value JAQ is used as a benchmark and multiplied by the expressions for the current active threat strength value DW and the intrusion prevention value RF, so that the impact of the current active threat strength value DW and the intrusion prevention value RF on the risk assessment can retain consideration of the baseline security assessment value JAQ.
[0042] Optionally, the calculation formula for the guidance and comprehensive adjustment unit is as follows:
[0043] TZ=[DP*(1+log 10 (1+SJ / DP))] / 1+(AS / 100) 0.5 ;
[0044] in:
[0045] TZ is the comprehensive safety adjustment value;
[0046] SJ represents the severity value of the last audit, reflecting the current status of the last security audit.
[0047] SJ / DP reflects the comparison between the current security status and the past and historical average levels;
[0048] log 10 (1+SJ / DP) is used to amplify the impact of the previous audit severity value SJ on the dynamic risk assessment value DP, while avoiding overreaction to a smaller previous audit severity value SJ.
[0049] Optionally, the security protection adjustment steps based on the aforementioned guidance and comprehensive adjustment unit are as follows:
[0050] S1. The formula for calculating the average value of the first m comprehensive security adjustment values TZ extracted from the data detection and acquisition module is as follows:
[0051] TZ avg =(TZ1+TZ2+TZ3+......TZ n ) / m;
[0052] m represents the total amount extracted;
[0053] S2, if TZ>TZ avg This indicates that the network faces significant security risks under the current security strategy, and corresponding security adjustments should be made.
[0054] S3, if TZ <TZ avg This indicates that the network has a high level of security under the current security policy. The current policy should be maintained, and security assessments and audits should be conducted regularly.
[0055] S4. If TZ = TZ avg This indicates that the network is in a relatively secure state under the current security policy. Continuous monitoring and close attention to the network's security status are necessary.
[0056] Optionally, the comprehensive security adjustment value TZ is a relative value used to guide security policy adjustments. In practice, TZ... <TZ avg Furthermore, negative numbers are relatively rare. If a negative number does occur under certain circumstances, the specific feedback and adjustments will be as follows:
[0057] During the adjustment process, the accuracy and reasonableness of intrusion prevention value (RF), security facility operational efficiency (AS), threat response time (WX), and average response time (PX) should be reassessed.
[0058] Measure and assess whether new threat factors and security requirements have been introduced. Based on the analysis and assessment results, formulate corresponding adjustment measures to optimize the calculation results of the comprehensive security adjustment value TZ and the network security status. Adjustment measures include optimizing the configuration and performance of security devices, strengthening security monitoring and response capabilities, and improving the network security strategy and its enforcement.
[0059] Compared with the prior art, the present invention has the following beneficial effects:
[0060] I. This invention achieves dynamic assessment of network security status through a quantitative network basic security level unit and a dynamic network risk assessment unit. The quantitative network basic security level unit comprehensively considers three dimensions: intrusion prevention capability, security facility efficiency, and threat response time, while the dynamic network risk assessment unit further introduces the current active threat level, making the assessment results more comprehensive and real-time.
[0061] Second, the invention guides the comprehensive adjustment unit to calculate the comprehensive security adjustment value TZ based on the results of the dynamic assessment of network risk units and the results of the previous security audit, providing a scientific basis for adjusting security strategies. Furthermore, through an automated adjustment mechanism, it can promptly detect and resolve security issues, thereby improving response speed and defense capabilities.
[0062] Third, the comprehensive security adjustment value TZ obtained by the present invention can be fed back into the adjustment of security strategy. These adjustments will indirectly affect the input value when the basic security assessment value JAQ is calculated in the next quantification of network basic security level unit, forming a cyclic optimization mechanism. This mechanism enables the security protection method to continuously adapt to changes in the network threat environment and maintain the best security status.
