Network security index assessment method and system
By analyzing vulnerability information and encryption and access control configurations in the network log, combining the response capabilities of simulated threat events, and calculating the network security index, the problem that traditional evaluation methods cannot provide a global perspective is solved, and accurate assessment of the current situation of network security and optimization of security policies are achieved.
Patent Information
- Application Number
- CN202510107824.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional network security assessment methods cannot provide a global perspective and cannot accurately judge the actual effectiveness and synergy of security measures, resulting in incomplete assessment of security status, affecting the formulation and optimization of security policies.
By extracting vulnerability information based on the system network log, analyzing the frequency of vulnerability occurrence and processing response time, calculating processing efficiency, and computing the network security index with encryption configuration, access control and event processing capabilities.
Accurate assessment of the current status of network security is achieved, helping to identify system weaknesses, providing practical guidance for security reinforcement, and evaluating the response capabilities of the security system by simulating threat events, and determining the actual strength and potential weaknesses of the security system.
Smart Images

Figure CN119995966A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security index evaluation method and system. Background Art
[0002] The field of network security technology focuses on protecting computer networks and their components from unauthorized access, abuse, modification or denial of service, including servers, endpoint devices and network communications. It integrates a variety of technologies and practices to ensure the confidentiality, integrity and availability of network data, including encryption, intrusion detection systems, security event management, firewalls and a variety of anti-malware tools, combined with advanced persistent threats, network threat intelligence collection and processing, to enhance security protection capabilities, ensure the confidentiality, integrity and availability of information, and respond to increasingly complex and intelligent network attacks.
[0003] Among them, the network security index assessment method is used to measure and evaluate the network security level of information systems. Through a variety of tools and quantitative indicators, it evaluates the network security status of an organization, including intrusion detection systems, firewall logs, and vulnerability scanning results, effectively identifies potential security vulnerabilities and threats, and reasonably optimizes and adjusts existing security measures to enhance the network's protection capabilities and improve the overall network security architecture, including system vulnerabilities, configuration errors, and the implementation of security policies, helping management to formulate targeted and effective security strategies and improve the network's security management level.
[0004] Traditional network security assessment methods cannot provide a global perspective when comprehensively evaluating the overall network security level, and cannot provide sufficient data support when evaluating the implementation effect of security measures, resulting in the security team being unable to accurately judge the actual effectiveness and synergy of various measures. When managing security incidents, there is a lack of continuous tracking of event processing time and vulnerability repair efficiency, which makes the security status assessment incomplete, affects the formulation and optimization of security strategies, and cannot effectively identify and strengthen the weak links in the security system, showing inadequacies when dealing with complex network threats. Summary of the invention
[0005] In order to solve the technical problem that it is difficult to judge the network security level in the prior art, the embodiment of the present invention provides a network security index evaluation method and system. The technical solution is as follows:
[0006] In one aspect, a network security index evaluation method is provided, the method comprising:
[0007] S1: Based on the system network log, extract the identified vulnerability information, analyze the occurrence frequency and processing response time of various security vulnerabilities, calculate the processing efficiency, and generate vulnerability processing efficiency information;
[0008] S2: Based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, analyzing the effectiveness of the data encryption configuration, and evaluating whether the implementation of the encryption strategy complies with the security standards, generating encryption capability evaluation information;
[0009] S3: Based on the encryption capability assessment information, by analyzing access permission settings and audit tracking records, assessing the applicability and execution consistency of role access control, verifying the effectiveness of access control, and generating access control capability information;
[0010] S4: Based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the system's response process and time, evaluating the response capability of security incidents, and generating an incident handling capability score;
[0011] S5: Based on the incident handling capability score, combined with vulnerability handling capability, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, the security index of the target network security system is calculated, and a network security index is generated.
[0012] As a further solution of the present invention, the vulnerability processing efficiency information includes vulnerability occurrence frequency, processing efficiency information, and vulnerability closure time; the encryption capability assessment information specifically includes the implementation of data encryption, the security of key management, and the effectiveness of encryption configuration; the access control capability information includes access permission settings, audit tracking records, and the effectiveness of role access control; the event processing capability score specifically refers to security threat simulation analysis results, response process records, and security incident response capabilities; the network security index includes indicator weight matching records, index calculation results, and the importance of multiple indicators.
