Security Risk Assessment Method and System for Informationization Platform

By collecting and processing the security feature factors of the information platform, building a training set and using a prediction neural network, the problem of insufficient data of the security feature factors of the information platform is solved, and the accuracy of risk assessment is improved.

CN119904106BActive Publication Date: 2025-08-05山东省大数据中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510386564.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-08-05
Estimated Expiration
2045-03-31

AI Technical Summary

Technical Problem

During the operation of the information platform, the insufficient amount of security characteristic factor data is caused by insufficient accuracy in security risk assessment.

Method used

By collecting the security feature factors of the information platform to be evaluated and other information platform, performing feature factor screening, format conversion, standardization processing, clustering and assigning labels, building training sets, and using predictive neural networks for risk assessment.

Benefits of technology

The data volume of the training set is expanded, the training accuracy and evaluation accuracy of the prediction model are improved, and the problem of insufficient data volume is solved.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention belongs to the field of risk assessment technology, and more specifically, relates to a security risk assessment method and system for an information platform. The security characteristic factors of the information platform to be assessed are collected within a preset time length to form a security characteristic factor data set 1; after clustering the security characteristic factors in the security characteristic factor data set, labels are assigned to the security characteristic factors in each cluster to obtain a training set 1; if the number of training set 1 is insufficient, data is collected from other information platforms to obtain a training set 2; after the labels in the training set 2 are corrected by correction factors, they are merged with the training set 1 to obtain a training set, and after training the predictive neural network, a security risk assessment is performed. This solves the problem of insufficient security characteristic factor data generated during the operation of the information platform and improves the accuracy of the assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of risk assessment, and more specifically, relates to a security risk assessment method and system for an information platform. Background Art

[0002] To achieve unified management and coordination of data, resources, and processes, various industries are establishing information platforms. With the widespread adoption of digital government, public-facing information platforms are being built. However, security issues require special attention during the operation of information platforms. Therefore, it is crucial to conduct security risk assessments based on the diverse data generated during their operation and to implement risk prevention and control measures based on the assessment results. Summary of the Invention

[0003] The present invention provides a method and system for assessing security risks of an information platform.

[0004] The security risk assessment method for the information platform includes:

[0005] S1: Collect several characteristic factors related to attack status, threat status, asset status, violation status, and system work order response processing of the information platform to be evaluated within a preset time period. Select security characteristic factors related to security from the characteristic factors, remove invalid data, convert the format, and perform standardization. Obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the security characteristic factor dataset 1.

[0006] S2: After clustering the security feature factors in the security feature factor dataset, labels are assigned to the security feature factors in each cluster to obtain training set 1. A determination is made as to whether the number of samples in training set 1 exceeds a sample number threshold. If so, training set 1 is used as the training set and S5 is executed. If not, S3 is executed.

[0007] S3: Collect several characteristic factors related to attack situation, threat situation, asset situation, violation situation, and system work order response processing from other information platforms within a preset time period. Select security characteristic factors related to security from these characteristic factors, remove invalid data, convert the format, and perform standardization. Obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the second security characteristic factor dataset.

[0008] S4: After clustering the security feature factors in the security feature factor dataset 2, labels are assigned to the security feature factors in each cluster to obtain the training set 2; the labels in the training set 2 are corrected by the correction factor and then merged with the training set 1 to obtain the training set.

[0009] S5: Use the training set to train the prediction neural network to obtain a trained prediction neural network;

[0010] S6: The newly obtained security characteristic factors of the evaluation information platform are processed using the trained predictive neural network to obtain the security risk assessment results.

[0011] Security characteristic factors include confidentiality, number of vulnerabilities, number of alarms, whether there is security protection, open port monitoring, whether there is a responsible person, whether there is security equipment, whether the storage address is clear, number of security incidents within the statistical period, number of vulnerabilities within the statistical period, number of attacks, number of threats, number of dangers, and number of violations.

[0012] Attacks include DDos attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, phishing, SQL injection, information tampering, information leakage, and information theft;

[0013] Threats include viruses, vulnerabilities, worms, Trojans, botnets, malicious code, and network information sniffing;

[0014] Violations include exceeding access frequency limits, exceeding access traffic limits, outbound file transmission, illegal external connections, illegal access, and illegal file downloads.

