Network asset risk assessment method and device in industrial control environment
By conducting multi-dimensional risk assessment of network assets in an industrial control environment, the problem of single data source and evaluation direction in the existing technology is solved, and a more accurate and adaptable risk assessment is achieved.
Patent Information
- Application Number
- CN202510105491.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-13
AI Technical Summary
In the existing industrial control environment, the data source of network asset risk assessment methods is single and the evaluation direction is single, and the risks of internal network assets are not effectively evaluated.
A method of risk assessment of network assets in industrial control environment is proposed, and assets are retrieved through industrial control asset search engine, network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment are carried out, and the risk level of assets is judged based on the weight ratio of preset weights.
It improves the accuracy of evaluation, adapts to industrial control scenarios, can dynamically evaluate, reduces false alarm rates, and reduces system pressure.
Smart Images

Figure CN119995965A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of industrial system control, and in particular relates to a network asset risk assessment method and device in an industrial control environment. Background Art
[0002] Industrial control systems (ICS) consist of control devices such as DCS / PLC, temperature / pressure sensors, and host computers. They monitor and control industrial production processes and are the core of industrial production. With the rapid development and popularization of the Internet, asset security issues are becoming increasingly prominent. Various security incidents such as hacker attacks, virus transmission, and data leakage occur frequently, posing a huge threat to the property and privacy of enterprises. The closed nature of industrial control systems is gradually broken. Existing asset risk assessments are calculated based on asset value, vulnerability risk value, and threat event risk value.
[0003] The existing technical problems are:
[0004] 1. The data source is relatively single, and can only be evaluated through vulnerability scanning results. Whether the vulnerability is exploited is a huge risk, but it is not mentioned in existing technologies.
[0005] 2. The assessment direction is relatively simple, and only the vulnerability aspect is mentioned.
[0006] 3. The industrial control environment is generally an internal network, and the existing solutions do not assess whether it is an internal network. Summary of the invention
[0007] In view of the above-mentioned deficiencies in the prior art, the present application provides a method and device for network asset risk assessment in an industrial control environment.
[0008] In a first aspect, the present application proposes a network asset risk assessment method in an industrial control environment, comprising the following steps:
[0009] Use the industrial control asset search engine to search for industrial control assets in the current industrial control environment to obtain the industrial control assets to be evaluated;
[0010] Conducting network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtaining corresponding assessment scores;
[0011] The various evaluation scores are weighted and summarized according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and the risk level of the industrial control asset to be evaluated is determined according to the total asset risk score.
[0012] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the network risk assessment includes:
[0013] Step 1: Analyze the network data received by the industrial control host to determine whether the industrial control asset to be evaluated has reported network information. If not, proceed to step 2. If network information is reported, further determine whether the network information is unknown. If so, proceed to step 2. If not, the reported network information shall prevail. The reported network information includes an intranet or a public network.
[0014] Step 2: Analyze the access relationship of the industrial control asset to be evaluated. If there is an access relationship with the industrial control asset to be evaluated, proceed to step 2.1; if there is no access relationship, proceed to step 2.2;
[0015] Step 2.1: Determine whether the srcIp of the access to the industrial control asset to be evaluated belongs to the local area network address segment library. If not, determine that the access is to the external network; if so, determine that the access is to the internal network;
[0016] Step 2.2: Analyze whether the address of the industrial control asset to be evaluated belongs to the local area network address segment library. If not, it is determined that the industrial control asset to be evaluated belongs to an unknown network. If yes, it is determined that the industrial control asset to be evaluated belongs to an intranet network.
[0017] Step 3: When it is determined that any one of the network information, access relationship or address of the industrial control asset to be evaluated is an external network, a first network risk assessment score is obtained; when it is an internal network, a second network risk assessment score is obtained; when it is an unknown network, a third network risk assessment score is obtained; and the current network risk assessment score is obtained based on the first network risk assessment score, the second network risk assessment score or the third network risk assessment score.