[0013] As a further solution of the present invention, based on the system network log, the steps of extracting the identified vulnerability information, analyzing the occurrence frequency and processing response time of various security vulnerabilities, calculating the processing efficiency, and generating the vulnerability processing efficiency information are specifically as follows:
[0014] S101: extracting identified vulnerability information based on the system network log, recording event timestamps, event types, and processing results, and generating a vulnerability processing information set;
[0015] S102: Based on the event processing information set, analyzing the occurrence frequencies of various types of vulnerabilities, calculating the average response time of the vulnerabilities, and generating a response time analysis result;
[0016] S103: Based on the response time analysis result, the target network security system is evaluated for system vulnerability processing efficiency, and vulnerability processing efficiency information is generated.
[0017] As a further solution of the present invention, the specific formula for evaluating the target network security system's efficiency in handling system vulnerabilities is:
[0018]
[0019] Among them, E represents the calculated vulnerability processing efficiency, w i represents the severity weight of the i-th vulnerability, t i represents the actual processing time of the i-th type of vulnerability, s i is the occurrence frequency of the i-th vulnerability, and i is the index of the vulnerability category.
[0020] As a further solution of the present invention, based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, the effectiveness of the data encryption configuration is analyzed, and whether the implementation of the encryption strategy meets the security standards is evaluated. The steps of generating encryption capability evaluation information are specifically as follows:
[0021] S201: Based on the vulnerability processing efficiency information, check the log records of data encryption implementation, analyze the use of encryption algorithms and the logs of key generation, update and destruction, and generate encryption log analysis results;
[0022] S202: Based on the encryption log analysis result, the security of key management is evaluated by analyzing whether the key length, complexity, and replacement frequency meet industry security standards, and a security evaluation result is generated;
[0023] S203: Based on the security assessment result, the validity of the data encryption configuration of the target network security system is assessed, and encryption capability assessment information is generated.
[0024] As a further solution of the present invention, based on the encryption capability evaluation information, by analyzing the access permission settings and audit tracking records, evaluating the applicability and execution consistency of the role access control, and verifying the effectiveness of the access control, the steps of generating the access control capability information are specifically as follows:
[0025] S301: Analyze access permission settings based on the encryption capability assessment information, analyze the rationality of permission allocation by comparing the access permissions and role responsibility information of multiple roles, and generate permission setting review results;
[0026] S302: Based on the permission setting audit result, the audit tracking record is analyzed, the access control log is checked, and the consistency analysis result is generated by comparing the consistency between the actual access control log and the preset access rights;
[0027] S303: Based on the consistency analysis result, by analyzing the detection and response capabilities of the access control settings to unauthorized access, the effectiveness of the access control configuration is evaluated to generate access control capability information.
[0028] As a further solution of the present invention, based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the reaction process and time of the system, evaluating the response capability of security incidents, and generating the event handling capability score are specifically as follows:
[0029] S401: Based on the access control capability information, simulate network security threats, including simulated attacks and system intrusion attempts, detect and analyze the monitoring and alarm mechanisms of the target network security system, and generate threat simulation test results;
[0030] S402: Based on the threat simulation test results, analyze the response process of the target network security system to the simulated threat, record the system's alarm response time and processing measures, and generate a response efficiency analysis result;
[0031] S403: Based on the response efficiency analysis result, by analyzing the detection capability, response time, and processing results of the target network security system for security incidents, the system's processing capability for security incidents is evaluated, and an incident processing capability score is generated.
[0032] As a further solution of the present invention, the specific formula for evaluating the processing capability of the evaluation system for security events is:
[0033]
[0034] R is the event handling capability score, D is the detection capability score, T is the response time score, P is the processing result score, and W is the event handling capability score. D is the weight of detection capability, W T is the weight of response time, W P is the weight of the processing result.
[0035] As a further solution of the present invention, based on the event handling capability score, combined with vulnerability handling capability, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, and the security index of the target network security system is calculated. The steps of generating the network security index are specifically as follows:
[0036] S501: Based on the event handling capability score, extract multiple indicator information of the target network security system, including vulnerability handling time, encryption strength, access control capability, and security incident response capability, analyze the impact of multiple indicators on security protection capability, and generate indicator impact analysis results;
[0037] S502: Based on the indicator impact analysis result, weights are matched for the multiple indicators according to their contribution to system security, and a weight allocation list is generated;
[0038] S503: Using the weight distribution list, calculate the security index of the target network security system, evaluate the security status of the network, and generate a network security index.
