A State Evaluation Method and System Based on Network Security
By analyzing the network topology architecture and historical security vulnerabilities characteristics, and evaluating the scale and repair capabilities of network attacks, the evaluation error problems caused by complex network architecture and wide variety of attacks are solved, and accurate status evaluation and timely processing are achieved.
Patent Information
- Application Number
- CN202510019932.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-01-07
AI Technical Summary
The existing network architecture is complex and has a wide variety of attacks, resulting in large errors in state evaluation and affecting the timeliness of targeted processing.
By obtaining the network topology architecture, analyzing attackable paths and association sets, calculating the risk coefficients and attack characteristics of historical security vulnerabilities, evaluating the scale of the network attack, and judging the network security status based on the emergency repair speed.
Accurate network security status assessment is achieved, timely warning and targeted processing can be carried out at the initial moment of abnormal occurrence, reducing the cost of misjudgment and expert repair.
Smart Images

Figure CN119728288B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically relates to a method and system for state evaluation based on network security. Background Art
[0002] With the rapid development of computer technology, information networks have become an important guarantee for social development and are crucial for personal, enterprise, and institutional applications. Network security ensures that the hardware, software, and data in a network system are protected and not damaged, altered, or leaked due to accidental or malicious reasons, enabling the network system to operate continuously, reliably, and normally, and the network services to be uninterrupted. Therefore, it is necessary to evaluate network security, give timely warnings at the initial moment of anomalies, and then carry out targeted processing.
[0003] The existing network architectures are complex, and there are various types of network attacks. When conducting evaluations, the error in state evaluation is relatively large, making it impossible to make accurate judgments, which in turn affects the timeliness of targeted processing. Summary of the Invention
[0004] To solve the above technical problems, a method and system for state evaluation based on network security are provided. The present technical solution solves the problem in the above background art that the existing network architectures are complex, there are various types of network attacks, and when conducting evaluations, the error in state evaluation is relatively large, making it impossible to make accurate judgments, which in turn affects the timeliness of targeted processing.
[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0006] A method for state evaluation based on network security, comprising:
[0007] Obtain the topological architecture of network operation, where the topological architecture is composed of at least one network node and its connection relationship, analyze the defense capabilities of the topological architecture to obtain at least one attackable path, where the attackable path is composed of connected network nodes, and analyze the correlation of network nodes in the topological architecture to obtain the correlation set of network nodes;
[0008] Obtain at least one historical security vulnerability, calculate the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability, and form an attack feature for the historical security vulnerability;
[0009] Obtain at least one network attack within a preset time in the network operation environment, and correspond the network attack presenting the attack feature of the historical security vulnerability with the historical security vulnerability;
[0010] Form a danger critical value for the attackable path, such that when the danger coefficient is greater than the danger critical value, the historical security vulnerabilities corresponding to the danger coefficient cause network damage to the attackable path, where the danger critical values of different attackable paths are different;
[0011] Based on the danger critical value of the attackable path, evaluate the attack scale of at least one network attack to obtain an overall predicted scale, where the overall predicted scale is the attack scale within a preset time;
[0012] Obtain the emergency repair speed of the network node and calculate the attack cancellation scale;
[0013] When the overall predicted scale does not exceed the attack cancellation scale, then determine that the network security is in a normal state; otherwise, determine that the network security is in an abnormal state.
[0014] Preferably, the obtaining of the topological architecture of the network operation includes the following steps:
[0015] Obtain at least one network node used for data transmission during network operation and at least one transmission path used for data transmission during network operation;
[0016] Correspond the network nodes passed by the transmission path with the transmission path, and the network nodes corresponding to the same transmission path have a connection relationship;
[0017] Summarize the correspondence between the network nodes and the transmission paths and the transmission paths to obtain the topological architecture of the network operation.
