A method and apparatus for risk assessment of network assets
By quantitatively analyzing alarm data of network assets and combining the perspectives of threat actors and network assets, this approach addresses the problem that traditional risk assessment methods struggle to adapt to rapid changes in complex environments. It achieves accuracy and quantification in risk assessment, supporting strategy adjustments.
Patent Information
- Application Number
- CN202510021875.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-01-03
AI Technical Summary
Traditional risk assessment methods struggle to detect real-time anomalies in complex and ever-changing network environments, are unable to adapt to rapid changes in system architecture and external threats, and lack quantitative indicators to provide clear guidance for decision-makers.
By acquiring alarm data from multiple network assets and combining the perspectives of threat actors and network assets, quantitative analysis methods are used to transform the alarm data into intuitive risk scores, including threat level scores, vulnerability scores, and risk scores, for comprehensive evaluation.
It improves the accuracy of risk identification, provides quantitative risk assessment results, and offers effective decision support for subsequent strategy adjustments.
Smart Images

Figure CN119906561B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method and apparatus for risk assessment of network assets. Background Technology
[0002] In recent years, with the large-scale development of new technologies and applications such as cloud computing, big data, the Internet of Things, the Industrial Internet, and artificial intelligence, and the continuous improvement of informatization, different network assets face a variety of security threats. Traditional risk assessment methods usually rely on fixed rules and preset models for risk assessment, which proves inadequate in the face of complex and ever-changing network environments. Static methods struggle to detect real-time abnormal activities, cannot adapt to rapid changes in system architecture and external threats, and the results of risk assessments often lack quantitative indicators, making it difficult to provide clear guidance for decision-makers.
[0003] Therefore, in the complex and ever-changing network environment, how to conduct risk assessment of network assets still requires further research. Summary of the Invention
[0004] This application provides a method and apparatus for risk assessment of network assets. Through quantitative analysis, complex alarm data is transformed into intuitive risk scores, thereby achieving risk assessment of network assets and providing effective decision support for subsequent strategy adjustments.
[0005] In a first aspect, embodiments of this application provide a method for risk assessment of network assets. The method includes: acquiring alarm data from multiple network assets, wherein the alarm data is used to indicate at least one threat subject attacking the multiple network assets; determining a threat score for each of the at least one threat subject based on the alarm data; determining a first risk score for the first network asset being attacked based on the threat score of each threat subject and the weight of each threat subject corresponding to a first network asset among the multiple network assets; determining a second risk score for the first network asset being attacked based on the Common Vulnerability Scoring System (CVSS) score, dynamic risk score, and the number of vulnerabilities in at least one vulnerability of the first network asset; and determining a total risk score for the first network asset being attacked based on the first risk score and the second risk score.
[0006] By using the above method, various relevant alarm logs can be obtained from multiple network assets, and risk assessment can be conducted from both the perspectives of threat actors and network assets, which can improve the accuracy of identifying potential risks. Based on the first risk score and the second risk score, the risk of network assets is quantified to obtain the risk score of network assets, so as to provide effective decision support for subsequent strategy adjustments.
[0007] In one optional embodiment, determining a threat score for each of the at least one threat subjects based on the alarm data includes: determining an alarm type popularity score, a focus score, and a time dispersion score for each threat subject based on the alarm data. The alarm type popularity score is used to assess the popularity of the attack methods of the threat subject. The focus score is used to assess the concentration of the attacks by the threat subject and the importance of the target domain to which the network assets attacked by the threat subject belong. The time dispersion score is used to assess the time span of the attacks by the threat subject.
[0008] The threat level score for each threat subject is determined based on its alarm type popularity score, focus score, and time dispersion score.
[0009] Using the above methods, a comprehensive analysis of the threat level of threat subjects from multiple dimensions such as alarm type popularity score, focus score, and time dispersion score can help to further improve the accuracy of the first network asset risk assessment.
[0010] In one optional embodiment, the alarm type popularity score satisfies the following formula: in, Let be the percentage of missed scans for the i-th threat among the at least one threat subjects within a preset first time interval j; let D be the total number of alerts generated by the i-th threat subject using attacks within the preset first time interval j; let E be the reciprocal of the number of threat subjects using popular attacks within the preset first time interval j; and ∝ be the percentage of missed scans for the i-th threat subject among the at least one threat subjects. The adjustment factor is β, where β is the adjustment factor for E.