[0039] On the other hand, a network security index evaluation system is provided, which is applied to the network security index evaluation method, and the system includes:
[0040] The system information extraction module extracts the identified vulnerability information based on the system network log, records the vulnerability type and occurrence time, and generates an identified vulnerability data set;
[0041] The processing capability analysis module calculates the processing time and response speed of the target network security system to multiple vulnerabilities based on the identified vulnerability data set, evaluates the vulnerability processing efficiency, and generates vulnerability processing efficiency information;
[0042] The encryption configuration analysis module analyzes the implementation of data encryption and the security of key management based on the vulnerability processing efficiency information, evaluates the effectiveness of the data encryption configuration of the target network security system, and generates encryption capability evaluation information;
[0043] The access setting evaluation module analyzes access permission settings and audit trail records based on the encryption capability evaluation information, evaluates the applicability and consistency of access control settings, and generates access control capability information;
[0044] The response simulation test module simulates various network security threats based on the access control capability information, analyzes and records the system's response process, evaluates the system's response capability to security incidents, and generates an incident handling capability score;
[0045] The security level calculation module assigns weights to various indicators of the target network security system based on the event handling capability score and according to the importance and impact, calculates the security index, and generates a network security index.
[0046] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0047] By evaluating the efficiency of vulnerability handling, analyzing the implementation of data encryption and the security of key management, and verifying the consistency of access rights, the effectiveness of multiple security measures is evaluated to help reveal system weaknesses, provide practical guidance for security reinforcement, and achieve an accurate assessment of the current state of network security. By simulating threat events, the response capabilities of security systems to network threats are evaluated, and the actual strength and potential weaknesses of the security system are determined. By aggregating different security indicators into a comprehensive security index, a basis is provided for management decision-making, enabling security policy adjustments based on actual data. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0049] Figure 1 It is a schematic diagram of the workflow of the present invention;
[0050] Figure 2 This is a detailed flow chart of S1 of the present invention;
[0051] Figure 3 This is a detailed flow chart of S2 of the present invention;
[0052] Figure 4 This is a detailed flow chart of S3 of the present invention;
[0053] Figure 5 This is a detailed flow chart of S4 of the present invention;
[0054] Figure 6 This is a detailed flow chart of S5 of the present invention;
[0055] Figure 7 It is a system flow chart of the present invention. DETAILED DESCRIPTION
[0056] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0057] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "example" in the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present the concept in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or it can be either of the two.
[0058] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same. "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same.
[0059] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.
[0060] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0061] The embodiment of the present invention provides a network security index evaluation method, such as Figure 1 The process flow of the network security index evaluation method shown in the figure may include the following steps:
[0062] S1: Based on the system network log, extract the identified vulnerability information, analyze the occurrence frequency and processing response time of various security vulnerabilities, calculate the processing efficiency, and generate vulnerability processing efficiency information;
[0063] S2: Based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, the effectiveness of data encryption configuration is analyzed, and whether the implementation of encryption strategy meets the security standards is evaluated to generate encryption capability evaluation information;
[0064] S3: Based on the encryption capability assessment information, by analyzing the access permission settings and audit tracking records, evaluate the applicability and execution consistency of role access control, verify the effectiveness of access control, and generate access control capability information;
[0065] S4: Based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the system's response process and time, evaluating the response capability of security incidents, and generating an incident handling capability score;
[0066] S5: Based on the incident handling capability score, combined with vulnerability handling capabilities, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, the security index of the target network security system is calculated, and a network security index is generated.
[0067] Vulnerability handling efficiency information includes vulnerability occurrence frequency, handling efficiency information, and vulnerability closure time. Encryption capability assessment information specifically includes the implementation of data encryption, the security of key management, and the effectiveness of encryption configuration. Access control capability information includes access permission settings, audit tracking records, and the effectiveness of role access control. The event handling capability score specifically refers to security threat simulation analysis results, response process records, and security incident response capabilities. The network security index includes indicator weight matching records, index calculation results, and the importance of multiple indicators.
[0068] See also Figure 2 ,Based on the system network log, extract the identified vulnerability information, analyze the occurrence frequency and processing response time of various security vulnerabilities, calculate the processing efficiency, and generate the vulnerability processing efficiency information in the following steps:
[0069] S101: Based on the system network log, extract the identified vulnerability information, record the event timestamp, event type and processing result, and generate a vulnerability processing information set:
[0070] In sub-step S101, an automated keyword search is performed to identify events related to security vulnerabilities. Records containing "vulnerability detection" and "vulnerability repair" are searched for, and the timestamp, event type and processing results of each event are recorded in detail. Through the log management system, the target events are automatically marked and classified. Each event stores detailed information including event description and processing measures. The target data is sorted and stored in the vulnerability processing information set. The process includes data formatting and data cleaning to ensure the accuracy and ease of processing of the recorded data, providing detailed data support for the network security team to facilitate their tracking and analysis of the processing details and efficiency of each vulnerability.
