Security assessment method and device, and storage medium
By acquiring attack instances and user behavior characteristics, combined with abnormal behavior indices and source tracing analysis, the security assessment device accurately assesses the security of the object to be assessed, solving the problem of inaccurate assessment caused by subjective judgment in existing technologies, and achieving objective and efficient security assessment.
Patent Information
- Application Number
- CN202510089363.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2045-01-20
AI Technical Summary
In existing technologies, technicians assess the safety of the object under evaluation through subjective judgment, which lacks objectivity and accuracy and cannot accurately assess the safety of the object under evaluation.
Security assessment devices are used to obtain attack instances and their historical behavior information. The weight of the risk assessment value is determined based on the frequency of the attack instances and the level of the security incident. Combined with user behavior characteristics and abnormal behavior index, an attack evidence chain is constructed to trace the source of the attack and achieve security assessment.
This ensures the accuracy of the safety assessment results for the assessed objects, avoids misjudgments or omissions caused by subjective judgment, and improves the objectivity and accuracy of the assessment.
Smart Images

Figure CN119788408B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a security evaluation method and device and a storage medium. BACKGROUND
[0002] With the rapid development of information technology, big data has become an important resource in today's society. However, the collection, storage, processing and transmission of big data are all faced with various security threats. These threats not only may lead to the leakage of enterprise or personal information, but also may have a serious impact on collective security.
[0003] In the related art, a technician identifies and counts current risk information, and based on the current risk information, the security of an object to be evaluated is evaluated by a subjective judgment method. However, the subjective judgment of the technician lacks objectivity and accuracy, and the security of the object to be evaluated cannot be accurately evaluated. Therefore, how to improve the accuracy of evaluating the object to be evaluated is still a technical problem to be solved. SUMMARY
[0004] The present application provides a security evaluation method and device and a storage medium, which are used to improve the accuracy of evaluating an object to be evaluated.
[0005] To achieve the above object, the present application adopts the following technical solutions:
[0006] In a first aspect, the present application provides a security evaluation method. A security evaluation device obtains attack instances to which an object to be evaluated is subjected, and historical behavior information of the attack instances. The historical behavior information includes a frequency of occurrence of the attack instances and / or a security event level caused by the attack instances. The security evaluation device determines a security evaluation result of the object to be evaluated according to the attack instances and the historical behavior information of the attack instances.
[0007] In a possible implementation manner, an attack type of each attack instance in the attack instances is obtained. A risk evaluation value of each attack instance is determined according to the attack type of the attack instance. A weight of the risk evaluation value of the attack instance is determined according to the frequency of occurrence of the attack instance and / or the security event level caused by the attack instance. The weight of the risk evaluation value of the attack instance is negatively correlated with the frequency of occurrence of the attack instance. The security evaluation result of the object to be evaluated is determined according to the risk evaluation value of the attack instance and the weight of the risk evaluation value of the attack instance.
[0008] In a possible implementation manner, a user behavior feature of the object to be evaluated is obtained. The user behavior feature includes abnormal behavior data. An abnormal behavior index is determined according to the abnormal behavior data. The security evaluation result of the object to be evaluated is determined according to the attack instances, the historical behavior information of the attack instances and the abnormal behavior index.
[0009] In a possible implementation, the abnormal behavior index is determined according to a relationship between the abnormal behavior data and normal behavior data.
[0010] In a possible implementation, when the security evaluation result of the to-be-evaluated object indicates that the to-be-evaluated object has a security risk, the data source feature of the attack instance is obtained; and the attack source is determined according to the data source feature of the attack instance.
[0011] In a possible implementation, the corresponding attack evidence of the attack instance is obtained; the attack evidence is used to record data information of the attack instance; the attack evidence chain is constructed according to the attack evidence and the attack source; the attack evidence chain is used to represent an attack path of the attack instance; the traceability function of each piece of evidence chain in the attack evidence chain is obtained; and the accuracy of the traceability analysis result of the attack source is determined according to the traceability function of each piece of evidence chain in the attack evidence chain.
[0012] In a second aspect, the present application provides a security evaluation device, comprising: an obtaining unit and a processing unit; the obtaining unit is used to obtain an attack instance and historical behavior information of the attack instance suffered by a to-be-evaluated object; the historical behavior information comprises a frequency of occurrence of the attack instance and / or a security event level caused by the attack instance; and the processing unit is used to determine a security evaluation result of the to-be-evaluated object according to the attack instance and the historical behavior information of the attack instance.
[0013] In a possible implementation, the obtaining unit is further used to obtain an attack type of each attack instance in the attack instance; the processing unit is further used to determine a risk evaluation value of each attack instance according to the attack type of the attack instance; the processing unit is further used to determine a weight of the risk evaluation value of the attack instance according to the frequency of occurrence of the attack instance and / or the security event level caused by the attack instance; the weight of the risk evaluation value of the attack instance is negatively correlated with the frequency of occurrence of the attack instance; and the processing unit is further used to determine the security evaluation result of the to-be-evaluated object according to the risk evaluation value of the attack instance and the weight of the risk evaluation value of the attack instance.
[0014] In a possible implementation, the obtaining unit is further used to obtain a user behavior feature of the to-be-evaluated object; the user behavior feature comprises abnormal behavior data; the processing unit is further used to determine an abnormal behavior index according to the abnormal behavior data; and the processing unit is further used to determine the security evaluation result of the to-be-evaluated object according to the attack instance, the historical behavior information of the attack instance, and the abnormal behavior index.
