Digital asset security assessment management system
By introducing scenario analysis and risk simulation modules into the digital asset security assessment and management system, the shortcomings of existing systems in dynamic adaptability are solved, real-time tracking of the security status of digital assets and dynamic analysis of risks are realized, ensuring that users can timely understand and respond to security threats.
Patent Information
- Application Number
- CN202510432096.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing digital asset security assessment management system has shortcomings in terms of dynamic adaptability and is unable to respond to new security threats or changing security needs in a timely manner, resulting in companies not being able to understand the security protection performance of digital assets in a timely manner.
A digital asset security assessment and management system was designed, including the user side and the platform side, which included scenario analysis module and risk simulation module. The scenario analysis module is used to configure user reserve scenario tables for the user side, obtain and analyze scene material data from different industry fields in real time, merge and analyze security protection result data of each scenario, and generate asset scenarios. The risk simulation module is used to conduct risk simulation of digital assets, establish a risk information database, identify asset scenarios and classifications, set simulation conditions, and conduct risk simulation based on the simulation conditions, and generate user risk comparison tables.
Through real-time tracking and analysis of the system, the potential risks of digital assets can be analyzed dynamically and alerted to users in a timely manner to ensure that users can take quick measures to respond. The system can also automatically adjust the protection strategy to maximize the protection effect.
Smart Images

Figure CN119940947A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of digital asset security technology, and in particular is a digital asset security assessment and management system. Background Art
[0002] With the rapid development of information technology, digital assets have become an indispensable component of corporate activities. Digital assets, including but not limited to electronic currency, digital securities, data resources, and software code, possess extremely high value and importance. However, the security of digital assets has become increasingly prominent, becoming a significant constraint on their further development. To address this challenge, digital asset security assessment and management systems have emerged. However, in practical applications, existing systems still have some functional limitations. For example, the security status of digital assets is dynamic, requiring the system to perceive and adapt to these changes in real time. However, existing systems often lack dynamic adaptability and are unable to promptly respond to new security threats or changing security requirements, resulting in enterprises being unable to timely understand the security protection performance of their digital assets.
[0003] Based on this, the present invention provides a digital asset security assessment and management system. Summary of the Invention
[0004] In order to solve the problems existing in the above solutions, the present invention provides a digital asset security assessment and management system to solve the problem that users have difficulty in timely understanding the security protection performance of digital assets.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A digital asset security assessment and management system, comprising a user end and a platform end; The platform includes a scenario analysis module and a risk simulation module; The scenario analysis module is used to configure a user reserve scenario table for the corresponding user terminal.
[0006] Furthermore, a user reserve scenario table is configured for the user terminal, including: Determine the asset scenarios of users in different industry fields in real time, and generate scenario information tables based on asset scenarios and industry fields; Identify user information sent by the corresponding user terminal in real time, match the corresponding asset scenario from the scenario information table according to the user information, set the user reserve scenario table according to the asset scenario, and send the user reserve scenario table to the corresponding user terminal.
[0007] Furthermore, we identify the asset scenarios of users in different industries, including: Real-time acquisition of scene material data from different industries and fields, where the scene material data is historical security protection data from the corresponding industry and fields; identification of various scenarios contained in the scene material data, and statistical analysis of security protection result data corresponding to the scenarios based on the scene material data; Based on the security protection result data, each scenario is combined and analyzed to obtain the asset scenario corresponding to the industry field.
[0008] Furthermore, the security protection results data is used to conduct a combined analysis of each scenario, including: Step SA1: Calculate the similarity between each security protection result data; When the similarity is not less than the threshold X1, the corresponding two scenes are merged to obtain a new scene, and the security protection result data of the new scene is determined; When the similarity is less than the threshold X1, it is determined that the corresponding two scenes do not meet the merging requirements; Step SA2: Loop step SA1 until all scenes no longer meet the merging requirements, and mark the remaining scenes as asset scenes.