[0071] S102: Based on the event processing information set, analyze the occurrence frequency of various types of vulnerabilities, calculate the average response time of the vulnerabilities, and generate response time analysis results:
[0072] In sub-step S102, the average response time and frequency of occurrence of different types of vulnerabilities are calculated. The time period from discovery to completion of processing of each vulnerability type is statistically analyzed through time series analysis tools, and the average processing time is calculated. The analysis involves extracting time data from a large amount of event data, and using statistical software to perform data aggregation and calculation operations to ensure that the average response time of each vulnerability is accurately reflected. The tool quantifies the frequency of vulnerability occurrence and counts the number of times each type of vulnerability occurs within a certain period of time. The target data helps the network security team to optimize security strategies in a targeted manner and improve the overall efficiency of network security defense.
[0073] S103: Based on the response time analysis result, the target network security system is evaluated for its efficiency in handling system vulnerabilities, and vulnerability handling efficiency information is generated:
[0074] The specific formula for evaluating the target network security system's efficiency in dealing with system vulnerabilities is:
[0075]
[0076] Among them, E represents the calculated vulnerability processing efficiency, w i represents the severity weight of the i-th vulnerability, t i represents the actual processing time of the i-th type of vulnerability, s i is the occurrence frequency of the i-th vulnerability, and i is the index of the vulnerability category.
[0077] formula:
[0078]
[0079] Detailed explanation of the formula and the process of formula calculation and derivation:
[0080] This formula is used to calculate the comprehensive processing efficiency of various vulnerabilities in the network security system, taking into account the severity weight, processing time and frequency of occurrence of the vulnerability. The results are used to evaluate the overall vulnerability response performance;
[0081] Parameter meaning and setting value:
[0082] w i is the severity weight of the i-th vulnerability, t i is the processing time of the i-th type of vulnerability, s i is the occurrence frequency of the i-th type of vulnerability. Assuming there are three types of vulnerabilities in the system, w1=0.8, t1=5, s1=20, w2=0.5, t2=3, s2=50, w3=0.2, t3=1, s3=100;
[0083] Substitute the parameters into the formula for calculation:
[0084]
[0085] The result 0.517 indicates that the system's overall efficiency score in handling vulnerabilities is 0.517, reflecting the average processing speed after considering the severity and frequency of vulnerabilities.
[0086] See also Figure 3 ,Based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, the effectiveness of data encryption configuration is analyzed, and whether the implementation of encryption strategy meets the security standards is evaluated. The specific steps for generating encryption capability evaluation information are as follows:
[0087] S201: Based on the vulnerability processing efficiency information, check the log records of data encryption implementation, analyze the encryption algorithm usage and key generation, update and destruction logs, and generate encryption log analysis results:
[0088] In sub-step S201, a data log analysis system is used to index and classify application instances of encryption algorithms and record all relevant encryption operations, including key generation, updating and destruction. The log analysis results reflect the frequency of use and management of various encryption algorithms in actual operations, providing detailed basic data for further analysis. The system will automatically extract and compile relevant information from the log, such as the encryption algorithm type, timestamp of key usage, and key life cycle status, to ensure that each piece of data accurately represents the specific circumstances of the encryption activity. By setting key performance indicators, the efficiency and security of algorithm execution are evaluated to ensure that the encryption log analysis results can directly support subsequent security assessments.
[0089] S202: Based on the results of the encryption log analysis, the security of key management is evaluated by analyzing whether the key length, complexity, and replacement frequency meet industry security standards, and a security assessment result is generated:
[0090] In sub-step S202, a security assessment of key management is performed. Based on the key log analysis results, the key length, key complexity, and change frequency f in the key log are extracted and calculated by formula Computational key management security;
[0091] In the formula, S represents the comprehensive security score of key management, l represents the length of the key, C represents the complexity of the key, f represents the frequency of key replacement, and w l and w C Represent the weight factors of key length and key complexity respectively;
[0092] Detailed explanation of the formula and the process of formula calculation and derivation:
[0093] Assume the key length weight w l =0.6, key complexity weight w C =0.4, key length l=128, complexity C=3, replacement frequency f is every 30 days,
[0094] Calculate S:
[0095]
[0096] The results show that under the current key management settings, the security score is 2.6. The value is used to guide whether the key policy needs to be adjusted. By quantitatively analyzing multiple aspects of key management, the security of key management is evaluated to determine whether adjustments are needed.
