A cyberspace security credibility detection method and system based on security protocol
By deploying lightweight intrusion detection systems and security protocols on edge devices, the problem of excessive resource consumption in cyberspace security and trustworthiness detection is solved, and more efficient and accurate security detection and control is achieved.
Patent Information
- Application Number
- CN202510307613.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-03-17
AI Technical Summary
When the prior art uses security protocols to detect security and trustworthiness in cyberspace, it occupies too much processing resources for terminal equipment, resulting in performance degradation, especially on terminal equipment with limited resources.
By deploying lightweight intrusion detection systems and security protocols to edge devices, and using edge devices to share computing load, optimize storage resources, and configure different security protocols to meet the risk prevention needs of different access objects.
It improves the pertinence and accuracy of security protocols, enhances the security of access objects, reduces the attack surface, and realizes refined access control and more efficient trustworthiness detection.
Smart Images

Figure CN119835091B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cyberspace security detection technology, and in particular to a cyberspace security credibility detection method and system based on a security protocol. Background Art
[0002] Using security protocols to perform security credibility testing on cyberspace will occupy a large amount of processing resources of terminal devices, such as computing resources, storage resources, and network resources. Specifically, security protocols usually require operations such as encryption, decryption, authentication, behavior analysis, and anomaly detection. These processes will occupy a large amount of computing resources and may cause performance degradation, especially on terminal devices with limited resources, such as mobile devices or embedded systems. In addition, in order to be able to trace abnormal behavior and perform trend analysis, security credibility testing often generates a large number of log files, and these log files and data themselves will also occupy a lot of storage resources.
[0003] Edge devices can effectively alleviate the problem of processing resource consumption in cyberspace security credibility detection. They can not only share computing loads and optimize storage resources, but also alleviate bandwidth pressure and improve detection efficiency. Therefore, "how to deploy security protocols in edge devices and perform credibility detection" is the technical problem that the present invention needs to solve. Summary of the invention
[0004] The purpose of the present invention is to provide a cyberspace security credibility detection method and system based on a security protocol to solve the problem of "how to deploy security protocols in edge devices and perform credibility detection" raised in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A method for detecting the security credibility of a cyberspace based on a security protocol, the method comprising:
[0007] S100: Delineating a monitoring area for cyberspace security, finding a number of edge devices, marking access objects of the edge devices, integrating the edge devices and their corresponding access objects, and constructing a number of edge networks;
[0008] S200: Select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network;
[0009] S300: Configure a security protocol and determine attributes, wherein the attributes include at least authentication, authorization, and defense type. Through the attributes and risk levels, embed the security protocol into the edge network, traverse the running tasks in the access object, and split them to obtain a number of single items, wherein the single items include at least input items, output items, dependency items, target items, and execution condition items, and read out the potential risks in each single item;
[0010] S400: Create a monitoring tree, and mount the edge device to the left side of the monitoring tree, and mount the access object to the right side, to determine whether the security protocol in the edge device can meet the defense requirements of potential risks in the access object. If not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, and define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
[0011] Furthermore, the S100 includes:
[0012] Building a management platform for edge devices and integrating the monitoring tree into the management platform;
[0013] Setting a unique identifier for each edge device and determining basic information of the edge device, wherein the basic information includes at least: location, access object, and historical activities;
[0014] The basic information and the unique identifier are integrated to draw a comparison table.
[0015] Further, the S200 includes:
[0016] Determining sources of multimodal data, wherein the sources include at least: network traffic data, device logs, and sensor data;
[0017] Using the sources, a risk level of the edge network is modified.
[0018] Furthermore, the S200 further includes:
[0019] Building a verification mechanism consisting of several layers and integrating the verification mechanism into the edge network;
[0020] A correspondence between the risk level and the hierarchy is established, and the hierarchy is used to verify the access object.
[0021] Further, the S300 includes:
[0022] Inserting a scheduling node into the management platform and configuring scheduling rules;
[0023] The scheduling nodes and scheduling rules are integrated to adjust the tasks, wherein the adjustment at least includes: starting, terminating, allocating and migrating.