[0018] Preferably, the analysis of the defense force of the topological architecture to obtain at least one attackable path includes the following steps:
[0019] Based on historical data, obtain the repair strategy for historical security vulnerabilities;
[0020] Use the historical security vulnerabilities to test the network nodes a preset number of times. After each test, use the repair strategy for the historical security vulnerabilities to repair the network nodes;
[0021] Divide the number of times the network nodes correctly identify the historical security vulnerabilities by the preset number of times to obtain the correct identification rate, and take the average of the correct identification rates of the network nodes relative to at least one historical security vulnerability to obtain the average correct identification rate;
[0022] Use the defense force formula to calculate the vulnerability identification rate of the transmission path;
[0023] When the vulnerability identification rate is lower than the preset value, then use the transmission path as an attackable path;
[0024] The defense force formula is as follows:
[0025] ,
[0026] Among them, A is the vulnerability recognition rate, i is the subscript, n is the total number of network nodes in the transmission path, is the average correct recognition of the i-th network node in the transmission path.
[0027] Preferably, the step of performing correlation analysis on the network nodes in the topological architecture to obtain the association set of network nodes includes the following steps:
[0028] Take the transmission path where the network node appears as the target transmission path;
[0029] Take the remaining network nodes different from the network node in the target transmission path as the target network nodes;
[0030] Judge whether the network node is a necessary node for the data transmission of the target network node. If so, add the target network node to the association set of network nodes. If not, do nothing. The initial state of the association set of network nodes is an empty set.
[0031] Preferably, the step of calculating the risk coefficient of historical security vulnerabilities based on the effect of historical security vulnerabilities includes the following steps:
[0032] Based on historical data, obtain the data repair cost caused by historical security vulnerabilities, obtain the data destruction amount of historical security vulnerabilities, obtain the vulnerability repairability rate of historical security vulnerabilities, and obtain the fault triggering rate of historical security vulnerabilities;
[0033] Use the risk formula to calculate the risk coefficient of historical security vulnerabilities;
[0034] The risk formula is as follows:
[0035] ,
[0036] Among them, B is the risk coefficient of historical security vulnerabilities, a is the data repair cost, b is the data destruction amount, c is the fault triggering rate, and d is the vulnerability repairability rate.
[0037] Preferably, the step of forming attack features for historical security vulnerabilities includes the following steps:
[0038] Based on historical data, obtain at least one historical attack that triggers historical security vulnerabilities;
[0039] Extract features from historical attacks to obtain at least one suspected feature;
[0040] Based on historical data, count the triggering probability of historical security vulnerabilities when the suspected feature appears;
[0041] When the triggering probability is greater than the preset probability, the suspected feature is taken as the attack feature of the historical security vulnerability, where the preset probability is set based on empirical data.
[0042] Preferably, the forming of the danger threshold for the attackable path includes the following steps:
[0043] Obtain the value range of the danger coefficient of the historical security vulnerability, equally divide the value range of the high danger coefficient to obtain at least one identification point;
[0044] Take the historical security vulnerability whose danger coefficient is equal to the value at the identification point as the target historical security vulnerability;
[0045] Summarize the attack features of the target historical security vulnerabilities to obtain the vulnerability-triggered attack;
[0046] Use the vulnerability-triggered attack to attack the attackable path. When the attack triggers a vulnerability, take the identification point as the target identification point. After the attack, use the repair strategy of the target historical security vulnerability to repair the vulnerability;
[0047] Take the minimum value of at least one target identification point as the danger threshold.
[0048] Preferably, the evaluating the attack scale of at least one network attack to obtain the overall prediction scale includes the following steps:
[0049] Obtain at least one target attackable path that satisfies the condition that the danger coefficient of the historical security vulnerability corresponding to the network attack exceeds the danger threshold of the target attackable path;
[0050] Merge the association sets corresponding to the network nodes passed by at least one target attackable path to obtain the abnormal node set;
[0051] Take the number of elements in the abnormal node set as the overall prediction scale.