[0011] In one optional embodiment, the focus score satisfies the following formula: Among them, H i To represent the distribution density of the threat posed to the target domain by the i-th threat subject among the at least one threat subjects within a preset first time interval j, W k γ represents the importance of the target domain, and H represents the importance of the target domain. i The adjustment factor, δ, is the W k The adjustment factor.
[0012] In one alternative embodiment, the time dispersion score satisfies the following formula: Among them, A i (j) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset first time interval j. i(j, g) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset second time interval g, where the second time interval g belongs to the first time interval j, and ε is the attenuation index.
[0013] In one optional embodiment, determining the risk score of the first network asset being attacked based on the first risk score and the second risk score includes: determining the risk score of the first network asset being attacked according to the following formula: in, Let ω'1 be the first risk score for the first network asset being attacked, and ω'1 be the weight corresponding to the first risk score. ω'2 represents the second risk score for the attack on the first network asset, and ω'2 represents the weight corresponding to the second risk score.
[0014] Secondly, embodiments of this application provide a risk assessment device for network assets, the device comprising:
[0015] An acquisition unit is used to acquire alarm data from multiple network assets, wherein the alarm data from the multiple network assets is used to indicate at least one threat subject attacking the multiple network assets;
[0016] The determining unit is configured to: determine a threat score for each of the at least one threat subjects based on the alarm data; determine a first risk score for the first network asset being attacked based on the threat score of each threat subject and the weight of each threat subject corresponding to the first network asset among the plurality of network assets; determine a second risk score for the first network asset being attacked based on the CVSS score, dynamic risk score, and the number of vulnerabilities in at least one vulnerability of the first network asset; and determine a total risk score for the first network asset being attacked based on the first risk score and the second risk score.
[0017] In an optional embodiment, the determining unit is specifically configured to: determine, based on the alarm data, an alarm type popularity score, a focus score, and a time dispersion score for each threat entity; the alarm type popularity score is used to assess the popularity of the attack methods of the threat entity; the focus score is used to assess the concentration of the threat entity's attacks and the importance of the target domain to which the network assets attacked by the threat entity belong; and the time dispersion score is used to assess the time span of the threat entity's attacks; and determine the threat score for each threat entity based on the alarm type popularity score, focus score, and time dispersion score for each threat entity.
[0018] In one optional embodiment, the alarm type popularity score satisfies the following formula: in, Let be the percentage of missed scans for the i-th threat among the at least one threat subjects within a preset first time interval j; let D be the total number of alerts generated by the i-th threat subject using attacks within the preset first time interval j; let E be the reciprocal of the number of threat subjects using popular attacks within the preset first time interval j; and ∝ be the percentage of missed scans for the i-th threat subject among the at least one threat subjects. The adjustment factor is β, where β is the adjustment factor for E.
[0019] In one optional embodiment, the focus score satisfies the following formula: Among them, H i To represent the distribution density of the threat posed to the target domain by the i-th threat subject among the at least one threat subjects within a preset first time interval j, W k γ represents the importance of the target domain, and H represents the importance of the target domain. i The adjustment factor, δ, is the W k The adjustment factor.
[0020] In one alternative embodiment, the time dispersion score satisfies the following formula: Among them, A i (j) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset first time interval j. i (j,g) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset second time interval g, where the second time interval g belongs to the first time interval j, and ε is the attenuation index.
[0021] In an optional embodiment, the processing unit is further configured to determine a risk score for the first network asset being attacked according to the following formula: in, Let ω'1 be the first risk score for the first network asset being attacked, and ω'1 be the weight corresponding to the first risk score. ω'2 represents the second risk score for the attack on the first network asset, and ω'2 represents the weight corresponding to the second risk score.
[0022] Thirdly, embodiments of the present invention provide an anomaly detection device for network log data, comprising: a memory for storing a computer program; and a processor for executing the method described in the first aspect according to the obtained program when executing the computer program stored in the memory.
[0023] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein when a computer reads and executes the computer program, the method described in the first aspect is performed.