[0097] S203: Based on the security assessment results, the effectiveness of the target network security system data encryption configuration is assessed, and encryption capability assessment information is generated:
[0098] In sub-step S203, use the configuration analysis tool to check the implementation details of the encryption protocol and key management measures in detail to ensure that each setting complies with the predefined security standards. By analyzing the implementation of encryption algorithms in the system, such as the use of AES and RSA and their configuration parameters, such as key length and encryption mode, ensure that all configurations meet the security compliance requirements. Pay special attention to checking whether the key expiration management and automatic update mechanism can effectively prevent the use of expired keys and enhance the reliability of data protection. Based on this series of inspections and analyses, encryption capability assessment information is generated, which describes whether each indicator of the current encryption configuration meets the standards.
[0099] See also Figure 4 Based on the encryption capability assessment information, the applicability and execution consistency of role-based access control are evaluated by analyzing access permission settings and audit trail records, and the effectiveness of access control is verified. The specific steps for generating access control capability information are as follows:
[0100] S301: Based on the encryption capability assessment information, analyze the access permission settings, compare the access permissions and role responsibilities of multiple roles, analyze the rationality of permission allocation, and generate permission setting review results:
[0101] In sub-step S301, the access permission management system is used to collect and analyze the permission settings of different roles, and compare them with the responsibilities and business needs of each role to ensure that the permission allocation meets the flexibility of business operations and complies with the principle of least privilege, reducing the possibility of internal risks. A role access audit mechanism is introduced to check historical access records and analyze any abuse of permissions or misconfiguration. Anomalies or redundant settings in permission configurations are automatically identified through algorithms, optimization suggestions are made, and permission setting audit results are generated, which show the rationality evaluation and improvement suggestions for each role's permission settings, providing a basis for improving the efficiency and security of the access control system.
[0102] S302: Based on the result of the permission setting audit, the audit tracking record is analyzed, the access control log is checked, and the consistency analysis result is generated by comparing the consistency between the actual access control log and the preset access rights:
[0103] In sub-step S302, use log analysis tools, such as Splunk or LogRhythm, to systematically check and compare access control logs with preset access permission models, analyze users' access time, access type, and access permissions, ensure that actual access activities strictly follow authorization policies, and make detailed abnormal activity reports for any inconsistencies found, including specific instances of inconsistent access and possible security vulnerability prompts. Based on the completeness and accuracy of the access logs, evaluate the maintenance and monitoring efficiency of the access control system, and generate consistency analysis results through target comprehensive analysis. The results indicate the consistency level of the access control logs and any security risks that need attention.
[0104] S303: Based on the consistency analysis result, the effectiveness of the access control configuration is evaluated by analyzing the detection and response capabilities of the access control settings for unauthorized access, and access control capability information is generated:
[0105] In sub-step S303, use access control assessment tools, such as Microsoft ATA, to monitor and analyze unauthorized access attempts, evaluate the effectiveness and timeliness of protective measures, and evaluate the enforcement strength and speed of access control policies in actual threat situations by reviewing the system's response logs in detail, including the blocking of unauthorized access, alarm triggering, and post-processing. Based on the system's response time and processing efficiency for high-risk access, determine the suitability and improvement points of the access control configuration, achieve instant identification of unauthorized access, evaluate the reliability of long-term security strategies and defensive measures, generate access control capability information, and summarize the overall performance of the access control system and improvement suggestions in key areas.
[0106] See also Figure 5 Based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the system's response process and time, and evaluating the response capability of security incidents, the steps for generating the incident handling capability score are as follows:
[0107] S401: Based on the access control capability information, simulate network security threats, including simulated attacks and system intrusion attempts, detect and analyze the monitoring and alarm mechanisms of the target network security system, and generate threat simulation test results:
[0108] In sub-step S401, use network simulation tools, such as GNS3 or EVE-NG, and network intrusion testing tools, such as Metasploit and Nmap, to simulate various network attacks and system intrusion attempts, set the parameters of the simulation environment, including attack type, attack frequency, and preset attack path, execute simulated attacks and monitor the system's response in real time, including the alarm activation of the intrusion detection system, the blocking operation of the firewall, and the log records of the security information and event management system. Through target testing, generate detailed threat simulation test results. The target results record in detail the system's response capability to each simulated attack type and the alarm efficiency of the monitoring system.
