Comprehensive assessment method and system for database vulnerability risk and storage medium

By establishing knowledge information in the user's local environment and calculating the business level and the impact of security vulnerabilities carried by the database, the problem of difficulty in evaluating database vulnerability risks in the prior art is solved, and a multi-dimensional assessment and accurate calculation of database vulnerability risks are achieved.

CN119917481APending Publication Date: 2025-05-02BEIJING AN XIN TIAN XING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411798352.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The prior art is difficult to effectively evaluate and calculate the risk of vulnerability of databases, especially in the user's local environment, and it is impossible to accurately distinguish the business capabilities carried by the database from the impact of vulnerabilities.

Method used

By establishing user local knowledge and information, calculating the business level and the impact of security vulnerabilities carried by the database, combining the exploitability of the vulnerabilities, multi-dimensional quantitative indicators are used to calculate the vulnerability risk score of the database, and cumulative calculations are performed on all databases to obtain the risk value of the overall database.

Benefits of technology

A comprehensive assessment of the risk of database vulnerability is achieved, which can accurately reflect the importance and vulnerability risks of databases and provide more accurate risk assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119917481A_ABST
    Figure CN119917481A_ABST
Patent Text Reader

Abstract

The invention relates to a comprehensive assessment method for database vulnerability risks, and the method comprises the steps: S1, calculating the importance of a database based on the grade of a business borne by the database, and assessing the importance of the database; the service level comprises a core service, a key service, an important service, a general service and a common service; s2, calculating a quantitative index of database vulnerability influence based on the influence degree of security vulnerabilities in the database and the vulnerability influence probability brought by the vulnerabilities; s3, calculating a quantitative index of the difficulty level of database vulnerability utilization; integrating the importance of the database in the step S1, the influence of the vulnerability in the step S2 on the database and the utilization degree of the vulnerability of the database in the step S3 to obtain a single database risk; and carrying out accumulation calculation on all database risks to obtain a risk value of the whole database. The invention also provides a system for realizing the database vulnerability risk comprehensive assessment method and a storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of databases, and in particular relates to a method, system and storage medium for comprehensive assessment of database vulnerability risks. Background Art

[0002] Currently, there are many types and numbers of databases, and the business situations carried by the databases are relatively complex. There are few calculation dimensions for database risk assessment, and the business capabilities of the databases are not differentiated. The vulnerabilities in the databases are not effectively calculated, and the risk value of the database cannot be effectively derived.

[0003] Aiming at the vulnerability risk assessment of the database of the user's local actual business, the analysis of the vulnerability impact and the vulnerability exploitation based on the user's local environment, and the difficulty in quantitatively calculating the risk of the user's local overall database, a comprehensive calculation method for the vulnerability of the user's local database is designed, including the establishment of user local knowledge intelligence, statistics on the user's local database and business system, mastering the level of the business system carried by the database, calculating the important index of the database, and combining the vulnerabilities existing in the database and the exploitability of the corresponding vulnerabilities for comprehensive calculation to obtain the vulnerability risk score of the database and the vulnerability risk score of all local databases of the user. Summary of the invention

[0004] The purpose of the present invention is to provide a method, system and storage medium for comprehensive assessment of database vulnerability risks, so as to solve the problems existing in the prior art.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions:

[0006] A comprehensive assessment method for database vulnerability risk, the method comprising:

[0007] S1: Calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database;

[0008] The business levels include core business, key business, important business, general business, and ordinary business;

[0009] S2: Based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities, the quantitative index of the impact of database vulnerabilities is calculated;

[0010] S3: Calculates the quantitative index of the ease with which database vulnerabilities can be exploited;

[0011] S4: The risk of a single database is derived by combining the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited;

[0012] S5: Accumulate the risks of all databases to obtain the risk value of the entire database.

[0013] Furthermore, the importance of the evaluation database described in S1 is calculated as follows:

[0014] D importance =i+(ji)*n, where,

[0015] D importance Represents the database importance index, and the calculation result ranges from 0 to 1;

[0016] i represents the initial business value, ranging from 0 to 1;

[0017] j represents the maximum value limit of the index, which is 1;

[0018] n represents the importance of the business, which is initially equal to i and then equal to D importance ;

[0019] Furthermore, the quantitative index for calculating the impact of database vulnerability described in S2 is calculated as follows:

[0020]

[0021] Among them, V impact Refers to the quantitative index of the impact of database vulnerability, ranging from 0 to 100;

[0022] P i Represents the probability of vulnerability impact brought by the i-th vulnerability, and its value is between 0 and 1. l is a custom coefficient, which can also be defined from the blacklist and whitelist in the knowledge intelligence library. The coefficient ranges from 0 to 1 and is usually set to 0 or 1;

[0023] The probability of vulnerability impact brought by the i-th vulnerability is calculated as follows:

[0024]

[0025] x is a feedback or fine-tuning parameter, which is based on the probability statistics of the vulnerability that is of particular concern in the system. Its value range is between 0 and 1 and is usually set to 1.