[0024] Fifthly, embodiments of the present invention provide a computer program product that, when read and executed by a computer, causes the method described in the first aspect to be executed. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 A flowchart corresponding to a risk assessment method for network assets provided in this application embodiment;
[0027] Figure 2 A flowchart for determining the threat level score of each threat subject, provided for embodiments of this application;
[0028] Figure 3 An architecture diagram of a risk assessment method for network assets provided in an embodiment of this application;
[0029] Figure 4 A schematic diagram of the structure of a network asset risk assessment device provided in this application embodiment;
[0030] Figure 5 This is a schematic diagram of the structure of a network asset risk assessment device provided in an embodiment of this application. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0032] Based on the exemplary embodiments shown in this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application. Furthermore, although the disclosures in this application are presented by way of one or more exemplary examples, it should be understood that each aspect of these disclosures can constitute a complete technical solution on its own.
[0033] It should be understood that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate, for example, to allow implementation in orders other than those given in the embodiments illustrated or described in this application.
[0034] In recent years, with the large-scale development of new technologies and applications such as cloud computing, big data, the Internet of Things, the Industrial Internet, and artificial intelligence, and the continuous improvement of informatization, different network assets are facing a variety of security threats.
[0035] Traditional risk assessment methods are usually based on rule matching and statistical analysis. Due to the static and subjective nature of rules, they cannot adapt to constantly changing attack patterns, resulting in a high false alarm rate and building collapse rate. Furthermore, risk assessment strategies based on static rules cannot provide a methodology from qualitative to quantitative analysis, and there is a relatively long delay.
[0036] Based on this, this application provides a method for risk assessment of network assets. This method is based on alarm data of multiple network assets and combines the perspectives of threat subjects and network assets to conduct risk assessment. It can effectively improve the accuracy of identifying potential risks. Through quantitative analysis, complex alarm data is transformed into intuitive risk scores, so as to provide effective decision support for subsequent strategy adjustments.
[0037] Figure 1 This is a flowchart illustrating a risk assessment method for network assets provided in an embodiment of this application. The method can be executed by a network asset risk assessment device (hereinafter referred to as the risk assessment device). The risk assessment device can be any one of multiple network assets, or it can be an independently deployed device. The network assets can be network devices, network security devices, data security devices, servers, terminals, etc., and are not specifically limited here. Figure 1 As shown, the method includes:
[0038] Step 101: The risk assessment device acquires alarm data from multiple network assets.
[0039] Here, network assets can be network devices, network security devices, data security devices, servers, terminal devices, etc., but are not limited to these. Alarm data from multiple network assets are used to indicate at least one threat entity attacking multiple network assets. The threat entity can be a malicious network attack organization or individual of different levels, including state-level, large, organized groups, small organizations, and individuals.
[0040] For example, the risk assessment device collects alarm-related information from multiple network assets, processes the collected alarm-related information into a unified data format, and obtains alarm data from multiple network assets. Here, the alarm-related information includes at least one of the following: network traffic logs, intrusion detection system (IDS) alarm information, system vulnerability reports, user behavior logs, and operational security monitoring data. The risk assessment device can collect alarm-related information in various ways, such as through protocol analyzers and log collection tools. The risk assessment device can also process the alarm-related information into a unified data format in various ways, such as using noise algorithms to filter out noisy data and identifying, correcting, or deleting inaccurate, incomplete, duplicate, or invalid information in the alarm-related information. No specific limitations are made here.
[0041] Step 102: The risk assessment device determines the threat level score of each of at least one threat subjects based on the alarm data.
[0042] For example, the risk assessment device determines the alarm type popularity score, focus score, and time dispersion score for each threat subject based on alarm data. Based on the alarm type popularity score, focus score, and time dispersion score for each threat subject, it determines the threat score for each threat subject. The alarm type popularity score is used to assess the popularity of the threat subject's attack method, the focus score is used to assess the concentration of the threat subject's attack and the importance of the target domain to which the network asset attacked by the threat subject belongs, and the time dispersion score is used to assess the time span of the threat subject's attack.
[0043] Figure 2 The flowchart for determining the threat score of each threat subject provided in the embodiments of this application is as follows: Figure 2 As shown, the specific steps are as follows:
[0044] Step 201: The risk assessment device determines the alarm type popularity score for each threat subject based on the alarm data.
[0045] Specifically, the steps for determining the popularity score of each threat subject's alarm type are as follows:
[0046] Step 2011: Determine the percentage of missed scans for each threat subject.
[0047] For example, the formula for calculating the missed scan rate of each threat subject is shown in formula (1):
[0048]
[0049] in, Threaten is the sum of the number of alarms for the i-th threat subject that match the characteristics of all machine missed scans within a preset first time interval j. ic The sum of alarms for the i-th threat subject that matches the c-th machine's missed scan behavior characteristics; Let be the sum of the number of times the i-th threat entity is attacked within a preset first time interval j.