[0109] S402: Based on the threat simulation test results, analyze the target network security system's response process to the simulated threat, record the system's alarm response time and processing measures, and generate response efficiency analysis results:
[0110] In sub-step S402, based on the threat simulation test results, the target network security system's response process to the simulated threat is analyzed. During the analysis, data analysis software, such as Splunk or Power BI, is used to conduct a detailed evaluation of the alarm response time and processing measures, including statistical analysis of the response time, calculation of the average time from alarm triggering to completion of the response, and analysis of the suitability and effectiveness of the processing measures. The system's automated response configuration and manual intervention efficiency are evaluated, and bottlenecks and optimization points are identified. The target analysis helps generate response efficiency analysis results. The target results reveal the performance of the network security system in actual attack scenarios, providing a scientific basis for further system tuning and policy adjustments.
[0111] S403: Based on the response efficiency analysis results, the target network security system's detection capability, response time, and processing results for security incidents are analyzed to evaluate the system's processing capability for security incidents and generate an incident processing capability score:
[0112] The specific formula for evaluating the system's ability to handle security incidents is:
[0113]
[0114] R is the event handling capability score, D is the detection capability score, T is the response time score, P is the processing result score, and W is the event handling capability score. D is the weight of detection capability, W T is the weight of response time, W P is the weight of the processing result.
[0115] formula
[0116]
[0117] Detailed explanation of the formula and the process of formula calculation and derivation
[0118] The formula is used to comprehensively evaluate the network security system's ability to handle security incidents, by calculating a comprehensive score that reflects the system's detection capability, response time, and processing results;
[0119] Parameter meaning and setting value
[0120] D is the detection capability score, which evaluates the proportion of security threats successfully detected by the system. Assuming that the total number of threats successfully detected by the system accounts for 90%, D = 90;
[0121] T is the response time score, assuming T = 33.33;
[0122] P is the score of the processing result, assuming P = 100;
[0123] W D is the detection capability weight, assumed to be 0.4;
[0124] W T is the response time weight, reflecting the importance of response speed, assumed to be 0.3;
[0125] W P is the processing result weight, which is assumed to be 0.3;
[0126] Substitute the parameters into the formula for calculation
[0127]
[0128] R = 76;
[0129] The result R=76 indicates that the overall performance of the network security system in handling security incidents is 76, indicating that the system performs well in detecting threats, responding to incidents, and recovering after processing. The results are used to help clarify the direction of improvement, including optimizing response strategies and processes to improve overall security performance.
[0130] See also Figure 6 ,Based on the incident handling capability score, combined with the vulnerability handling capability, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, and the security index of the target network security system is calculated. The specific steps for generating the network security index are as follows:
[0131] S501: Based on the incident handling capability score, extract multiple indicator information of the target network security system, including vulnerability handling time, encryption strength, access control capability, and security incident response capability, analyze the impact of multiple indicators on security protection capabilities, and generate indicator impact analysis results:
[0132] In sub-step S501, data analysis tools such as SAS or Python's Pandas library are used to process and analyze data, and key security performance indicators such as vulnerability processing time, encryption strength, access control capabilities, and security incident response capabilities are extracted from the system database. The data of the target indicators are cleaned and formatted to ensure data consistency and accuracy. Statistical analysis methods such as covariance analysis are applied to evaluate the impact of each security performance indicator on the system protection capability, including calculating the correlation coefficient and influence score of each indicator. Through comprehensive target analysis, the indicator impact analysis results are generated. The target results describe in detail the contribution and priority of each security performance indicator to the overall system protection capability.
[0133] S502: Based on the indicator impact analysis results, weights are matched for the various indicators according to their contribution to system security, and a weight allocation list is generated:
[0134] In sub-step S502, decision support system software such as Tableau or Microsoft Power BI is used for visual analysis to assist in weight allocation decisions. The impact analysis results of each safety performance indicator are imported, and scoring criteria such as impact score and criticality level are set. The weighted average method is applied to calculate the weight value of each indicator. The calculation takes into account the system security contribution of the indicator and the actual needs of business operations. Interactive adjustments are made through the user interface to ensure that the weight allocation reasonably reflects the organization's security policies and priorities. A weight allocation list is generated, which lists in detail the weight of each safety performance indicator and its calculation basis.