[0063] Fourth, the method proposed in this invention not only considers traditional factors such as intrusion prevention capabilities and security facility efficiency, but also introduces threat response time (WX), average response time (PX), current active threat level, and the results of the last security audit as new evaluation dimensions, thereby achieving comprehensive coverage and in-depth evaluation of network security. Attached Figure Description
[0064] Figure 1 This is a flowchart of the information security protection method for this computer network;
[0065] Figure 2 This is a schematic diagram of the data integration and processing module of the present invention;
[0066] Figure 3 This is a schematic diagram illustrating the results and measures of the cyclic feedback of the comprehensive safety adjustment value TZ in this invention;
[0067] Figure 4 This is a schematic diagram illustrating the rare results and measures of the integrated safety adjustment value TZ cyclic feedback in this invention. Detailed Implementation
[0068] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0069] The information security protection method for this computer network differs from traditional security protection methods. Traditional methods often rely on static security policies and fixed security equipment configurations, making it difficult to adapt to the rapidly changing network threat environment. As network attack methods continue to evolve and become more complex, traditional protection methods have gradually revealed their limitations, including slow response speed, insufficient defense capabilities, and lagging security policy adjustments. In contrast, this algorithm unit realizes dynamic assessment and scientific adjustment of network security status, solving the problems and shortcomings of existing technologies and providing new ideas and methods for information security protection of computer networks.
[0070] For examples, please refer to Figures 1 to 4 This implementation provides a method for information security protection of computer networks, and the specific implementation steps are as follows:
[0071] The data detection and acquisition module is used to collect detection data on computer network security configuration information;
[0072] The configuration information detection data includes scores based on the deployment, updates, and policy effectiveness of the intrusion prevention system;
[0073] Use monitoring and log analysis tools to analyze and determine the operational efficiency of security devices;
[0074] Detect threat response time WX and average response time PX, and use network performance testing tools to provide response efficiency XX;
[0075] Monitor and detect active threats in the network;
[0076] Security audit tools are used to conduct regular security audits and record the number and severity of issues found.
[0077] The detection data is fed into the data processing module to obtain the basic safety assessment value JAQ, the dynamic risk assessment value DP, and the comprehensive safety adjustment value TZ.
[0078] By comparing the difference between the comprehensive security adjustment value TZ and the average value of the previous m comprehensive security adjustment values TZ extracted from the data detection and acquisition module, the security areas to be adjusted are determined, including improving intrusion prevention capabilities, optimizing security facility efficiency, and reducing the level of current activity threats.
[0079] The data processing module includes a unit for quantifying the basic network security level, a unit for dynamically assessing network risks, and a unit for guiding comprehensive adjustments.
[0080] The equipment used in the data detection and acquisition module includes intrusion prevention systems, firewalls, intrusion detection systems, network performance testing tools, security auditing tools, and monitoring and log analysis tools.
[0081] The data processing module uses equipment including servers and storage devices.
[0082] This embodiment provides a systematic approach to assessing and adjusting the information security protection of computer networks. Through modular and unit-based design, the entire process becomes clearer and easier to manage. At the same time, by introducing specific equipment and tools, the accuracy and effectiveness of the assessment and adjustment process are ensured.
[0083] In this embodiment, the system utilizes the cooperation of three algorithm units to quantitatively assess and adjust the network's security status, providing network administrators with strong decision support. The combined results of JAQ, DP, and TZ calculations constitute a complete assessment and adjustment system, aiming to ensure the network maintains optimal security in dynamic environments. JAQ is the basic security assessment value, quantifying the network's basic security level at a given moment, helping network administrators intuitively understand the network's current security status, including its defense capabilities and response speed. DP is the dynamic risk assessment value; this dynamic adjustment mechanism makes risk assessment more accurate and timely, helping network administrators react quickly when threats occur. TZ is the comprehensive security adjustment value, considering not only the network's current security status and threat level but also issues discovered during security audits, thus providing network administrators with comprehensive security adjustment suggestions. Furthermore, the TZ calculation result can influence the calculations of JAQ and DP, resulting in a high degree of correlation and interdependence among the three algorithms. This allows the overall algorithm system to automatically respond and optimize based on actual conditions, making it more realistic.
[0084] Please see Figures 1 to 4 The calculation formula for the quantitative network basic security level unit is as follows:
[0085] JAQ = [(RF + AS) + XX] 0.5 ;
[0086] XX = WX / PX;
[0087] in:
[0088] JAQ is a basic security assessment value;
[0089] RF stands for Intrusion Prevention Value, which reflects the network's defense capabilities.
[0090] AS stands for Safety Facility Operation Efficiency;
[0091] WX stands for Threat Response Time. WX measures the time interval between when the system detects a threat and when it begins to take response measures.
[0092] PX represents the average response time;
[0093] XX represents response efficiency. XX is used to compare threat response time WX and average response time PX to evaluate the efficiency of the network's response when facing threats.