[0018] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the port risk assessment includes:
[0019] Acquire the port information of the industrial control asset to be evaluated, and determine the number of open ports according to the port information, wherein the open ports include general ports and risk ports, and the number of risk ports is set according to the evaluation requirements of the industrial control asset to be evaluated, and each general port is provided with a general port score value, and each risk port is provided with a risk port score value;
[0020] The port risk assessment algorithm is expressed as:
[0021]
[0022]
[0023] in, Indicates the total score of open ports. Indicates the total score of the scanned open ports. Indicates the number of risky ports, Indicates the number of general ports. It indicates the average value of the port score, which can reflect the proportion of risky ports. If the value is 5, it means that all ports are risky ports. If it is 1, it means that all ports are normal ports. Indicates the influence coefficient. The larger the coefficient, the slower the impact of quantity on the result. Conversely, the smaller the coefficient, the more obvious the impact of quantity on the result. If all ports are general ports, the risk value will not change much as the number of ports increases. If all ports are risk ports, the risk value will change greatly as the number of ports increases. Indicates the number of ports scanned;
[0024] The current port risk assessment score is calculated according to the port risk assessment algorithm.
[0025] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the asset value assessment includes:
[0026] Confirm the asset type of the industrial control asset to be evaluated, confirm the application type that needs to be installed based on the asset type, preset the corresponding asset type score and application type score based on the asset type and the application type, add the asset type score and the application type score to obtain the current asset value evaluation score, preset a limit value for the current asset value evaluation score, and when the current asset value evaluation score reaches the limit value, the current asset value evaluation score is the limit value.
[0027] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the alarm risk assessment includes:
[0028] The alarm risk assessment calculation formula is expressed as:
[0029]
[0030] in, Indicates the number of alarm levels. Indicates the alarm level value. Indicates that the alarm level is converted to a higher level with a larger value. Indicates the alarm level. Indicates the alarm severity level.
[0031] The alarm risk assessment calculation formula is used to perform alarm statistics on the industrial control assets to be assessed to obtain a current alarm risk assessment score.
[0032] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the virus risk assessment includes:
[0033] The virus risk assessment calculation formula is expressed as:
[0034]
[0035] in, Indicates the severity level of the virus, which must be a continuous positive integer. Indicates the severity level of the virus. Indicates the index of a specific virus. Indicates the total number of viruses;
[0036] The virus risk assessment calculation formula is used to perform virus severity statistics on the industrial control assets to be assessed according to the severity level of the virus to obtain a current virus risk assessment score.
[0037] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the vulnerability risk assessment includes:
[0038] The vulnerability risk assessment calculation formula is expressed as:
[0039]
[0040] in, Indicates the risk level of the vulnerability; Indicates the risk level value of the vulnerability. Indicates the number of exploited vulnerabilities. This means that when an exploited vulnerability appears, the risk value increases rapidly, and 30 points are added to the vulnerability risk assessment score. Indicates the number of risk levels of vulnerabilities. Indicates Risk level;
[0041] The vulnerability risk assessment calculation formula is used to perform vulnerability scanning statistics on the industrial control assets to be assessed according to the risk level of the vulnerabilities to obtain a current vulnerability risk assessment score.
[0042] In some embodiments, the weighted aggregation of the evaluation scores according to the preset weight ratio to obtain the total asset risk score corresponding to the industrial control asset to be evaluated, and the risk level of the industrial control asset to be evaluated is determined according to the total asset risk score, including:
[0043] Total asset risk score = first weight Network risk assessment Second weight Port risk assessment The third weight Asset valuation Fourth Weight Alarm risk assessment Fifth Weight Virus risk assessment Sixth weight Vulnerability risk assessment, obtaining the corresponding values of the first weight, the second weight, the third weight, the fourth weight, the fifth weight and the sixth weight according to the preset weight ratio, and the risk level includes five levels: lowest, low, medium, high and highest.
[0044] In some embodiments, a dynamic assessment step is also included, including that after collecting data on opening and closing ports, fixing vulnerabilities or antivirus, the scores of industrial control assets will be automatically re-evaluated to obtain the latest total asset risk score and corresponding risk level.
[0045] In the second aspect, the present application proposes a network asset risk assessment device in an industrial control environment, including an asset retrieval module, an asset assessment module and a risk determination module;
[0046] The asset retrieval module is used to use the industrial control asset retrieval engine to retrieve the industrial control assets in the current industrial control environment to obtain the industrial control assets to be evaluated;
[0047] The asset assessment module is used to perform network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtain corresponding assessment scores;
[0048] The risk determination module is used to perform weighted aggregation on each evaluation score according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and determine the risk level of the industrial control asset to be evaluated according to the total asset risk score.