[0026] S ci Indicates the impact of the i-th vulnerability, and its value range is also between 0 and 10;

[0027] The impact degree caused by the i-th vulnerability is calculated as follows:

[0028] S c =l×S cvss×[1-(1-VC i )×(1-VI i )×(1-VA i )]

[0029] Among them, S c Refers to the impact of the i-th security vulnerability in the database, and its value ranges from 0 to 10;

[0030] l is a custom coefficient, which is the blacklist or whitelist in the knowledge intelligence database. It is usually set to 0 or 1, with the whitelist being 0 and the blacklist or graylist being 1;

[0031] S cvss Refers to the Common Vulnerability Scoring System (CVSS) score of the i-th security vulnerability in the database, and its value is also between 0 and 10;

[0032] VC i Refers to the impact of the i-th security vulnerability in the database on the confidentiality of the database, and its value is between 0 and 1;

[0033] VI i Refers to the impact of the i-th security vulnerability in the database on the integrity of the database, and its value is between 0 and 1;

[0034] VA i Refers to the impact of the i-th security vulnerability in the database on the database availability, and its value is between 0 and 1.

[0035] Furthermore, the quantitative index of the ease with which the database vulnerability described in S3 can be exploited is calculated as follows:

[0036]

[0037] Among them, V exploit , the value range is between 0 and 10,

[0038] S m1 The score that indicates the vulnerability with the highest risk of being exploited, and its value range is also between 0 and 10;

[0039] w is the protection effect coefficient of the system's existing protection measures against specific vulnerabilities, and its value range is between 0 and 1;

[0040] S mi is the exploit risk score of the i-th vulnerability, and its value range is between 0 and 10;

[0041] g is the convergence coefficient, which is usually preset to 1.

[0042] Furthermore, the risk of a single database is obtained by combining the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the vulnerability of the database described in S3 is exploited. The calculation formula is:

[0043] V 数据库i =D importance *V impact *V exploit / 2

[0044] Among them, V 数据库i For a single database risk.

[0045] Furthermore, the risks of all databases described in S5 are cumulatively calculated to obtain the risk value of the entire database. The calculation formula is:

[0046]

[0047] Among them, V 数据库 Zi is the risk value of the entire database, Z i is the weight coefficient, and the sum of Zi is 1.

[0048] The present invention also provides a comprehensive assessment system for database vulnerability risk, the assessment system comprising:

[0049] A database importance calculation module is used to calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database;

[0050] The business levels include core business, key business, important business, general business, and ordinary business;

[0051] A quantitative index calculation module for the impact of database vulnerability, which is used to calculate the quantitative index of the impact of database vulnerability based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities;

[0052] A module for calculating the degree of difficulty of exploiting database vulnerabilities, used to calculate the quantitative index of the degree of difficulty of exploiting database vulnerabilities;

[0053] A single database risk calculation module is used to comprehensively calculate the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited to derive the risk of a single database;

[0054] The risk value calculation module of the entire database is used to accumulate and calculate the risks of all databases to obtain the risk value of the entire database.

[0055] The present invention also provides a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are executed by a computer, the computer executes the steps of the above-mentioned database vulnerability risk comprehensive assessment method.

[0056] By adopting the above technical solution, the present invention has the following beneficial effects:

[0057] (1) This application introduces the impact of business factors on database importance assessment, calculates the database importance index according to different business levels and the number of businesses, and combines business scenarios to enhance the practical application value of database risk assessment.

[0058] (2) For database-related vulnerabilities, the vulnerability risk results of the database are comprehensively calculated according to the degree of vulnerability impact, the ease of vulnerability exploitation, the database's important value index, and the asset risk assessment perspective. Through a multi-dimensional unified assessment, a comprehensive assessment result is finally obtained, making the risk assessment result more accurate.

