Network security vulnerability assessment method and system

Through the comprehensive evaluation method of multi-source heterogeneous data acquisition and multiple data analysis models, the problem of low reliability of existing network security vulnerability assessment methods is solved, and a comprehensive assessment of network security vulnerabilities and the discovery of unknown attack patterns are achieved.

CN119892409BActive Publication Date: 2025-09-30NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411853356.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-09-30
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

Existing network security vulnerability assessment methods have low reliability, cannot fully reflect the security risks existing in the system, and have difficulty taking into account various data format differences.

Method used

Adopt multi-source heterogeneous data acquisition and multiple data analysis models, conduct comprehensive analysis through data transmission channels, generate vulnerability analysis reports, and use multiple data analysis models to deeply process and evaluate network security information.

Benefits of technology

It improves the reliability of network security vulnerability assessment, can fully reflect the security risks in the system, discover unknown attack modes, and achieve a comprehensive assessment of network security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892409B_ABST
    Figure CN119892409B_ABST
Patent Text Reader

Abstract

The present application provides a network security vulnerability assessment method and system, relating to the field of network security technology. The method includes: obtaining multi-source heterogeneous data through a data reading cluster, wherein the multi-source heterogeneous data is data used to indicate network security information; using multiple data transmission channels to transmit the multi-source heterogeneous data to multiple data analysis models to obtain multiple analysis data sets, wherein each data analysis model corresponds to a data transmission channel, and each data analysis model corresponds to an analysis data set; generating a vulnerability analysis report based on data analysis requirements and at least one analysis data set from the multiple analysis data sets, and determining a network security vulnerability assessment result based on the vulnerability analysis report. This method solves the problem of low reliability of existing network security vulnerability assessment methods and improves the reliability of network security vulnerability assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a network security vulnerability assessment method and system. Background Art

[0002] During the construction of operational networks, due to a combination of factors such as hardware deployment, system vulnerabilities, software design, and security policies, weak links or vulnerabilities inevitably exist within the network, potentially allowing attackers to exploit them and pose threats (network security vulnerability refers to potential loopholes or weaknesses in the network system). Assessing the defensive vulnerability of operational networks can identify system vulnerabilities and weaknesses before an attack on the network occurs, effectively reducing systemic risks and improving security within the network.

[0003] In related technologies, when conducting network security vulnerability assessments, a single relatively simple assessment method based on security standards, security equipment, or vulnerability detection is usually used. In addition, the existing defense security information based on different network security equipment manufacturers also has different data formats, so there is no way to take into account multiple aspects of data. However, this method is too single, resulting in low reliability of the assessment results of network security vulnerability assessments, and there is no way to fully reflect the security risks existing in the system.

[0004] To address the low reliability of existing network security vulnerability assessment methods, no effective technical solution has been proposed. Summary of the Invention

[0005] The embodiments of the present application provide a network security vulnerability assessment method and system to at least solve the problem of low reliability of existing network security vulnerability assessment methods.

[0006] According to one aspect of an embodiment of the present application, a network security vulnerability assessment method is provided, including: acquiring multi-source heterogeneous data through a data reading cluster, wherein the multi-source heterogeneous data is data used to indicate network security information; using multiple data transmission channels to transmit the multi-source heterogeneous data to multiple data analysis models to obtain multiple analysis data sets, wherein each data analysis model corresponds to a data transmission channel, and each data analysis model corresponds to an analysis data set; generating a vulnerability analysis report according to data analysis requirements and at least one analysis data set among the multiple analysis data sets, and determining a network security vulnerability assessment result according to the vulnerability analysis report.

[0007] According to another aspect of an embodiment of the present application, a network security vulnerability assessment system is also provided, including: a data acquisition unit, used to obtain multi-source heterogeneous data through a data reading cluster, and use multiple data transmission channels to transmit the multi-source heterogeneous data to multiple data analysis models, wherein the multi-source heterogeneous data is data used to indicate network security information; a vulnerability model detection unit, used to use multiple data analysis models to analyze the input multi-source heterogeneous data to obtain multiple analysis data sets, wherein each data analysis model corresponds to a data transmission channel, and each data analysis model corresponds to an analysis data set; a vulnerability analysis reporting unit, used to generate a vulnerability analysis report according to data analysis requirements and at least one analysis data set among the multiple analysis data sets, and determine the network security vulnerability assessment result according to the vulnerability analysis report.

[0008] Optionally, the vulnerability model detection unit includes a classification subunit for classifying multi-source heterogeneous data to obtain multiple reference data sets indicating different categories of network security information, wherein each reference data set corresponds to a category of network security information, and each reference data set includes multiple reference data subsets; a first acquisition subunit for acquiring multiple data analysis models, and acquiring the data set to be analyzed corresponding to each data analysis model from the multiple reference data subsets included in the multiple reference data sets, wherein the multiple data analysis models include: a security vulnerability detection analysis model, a device status management detection analysis model, and a device configuration defect detection analysis model; a transmission subunit for using data transmission channels corresponding to each of the multiple data analysis models to transmit the data set to be analyzed corresponding to each data analysis model to the multiple data analysis models, respectively, to obtain multiple analysis data sets output by the multiple data analysis models.

[0009] Optionally, the above-mentioned transmission sub-unit includes a first acquisition module, which is used to obtain a first data set to be analyzed corresponding to the security vulnerability detection and analysis model; a feature extraction module, which is used to perform feature extraction on the first data subset and the second data subset respectively, to obtain a first feature set corresponding to the first data subset, and a second feature set corresponding to the second data subset, wherein the first data set to be analyzed includes a first feature set and a second feature set, wherein the first data subset is used to indicate asset data and the second data subset is used to indicate vulnerability data; a standardization module, which is used to perform data standardization on the second feature set to obtain a standardized feature set; a matching module, which is used to match the first feature set and the standardized feature set to obtain an analysis data set corresponding to the security vulnerability detection and analysis model.