[0049] In a third aspect, the present application proposes an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0050] In a fourth aspect, the present application proposes a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0051] Beneficial effects of the present invention:
[0052] This solution has diversified data reference sources and assessment dimensions. By conducting network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on assets, the accuracy of the assessment is improved. It is more suitable for industrial control scenarios and assessments in non-network environments. Dynamic assessments can be performed to ensure the accuracy and real-time nature of risk values. When changes occur, the assessment will be automatically triggered. In addition, in the security field, frequent comprehensive assessments will increase the probability of false alarms. This solution can automatically assess except for the first comprehensive assessment, reduce system pressure, avoid assessing all assets every time, and reduce system pressure and false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 It is the overall flow chart of the present invention.
[0054] Figure 2 It is a system principle block diagram of the present invention.
[0055] Figure 3 This is the function trend diagram when all ports are risk ports.
[0056] Figure 4 This is the function trend diagram when the coefficient is 2.5.
[0057] Figure 5 This is the function trend diagram when all ports are general ports.
[0058] Figure 6 This is a trend chart when an exploited vulnerability appears.
[0059] Figure 7 It is a device module diagram of the present invention. DETAILED DESCRIPTION
[0060] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein; on the contrary, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.
[0061] In a first aspect, the present application proposes a network asset risk assessment method in an industrial control environment, comprising the following steps:
[0062] S100: Using an industrial control asset search engine to search for industrial control assets in the current industrial control environment, and obtaining industrial control assets to be evaluated;
[0063] S200: Performing network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtaining corresponding assessment scores;
[0064] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the network risk assessment includes:
[0065] Step 1: Analyze the network data received by the industrial control host to determine whether the industrial control asset to be evaluated has reported network information. If not, proceed to step 2. If network information is reported, further determine whether the network information is unknown. If so, proceed to step 2. If not, the reported network information shall prevail. The reported network information includes an intranet or a public network.
[0066] Step 2: Analyze the access relationship of the industrial control asset to be evaluated. If there is an access relationship with the industrial control asset to be evaluated, proceed to step 2.1; if there is no access relationship, proceed to step 2.2;
[0067] Step 2.1: Determine whether the srcIp of the access to the industrial control asset to be evaluated belongs to the local area network address segment library. If not, determine that the access is to the external network; if so, determine that the access is to the internal network;
[0068] Step 2.2: Analyze whether the address of the industrial control asset to be evaluated belongs to the local area network address segment library. If not, it is determined that the industrial control asset to be evaluated belongs to an unknown network. If yes, it is determined that the industrial control asset to be evaluated belongs to an intranet network.
[0069] Step 3: When it is determined that any one of the network information, access relationship or address of the industrial control asset to be evaluated is an external network, a first network risk assessment score is obtained; when it is an internal network, a second network risk assessment score is obtained; when it is an unknown network, a third network risk assessment score is obtained; and the current network risk assessment score is obtained based on the first network risk assessment score, the second network risk assessment score or the third network risk assessment score.
[0070] Among them, asset risk is closely related to the network. The higher the degree of network openness, the higher the asset risk.
[0071] Network type identification comes from three aspects of data:
[0072] 1. If the device or network uses a private IP address (such as 10.xxx, 172.16.xx to 172.31.xx, 192.168.xx), establish a LAN address segment. If so, it is preliminarily identified as an intranet address;
[0073] 2. Obtain data based on the data reported by the host software. If the network type is not reported, it will default to an unknown network.
[0074] Check the access relationship of the asset. If the srcIp addresses accessing the asset all belong to the LAN address segment, they are considered to be intranet addresses. If there are addresses that do not belong to the LAN, they may be accessed from the external network and belong to the public network.