[0015] In a possible implementation, the processing unit is further used to determine the abnormal behavior index according to a relationship between the abnormal behavior data and normal behavior data.
[0016] In a possible implementation, when the security evaluation result of the object to be evaluated indicates that the object to be evaluated has a security risk, the obtaining unit is further configured to obtain a data source feature of the attack instance; and the processing unit is further configured to determine the attack source according to the data source feature of the attack instance.
[0017] In a possible implementation, the obtaining unit is further configured to obtain corresponding attack evidence of the attack instance, the attack evidence being used to record data information of the attack instance; and the processing unit is further configured to construct an attack evidence chain according to the attack evidence and the attack source, the attack evidence chain being used to represent an attack path of the attack instance; the obtaining unit is further configured to obtain a traceability function of each piece of evidence chain in the attack evidence chain; and the processing unit is further configured to determine an accuracy of the traceability analysis result of the attack source according to the traceability function of each piece of evidence chain in the attack evidence chain.
[0018] In a third aspect, a security evaluation device is provided, which includes a processor and a memory; the memory is configured to store computer execution instructions; when the security evaluation device is running, the processor executes the computer execution instructions stored in the memory, so that the security evaluation device performs the security evaluation method described in the first aspect and any possible implementation manner of the first aspect.
[0019] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores instructions; when the instructions in the computer readable storage medium are executed by a processor of a security evaluation device, the security evaluation device can perform the security evaluation method described in the first aspect and any possible implementation manner of the first aspect.
[0020] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is configured to run a computer program or instructions, so as to implement the security evaluation method described in the first aspect and any possible implementation manner of the first aspect.
[0021] In a sixth aspect, a computer program product including instructions is provided, when the computer program product is run on a computer, the computer can execute the security evaluation method described in the first aspect and any possible implementation manner of the first aspect.
[0022] These aspects and other aspects of the present application will be more apparent in the following description.
[0023] The above scheme at least has the following beneficial effects: in the embodiment of the application, the current behavior of the attack type is predicted considering the historical behavior information of the attack instance, and the frequency of the attack instance in the historical behavior information of the attack instance and the security event level caused by the attack instance in the historical behavior information of the attack instance are both negatively correlated with the security of the to-be-evaluated object, so that the security evaluation device can accurately determine the security evaluation result of the to-be-evaluated object according to the attack instance and the historical behavior information of the attack instance. Compared with the prior art, the security evaluation device in the embodiment of the application does not need to rely on the subjective judgment of the relevant technical personnel to evaluate the security of the to-be-evaluated object, avoids the judgment of the staff influencing objectivity, leads to misjudgment or omission, and achieves the purpose of accurately evaluating the to-be-evaluated object. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0025] Figure 1 A structural schematic diagram of a security evaluation system provided by an embodiment of the application is shown in the figure.
[0026] Figure 2 A structural schematic diagram of a security evaluation device provided by an embodiment of the application is shown in the figure.
[0027] Figure 3 A flowchart of a security evaluation method provided by an embodiment of the application is shown in the figure.
[0028] Figure 4 A flowchart of another security evaluation method provided by an embodiment of the application is shown in the figure.
[0029] Figure 5 A flowchart of another security evaluation method provided by an embodiment of the application is shown in the figure.
[0030] Figure 6 A flowchart of another security evaluation method provided by an embodiment of the application is shown in the figure.
[0031] Figure 7 A flowchart of another security evaluation method provided by an embodiment of the application is shown in the figure.
[0032] Figure 8 A flowchart of another security evaluation method provided by an embodiment of the application is shown in the figure.
[0033] Figure 9 A structural schematic diagram of another security evaluation device provided by an embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0034] The term "and / or", used in the present application, only describes an association relationship of associated objects, and means that three relationships can exist, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone.
[0035] The terms "first" and "second" and the like in the description of the present application and the drawings are used to distinguish different objects or to distinguish different treatments of the same object, and are not used to describe a specific order of the objects.
[0036] In addition, the terms "include" and "have" and any variations thereof mentioned in the description of the present application are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include other steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.
[0037] It should be noted that in the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or having more advantages than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present relevant concepts in a concrete manner.
[0038] In the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise specified.
[0039] With the rapid development of information technology, big data has become an important resource in today's society. However, the collection, storage, processing and transmission of big data face various security threats. These threats not only may lead to the leakage of enterprise or personal information, but also may have a serious impact on collective security.
[0040] In the related art, a technician identifies and counts current risk information, and based on the current risk information, assesses the security of an object to be assessed by a subjective judgment method. However, the subjective judgment of the technician lacks objectivity and accuracy, and cannot accurately assess the security of the object to be assessed. Therefore, how to improve the accuracy of assessing the object to be assessed is still a technical problem to be solved.
[0041] In order to solve the technical problems in the related art, the historical behavior information of the attack instance is considered in the embodiment of the present application, the current behavior of the attack type can be predicted, and the frequency of the attack instance in the historical behavior information of the attack instance and the security event level caused by the attack instance in the historical behavior information of the attack instance are both negatively correlated with the security of the to-be-evaluated object. Therefore, the security evaluation device can accurately determine the security evaluation result of the to-be-evaluated object according to the attack instance and the historical behavior information of the attack instance. Compared with the prior art, the security evaluation device in the embodiment of the present application does not need to rely on the subjective judgment of the related technical personnel to evaluate the security of the to-be-evaluated object, avoids the judgment of the staff influencing the objectivity, leads to misjudgment or omission, and achieves the purpose of accurately evaluating the to-be-evaluated object.
