Database data leakage risk assessment method and system
By introducing regulators into the database data breach risk assessment method, the problem of failure to consider the correction impact of data security means on risks in the prior art is solved, and a more accurate and dynamic risk assessment results are achieved.
Patent Information
- Application Number
- CN202510082329.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-06
AI Technical Summary
When evaluating the risk of database data leakage, the prior art failed to consider the impact of the data security measures taken on the risk correction on the risk, and the evaluation method lacks dynamicity and cannot reflect the changes in the unit's database protection measures in real time.
A database data leakage risk assessment method is proposed, and the database data leakage risk assessment results are calculated by obtaining the database's leakage possibility score, loss scoring and adjustment factors. The regulator is determined by the attack test results, reflects the effectiveness of current security measures, and corrects for risk assessment.
By introducing regulators, the evaluation results more accurately reflect the actual leakage risk of the database, and can dynamically adjust the evaluation results to respond to changes in the unit's protection measures for the database.
Smart Images

Figure CN119939603A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer information security technology, and in particular to a database data leakage risk assessment method and system. Background Art
[0002] In today's information age, incidents of sensitive information leakage and abuse of government agencies, enterprises, institutions and individuals occur frequently, and data security issues are becoming more and more prominent. Therefore, in the process of database system construction and operation and maintenance, it is necessary to assess the security risks of data leakage and then take measures to strengthen or protect security.
[0003] Traditional data leakage risk assessment methods mainly evaluate from two aspects: the possibility of threat occurrence and the value of data. That is, on the one hand, it is to judge how great the probability of data leakage is (for example, the probability of key confidential units and financial institutions being attacked is high; for example, the possibility of sensitive data being leaked or stolen is high); on the other hand, it is to judge how much loss or harm will be caused once the data is leaked (including economic loss, social impact, etc.).
[0004] Problems with existing evaluation methods:
[0005] (1) The risk of data of the same nature and value in two different units may be different, because different units adopt different database security countermeasures and means, and the size of data risk will also change accordingly. The existing assessment method fails to consider the corrective effect of the security measures already taken on data risk.
[0006] (2) In the same unit, the risk of the same type of data is not static. As the unit continues to strengthen its database data protection measures, its data risk will also change. Existing assessment methods are mostly one-time assessments that do not take into account the dynamic nature of the assessment. Summary of the invention
[0007] The present application provides a database data leakage risk assessment method and system, which can solve the technical problem that the database data leakage risk assessment method in the prior art fails to consider the correction effect of the adopted data security measures on the data leakage risk.
[0008] In a first aspect, the present application provides a method for assessing the risk of database data leakage, comprising the following steps:
[0009] Obtain the leakage probability score of the database to be evaluated;
[0010] Get the damage score caused by the leak to the database;
[0011] Obtaining adjustment factors for data leakage risk in the database;
[0012] The database data leakage risk assessment result is calculated by multiplying the leakage possibility score, the loss score and the adjustment factor.
[0013] In conjunction with the first aspect, in one implementation, obtaining the leakage possibility score of the database to be evaluated specifically includes the following steps:
[0014] Obtaining a database data leakage possibility analysis table, wherein the database data leakage possibility analysis table includes a probability of occurrence of a data leakage risk, a corresponding leakage possibility score, and a description of the probability of occurrence of a data leakage risk;
[0015] Quantitatively query the database data leakage possibility analysis table to obtain the leakage possibility score of the data in the database to be evaluated.
[0016] In combination with the first aspect, in one implementation, obtaining a score for the loss caused by the leakage to the database specifically includes the following steps:
[0017] Obtaining a data value assessment table, wherein the data value assessment table includes a data value index and a corresponding loss score and a data value index degree definition;
[0018] A quantitative query is performed based on the database value assessment table to obtain a score for the loss caused by data leakage in the database to be assessed.