[0052] Preferably, the obtaining the emergency repair speed of the network node and calculating the attack cancellation scale includes the following steps:
[0053] Obtain the emergency repair speed of the network for the network node, where the emergency repair speed is the number of attacked network nodes repaired per unit time;
[0054] Multiply the emergency repair speed by the preset time to obtain the attack cancellation scale.
[0055] A state evaluation system based on network security for implementing the above-mentioned state evaluation method based on network security, includes:
[0056] A node analysis module, which obtains the topological structure of network operation. The topological structure is composed of at least one network node and its connection relationship, analyzes the defense ability of the topological structure to obtain at least one attackable path, where the attackable path is composed of connected network nodes, and analyzes the correlation of the network nodes in the topological structure to obtain the correlation set of network nodes;
[0057] A vulnerability analysis module, which obtains at least one historical security vulnerability, calculates the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability, and forms an attack feature for the historical security vulnerability;
[0058] An attack analysis module, which obtains at least one network attack within a preset time in the network operation environment, and corresponds the network attack with the historical security vulnerability that presents the attack feature of the historical security vulnerability;
[0059] A numerical value formation module, which forms a danger critical value for the attackable path, such that when the risk coefficient is greater than the danger critical value, the historical security vulnerability corresponding to the risk coefficient causes network damage to the attackable path;
[0060] An attack prediction module, which evaluates the attack scale of at least one network attack based on the danger critical value of the attackable path to obtain the overall prediction scale;
[0061] A repair prediction module, which obtains the emergency repair speed of network nodes and calculates the attack cancellation scale;
[0062] A status evaluation module, which determines that the network security is in a normal state when the overall prediction scale does not exceed the attack cancellation scale, otherwise, determines that the network security is in an abnormal state.
[0063] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0064] By setting up a node analysis module, a vulnerability analysis module, an attack analysis module, an attack prediction module and a repair prediction module, it can analyze the transmission path according to the topological structure of network operation, and comprehensively consider the characteristics of different security vulnerabilities to estimate the damage that the security vulnerabilities may cause, so as to estimate the impact of the security vulnerabilities caused by network attacks in the network operation environment, and combine the self-repair ability of the network to make a final judgment. Thus, an evaluation result that is more consistent with the actual situation can be obtained, and the evaluation result has strong reference value, and can give an early warning at the initial moment when an abnormality appears, and then conduct targeted processing in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1Schematic flow chart of the state evaluation method based on network security according to the present invention;
[0066] Figure 2 Schematic flow chart of the process for obtaining the topological structure of network operation according to the present invention;
[0067] Figure 3 Schematic flow chart of the process for analyzing the defense power of the topological structure to obtain at least one attackable path according to the present invention;
[0068] Figure 4 Schematic flow chart of the process for analyzing the relevance of network nodes in the topological structure to obtain the association set of network nodes according to the present invention;
[0069] Figure 5 Schematic flow chart of the process for calculating the risk coefficient of historical security vulnerabilities based on the effect of historical security vulnerabilities according to the present invention;
[0070] Figure 6 Schematic flow chart of the process for forming attack features for historical security vulnerabilities according to the present invention;
[0071] Figure 7 Schematic flow chart of the process for forming a danger threshold for attackable paths according to the present invention;
[0072] Figure 8 Schematic flow chart of the process for evaluating the attack scale of at least one network attack to obtain the overall predicted scale according to the present invention;
[0073] Figure 9 Schematic flow chart of the process for obtaining the emergency repair speed of network nodes and calculating the attack cancellation scale according to the present invention. Detailed implementation manner
[0074] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.