[0042] In the following, the security evaluation system 10 provided by the embodiment of the present application is described in detail. Figure 1 The security evaluation system 10 includes a security evaluation device 11 and a to-be-evaluated object 12, as shown in the figure. Figure 1
[0043] The security evaluation device 11 can be deployed in the to-be-evaluated object 12 or outside the to-be-evaluated object 12.
[0044] The security evaluation device 11 can obtain the attack instance suffered by the to-be-evaluated object 12, and then obtain the historical behavior information of the attack instance. Subsequently, the security evaluation device 11 can refer to the historical behavior information of the attack instance to determine the security evaluation result of the to-be-evaluated object 12.
[0045] It should be noted that the security evaluation device 11 is a device with wireless communication function, which can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted. It can also be deployed on water (such as ships, etc.). It can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The user terminal device is also called mobile station (MS), mobile terminal (MT) and terminal device, which is a device that provides voice and / or data connectivity to users. For example, the terminal device includes handheld devices with wireless connection function, vehicle-mounted devices, etc. At present, the terminal device can be: mobile phone, tablet computer, notebook computer, palm computer, mobile internet device (MID), wearable device (such as smart watch, smart bracelet, pedometer, etc.), vehicle-mounted device (such as car, bicycle, electric vehicle, airplane, ship, train, high-speed rail, etc.), virtual reality (VR) device, augmented reality (AR) device, wireless terminal device in industrial control, smart home device (such as refrigerator, television, air conditioner, electric meter, etc.), smart robot, workshop equipment, wireless terminal device in self driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, or wireless terminal device in smart home, flight equipment (such as smart robot, hot air balloon, unmanned aerial vehicle, airplane), etc. In a possible application scenario of the present application, the security evaluation device 11 is a terminal device that usually works on the ground, such as a vehicle-mounted device. In the present application, in order to facilitate description, the chip deployed in the above device, such as system on a chip (SOC), baseband chip, etc., or other communication function chip can also be called user terminal device.
[0046] Optionally, the security evaluation device 11 can be an embedded communication device, or a user handheld communication device, including mobile phone, tablet computer, etc.
[0047] As an example, in this embodiment, the safety assessment device 11 can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0048] Optionally, the physical device of the object to be evaluated, 12, can be a server.
[0049] Optionally, the server mentioned above can be one of the servers in a server cluster (composed of multiple servers), a chip in the server, a system-on-a-chip in the server, or a virtual machine (VM) deployed on a physical machine. This application embodiment does not limit this.
[0050] This application provides a security assessment apparatus for executing the security assessment system provided in this application. Figure 2 This is a schematic diagram of a safety assessment device provided in an embodiment of this application. Figure 2 As shown, the security assessment device 200 includes a processor 201, a communication line 202, and a communication interface 204, and may also include a memory 203. The processor 201, memory 203, and communication interface 204 can be connected via the communication line 202.
[0051] The processor 201 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0052] Communication line 202 may include a path for transmitting information between the aforementioned components.
[0053] The communication interface 204, configured to communicate with other devices or communication networks, can use any transceiver device, such as Ethernet, radio access network (RAN), WLAN, etc.
[0054] The memory 203 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this.
[0055] In one possible design, the memory 203 can exist independently of the processor 201, i.e., the memory 203 can be an external memory of the processor 201, and the memory 203 can be connected to the processor 201 through the communication line 202, used to store execution instructions or application program codes, and controlled by the processor 201 to perform, to implement the security evaluation method provided by the embodiments of the present application. In another possible design, the memory 203 can also be integrated with the processor 201, i.e., the memory 203 can be an internal memory of the processor 201, for example, the memory 203 is a cache, which can be used to temporarily store some data and instruction information, etc.
[0056] As one possible implementation, the processor 201 can include one or more CPUs, for example, the CPU0 and the CPU1 in FIG. 1. As another possible implementation, the security evaluation apparatus 200 can include multiple processors, for example, the processor 201 and the processor 207 in FIG. 1. As still another possible implementation, the security evaluation apparatus 200 can further include the output device 205 and the input device 206. Figure 2 Figure 2 As one possible implementation, the processor 201 can include one or more CPUs, for example, the CPU0 and the CPU1 in FIG. 1. As another possible implementation, the security evaluation apparatus 200 can include multiple processors, for example, the processor 201 and the processor 207 in FIG. 1. As still another possible implementation, the security evaluation apparatus 200 can further include the output device 205 and the input device 206.
[0057] In the following, the security evaluation method provided by the embodiments of the present application will be described in detail, for example, the security evaluation method provided by the embodiments of the present application can be implemented by the security evaluation apparatus 200. Figure 3 Figure 3 As shown, the security evaluation method includes S301-S302.
[0058] S301, the security evaluation device acquires an attack instance suffered by the to-be-evaluated object and historical behavior information of the attack instance.
[0059] The historical behavior information includes a frequency of occurrence of the attack instance and / or a security event level caused by the attack instance.
[0060] Optionally, the attack instance includes at least one of the following: a re-identification attack, a statistical inference attack, and a differential attack. The attack instance can be an attack event.
[0061] It should be explained that the re-identification attack refers to a process of re-associating anonymized / de-identified data to an original personal information subject or a group of personal information subjects, and the re-identification attack is a reverse operation of anonymization / de-identification. The statistical inference attack is an attack mode of deriving sensitive information according to one or more statistical results. The differential attack is an attack mode of attacking a cryptographic algorithm by comparing and analyzing changes in propagation of plaintexts with specific differences after encryption.