[0019] In combination with the first aspect, in one implementation, obtaining the adjustment factor of the data leakage risk in the database specifically includes the following steps:
[0020] Set attack test methods with different attack difficulty levels;
[0021] Perform attack tests on the database to be evaluated in order of attack difficulty level from low to high, until the attack test fails or passes the test verification of attack test methods of all attack difficulty levels, and obtain the attack test results;
[0022] Obtain the adjustment factor based on the attack test results of the database to be evaluated.
[0023] In combination with the first aspect, in one implementation, the attack test mode of setting different attack difficulty levels specifically includes the following steps:
[0024] Setting a group of attack test modules, wherein the group of attack test modules includes attack test methods for implementing different attack difficulty levels;
[0025] For each attack test module, an executable program and the dependent data set of the program are packaged and put into the risk response verification library.
[0026] In combination with the first aspect, in one implementation, performing attack tests on the database to be evaluated in order of attack difficulty levels from low to high until the attack test fails or passes the test verification of attack test methods of all attack difficulty levels, and obtaining the attack test results, specifically includes the following steps:
[0027] Select the basic container image of the attack test module according to the model, version, operating system, and CPU architecture of the database to be evaluated;
[0028] The basic container image, packaged executable program, dependent data set of program operation, and customized evaluation data for the evaluated database are built into a Docker container for each attack test module through Dockerfile;
[0029] The attack test modules of different attack difficulty levels are executed in sequence from low to high to perform attack tests on the database to be evaluated, and the attack test results of the database to be evaluated are obtained.
[0030] In combination with the first aspect, in one implementation, obtaining the adjustment factor according to the attack test result of the database to be evaluated specifically includes the following steps:
[0031] If the database to be evaluated fails the test verification of the attack test method of one of the attack difficulty levels, the adjustment factor is obtained by querying the attack test performance comparison table according to the actual attack test performance of the database to be evaluated;
[0032] If the database to be evaluated passes the test verification of all attack test methods of attack difficulty levels, the adjustment factor is 0;
[0033] If the database to be evaluated fails the test verification of any attack test method of the attack difficulty level, the adjustment factor is 1.
[0034] In combination with the first aspect, in one embodiment, the attack test performance comparison table includes at least an attack test method, an attack test performance and an adjustment factor; wherein the attack test method includes attack test methods of different attack difficulty levels, and the attack test performance includes various attack test performances corresponding to the attack test method of each attack difficulty level.
[0035] In a second aspect, the present application provides a database data leakage risk assessment system, comprising:
[0036] A leakage possibility score acquisition module is used to obtain the leakage possibility score of the database to be evaluated;
[0037] The data value loss score acquisition module is used to obtain the loss score caused by the leakage to the database;
[0038] An adjustment factor acquisition module is used to obtain an adjustment factor of data leakage risk in a database;
[0039] The data leakage risk assessment module is in communication with the leakage possibility score acquisition module, the data value loss score acquisition module and the adjustment factor acquisition module, and is used to calculate the database data leakage risk assessment result by multiplying the leakage possibility score, the loss score and the adjustment factor.
[0040] In conjunction with the second aspect, in one implementation, the adjustment factor acquisition module includes:
[0041] An attack test mode setting unit is used to set attack test modes of different attack difficulty levels;
[0042] An attack test result acquisition unit, which is in communication connection with the attack test mode setting unit, and is used to perform attack tests on the database to be evaluated in order of attack difficulty levels from low to high, until the attack test fails or passes the test verification of the attack test modes of all attack difficulty levels, and acquire the attack test results;
[0043] The adjustment factor acquisition unit is in communication connection with the attack test result acquisition unit and is used to acquire the adjustment factor according to the attack test result of the database to be evaluated.