[0059] (3) By calculating the vulnerability risks of multiple databases, the overall risk situation of the user's local database environment is obtained. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0061] Figure 1 A flowchart of a comprehensive database vulnerability risk assessment method provided by the present invention;

[0062] Figure 2 A schematic diagram of a comprehensive database vulnerability risk assessment system provided by the present invention;

[0063] Figure 3 A schematic diagram of a computer-readable storage medium according to the present invention. DETAILED DESCRIPTION

[0064] The technical solution of the present invention will be described clearly and completely below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0065] Combination Figure 1 As shown, the present invention provides a comprehensive assessment method for database vulnerability risk, the method comprising:

[0066] S1: Calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database;

[0067] The business levels include core business, key business, important business, general business, and ordinary business;

[0068] S2: Based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities, the quantitative index of the impact of database vulnerabilities is calculated;

[0069] S3: Calculates the quantitative index of the ease with which database vulnerabilities can be exploited;

[0070] S4: The risk of a single database is derived by combining the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited;

[0071] S5: Accumulate the risks of all databases to obtain the risk value of the entire database.

[0072] Specifically, see Figure 1 , Figure 2 As shown, the user has MySQL1 and MySQL2 databases locally, and MySQL1 runs OA and CRM business systems, among which OA system is an important information system and CRM is a general information system; MySQL2 also runs important business.

[0073] The initial index i of different levels of business is defined as follows

[0074] Serial number Business Level Initial index i 1 Core Business 1 2 Key Business 0.98 3 Important business 0.8 4 General Business 0.4 5 General business 0.2

[0075] 1. Risk-related calculations for database MySQL1

[0076] 1. Database importance calculation

[0077] D importance =i+(ji)*n, where,

[0078] D importance Represents the database importance index, and the calculation result ranges from 0 to 1;

[0079] i represents the initial business value, ranging from 0 to 1;

[0080] j represents the maximum value limit of the index, which is 1;

[0081] n represents the importance of the business, which is initially equal to i and then equal to Dimportance ;

[0082] Initial index i for different levels of business.

[0083] MySQL1 runs OA and CRM business systems, of which the OA system is an important information system. As can be seen from the above table, the initial index i is 0.8. According to the residual score algorithm, the calculation is performed based on the accumulation of different systems. Here, Gao Feng's information system is given priority.

[0084] Important information system: D1 = 0.8 + (1-0.8) * 0.8 = 0.8 + 0.16 = 0.96

[0085] General business system: D2 = 0.96 + (1-0.96) * 0.4 = 0.976

[0086] The final cumulative database MySQL1 score was 0.976.

[0087] 2. Calculation of the impact of database vulnerabilities. Currently, MySQL1 has vulnerabilities 1 and 2. The Common Vulnerability Scoring System (CVSS) S of vulnerabilities 1 and 2 cvss 6 and 5 respectively, VC i VI i and VA i They are divided into three levels: no impact, low impact and high impact, and the values ​​are set to 0, 0.65 and 1 respectively. Calculate according to the following formula.

[0088] S c =S cvss ×[1-(1-VC i )×(1-VI i )×(1-VA i )]

[0089] First vulnerability 1 Severity S C1 =6*{1-(1-0)(1-0.65)(1-1)}=6

[0090] The second vulnerability is 2 severity S C2 =5*{1-(1-0)(1-0.65)(1-1)}=5

[0091] Among them, S c Refers to the impact of the i-th security vulnerability in the database, and its value ranges from 0 to 10;

[0092] l is a custom coefficient, which is the blacklist or whitelist in the knowledge intelligence database. It is usually set to 0 or 1, with the whitelist being 0 and the blacklist or graylist being 1;

[0093] VC iRefers to the impact of the i-th security vulnerability in the database on the confidentiality of the database, and its value is between 0 and 1;

[0094] VI i Refers to the impact of the i-th security vulnerability in the database on the integrity of the database, and its value is between 0 and 1;

[0095] VA i Refers to the impact of the i-th security vulnerability in the database on the database availability, and its value is between 0 and 1.

[0096] 3. Calculation of the probability of vulnerability impact caused by each vulnerability

[0097] P i Represents the probability of vulnerability impact brought by the i-th vulnerability, and its value is between 0 and 1. l is a custom coefficient, which can also be defined from the blacklist and whitelist in the knowledge intelligence library. The coefficient ranges from 0 to 1 and is usually set to 0 or 1;

[0098] The probability of vulnerability impact brought by the i-th vulnerability is calculated as follows:

[0099]

[0100] x is a feedback or fine-tuning parameter, which is based on the probability statistics of the vulnerability that is of particular concern in the system. Its value range is between 0 and 1 and is usually set to 1.