[0024] Furthermore, the S300 further includes:
[0025] Traversing the connection relationship between the edge device and the access object, and shifting the connection relationship by utilizing the potential risk;
[0026] The connection relationship is marked in the monitoring tree.
[0027] Furthermore, the S400 includes:
[0028] Using the access object, a terminal relationship graph is generated to traverse the risk propagation path;
[0029] From the risk propagation path, locate key nodes and cluster the key nodes into several priorities;
[0030] The scanning frequency is inserted into the management platform, and a mapping between the priority and the scanning frequency is configured.
[0031] Furthermore, the system comprises:
[0032] A construction module is used to define a monitoring area for cyberspace security, find a number of edge devices, mark the access objects of the edge devices, integrate the edge devices and their corresponding access objects, and construct a number of edge networks;
[0033] A determination module is used to select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network;
[0034] A reading module is used to configure a security protocol and determine attributes, wherein the attributes include at least authentication, authorization, and defense type. The security protocol is embedded into the edge network through the attributes and risk levels. The running tasks in the access object are traversed and split to obtain a number of single items, wherein the single items include at least input items, output items, dependency items, target items, and execution condition items. The potential risks in each single item are read out.
[0035] An access module is used to create a monitoring tree, mount the edge device on the left side of the monitoring tree, mount the access object on the right side, determine whether the security protocol in the edge device can meet the defense requirements of potential risks in the access object, and if not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
[0036] Furthermore, the building blocks include:
[0037] An integration unit, used to build a management platform for edge devices and integrate the monitoring tree into the management platform;
[0038] A setting unit, configured to set a unique identifier for each edge device and determine basic information of the edge device, wherein the basic information includes at least: location, access object, and historical activities;
[0039] A drawing unit is used to integrate the basic information and the unique identifier to draw a comparison table.
[0040] Furthermore, the determination module:
[0041] A tracing unit, used to determine the source of the multimodal data, wherein the source includes at least: network traffic data, device logs and sensor data;
[0042] a correction unit, configured to correct the risk level of the edge network by using the source;
[0043] An integration unit, configured to construct a verification mechanism consisting of several layers and integrate the verification mechanism into an edge network;
[0044] The verification unit is used to establish a corresponding relationship between the risk level and the hierarchy, and to verify the access object using the hierarchy.
[0045] Compared with the prior art, the present invention has the following beneficial effects:
[0046] By demarcating monitoring areas, the pertinence and accuracy of security protocols can be improved. By determining edge devices and their corresponding access objects, network areas can be isolated and different security protocols can be configured to greatly enhance the security of access objects, reduce attack surfaces, and refine access control while improving the accuracy of credibility detection. By configuring risk levels, data support can be provided for the allocation of security protocols. By creating a monitoring tree, access objects with potential risks can be intuitively displayed, network access can be adjusted in a timely manner, threats can be quickly isolated, access control can be performed more accurately, and the detection process can be optimized, greatly improving the effectiveness and comprehensiveness of detection results. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 A flowchart of a method for detecting the security credibility of a network space based on a security protocol provided by an embodiment of the present invention;
[0048] Figure 2 A first sub-process flowchart of a method for detecting cyberspace security credibility based on a security protocol provided by an embodiment of the present invention;
[0049] Figure 3 A second sub-process flowchart of a method for detecting cyberspace security credibility based on a security protocol provided by an embodiment of the present invention;
[0050] Figure 4 A third sub-flow diagram of the method for detecting the cyberspace security credibility based on a security protocol provided by an embodiment of the present invention;
[0051] Figure 5 A fourth sub-flow diagram of the cyberspace security credibility detection method based on a security protocol provided in an embodiment of the present invention;
[0052] Figure 6 A block diagram of the composition of a cyberspace security credibility detection system based on a security protocol provided by an embodiment of the present invention;
[0053] Figure 7 A block diagram of the components of the building blocks in the cyberspace security credibility detection system based on the security protocol provided by the embodiment of the present invention;
[0054] Figure 8 A block diagram of the composition of a determination module in a cyberspace security credibility detection system based on a security protocol provided by an embodiment of the present invention;
[0055] Fig. 9 A block diagram of the composition of a reading module in a cyberspace security credibility detection system based on a security protocol provided by an embodiment of the present invention;
[0056] Fig.10 A block diagram of the composition of an access module in a cyberspace security credibility detection system based on a security protocol provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0057] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0058] In Example 1, Figure 1The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and is described in detail below, as follows:
[0059] S100: Delineate a monitoring area for cyberspace security, find out a number of edge devices, mark access objects of the edge devices, integrate the edge devices and their corresponding access objects, and construct a number of edge networks.