[0094] The specific response details and calculation formulas for Threat Response Time (WX) and Average Response Time (PX) are as follows:
[0095] WX=XS-JS;
[0096] XS is the response time, which reflects the specific point in time when the system begins to respond to a threat.
[0097] JS represents the detection time; JS reflects the specific point in time when the threat was detected.
[0098] Assuming June 5, 2024, 15:20:10 is the detection time JS, and June 5, 2024, 15:20:35 is the response time XS, the formula is as follows;
[0099] June 5, 2024, 15:20:35 - June 5, 2024, 15:20:10 = 25, therefore the threat response time WX is 25.
[0100] PX = (WX1 + WX2 + WX3 + ... + WX) n ) / n;
[0101] WX1+WX2+WX3+......WX n The sum of all threat response times (WX);
[0102] n represents the total number of responses.
[0103] In this embodiment: First, in this algorithm unit, the three values of intrusion prevention value RF, security facility operation efficiency AS, and response efficiency XX are selected to calculate the basic security assessment value JAQ because they can comprehensively reflect the basic security level of the network. The intrusion prevention value RF represents the network's defense capability, the security facility operation efficiency AS represents the operation efficiency of security devices, and the response efficiency XX reflects the network's response speed to threats and requests. These four factors are interrelated and together constitute the cornerstone of network security.
[0104] The response efficiency XX is calculated using threat response time WX and average response time PX. In network security and performance evaluation, threat response time WX and average response time PX are two important metrics used to measure the speed at which a network and system respond to threats and general requests. However, these two metrics typically do not directly involve specific time representations like "time in hours and minutes," as they focus more on measuring time intervals and latency. Therefore, they can be expressed using formulas such as "WX = XS - JS" and "PX = (WX1 + WX2 + WX3 + ... + WX...". n The specific values are calculated separately for each ) / n”;
[0105] The basic security assessment value JAQ obtained by this algorithm unit comprehensively considers the relationship between intrusion prevention value RF, security facility operation efficiency AS, and response efficiency XX, and provides a comprehensive quantitative assessment of the basic security level of the network at a certain moment. This assessment helps network administrators quickly understand the overall security status of the network, and this multi-dimensional quantitative assessment provides network administrators with a detailed security profile, helping them to understand the security status of the network from multiple perspectives.
[0106] The assessment results of the Basic Security Assessment Value (JAQ) can serve as the basis for formulating preliminary security strategies. For example, if the JAQ value is low, it means that it is necessary to enhance intrusion prevention capabilities and optimize the configuration of security facilities.
[0107] By regularly calculating the Basic Security Assessment (JAQ) value, network administrators can track changes in network security status, promptly identify and resolve potential security issues, thereby driving continuous improvement in network security. Specifically, network administrators can predict potential security risks and take preventative measures in advance. This proactive management strategy helps reduce the occurrence of security incidents and improve the overall security of the network.
[0108] Please see Figures 1 to 4 The calculation formula for dynamically assessing network risk units is as follows:
[0109] DP = JAQ * [1 + (DW / (JAQ / RF)] 0.5 ))];
[0110] in:
[0111] DP stands for Dynamic Risk Assessment Value;
[0112] DW represents the current active threat intensity value, and DW affects the risk level of the dynamic risk assessment value DP.
[0113] The baseline security assessment value JAQ is used as a benchmark and multiplied by the expressions for the current active threat strength value DW and the intrusion prevention value RF, so that the impact of the current active threat strength value DW and the intrusion prevention value RF on the risk assessment can retain consideration of the baseline security assessment value JAQ.
[0114] In this embodiment, firstly, in the dynamic network risk assessment unit, the current active threat strength value DW is not directly used for simple mathematical operations with the basic security assessment value JAQ and the intrusion prevention value RF. Instead, it is used as an adjustment factor to affect the calculation of the dynamic risk assessment value DP through a specific mathematical expression. Specifically, this expression takes into account the weight and degree of influence of the current active threat strength value DW relative to the basic security assessment value JAQ and the intrusion prevention value RF.
[0115] However, to simplify the understanding, we can imagine this process as a weighted adjustment process. When the Current Active Threat Intensity (DW) value is high, it indicates that the network is facing a high level of threat. Even if the Basic Security Assessment (JAQ) and Intrusion Prevention (RF) values are also high, the network still faces significant risks due to the severity of the threat. Therefore, when calculating the Dynamic Risk Assessment (DP) value, a high DW value will "emphasize" the risk assessment, resulting in a relatively high DP value.