[0101] The first vulnerability 1 causes risk P1 = 2 / (1+e 4.1 )*6=0.195

[0102] The second vulnerability 2 causes risk P2 = 2 / (1+e 5.1 )*5=0.06

[0103] 4. If a database has n vulnerabilities, the overall vulnerability impact of the database can be obtained by summing up the impact of all vulnerabilities. In other words, the quantitative index of the impact of database vulnerability is calculated as follows:

[0104]

[0105] Among them, V impact Refers to the quantitative index of the impact of database vulnerability, ranging from 0 to 100; It is the cumulative multiplication method;

[0106] Calculation result V impact =1*{1-(1-(0.195))(1-(0.06))}100=24.33

[0107] 5. The quantitative index of the ease with which database vulnerabilities can be exploited. The calculation formula is as follows:

[0108]

[0109] Among them, V exploit , the value range is between 0 and 10,

[0110] S m1 The score that indicates the vulnerability with the highest risk of being exploited, and its value range is also between 0 and 10;

[0111] w is the protection effect coefficient of the system's existing protection measures against specific vulnerabilities, and its value range is between 0 and 1;

[0112] S mi is the exploit risk score of the i-th vulnerability, and its value range is between 0 and 10;

[0113] g is the convergence coefficient, which is usually preset to 1.

[0114] Through automated and expert evaluation, the highest exploitation risk scores for vulnerability 1 and vulnerability 2 are 6 and 5 respectively. g is the convergence coefficient, which is set to 1; the local environment verification is weak protection, and the protection coefficient w is set to 1; the custom coefficient l is 1.

[0115]

[0116] The result is: V exploit =1*1*6+1*(1*1+1*(5*5) / (6*6))*1=7.694

[0117] 6. Single database risk, calculation formula,

[0118] V 数据库i =D importance *V impact *V exploit / 2

[0119] Among them, V 数据库i For a single database risk.

[0120] The risk score of MySQL1 is calculated according to the following formula based on the importance of the database, the impact of the vulnerability on the database, and the degree to which the vulnerability is exploited.

[0121] The result is: V MySQL1 =0.976*(24.33*7.694)=91.35

[0122] 2. Risk-related calculations for MySQL2 database

[0123] 1. Database importance calculation

[0124] D importance =i+(ji)*n, where,

[0125] D importance Represents the database importance index, and the calculation result ranges from 0 to 1;

[0126] i represents the initial business value, ranging from 0 to 1;

[0127] j represents the maximum value limit of the index, which is 1;

[0128] n represents the importance of the business, which is initially equal to i and then equal to D importance ;

[0129] Initial index i for different levels of business.

[0130] MySQL2 is also running important business. The initial index i is 0.8. According to the residual score algorithm, the calculation is based on the accumulation of different systems. Here, Gaofeng's information system is given priority.

[0131] Important information system: D1 = 0.8 + (1-0.8) * 0.8 = 0.8 + 0.16 = 0.96

[0132] General business system: D2 = 0.96 + (1-0.96) * 0.4 = 0.976

[0133] The final cumulative database MySQL2 score was 0.976.

[0134] 2. Calculation of the impact of database vulnerabilities. Currently, MySQL2 has vulnerabilities 1 and 2. The Common Vulnerability Scoring System (CVSS) S of vulnerabilities 1 and 2 cvss 4 and 5 respectively, VC i VI i and VA i They are divided into three levels: no impact, low impact and high impact, and the values ​​are set to 0, 0.65 and 1 respectively. Calculate according to the following formula.

[0135] S c =S cvss ×[1-(1-VC i )×(1-VI i )×(1-VA i )]

[0136] First vulnerability 1 Severity S C1 =4*{1-(1-0)(1-0.65)(1-1)}=4

[0137] The second vulnerability is 2 severity S C2=5*{1-(1-0)(1-0.65)(1-1)}=5

[0138] 3. Calculation of the probability of vulnerability impact caused by each vulnerability

[0139] P i Represents the probability of vulnerability impact brought by the i-th vulnerability, and its value is between 0 and 1. l is a custom coefficient, which can also be defined from the blacklist and whitelist in the knowledge intelligence library. The coefficient ranges from 0 to 1 and is usually set to 0 or 1;

[0140] The probability of vulnerability impact brought by the i-th vulnerability is calculated as follows:

[0141]

[0142] x is a feedback or fine-tuning parameter, which is based on the probability statistics of the vulnerability that is of particular concern in the system. Its value range is between 0 and 1 and is usually set to 1.