[0060] In the process of cyberspace security detection, the monitoring area is delineated by integrating information such as the geographical location, traffic distribution and security requirements of the cyberspace. The monitoring area is the area where the cyberspace security credibility detection needs to be carried out; several edge devices are found in the monitoring area. The edge devices can be routers, switches and other terminal devices. The edge devices are responsible for data transmission and processing in the monitoring area; the terminals connected to the edge devices, that is, the access objects, are determined. The access objects can be user terminals, Internet of Things devices or other terminal devices. There are multiple edge devices, and each edge device is connected to at least one terminal device. The network structure consisting of an edge device and its access objects is called an edge network.
[0061] S200: Select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network.
[0062] A lightweight intrusion detection system is deployed in the edge network. The lightweight intrusion detection system has low resource consumption and efficient real-time detection capabilities. After deployment, it can monitor network traffic in real time, identify and collect potential risk features, where risk features include malicious traffic, abnormal behavior, and unauthorized access; count the number of risk features in each edge network, and determine the impact of each risk feature, where the impact level can be high, medium, and low. According to the number and impact level of risk features, the risk level of each edge network is determined; wherein, a weight value can be set for each impact level, and the sum of the weight values of each edge network is calculated by superposition. According to this sum, the edge network can be divided into multiple risk levels.
[0063] S300: Configure the security protocol and determine the attributes, wherein the attributes include at least authentication, authorization and defense type. Through the attributes and risk levels, embed the security protocol into the edge network, traverse the running tasks in the access object, and split them into several items, wherein the items include at least input items, output items, dependency items, target items and execution condition items, and read out the potential risks in each item.
[0064] From the existing technology, select a security protocol, which may be SSL / TLS or HTTPS, etc. Each security protocol includes at least three core attributes: authentication, authorization and defense type. Authentication is used to verify the identity of devices or users in the network to ensure that only terminal devices with legal identities can access the network, and authorization ensures that different users or devices access specific resources or services according to their roles or permissions. Match the risk level with the security protocol to find out the security protocol that can meet the defense requirements of each risk level, and embed the security protocol into the corresponding edge network. In actual use, if more frequent or complex attacks are detected, the risk level of the edge network needs to be adjusted.
[0065] Traverse the running tasks in all access objects, identify the detailed execution content of each task, and split it into several items, each of which represents an independent part of the task, such as input items (i.e., the original data or information required for task execution), output items (the results or changes produced after task execution), dependency items (other tasks or resources required before or during task execution), target items (clearly define the goals of task execution or the expected results), and execution condition items (prerequisites or triggering conditions for task execution, such as time, events, or status); read out potential risks from the items, which include but are not limited to security risks such as data leakage, privilege escalation, execution failure, and dependency failure; if there are potential risks in an edge network, it means that there are security vulnerabilities in the current network configuration, that is, the security protocol cannot meet the security requirements of the current edge network; for example, the edge device is configured with a relatively basic authentication protocol, but due to the high risk level of the edge network built by the edge device, the existing authentication mechanism may not be able to effectively prevent malicious access, or the authorization control is too loose. At this time, it is necessary to change the security protocol, that is, migrate the access device to other edge devices.