[0050] Step 2012: Determine the alarm type popularity score for each threat subject based on the missed scan rate of each threat subject and the popularity of the attack methods used by each threat subject.
[0051] For example, the popularity of the attack method used by each threat actor can be determined by counting the number of threat actors using that attack method within a preset first time interval.
[0052] The formula for calculating the popularity score of alarm type for each threat subject is shown in formula (2):
[0053]
[0054] in, Let be the percentage of missed scans for the i-th threat among the at least one threat subjects within a preset first time interval j; let D be the total number of alerts generated by the i-th threat subject using attacks within the preset first time interval j; let E be the reciprocal of the number of threat subjects using popular attacks within the preset first time interval j; and ∝ be the percentage of missed scans for the i-th threat subject among the at least one threat subjects. The adjustment factor is used to balance the proportion of missed scans. The contribution of popularity score, β is the adjustment coefficient of E, used to balance the contribution of popularity level E to popularity score.
[0055] Step 202: Based on the alarm data, the risk assessment device determines the focus score for each threat actor.
[0056] Specifically, the risk assessment device determines the focus score for each threat actor based on the distribution density of the threat target domain and the importance of the target domain to which the attacked network assets belong. The distribution density of the threat target domain of the threat actor satisfies the following formula:
[0057]
[0058]
[0059] Where Threaten(i,k,t) represents the number of attacks made by the i-th threat agent against the k target domains at time point t within a preset first time interval j, and each asset belongs to at least one target domain. This represents the total number of attacks on network assets by the i-th threat actor within a preset first time interval j. Let H be the probability distribution of the i-th threatening agent across k target domains. i Entropy is used to measure the uniformity of the distribution of threat subjects and target domains.
[0060] At this point, the formula for calculating the focus score of each threat subject is shown in formula (3):
[0061]
[0062] Among them, H i W represents the distribution density of the threat target domain of the i-th threat subject among the at least one threat subjects within a preset first time interval j. k The importance of a target domain is determined by the degree of focus of a threat actor in attacking a specific network asset. The more focused the threat actor is on attacking a particular network asset, the higher the importance of the target domain to which that asset belongs. γ represents the importance of H. i The adjustment factor, δ, is used to balance the impact of the uniformity of the distribution of threat subjects and threat target domains on the focus score. k An adjustment factor is used to balance the impact of the importance of the target domain on the focus score.
[0063] Step 203: The risk assessment device determines the time dispersion score of each threat subject based on the alarm data.
[0064] Specifically, the steps for determining the time dispersion score for each threat subject are as follows:
[0065] Step 2031: Count the number of alarms issued by each threat subject within a preset first time interval.
[0066] Step 2032: Count the number of alarms issued by each threat subject within a preset second time interval.
[0067] Based on steps 2031 and 2032, the time dispersion score of each threat subject is determined, and the time dispersion score of the i-th threat subject satisfies the following formula:
[0068]
[0069] in, ai (d) represents the number of alarms issued by the i-th threat subject on day d within a preset first time interval j. i (j) represents the total number of alarms from the i-th threat subject among at least one threat subject within a preset first time interval j; a i (d,h) represents the number of alarms from the i-th threat subject at the g-th hour of day d within the preset first time interval j. A i (j,g) represents the total number of alarms from at least the i-th threat subject within a preset second time interval g, where the second time interval g belongs to the first time interval j. ε is the decay exponent, which can be β·θ. θ is the number of penalties added for each day back in the first time interval, with a value set in [0-1]. β is used to adjust the weight at different times; the earlier the attack, the smaller the corresponding weight, with a value set in [0-1].
[0070] For example, the time dispersion score of each threat subject may also include a periodic adjustment factor P, used to reduce the time dispersion score of periodic attacks. In this case, the time dispersion score of the i-th threat subject...
[0071] Step 204: The risk assessment device determines the threat level score for each threat subject based on its alarm type popularity score, focus score, and time dispersion score.
[0072] For example, the risk assessment device scores the popularity determined in step 201. Attention score determined in step 202 and the time dispersion score determined in step 203 The threat score of each threat subject is obtained by weighted averaging. The calculation formula for the threat score of the i-th threat subject is shown in formula (5):
[0073]
[0074] in, and Yes and The result is obtained through standardization, which can be achieved using Z-score, where ω1 is... The corresponding weights, ω2 are The corresponding weights, ω3 are The corresponding weights It is the average value of ω1, ω2 and ω3.