[0009] The risk simulation module is used to simulate the risks of digital assets and configure a corresponding user risk comparison table for the corresponding user terminal. The user risk comparison table is used to count the corresponding simulation conditions, risk attack methods, protection success probability and attack application information.
[0010] Furthermore, risk simulation of digital assets is performed, including: Establish a risk information database to store various risk attack methods corresponding to digital assets and attack application information corresponding to the risk attack methods, including asset characteristics and application probability; Obtaining a scenario information table, identifying various asset scenarios in the scenario information table, determining various asset classifications in the asset scenarios, and setting corresponding simulation conditions based on the asset scenarios and asset classifications; Perform risk simulation on the simulation condition according to the risk information database to obtain the protection success probability of the simulation condition under the risk attack mode; Establish an attack comparison table based on simulation conditions, risk attack methods, protection success probability, and attack application information; The attack comparison table is screened according to the user information to obtain a user risk comparison table for the user; and the user risk comparison table is sent to the corresponding user terminal.
[0011] The user terminal includes an asset identification module and a risk analysis module; The asset identification module is used to identify the digital assets of the user in real time, classify the digital assets, and obtain several asset classifications; collect asset record data in real time, determine the asset scenarios corresponding to the asset classifications based on the asset record data; and generate an asset detailed list based on the asset classifications and asset scenarios.
[0012] Furthermore, the collection of asset record data includes: Identify user information, send the user information to the platform, receive the user reserve scenario table sent by the platform, identify the asset scenario in the user reserve scenario table, collect data according to the asset scenario, and obtain asset record data.
[0013] The risk analysis module is used to perform real-time risk assessment on the user's digital assets, obtain the user risk comparison table and asset detailed table, generate an asset risk map based on the user risk comparison table and asset detailed table, and the asset risk map includes the potential risk values corresponding to the corresponding digital assets; and display the asset risk map to the user.
[0014] Furthermore, an asset risk map is generated based on the user risk comparison table and the asset details table, including: Identify the asset classification and asset scenario corresponding to the asset details table, input the combination of the asset classification and asset scenario into the user risk comparison table for matching, and obtain the protection success probability of the asset classification under the corresponding asset scenario and risk attack method; identify the digital assets of the user corresponding to the asset classification, and determine the protection success probability of the digital assets under the corresponding asset scenario and risk attack method; Identify the asset characteristics of the digital asset and match the application probability of the corresponding digital asset under the corresponding risk attack mode from the user risk comparison table based on the asset characteristics; Calculate the potential risk value of the digital asset, and generate an asset risk map based on the digital asset and the potential risk value.
[0015] Furthermore, the potential risk value of digital assets is calculated, including: The combination of asset scenario and risk attack mode is marked as i, i = 1, 2, ..., n, n is the number of combinations of asset scenario and risk attack mode; the probability of successful protection is marked as μ i ; According to the risk attack mode corresponding to the protection success probability, the corresponding application probability is identified and the application probability is marked as δ i ; Calculate the potential risk value of the corresponding digital asset according to the risk calculation formula. The risk calculation formula is: ; Where: QF is the potential risk value.
[0016] Furthermore, the user terminal also includes a risk management module, which is used to perform risk management based on the asset risk map, obtain risk management requirements, perform real-time early warning analysis on the asset risk map based on the risk management requirements, determine digital assets that meet the risk management requirements, and mark the digital assets as target management assets; and optimize asset protection methods based on the target management assets.