[0044] The beneficial effects brought by the technical solution provided by the embodiment of the present application include at least:
[0045] By introducing an adjustment factor into the assessment method, which depends on the effectiveness of the current security countermeasures tested, and the leakage risk assessment is corrected by the adjustment factor, a more accurate database data leakage risk assessment result is obtained by combining the adjustment factor, the data leakage possibility score, and the loss score caused by the data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 A flowchart of a database data leakage risk assessment method provided in an embodiment of the present application;
[0047] Figure 2 A flowchart of a database data leakage risk assessment method provided in an embodiment of the present application;
[0048] Figure 3 This is a flow chart of the method of Example 1 of the present application;
[0049] Figure 4 This is a flow chart of the method of Example 2 of the present application;
[0050] Figure 5 A schematic diagram of a database data leakage risk assessment system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0052] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit "first", "second" and "third" to different types.
[0053] In the description of the embodiments of the present application, "exemplary", "for example" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary", "for example" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary", "for example" or "for example" is intended to present related concepts in a specific way.
[0054] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; the “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.
[0055] In some processes described in the embodiments of the present application, multiple operations or steps that appear in a specific order are included, but it should be understood that these operations or steps may not be executed in the order in which they appear in the embodiments of the present application or in parallel, and the sequence number of the operation is only used to distinguish the different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed in sequence or in parallel, and these operations or steps may be combined.
[0056] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0057] First, as Figure 1-Figure 2 As shown, the embodiment of the present application provides a database data leakage risk assessment method, comprising the following steps:
[0058] Step S1: Obtain the leakage possibility score of the database to be evaluated;
[0059] Step S2: Obtain the damage score caused by the leakage to the database;
[0060] Step S3: Obtaining the adjustment factor of the data leakage risk in the database;
[0061] Step S4: The database data leakage risk assessment result is calculated by multiplying the leakage possibility score, the loss score and the adjustment factor.
[0062] This application introduces an adjustment factor into the evaluation method. The adjustment factor depends on the effectiveness of the current security countermeasures tested, and the leakage risk assessment is corrected by the adjustment factor. The adjustment factor, the data leakage possibility score, and the loss score caused by the data leakage are combined to obtain a more accurate database data leakage risk assessment result.
[0063] In one embodiment, the step S1: obtaining the leakage possibility score of the database to be evaluated specifically includes the following steps:
[0064] Step S11: Obtain a database data leakage possibility analysis table, as shown in Table 1:
[0065] Table 1 Database data leakage possibility analysis table
[0066]
[0067]
[0068] Step S12: quantitatively query the database data leakage possibility analysis table to obtain the leakage possibility score of the data in the database to be evaluated; specifically, quantitatively query the occurrence probability of data leakage risk in the database to be evaluated to obtain the corresponding data leakage possibility score of the database to be evaluated.
[0069] In one embodiment, the step S2: obtaining a score of the loss caused by the leakage to the database, specifically includes the following steps:
[0070] Step S21: Obtain a data value assessment table, as shown in Table 2:
[0071] Table 2 Data value assessment table
[0072]
[0073] Step S22: quantitatively query the database value assessment table to obtain the loss score caused by data leakage in the database to be assessed; specifically, quantitatively query the data value assessment table according to the data value index of the database to be assessed to obtain the corresponding data value index assignment as the loss score caused by data leakage.
[0074] In one embodiment, the step S3: obtaining the adjustment factor of the data leakage risk in the database specifically includes the following steps:
[0075] Step S31: Setting attack test modes of different attack difficulty levels;
[0076] Step S32: performing attack tests on the database to be evaluated in order of attack difficulty levels from low to high, until the attack test fails or passes the test verification of attack test methods of all attack difficulty levels, and obtaining the attack test results;
[0077] Step S33: Obtain an adjustment factor according to the attack test result of the database to be evaluated.