[0075] Referring to Figure 1 As shown, a state evaluation method based on network security includes:
[0076] Obtain the topological structure of network operation, where the topological structure is composed of at least one network node and its connection relationship, analyze the defense power of the topological structure to obtain at least one attackable path, and the attackable path is composed of network node connections. Analyze the relevance of network nodes in the topological structure to obtain the association set of network nodes;
[0077] Obtain at least one historical security vulnerability, calculate the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability, and form attack features for the historical security vulnerability;
[0078] Obtain at least one network attack within a preset time in the network operating environment, and correspond the network attacks with historical security vulnerabilities that exhibit the attack characteristics of historical security vulnerabilities;
[0079] Form a danger critical value for the attackable path, such that when the danger coefficient is greater than the danger critical value, the historical security vulnerability corresponding to the danger coefficient causes network damage to the attackable path, where the danger critical values of different attackable paths are different;
[0080] Based on the danger critical value of the attackable path, evaluate the attack scale of at least one network attack to obtain an overall predicted scale, where the overall predicted scale is the attack scale within the preset time;
[0081] Obtain the emergency repair speed of the network node and calculate the attack cancellation scale;
[0082] When the overall predicted scale does not exceed the attack cancellation scale, then determine that the network security is in a normal state; otherwise, determine that the network security is in an abnormal state.
[0083] There are various types of network attacks. Therefore, the effects produced by network attacks are also different. Each network attack will trigger different security vulnerabilities, and the recognition capabilities of different network nodes may be different. Therefore, security vulnerabilities may not be recognized and no defense is carried out, resulting in the attack being successful. In addition, since network nodes may appear in multiple transmission paths, once a network node is abnormal, the corresponding transmission path may also be abnormal, depending on whether the transmission of the transmission path must pass through the network node. Therefore, it is relatively complex to estimate the scale caused by problems with network nodes. Thus, it is difficult to determine whether it exceeds the repair speed of the anti-virus software carried by the network itself, leading to a large misjudgment in the assessment of the network state. This misjudgment will result in hiring experts to repair the network under unnecessary circumstances, thereby increasing costs. Therefore, in this solution, the above-mentioned situations are handled specifically to ensure a relatively high assessment accuracy.
[0084] Refer to Figure 2 As shown, obtaining the topological architecture of network operation includes the following steps:
[0085] Obtain at least one network node used for data transmission during network operation and at least one transmission path used for data transmission during network operation;
[0086] Correspond the network nodes passed by the transmission path with the transmission path, and the network nodes corresponding to the same transmission path have a connected relationship;
[0087] Summarize the correspondence between the network nodes and the transmission paths and the transmission paths to obtain the topological architecture of network operation.
[0088] The transmission paths may cross each other.
[0089] Refer to Figure 3 As shown, to perform a defense analysis on the topology architecture and obtain at least one attackable path, the following steps are included:
[0090] Based on historical data, obtain the repair strategies for historical security vulnerabilities;
[0091] Use the historical security vulnerabilities to perform tests on the network nodes for a preset number of times. After each test, use the repair strategies for the historical security vulnerabilities to repair the network nodes;
[0092] Divide the number of times the network nodes correctly identify the historical security vulnerabilities by the preset number of times to obtain the correct identification rate. Take the average of the correct identification rates of the network nodes relative to at least one historical security vulnerability to obtain the average correct identification rate;
[0093] Use the defense formula to calculate the vulnerability identification rate of the transmission path;
[0094] When the vulnerability identification rate is lower than the preset value, then regard the transmission path as an attackable path;
[0095] The defense formula is as follows:
[0096] ,
[0097] where A is the vulnerability identification rate, i is the subscript, n is the total number of network nodes in the transmission path, is the average correct identification rate of the i-th network node in the transmission path.
[0098] Once the network nodes in the transmission path cannot identify the historical security vulnerabilities, they will not make defenses, and thus the vulnerabilities will occur. Therefore, the transmission path where the network nodes are located will be abnormal due to the network nodes being attacked. Since the appearance of any network node in the transmission path will cause the abnormality of the transmission path, when judging whether the transmission path is an attackable path, it is necessary to multiply the average correct identification rates of all the network nodes in the transmission path. The obtained vulnerability identification rate can reflect whether the transmission path will be attacked by historical security vulnerabilities.