[0066] S400: Create a monitoring tree, and mount the edge device to the left side of the monitoring tree, and mount the access object to the right side, to determine whether the security protocol in the edge device can meet the defense requirements of potential risks in the access object. If not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, and define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
[0067] A monitoring tree corresponding to the network space is created, where the monitoring tree consists of two parts, the left part and the right part. The monitoring tree is a tree-like data structure, which is mainly used to establish the access relationship between the edge device and the mounted object. Specifically, there must be multiple terminal devices (access objects) and edge devices in the monitoring area. Different security protocols are embedded in each edge device, and the terminal devices are connected to different edge devices according to the attributes of the security protocols. During the operation of the terminal device, the terminal device is monitored in real time. If potential risks are detected in the terminal device, the terminal device is connected to the edge device corresponding to other security protocols.
[0068] To summarize, by creating a monitoring tree, the access status of the terminal device can be intuitively displayed, and the access status can be adjusted in real time; the tilted monitoring tree is mainly used to intuitively display the security and reliability of the network space; if the security protocol in the edge device can meet the defense needs of the access object, then maintain real-time monitoring of the access object; if the security protocol cannot meet the defense needs of the access object, then tilt the monitoring tree and define the access object as a risk object; traverse all edge devices in turn to find the security protocol that can meet the defense needs of the risk object, and define the edge device corresponding to the found security protocol as the target device, and re-connect the risk object to the target device.
[0069] In Example 2, Figure 2 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S100 is described in detail as follows:
[0070] S101: construct a management platform for edge devices, and integrate the monitoring tree into the management platform.
[0071] Create a management platform, which is mainly used to monitor, configure and maintain all edge devices and terminal devices distributed in the edge network.
[0072] S102: Setting a unique identifier for each edge device and determining basic information of the edge device, wherein the basic information at least includes: location, access object, and historical activities.
[0073] A unique identifier is set for each edge device, the basic information of each edge device is read out, and a corresponding relationship between the unique identifier and the basic information is established.
[0074] S103: Integrate the basic information and the unique identifier and draw a comparison table.
[0075] Integrate basic information and unique identifiers to generate a comparison table.
[0076] In Example 3, Figure 3 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S200 is described in detail as follows:
[0077] S201: Determine sources of multimodal data, wherein the sources include at least: network traffic data, device logs, and sensor data.
[0078] Determine the risk level of the edge network, where the risk level is influenced by factors other than risk characteristics, including at least network traffic data, device logs, and sensor data; in other words, the source should also be referenced when determining the risk level of the edge network.
[0079] S202: Using the source, modify the risk level of the edge network.
[0080] Based on the above sources, the risk level is adjusted.
[0081] In Example 4, Figure 3 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S200 is further described in detail as follows:
[0082] S203: Construct a verification mechanism consisting of several levels, and integrate the verification mechanism into the edge network.
[0083] The verification mechanism is a set of several levels, each level contains a verification method, and each edge network corresponds to a verification method.
[0084] S204: Establishing a correspondence between the risk level and the level, and using the level to verify the access object.
[0085] Establish a correspondence between risk levels and hierarchies. In other words, different risk levels correspond to different verification methods. After passing the verification, the access object will be connected to the corresponding edge device.
[0086] In Example 5, Figure 4 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S300 is described in detail as follows:
[0087] S301: inserting a scheduling node into the management platform and configuring scheduling rules.
[0088] Insert a scheduling node into the management platform and integrate the scheduling rules into the scheduling node, where the scheduling node is mainly used to adjust the access objects in the edge device; for example, if the scheduling rule exceeds the preset traffic threshold, the access object is adjusted; if in actual use, the bandwidth of an edge device is less than the preset threshold, the access object is migrated to other edge devices.
[0089] S302: Integrate the scheduling nodes and scheduling rules, and adjust the tasks, wherein the adjustment at least includes: starting, terminating, allocating, and migrating.