[0078] In one embodiment, the step S31: setting attack test modes with different attack difficulty levels specifically includes the following steps:
[0079] Step S311: a group of attack test modules is set, wherein the group of attack test modules includes attack test methods with different attack difficulty levels, and an adjustment value range is set for each attack test module, wherein the upper limit of the range is 1 and the lower limit is 0. The attack test module with a higher attack difficulty level has a smaller corresponding adjustment value, indicating that a smaller adjustment factor can be obtained through the attack test, thereby adjusting the final risk value to a smaller value;
[0080] Step S312: for each attack test module, an executable program and a dependent data set of the program running are packaged and put into the risk response measure verification library, and the risk response measure verification library is constructed, as shown in Table 3; wherein the executable program is a Java executable program, a Python executable program or a Shell script, etc.; the dependent data set of the program running is the dependent library of the program running, the environment variables, and the necessary data of the attack assessment (such as the weak password library, the vulnerability library, etc.);
[0081] Table 3 Risk response measures verification library
[0082]
[0083] The running platform subsystem is used as the carrier for the attack test module program. Specifically, the container platform can be used to quickly generate and distribute the attack test module program. The running platform subsystem is also responsible for managing various basic images (such as container images).
[0084] In one embodiment, the step S32: performing attack tests on the database to be evaluated in order of attack difficulty levels from low to high, until the attack test fails or passes the test verification of attack test methods of all attack difficulty levels, and obtaining the attack test results, specifically includes the following steps:
[0085] Step S321: reselecting a basic container image (such as a container image) of the attack test module from the running platform subsystem according to the model, version, operating system and CPU architecture of the database to be evaluated;
[0086] Step S322: Take out the executable program and dependent data of each attack test module from the risk response measures verification library, package the above two parts of data into an executable image (for example, use Dockerfile to make a container), and add customized evaluation data for the evaluated database (for example, database address, targeted cracking dictionary, etc.) during the packaging process. The basic container image, the packaged executable program and the dependent data set of the program operation and the customized evaluation data for the evaluated database are constructed into a Docker container for each attack test module through Dockerfile;
[0087] Step S323: Execute the attack test modules of data leakage risk in sequence from attack difficulty level 1 to attack difficulty level n to obtain the attack test results of the database to be evaluated.
[0088] In one embodiment, the step S33: obtaining the adjustment factor according to the attack test result of the database to be evaluated, specifically includes the following steps:
[0089] Step S331: If the database to be evaluated fails the test verification of the attack test method of a certain attack difficulty level, the attack test performance comparison table is queried to obtain the adjustment factor according to the actual attack test performance shown in Table 4:
[0090] Table 4 Test performance comparison table
[0091]
[0092]
[0093] Step S332: If the database to be evaluated passes the test verification of the attack test methods of all attack difficulty levels, the adjustment factor is 0;
[0094] Step S333: If the database to be evaluated fails the test verification of any attack test method of the attack difficulty level, the adjustment factor is set to 1.
[0095] In one embodiment, the attack test performance comparison table includes at least an attack test method, an attack test performance and an adjustment factor; wherein the attack test method includes attack test methods of different attack difficulty levels, and the attack test performance includes various attack test performances corresponding to the attack test method of each attack difficulty level.
[0096] The following provides a specific database leakage risk assessment method embodiment:
[0097] Example 1
[0098] This application provides a database data leakage risk assessment method, the embodiment steps are as follows Figure 3 shown.
[0099] Taking the user information data of the financial industry as an example, the steps to implement the assessment are as follows.
[0100] S101. Construct a risk response verification library. In the risk response verification library, a set of three attack test modules with difficulty from low to high is set for the risk of database data leakage: "Use known or 0day vulnerabilities of the model and version of the database to enter the database" (hereinafter referred to as the first attack test module), "Enter the database by brute force cracking the database password" (hereinafter referred to as the second attack test module), "Unable to crack the database through vulnerabilities or brute force, after entering the database with the password, try to crack user sensitive data" (hereinafter referred to as the third attack test module), such as Figure 5 shown.