[0099] Refer to Figure 4 As shown, to perform a correlation analysis on the network nodes in the topology architecture and obtain the correlation set of the network nodes, the following steps are included:
[0100] Regard the transmission paths where the network nodes appear as the target transmission paths;
[0101] Regard the remaining network nodes in the target transmission paths that are different from the network nodes as the target network nodes;
[0102] Determine whether the network node is a necessary node for the data transmission of the target network node. If so, add the target network node to the associated set of network nodes. If not, do nothing. The initial state of the associated set of network nodes is an empty set.
[0103] It should be noted that when a network node has an anomaly, the network nodes in the target transmission path may not necessarily have an anomaly, because there may be other paths in the target transmission path that do not pass through the network node with the anomaly. This is because the transmission paths intersect with each other, and the transmission can be completed through other network nodes.
[0104] The data transmission of the elements in the associated set must pass through the network node. Therefore, when a network node has an anomaly, the elements in the associated set will surely have an anomaly as well. Thus, based on this, an estimation can be made on the total number of network nodes with anomalies.
[0105] Refer to Figure 5 As shown, calculating the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability includes the following steps:
[0106] Based on historical data, obtain the data repair cost caused by the historical security vulnerability, obtain the data destruction amount of the historical security vulnerability, obtain the vulnerability repairability rate of the historical security vulnerability, and obtain the fault triggering rate of the historical security vulnerability.
[0107] Use the risk formula to calculate the risk coefficient of the historical security vulnerability.
[0108] The risk formula is as follows:
[0109] ,
[0110] where B is the risk coefficient of the historical security vulnerability, a is the data repair cost, b is the data destruction amount, c is the fault triggering rate, and d is the vulnerability repairability rate.
[0111] The risk coefficient of the historical security vulnerability is used to estimate the degree of danger of the historical security vulnerability. Thus, based on the correspondence between the historical security vulnerability and the network attack, it can be determined which attackable paths will be successfully attacked by the network attack. Since the defense capabilities of each attackable path are different, the scale of the attack can be estimated based on the attackable paths that are successfully attacked.
[0112] Refer to Figure 6 As shown, forming an attack feature for the historical security vulnerability includes the following steps:
[0113] Based on historical data, obtain at least one historical attack that triggers the historical security vulnerability.
[0114] Extract features from historical attacks to obtain at least one suspected feature;
[0115] Based on historical data, statistically calculate the triggering probability of historical security vulnerabilities when the suspected feature appears;
[0116] When the triggering probability is greater than the preset probability, the suspected feature is used as the attack feature of the historical security vulnerability, where the preset probability is set based on empirical data.
[0117] Historical security vulnerabilities require triggering conditions, which are various attacks existing in the network. To identify the attacks that trigger historical security vulnerabilities, feature extraction is required. Therefore, the attack features corresponding to historical security vulnerabilities are obtained. To avoid misidentification, the triggering probability is also statistically calculated to ensure there is a correlation between the two. Thus, network attacks can be corresponded to historical security vulnerabilities according to the attack features.
[0118] Refer to Figure 7 As shown, forming a danger threshold for an attackable path includes the following steps:
[0119] Obtain the value range of the danger coefficient of historical security vulnerabilities, equally divide the value range of the high danger coefficient to obtain at least one identification point;
[0120] Use the historical security vulnerabilities with the danger coefficient equal to the value at the identification point as the target historical security vulnerabilities;
[0121] Summarize the attack features of the target historical security vulnerabilities to obtain a vulnerability-triggering attack;
[0122] Use the vulnerability-triggering attack to attack the attackable path. When the attack triggers a vulnerability, use the identification point as the target identification point. After the attack, use the repair strategy of the target historical security vulnerability to repair the vulnerability;
[0123] Use the minimum value of at least one target identification point as the danger threshold.