[0075] Step 103: Determine the first risk score of the first network asset being attacked based on the threat score of each threat subject and the weight of each threat subject corresponding to the first network asset among multiple network assets.
[0076] For example, the risk assessment device scores each threat subject's threat level Y. i The weight of each threat subject corresponding to the first network asset is used to determine the first risk score of the first network asset being attacked. The calculation formula for the first risk score is shown in formula (6):
[0077]
[0078] Among them, Y i Give a threat score to the i-th threat subject among I threat subjects. denoted as the weight of the i-th threat subject corresponding to the first network asset.
[0079] Step 104: Determine a second risk score for the attack on the first network asset based on the Common Vulnerability Scoring System (CVSS) score for each vulnerability in at least one vulnerability of the first network asset, the dynamic risk score, and the number of vulnerabilities in the first network asset.
[0080] For example, for a first network asset, the risk assessment device quantifies the risk of the first asset being attacked based on the expected risk of each vulnerability.
[0081] Specifically, based on the CVSS score of each vulnerability in at least one vulnerability of the first network asset, the dynamic risk score, and the number of vulnerabilities in the first network asset, a second risk score for the attack on the first network asset is determined. The quantitative formula for the second risk score is as follows:
[0082]
[0083] Among them, VS m Let m be the CVSS score of the m-th vulnerability out of M vulnerabilities in the first network asset. This represents the dynamic risk score of the m-th vulnerability among the M vulnerabilities in the first network asset. The impact factor for all threat actors who exploit the m-th attack on the first network asset.
[0084] It is determined based on the attack frequency, attack success rate, and the threat actor's historical attack behavior. The calculation formula is as follows:
[0085]
[0086] Among them, F i S represents the attack frequency of the i-th threat actor against the first network asset. i The success rate of an attack launched by the i-th threat actor against the first network asset, G i Let represent the number of historical attacks by the i-th threat actor, and I represent the total number of threat actors.
[0087] Step 105: Determine the risk score of the first network asset being attacked based on the first risk score and the second risk score.
[0088] For example, the risk score of the first network asset being attacked is determined according to the following formula:
[0089]
[0090] in, The first risk score represents the first network asset being attacked, and ω'1 represents the weight corresponding to the first risk score. The second risk score is the first risk score for the attack on the network asset. ω'2 is the weight corresponding to the second risk score. The weights corresponding to the first and second risk scores can be determined based on historical data analysis and expert opinions, and no specific limitations are made here.
[0091] For example, based on the risk score and risk level thresholds of the first network asset determined above, the risk level of the first network asset is determined. This risk level can then be used to adjust security strategies, resource allocation, and risk avoidance. The risk level can be divided into four levels: critical, high-risk, medium-risk, and low-risk. Each level corresponds to a different threshold. For instance, if the risk score of the first network asset is greater than or equal to the first threshold, the risk level of the first network asset is critical; if the risk score is greater than or equal to the second threshold but less than the first threshold, the risk level of the first network asset is high-risk; if the risk score is greater than or equal to the third threshold but less than the second threshold, the risk level of the first network asset is medium-risk; and if the risk score is greater than or equal to the fourth threshold but less than the third threshold, the risk level of the first network asset is low-risk. The number of risk levels and their corresponding thresholds can be determined according to the actual situation and are not specifically limited here.
[0092] Using the above methods, such as Figure 3As shown, obtaining various relevant alarm logs from multiple network assets and uniformly formatting the data ensures data consistency while maintaining data diversity. Combining risk assessment from both threat actor and network asset perspectives improves the accuracy of identifying potential risks. A comprehensive analysis of the threat level of threat actors is conducted using three dimensions: alarm type popularity score, focus score, and time dispersion score. Based on the threat level score of each threat actor and the weight of each threat actor corresponding to the network asset, a first risk score for network asset attack is determined. A second risk score for network asset attack is determined based on vulnerability-related information of the network asset. The risk of the network asset is quantified based on the first and second risk scores to obtain a network asset risk score, providing effective decision support for subsequent strategy adjustments.