[0135] S503: Using the weight distribution list, calculate the security index of the target network security system, evaluate the security status of the network, and generate a network security index:
[0136] In sub-step S503, security scoring software such as RiskLens is used for integrated analysis. The current value of each security performance indicator and its corresponding weight are input, and a comprehensive scoring algorithm, such as a linear weighted score model, is applied to calculate a comprehensive security index. This algorithm multiplies the value of each indicator by its weight and then sums them to obtain a numerical value that reflects the overall security status. It evaluates the current security status of the network and can be compared with historical data and industry standards to generate a network security index to provide decision support for senior management.
[0137] See also Figure 7 , a network security index evaluation system, the network security index evaluation system is used to execute the above network security index evaluation method, the system includes:
[0138] The system information extraction module extracts the identified vulnerability information based on the system network log, records the vulnerability type and occurrence time, and generates an identified vulnerability data set;
[0139] The processing capability analysis module calculates the processing time and response speed of the target network security system to various vulnerabilities based on the identified vulnerability data set, evaluates the vulnerability processing efficiency, and generates vulnerability processing efficiency information;
[0140] The encryption configuration analysis module analyzes the implementation of data encryption and the security of key management based on vulnerability processing efficiency information, evaluates the effectiveness of the target network security system data encryption configuration, and generates encryption capability assessment information;
[0141] The access setting assessment module analyzes access permission settings and audit trail records based on the encryption capability assessment information, assesses the applicability and consistency of the access control settings, and generates access control capability information;
[0142] The response simulation test module simulates various network security threats based on access control capability information, analyzes and records the system's response process, evaluates the system's response capability to security incidents, and generates an incident handling capability score;
[0143] The security level calculation module is based on the event handling capability score. According to the importance and impact, it assigns weights to various indicators of the target network security system, calculates the security index, and generates a network security index.
[0144] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented by software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When a computer instruction or computer program is loaded or executed on a computer, a process or function according to an embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state hard disk.
[0145] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.
[0146] In the present invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0147] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0148] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0149] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0150] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0151] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0152] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0153] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0154] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A network security index evaluation method, characterized in that: The method comprises: Based on the system network log, extract the identified vulnerability information, analyze the occurrence frequency and processing response time of various security vulnerabilities, calculate the processing efficiency, and generate vulnerability processing efficiency information; Based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, analyzing the effectiveness of data encryption configuration, and evaluating whether the implementation of encryption strategy meets security standards, generating encryption capability evaluation information; Based on the encryption capability assessment information, by analyzing access permission settings and audit tracking records, assessing the applicability and execution consistency of role-based access control, verifying the effectiveness of access control, and generating access control capability information; Based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the system's response process and time, evaluating the response capability of security incidents, and generating an incident handling capability score; Based on the incident handling capability score, combined with vulnerability handling capabilities, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, the security index of the target network security system is calculated, and a network security index is generated.
2. The network security index evaluation method according to claim 1, characterized in that: The vulnerability processing efficiency information includes vulnerability occurrence frequency, processing efficiency information, and vulnerability closure time. The encryption capability assessment information specifically includes the implementation of data encryption, the security of key management, and the effectiveness of encryption configuration. The access control capability information includes access permission settings, audit tracking records, and the effectiveness of role access control. The event handling capability score specifically refers to security threat simulation analysis results, response process records, and security incident response capabilities. The network security index includes indicator weight matching records, index calculation results, and the importance of multiple indicators.
3. The network security index evaluation method according to claim 1, characterized in that: Based on the system network log, extract the identified vulnerability information, analyze the occurrence frequency and processing response time of various security vulnerabilities, calculate the processing efficiency, and generate the vulnerability processing efficiency information in the following steps: Based on the system network log, extract the identified vulnerability information, record the event timestamp, event type and processing result, and generate a vulnerability processing information set; Based on the event processing information set, analyzing the occurrence frequency of various types of vulnerabilities, calculating the average response time of the vulnerabilities, and generating a response time analysis result; Based on the response time analysis results, the target network security system's efficiency in handling system vulnerabilities is evaluated, and vulnerability handling efficiency information is generated.
4. The network security index evaluation method according to claim 3 is characterized in that: The specific formula for evaluating the target network security system's efficiency in handling system vulnerabilities is: Among them, E represents the calculated vulnerability processing efficiency, w i represents the severity weight of the i-th vulnerability, t i represents the actual processing time of the i-th type of vulnerability, s i is the occurrence frequency of the i-th vulnerability, and i is the index of the vulnerability category.