[0010] Optionally, the above-mentioned transmission sub-unit also includes: a second acquisition module, used to obtain a second data set to be analyzed corresponding to the equipment status management detection and analysis model, the second data set to be analyzed including a first data subset, a third data subset, and a fourth data subset; a classification module, used to perform hierarchical classification on the first data subset to obtain a hierarchical data set; a comparison module, used to perform threshold comparison on the data in the third data subset to obtain a state abnormality data set, wherein the third data subset is used to indicate the equipment status; a third acquisition module, used to obtain multiple topological paths corresponding to the fourth data subset, and determine the influencing device data set corresponding to the fourth data subset based on the multiple topological paths, wherein the fourth data subset is used to indicate the network connection relationship between multiple devices; a first evaluation module, used to perform a first evaluation based on the hierarchical data set, the state abnormality data set, and the influencing device data set to obtain an analysis data set corresponding to the equipment status management detection and analysis model.

[0011] Optionally, the above-mentioned transmission sub-unit also includes a fourth acquisition module, which is used to obtain a third data set to be analyzed corresponding to the equipment configuration defect detection and analysis model, wherein the third data set to be analyzed includes a fifth data subset and a sixth data subset; a policy verification module, which is used to perform a policy verification on the fifth data subset to obtain a verification data set, wherein the fifth data subset is used to indicate the device configuration information corresponding to each of the multiple devices, and the policy verification is used to verify whether the device configuration information meets the preset configuration requirements; a risk assessment module, which is used to perform a risk assessment on the fifth data subset to obtain a risk assessment data set, wherein the fifth data set is used to indicate data that poses a security threat; a second evaluation module, which is used to perform a second evaluation based on the verification data set and the risk assessment data set to obtain an analysis data set corresponding to the equipment configuration defect detection and analysis model.

[0012] Optionally, the vulnerability analysis report unit includes a second acquisition subunit for acquiring data analysis requirements; a third acquisition subunit for acquiring a report template according to the data analysis requirements, and acquiring at least one analysis data set from multiple analysis data sets; and a mapping subunit for mapping multiple data in at least one analysis data set to designated positions in the report template to obtain a vulnerability analysis report.

[0013] Optionally, the network security vulnerability assessment system further includes a data storage unit for storing the plurality of reference data sets, the plurality of analysis data sets, and the vulnerability analysis report in preset designated storage locations respectively.

[0014] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the above network security vulnerability assessment method.

[0015] According to another aspect of the embodiments of the present application, an electronic device is also provided, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the network security vulnerability assessment method as described above.

[0016] Compared with the prior art, the technical solution provided by the embodiments of the present application can have the following beneficial effects:

[0017] Through the above network security vulnerability assessment method, the above approach solves the problem of low reliability of the existing network security vulnerability assessment method and improves the reliability of the network security vulnerability assessment method. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0019] Figure 1 is a schematic structural diagram of an optional network security vulnerability assessment system according to the present invention;

[0020] Figure 2 is a flow chart of an optional network security vulnerability assessment method according to the present invention;

[0021] Figure 3 is a schematic diagram of another optional network security vulnerability assessment method according to the present invention;

[0022] Figure 4 It is a schematic diagram of another optional network security vulnerability assessment method according to the present invention. DETAILED DESCRIPTION

[0023] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only embodiments of a part of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of this application. The content of this specification should not be understood as limiting the present invention. Therefore, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

[0024] It should be noted that the terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that such terms are interchangeable where appropriate so that the embodiments of the invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0025] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. Moreover, the system embodiments described above are merely schematic, in which the modules and units described as separate components may or may not be physically separated, that is, they may be located on one network unit, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.

[0026] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0027] Regarding the problem of network security vulnerability analysis, the existing network security vulnerability assessment methods have the problem of difficulty in comprehensively assessing vulnerabilities from the perspective of the entire operating network, and therefore have the problem of low reliability when assessed from a single perspective.

[0028] In order to solve the above problems, the embodiment of the present application provides an evaluation method that is relatively simple compared to those based on security standards, security equipment, vulnerability detection, etc., namely the above-mentioned network security vulnerability evaluation method. This method quantitatively evaluates the operational network security vulnerability based on multiple security models in the vulnerability model detection unit, which can more comprehensively reflect the security risks existing in the system, and can discover unknown attack modes and system vulnerabilities, which is conducive to a comprehensive evaluation of network security vulnerabilities, thereby improving the reliability of network security vulnerability evaluation. As an optional implementation method, the above-mentioned network security vulnerability evaluation method can be applied to, but is not limited to, Figure 1The network security vulnerability assessment system 100 shown in FIG. 1 is composed of a data acquisition unit 102 (also referred to as a data acquisition subsystem), a vulnerability model detection unit 104 (also referred to as a vulnerability model detection subsystem), a vulnerability analysis and reporting unit 106 (also referred to as a vulnerability analysis and reporting subsystem), and a data storage unit 108. Figure 1 As shown, the data acquisition unit 102, the vulnerability model detection unit 104, and the vulnerability analysis reporting unit 106 are all connected to the data storage unit 108, the data acquisition unit 102 is connected to the vulnerability model detection unit 104, and the vulnerability analysis reporting unit 106 is connected to the vulnerability model detection unit 104. The connection can be a connection through a network, and the network can include but is not limited to: a wired network, a wireless network, wherein the wired network includes: a local area network, a metropolitan area network and a wide area network, and the wireless network includes: Bluetooth, WIFI and other networks that realize wireless communication.

[0029] According to one aspect of an embodiment of the present invention, the network security vulnerability assessment system 100 can also perform the following steps: the data acquisition unit 102 obtains multi-source heterogeneous data through a data reading cluster, and adopts multiple data transmission channels to transmit the multi-source heterogeneous data to multiple data analysis models, wherein the multi-source heterogeneous data is data used to indicate network security information; the vulnerability model detection unit 104 adopts multiple data analysis models to analyze the input multi-source heterogeneous data to obtain multiple analysis data sets, wherein each data analysis model corresponds to a data transmission channel, and each data analysis model corresponds to an analysis data set; the vulnerability analysis reporting unit 106 generates a vulnerability analysis report according to the data analysis requirements and at least one analysis data set among the multiple analysis data sets, and determines the network security vulnerability assessment result according to the vulnerability analysis report.