[0075] The risk value description of the current network risk assessment score is shown in Table 1:
[0076] Table 1
[0077] network Value at Risk illustrate Unknown 5 Unknown network (not sure whether it is in the intranet or the public network) Intranet (private) 5 The asset is in the intranet and cannot be accessed from the public network. Public 20 The device is on the public network and can be accessed by the public network
[0078] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the port risk assessment includes:
[0079] Acquire the port information of the industrial control asset to be evaluated, and determine the number of open ports according to the port information, wherein the open ports include general ports and risk ports, and the number of risk ports is set according to the evaluation requirements of the industrial control asset to be evaluated, and each general port is provided with a general port score value, and each risk port is provided with a risk port score value;
[0080] The port risk assessment algorithm is expressed as:
[0081]
[0082]
[0083] in, Indicates the total score of open ports. Indicates the total score of the scanned open ports. Indicates the number of risky ports, Indicates the number of general ports. It indicates the average value of the port score, which can reflect the proportion of risky ports. If the value is 5, it means that all ports are risky ports. If it is 1, it means that all ports are normal ports. Indicates the influence coefficient. The larger the coefficient, the slower the impact of quantity on the result. Conversely, the smaller the coefficient, the more obvious the impact of quantity on the result. If all ports are general ports, the risk value will not change much as the number of ports increases. If all ports are risk ports, the risk value will change greatly as the number of ports increases. Indicates the number of ports scanned;
[0084] The current port risk assessment score is calculated according to the port risk assessment algorithm.
[0085] Furthermore, there is a complete set of port descriptions in this solution, and the data sources of the ports include three aspects:
[0086] 1. Nmap scan, scan the open ports of assets.
[0087] 2. Host software reporting.
[0088] 3. Data collection.
[0089] Open ports are divided into general ports and risk ports. Risk ports can be dynamically configured according to user needs, as shown in Table 2:
[0090] Table 2
[0091] port effect tcp 20,21 FTP (File Transfer Protocol) TCP 22 SSH (Secure Shell Protocol) TCP 23 Telnet (Remote Terminal Protocol) TCP 25 SMTP (Simple Mail Transfer Protocol) TCP / UDP 53 DNS (Domain Name System) TCP / UDP 69 TFTP (Trivial File Transfer Protocol) tcp 80-89,443,8440-8450,8080-8089 Various commonly used Web service ports TCP 110 POP3 (Post Office Protocol version 3) tcp 111,2049 NFS (Network File System) TCP 137,139,445 SMB (NETBIOS protocol) TCP 143 IMAP (IMAP) udp 161 SNMP (Simple Network Management Protocol) TCP 389 LDAP (Lightweight Directory Access Protocol) TCP 512,513,514 Linux rexec (remote login) TCP 873 Rsync (data mirroring backup tool) TCP 1194 OpenVPN (Virtual Private Tunnel) TCP 1352 Lotus (Lotus software) TCP 1433 SQL Server (database management system) TCP 1521 Oracle tcp 1500 ISPmanager (hosting control panel) TCP 1723 PPTP (Point-to-Point Tunneling Protocol) tcp 2082,2083 cPanel (virtual machine control system) TCP 2181 ZooKeeper (a reliable coordination system for distributed systems) tcp 2601,2604 Zebra (zebra routing) TCP 3128 Squid (Proxy Cache Server) tcp 3312,3311 kangle (web server) TCP 3306 MySQL (Database) TCP 3389 Windows rdp (Desktop Protocol) TCP 3690 SVN (open source version control system) TCP 4848 GlassFish (Application Server) tcp 5000 Sybase / DB2 (Database) TCP 5432 PostgreSQL (Database) tcp 5900,5901,5902 VNC (Virtual Network Console, Remote Control) TCP 5984 CouchDB (Database) TCP 6379 Redis (Database) tcp 7001,7002 WebLogic (WEB application system) TCP 7778 Kloxo (virtual host management system) tcp 8000 Ajenti (Linux Server Management Panel) TCP 8443 Plesk (web hosting management panel) tcp 8069 Zabbix (system network monitoring) tcp 8080-8089 Jenkins, JBoss (application server) tcp 9080-9081,9090 WebSphere (Application Server) tcp 9200,9300 ElasticSearch (Lucene search server) tcp 11211 Memcached (caching system) tcp 27017,27018 MongoDB (Database) tcp 50070,50030 Hadoop (distributed file system) TCP 1099 rmiregistry TCP 2375 Docker TCP 4899 radmin TCP 5632 PyAnywhere TCP 8009 ajp13 tcp 9000 fastcgi tcp 9001 Supervisord tcp 10050 zabbix-agent tcp 10051 zabbix-trapper tcp 43958 Ser-U tcp 61616 ActiveMQ
[0092] Among them, when all ports are dangerous, the function trend graph is as follows Figure 3 As shown, when the coefficient is 2.5, the function trend graph is as follows Figure 4 As shown, when all ports are general ports, the function trend graph is as follows Figure 5As shown in the figure, v / x represents the average port score, which can reflect the proportion of risk ports. If the value is 5, it means that all ports are risky, and if it is 1, it means that all ports are general ports. The x / v coefficient, the larger the coefficient, the slower the impact of quantity on the result, and vice versa, the smaller the coefficient, the more obvious the impact of quantity on the result. In other words, if all ports are general ports, the risk value will not change much as the number of ports increases. If all ports are risky, the risk value will change greatly as the number of ports increases.