[0017] Compared with the prior art, the present invention has the following beneficial effects: Through the interoperability of various modules, the security status of digital assets can be tracked and analyzed in real time. Dynamic analysis of potential risks across digital assets, along with evolving attack and protection technologies, allows users to intuitively and promptly understand the potential risks of all digital assets. Upon detecting a potential security threat or risk change, the system immediately triggers an early warning mechanism and sends an alert to the user, ensuring they can quickly take countermeasures. By dynamically updating the risk information database, the system can promptly respond to emerging attack techniques and security threats. Furthermore, the system automatically adjusts protection strategies based on the type and size of the user's digital assets to maximize protection effectiveness. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 This is a principle block diagram of the present invention. DETAILED DESCRIPTION
[0020] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0021] like Figure 1 As shown, a digital asset security assessment and management system includes a user end and a platform end; The user terminal is used by users and includes an asset identification module, a risk analysis module and a risk management module; The asset identification module is used to identify the digital assets of the user in real time, classify the identified digital assets, and obtain several asset classifications; obtain asset record data of the user's digital assets in real time; determine the asset scenarios corresponding to each asset classification based on the asset record data; and generate an asset detailed list based on the asset classification and asset scenario.
[0022] In one embodiment, the collection of asset record data includes: Identify user information, send user information to the platform, receive the user reserve scenario table sent by the platform, identify the asset scenarios in the user reserve scenario table, collect data based on whether each asset classification has the corresponding asset scenario, and obtain asset record data.
[0023] In one embodiment, determining the asset scenario corresponding to each asset classification based on the asset record data includes: Match the corresponding asset scenarios from the user reserve scenario table based on the asset record data; specifically, the matching can be performed according to the existing matching method; for example, the asset record data can be identified and matched according to the various scenarios corresponding to the asset scenarios, or the scenarios in the asset record data can be identified first and then matched.
[0024] The risk analysis module is used to perform real-time risk assessment on digital assets, obtain a user risk comparison table and an asset detail table, generate an asset risk map based on the user risk comparison table and the asset detail table, and the asset risk map includes the potential risk value corresponding to each digital asset; and display the asset risk map to the user.
[0025] In one embodiment, generating an asset risk map based on the user risk comparison table and the asset details table includes: Identify the asset classification and asset scenario corresponding to the asset details table, input the combination of asset classification and asset scenario into the user risk comparison table for matching, and obtain the protection success probability of the asset classification under the corresponding asset scenario and risk attack method; identify the digital assets of the user corresponding to the asset classification, and determine the protection success probability of the digital assets under the corresponding asset scenario and risk attack method.
[0026] Identify the asset characteristics of digital assets, such as asset value and importance, which can be determined based on the user's actual situation, such as user-setup, intelligent assessment, etc.; based on the asset characteristics, match the application probability of the corresponding digital asset under the corresponding risk attack method from the user's risk comparison table.
[0027] Calculate the potential risk value of the corresponding digital asset and generate an asset risk map based on the digital asset and potential risk value; that is, use the asset risk map to intuitively represent the potential risk value of each digital asset, so that users can understand the current potential risk status of various digital assets in real time and dynamically.
[0028] In one embodiment, calculating the potential risk value of a digital asset includes: The combination of asset scenario and risk attack mode is marked as i, i = 1, 2, ..., n, n is the number of combinations of asset scenario and risk attack mode; the probability of successful protection is marked as μ i ; According to the risk attack mode corresponding to the protection success probability, the corresponding application probability is identified and the application probability is marked as δ i ; Calculate the potential risk value of the corresponding digital asset according to the risk calculation formula. The risk calculation formula is: ; Where: QF is the potential risk value.
[0029] In one embodiment, calculating the potential risk value of a digital asset includes: Eliminate risk attack methods with a probability less than a threshold value X2, such as 5%, 10%, or 20%. Set the threshold value X2 based on actual conditions. Calculate the potential risk value based on the remaining risk attack methods using the above risk calculation formula.
[0030] In one embodiment, calculating the potential risk value of a digital asset includes: Identify the application probability and protection success probability corresponding to the combination of asset scenarios and risk attack methods, multiply the application probability and protection success probability, calculate the potential risk value of the combination, and select the combination with the largest potential risk value from each combination and output it as the potential risk value of the digital asset.
[0031] In one embodiment, the potential risk value of the digital asset may also be calculated based on existing methods.