[0015] The correction factor is determined based on the business overlap, characteristic factor overlap, and visit volume difference ratio of different information platforms.

[0016] The proportion of security feature factors from a certain information platform in training set 2 is positively correlated with its correction factor.

[0017] Security risk assessment system for information platform,

[0018] The first security feature factor dataset construction module collects several feature factors related to attack status, threat status, asset status, violation status, and system work order response processing of the information platform to be evaluated within a preset time period. Security-related security feature factors are screened from the feature factors, invalid data is removed, and after format conversion and standardization, the variance of each security feature factor is obtained. Security feature factors with variances exceeding the variance threshold are selected to form the first security feature factor dataset.

[0019] Training set 1 construction module: After clustering the security signature factors in the security signature factor dataset, labels are assigned to the security signature factors in each cluster to obtain training set 1. A determination is made as to whether the number of samples in training set 1 exceeds the sample number threshold. If so, training set 1 is used as the training set and input into the training module. If not, the contents of the security signature factor dataset 2 construction module are executed.

[0020] The second security feature factor dataset construction module collects several feature factors related to attack trends, threat trends, asset trends, violation trends, and system work order response processing from other information platforms within a preset time period. Security-related security feature factors are screened from these feature factors, invalid data is removed, format conversion is performed, and standardization is performed. The variance of each security feature factor is obtained, and security feature factors with variances exceeding the variance threshold are selected to form the second security feature factor dataset.

[0021] Training set construction module: After clustering the security feature factors in the security feature factor dataset 2, labels are assigned to the security feature factors in each cluster to obtain the training set 2; the labels in the training set 2 are corrected by the correction factor and then merged with the training set 1 to obtain the training set.

[0022] Training module: Use the training set to train the prediction neural network to obtain the trained prediction neural network;

[0023] Evaluation module: The newly obtained security characteristic factors of the evaluation information platform are processed using the trained predictive neural network to obtain the security risk assessment results.

[0024] Beneficial effects of the present invention:

[0025] 1. By designing correction factors based on the business overlap, characteristic factor overlap, and visit volume difference ratio between other informatization platforms and the informatization platform to be evaluated, the data volume of the training set can be expanded, solving the problem of insufficient data volume of security characteristic factors generated during the operation of the informatization platform, improving the training accuracy of the prediction model, and enhancing the accuracy of the evaluation;

[0026] 2. During the construction of the characteristic factor data set, the variance of each safety characteristic factor is obtained by screening the characteristic factors, removing invalid data, converting the format, and performing standardization. The safety characteristic factors with variances exceeding the variance threshold are selected to screen out the characteristic factors that have a greater impact on the safety performance evaluation and improve the evaluation accuracy. DETAILED DESCRIPTION

[0027] The technical solution of this application is described in detail below with reference to specific embodiments.

[0028] The security risk assessment method for the information platform includes:

[0029] S1: Collect several characteristic factors related to the attack situation, threat situation, asset situation, violation situation, and system work order response processing of the information platform to be evaluated within a preset time length, filter security characteristic factors related to security from the characteristic factors, remove invalid data, convert the format, and perform standardization processing to obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the security characteristic factor data set 1.

[0030] Security assessments are conducted based on security characteristics such as attack situation, threat situation, asset situation, violation situation, and system work order response processing, including:

[0031] 1. Attack Situation

[0032] The number of attacks from outside the network during the statistical period, including but not limited to DDos attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, phishing, SQL injection, information tampering, information leakage, and information theft.

[0033] 2. Threat Landscape

[0034] The number of threats detected from threat intelligence during the statistical period, including but not limited to viruses, vulnerabilities, worms, Trojans, botnets, malicious codes, and network information sniffing.

[0035] 3. Asset situation

[0036] Vulnerability and configuration weakness data from assets during the statistical period, including but not limited to relevant risk indices, and the impact or degree of damage caused to the assets.

[0037] 4. Illegal behavior

[0038] Frequency statistics of internal violations during the statistical period, including but not limited to access frequency exceeding the limit, access traffic exceeding the limit, file outbound transmission, illegal external connection, illegal access, illegal file download, etc.

[0039] 5. Work order response processing

[0040] Responses to security issue tickets during the statistical period, including but not limited to the number of tickets, number of processed tickets, processing time, etc.