[0116] Conversely, when the Current Active Threat Intensity (DW) value is low, it indicates that the network is facing a low level of threat. Even if the Basic Security Assessment (JAQ) and Intrusion Prevention (RF) values are relatively low, the network risk is also relatively low because the severity of the threat is not enough to pose a significant threat to the network. Therefore, the low value of the Current Active Threat Intensity (DW) value will "mitigate" the risk assessment, resulting in a relatively low value of the Dynamic Risk Assessment (DP) value.
[0117] The dynamic risk assessment value DP output by this algorithm unit introduces the current active threat intensity value DW as an assessment factor on the basis of the basic security assessment value JAQ. This enables network administrators to quickly understand the current threat level and immediately activate the corresponding emergency response mechanism. This instant response capability is crucial for dealing with sudden security incidents and helps to reduce the scope and duration of the impact of security incidents on the network.
[0118] This algorithm unit correlates the current active threat strength value DW with the basic security assessment value JAQ and intrusion prevention value RF. The dynamic risk assessment value DP can balance the network's defense capabilities with the current threat level. Even in a high-threat environment, the high intrusion prevention capability can partially offset the impact of the threat and maintain the network's security and stability.
[0119] The dynamic risk assessment value (DP) of this algorithm unit helps network administrators allocate security resources rationally based on the current threat level. This includes increasing the capabilities of security monitoring and response teams to cope with high-threat environments. In particular, by identifying key threats and vulnerabilities, administrators can allocate security resources more accurately to ensure that critical business operations and sensitive data are adequately protected.
[0120] Please see Figures 1 to 4 The calculation formula for the comprehensive adjustment unit is as follows:
[0121] TZ=[DP*(1+log 10 (1+SJ / DP))] / 1+(AS / 100) 0.5 ;
[0122] in:
[0123] TZ is the comprehensive safety adjustment value;
[0124] SJ represents the severity value of the last audit, reflecting the current status of the last security audit.
[0125] SJ / DP reflects the comparison between the current security status and the past and historical average levels;
[0126] log 10 (1+SJ / DP) is used to amplify the impact of the previous audit severity value SJ on the dynamic risk assessment value DP, while avoiding overreaction to a smaller previous audit severity value SJ.
[0127] In this embodiment, the algorithm unit first combines the dynamic risk assessment value DP and the severity value SJ of the previous audit to provide a scientific basis for adjusting the security policy. By calculating the comprehensive security adjustment value TZ, the network administrator can clearly know the direction and intensity of the adjustment.
[0128] In the guidance of the comprehensive adjustment unit, log 10 The calculation of (1+SJ / DP) amplifies the impact of the previous audit severity value SJ on the comprehensive security adjustment value TZ, but avoids overreacting to smaller previous audit severity values SJ. This helps prevent unnecessary over-adjustment when the RA value is small.
[0129] AS / 100 is used to adjust the overall security adjustment value TZ based on the efficiency of security facilities. This adjustment mechanism enables the overall security adjustment value TZ to adapt to the security needs of different network environments, ensuring that the adjustment of security policies is more accurate and effective.
[0130] The comprehensive security adjustment value TZ of this algorithm unit provides network administrators with comprehensive security adjustment suggestions, indicating the direction and intensity of the adjustment, and providing specific adjustment strategies and measures. These strategies and measures are targeted and operable, which can help network administrators quickly implement security adjustment plans and improve the effectiveness and efficiency of security adjustments.
[0131] The cyclical impact mechanism of this algorithm unit enables the network's security status to be continuously improved. By constantly monitoring, evaluating, and adjusting security policies, network administrators can gradually optimize the network's security protection system and improve the overall security and stability of the network.
[0132] Please see Figures 1 to 4 The safety protection adjustment steps based on the guidance of the integrated adjustment unit are as follows:
[0133] S1. The formula for calculating the average value of the first m comprehensive safety adjustment values TZ extracted from the data detection and acquisition module is as follows:
[0134] TZ avg =(TZ1+TZ2+TZ3+......TZ n ) / m;
[0135] m represents the total amount extracted;
[0136] S2, if TZ>TZ avg This indicates that the network faces significant security risks under the current security strategy, and corresponding security adjustments should be made.