[0032] The risk management module is used to perform risk management based on the asset risk map. The platform or the user sets the risk management requirements, that is, the potential risk value above which risk management is required. The risk management requirements can also be set differently based on the different digital assets. Because the potential risk value is based on a percentage system, it is convenient for users to set risk management requirements, such as 60, 70, 80, etc. The asset risk map is analyzed in real time based on the risk management requirements to determine the digital assets that meet the risk management requirements. The corresponding digital assets are marked as target management assets. Meeting the risk management requirements means that the potential risk value is greater than the preset value. Optimize asset protection methods based on target managed assets. This involves optimizing and adjusting the target managed assets based on their protection success probability and application probability for corresponding risk attack methods, ensuring that the potential risk value of the optimized target managed assets does not meet risk management requirements. For example, by screening and analyzing existing protection technologies from the perspective of reducing application probability and increasing protection success probability, the optimized protection technology is determined.
[0033] The platform side is used by the platform party, including a scenario analysis module and a risk simulation module; The scenario analysis module is used to analyze the asset scenarios of users in different industries in real time, and generate a scenario information table based on the obtained asset scenarios. The scenario information table is used to count the various asset scenarios corresponding to users in different industries; Real-time identification of user information sent by the corresponding user end, including information related to the matching asset scenario, such as the industry field to which the user belongs; matching the possible asset scenarios of the user from the scenario information table based on the user information, integrating them into a user reserve scenario table, and sending the user reserve scenario table to the corresponding user end.
[0034] In one embodiment, real-time analysis of asset scenarios of users in different industries and fields includes: Acquire scenario material data from different industry fields in real time. Scenario material data refers to historical security protection data in the corresponding industry fields using this digital asset protection method or an equivalent digital asset protection method. Identify the various scenarios contained in the scenario material data, i.e., the scenarios of digital assets. Scenario refers to situations with differences in industry, environment, demand conditions, etc., and the environment can be a storage environment, a usage environment, etc.; compile statistics on the security protection result data corresponding to each scenario based on the scenario material data, i.e., summarize the protection results of the scenario to form security protection result data. Based on the security protection result data, each scenario is combined and analyzed to obtain several asset scenarios corresponding to the industry field.
[0035] In one embodiment, a combined analysis of various scenarios is performed based on the security protection result data, including: Step SA1: Calculate the similarity between each security protection result data; When the similarity is not less than a threshold value X1, the corresponding two scenes are merged to obtain a new scene; the threshold value X1 is set by a person skilled in the art according to actual conditions or obtained by simulation of a large amount of data, such as 90%, 95%, 99%, or 100%; the security protection result data of the new scene is determined, that is, the two security protection result data are integrated and counted, such as the scene material data corresponding to the two scenes are integrated together to count the corresponding security protection result data. Generally, the new security protection result data can be directly determined based on the two security protection result data; When the similarity is less than the threshold X1, it is determined that the corresponding two scenes do not meet the merging requirement, and there is no need to perform subsequent merging analysis on the corresponding scenes or the merged scenes including the corresponding scenes.
[0036] Step SA2: Loop step SA1 until all scenes no longer meet the merging requirements, and mark the remaining scenes as asset scenes.
[0037] In one embodiment, each scenario is merged and analyzed based on the security protection result data, and the merging can be performed based on an existing merging method, such as a merging analysis based on a clustering algorithm, a deep learning algorithm, etc.
[0038] The risk simulation module is used to utilize the sufficient resource data of the platform to simulate the security risks of various digital assets, and to determine in real time the various risk attack methods currently available based on the existing protection methods of digital assets, such as risk attack methods that attack and crack the defects of protection methods such as blockchain technology, biometric technology, and data encryption technology. It mainly utilizes the platform's information resources, data statistical capabilities, etc. to determine various risk attack methods in real time, including new attack methods generated by technological updates; illustratively, attack application methods in various modes such as attacks through social engineering malware, phishing, password attacks, man-in-the-middle attacks, and SIM card hijacking.