[0101] The different difficulties of the three attack test modules refer to: the first attack test module is a primary means, which uses known vulnerabilities to directly enter the database; the second attack test module is an intermediate means, that is, the target database has no obvious exploitable vulnerabilities, and the database can only be entered through brute force by detecting the password; the third attack test module is an advanced means, that is, the database is directly broken through vulnerabilities or brute force, and the database can only be entered after the password is given, and further attempts to crack user sensitive data.
[0102] S102, setting an adjustment value range for each attack test module. The upper limit of the range is 1, and the lower limit is 0 (the higher the level of the attack test module, the smaller the corresponding adjustment value, indicating that a smaller adjustment factor can be obtained through the test, and the final risk value will be adjusted to be smaller).
[0103] S103, for each attack test module, packaging an executable program and a dependent data set of the program running, and putting them into the risk response measure verification library;
[0104] S104. When conducting the assessment, firstly, the possibility score of the risk and the loss score caused by the risk once it occurs are quantitatively checked according to the leakage possibility analysis table and the data value assessment table, as shown in Table 1 and Table 2. In the embodiment of the present application, the threat that may occur to user information data in the financial field under special conditions has a medium frequency of occurrence and has been confirmed to have occurred. By comparing the leakage possibility analysis table, the threat possibility value is 3; once the financial user data is leaked, it will cause significant damage to the financial enterprise; and it will cause serious harm to the economic operation, social stability, and public interests. By comparing the data value assessment table, the data value is 4.
[0105] S105, construct each attack test module according to the risk response measure verification library. First, select the basic container image of the attack test module according to the model, version, operating system, and CPU architecture of the tested database.
[0106] S106. The basic container image in S105, the executable program packaged in S103 and the dependent data set of the program running, as well as the customized evaluation data for the evaluated database (such as the database address, the targeted password cracking dictionary, etc.) are constructed into a docker container for each attack test module through the dockerfile.
[0107] S107, obtaining the adjustment factor of the database data leakage risk. First, the attack test modules of the data leakage risk are executed in sequence from attack difficulty level 1 to attack difficulty level n. Whenever an attack test module is passed, the attack test module of the higher level is continued to be executed.
[0108] S107-1. If a certain attack test module fails to pass the test, and based on the actual test performance, the test performance comparison table is queried to obtain a specific adjustment factor value, see Table 4, and the subsequent attack test modules with higher levels are no longer executed. In this embodiment, the attacked database passes the first attack test module, but fails the second attack test module, and during the attack, the advanced cracking dictionary (including a customized blasting dictionary for the evaluated unit) is used to successfully crack, and the cracking time is less than the set threshold of 4 hours. Therefore, the adjustment factor is 0.5, and the third attack test module does not need to be executed.
[0109] S107-2. If all attack test modules are passed, the adjustment factor is 0, which means that the current data security countermeasure has a complete protection effect. In subsequent calculations, the risk will be reduced to 0 (no risk or almost no risk).
[0110] S107-3. If any attack test module fails, the adjustment factor is 1, which means that the current data security countermeasures have no effect, that is, in the subsequent calculation of the final risk value, no adjustment correction will be made to the result.
[0111] S108. The quantitative analysis values of step S104 and step S107 are combined to obtain the final result of risk assessment according to R=A (loss score)×F (leakage possibility score)×B (adjustment factor). In the embodiment of the present application, A=4, F=3, B=0.5, and the final assessment result R=6.
[0112] S109. Periodically repeat steps S107 and S108 to obtain updated risk assessment results; whenever the assessed unit updates its data security countermeasures, repeat steps S107 and S108 to obtain the latest data risk assessment results, taking into account the dynamic nature of the assessment.
[0113] It should be noted that the risk attack test module and the test performance comparison table set in this embodiment are a typical test method and test result analysis method. In the actual database leakage assessment scenario, similar risk attack test modules and test performance comparison tables can be used as needed, which also complies with the evaluation method of this patent. The operating environment of the attack test module in this embodiment is a container platform, which is a typical operating environment. In the actual database leakage assessment scenario, a virtualized cloud platform or a serverless platform can be used as needed, which also complies with the evaluation method of this application.