[0093] Example:
[0094] Assume that the scanned port statistics are as shown in Table 3:
[0095] Table 3
[0096] Port Class quantity Risk Port 3 General Port 10
[0097] Calculate the current port risk assessment score as:
[0098]
[0099] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the asset value assessment includes:
[0100] Confirm the asset type of the industrial control asset to be evaluated, confirm the application type that needs to be installed based on the asset type, preset the corresponding asset type score and application type score based on the asset type and the application type, add the asset type score and the application type score to obtain the current asset value evaluation score, preset a limit value for the current asset value evaluation score, and when the current asset value evaluation score reaches the limit value, the current asset value evaluation score is the limit value.
[0101] Among them, as shown in Table 4 and Table 5:
[0102] Table 4
[0103] Asset Type Points Industrial control equipment 2 Video surveillance equipment 1 Network communication equipment 1 Safety protection equipment 2 server 2 workstation 2
[0104] Table 5
[0105] application Points database 1 app 1 mail 1 Print 1 ...... 1
[0106] In the actual scoring process, it is necessary to confirm the type of asset, such as industrial control equipment assets, network communication equipment assets, etc. Then it is necessary to confirm the type of application installed in the asset, such as installing a database as a data storage asset, installing a print driver as a print server asset, installing a mail service as a mail server asset, etc. Of course, some assets may have multiple applications installed at the same time, so the total risk value of the application can be obtained by adding up the scores of different applications, and then adding the value of the asset importance to obtain the asset value score. The asset application and the asset importance each account for half of the score.
[0107] Rating example:
[0108] Assume that an asset is an industrial control equipment asset (2 points), and a MySQL database (1 point) and an industrial control application platform (1 point) are installed in it. The score calculation formula based on the respective settings is as follows:
[0109]
[0110] min(2+1+1,5)=4 points
[0111] The application score does not increase infinitely. When the score exceeds the total score limit of 5, it will no longer increase and the application score will be limited to 5.
[0112] Importance calculation score:
[0113] Within a certain period, such as the week before the assessment, estimate the importance of assets based on the number of logs generated, the number of access devices, the number of times devices are accessed, the number of times accessed, and the number of devices accessed.
[0114]
[0115] like:
[0116]
[0117] c: Number of logs generated;
[0118] l: The number of logs that should be generated for general communication;
[0119] c1: number of times the device is accessed;
[0120] N1: number of access devices;
[0121] c2: number of visits;
[0122] N2: number of devices accessed;
[0123] The score of the asset type is added to the score of the application list. If the result is greater than 10, the score is calculated as 10.
[0124] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the alarm risk assessment includes:
[0125] The alarm risk assessment calculation formula is expressed as:
[0126]
[0127] in, Indicates the number of alarm levels. Indicates the alarm level value. Indicates that the alarm level is converted to a higher level with a larger value. Indicates the alarm level. Indicates the alarm severity level.
[0128] The alarm risk assessment calculation formula is used to perform alarm statistics on the industrial control assets to be assessed to obtain a current alarm risk assessment score.