[0143] The first vulnerability 1 causes risk P1 = 2 / (1+e 6.1 )*6=0.018

[0144] The second vulnerability 2 causes risk P2 = 2 / (1+e 5.1 )*5=0.06

[0145] 4. If a database has n vulnerabilities, the overall vulnerability impact of the database can be obtained by summing up the impact of all vulnerabilities. In other words, the quantitative index of the impact of database vulnerability is calculated as follows:

[0146]

[0147] Among them, V impact Refers to the quantitative index of the impact of database vulnerability, ranging from 0 to 100;

[0148] Calculation result V impact =1*{1-(1-(0.018))(1-(0.06))}100=7.69

[0149] 5. The quantitative index of the ease with which database vulnerabilities can be exploited. The calculation formula is as follows:

[0150]

[0151] Among them, V exploit , the value range is between 0 and 10,

[0152] S m1The score that indicates the vulnerability with the highest risk of being exploited, and its value range is also between 0 and 10;

[0153] w is the protection effect coefficient of the system's existing protection measures against specific vulnerabilities, and its value range is between 0 and 1;

[0154] S mi is the exploit risk score of the i-th vulnerability, and its value range is between 0 and 10;

[0155] g is the convergence coefficient, which is usually preset to 1.

[0156] Through automated and expert evaluation, the highest exploitation risk scores for vulnerability 1 and vulnerability 2 are 8 and 5, respectively. g is the convergence coefficient, which is set to 1; the local environment verification is weak protection, and the protection coefficient w is set to 1; the custom coefficient l is 1.

[0157]

[0158] The result is: V exploit =1*1*8+1*(1*1+1*(5*5) / (8*8))*1=9.39

[0159] 6. Single database risk, calculation formula,

[0160] V 数据库i =D importance *V impact *V exploit / 2

[0161] Among them, V 数据库i For a single database risk.

[0162] The risk score of MySQL2 is calculated according to the following formula based on the importance of the database, the impact of the vulnerability on the database, and the degree to which the vulnerability is exploited.

[0163] The result is: V MySQL1 =0.976*(7.69*9.39)=70.47

[0164] 3. Overall Database Risk Calculation

[0165] The risk score of MySQL1 is 91.35 points, and the score of MySQL2 is 70.47 points. The overall database vulnerability risk is obtained, and the weight coefficients of MySQL1 and MySQL2 are 0.6 and 0.4 respectively.

[0166] The overall vulnerability score of the database is calculated based on the following formula.

[0167]

[0168] The result is: V 数据库 =91.35*0.6+70.47*0.4=83

[0169] See also Figure 2 As shown, the present invention provides a comprehensive assessment system for database vulnerability risk, the assessment system comprising:

[0170] A database importance calculation module is used to calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database;

[0171] The business levels include core business, key business, important business, general business, and ordinary business;

[0172] A quantitative index calculation module for the impact of database vulnerability, which is used to calculate the quantitative index of the impact of database vulnerability based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities;

[0173] A module for calculating the degree of difficulty of exploiting database vulnerabilities, used to calculate the quantitative index of the degree of difficulty of exploiting database vulnerabilities;

[0174] A single database risk calculation module is used to comprehensively calculate the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited to derive the risk of a single database;

[0175] The risk value calculation module of the entire database is used to accumulate and calculate the risks of all databases to obtain the risk value of the entire database.

[0176] See also Figure 3 As shown, the present invention also provides a computer-readable storage medium, which stores computer program instructions. When the computer program instructions are executed by a computer, the computer executes the steps of the above-mentioned method for comprehensive assessment of database vulnerability risks.

[0177] It should be noted that the basic conditions of the user are: the user has several databases and business systems locally, the database carries different business systems and can perform data statistics, and maintains a local knowledge intelligence database. The knowledge intelligence database is equipped with black and white lists, vulnerability intelligence, threat intelligence, etc., and can be applied to risk calculation.

[0178] It should be noted that the storage medium shown in the embodiment of the present invention may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, device or device. In the present invention, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any storage medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0179] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A comprehensive assessment method for database vulnerability risk, characterized in that: The method comprises: S1: Calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database; The business levels include core business, key business, important business, general business, and ordinary business; S2: Based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities, the quantitative index of the impact of database vulnerabilities is calculated; S3: Calculates the quantitative index of the ease with which database vulnerabilities can be exploited; S4: The risk of a single database is derived by combining the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited; S5: Accumulate the risks of all databases to obtain the risk value of the entire database.