[0030] It should be noted that the data acquisition unit 102 is also used to roughly classify the read multi-source heterogeneous data and transmit the roughly classified multi-source heterogeneous data to the vulnerability model detection unit 104; the vulnerability model detection unit 104 is also used to provide comprehensive vulnerability detection analysis model management (i.e., multiple data analysis models), and deeply process different categories of defense security information, using the data analysis model to derive the data sets (i.e., multiple analysis data sets) required by the operational network vulnerability assessment subsystem (i.e., vulnerability analysis reporting unit 106); the vulnerability analysis reporting unit 106 is also used to configure vulnerability scoring metrics and output vulnerability analysis reports according to different dimensions. The data storage unit 108 is used to store the collected data, the data after model processing, and the final generated analysis report. That is, the data storage unit 108 is used to store the following different categories of standardized defense security information, analysis process information, and assessment report files.

[0031] In the above embodiment of the present invention, the above network security vulnerability assessment method can be used to comprehensively assess network security from multiple aspects, thereby solving the problem of low reliability of existing network security vulnerability assessment methods and improving the reliability of network security vulnerability assessment methods.

[0032] The above is only an example and is not limited in this embodiment.

[0033] As an optional implementation, please refer to Figure 2 , which shows a flow chart of a network security vulnerability assessment method provided by one embodiment of the present application. The execution entity of each step of the method can be the network security vulnerability assessment system 100 introduced above. The following is a detailed description of the method. The method can include at least one of the following steps (S202 to S206):

[0034] S202, acquiring multi-source heterogeneous data through a data reading cluster, wherein the multi-source heterogeneous data is data used to indicate network security information;

[0035] S204, using multiple data transmission channels to transmit the multi-source heterogeneous data to multiple data analysis models to obtain multiple analysis data sets, wherein each data analysis model corresponds to a data transmission channel, and each data analysis model corresponds to an analysis data set;

[0036] S206: Generate a vulnerability analysis report based on the data analysis requirements and at least one analysis data set from the multiple analysis data sets, and determine a network security vulnerability assessment result based on the vulnerability analysis report.

[0037] The operation of acquiring multi-source heterogeneous data through a data reading cluster in S202 can be understood as, but not limited to, using multiple data reading clusters (multiple data reading clusters included in the data acquisition unit 102) to read data from multiple data sources within a configured set time window (i.e., data acquired within a period of time, such as within 24 hours or within a month). Each data reading cluster can correspond to one or more data sources. Each data reading cluster adopts a management node-worker node architecture, i.e., a master-slave architecture of a master node, which is equivalent to a terminal managing multiple acquisition tools (i.e., data reading clusters). These tools are distributed, and the management node is responsible for managing the work nodes and the status of the cluster. The work nodes are data reading nodes. Multi-source heterogeneous data is data of different structures, types, or formats read from multiple data sources. Multi-source heterogeneous data includes asset data, vulnerability data, and security situation data from multiple different data sources, and the asset data, vulnerability data, and security situation data from multiple different data sources have the same or different formats. Multi-source heterogeneous data can be understood as, but is not limited to, distributed data (some collected directly from databases, some transmitted via network interfaces). These data include traffic data, log data, or security alarm data. This data can then be pooled together according to the channel corresponding to the data source. The data in this pool is multi-source heterogeneous data. Network security vulnerabilities include any one or more of the following: vulnerability-asset association vulnerabilities, security device configuration / status vulnerabilities, risk level vulnerabilities, and asset vulnerability distribution.

[0038] The operations in S202 described above can be understood as, but are not limited to, data collection operations. During data collection, various security information to be collected can be defined based on data needs (i.e., pre-defining what data to collect before collection), and a data collection strategy can be formulated (i.e., whether to collect data at regular intervals or collect data directly as it becomes available). Data collection operations include obtaining defense security information from multiple data sources using a variety of different reading methods, including but not limited to interfaces, logs, and databases.

[0039] The data acquisition method in the above S202 is used to achieve unified access to multi-source heterogeneous defense security information; the defense security information after access is classified and processed through the coarse classification platform; the efficiency of subsequent data processing is improved to ensure the timeliness of data access.

[0040] The multiple data analysis models in S204 are used to analyze the data of the input model. Each data analysis model has different data analysis logic, and each data analysis model corresponds to a data transmission channel. Figure 1The data collection unit 102 shown can transmit different types of network security information (ie, multi-source heterogeneous data) to the network security information collection unit 102 through different data transmission channels. Figure 1 The various data analysis models in the vulnerability model detection unit 104 shown, that is, what kind of data each data analysis model needs, can be obtained from the asset data, vulnerability data or security data (that is, multi-source heterogeneous data) according to the needs, and what kind of data is needed can be obtained. Therefore, each data analysis model corresponds to a data transmission channel, and the data in the analysis data set finally output by each data analysis model can be directly mapped to the data in the report template. By directly mapping each data in the analysis data set to a fixed position in the report template, the analysis report can be directly obtained (at most a simple time or statistical operation is performed). The operation in S204 can be understood as, but not limited to, obtaining the input data required by each data analysis model based on multiple data analysis models, and calling the respective processing algorithms of each data analysis model, outputting the analysis and evaluation results (that is, using multiple data analysis models (also called vulnerability analysis models), through association, analysis, evaluation and other processing, outputting the data set required for the vulnerability analysis report), and writing the data set of the evaluation results to the database.

[0041] Through the in-depth analysis of multi-source heterogeneous data by multiple data analysis models in S204, the output of defense security assessment data set is carried out using the vulnerability and asset association vulnerability analysis model, the security device configuration / status vulnerability analysis model, the risk level vulnerability analysis model, and the asset vulnerability distribution analysis model.

[0042] The data analysis requirements in S206 can be understood as, but not limited to, what kind of vulnerability analysis report is needed. Then, a target report template (i.e., the report template described below) can be determined from multiple preset report templates based on the data analysis requirements. Then, at least one analysis data set from multiple analysis data sets is mapped to the target report template to obtain a vulnerability analysis report. The vulnerability analysis report is a report that combines text and images. The network security vulnerability assessment results can be directly derived from the results displayed in the vulnerability analysis report. The vulnerability analysis report provides multiple types of reports such as vulnerability development trends, vulnerability distribution, vulnerability scores, vulnerability impact domain analysis, and comprehensive security analysis. The operation in S206 can be understood as, but not limited to, obtaining the assessment result data sets (i.e., multiple analysis data sets) of multiple vulnerability analysis models, placing them into a data resource pool, and then, according to the report requirements, retrieving the data required for the report from the data resource pool to provide assessment reports such as vulnerability development trends, vulnerability distribution, vulnerability scores, impact analysis, and comprehensive security reports (automatically generating various types of analysis reports).