[0124] Since the composition of each attackable path is different, the threshold triggered by vulnerabilities is also different. Therefore, it is necessary to form its corresponding danger threshold for each attackable path.
[0125] Refer to Figure 8 As shown, evaluating the attack scale of at least one network attack to obtain the overall prediction scale includes the following steps:
[0126] Obtain at least one target attackable path that satisfies that the danger coefficient of the historical security vulnerability corresponding to the network attack exceeds the danger threshold of the target attackable path;
[0127] Merge the association sets corresponding to the network nodes through which at least one target attackable path passes to obtain a set of abnormal nodes;
[0128] Use the number of elements in the set of abnormal nodes as the overall prediction scale.
[0129] Since the target attackable path is a path that can be successfully attacked, all the network nodes it passes through have the possibility of being successfully attacked. Therefore, it will also cause all the elements in the association sets corresponding to the network nodes passed by the target attackable path to be abnormal. Thus, the overall prediction scale can be obtained by merging.
[0130] Refer to Figure 9 As shown, to obtain the emergency repair speed of network nodes and calculate the attack cancellation scale, the following steps are included:
[0131] Obtain the emergency repair speed of the network for network nodes. The emergency repair speed is the number of attacked network nodes repaired per unit time;
[0132] Multiply the emergency repair speed by the preset time to obtain the attack cancellation scale.
[0133] The network itself has settings for defense mechanisms such as anti-virus software. The network anomaly must be due to the repair speed being less than the attack speed. Since both the overall prediction scale and the attack cancellation scale are statistical results within the preset time, the comparison between the two can be used as the basis for anomaly judgment.
[0134] A state evaluation system based on network security for implementing the above-mentioned state evaluation method based on network security, including:
[0135] A node analysis module that obtains the topological structure of network operation. The topological structure consists of at least one network node and its connection relationships, analyzes the defense capabilities of the topological structure to obtain at least one attackable path, where the attackable path is composed of network node connections, and analyzes the correlation of network nodes in the topological structure to obtain the association sets of network nodes;
[0136] A vulnerability analysis module that obtains at least one historical security vulnerability, calculates the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability, and forms an attack feature for the historical security vulnerability;
[0137] An attack analysis module that obtains at least one network attack within the preset time in the network operation environment, and correlates the network attacks with historical security vulnerabilities that exhibit the attack features of historical security vulnerabilities;
[0138] A numerical value forming module, which forms a danger critical value for an attackable path, such that when the danger coefficient is greater than the danger critical value, the historical security vulnerabilities corresponding to the danger coefficient cause network damage to the attackable path;
[0139] An attack prediction module, which evaluates the attack scale of at least one network attack based on the danger critical value of the attackable path to obtain an overall predicted scale;
[0140] A repair prediction module, which obtains the emergency repair speed of network nodes and calculates the attack cancellation scale;
[0141] A status evaluation module, which determines that the network security is in a normal state when the overall predicted scale does not exceed the attack cancellation scale, otherwise, determines that the network security is in an abnormal state.
[0142] Furthermore, this solution also proposes a storage medium, on which a computer-readable program is stored. When the computer-readable program is called, it executes the above-mentioned state evaluation method based on network security.
[0143] It can be understood that the storage medium can be a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape; an optical medium such as a DVD; or a semiconductor medium such as a solid state disk (SSD), etc.
[0144] In summary, the advantages of the present invention are as follows: By setting up a node analysis module, a vulnerability analysis module, an attack analysis module, an attack prediction module, and a repair prediction module, it is possible to analyze the transmission path according to the topological structure of network operation, and comprehensively consider the characteristics of different security vulnerabilities to estimate the damage that may be caused by security vulnerabilities, so as to estimate the impact of security vulnerabilities caused by network attacks in the network operation environment, and combine the self-repair ability of the network to make a final judgment. Therefore, an evaluation result that is more consistent with the actual situation can be obtained, and the evaluation result has strong reference value, and can give an early warning at the initial moment when an anomaly appears, and then carry out targeted processing in a timely manner.