5. The network security index evaluation method according to claim 1, characterized in that: Based on the vulnerability processing efficiency information, by analyzing the implementation of data encryption and the security of key management, the effectiveness of the data encryption configuration is analyzed, and whether the implementation of the encryption strategy meets the security standards is evaluated. The specific steps for generating encryption capability evaluation information are as follows: Based on the vulnerability processing efficiency information, check the log records of data encryption implementation, analyze the use of encryption algorithms and the logs of key generation, update and destruction, and generate encryption log analysis results; Based on the encryption log analysis results, the security of key management is evaluated by analyzing whether the key length, complexity, and replacement frequency meet industry security standards, and a security assessment result is generated; Based on the security assessment results, the effectiveness of the target network security system data encryption configuration is evaluated and encryption capability assessment information is generated.
6. The network security index evaluation method according to claim 1, characterized in that: Based on the encryption capability assessment information, by analyzing access permission settings and audit tracking records, evaluating the applicability and execution consistency of role access control, and verifying the effectiveness of access control, the steps of generating access control capability information are specifically as follows: Based on the encryption capability assessment information, analyze the access permission settings, analyze the rationality of permission allocation by comparing the access permissions and role responsibility information of multiple roles, and generate permission setting review results; Based on the permission setting audit results, the audit tracking records are analyzed, the access control logs are checked, and the consistency analysis results are generated by comparing the actual access control logs with the preset access rights; Based on the consistency analysis result, by analyzing the detection and response capabilities of the access control settings to unauthorized access, the effectiveness of the access control configuration is evaluated and access control capability information is generated.
7. The network security index evaluation method according to claim 1, characterized in that: Based on the access control capability information, by simulating network security threats, analyzing the monitoring and response mechanism of the target network security system, identifying and recording the system's reaction process and time, evaluating the response capability of security incidents, and generating the incident handling capability score, the specific steps are: Based on the access control capability information, simulate network security threats, including simulated attacks and system intrusion attempts, detect and analyze the monitoring and alarm mechanisms of the target network security system, and generate threat simulation test results; Based on the threat simulation test results, analyze the target network security system's response process to the simulated threat, record the system's alarm response time and processing measures, and generate response efficiency analysis results; Based on the response efficiency analysis results, by analyzing the target network security system's detection capability, response time, and processing results for security incidents, the system's ability to handle security incidents is evaluated and an incident handling capability score is generated.
8. The network security index evaluation method according to claim 7, characterized in that: The specific formula for evaluating the system's ability to handle security incidents is: R is the event handling capability score, D is the detection capability score, T is the response time score, P is the processing result score, and W is the event handling capability score. D is the weight of detection capability, W T is the weight of response time, W P is the weight of the processing result.
9. The network security index evaluation method according to claim 1, characterized in that: Based on the incident handling capability score, combined with vulnerability handling capability, encryption configuration and access control effectiveness, weights are matched for multiple indicators according to importance and impact, and the security index of the target network security system is calculated. The specific steps for generating the network security index are as follows: Based on the incident handling capability score, extract multiple indicator information of the target network security system, including vulnerability handling time, encryption strength, access control capability, and security incident response capability, analyze the impact of multiple indicators on security protection capabilities, and generate indicator impact analysis results; Based on the indicator impact analysis results, weights are matched for the various indicators according to their contribution to system security, and a weight allocation list is generated; The weight distribution list is used to calculate the security index of the target network security system, evaluate the security status of the network, and generate a network security index.
10. A network security index evaluation system, characterized in that: According to any one of claims 1 to 9, the network security index evaluation method comprises: The system information extraction module extracts the identified vulnerability information based on the system network log, records the vulnerability type and occurrence time, and generates an identified vulnerability data set; The processing capability analysis module calculates the processing time and response speed of the target network security system to multiple vulnerabilities based on the identified vulnerability data set, evaluates the vulnerability processing efficiency, and generates vulnerability processing efficiency information; The encryption configuration analysis module analyzes the implementation of data encryption and the security of key management based on the vulnerability processing efficiency information, evaluates the effectiveness of the data encryption configuration of the target network security system, and generates encryption capability evaluation information; The access setting evaluation module analyzes access permission settings and audit trail records based on the encryption capability evaluation information, evaluates the applicability and consistency of the access control settings, and generates access control capability information; The response simulation test module simulates various network security threats based on the access control capability information, analyzes and records the system's response process, evaluates the system's response capability to security incidents, and generates an incident handling capability score; The security level calculation module assigns weights to various indicators of the target network security system based on the event handling capability score and according to the importance and impact, calculates the security index, and generates a network security index.
Citation Information
Cited By
Industrial internet security capability assessment framework
CN122339795A