[0039] Obtain historical attack records of various risk attack methods. Historical attack records mainly include relevant information such as the attacked digital assets, asset value, and attack frequency. Feature extraction is performed on historical attack records to obtain attack application information of the risk attack records. Attack application information includes asset characteristics and application probability. Asset characteristics refer to characteristics related to the digital asset, such as digital assets, asset value, asset background, and other asset information of interest to the relevant attackers. Application probability is the probability of the risk attack method being applied to the asset characteristics based on statistics from historical attack records.
[0040] A risk information database is established based on risk attack methods and attack application information. The risk information database is used to store various risk attack methods and attack application information; and the risk information database is updated in real time; it can also be directly established and maintained manually by the platform.
[0041] Obtain the scenario information table, identify the various asset scenarios in the scenario information table, determine the various asset classifications that the asset scenarios can correspond to based on the corresponding historical data, and combine the asset scenarios and asset classifications into different simulation conditions, that is, under what asset scenarios and asset classifications are risk simulations performed; perform risk simulations on various simulation conditions based on the risk information library, and obtain the protection success probability of the corresponding simulation conditions under the corresponding risk attack mode; that is, perform attack simulations on the simulation conditions under application security protection based on the corresponding risk attack mode, and calculate the protection success probability. Specifically, use existing simulation methods to perform attack simulations, such as the platform building a corresponding protection system, debugging it according to the simulation conditions, using the corresponding risk attack mode to attack, and calculating the protection success probability; intelligent simulation methods can also be used to perform intelligent attack simulations, and specifically, multiple attack simulation methods can be used.
[0042] Summarize the simulation conditions, risk attack methods, protection success probability, and attack application information to create an attack comparison table; Identify user information, filter the attack comparison table based on the user information, remove information that the user will not use, and form a user risk comparison table applicable to the user; send the user risk comparison table to the corresponding user end.
[0043] The above formulas are all calculated by removing dimensions and taking their numerical values. The formula is a formula that is closest to the actual situation obtained by collecting a large amount of data and performing software simulation. The preset parameters and preset thresholds in the formula are set by technicians in this field according to actual conditions or obtained by simulating a large amount of data.
[0044] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A digital asset security assessment management system, characterized in that: Including user side and platform side; The platform includes a scenario analysis module and a risk simulation module; The scenario analysis module is used to configure a user reserve scenario table for the corresponding user terminal; The risk simulation module is used to perform risk simulation on digital assets and configure a corresponding user risk comparison table for the corresponding user terminal. The user risk comparison table is used to count the corresponding simulation conditions, risk attack methods, protection success probability and attack application information; The user terminal includes an asset identification module and a risk analysis module; The asset identification module is used to identify the digital assets of the user in real time, classify the digital assets, and obtain a number of asset classifications; collect asset record data in real time, and determine the asset scene corresponding to the asset classification according to the asset record data; Generate asset details list based on asset classification and asset scenario; The risk analysis module is used to perform real-time risk assessment on the user's digital assets, obtain the user risk comparison table and asset detail table, and generate an asset risk map based on the user risk comparison table and asset detail table. The asset risk map includes the potential risk value corresponding to the corresponding digital asset; Display the asset risk map to users.
2. A digital asset security assessment management system according to claim 1, characterized in that: Configure the user reserve scenario table for the user terminal, including: Determine the asset scenarios of users in different industry fields in real time, and generate scenario information tables based on asset scenarios and industry fields; Identify the user information sent by the corresponding user terminal in real time, match the corresponding asset scene from the scene information table according to the user information, set the user reserve scene table according to the asset scene, and send the user reserve scene table to the corresponding user terminal.