[0137] S3, if TZ <TZ avg This indicates that the network has a high level of security under the current security policy. The current policy should be maintained, and security assessments and audits should be conducted regularly.
[0138] S4. If TZ = TZ avg This indicates that the network is in a relatively secure state under the current security policy. Continuous monitoring and close attention to the network's security status are necessary.
[0139] In this embodiment, the algorithm unit is based on the average value TZ of the previous m comprehensive security adjustment values TZ. avgBy comparing the comprehensive security adjustment value TZ, we can obtain the risk status of the current security strategy and the corresponding measures. The average value of the previous m times can serve as a reference standard comparison value and, combined with the recent adjustments to computer network information security, has accurate and targeted reference value.
[0140] The calculation result of the comprehensive security adjustment value TZ indirectly affects the evaluation result of the next basic security assessment value JAQ by guiding the adjustment of security policies. This closed-loop feedback mechanism makes network security management a continuous process, which helps network administrators to continuously optimize and improve security policies. Moreover, over time, the cyclical impact of the comprehensive security adjustment value TZ on the basic security assessment value JAQ will gradually accumulate and produce a significant effect. Through continuous adjustment and optimization of security policies, the security status of the network will gradually improve and be enhanced, forming a virtuous cycle.
[0141] The cyclical impact of the comprehensive adjustment unit on the quantitative network basic security level unit will promote the improvement of the overall network security level. Through scientific evaluation, precise adjustment and continuous improvement, network administrators can build an efficient, reliable and secure network protection system, providing strong protection for the safe and stable operation of the network.
[0142] In summary, during the specific implementation process, the quantitative network basic security level unit, the dynamic network risk assessment unit, and the guidance and comprehensive adjustment unit, along with their cyclical influence, together constitute a complete computer network information security protection system, providing strong protection for the safe and stable operation of the network.
[0143] Please see Figures 1 to 4 The comprehensive security adjustment value TZ is a relative value used to guide security policy adjustments. In practice, TZ... <TZ avg Furthermore, negative numbers are relatively rare. If a negative number does occur under certain circumstances, the specific feedback and adjustments will be as follows:
[0144] During the adjustment process, the accuracy and reasonableness of intrusion prevention value (RF), security facility operational efficiency (AS), threat response time (WX), and average response time (PX) should be reassessed.
[0145] Measure and assess whether new threat factors and security requirements have been introduced. Based on the analysis and assessment results, formulate corresponding adjustment measures to optimize the calculation results of the comprehensive security adjustment value TZ and the network security status. Adjustment measures include optimizing the configuration and performance of security devices, strengthening security monitoring and response capabilities, and improving the network security strategy and its enforcement.
[0146] In this embodiment, the comprehensive security adjustment value TZ serves as an important indicator for guiding security policy adjustments. A negative value will mislead administrators into taking inappropriate security measures, such as incorrectly reducing security resource investment and relaxing vigilance against potential threats. Furthermore, a negative result for the comprehensive security adjustment value TZ directly points to problems with the calculation model and parameter settings. This requires administrators to re-examine and verify the rationality and accuracy of the entire security assessment system. When allocating resources based on the comprehensive security adjustment value TZ, a negative value will lead to the incorrect reduction and reallocation of security resources, thereby affecting the overall layout and effectiveness of network security.
[0147] By adjusting and optimizing the calculation model and parameter settings, the accuracy and reliability of the comprehensive security adjustment value TZ can be ensured, thereby enhancing the credibility of the entire security assessment system. After correcting the comprehensive security adjustment value TZ, the allocation of security resources can be more scientifically guided, ensuring that critical business and sensitive data are adequately protected while avoiding resource waste. Targeted adjustments can be made to address the issues revealed by negative comprehensive security adjustment values TZ, including strengthening security monitoring, improving response speed, and optimizing security strategies, which can significantly improve the network's security defense capabilities. During the adjustment process, administrators need to deeply analyze the causes and impacts of negative comprehensive security adjustment values TZ, which helps them better understand the network's security status and risk points, thereby improving the efficiency and accuracy of emergency response. In addition, the occurrence of negative comprehensive security adjustment values TZ and the subsequent adjustment process is a continuous learning and improvement process. Through this process, administrators can accumulate experience, improve systems, optimize processes, and thus promote the continuous improvement and enhancement of network security.
[0148] In conclusion, while a negative overall security adjustment value (TZ) is unfavorable, timely adjustments and optimizations can transform it into an opportunity to improve and enhance cybersecurity.