[0041] The characteristic factors of an information platform include factors related to value, security, and health. For the security model, 16 security characteristic factors of the information platform were selected from 68 characteristic factors, as shown in Table 1 below:

[0042] Table 1 Safety characteristic factors

[0043] English name of safety characteristic factor Chinese name of safety characteristic factor confidentiality Confidentiality hole_high_cnt Number of Vulnerabilities - High hole_mid_cnt Number of vulnerabilities - Medium warn_high_cnt Number of Alarms - High warn_low_cnt Number of Alarms - Medium isHierarchyProtection Whether the insurance openPortMonitor Open port monitoring personInCharge Is there a responsible person? securityDevice Is there safety equipment? storeLocation Is the storage address clear? l1m_security_num Number of security incidents in the past month l1m_flaw_num Number of vulnerabilities in the past month attack_num Number of attacks threat_num Number of threats danger_num Number of dangers violation_num Number of violations .

[0044] Collect monthly or weekly data of the above-mentioned safety characteristic factors. The data needs to be pre-processed before use, which mainly includes the following processing steps:

[0045] 1. Factor feature transformation

[0046] For character data in factors, to facilitate modeling and calculation, they need to be converted through code mapping or direct conversion to numerical values.

[0047] Convert null values in factor columns to zero values. For example, if the value of the alarm quantity - high school column is null, convert it to 0.

[0048] 2. Invalid column processing

[0049] During the feature factor data statistics process, there may be cases where there is no data. These invalid factor columns need to be removed before modeling. For example, if there is no data in the attack count column, this column should be removed.

[0050] 3. Eigenvalue processing

[0051] The degree of discreteness of factor eigenvalues determines the effectiveness of factor re-clustering. Factor columns without discrete properties are meaningless for classification and should be removed before modeling. For example, if the "Whether to Clearly Store Addresses" column has a "No" value and the number of field enumeration types is 1, then the column does not have discrete properties and should be removed.

[0052] 4. Feature Filtering

[0053] Considering the characteristic variance of factors and selecting factors with relatively good dispersion for modeling helps avoid the high model errors caused by high-dimensional clustering and improves modeling effectiveness. Specifically, the variance of each factor in the standardized or normalized data can be calculated, observing the differences between the variances and prioritizing factors with larger variances. Alternatively, by setting the parameter for selecting the number of factors, select the top N factors with the largest variances. For example, if the variance of the medium alarm number is lower than that of the low alarm number and high alarm number, it can be discarded during the final factor selection process.

[0054] 5. Data standardization

[0055] In data analysis, the mathematical scales of the system's characteristic factors are inconsistent, so a standardization step is needed to process the characteristic factors and eliminate the differences between them. Standardization is to uniformly map the characteristic factors to the interval [0,1].

[0056] For example, data normalization is used to standardize the data, that is, to uniformly map the characteristic factors to the interval [0,1] and distinguish between indicators with positive and negative effects.

[0057] IsHierarchyProtectiony (Is Hierarchy Protection) reduces risk, so it is negatively impacted and mapped to the range [-1, 0]. A value of 0 indicates no, so a -1 mapping is performed; a value of 1 indicates yes, so a 0 mapping is performed.

[0058] The normalization idea can be realized through the following formula:

[0059] New data = (original data - minimum value) / (maximum value - minimum value)

[0060] S2: After clustering the security feature factors in the security feature factor data set, labels are assigned to the security feature factors in each cluster to obtain training set 1; determine whether the number of samples in training set 1 exceeds the sample number threshold. If so, use training set 1 as the training set and execute S5. If not, execute S3.

[0061] Clustering is to cluster the analysis objects, which is to regard the standardized objects as "individuals". The correlation coefficient between objects describes the similarity between "individuals".

[0062] (1) Object table conversion processing

[0063] All analysis objects are standardized to compare the relationships between them.

[0064] (2) Object clustering

[0065] The correlation coefficient between objects is used as the similarity measure between objects in the model, and the objects are clustered using existing clustering methods (such as the K-Means algorithm) to divide the objects into N categories as needed.

[0066] (3) Object screening

[0067] According to the clustering results, one object is selected from each class as the representative of this type of variable, and the integrated objects are used as the screening results.

[0068] The representative of each class is assigned a benchmark label of this class, and the remaining objects are adjusted based on the benchmark label according to the correlation coefficient, which can be defined using the Euclidean distance.