[0062] In a possible implementation, the security evaluation device sends first request information to the to-be-evaluated object, receives first request response information from the to-be-evaluated object, and determines the attack instance suffered by the to-be-evaluated object according to a data set in the first request response information. The security evaluation device acquires the historical behavior information of the attack instance from a historical database according to the attack instance suffered by the to-be-evaluated object.
[0063] Optionally, the historical database stores at least one attack instance and historical behavior information corresponding to the at least one attack instance.
[0064] It can be understood that the security evaluation device acquires the attack instance suffered by the to-be-evaluated object, and further acquires the historical behavior information of the attack instance, so that the security evaluation device can refer to the historical behavior information of the attack instance to evaluate an impact of the attack instance on the to-be-evaluated object.
[0065] S302, the security evaluation device determines a security evaluation result of the to-be-evaluated object according to the attack instance and the historical behavior information of the attack instance.
[0066] In a possible implementation, the security evaluation device determines the security evaluation result of the to-be-evaluated object according to a risk evaluation function of each attack instance in a plurality of attack instances.
[0067] The above solution offers at least the following advantages: In this embodiment, considering the historical behavior information of attack instances, the current behavior of the attack type can be predicted. Furthermore, the frequency of attack instances in the historical behavior information and the security event level caused by these attack instances are negatively correlated with the security of the object to be evaluated. Therefore, the security assessment device can accurately determine the security assessment result of the object to be evaluated based on the attack instances and their historical behavior information. Compared with existing technologies, the security assessment device in this embodiment does not require the subjective judgment of relevant technical personnel to assess the security of the object to be evaluated, avoiding the influence of staff on objectivity and preventing misjudgments or omissions, thus achieving the goal of accurately assessing the object to be evaluated.
[0068] In one possible implementation, combining Figure 3 ,like Figure 4 As shown in S302, the process by which the security assessment device determines the security assessment result of the object to be assessed based on the attack instance and the historical behavior information of the attack instance can be specifically implemented through the following S401-S404.
[0069] S401. The security assessment device obtains the attack type of each attack instance in the attack instances.
[0070] Optionally, attack examples include: re-identification attacks, statistical inference attacks, and differential attacks.
[0071] In one possible implementation, the security assessment device acquires the data characteristics corresponding to the attack instance, and determines the attack type of each attack instance in the attack instance based on the data characteristics corresponding to the attack instance.
[0072] Understandably, the security assessment device obtains the attack type of each attack instance in the attack instance, and then determines the security assessment result of the object to be assessed based on the different types of attack instances.
[0073] S402. The security assessment device determines the risk assessment value of each attack instance based on the attack type of the attack instance.
[0074] In one possible implementation, when the attack type of the attack instance is a re-identification attack, the security assessment device determines a re-identification attack risk assessment function based on the sensitivity of the dataset and the quantity and quality of personal identification information. The security assessment device then determines the risk assessment value of the re-identification attack instance based on this risk assessment function.
[0075] It should be explained that the reidentification attack risk assessment function will analyze the possibility that attackers can use known personal identification data to relocate and identify specific personal privacy information.
[0076] In another possible implementation, when the attack type of the attack instance is a statistical inference attack, the security evaluation apparatus determines a statistical inference attack risk evaluation function according to statistical characteristics and correlation analysis of the data.
[0077] It should be explained that the statistical inference attack function will evaluate the possibility of an attacker inferring sensitive information or private data by analyzing statistical characteristics in a large data set.
[0078] In another possible implementation, when the attack type of the attack instance is a differential attack, the security evaluation apparatus determines a differential attack risk evaluation function according to security, key length and complexity of the cryptographic algorithm. The security evaluation apparatus determines the risk evaluation value of the differential attack instance according to the differential attack risk evaluation function.
[0079] It should be explained that the differential attack function will analyze the possibility of an attacker extracting a key by using a chosen plaintext attack method of a block cipher.
[0080] S403, the security evaluation apparatus determines the weight of the risk evaluation value of the attack instance according to the frequency of the attack instance and / or the security event level caused by the attack instance.
[0081] The weight of the risk evaluation value of the attack instance is negatively related to the frequency of the attack instance, and the weight of the risk evaluation value of the attack instance is negatively related to the security event level caused by the attack instance.
[0082] In one possible implementation, the security evaluation apparatus obtains the frequency of the attack instance and a frequency threshold, and determines the weight of the risk evaluation value of the attack instance according to the relationship between the frequency of the attack instance and the frequency threshold.
[0083] In another possible implementation, the security evaluation apparatus obtains the security event level caused by the attack instance and a level threshold, and determines the weight of the risk evaluation value of the attack instance according to the relationship between the security event level caused by the attack instance and the level threshold.
[0084] In another possible implementation, the security evaluation apparatus obtains the frequency of the attack instance, the security event level caused by the attack instance, the frequency threshold and the level threshold, and determines the weight of the risk evaluation value of the attack instance according to the relationship between the frequency of the attack instance and the frequency threshold and the relationship between the security event level caused by the attack instance and the level threshold.
[0085] S404, the security evaluation apparatus determines the security evaluation result of the to-be-evaluated object according to the risk evaluation value of the attack instance and the weight of the risk evaluation value of the attack instance.