[0114] In a second aspect, the present application provides a database data leakage risk assessment system, comprising:
[0115] A leakage possibility score acquisition module is used to obtain the leakage possibility score of the database to be evaluated;
[0116] The data value loss score acquisition module is used to obtain the loss score caused by the leakage to the database;
[0117] An adjustment factor acquisition module is used to obtain an adjustment factor of data leakage risk in a database;
[0118] The data leakage risk assessment module is in communication with the leakage possibility score acquisition module, the data value loss score acquisition module and the adjustment factor acquisition module, and is used to calculate the database data leakage risk assessment result by multiplying the leakage possibility score, the loss score and the adjustment factor.
[0119] In one embodiment, the adjustment factor acquisition module includes:
[0120] An attack test mode setting unit is used to set attack test modes of different attack difficulty levels;
[0121] An attack test result acquisition unit, which is in communication connection with the attack test mode setting unit, and is used to perform attack tests on the database to be evaluated in order of attack difficulty levels from low to high, until the attack test fails or passes the test verification of the attack test modes of all attack difficulty levels, and acquire the attack test results;
[0122] The adjustment factor acquisition unit is in communication connection with the attack test result acquisition unit and is used to acquire the adjustment factor according to the attack test result of the database to be evaluated.
[0123] In the embodiment of the present application, a system for assessing the risk of database data leakage includes six subsystems, namely, a risk response measure verification library, an operation platform subsystem, an attack test module program construction subsystem, a risk assessment execution subsystem, a risk assessment data analysis subsystem, and a risk assessment task management subsystem. Figure 5 .
[0124] The risk response verification library defines a set of attack test modules for database data leakage risks. Each set of attack test modules includes test verification programs for implementing attacks of different difficulty levels. Each test verification program contains an executable program and a dependent data set for program operation. Typically, the executable program is a Java executable program, a Python executable program, a Shell script, etc.; the dependent data set for program operation is the dependent library of program operation, environment variables, and necessary data for attack evaluation (such as weak password library, vulnerability library, etc.)
[0125] The operating platform subsystem is the carrier for the attack test module program to run. Specifically, the container platform can be used to quickly generate and distribute the attack test module program. The operating platform subsystem is also responsible for managing various basic images (typically, such as container images).
[0126] The attack test module program construction subsystem is responsible for selecting a basic image (such as a container image) from the running platform subsystem according to the model, version, operating system, and CPU architecture of the database to be evaluated, taking out the executable program and dependent data of each attack test module from the risk response verification library, and packaging the above two parts of data into an executable image (for example, using Dockerfile to make a container), and adding customized evaluation data for the database to be evaluated during the packaging process (such as database address, targeted cracking dictionary, etc.).
[0127] The risk assessment execution subsystem is responsible for sending the executable images prepared in the previous step to the operation platform subsystem for execution according to the levels of the attack test modules from low to high.
[0128] The risk assessment data analysis subsystem is responsible for selecting adjustment factors based on the execution results, and ultimately combining the "Leakage Possibility Analysis Table" and the "Data Value Assessment Table" to quantitatively check the threat possibility score of the risk and the loss score (data value) caused once the risk occurs, and obtain the final data leakage risk value through the three scores.
[0129] The risk assessment task management subsystem is responsible for periodically scheduling assessment tasks so that the latest data leakage risk value of the assessed unit can be obtained after the database protection measures are changed.
[0130] Example 2
[0131] This application provides a system for assessing the risk of database data leakage. The system workflow is as follows: Figure 4 shown.
[0132] S201. Set up a group of attack test modules, each group of attack test modules includes test verification programs for implementing attacks of different difficulty levels, each test verification program contains an executable program (Java executable program, Python executable program, a Shell script, etc.) and a dependent data set for program operation (dependent libraries for program operation, environment variables, necessary data for attack evaluation, such as cracking dictionaries, vulnerability libraries, etc.), and store this group of attack test modules in the risk response measures verification library subsystem.