[0069] For example, the labels of objects other than the representative in each class can be calculated according to the following formula:

[0070] T j =T0+α j ·ρ j ;

[0071] Where T jis the label of the jth object in each class except the representative, T0 is the benchmark label, α j is the weight of the j-th object, ρ j is the correlation coefficient between the jth object and the representative, and the Spearman rank correlation coefficient can be used, which ranges from -1 to 1.

[0072] S3: Collect several characteristic factors related to attack situation, threat situation, asset situation, violation situation and system work order response processing from other information platforms within a preset time length, filter security characteristic factors related to security from the characteristic factors, remove invalid data, convert the format, and perform standardization processing to obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the security characteristic factor data set 2.

[0073] During the operation of the information platform, the number of available security feature factors may be relatively small during the data collection cycle, and it may not be possible to form a training set that can meet the required number for training the predictive neural network. In order to solve this problem, security feature factors from other information platforms are introduced.

[0074] To avoid the introduction of invalid or unusable data in subsequent operations, when selecting other information platforms, focus on those that have at least some overlap in business with the platform being evaluated. For example, if the platform being evaluated is a government information platform that includes a business module for the latest policies or work notifications, then when selecting other information platforms, focus on those that also include this business module.

[0075] After selecting other information platforms, several characteristic factors are collected, security characteristic factors are screened, and the specific operations of selecting security characteristic factors whose variance exceeds the variance threshold to form the second security characteristic factor data set are the same as in step S1.

[0076] However, because different information platforms have different business contents, their potential security risks will also vary. In order to eliminate or reduce the impact of such differences as much as possible, the concept of correction factor is introduced.

[0077] S4: After clustering the security feature factors in the security feature factor dataset 2, labels are assigned to the security feature factors in each cluster to obtain the training set 2; the labels in the training set 2 are corrected by the correction factor and then merged with the training set 1 to obtain the training set.

[0078] After clustering the security feature factors in the second security feature factor dataset, labels are assigned to the security feature factors in each cluster to obtain the second training set. The operation is the same as step S2 and will not be repeated here.

[0079] Different information platforms have different security characteristics such as attack situation, threat situation, asset situation, violation situation, and system work order response processing due to differences in business. As a result, security risks will also vary due to such differences. Correction factors are set based on such differences.

[0080] The correction factor can be calculated based on the business overlap, characteristic factor overlap, and visit volume difference ratio of different information platforms.

[0081] Business overlap has been discussed above. Business overlap refers to the number of overlapping businesses on other informatization platforms compared to the total number of businesses on the informatization platform being evaluated. For example, if another informatization platform has two overlapping businesses with the informatization platform being evaluated, and the total number of businesses on the informatization platform being evaluated is 10, then the business overlap = 2 / 10 = 20%. A higher business overlap indicates a higher correlation between the two informatization platforms.

[0082] The overlap of characteristic factors refers to the 16 security characteristic factors screened out in S1. If all other information platforms include them, the overlap of characteristic factors is 100%. If only 10 of them are included, the overlap of characteristic factors = 10 / 16 = 62.5%.

[0083] The visit volume difference ratio refers to the ratio of the difference in visit volume between other information platforms and the platform being evaluated to the total visit volume of the platform being evaluated. For example, if, within a certain time period, other information platforms received 2,000 visits, while the platform being evaluated received 2,500 visits, the visit volume difference ratio = (2,000 - 2,500) / 2,500 = -20%. This value is positive if other information platforms receive more visits than the platform being evaluated.

[0084] Correction factor Q of the i-th information platform i The calculation can refer to the following formula:

[0085] Q i =a·M i +b·N i +c·E i

[0086] Among them, a, b, and c are the correction coefficients of the corresponding factors, which can be pre-set according to the importance of business overlap, characteristic factor overlap, and visit volume difference ratio on different information platforms. i is the business overlap between the i-th information platform and the information platform to be evaluated, N i is the overlap of characteristic factors between the i-th information platform and the information platform to be evaluated, E iis the difference ratio of visits between the i-th information platform and the information platform to be evaluated.

[0087] When performing the above operations, correction factors can be calculated for all collected information platforms in advance. These can then be sorted from largest to smallest based on the correction factor values. Starting from the first position, the appropriate number of information platforms corresponding to the correction factors can be selected for use. The number of other information platforms introduced can be limited by setting a correction factor threshold. Alternatively, the number of samples in the training set can be set to determine the number of other information platforms introduced based on the number of samples each information platform can provide.