[0090] While migrating the access object, it is also necessary to adjust the tasks in the access object. The specific adjustment steps include: starting, terminating, allocating and migrating; for example, terminating redundant tasks to reduce bandwidth consumption.
[0091] In Example 6, Figure 4 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S300 is further described in detail as follows:
[0092] S303: Traverse the connection relationship between the edge device and the access object, and use the potential risk to shift the connection relationship.
[0093] After the access object is connected to the edge device, a connection relationship is generated. According to the potential risks, the two ends of the connection relationship are offset, that is, the access object is connected to other edge devices.
[0094] S304: Mark the connection relationship into the monitoring tree.
[0095] The connection relationship is marked in the monitoring tree to intuitively display the relationship between the access object and the edge device.
[0096] In Example 7, Figure 5 The implementation process of the network space security credibility detection method based on the security protocol provided by the embodiment of the present invention is shown, and S400 is described in detail as follows:
[0097] S401: Generate a terminal relationship graph using the access object and traverse a risk propagation path.
[0098] With access objects or edge devices as nodes and connection relationships as edges, a terminal relationship map is drawn; the risk propagation path is traversed in the terminal relationship map, and the specific analysis process of the risk propagation path is as follows: starting from a potential risk source (for example, a terminal that has been attacked), analyze how the potential risk propagates through different terminal devices in the network. These paths may involve multiple nodes, and each node may become a bridge for risk propagation; for example, a terminal device may become a source of propagation due to being infected by malware, thereby affecting other terminals it depends on or devices that communicate with it; based on the above propagation process, the risk propagation path is determined.
[0099] S402: locating key nodes from the risk propagation path, and clustering the key nodes into several priorities.
[0100] The bridge mentioned above is the key node, which is usually the intersection between multiple terminal devices, or a device with important control functions, such as a core switch, firewall or database server. According to the degree of influence of each key node on the entire network space, the key nodes are divided into several priorities, including high, medium and low.
[0101] S403: Insert the scanning frequency into the management platform, and configure the mapping between the priority and the scanning frequency.
[0102] Different scanning frequencies are set for key nodes of different priorities. A lightweight intrusion detection system and scanning frequency are used to monitor all edge devices, access objects and key nodes in the management platform. The scanning frequencies of edge devices and access objects are pre-determined by professionals. By configuring different scanning frequencies, it is possible to improve the security protection capabilities of the entire network space while reducing unnecessary computing consumption.
[0103] Figure 6 The structure diagram of the network space security credibility detection system based on the security protocol provided by the embodiment of the present invention is shown. The network space security credibility detection system based on the security protocol 1 includes:
[0104] A construction module 11 is used to define a monitoring area for network space security, find a number of edge devices, mark the access objects of the edge devices, integrate the edge devices and their corresponding access objects, and construct a number of edge networks;
[0105] A determination module 12 is used to select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network;
[0106] A reading module 13 is used to configure a security protocol and determine attributes, wherein the attributes include at least authentication, authorization, and defense type. The security protocol is embedded into the edge network through the attributes and risk levels, and the running tasks in the access object are traversed and split to obtain a plurality of single items, wherein the single items include at least input items, output items, dependency items, target items, and execution condition items, and the potential risks in each single item are read out;
[0107] The access module 14 is used to create a monitoring tree, mount the edge device to the left side of the monitoring tree, mount the access object to the right side, determine whether the security protocol in the edge device can meet the defense requirements of the potential risks in the access object, and if not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
[0108] Figure 7 The structure diagram of the network security credibility detection system based on the security protocol provided by the embodiment of the present invention is shown, and the building module 11 includes:
[0109] An integration unit 111, configured to construct a management platform for edge devices and integrate the monitoring tree into the management platform;
[0110] A setting unit 112, configured to set a unique identifier for each edge device and determine basic information of the edge device, wherein the basic information includes at least: location, access object, and historical activities;
[0111] The drawing unit 113 is used to integrate the basic information and the unique identifier to draw a comparison table.