2. The database vulnerability risk comprehensive assessment method according to claim 1 is characterized in that: The importance of the evaluation database described in S1 is calculated as follows: D importance =i+(ji)*n, where, D importance Represents the database importance index, and the calculation result ranges from 0 to 1; i represents the initial business value, ranging from 0 to 1; j represents the maximum value limit of the index, which is 1; n represents the importance of the business, which is initially equal to i and then equal to D importance .

3. The database vulnerability risk comprehensive assessment method according to claim 2 is characterized in that: The quantitative index for calculating the impact of database vulnerability described in S2 is calculated as follows: Among them, V impact Refers to the quantitative index of the impact of database vulnerability, ranging from 0 to 100; P i Represents the probability of vulnerability impact brought by the i-th vulnerability, and its value is between 0 and 1. l is a custom coefficient, which can also be defined from the blacklist and whitelist in the knowledge intelligence library. The coefficient ranges from 0 to 1 and is usually set to 0 or 1; The probability of vulnerability impact brought by the i-th vulnerability is calculated as follows: x is a feedback or fine-tuning parameter, which is based on the probability statistics of the vulnerability that is of particular concern in the system. Its value range is between 0 and 1 and is usually set to 1. S ci Indicates the impact of the i-th vulnerability, and its value range is also between 0 and 10; The impact degree caused by the i-th vulnerability is calculated as follows: S c =l×S cvss ×[1-(1-VC i )×(1-VI i )×(1-VA i )] Among them, S c Refers to the impact of the i-th security vulnerability in the database, and its value ranges from 0 to 10; l is a custom coefficient, which is the blacklist or whitelist in the knowledge intelligence database. It is usually set to 0 or 1, with the whitelist being 0 and the blacklist or graylist being 1; S cvss Refers to the Common Vulnerability Scoring System (CVSS) score of the i-th security vulnerability in the database, and its value is also between 0 and 10; VC i Refers to the impact of the i-th security vulnerability in the database on the confidentiality of the database, and its value is between 0 and 1; VI i Refers to the impact of the i-th security vulnerability in the database on the integrity of the database, and its value is between 0 and 1; VA i Refers to the impact of the i-th security vulnerability in the database on the database availability, and its value is between 0 and 1.

4. The database vulnerability risk comprehensive assessment method according to claim 3 is characterized in that: The quantitative indicator of the ease with which the database vulnerability described in S3 can be exploited is calculated as follows: Among them, V exploit , the value range is between 0 and 10, S m1 The score that indicates the vulnerability with the highest risk of being exploited, and its value range is also between 0 and 10; w is the protection effect coefficient of the system's existing protection measures against specific vulnerabilities, and its value range is between 0 and 1; S mi is the exploit risk score of the i-th vulnerability, and its value range is between 0 and 10; g is the convergence coefficient, which is usually preset to 1.

5. The method for comprehensive assessment of database vulnerability risk according to claim 4, characterized in that: The risk of a single database is calculated by combining the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the vulnerability of the database described in S3 is exploited. The calculation formula is: V 数据库i =D importance *V impact *V exploit / 2 Among them, V 数据库i For a single database risk.

6. The method for comprehensive assessment of database vulnerability risk according to claim 5, characterized in that: As described in S5, all database risks are cumulatively calculated to obtain the risk value of the overall database. The calculation formula is: Among them, V 数据库 Zi is the risk value of the entire database, Z i is the weight coefficient, and the sum of Zi is 1.

7. A comprehensive assessment system for database vulnerability risk, characterized in that: The evaluation system comprises: A database importance calculation module is used to calculate the importance of the database based on the service level carried by the database and evaluate the importance of the database; The business levels include core business, key business, important business, general business, and ordinary business; A quantitative index calculation module for the impact of database vulnerability, which is used to calculate the quantitative index of the impact of database vulnerability based on the impact of security vulnerabilities in the database and the probability of vulnerability impact caused by the vulnerabilities; A module for calculating the degree of difficulty of exploiting database vulnerabilities, used to calculate the quantitative index of the degree of difficulty of exploiting database vulnerabilities; A single database risk calculation module is used to comprehensively calculate the importance of the database described in S1, the impact of the vulnerability described in S2 on the database, and the degree to which the database vulnerability described in S3 is exploited to derive the risk of a single database; The risk value calculation module of the entire database is used to accumulate and calculate the risks of all databases to obtain the risk value of the entire database.

8. A computer-readable storage medium storing computer program instructions, wherein when the computer program instructions are executed by a computer, the computer executes the steps of the database vulnerability risk comprehensive assessment method according to any one of claims 1 to 6.