[0086] In one possible implementation, the security assessment result of the object to be assessed, the risk assessment value of the attack instance, and the weight of the risk assessment value of the attack instance satisfy the following formula:
[0087]
[0088] Where R(t) is the total risk value within time t, x i (s) represents a re-identification attack instance, y i (s) represents a statistical inference attack, z i (s) represents a differential attack instance, f re-id (x i (s) is the re-identification attack risk assessment function, f stat-inf (y i (s) is the statistical inference attack risk assessment function, f diff-att (z i (s) is the differential attack risk assessment function, α i (s) represents the weight of the risk assessment value for re-identification attack instances, β i (s) represents the weight of the risk assessment value of the statistically inferred attack instance, γ i (s) represents the weight of the risk assessment value of the differential attack instance.
[0089] The above solution offers at least the following advantages: In this embodiment, considering that re-identification attack instances, differential attack instances, and differential attack instances are the most significant attack instances in terms of attack power, the security assessment device in this embodiment determines the weights of the risk assessment values of re-identification attack instances, differential attack instances, and differential attack instances based on the frequency of attack instances and / or the security event level caused by the attack instances. Thus, the security assessment device can determine the security assessment result of the object to be assessed based on the functions of re-identification attack instances, differential attack instances, and differential attack instances, and the weights of their risk assessment values.
[0090] In one possible implementation, combining Figure 3 ,like Figure 5 As shown in S302, the process by which the security assessment device determines the security assessment result of the object to be assessed based on the attack instance and the historical behavior information of the attack instance can be specifically implemented through the following S501-S503.
[0091] S501, The security assessment device acquires the user behavior characteristics of the object to be assessed.
[0092] User behavior characteristics include abnormal behavior data.
[0093] In one possible implementation, the security assessment device obtains the user behavior characteristics of the object to be assessed from the recorded information.
[0094] Optionally, the record information comprises at least one of the following: login record of the user, operation record of the user, and query record of the user.
[0095] It should be explained that the abnormal behavior data comprises behaviors that do not conform to a regular operation mode, and frequently-occurring erroneous operations.
[0096] S502, the security evaluation apparatus determines an abnormal behavior index according to the abnormal behavior data.
[0097] In a possible implementation, the security evaluation apparatus determines an abnormal behavior detection function according to a first preset algorithm, and then determines the abnormal behavior index according to the abnormal behavior data and the abnormal behavior detection function.
[0098] Optionally, the first preset algorithm comprises at least one of the following: 3sigma criterion, Z-score method, boxplot method, Grubbs hypothesis test, K-Nearest Neighbor (KNN) algorithm, Local Outlier Factor (LOF) algorithm, and support vector machine and Gaussian kernel function.
[0099] It should be explained that the abnormal behavior index is used to measure the significant degree of the abnormal behavior in the to-be-evaluated object, and the security evaluation apparatus can determine the security evaluation result of the to-be-evaluated object according to the significant degree of the abnormal behavior.
[0100] S503, the security evaluation apparatus determines the security evaluation result of the to-be-evaluated object according to the attack instance, the historical behavior information of the attack instance, and the abnormal behavior index.
[0101] In a possible implementation, the security evaluation apparatus determines a first score of the to-be-evaluated object according to the attack instance and the historical behavior information of the attack instance; the security evaluation apparatus determines a second score according to the abnormal behavior index and an abnormal behavior threshold; and the security evaluation apparatus determines the security evaluation result of the to-be-evaluated object according to the mean value of the first score and the second score.
[0102] The above scheme at least brings the following beneficial effects: in the embodiments of the present application, the influence of the abnormal behavior index on the security evaluation result of the to-be-evaluated object is considered. In the embodiments of the present application, the security evaluation apparatus determines the abnormal behavior index according to the abnormal behavior data. Then, the security evaluation apparatus determines the security evaluation result of the to-be-evaluated object according to the attack instance, the historical behavior information of the attack instance, and the abnormal behavior index, thereby improving the security evaluation result of the to-be-evaluated object.
[0103] In a possible implementation, the security evaluation apparatus determines the security evaluation result of the to-be-evaluated object according to the attack instance, the historical behavior information of the attack instance, and the abnormal behavior index. Figure 5 For example, Figure 6As shown in S502, the process by which the safety assessment device determines the abnormal behavior index based on the abnormal behavior data can be specifically implemented through the following S601.
[0104] S601, The safety assessment device determines the abnormal behavior index based on the relationship between abnormal behavior data and normal behavior data.
[0105] User behavior characteristics also include normal behavior data.
[0106] In one possible implementation, the security assessment device determines a normal behavior detection function based on a second preset algorithm, and then determines an abnormal behavior index based on normal behavior data, the normal behavior detection function, abnormal behavior data, and the abnormal behavior detection function.
[0107] Optionally, the second preset algorithm includes a machine learning algorithm based on support vector machines.
[0108] Optionally, the abnormal behavior index and the abnormal behavior data and normal behavior data satisfy the following formula:
[0109]
[0110] Where A(t) is the anomalous behavior index within time t, and λ is the decay factor, indicating that the influence of the anomalous behavior gradually weakens over time. j Let g be the time when the j-th abnormal behavior occurs. anomaly (u j (t) is the abnormal behavior detection function, h norm (v k (t) is the normal behavior detection function, used to compare and benchmark the results of abnormal behavior detection, where m is the total number of behavioral features.