[0112] Figure 8 The structural block diagram of the network space security credibility detection system based on the security protocol provided by the embodiment of the present invention is shown, and the determination module 12 includes:
[0113] A tracing unit 121 is used to determine the source of the multimodal data, wherein the source includes at least: network traffic data, device logs and sensor data;
[0114] A correction unit 122, configured to correct the risk level of the edge network using the source;
[0115] An integration unit 123, configured to construct a verification mechanism consisting of several levels and integrate the verification mechanism into the edge network;
[0116] The verification unit 124 is used to establish a corresponding relationship between the risk level and the hierarchy, and verify the access object using the hierarchy.
[0117] Fig. 9 The structure diagram of the network space security credibility detection system based on the security protocol provided by the embodiment of the present invention is shown, and the reading module 13 includes:
[0118] A configuration unit 131, configured to insert a scheduling node into the management platform and configure scheduling rules;
[0119] An adjustment unit 132, configured to integrate the scheduling node and the scheduling rule and adjust the task, wherein the adjustment at least includes: starting, terminating, allocating and migrating;
[0120] An offset unit 133, configured to traverse the connection relationship between the edge device and the access object, and offset the connection relationship by using the potential risk;
[0121] The marking unit 134 is used to mark the connection relationship into the monitoring tree.
[0122] Fig.10 The structure diagram of the network space security credibility detection system based on the security protocol provided by the embodiment of the present invention is shown, and the access module 14 includes:
[0123] A generating unit 141 is used to generate a terminal relationship graph using the access object and traverse a risk propagation path;
[0124] A clustering unit 142 is used to locate key nodes from the risk propagation path and cluster the key nodes into a plurality of priorities;
[0125] The configuration unit 143 is used to insert the scanning frequency into the management platform and configure the mapping between the priority and the scanning frequency.
[0126] The construction module 11 is mainly used to complete step S100, the determination module 12 is mainly used to complete step S200, the reading module 13 is mainly used to complete step S300, and the access module 14 is mainly used to complete step S400;
[0127] The integration unit 111 is mainly used to complete step S101, the setting unit 112 is mainly used to complete step S102, and the drawing unit 113 is mainly used to complete step S103;
[0128] The traceability unit 121 is mainly used to complete step S201, the correction unit 122 is mainly used to complete step S202, the integration unit 123 is mainly used to complete step S203, and the verification unit 124 is mainly used to complete step S204;
[0129] The configuration unit 131 is mainly used to complete step S301, the adjustment unit 132 is mainly used to complete step S302, the offset unit 133 is mainly used to complete step S303, and the marking unit 134 is mainly used to complete step S304;
[0130] The generating unit 141 is mainly used to complete step S401 , the clustering unit 142 is mainly used to complete step S402 , and the configuring unit 143 is mainly used to complete step S403 .
[0131] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0132] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
[0133] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A cyberspace security credibility detection method based on a security protocol, characterized in that: The method comprises: S100: Delineating a monitoring area for cyberspace security, finding a number of edge devices, marking access objects of the edge devices, integrating the edge devices and their corresponding access objects, and constructing a number of edge networks; S200: Select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network; S300: Configure a security protocol and determine attributes, wherein the attributes include at least authentication, authorization, and defense type. Through the attributes and risk levels, embed the security protocol into the edge network, traverse the running tasks in the access object, and split them to obtain a number of single items, wherein the single items include at least input items, output items, dependency items, target items, and execution condition items, and read out the potential risks in each single item; S400: Create a monitoring tree, and mount the edge device to the left side of the monitoring tree, and mount the access object to the right side, to determine whether the security protocol in the edge device can meet the defense requirements of potential risks in the access object. If not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, and define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
2. The method for detecting the security credibility of cyberspace based on security protocol according to claim 1 is characterized in that: The S100 includes: Building a management platform for edge devices and integrating the monitoring tree into the management platform; Setting a unique identifier for each edge device and determining basic information of the edge device, wherein the basic information includes at least: location, access object, and historical activities; The basic information and the unique identifier are integrated to draw a comparison table.