[0088] The number of data included in the second training set is determined by the difference between the total number of data in the required training set and the number of data in the first training set.

[0089] At the same time, the proportion of security feature factors from this information platform in training set 2 can also be determined based on the value of the correction factor. For example, the larger the correction factor, the larger its proportion can be set. That is, the proportion of security feature factors from a certain information platform in training set 2 is positively correlated with its correction factor.

[0090] P i =X i Q i ,

[0091] Among them, P i is the proportion of samples from the i-th information platform in the second training set, X i is the adjustment coefficient, Q i is the correction factor of the i-th information platform.

[0092] You can also use the above method to construct a test set, which will not be described here.

[0093] S5: Use the training set to train the prediction neural network to obtain a trained prediction neural network.

[0094] The prediction neural network can be a BP neural network or other neural network with prediction function that is currently widely used.

[0095] S6: The newly obtained security characteristic factors of the information platform to be evaluated are processed using the trained predictive neural network to obtain the security risk assessment results.

[0096] By setting thresholds, the risk probability output by the trained predictive neural network is divided into several intervals, such as no risk (e.g., 0-50%), low risk (e.g., 50-70%), medium risk (e.g., 70-85%), and high risk (e.g., greater than 85%). After processing by the predictive neural network, if the output probability is 63%, it falls into the low-risk interval. The above interval settings are only examples; specific thresholds and interval settings can be customized based on the specific circumstances of the information platform being evaluated.

[0097] The above method can be used when one of the monitored information platforms is used as the evaluation target. It can also be used for all the monitored information platforms. It is only necessary to first select one of the information platforms as the basic evaluation target. This selection can be based on the comprehensiveness and number of business modules covered by the information platform, such as selecting the platform with the largest number of business modules or the widest business coverage. The method of the present invention has very broad applicability.

[0098] Security risk assessment system for information platform,

[0099] The first security feature factor dataset construction module collects several feature factors related to attack status, threat status, asset status, violation status, and system work order response processing of the information platform to be evaluated within a preset time period. Security-related security feature factors are screened from the feature factors, invalid data is removed, and after format conversion and standardization, the variance of each security feature factor is obtained. Security feature factors with variances exceeding the variance threshold are selected to form the first security feature factor dataset.

[0100] Training set 1 construction module: After clustering the security signature factors in the security signature factor dataset, labels are assigned to the security signature factors in each cluster to obtain training set 1. A determination is made as to whether the number of samples in training set 1 exceeds the sample number threshold. If so, training set 1 is used as the training set and input into the training module. If not, the contents of the security signature factor dataset 2 construction module are executed.

[0101] The second security feature factor dataset construction module collects several feature factors related to attack trends, threat trends, asset trends, violation trends, and system work order response processing from other information platforms within a preset time period. Security-related security feature factors are screened from these feature factors, invalid data is removed, format conversion is performed, and standardization is performed. The variance of each security feature factor is obtained, and security feature factors with variances exceeding the variance threshold are selected to form the second security feature factor dataset.

[0102] Training set construction module: After clustering the security feature factors in the security feature factor dataset 2, labels are assigned to the security feature factors in each cluster to obtain the training set 2; the labels in the training set 2 are corrected by the correction factor and then merged with the training set 1 to obtain the training set.

[0103] Training module: Use the training set to train the prediction neural network to obtain the trained prediction neural network;

[0104] Evaluation module: The newly obtained security characteristic factors of the evaluation information platform are processed using the trained predictive neural network to obtain the security risk assessment results.