[0149] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for information security protection of computer networks, characterized in that, The specific implementation steps are as follows: Step 1: Use the data detection and acquisition module to collect detection data on computer network security configuration information; Step 2: Substitute the detection data into the data integration processing module to output the basic safety assessment value JAQ, dynamic risk assessment value DP, and comprehensive safety adjustment value TZ. Step 3: Compare the difference between the comprehensive security adjustment value TZ and the average value of the previous m comprehensive security adjustment values TZ extracted from the data detection and acquisition module to determine the security areas to be adjusted, including improving intrusion prevention capabilities, optimizing security facility efficiency, and reducing the level of current activity threats; The data processing module includes a unit for quantifying the basic network security level, a unit for dynamically assessing network risks, and a unit for guiding comprehensive adjustments. The calculation formula for the dynamic assessment network risk unit is as follows: DP=JAQ*[1+(DW / (JAQ / RF 0.5 ))]; in: DP stands for Dynamic Risk Assessment Value; DW represents the current active threat strength value; RF stands for Intrusion Prevention Value; The calculation formula for the guidance and comprehensive adjustment unit is as follows: TZ=[DP*(1+log 10 (1+SJ / DP))] / [1+(AS / 100) 0.5 ]; in: TZ is the comprehensive safety adjustment value; AS stands for Safety Facility Operation Efficiency; SJ represents the severity value of the last audit, reflecting the current status of the last security audit. log 10 (1+SJ / DP) is used to amplify the impact of the previous audit severity value SJ on the dynamic risk assessment value DP, while avoiding overreaction to a smaller previous audit severity value SJ.
2. The information security protection method for a computer network according to claim 1, characterized in that, The equipment used in the data detection and acquisition module includes intrusion prevention systems, firewalls, intrusion detection systems, network performance testing tools, security auditing tools, and monitoring and log analysis tools. The data processing module uses equipment including servers and storage devices.
3. The information security protection method for a computer network according to claim 2, characterized in that: The detection data for the configuration information includes a score based on the deployment, updates, and policy effectiveness of the intrusion prevention system. Use monitoring and log analysis tools to analyze and determine the operational efficiency of security devices; Detect threat response time WX and average response time PX, and use network performance testing tools to provide response efficiency XX; Monitor and detect active threats in the network; Security auditing tools are used to conduct regular security audits and record the number and severity of issues found.
4. The information security protection method for a computer network according to claim 3, characterized in that: The calculation formula for the quantitative network basic security level unit is as follows: JAQ=[(RF+AS)+XX] 0.5 ; XX = WX / PX; in: JAQ is a basic security assessment value; WX stands for Threat Response Time. WX measures the time interval between when the system detects a threat and when it begins to take response measures. PX represents the average response time; XX represents response efficiency. XX is used to compare threat response time WX and average response time PX to evaluate the efficiency of the network's response when facing threats.
5. The information security protection method for a computer network according to claim 4, characterized in that: The specific response time WX and the average response time PX are explained and calculated using the following formulas: WX=XS-JS; XS is the response time, which reflects the specific point in time when the system begins to respond to a threat. JS represents the detection time; JS reflects the specific point in time when the threat was detected. PX=(WX1+WX2+WX3+......WX n ) / n; WX1+WX2+WX3+......WX n The sum of all threat response times (WX); n represents the total number of responses.
6. The information security protection method for a computer network according to claim 5, characterized in that: The security protection adjustment steps based on the aforementioned guidance and integrated adjustment unit are as follows: S1. The formula for calculating the average value of the first m comprehensive security adjustment values TZ extracted from the data detection and acquisition module is as follows: TZ avg =(TZ1+TZ2+TZ3+......TZ n ) / m; m represents the total amount extracted; S2, if TZ>TZ avg This indicates that the network faces significant security risks under the current security policy, and corresponding security adjustments should be made. S3, if TZ <TZ avg This indicates that the network has a high level of security under the current security policy. The current policy should be maintained, and security assessments and audits should be conducted regularly. S4. If TZ = TZ avg This indicates that the network is in a relatively secure state under the current security policy. Continuous monitoring and close attention to the network's security status are necessary.
Citation Information
Patent Citations
Security assessment method and device for information technology system and electronic equipment
CN118133290A
Construction engineering site risk assessment method
CN118839974A