[0043] The process in the above S206 includes: obtaining data analysis requirements; obtaining a report template according to the data analysis requirements, and obtaining at least one analysis data set from multiple analysis data sets; mapping multiple data in the at least one analysis data set to designated locations in the report template to obtain a vulnerability analysis report.

[0044] By setting the assessment type and assessment weight, not only a multi-dimensional and comprehensive assessment of network vulnerability is achieved, but also when security data information and network structure change, the relevant configuration information can be easily modified to adapt to changes in various network states.

[0045] It should be noted that the network security vulnerability assessment method also includes: storing multiple reference data sets, multiple analysis data sets and vulnerability analysis reports in preset designated storage locations respectively, that is, after obtaining multi-source heterogeneous data, the multi-source heterogeneous data will be stored in the storage location corresponding to the multi-source heterogeneous data; after classifying the multi-source heterogeneous data to obtain multiple reference data sets, the multiple reference data sets will be stored in the storage location corresponding to the multiple reference data sets; after obtaining multiple analysis data sets output by multiple data analysis models, the multiple analysis data sets will be stored in the storage location corresponding to the analysis data sets; after generating the vulnerability analysis report, the vulnerability analysis report will also be stored in the storage location corresponding to the vulnerability analysis report.

[0046] Through the above-described embodiments of this application and the use of the above-described network security vulnerability assessment method, a comprehensive assessment of network security can be conducted from multiple perspectives, thereby resolving the low reliability issue of existing network security vulnerability assessment methods and improving their reliability. Furthermore, the above-described embodiments can be used to comprehensively assess the network security vulnerabilities of operational networks.

[0047] As an optional implementation, multiple data transmission channels are used to transmit multi-source heterogeneous data to multiple data analysis models to obtain multiple analysis data sets, including:

[0048] S1, classifying multi-source heterogeneous data to obtain multiple reference data sets for indicating different categories of network security information, wherein each reference data set corresponds to a category of network security information and each reference data set includes multiple reference data subsets;

[0049] S2, obtaining multiple data analysis models, and obtaining a data set to be analyzed corresponding to each data analysis model from multiple reference data subsets included in the multiple reference data sets, wherein the multiple data analysis models include: a security vulnerability detection analysis model, a device status management detection analysis model, and a device configuration defect detection analysis model;

[0050] S3, using data transmission channels corresponding to the multiple data analysis models, respectively transmitting the data sets to be analyzed corresponding to each data analysis model to the multiple data analysis models, to obtain multiple analysis data sets output by the multiple data analysis models.

[0051] The classification operation in S1 (i.e., rough classification, which may be performed according to a pre-defined data processing strategy) may be understood as follows, but is not limited to: Figure 1 After collecting multi-source heterogeneous data, the data collection unit 102 in the illustrated network security vulnerability assessment system 100 also classifies the data. Specifically, it roughly classifies the network security information from multiple different data sources read by the data reading cluster based on the vulnerability data source assets, vulnerability data types, log content formats, etc., to obtain different categories of network security information. This rough classification not only obtains broad categories of network security information, but also sub-categorizes each broad category. This can be understood as obtaining standardized defense security information of different categories.

[0052] For example, coarse classification can be performed on multi-source heterogeneous data through the log content format and type of network devices, security devices, business systems, and terminal applications to obtain different categories of defense security information, including device status data, device configuration, port data, system status, vulnerability intelligence (vulnerability intelligence is classified according to the vulnerability library. According to CVE, CNNVD, and CNVD, vulnerability attribute elements include vulnerability name, level, type, vulnerability description, vulnerability repair suggestion, risk value, reference information), device configuration, threat situation, and other data.

[0053] The operation in S1 can be understood as, but not limited to, dividing the collected traffic data and log data into the following categories: Figure 3 ( Figure 3 The various data shown are only a specific application example, that is, the classified data is not only Figure 3 The data shown in the figure are not limited to the data input into each data analysis model. Figure 3The data in the model shown) include asset data, vulnerability data and security data (multiple reference data sets). Among the security data, 1) device configuration data mainly refers to the device's security configuration method or policy, which may include: account management policy, password policy, remote authorization policy, MAC address binding, authentication method, ACL policy, VPN policy, etc.; 2) security threat data mainly refers to the attack situation of the nodes that make up the operating network. The main data elements include attack methods (worms / viruses / trojans, etc.), attacked target IP, attacked URL, attack alarm information, attack exploitation tools, etc.; 3) device operation status mainly refers to the operation status of each component of the device, including CPU occupancy, memory occupancy, log buffer status, network service port status, etc.; 4) security situation data refers to the data output by the existing external vulnerability detection system, which mainly includes vulnerability risk quantification, vulnerability type, security status of protective software, and port development status. And the subcategories included in each major category will also be classified, such as Figure 3 ( Figure 3 The data sets listed in the table are all the security data that the system can obtain, and are continuously accumulated. When the user needs to form an analysis report, all three analysis models will be called, and the roughly divided data sets will be input into all three models as needed, and the output data will be stored in the database for analysis report subsystem calls. The asset data shown in the table includes network data, security data, business system and terminal application data; vulnerability intelligence includes CNNVD (China National Information Security Vulnerability Database), CNVD (National Information Security Vulnerability Sharing Platform) and CVE (Common Vulnerabilities & Exposures, CVE can be understood as a dictionary table that gives a common name to widely recognized information security vulnerabilities or weaknesses that have been exposed); and security data includes device configuration data, security threat data, device operating status and security situation data (multiple reference data subsets).

[0054] The multiple data analysis models in S2 are data analysis models that are pre-trained using training samples and can accurately analyze data. The operation of obtaining the data set to be analyzed in S2 can be understood as, but not limited to, obtaining the data set to be analyzed corresponding to each different data analysis model from the multiple reference data subsets included in each of the multiple reference data sets, that is, the data set to be analyzed includes at least one reference data subset from the multiple reference data subsets included in each of the multiple reference data sets. The multiple data analysis models include Figure 3 The security vulnerability detection and analysis model, device status management detection and analysis model, and device configuration defect detection and analysis model are shown.