3. A digital asset security assessment management system according to claim 2, characterized in that: Identify asset scenarios for users in different industry sectors, including: Acquire scene material data of different industries and fields in real time, where the scene material data is historical security protection data of the corresponding industry and fields; identify various scenes in the scene material data, and count the security protection result data corresponding to the scenes based on the scene material data; Based on the security protection result data, each scenario is combined and analyzed to obtain the asset scenario corresponding to the industry field.
4. A digital asset security assessment management system according to claim 3, characterized in that: Combine and analyze each scenario based on the security protection result data, including: Step SA1: Calculate the similarity between each security protection result data; When the similarity is not less than the threshold value X1, the corresponding two scenes are merged to obtain a new scene, and the security protection result data of the new scene is determined; When the similarity is less than the threshold X1, it is determined that the corresponding two scenes do not meet the merging requirements; Step SA2: loop step SA1 until all scenes do not meet the merging requirements, and mark the remaining scenes as asset scenes.
5. A digital asset security assessment management system according to claim 2, characterized in that: Conduct risk simulation on digital assets, including: Establishing a risk information database, which is used to store various risk attack methods corresponding to digital assets and attack application information corresponding to the risk attack methods, wherein the attack application information includes asset characteristics and application probability; Obtain a scenario information table, identify various asset scenarios in the scenario information table, determine various asset classifications in the asset scenario, and set corresponding simulation conditions according to the asset scenario and asset classification; Perform risk simulation on the simulation condition according to the risk information database to obtain the protection success probability of the simulation condition under the risk attack mode; Establish an attack comparison table based on simulation conditions, risk attack methods, protection success probability, and attack application information; The attack comparison table is screened according to the user information to obtain a user risk comparison table for the user; and the user risk comparison table is sent to the corresponding user terminal.
6. A digital asset security assessment management system according to claim 1, characterized in that: Collection of asset record data, including: Identify user information, send the user information to the platform, receive the user reserve scenario table sent by the platform, identify the asset scenario in the user reserve scenario table, collect data according to the asset scenario, and obtain asset record data.
7. A digital asset security assessment management system according to claim 1, characterized in that: Generate an asset risk map based on the user risk comparison table and asset details table, including: Identify the asset classification and asset scenario corresponding to the asset list, input the combination of asset classification and asset scenario into the user risk comparison table for matching, and obtain the protection success probability of the asset classification under the corresponding asset scenario and risk attack mode; identify the digital assets of the user corresponding to the asset classification, and determine the protection success probability of the digital assets under the corresponding asset scenario and risk attack mode; Identify the asset characteristics of the digital asset, and match the application probability of the corresponding digital asset under the corresponding risk attack mode from the user risk comparison table according to the asset characteristics; The potential risk value of the digital asset is calculated, and an asset risk map is generated according to the digital asset and the potential risk value.
8. A digital asset security assessment management system according to claim 7, characterized in that: Calculate the potential risk value of digital assets, including: The combination of asset scenario and risk attack mode is marked as i, i=1, 2, ..., n, n is the number of combinations of asset scenario and risk attack mode; the probability of successful protection is marked as μ i ; According to the risk attack mode corresponding to the protection success probability, the corresponding application probability is identified and the application probability is marked as δ i ; Calculate the potential risk value of the corresponding digital asset according to the risk calculation formula. The risk calculation formula is: ; Where: QF is the potential risk value.
9. A digital asset security assessment management system according to claim 1, characterized in that: The user terminal also includes a risk management module, which is used to perform risk management according to the asset risk map, obtain risk management requirements, perform real-time early warning analysis on the asset risk map according to the risk management requirements, determine digital assets that meet the risk management requirements, and mark the digital assets as target management assets; Optimize asset protection methods based on target asset management.
Citation Information
Patent Citations
Risk assessment method, system and equipment for intelligent network connection industrial control system and medium
CN117579388A
API asset risk analysis method and device, electronic equipment and storage medium
CN117786696A
Risk identification method and system based on intelligent driving
CN118504963A
Data center security assessment method and system
CN119299322A
Risk evaluation system and risk evaluation method
JP2022002057A