[0093] Based on the same technical concept, this application also provides a network asset risk assessment device 4000. Figure 4 This is a schematic diagram of the structure of the network asset risk assessment device provided in the embodiments of this application, as shown below. Figure 4 As shown, the device 4000 includes:
[0094] The acquisition unit 401 is used to acquire alarm data from multiple network assets, wherein the alarm data from the multiple network assets is used to indicate at least one threat subject attacking the multiple network assets;
[0095] The determining unit 402 is configured to: determine a threat score for each of the at least one threat subjects based on the alarm data; determine a first risk score for the first network asset being attacked based on the threat score of each threat subject and the weight of each threat subject corresponding to the first network asset among the plurality of network assets; determine a second risk score for the first network asset being attacked based on the CVSS score, dynamic risk score, and the number of vulnerabilities in at least one vulnerability of the first network asset; and determine a risk score for the first network asset being attacked based on the first risk score and the second risk score.
[0096] Optionally, the determining unit 402 is specifically used to: determine, based on the alarm data, an alarm type popularity score, a focus score, and a time dispersion score for each threat entity; the alarm type popularity score is used to assess the popularity of the attack methods of the threat entity; the focus score is used to assess the concentration of the attacks by the threat entity and the importance of the target domain to which the network assets attacked by the threat entity belong; and the time dispersion score is used to assess the time span of the attacks by the threat entity; and determine the threat score for each threat entity based on the alarm type popularity score, focus score, and time dispersion score for each threat entity.
[0097] Optionally, the alarm type popularity score satisfies the following formula: in, Let be the percentage of missed scans for the i-th threat among the at least one threat subjects within a preset first time interval j; let D be the total number of alerts generated by the i-th threat subject using attacks within the preset first time interval j; let E be the reciprocal of the number of threat subjects using popular attacks within the preset first time interval j; and ∝ be the percentage of missed scans for the i-th threat subject among the at least one threat subjects. The adjustment factor is β, where β is the adjustment factor for E.
[0098] Optionally, the focus score satisfies the following formula: Among them, H i To represent the distribution density of the threat posed to the target domain by the i-th threat subject among the at least one threat subjects within a preset first time interval j, W k γ represents the importance of the target domain, and H represents the importance of the target domain. i The adjustment factor, δ, is the W k The adjustment factor.
[0099] Optionally, the time dispersion score satisfies the following formula: Among them, A i (j) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset first time interval j. i (j,g) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset second time interval g, where the second time interval g belongs to the first time interval j, and ε is the attenuation index.
[0100] Optionally, the processing unit is further configured to determine a risk score for the first network asset being attacked according to the following formula: in, Let ω'1 be the first risk score for the first network asset being attacked, and ω'1 be the weight corresponding to the first risk score. ω'2 represents the second risk score for the attack on the first network asset, and ω'2 represents the weight corresponding to the second risk score.
[0101] Based on the same technological concept Figure 5 This is a schematic diagram of the structure of a device 5000 provided in an embodiment of this application, as shown below. Figure 5 As shown, the device 5000 includes at least one processor 501 and a memory 502 connected to the at least one processor 501. In this embodiment, the specific connection medium between the processor 501 and the memory 502 is not limited. Figure 5Taking the connection between processor 501 and memory 502 via a bus as an example, the bus can be divided into address bus, data bus, control bus, etc. In this embodiment of the invention, memory 502 stores instructions that can be executed by at least one processor 501. By executing the instructions stored in memory 502, at least one processor 501 can implement the steps of the above-mentioned network asset risk assessment method.
[0102] The processor 501 is the control center of the computer device, capable of connecting various parts of the computer device via various interfaces and lines. It performs resource configuration by running or executing instructions stored in the memory 502 and accessing data stored in the memory 502. Optionally, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles wireless communication. It is understood that the modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 502 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.
[0103] Processor 501 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0104] Memory 502, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 502 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 502 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 502 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0105] Based on the same technical concept, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein the computer program is executed by a processor using the aforementioned risk assessment method for network assets.
[0106] Based on the same technical concept, various aspects of the network asset risk assessment method provided in this application can also be implemented in the form of a program product, which includes a computer program. When the program product is run on an electronic device, the computer program is used to cause the electronic device to perform the steps in the network asset risk assessment method according to the various exemplary embodiments of this application described above.