[0055] For the convenience of description, the multiple reference data subsets included in each of the above-mentioned multiple reference data sets will be referred to as all reference data subsets. It should be noted that before all reference data subsets are input into different data analysis models according to the needs of different data analysis models, all reference data subsets will be deep processed. The deep processing is used to process the data in all reference data subsets according to the data processing requirements of different data analysis models, and process the reference data subsets required by different data analysis models into standard data (that is, data that can be read by the corresponding data analysis model).

[0056] like Figure 3 The security vulnerability detection analysis model, device status management detection analysis model, and device configuration defect detection analysis model shown all correspond to an input, which can be but is not limited to being understood as a database input algorithm. The database input algorithm corresponds to the above-mentioned process of obtaining the data set to be analyzed corresponding to each data analysis model from all reference data subsets, that is, the input corresponding to the security vulnerability detection analysis model is used to filter the data set to be analyzed corresponding to the security vulnerability detection analysis model from all reference data subsets, the input corresponding to the device status management detection analysis model is used to filter the data set to be analyzed corresponding to the device status management detection analysis model from all reference data subsets, and the input corresponding to the device configuration defect detection analysis model is used to filter the data set to be analyzed corresponding to the device configuration defect detection analysis model from all reference data subsets. Figure 3 The order of input and deep processing described above can be: first perform deep processing on the entire reference data subset, then perform data screening using the database input algorithm described above; or first perform data screening using the database input algorithm, then perform deep processing on the filtered data. In short, the data ultimately input into multiple data analysis models is the data that can be directly mapped to the data analysis models after undergoing both the database input algorithm and deep processing.

[0057] The above-mentioned deep processing includes any one or more of the following: data format conversion (also known as data type conversion, converting the data type into the type of data required by the data analysis model, such as converting int type data into double type data), data verification (verifying the legitimacy of the data itself, such as entering a contact information or ID number. If even the number of digits in the data is incorrect, then it is not a legal data that can be used), dictionary conversion (can be understood as but not limited to converting the format of the data content into a standard format. For example, if multiple types of data are in the same row, dictionary conversion can convert multiple types of data into one type of data per row), and data distribution (sending data to each model).

[0058] It should be noted that the model types of the above-mentioned multiple data analysis models may be the same or different. The model types include regression models, classification models, clustering models, time series models, deep learning models, etc., and the above-mentioned multiple analysis models are any one of the above-mentioned model types.

[0059] Each data analysis model corresponds to a data transmission channel. In the above S3, each data set to be analyzed is transmitted to multiple data analysis models according to the data transmission channel corresponding to each data analysis model (which can be understood, but not limited to, as reading corresponding standardized defense security information according to different categories of vulnerability detection analysis models). Then, multiple data analysis models conduct analysis according to the model rules corresponding to each data analysis model. Finally, each data analysis model outputs the data set required for the vulnerability assessment report of the operation network, namely, the above-mentioned multiple analysis data sets (also referred to as vulnerability assessment data sets). After that, different types of vulnerability assessment reports (i.e., the above-mentioned vulnerability analysis reports) can be output based on the analysis data sets.

[0060] Through the above-mentioned implementation of the present application, in order to address the problems caused by the different formats of existing defense security information based on different network security equipment manufacturers, this example provides an operational network defense vulnerability assessment method and system. Based on this solution, the defense security information generated by various types of equipment can be unified into the system, and the necessary data processing capabilities are provided. Through multiple vulnerability detection and analysis models, a defense vulnerability assessment report for the operational network is formed. At the same time, the above-mentioned implementation can also be used to conduct a comprehensive assessment of the network security vulnerability of the operational network, thereby improving the reliability of the assessment. In addition, the above-mentioned implementation realizes the setting and management of various configuration information, policy information, and asset information (i.e., the above-mentioned multi-source heterogeneous data), so that adaptive assessments can be easily made when the network status changes.

[0061] The operational network being assessed is often characterized by its large scale, more elements, and more dimensions and data volumes than the vulnerability assessments previously conducted on single targets or groups of targets. In particular, the operational network's defense status is often in dynamic change, requiring not only analysis of the operational network's security status at a specific event cross-section, but also dynamic vulnerability assessments in both time and space, reflecting these in the various model analysis algorithms. Figure 3 The analysis operations performed in each data analysis model are described in detail:

[0062] As an optional implementation, the above-mentioned data set to be analyzed corresponding to each data analysis model is transmitted to multiple data analysis models respectively, and multiple analysis data sets output by multiple data analysis models are obtained, including: S1, obtaining the first data set to be analyzed corresponding to the security vulnerability detection analysis model; S2, performing feature extraction on the first data subset and the second data subset respectively, to obtain a first feature set corresponding to the first data subset, and a second feature set corresponding to the second data subset, wherein the first data set to be analyzed includes a first feature set and a second feature set, wherein the first data subset is used to indicate asset data and the second data subset is used to indicate vulnerability data; S3, performing data standardization on the second feature set to obtain a standardized feature set; S4, matching the first feature set and the standardized feature set to obtain the analysis data set corresponding to the security vulnerability detection analysis model.

[0063] The above S1 to S4 can be understood as, but not limited to, specific analysis operations performed by the above security vulnerability detection and analysis model on the input data. The above first data subset can be understood as, but not limited to, Figure 3 The asset data shown includes multiple reference data subsets, and the second data subset can be understood as but not limited to the following: Figure 3 The plurality of reference data subsets in the vulnerability intelligence shown, the first data set to be analyzed includes the asset data and the plurality of reference data subsets in the vulnerability intelligence. After obtaining the first data set to be analyzed, the security vulnerability detection analysis model first extracts features from the first data set to be analyzed (i.e., the aforementioned S2), thereby obtaining a first feature set (e.g., Figure 3 The asset data feature set shown) and the second feature set (such as Figure 3 The unknown vulnerability feature set shown in FIG. 1 is then executed S2 to normalize the data and obtain a standardized feature set (such as Figure 3 The unknown vulnerability feature set standardization results are shown in the figure. It should be noted that before data standardization, the second feature set is also case-converted. Field case conversion can be understood as follows: Generally, in file upload scenarios, especially web file uploads, case conversion is used to evade detection and gain control of devices and systems. Therefore, the field case conversion is performed to detect such evasion methods and thus perform accurate detection.