[0133] The operating platform subsystem is the carrier for the attack test module program to run. Typically, the container platform is used to quickly generate and distribute the attack test module program. The operating platform subsystem is also responsible for managing various basic images (such as container images).
[0134] S202. Build a subsystem through the attack test module program. According to the model, version, operating system, and CPU architecture of the tested database, select a basic container image from the running platform subsystem. Take out the executable program and dependent data of each attack test module from the risk response measure verification library subsystem. Use Dockerfile to make containers and package the above two parts of data into an executable container image. In the packaging process, add customized evaluation data for the tested database (such as database address, targeted cracking dictionary, etc.).
[0135] S203, the risk assessment execution subsystem sends the executable images prepared in the previous step to the operation platform subsystem for execution according to the levels of the attack test modules from low to high.
[0136] S204. Analyze the execution results in S203 through the risk assessment data analysis subsystem, select the adjustment factors according to the patent database data leakage risk assessment method, and combine the "leakage possibility analysis table" and "data value assessment table" to quantitatively check the possibility score of risk occurrence and the loss score caused by the risk once it occurs, and obtain the final data leakage risk value through the three scores.
[0137] S205. Periodically schedule assessment tasks through the risk assessment task management subsystem so as to obtain the latest data leakage risk value of the assessed unit after the database protection measures are changed.
[0138] In a third aspect, an embodiment of the present application provides a database data leakage risk assessment device, which may be a personal computer (PC), a laptop computer, a server, or other device with data processing capabilities.
[0139] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces, which are used to interconnect devices within the database data leakage risk assessment device, and interfaces used to interconnect the database data leakage risk assessment device with other devices (such as other computing devices or user devices). The physical interface can be an Ethernet interface, a fiber optic interface, an ATM interface, etc.; the user device can be a display, a keyboard, etc.
[0140] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0141] The processor may be a general-purpose processor, and the general-purpose processor may call the database data leakage risk assessment program stored in the memory and execute the database data leakage risk assessment method provided in the embodiment of the present application. For example, the general-purpose processor may be a central processing unit (CPU). The method executed when the database data leakage risk assessment program is called may refer to the various embodiments of the database data leakage risk assessment method of the present application, and will not be repeated here.
[0142] In a fourth aspect, an embodiment of the present application also provides a readable storage medium.
[0143] The readable storage medium of the present application stores a database data leakage risk assessment program, wherein when the database data leakage risk assessment program is executed by a processor, the steps of the above-mentioned database data leakage risk assessment method are implemented.
[0144] Among them, the method implemented when the database data leakage risk assessment program is executed can refer to the various embodiments of the database data leakage risk assessment method of the present application, and will not be repeated here.
[0145] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0146] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, disk, CD) as described above, and includes a number of instructions for a terminal device to execute the methods described in each embodiment of the present application.
[0147] The above are only preferred embodiments of the present application, and are not intended to limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A database data leakage risk assessment method, characterized in that: The following steps are involved: Obtain the leakage probability score of the database to be evaluated; Get the damage score caused by the leak to the database; Obtaining adjustment factors for data leakage risk in the database; The database data leakage risk assessment result is calculated by multiplying the leakage possibility score, the loss score and the adjustment factor.
2. The database data leakage risk assessment method according to claim 1, characterized in that: The step of obtaining the leakage possibility score of the database to be evaluated specifically includes the following steps: Obtaining a database data leakage possibility analysis table, wherein the database data leakage possibility analysis table includes a probability of occurrence of a data leakage risk, a corresponding leakage possibility score, and a description of the probability of occurrence of a data leakage risk; Quantitatively query the database data leakage possibility analysis table to obtain the leakage possibility score of the data in the database to be evaluated.