[0129] Example:
[0130] The statistical results obtained after alarm statistics for a certain asset are shown in Table 6 below:
[0131] Table 6
[0132] Alarm level Number of alarms 0-Important warning 1 1-Major alarm 2 2-Minor alarm 1 3- Prompt warning 2
[0133] Calculate the alarm score formula:
[0134]
[0135] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the virus risk assessment includes:
[0136] The virus risk assessment calculation formula is expressed as:
[0137]
[0138] in, Indicates the severity level of the virus, which must be a continuous positive integer. Indicates the severity level of the virus. Indicates the index of a specific virus. Indicates the total number of viruses;
[0139] The virus risk assessment calculation formula is used to perform virus severity statistics on the industrial control assets to be assessed according to the severity level of the virus to obtain a current virus risk assessment score.
[0140] Example:
[0141] Assuming that the severity levels of viruses are from low to high as 1 < 2 < 3 < 4 < 5, the list of scanned viruses is shown in Table 7 below:
[0142] Table 7
[0143] Virus Severity Virus 1 1 Virus 2 2 Virus 3 3 Virus 4 4 Virus 5 5
[0144] Calculate the viral score:
[0145]
[0146] In some embodiments, the industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, and the vulnerability risk assessment includes:
[0147] The vulnerability risk assessment calculation formula is expressed as:
[0148]
[0149] in, Indicates the risk level of the vulnerability; Indicates the risk level value of the vulnerability. Indicates the number of exploited vulnerabilities. This means that when an exploited vulnerability appears, the risk value increases rapidly, and 30 points are added to the vulnerability risk assessment score. Indicates the number of risk levels of vulnerabilities. Indicates Risk level;
[0150] The vulnerability risk assessment calculation formula is used to perform vulnerability scanning statistics on the industrial control assets to be assessed according to the risk level of the vulnerabilities to obtain a current vulnerability risk assessment score.
[0151] Example:
[0152] Assume that the results of a vulnerability scan are shown in Table 8 below:
[0153] Table 8
[0154] Vulnerabilities Risk Level Vulnerability 1 1 Vulnerability 2 2 Vulnerability 3 0 Vulnerability 4 3 Vulnerability 5 3
[0155] When an exploit occurs, the trend is as follows Figure 6As shown in the figure, when there is an exploited vulnerability, the risk value will increase rapidly, and it can be increased by 30 points on the basis of 20%, and the number of exploited vulnerabilities is 0. At this time, the calculation formula is:
[0156]
[0157] If the number of these vulnerabilities exploited is 2, the risk value will increase significantly, and the calculation formula is:
[0158]
[0159] S300: performing weighted aggregation on each evaluation score according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and determining the risk level of the industrial control asset to be evaluated according to the total asset risk score.
[0160] In some embodiments, the weighted aggregation of the evaluation scores according to the preset weight ratio to obtain the total asset risk score corresponding to the industrial control asset to be evaluated, and the risk level of the industrial control asset to be evaluated is determined according to the total asset risk score, including:
[0161] Total asset risk score = first weight Network risk assessment Second weight Port risk assessment The third weight Asset valuation Fourth Weight Alarm risk assessment Fifth Weight Virus risk assessment Sixth weight Vulnerability risk assessment, obtaining the corresponding values of the first weight, the second weight, the third weight, the fourth weight, the fifth weight and the sixth weight according to the preset weight ratio, and the risk level includes five levels: lowest, low, medium, high and highest.
[0162] In this embodiment, the first weight accounts for 20%, the second weight accounts for 20%, the third weight accounts for 10%, the fourth weight accounts for 10%, the fifth weight accounts for 20%, and the sixth weight accounts for 20%. The mapping relationship between asset risk value and risk level is shown in Table 9 below:
[0163] Table 9
[0164] Risk Level Value at Risk Logo color describe 5 80~100 Very high red Once it happens, it will have very serious economic or social impacts, such as serious damage to the organization's reputation, serious impact on the organization's normal operations, heavy economic losses and adverse social impacts. 4 60~80 high orange color Once it occurs, it will have a greater economic or social impact, causing damage to the organization's operations and reputation to a certain extent. 3 40~60 medium yellow Once it happens, it will cause certain economic, social or production and operation impacts, but the scope and extent of the impact will not be large. 2 20~40 Low blue Once it occurs, the impact is relatively low and is generally limited to within the organization and can be quickly resolved through certain means. 1 0~20 Very low green Once it occurs, the impact is almost non-existent and can be compensated by simple measures.