[0111] The above solution offers at least the following advantages: In this embodiment, the impact of normal behavior data on the abnormal behavior index is considered. The security assessment device in this embodiment determines the abnormal behavior index based on the relationship between abnormal behavior data and normal behavior data. Furthermore, based on attack instances, historical behavior information of attack instances, and the abnormal behavior index, the accuracy of the security assessment result for the object to be assessed can be improved.
[0112] In one possible implementation, combining Figure 3 ,like Figure 7 As shown, in S302, after the security assessment device determines the security assessment result of the object to be assessed based on the attack instance and its historical behavior information, the security assessment device traces the attack source. The process of tracing the attack source by the security assessment device can be specifically implemented through the following S701-S702.
[0113] S701, when the security evaluation result of the to-be-evaluated object indicates that the to-be-evaluated object has a security risk, the security evaluation device obtains a data source feature of the attack instance.
[0114] Optionally, the data source feature comprises at least one of an attack source Internet Protocol (IP) address, an attack time, an attack type, an attack target, and an abnormal behavior pattern in an attack process.
[0115] It should be explained that the attack source IP address is used to represent the IP address from which the attacker launches an attack, the attack type is used to represent the attack means or tool used by the attacker, the attack target is used to represent the target system or application attacked by the attacker, and the abnormal behavior pattern in the attack process is used to represent the abnormal behavior pattern exhibited by the attacker in the attack process.
[0116] In a possible implementation, the security evaluation device obtains the data source feature of the attack instance based on a privacy protection policy.
[0117] It can be understood that the security evaluation device generates the privacy protection policy and obtains the data source feature of the attack instance based on the privacy protection policy, so that the protection of user information can be realized.
[0118] Optionally, after the security evaluation device obtains the data source feature of the attack instance based on the privacy protection policy, the security evaluation device can evaluate the privacy protection effect according to a sensitivity function, a privacy protection strength function, and an availability function.
[0119] In a possible implementation, the privacy protection effect evaluation value satisfies the following formula in relation to the sensitivity function, the privacy protection strength function, and the availability function.
[0120]
[0121] wherein, P(d) is the privacy protection effect evaluation value, used to measure the balance between the effectiveness of the privacy protection policy and the availability of the data; σ(d i is the sensitivity function of the data d i , indicating the sensitivity of the data; ρ privacy (d i ) is the privacy protection strength function of the data d i , indicating the protection degree of the data by the privacy protection policy; ρ utility (d i ) is the availability function of the data d i , indicating the availability of the data under the privacy protection policy; a and b are the upper and lower limits of the data range; and ε is a positive integer.
[0122] It should be explained that the sensitivity function can be based on the type, content, source and potential risks of the data, etc. The privacy protection strength function should consider the sensitivity of the data, business needs and laws and regulations, etc. The availability function can be determined based on the integrity, accuracy, explainability and other factors of the data.
[0123] For example, for data items containing personal privacy, their sensitivity can be set to be high, while for public information or insignificant data items, their sensitivity can be set to be low.
[0124] In another possible implementation, after the security evaluation device evaluates the privacy protection effect, it generates a privacy protection optimization strategy according to the risk value of the object to be evaluated before using the privacy protection strategy and the risk value of the object to be evaluated after using the privacy protection strategy.
[0125] Optionally, the privacy protection optimization strategy and the risk value of the object to be evaluated before using the privacy protection strategy and the risk value of the object to be evaluated after using the privacy protection strategy satisfy the following formula:
[0126] O(S)=max S∈S (∑ t∈T (λ t ·(R(t)-R′(t;S)))-μ·∑ d∈D (P(d)-P′(d;S)) 2 ) Formula Four
[0127] Wherein, O(S) is the optimization value of the privacy protection strategy S, used to evaluate the optimization effect of different privacy protection strategies;
[0128] S is a set of all possible privacy protection strategies; T is a set of time points, indicating that the strategy is evaluated at different time points; λ t is the weight of time point t, indicating the importance of the evaluation result at different time points; R(t) is the risk value before applying the strategy S at time point t; R'(t;S) is the risk value after applying the strategy S at time point t; μ is a balance factor, used to balance the weight between risk reduction and privacy protection effect improvement; D is a set of data sets; P(d) and P'(d;S) are the privacy protection effect evaluation values before and after applying the strategy S to the data d, respectively.
[0129] S702, the security evaluation device determines the attack source according to the data source characteristics of the attack instance.
[0130] In one possible implementation, the security assessment device identifies the data source characteristics of the attack instance, determines the registration information, geographical location, and attack device information of the IP address, and then locates the attack source based on the registration information, geographical location, and attack device information of the IP address.
[0131] It's important to explain that the security assessment device queries the WHOIS database to retrieve IP address registration information, obtaining domain name owners, contact information, and registrars. Using IP geolocation tools, the device pinpoints the attacker's geographical location based on their IP address, helping to determine their physical location and network environment. Furthermore, the device can perform reverse penetration testing on the attacker's IP address to further analyze their network architecture, operating system, open ports, and other information, thereby gaining a deeper understanding of the attacker's background and attack methods.
[0132] The above solution brings at least the following beneficial effects: In this embodiment, when the security assessment result of the object to be assessed indicates that there is a security risk to the object, the security assessment device obtains the data source characteristics of the attack instance. Since the data source characteristics include at least one of the following: attack source IP address, attack time, attack type, attack target, and abnormal behavior patterns during the attack process, the security assessment device locates the attack source based on the data source characteristics of the attack instance, so as to further block the attack from the attack source.