3. The database data leakage risk assessment method according to claim 1, characterized in that: The step of obtaining the score of the damage caused by the leakage to the database specifically includes the following steps: Obtaining a data value assessment table, wherein the data value assessment table includes a data value index and a corresponding loss score and a data value index degree definition; A quantitative query is performed based on the database value assessment table to obtain a score for the loss caused by data leakage in the database to be assessed.
4. The database data leakage risk assessment method according to claim 1, characterized in that: The step of obtaining the adjustment factor of the data leakage risk in the database specifically includes the following steps: Set attack test methods with different attack difficulty levels; Perform attack tests on the database to be evaluated in order of attack difficulty level from low to high, until the attack test fails or passes the test verification of attack test methods of all attack difficulty levels, and obtain the attack test results; Obtain the adjustment factor based on the attack test results of the database to be evaluated.
5. The database data leakage risk assessment method according to claim 4, characterized in that: The attack test method of setting different attack difficulty levels specifically includes the following steps: Setting a group of attack test modules, wherein the group of attack test modules includes attack test methods for implementing different attack difficulty levels; For each attack test module, an executable program and the dependent data set of the program are packaged and put into the risk response verification library.
6. The database data leakage risk assessment method according to claim 5, characterized in that: The attack test is performed on the database to be evaluated in order of attack difficulty level from low to high, until the attack test fails or the attack test methods of all attack difficulty levels are tested and verified, and the attack test result is obtained, which specifically includes the following steps: Select the basic container image of the attack test module according to the model, version, operating system, and CPU architecture of the database to be evaluated; The basic container image, packaged executable program, dependent data set of program operation, and customized evaluation data for the evaluated database are built into a Docker container for each attack test module through Dockerfile; The attack test modules of different attack difficulty levels are executed in sequence from low to high to perform attack tests on the database to be evaluated, and the attack test results of the database to be evaluated are obtained.
7. The database data leakage risk assessment method according to claim 5, characterized in that: The step of obtaining the adjustment factor according to the attack test result of the database to be evaluated specifically includes the following steps: If the database to be evaluated fails the test verification of the attack test method of one of the attack difficulty levels, the adjustment factor is obtained by querying the attack test performance comparison table according to the actual attack test performance of the database to be evaluated; If the database to be evaluated passes the test verification of all attack test methods of all attack difficulty levels, the adjustment factor is 0; If the database to be evaluated fails the test verification of any attack test method of the attack difficulty level, the adjustment factor is 1.
8. The database data leakage risk assessment method according to claim 7, characterized in that: The attack test performance comparison table includes at least attack test methods, attack test performances and adjustment factors; wherein the attack test methods include attack test methods of different attack difficulty levels, and the attack test performances include various attack test performances corresponding to the attack test methods of each attack difficulty level.
9. A database data leakage risk assessment system, characterized in that: include: A leakage possibility score acquisition module is used to obtain the leakage possibility score of the database to be evaluated; Data value loss score acquisition module, used to obtain the loss score caused by the leakage to the database; An adjustment factor acquisition module is used to obtain an adjustment factor of data leakage risk in a database; The data leakage risk assessment module is in communication with the leakage possibility score acquisition module, the data value loss score acquisition module and the adjustment factor acquisition module, and is used to calculate the database data leakage risk assessment result by multiplying the leakage possibility score, the loss score and the adjustment factor.
10. The database data leakage risk assessment system according to claim 9, characterized in that: The adjustment factor acquisition module includes: An attack test mode setting unit is used to set attack test modes of different attack difficulty levels; An attack test result acquisition unit, which is in communication connection with the attack test mode setting unit, and is used to perform attack tests on the database to be evaluated in order of attack difficulty levels from low to high, until the attack test fails or passes the test verification of the attack test modes of all attack difficulty levels, and acquire the attack test results; The adjustment factor acquisition unit is in communication connection with the attack test result acquisition unit, and is used to acquire the adjustment factor according to the attack test result of the database to be evaluated.