[0165] In some embodiments, a dynamic assessment step is also included, including that after collecting data on opening and closing ports, fixing vulnerabilities or antivirus, the scores of industrial control assets will be automatically re-evaluated to obtain the latest total asset risk score and corresponding risk level.
[0166] In the second aspect, the present application proposes a network asset risk assessment device in an industrial control environment, including an asset retrieval module, an asset assessment module and a risk determination module;
[0167] The asset retrieval module is used to use the industrial control asset retrieval engine to retrieve the industrial control assets in the current industrial control environment to obtain the industrial control assets to be evaluated;
[0168] The asset assessment module is used to perform network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtain corresponding assessment scores;
[0169] The risk determination module is used to perform weighted aggregation on each evaluation score according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and determine the risk level of the industrial control asset to be evaluated according to the total asset risk score.
[0170] In a third aspect, the present application proposes an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0171] In a fourth aspect, the present application proposes a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0172] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0173] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0174] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this disclosure.
[0175] In the embodiments provided in the present disclosure, it should be understood that the disclosed apparatus / computer equipment and methods can be implemented in other ways. For example, the apparatus / computer equipment embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. Multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection of the apparatus or unit, which may be electrical, mechanical or other forms.
[0176] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0177] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0178] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present disclosure implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. The computer program may include computer program code, and the computer program code may be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electric carrier signals and telecommunication signals.
[0179] The above are only preferred implementations of the present invention. It should be pointed out that a number of modifications and improved technical solutions made by those skilled in the art without departing from the technical solution should also be deemed to fall within the scope of protection required by the claims.
Claims
1. A network asset risk assessment method in an industrial control environment, characterized by: The following steps are involved: Use the industrial control asset search engine to search for industrial control assets in the current industrial control environment to obtain the industrial control assets to be evaluated; Conducting network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtaining corresponding assessment scores; The various evaluation scores are weighted and summarized according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and the risk level of the industrial control asset to be evaluated is determined according to the total asset risk score.
2. The method according to claim 1, characterized in that: The network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment are performed on the industrial control assets to be assessed to obtain corresponding assessment scores. The network risk assessment includes: Step 1: Analyze the network data received by the industrial control host to determine whether the industrial control asset to be evaluated has reported network information. If not, proceed to step 2. If network information is reported, further determine whether the network information is unknown. If so, proceed to step 2. If not, the reported network information shall prevail. The reported network information includes an intranet or a public network. Step 2: Analyze the access relationship of the industrial control asset to be evaluated. If there is an access relationship with the industrial control asset to be evaluated, proceed to step 2.1; if there is no access relationship, proceed to step 2.2; Step 2.1: Determine whether the srcIp of the access to the industrial control asset to be evaluated belongs to the local area network address segment library. If not, determine that the access is to the external network; if so, determine that the access is to the internal network; Step 2.2: Analyze whether the address of the industrial control asset to be evaluated belongs to the local area network address segment library. If not, it is determined that the industrial control asset to be evaluated belongs to an unknown network. If yes, it is determined that the industrial control asset to be evaluated belongs to an intranet network. Step 3: When it is determined that any one of the network information, access relationship or address of the industrial control asset to be evaluated is an external network, a first network risk assessment score is obtained; when it is an internal network, a second network risk assessment score is obtained; when it is an unknown network, a third network risk assessment score is obtained; and the current network risk assessment score is obtained based on the first network risk assessment score, the second network risk assessment score or the third network risk assessment score.
3. The method according to claim 2, characterized in that: The industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the port risk assessment includes: Acquire the port information of the industrial control asset to be evaluated, and determine the number of open ports according to the port information, wherein the open ports include general ports and risk ports, and the number of risk ports is set according to the evaluation requirements of the industrial control asset to be evaluated, and each general port is provided with a general port score value, and each risk port is provided with a risk port score value; The port risk assessment algorithm is expressed as: in, Indicates the total score of open ports. Indicates the total score of the scanned open ports. Indicates the number of risky ports, Indicates the number of general ports. It indicates the average value of the port score, which can reflect the proportion of risky ports. If the value is 5, it means that all ports are risky ports. If it is 1, it means that all ports are normal ports. Indicates the influence coefficient. The larger the coefficient, the slower the impact of quantity on the result. Conversely, the smaller the coefficient, the more obvious the impact of quantity on the result. If all ports are general ports, the risk value will not change much as the number of ports increases. If all ports are risk ports, the risk value will change greatly as the number of ports increases. Indicates the number of ports scanned; The current port risk assessment score is calculated according to the port risk assessment algorithm.