[0064] The matching in S4 above is as follows Figure 3The asset feature-vulnerability fuzzy matching shown in the figure is mainly to extract the asset data (i.e., the data in the multi-source heterogeneous data) obtained by various detection methods and transmitted to the above-mentioned network security vulnerability assessment system, and match it with the vulnerability association objects and vulnerability descriptions released by CVE, CNNVD, and CNVD to obtain the possible vulnerabilities in the asset data. For example, there is a CVE-2019-0708 vulnerability in the Windows Server 2008 R2 version of the server. This vulnerability can cause attackers to obtain remote operation permissions for servers installed with the Windows Server 2008 R2 version of the operating system. Therefore, all servers in the operating network that are installed with the above-mentioned version of the operating system have corresponding security risks. After the above S1 to S4, the analysis data set corresponding to the security vulnerability detection analysis model can be obtained (i.e., Figure 3 The set of assets associated with the vulnerability as shown).

[0065] The aforementioned security vulnerability detection and analysis model primarily analyzes data on exploitation methods, targets, and vulnerability asset attributes. Exploitation methods include malicious emails, phishing attacks, and removable media; targets include code and protocols; and vulnerability assets include vulnerability unknown, vulnerability category, vulnerability cause, CVSS score, vulnerability level, scope of impact, release date, and severity. The CVSS score ranges from 0 to 10, referencing each vulnerability condition in the CVE database. A higher CVSS score indicates a greater degree of vulnerability risk to the network or system. However, for unknown vulnerabilities, their characteristics should also be considered for classification and storage. Ultimately, vulnerabilities are correlated with asset distribution.

[0066] Through the above-mentioned implementation manner of the present application, the security vulnerability detection and analysis model is used to analyze the first data set to be analyzed, thereby obtaining an analysis data set corresponding to the security vulnerability detection and analysis model.

[0067] As an optional implementation, the above-mentioned data set to be analyzed corresponding to each data analysis model is transmitted to multiple data analysis models respectively, and multiple analysis data sets output by multiple data analysis models are obtained, including: S1, obtaining the second data set to be analyzed corresponding to the equipment status management detection analysis model, the second data set to be analyzed including the first data subset, the third data subset, and the fourth data subset; S2, performing hierarchical classification on the first data subset to obtain a hierarchical data set; S3, performing threshold comparison on the data in the third data subset to obtain a status abnormality data set, wherein the third data subset is used to indicate the equipment status; S4, obtaining multiple topological paths corresponding to the fourth data subset, and determining the influencing device data set corresponding to the fourth data subset based on the multiple topological paths, wherein the fourth data subset is used to indicate the network connection relationship between multiple devices; S5, performing a first evaluation based on the hierarchical data set, the status abnormality data set, and the influencing device data set to obtain the analysis data set corresponding to the equipment status management detection analysis model.

[0068] The above S1 to S5 can be understood as, but not limited to, specific analysis operations performed by the above device status management detection and analysis model on the input data, such as Figure 3 As shown, the second data set to be analyzed includes an asset data set (the first data subset), a device status data set (the third data subset), and a network topology data set (the fourth data subset). The first data subset is then classified by asset level (i.e., the above-mentioned level classification). Asset data mainly refers to the basic attributes of various software and hardware objects being evaluated within the operating network. For example, the asset attributes of hardware such as network equipment and security equipment mainly include: asset name, asset type (hardware / software), asset brand, asset model, asset IP, device survival status (online / offline), open ports, startup services, etc. The asset attributes of software such as business systems and terminal applications mainly include: system / application name, asset type (hardware / software), identity authentication, communication ports, access control, interface call type, database selection type, system architecture type, middleware, etc.

[0069] The above asset classification mainly uses the impact and attention of information assets for comprehensive evaluation. It can be classified according to preset classification rules (or according to expert experience). The levels can be divided into: Severe: severe impact on network operation / critical assets / equipment / business system; High risk: greater impact on network operation / critical assets / equipment / business system; Medium risk: generally severe impact on network operation / critical assets / equipment / business system; Low risk: minor impact on network operation / critical assets / equipment / business system; Minor: extremely minor impact on network operation / critical assets / equipment / business system. After the above classification, the level data set (such as Figure 3The asset importance level data set shown in FIG. 4 is a graph showing the asset importance level data set. That is, the above asset level classification can be understood as, but is not limited to, a classification of asset data based on importance.

[0070] The threshold comparison in the above S3 can be understood, but not limited to, as comparing the state value of the device state with the preset state value. For example, if the CPU occupancy rate is higher than a certain value (for example, the CPU occupancy rate of the device for daily business generally does not exceed 90%), the device state is determined to be abnormal if it exceeds the value, thereby obtaining a state abnormality data set. The process of obtaining multiple topological paths in the above S4 (that is, what devices the entire operating network needs to pass through during the communication process, such as routers, business terminals, and business terminals connected to servers, then if a terminal is at risk, the server connected to this terminal will also be at risk, but if a small LAN is not connected to another small LAN, then the risky small LAN will not affect the other small LAN) can be understood, but not limited to, as follows Figure 3 The process of the topology path part shown in FIG is implemented by a topology path algorithm. The topology path algorithm can traverse the network topology graph to obtain the possible spread range of a security threat. The process of obtaining multiple topology paths in the above S4 is as follows: Figure 4 As shown, assuming that the interconnection between devices 401, 402, 403 and 404 is carried out through the operation network 1, and the interconnection between devices 405, 406, 407 and 408 is carried out through the operation network 2, and assuming that the operation network 1 is at risk and the operation network 2 is not at risk, then the devices connected through the operation network 1 may be at risk, that is, Figure 4 Devices 401, 402, 403, and 404 shown will be affected devices, while devices 405, 406, 407, and 408 will not be affected. Then the affected device data set includes devices 401, 402, 403, and 404. The above process of determining the affected device data set based on multiple topological paths can be understood as, but not limited to, traversing the network topology map (i.e., the topology map composed of multiple devices connected to the operating network) (it can also be understood as traversing multiple topological paths), thereby deriving the possible spread range of a certain security threat. Afterwards, a first evaluation can be performed based on the data sets obtained in S2 to S4 ( Figure 3 The equipment status and distribution evaluation shown in the figure) is used to obtain the analysis data set corresponding to the equipment status management detection and analysis model ( Figure 3 The first evaluation result set shown).