Claims

1. The security risk assessment method of the information platform is characterized by: include: S1: Collect several characteristic factors related to attack status, threat status, asset status, violation status, and system work order response processing of the information platform to be evaluated within a preset time period. Select security characteristic factors related to security from the characteristic factors, remove invalid data, convert the format, and perform standardization. Obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the security characteristic factor dataset 1. S2: After clustering the security feature factors in the security feature factor dataset, labels are assigned to the security feature factors in each cluster to obtain training set 1. A determination is made as to whether the number of samples in training set 1 exceeds a sample number threshold. If so, training set 1 is used as the training set and S5 is executed. If not, S3 is executed. S3: Collect several characteristic factors related to attack situation, threat situation, asset situation, violation situation, and system work order response processing from other information platforms within a preset time period. Select security characteristic factors related to security from these characteristic factors, remove invalid data, convert the format, and perform standardization. Obtain the variance of each security characteristic factor. Select the security characteristic factors whose variance exceeds the variance threshold to form the second security characteristic factor dataset. S4: After clustering the security characteristic factors in the second security characteristic factor dataset, labels are assigned to the security characteristic factors in each cluster to obtain a second training set. The labels in the second training set are corrected by correction factors and then merged with the first training set to obtain a training set. The correction factors are determined based on the business overlap, characteristic factor overlap, and visit volume difference ratio of different information platforms. S5: Use the training set to train the prediction neural network to obtain a trained prediction neural network; S6: The newly obtained security characteristic factors of the information platform to be evaluated are processed using the trained predictive neural network to obtain the security risk assessment results.

2. The security risk assessment method according to claim 1, characterized in that: Security characteristic factors include confidentiality, number of vulnerabilities, number of alarms, whether there is security protection, open port monitoring, whether there is a responsible person, whether there is security equipment, whether the storage address is clear, number of security incidents within the statistical period, number of vulnerabilities within the statistical period, number of attacks, number of threats, number of dangers, and number of violations.

3. The security risk assessment method according to claim 2, characterized in that: Attacks include DDos attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, phishing, SQL injection, information tampering, information leakage, and information theft; Threats include viruses, vulnerabilities, worms, Trojans, botnets, malicious code, and network information sniffing; Violations include exceeding access frequency limits, exceeding access traffic limits, outbound file transmission, illegal external connections, illegal access, and illegal file downloads.

4. The security risk assessment method according to claim 1, wherein: The proportion of security feature factors from a certain information platform in training set 2 is positively correlated with its correction factor.

5. The security risk assessment method according to claim 1, characterized in that: The correction factors of other information platforms collected are calculated in advance, and the data are sorted in descending order according to the values of the correction factors.

6. The security risk assessment system of the information platform is characterized by: The first security feature factor dataset construction module collects several feature factors related to attack status, threat status, asset status, violation status, and system work order response processing of the information platform to be evaluated within a preset time period. Security-related security feature factors are screened from the feature factors, invalid data is removed, and after format conversion and standardization, the variance of each security feature factor is obtained. Security feature factors with variances exceeding the variance threshold are selected to form the first security feature factor dataset. Training set 1 construction module: After clustering the security signature factors in the security signature factor dataset, labels are assigned to the security signature factors in each cluster to obtain training set 1. A determination is made as to whether the number of samples in training set 1 exceeds the sample number threshold. If so, training set 1 is used as the training set and input into the training module. If not, the contents of the security signature factor dataset 2 construction module are executed. The second security feature factor dataset construction module collects several feature factors related to attack trends, threat trends, asset trends, violation trends, and system work order response processing from other information platforms within a preset time period. Security-related security feature factors are screened from these feature factors, invalid data is removed, format conversion is performed, and standardization is performed. The variance of each security feature factor is obtained, and security feature factors with variances exceeding the variance threshold are selected to form the second security feature factor dataset. Training set construction module: After clustering the security feature factors in the second security feature factor dataset, labels are assigned to the security feature factors in each cluster to obtain the second training set. The labels in the second training set are corrected by correction factors and then merged with the first training set to obtain the training set. The correction factors are determined based on the business overlap, feature factor overlap, and visit volume difference ratio of different information platforms. Training module: Use the training set to train the prediction neural network to obtain the trained prediction neural network; Evaluation module: The newly obtained security characteristic factors of the evaluation information platform are processed using the trained predictive neural network to obtain the security risk assessment results.

7. The security risk assessment system according to claim 6, characterized in that: The security characteristic factors include confidentiality, number of vulnerabilities, number of alarms, whether there is security protection, open port monitoring, whether there is a responsible person, whether there is security equipment, whether the storage address is clear, number of security incidents within the statistical period, number of vulnerabilities within the statistical period, number of attacks, number of threats, number of dangers, and number of violations.

Citation Information

Patent Citations

  • Network security situation awareness model and method based on CE-RBF

    CN110392048A

  • Work platform task workload prediction method based on feedback correction

    CN111652403A