[0145] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A state evaluation method based on network security, characterized in that, Including: Obtain the topological architecture of network operation, which is composed of at least one network node and its connection relationship. Conduct a defense analysis on the topological architecture to obtain at least one attackable path, where the attackable path is composed of connected network nodes. Conduct a correlation analysis on the network nodes in the topological architecture to obtain the correlation set of network nodes; Obtain at least one historical security vulnerability. Based on the effect of the historical security vulnerability, calculate the risk coefficient of the historical security vulnerability and form an attack feature for the historical security vulnerability; Obtain at least one network attack within a preset time in the network operation environment, and correspond the network attack that presents the attack feature of the historical security vulnerability with the historical security vulnerability; Form a danger threshold for the attackable path, such that when the risk coefficient is greater than the danger threshold, the historical security vulnerability corresponding to the risk coefficient causes network damage to the attackable path, where the danger thresholds for different attackable paths are different; Based on the danger threshold of the attackable path, evaluate the attack scale of at least one network attack to obtain the overall predicted scale, and the overall predicted scale is the attack scale within the preset time; Obtain the emergency repair speed of the network node and calculate the attack offset scale; When the overall predicted scale does not exceed the attack offset scale, then determine that the network security is in a normal state, otherwise, determine that the network security is in an abnormal state.
2. The state evaluation method based on network security according to claim 1, characterized in that The obtaining the topological architecture of network operation includes the following steps: Obtain at least one network node for data transmission during network operation and at least one transmission path for data transmission during network operation; Correspond the network nodes passed by the transmission path with the transmission path, and the network nodes corresponding to the same transmission path have a connectivity relationship; Summarize the correspondence relationship between the network nodes and the transmission path and the transmission path to obtain the topological architecture of network operation.
3. The state evaluation method based on network security according to claim 2, wherein, The conducting a defense analysis on the topological architecture to obtain at least one attackable path includes the following steps: Based on historical data, obtain the repair strategy of the historical security vulnerability; Use the historical security vulnerability to test the network node a preset number of times. After each test, use the repair strategy of the historical security vulnerability to repair the network node; Divide the number of times the network node correctly identifies the historical security vulnerability by the preset number of times to obtain the recognition accuracy rate, and take the average of the recognition accuracy rates of the network node relative to at least one historical security vulnerability to obtain the average recognition accuracy; Use the defense formula to calculate the vulnerability recognition rate of the transmission path; When the vulnerability recognition rate is lower than the preset value, then take the transmission path as an attackable path; The defense formula is as follows: , Where A is the vulnerability recognition rate, i is the subscript, and n is the total number of network nodes in the transmission path. is the average correct recognition of the i-th network node in the transmission path.
4. The state evaluation method based on network security according to claim 3, wherein, The conducting a correlation analysis on the network nodes in the topological architecture to obtain the correlation set of network nodes includes the following steps: Take the transmission path where the network node appears as the target transmission path; Take the remaining network nodes in the target transmission path that are different from the network node as the target network nodes; Judge whether the network node is a necessary node for the data transmission of the target network node. If so, then include the target network node in the correlation set of network nodes. If not, then do nothing. The initial state of the correlation set of network nodes is an empty set.
5. A state evaluation method based on network security according to claim 4, characterized in that, Calculating the risk coefficient of historical security vulnerabilities based on the effects of historical security vulnerabilities includes the following steps: Based on historical data, obtain the data repair cost caused by historical security vulnerabilities, obtain the data destruction volume of historical security vulnerabilities, obtain the vulnerability repairability rate of historical security vulnerabilities, and obtain the fault triggering rate of historical security vulnerabilities; Use the risk formula to calculate the risk coefficient of historical security vulnerabilities; The risk formula is as follows: , Among them, B is the risk coefficient of historical security vulnerabilities, a is the data repair cost, b is the data destruction volume, c is the fault triggering rate, and d is the vulnerability repairability rate.