[0071] Device status management detection and analysis model: includes the device's asset attribute data set, device status, and network topology. Asset attributes include host, software, operating system, IP address, port, etc. Device status includes communication status, access status, business continuity status, etc. Topology information includes gateway, network, node, route, etc.

[0072] Through the above-mentioned implementation of the present application, by adopting the above-mentioned implementation, an analysis data set related to the device status can be accurately obtained, thereby ensuring analysis in terms of the device status.

[0073] As an optional implementation, the above-mentioned data set to be analyzed corresponding to each data analysis model is transmitted to multiple data analysis models respectively, and multiple analysis data sets output by multiple data analysis models are obtained, including: S1, obtaining a third data set to be analyzed corresponding to the equipment configuration defect detection analysis model, wherein the third data set to be analyzed includes a fifth data subset and a sixth data subset; S2, performing a policy check on the fifth data subset to obtain a verification data set, wherein the fifth data subset is used to indicate the device configuration information corresponding to each of the multiple devices, and the policy check is used to verify whether the device configuration information meets the preset configuration requirements; S3, performing a risk assessment on the fifth data subset to obtain a risk assessment data set, wherein the fifth data set is used to indicate data that poses a security threat; S4, performing a second assessment based on the verification data set and the risk assessment data set to obtain an analysis data set corresponding to the equipment configuration defect detection analysis model.

[0074] The operations in S1 to S4 above can be understood as, but not limited to, Figure 3 The specific analysis process of the equipment configuration defect detection analysis model shown in FIG. 1 on the input data, the fifth data subset in the above S1 can be understood as, but not limited to, Figure 3 The device configuration data set shown, the sixth data subset can be understood as but not limited to the following Figure 3 The security threat data set shown in the figure; the device configuration defect detection and analysis model includes a policy verification algorithm (the above-mentioned policy verification) and a risk impact domain assessment algorithm (the above-mentioned risk assessment). The policy verification can automatically verify the security policy data of the operating network terminals, the security protection equipment in the network, etc., evaluate the compliance of the security policy, detect the abnormal conditions in the security policy configuration, and give an assessment conclusion; the risk impact domain assessment algorithm can evaluate the potential risk impact domain through policy relevance. The second assessment in S4 is as follows: Figure 3 The device policy configuration defects and impact domain assessment shown in the figure are analyzed as follows: Figure 3 The second evaluation result set is shown.

[0075] It should be noted that if Figure 3The report output shown can be understood as, but not limited to, the input of data output by multiple data analysis models into Figure 1 The vulnerability analysis reporting unit 106 shown is used to generate a vulnerability analysis report, such as Figure 3 The storage output shown is used to store the data output by multiple data analysis models into the data storage unit for storage.

[0076] Through the above-mentioned implementation of the present application, by adopting the above-mentioned implementation, an analysis data set related to the device configuration information can be accurately obtained, thereby ensuring analysis in terms of the device status.

[0077] It should be noted that for the aforementioned method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present invention is not limited by the order of the actions described, because according to the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.

[0078] According to another aspect of an embodiment of the present invention, an electronic device for implementing the above-mentioned network security vulnerability assessment method is also provided, and the electronic device may be a terminal device or a server. This embodiment is illustrated by taking the electronic device as a terminal device as an example. The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor performs the steps in any one of the above-mentioned method embodiments. Optionally, in this embodiment, the above-mentioned electronic device may be located in at least one network device among a plurality of network devices of a computer network. Optionally, in this embodiment, the above-mentioned processor may be configured to execute the various steps in the above-mentioned network security vulnerability assessment method through a computer program.

[0079] Alternatively, those skilled in the art will appreciate that the structure of the electronic device described above is merely illustrative, and the electronic device may also be a terminal device such as a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, or a mobile internet device (MID), PAD, etc. The above description does not limit the structure of the electronic device described above. For example, the electronic device may include more or fewer components (such as a network interface, etc.) than described above, or have a configuration different from that described above. The memory may be used to store software programs and modules, such as the program instructions / modules corresponding to the network security vulnerability assessment method and system in the embodiments of the present invention. The processor executes the software programs and modules stored in the memory to perform various functional applications and data processing, thereby implementing the network security vulnerability assessment method described above. The memory may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the aforementioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. The memory may be specifically, but not limited to, used to store information involved in the above-mentioned network security vulnerability assessment method.

[0080] Optionally, the transmission device is used to receive or send data via a network. Specific examples of the network may include wired networks and wireless networks. In one example, the transmission device includes a network adapter (NIC), which can be connected to other network devices and a router via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly. In addition, the electronic device further includes: a display and a connection bus for connecting the various module components in the electronic device.

[0081] In other embodiments, the terminal device or server may be a node in a distributed system, which may be a blockchain system. The blockchain system may be a distributed system formed by connecting multiple nodes via network communication. The nodes may form a peer-to-peer (P2P) network, and any computing device, such as a server, terminal, or other electronic device, may become a node in the blockchain system by joining the peer-to-peer network.

[0082] According to one aspect of the present application, a computer program product is provided, comprising a computer program / instructions containing program code for executing a network security vulnerability assessment method. In such an embodiment, the computer program can be downloaded and installed from a network via a communication component and / or installed from a removable medium. When executed by a central processing unit, the computer program performs the various functions provided in the embodiments of the present application.

[0083] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0084] According to one aspect of the present application, a computer-readable storage medium is provided, and a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned network security vulnerability assessment method.

[0085] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for executing the network security vulnerability assessment method.

[0086] Those skilled in the art will understand that all or part of the processes in the above method embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes in the above method embodiments. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (FM), a hard disk drive (HDD), or a solid-state drive (SSD). The storage medium can also include a combination of the above types of memory. If the integrated unit in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the above-mentioned computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing one or more computer devices (which may be personal computers, servers, or network devices, etc.) to perform all or part of the steps of the above-mentioned methods of various embodiments of the present invention. In the above-mentioned embodiments of the present invention, the description of each embodiment has its own focus. For portions not detailed in one embodiment, please refer to the relevant descriptions of other embodiments.