3. The method for detecting the security credibility of cyberspace based on security protocol according to claim 1 is characterized in that: The S200 includes: Determining sources of multimodal data, wherein the sources include at least: network traffic data, device logs, and sensor data; Using the sources, a risk level of the edge network is modified.
4. The method for detecting the security credibility of cyberspace based on security protocol according to claim 3 is characterized in that: The S200 further includes: Building a verification mechanism consisting of several layers and integrating the verification mechanism into the edge network; A correspondence between the risk level and the hierarchy is established, and the hierarchy is used to verify the access object.
5. The method for detecting the security credibility of cyberspace based on security protocol according to claim 2 is characterized in that: The S300 includes: Inserting a scheduling node into the management platform and configuring scheduling rules; The scheduling nodes and scheduling rules are integrated to adjust the tasks, wherein the adjustment at least includes: starting, terminating, allocating and migrating.
6. The method for detecting the security credibility of cyberspace based on security protocol according to claim 1 is characterized in that: The S300 further includes: Traversing the connection relationship between the edge device and the access object, and shifting the connection relationship by utilizing the potential risk; The connection relationship is marked in the monitoring tree.
7. The method for detecting the security credibility of cyberspace based on security protocol according to claim 2 is characterized in that: The S400 includes: Using the access object, a terminal relationship graph is generated to traverse the risk propagation path; From the risk propagation path, locate key nodes and cluster the key nodes into several priorities; The scanning frequency is inserted into the management platform, and a mapping between the priority and the scanning frequency is configured.
8. A cyberspace security credibility detection system based on security protocol, characterized in that: The system comprises: A construction module is used to define a monitoring area for cyberspace security, find a number of edge devices, mark the access objects of the edge devices, integrate the edge devices and their corresponding access objects, and construct a number of edge networks; A determination module is used to select a lightweight intrusion detection system, deploy it to the edge network, collect risk features, count the number of risk features and the impact of each risk feature, and determine the risk level of each edge network; A reading module is used to configure a security protocol and determine attributes, wherein the attributes include at least authentication, authorization, and defense type. The security protocol is embedded into the edge network through the attributes and risk levels. The running tasks in the access object are traversed and split to obtain a number of single items, wherein the single items include at least input items, output items, dependency items, target items, and execution condition items. The potential risks in each single item are read out. An access module is used to create a monitoring tree, mount the edge device on the left side of the monitoring tree, mount the access object on the right side, determine whether the security protocol in the edge device can meet the defense requirements of potential risks in the access object, and if not, tilt the monitoring tree, define the access object where the potential risk is located as a risk object, find out the security protocol that can meet the defense requirements, define the edge device where the security protocol is located as a target device, and re-connect the risk object to the target device.
9. The cyberspace security credibility detection system based on security protocol according to claim 8 is characterized in that: The building blocks include: An integration unit, used to build a management platform for edge devices and integrate the monitoring tree into the management platform; A setting unit, configured to set a unique identifier for each edge device and determine basic information of the edge device, wherein the basic information includes at least: location, access object, and historical activities; A drawing unit is used to integrate the basic information and the unique identifier to draw a comparison table.
10. The cyberspace security credibility detection system based on security protocol according to claim 8 is characterized in that: The determination module: A tracing unit, used to determine the source of the multimodal data, wherein the source includes at least: network traffic data, device logs and sensor data; a correction unit, configured to correct the risk level of the edge network by using the source; An integration unit, configured to construct a verification mechanism consisting of several layers and integrate the verification mechanism into an edge network; The verification unit is used to establish a corresponding relationship between the risk level and the hierarchy, and to verify the access object using the hierarchy.
Citation Information
Patent Citations
Method and system for processing network security level protection data
CN116389295A
Overlay cyber security networked system and method
US10250619B1