4. The method according to claim 3, characterized in that: The industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores. The asset value assessment includes: Confirm the asset type of the industrial control asset to be evaluated, confirm the application type that needs to be installed based on the asset type, preset the corresponding asset type score and application type score based on the asset type and the application type, add the asset type score and the application type score to obtain the current asset value evaluation score, preset a limit value for the current asset value evaluation score, and when the current asset value evaluation score reaches the limit value, the current asset value evaluation score is the limit value.
5. The method according to claim 4, characterized in that: The industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the alarm risk assessment includes: The alarm risk assessment calculation formula is expressed as: in, Indicates the number of alarm levels. Indicates the alarm level value. Indicates that the alarm level is converted to a higher level with a larger value. Indicates the alarm level. Represents the alarm level number; the alarm statistics of the industrial control assets to be evaluated are performed using the alarm risk assessment calculation formula to obtain the current alarm risk assessment score.
6. The method according to claim 5, characterized in that: The industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the virus risk assessment includes: The virus risk assessment calculation formula is expressed as: in, Indicates the severity level of the virus, which must be a continuous positive integer. Indicates the severity level of the virus. Indicates the index of a specific virus. Indicates the total number of viruses; The virus risk assessment calculation formula is used to perform virus severity statistics on the industrial control assets to be assessed according to the severity level of the virus to obtain a current virus risk assessment score.
7. The method according to claim 6, characterized in that: The industrial control assets to be evaluated are respectively subjected to network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment to obtain corresponding assessment scores, wherein the vulnerability risk assessment includes: The vulnerability risk assessment calculation formula is expressed as: in, Indicates the risk level of the vulnerability; Indicates the risk level value of the vulnerability. Indicates the number of exploited vulnerabilities. This means that when an exploited vulnerability appears, the risk value increases rapidly, and 30 points are added to the vulnerability risk assessment score. Indicates the number of risk levels of vulnerabilities. Indicates Risk level; The vulnerability risk assessment calculation formula is used to perform vulnerability scanning statistics on the industrial control assets to be assessed according to the risk level of the vulnerabilities to obtain a current vulnerability risk assessment score.
8. The method according to claim 1, characterized in that: The step of weighting and aggregating the evaluation scores according to the preset weight ratio to obtain the total asset risk score corresponding to the industrial control asset to be evaluated, and judging the risk level of the industrial control asset to be evaluated according to the total asset risk score includes: Total asset risk score = first weight Network risk assessment Second weight Port risk assessment The third weight Asset valuation Fourth Weight Alarm risk assessment Fifth Weight Virus risk assessment Sixth weight Vulnerability risk assessment, obtaining the corresponding values of the first weight, the second weight, the third weight, the fourth weight, the fifth weight and the sixth weight according to the preset weight ratio, and the risk level includes five levels: lowest, low, medium, high and highest.
9. The method according to claim 8, characterized in that: It also includes a dynamic assessment step, including that when data on opening and closing ports, fixing vulnerabilities or performing antivirus operations is collected, the scores of industrial control assets will be automatically reassessed to obtain the latest total asset risk score and corresponding risk level.
10. A network asset risk assessment device in an industrial control environment, characterized in that: It includes asset retrieval module, asset assessment module and risk determination module; The asset retrieval module is used to use the industrial control asset retrieval engine to retrieve the industrial control assets in the current industrial control environment to obtain the industrial control assets to be evaluated; The asset assessment module is used to perform network risk assessment, port risk assessment, asset value assessment, alarm risk assessment, virus risk assessment and vulnerability risk assessment on the industrial control assets to be assessed, and obtain corresponding assessment scores; The risk determination module is used to perform weighted aggregation on each evaluation score according to a preset weight ratio to obtain a total asset risk score corresponding to the industrial control asset to be evaluated, and determine the risk level of the industrial control asset to be evaluated according to the total asset risk score.