6. The state evaluation method based on network security according to claim 5, wherein, Forming attack features for historical security vulnerabilities includes the following steps: Based on historical data, obtain at least one historical attack that triggers a historical security vulnerability; Extract features from the historical attack to obtain at least one suspected feature; Based on historical data, statistically calculate the triggering probability of historical security vulnerabilities when the suspected feature appears; When the triggering probability is greater than the preset probability, the suspected feature is used as the attack feature of the historical security vulnerability, where the preset probability is set based on empirical data.
7. A state evaluation method based on network security according to claim 6, characterized in that, Forming a danger threshold for attackable paths includes the following steps: Obtain the value range of the risk coefficient of historical security vulnerabilities, equally spaced share the value range of high-risk coefficients to obtain at least one identification point; Use the historical security vulnerabilities with the risk coefficient equal to the value at the identification point as the target historical security vulnerabilities; Summarize the attack features of the target historical security vulnerabilities to obtain a vulnerability-triggering attack; Use the vulnerability-triggering attack to attack the attackable path. When the attack triggers a vulnerability, use the identification point as the target identification point. After the attack, use the repair strategy of the target historical security vulnerability to repair the vulnerability; Use the minimum value of at least one target identification point as the danger threshold.
8. A state evaluation method based on network security according to claim 7, characterized in that Evaluating the attack scale of at least one network attack to obtain the overall prediction scale includes the following steps: Obtain at least one target attackable path that satisfies the condition that the risk coefficient of the historical security vulnerability corresponding to the network attack exceeds the danger threshold of the target attackable path; Merge the association sets corresponding to the network nodes passed by at least one target attackable path to obtain an abnormal node set; Use the number of elements in the abnormal node set as the overall prediction scale.
9. A state evaluation method based on network security according to claim 8, characterized in that, Obtaining the emergency repair speed of network nodes and calculating the attack cancellation scale includes the following steps: Obtain the emergency repair speed of the network for network nodes. The emergency repair speed is the number of attacked network nodes repaired per unit time; Multiply the emergency repair speed by the preset time to obtain the attack cancellation scale.
10. A state evaluation system based on network security, which is used to implement the state evaluation method based on network security according to any one of claims 1-9, characterized in that, Includes: A node analysis module. The node analysis module obtains the topological structure of network operation. The topological structure is composed of at least one network node and its connection relationship. Analyze the defense force of the topological structure to obtain at least one attackable path. The attackable path is composed of network node connections. Analyze the correlation of network nodes in the topological structure to obtain the association set of network nodes; Vulnerability analysis module, which obtains at least one historical security vulnerability, calculates the risk coefficient of the historical security vulnerability based on the effect of the historical security vulnerability, and forms an attack feature for the historical security vulnerability; Attack analysis module, which obtains at least one network attack within a preset time in the network operating environment, and correlates the network attack with the historical security vulnerability that presents the attack feature of the historical security vulnerability; Numerical formation module, which forms a danger critical value for the attackable path, such that when the risk coefficient is greater than the danger critical value, the historical security vulnerability corresponding to the risk coefficient causes network damage to the attackable path; Attack prediction module, which evaluates the attack scale of at least one network attack based on the danger critical value of the attackable path to obtain the overall predicted scale; Repair prediction module, which obtains the emergency repair speed of the network node and calculates the attack cancellation scale; Status evaluation module, which determines that the network security is in a normal state when the overall predicted scale does not exceed the attack cancellation scale, otherwise, determines that the network security is in an abnormal state.
Citation Information
Patent Citations
Network security emergency capability determination method and apparatus, and electronic device
CN110535859A
Network security test and evaluation system and method
CN117155703A