[0133] In one possible implementation, combining Figure 7 ,like Figure 8 As shown, in S702, after the security assessment device determines the attack source based on the data source characteristics of the attack instance, the security assessment device determines the accuracy of the source tracing analysis results of the attack source. The process by which the security assessment device determines the accuracy of the source tracing analysis results of the attack source can be specifically implemented through the following S801-S804.
[0134] S801, The security assessment device obtains the corresponding attack evidence for the attack instance.
[0135] Among them, attack evidence is used to record data information of attack instances.
[0136] Optionally, evidence of an attack may include at least one of the following: log file evidence, network traffic evidence, physical device evidence, and malicious code evidence.
[0137] In one possible implementation, the security assessment device acquires log data from the network, preprocesses the log data, and extracts corresponding attack evidence of attack instances from the preprocessed log data.
[0138] Optionally, preprocessing may include at least one of the following: data cleaning, format conversion, and time synchronization.
[0139] S802, the security evaluation device constructs an attack evidence chain according to the attack evidence and the attack source.
[0140] The attack evidence chain is used to represent an attack path of an attack instance.
[0141] In a possible implementation, the security evaluation device constructs the attack evidence chain according to the attack evidence, the attack source, and a relationship between the attack evidences.
[0142] Optionally, the relationship between the attack evidences includes at least one of the following: a time sequence, a cause-effect relationship, and a logical relationship.
[0143] S803, the security evaluation device acquires a traceability function of each piece of evidence chain in the attack evidence chain.
[0144] Optionally, the traceability function can be an algorithm or a model, and no limitation is made herein.
[0145] It should be explained that the traceability function can analyze connection relationships between nodes, information propagation paths, and other factors, so as to estimate a possibility of each node as a source node.
[0146] S804, the security evaluation device determines a traceability analysis result of the attack source according to the traceability function of each piece of evidence chain in the attack evidence chain.
[0147] In a possible implementation, the abnormal behavior index and the abnormal behavior data satisfy the following formula with the normal behavior data:
[0148]
[0149] wherein T(r) is a comprehensive score of the traceability analysis, used to evaluate accuracy and integrity of the traceability analysis; θ l is a weight of an l th traceability feature, φ l (r) is a performance of the l th traceability feature on evidence r, used to quantify effectiveness of the feature, ω q is a weight of a q th piece of evidence chain, ψ trace (q) is a traceability function of the q th piece of evidence chain, p is a total number of the traceability features, and r is a total number of the evidence chains.
[0150] The above scheme at least brings the following beneficial effects: in the embodiment of the application, the security evaluation device constructs the attack evidence chain according to the attack evidence and the attack source, verifies the traceability analysis result of the attack source according to the traceability function of each piece of evidence chain in the attack evidence chain, and improves reliability of locating the attack source.
[0151] It can be seen that the technical solutions provided by the embodiments of the present application are introduced mainly from the method aspect. In order to realize the above functions, the corresponding hardware structure and / or software module for executing each function are included. Those skilled in the art should easily realize that, in combination with the modules and algorithm steps of the examples described in the embodiments disclosed herein, the embodiments of the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is realized in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solutions. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0152] The embodiments of the present application also provide a computer readable storage medium, which stores instructions, when a computer executes the instructions, the computer executes each step in the method flow shown in the above method embodiments.
[0153] As shown in Figure 9 , it is a structure schematic diagram of a security evaluation device provided by the embodiments of the present application. The security evaluation device can be used to execute the security evaluation method shown in Figure 3 、 Figure 4 、 Figure 5 、 Figure 6 、 Figure 7 、 Figure 8 . Figure 9 The security evaluation device 90 shown in
[0154] The acquisition unit 901 is configured to acquire attack instances suffered by the to-be-evaluated object and historical behavior information of the attack instances, and the historical behavior information includes the frequency of occurrence of the attack instances and / or the security event level caused by the attack instances. The processing unit 902 is configured to determine the security evaluation result of the to-be-evaluated object according to the attack instances and the historical behavior information of the attack instances.
[0155] Optionally, the acquisition unit 901 is further configured to acquire the attack type of each attack instance in the attack instances. The processing unit 902 is further configured to determine the risk evaluation value of each attack instance according to the attack type of the attack instance. The processing unit 902 is further configured to determine the weight of the risk evaluation value of the attack instance according to the frequency of occurrence of the attack instance and / or the security event level caused by the attack instance. The weight of the risk evaluation value of the attack instance is negatively correlated with the frequency of occurrence of the attack instance. The processing unit 902 is further configured to determine the security evaluation result of the to-be-evaluated object according to the risk evaluation value of the attack instance and the weight of the risk evaluation value of the attack instance.
[0156] Optionally, the acquisition unit 901 is further configured to acquire a user behavior feature of the to-be-evaluated object; the user behavior feature comprises abnormal behavior data; the processing unit 902 is further configured to determine an abnormal behavior index according to the abnormal behavior data; and the processing unit 902 is further configured to determine a security evaluation result of the to-be-evaluated object according to the attack instance, the historical behavior information of the attack instance and the abnormal behavior index.
[0157] Optionally, the processing unit 902 is further configured to determine the abnormal behavior index according to a relationship between the abnormal behavior data and the normal behavior data.
[0158] Optionally, when the security evaluation result of the to-be-evaluated object indicates that the to-be-evaluated object has a security risk, the acquisition unit 901 is further configured to acquire a data source feature of the attack instance; and the processing unit 902 is further configured to determine an attack source according to the data source feature of the attack instance.