[0107] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0108] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0109] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0110] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0111] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0112] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for risk assessment of network assets, characterized in that, The method includes: Acquire alarm data from multiple network assets, wherein the alarm data from the multiple network assets is used to indicate at least one threat actor attacking the multiple network assets; Based on the alarm data, an alarm type popularity score, a focus score, and a time dispersion score are determined for each threat subject. The alarm type popularity score is used to assess the popularity of the attack methods of the threat subject. The alarm type popularity score is obtained based on the missed scan ratio of each threat subject and the popularity of the attack methods used by each threat subject. The focus score is used to assess the concentration of the threat subject's attacks and the importance of the target domain to which the network assets attacked by the threat subject belong. The time dispersion score is used to assess the time span of the threat subject's attacks. The threat score for each threat subject is determined based on its alarm type popularity score, focus score, and time dispersion score. Based on the threat score of each threat subject and the weight of each threat subject corresponding to the first network asset among the multiple network assets, a first risk score for the first network asset being attacked is determined. A second risk score for the attack on the first network asset is determined based on the Common Vulnerability Scoring System (CVSS) score, dynamic risk score, and the number of vulnerabilities in the first network asset for each vulnerability in at least one vulnerability of the first network asset. Based on the first risk score and the second risk score, a risk score for the first network asset being attacked is determined.
2. The method according to claim 1, characterized in that, The popularity score for the alarm type satisfies the following formula: in, Let be the percentage of missed scans for the i-th threat among the at least one threat subjects within a preset first time interval j; let D be the total number of alerts generated by the i-th threat subject using attacks within the preset first time interval j; let E be the reciprocal of the number of threat subjects using popular attacks within the preset first time interval j; and ∝ be the percentage of missed scans for the i-th threat subject among the at least one threat subjects. The adjustment factor is β, where β is the adjustment factor for E.
3. The method according to claim 1, characterized in that, The focus score satisfies the following formula: Among them, H i To represent the distribution density of the threat posed to the target domain by the i-th threat subject among the at least one threat subjects within a preset first time interval j, W k γ represents the importance of the target domain, and H represents the importance of the target domain. i The adjustment factor, δ, is the W k The adjustment factor.
4. The method according to claim 1, characterized in that, The time dispersion score satisfies the following formula: Among them, A i (j) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset first time interval j. i (j, g) represents the number of alarms issued by the i-th threat subject among the at least one threat subjects within a preset second time interval g, where the second time interval g belongs to the first time interval j, and ε is the attenuation index.
5. The method according to claim 1, characterized in that, Based on the first risk score and the second risk score, a risk score for the first network asset being attacked is determined, including: The risk score of the first network asset being attacked is determined according to the following formula: in, Let ω'1 be the first risk score for the first network asset being attacked, and ω'1 be the weight corresponding to the first risk score. ω'2 represents the second risk score for the attack on the first network asset, and ω'2 represents the weight corresponding to the second risk score.
6. A risk assessment device for network assets, characterized in that, The device includes: The acquisition unit is used to acquire alarm data from multiple network assets, wherein the alarm data from the multiple network assets is used to indicate at least one threat subject attacking the multiple network assets; The determining unit is configured to determine, based on the alarm data, an alarm type popularity score, a focus score, and a time dispersion score for each threat entity. The alarm type popularity score assesses the popularity of the threat entity's attack methods, and is obtained based on the vulnerability scan ratio and the popularity of the attack methods employed by each threat entity. The focus score assesses the concentration of the threat entity's attacks and the importance of the target domain to which the attacked network asset belongs. The time dispersion score assesses the duration of the threat entity's attacks. Based on the alarm type popularity score, focus score, and time dispersion score, the unit determines the threat level score for each threat entity. Based on the threat level score and the weight of each threat entity corresponding to the first network asset among the multiple network assets, the unit determines a first risk score for the first network asset being attacked. Based on the CVSS score, dynamic risk score, and the number of vulnerabilities in at least one vulnerability of the first network asset, the unit determines a second risk score for the first network asset being attacked. Based on the first and second risk scores, the unit determines a total risk score for the first network asset being attacked.
7. A risk assessment device for network assets, characterized in that, The device includes: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method according to any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a computer, cause the method as described in any one of claims 1-5 to be performed.
9. A computer program product, characterized in that, The computer program product includes computer program code that, when run on a computer, causes any one of claims 1-5 to be executed.
Citation Information
Patent Citations
Risk-based asset scoring method and system
CN110851839A
Industrial control environment network risk assessment method, equipment and medium
CN117675401A