[0087] In the several embodiments provided herein, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units described above is merely a logical functional division. In actual implementation, other divisions may be employed. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be through interfaces, or indirect couplings or communication connections between units or modules, and may be electrical or other forms. The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of these units may be selected to achieve the objectives of the present embodiments as needed. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The integrated units described above may be implemented in either hardware or software functional units.

[0088] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A network security vulnerability assessment method, applied to a network security vulnerability assessment system, characterized in that: include: Acquiring multi-source heterogeneous data through a data reading cluster, wherein the multi-source heterogeneous data is data used to indicate network security information; Classifying the multi-source heterogeneous data to obtain a plurality of reference data sets indicating different categories of network security information, wherein each reference data set corresponds to a category of network security information, and each reference data set includes a plurality of reference data subsets; Acquire multiple data analysis models, and acquire a data set to be analyzed corresponding to each of the data analysis models from multiple reference data subsets included in the multiple reference data sets; Using data transmission channels corresponding to the multiple data analysis models, respectively transmitting the data set to be analyzed corresponding to each data analysis model to the multiple data analysis models, thereby obtaining multiple analysis data sets output by the multiple data analysis models, wherein each data analysis model corresponds to one data transmission channel and each data analysis model corresponds to one analysis data set; A vulnerability analysis report is generated according to data analysis requirements and at least one analysis data set among a plurality of analysis data sets, and a network security vulnerability assessment result is determined according to the vulnerability analysis report.

2. The method according to claim 1, characterized in that The data analysis model includes: a security vulnerability detection analysis model, a device status management detection analysis model, and a device configuration defect detection analysis model.

3. The method according to claim 2, characterized in that Transmitting the data set to be analyzed corresponding to each data analysis model to the multiple data analysis models to obtain multiple analysis data sets output by the multiple data analysis models, including: Obtaining a first data set to be analyzed corresponding to the security vulnerability detection and analysis model; Performing feature extraction on the first data subset and the second data subset respectively to obtain a first feature set corresponding to the first data subset and a second feature set corresponding to the second data subset, wherein the first data set to be analyzed includes the first feature set and the second feature set, wherein the first data subset is used to indicate asset data, and the second data subset is used to indicate vulnerability data; performing data normalization on the second feature set to obtain a normalized feature set; The first feature set and the standardized feature set are matched to obtain an analysis data set corresponding to the security vulnerability detection analysis model.

4. The method according to claim 3, characterized in that Transmitting the data set to be analyzed corresponding to each data analysis model to the multiple data analysis models to obtain multiple analysis data sets output by the multiple data analysis models, including: Acquire a second data set to be analyzed corresponding to the device status management detection and analysis model, where the second data set to be analyzed includes the first data subset, the third data subset, and the fourth data subset; performing hierarchical classification on the first data subset to obtain a hierarchical data set; Performing a threshold comparison on data in a third data subset to obtain a state abnormality data set, wherein the third data subset is used to indicate a device state; Acquire multiple topological paths corresponding to a fourth data subset, and determine an influencing device data set corresponding to the fourth data subset based on the multiple topological paths, wherein the fourth data subset is used to indicate a network connection relationship between multiple devices; A first evaluation is performed based on the level data set, the abnormal state data set, and the impact device data set to obtain an analysis data set corresponding to the device state management detection and analysis model.

5. The method according to claim 2, characterized in that Transmitting the data set to be analyzed corresponding to each data analysis model to the multiple data analysis models to obtain multiple analysis data sets output by the multiple data analysis models, including: Acquire a third data set to be analyzed corresponding to the equipment configuration defect detection and analysis model, wherein the third data set to be analyzed includes a fifth data subset and a sixth data subset; performing a policy check on the fifth data subset to obtain a check data set, wherein the fifth data subset is used to indicate device configuration information corresponding to each of the plurality of devices, and the policy check is used to verify whether the device configuration information complies with preset configuration requirements; Performing a risk assessment on the fifth data subset to obtain a risk assessment data set, wherein the fifth data subset is used to indicate data that poses a security threat; A second evaluation is performed based on the verification data set and the risk assessment data set to obtain an analysis data set corresponding to the equipment configuration defect detection analysis model.

6. The method according to claim 1, characterized in that Generating a vulnerability analysis report according to a data analysis requirement and at least one of the plurality of analysis data sets includes: Obtaining the data analysis requirements; Acquire a report template according to the data analysis requirement, and acquire at least one analysis data set from a plurality of analysis data sets; A plurality of data in at least one of the analysis data sets are respectively mapped to designated positions in the report template to obtain the vulnerability analysis report.

7. The method according to claim 2, characterized in that Also includes: The plurality of reference data sets, the plurality of analysis data sets and the vulnerability analysis report are stored in a preset designated storage location respectively.

8. A network security vulnerability assessment system, characterized in that: include: a data acquisition unit, configured to acquire multi-source heterogeneous data through a data reading cluster, and transmit the multi-source heterogeneous data to multiple data analysis models using multiple data transmission channels, wherein the multi-source heterogeneous data is data indicating network security information, and the data acquisition unit is further configured to classify the multi-source heterogeneous data to obtain multiple reference data sets indicating different categories of network security information, wherein each reference data set corresponds to a category of network security information, and each reference data set includes multiple reference data subsets; a vulnerability model detection unit, configured to provide a plurality of the data analysis models, and to obtain a data set to be analyzed corresponding to each of the data analysis models from a plurality of reference data subsets included in the plurality of reference data sets, the vulnerability model detection unit being further configured to transmit the data set to be analyzed corresponding to each of the data analysis models to the plurality of data analysis models by using data transmission channels corresponding to the plurality of data analysis models, respectively, to obtain a plurality of analysis data sets output by the plurality of data analysis models, wherein each data analysis model corresponds to one data transmission channel, and each data analysis model corresponds to one analysis data set; The vulnerability analysis reporting unit is configured to generate a vulnerability analysis report based on data analysis requirements and at least one of the plurality of analysis data sets, and to determine a network security vulnerability assessment result based on the vulnerability analysis report.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the network security vulnerability assessment method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the network security vulnerability assessment method described in any one of claims 1-7.

Citation Information

Patent Citations

  • Method and apparatus for evaluating network security situation

    CN108683663A

  • Asset vulnerability analysis method and device based on multiple logs and storage medium

    CN116628625A