[0159] Optionally, the acquisition unit 901 is further configured to acquire corresponding attack evidence of the attack instance; the attack evidence is used to record data information of the attack instance; the processing unit 902 is further configured to construct an attack evidence chain according to the attack evidence and the attack source; the attack evidence chain is used to represent an attack path of the attack instance; the acquisition unit 901 is further configured to acquire a traceability function of each piece of evidence chain in the attack evidence chain; and the processing unit 902 is further configured to determine an accuracy of a traceability analysis result of the attack source according to the traceability function of each piece of evidence chain in the attack evidence chain.
[0160] The embodiment of the application further provides a chip, which comprises a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a computer program or an instruction to realize the security evaluation method in the method embodiment.
[0161] The embodiment of the application provides a computer program product comprising an instruction, when the instruction is run on a computer, the computer is caused to execute the security evaluation method in the method embodiment.
[0162] The computer readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a register, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes a floppy disk, a flexible disk, an optical disk, a hard disk, a solid state drive (SSD), a magnetic tape, or a compact disk. In some embodiments of the present application, the computer readable storage medium can be a tangible medium configured to store data that can be read by a computer system. In some embodiments of the present application, the computer readable storage medium can be a computer-readable storage medium.
[0163] Since the apparatus, device, computer readable storage medium, computer program product in the embodiments of the present application can be applied to the above-mentioned method, the technical effects that can be obtained are also referred to the above-mentioned method embodiments, which will not be described here in the embodiments of the present application.
[0164] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A safety assessment method, characterized in that, The method includes: Obtain attack instances against the object to be evaluated, as well as historical behavior information of the attack instances; the historical behavior information includes the frequency of the attack instances and / or the security event level caused by the attack instances; Based on the attack instance and its historical behavior information, the security assessment result of the object to be assessed is determined, including: Obtain the attack type for each attack instance in the attack instances; Based on the attack type of the attack instance, determine the risk assessment value of each attack instance; The weight of the risk assessment value of the attack instance is determined based on the frequency of the attack instance and / or the level of security incident caused by the attack instance; the weight of the risk assessment value of the attack instance is negatively correlated with the frequency of the attack instance and negatively correlated with the level of security incident caused by the attack instance. The security assessment result of the object to be assessed is determined based on the risk assessment value of the attack instance and the weight of the risk assessment value of the attack instance.
2. The method according to claim 1, characterized in that, The step of determining the security assessment result of the object to be assessed based on the attack instance and the historical behavior information of the attack instance includes: Obtain the user behavior characteristics of the object to be evaluated; the user behavior characteristics include abnormal behavior data; Based on the abnormal behavior data, an abnormal behavior index is determined; Based on the attack instance, the historical behavior information of the attack instance, and the abnormal behavior index, the security assessment result of the object to be assessed is determined.
3. The method according to claim 2, characterized in that, The user behavior characteristics also include normal behavior data, and the step of determining the abnormal behavior index based on the abnormal behavior data includes: The abnormal behavior index is determined based on the relationship between the abnormal behavior data and the normal behavior data.
4. The method according to claim 1, characterized in that, After determining the security assessment result of the object to be assessed based on the attack instance and the historical behavior information of the attack instance, the method further includes: When the security assessment result of the object to be assessed is used to indicate that the object to be assessed has a security risk, the data source characteristics of the attack instance are obtained; The attack source is determined based on the data source characteristics of the attack instance.
5. The method according to claim 4, characterized in that, After determining the attack source based on the data source characteristics of the attack instance, the method further includes: Obtain the corresponding attack evidence for the attack instance; the attack evidence is used to record the data information of the attack instance; Based on the attack evidence and the attack source, an attack evidence chain is constructed; the attack evidence chain is used to represent the attack path of the attack instance; Obtain the source tracing function for each link in the attack evidence chain; The accuracy of the source tracing analysis results of the attack source is determined based on the source tracing function of each evidence chain in the attack evidence chain.
6. A safety assessment device, characterized in that, The device includes: an acquisition unit and a processing unit; The acquisition unit is used to acquire attack instances suffered by the object to be evaluated, as well as historical behavior information of the attack instances; the historical behavior information includes the frequency of the attack instances and / or the security event level caused by the attack instances. The processing unit is configured to determine the security assessment result of the object to be assessed based on the attack instance and the historical behavior information of the attack instance, including: obtaining the attack type of each attack instance in the attack instance; determining the risk assessment value of each attack instance based on the attack type of the attack instance; determining the weight of the risk assessment value of the attack instance based on the frequency of the attack instance and / or the security event level caused by the attack instance; the weight of the risk assessment value of the attack instance is negatively correlated with the frequency of the attack instance, and the weight of the risk assessment value of the attack instance is negatively correlated with the security event level caused by the attack instance; and determining the security assessment result of the object to be assessed based on the risk assessment value of the attack instance and the weight of the risk assessment value of the attack instance.
7. A safety assessment device, characterized in that, include: A processor and a memory; wherein the memory is used to store computer execution instructions, and when the security assessment device is running, the processor executes the computer execution instructions stored in the memory to cause the security assessment device to perform the security assessment method according to any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes instructions that, when executed by a security assessment apparatus, cause the computer to perform the security assessment method as described in any one of claims 1-5.
9. A computer program product, the computer program product comprising computer instructions, characterized in that, When executed by a processor, the computer instructions implement the security assessment method according to any one of claims 1-5.
Citation Information
Patent Citations
Network security detection method and system based on big data analysis
CN116707924A
Security risk assessment system and method based on Internet of Things
CN119135436A