Network security risk assessment method and device, electronic equipment and storage medium
By embedded network security risk evaluator in the network security middleware architecture of the central computing platform, combining threat analysis and risk assessment system and vulnerability scoring system to dynamically evaluate vehicle network security risks, the problem of difficulty in dynamically judging vehicle network security risks in the existing technology is solved, and risk assessment with high accuracy and stability is achieved.
Patent Information
- Application Number
- CN202510160526.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art is difficult to dynamically judge the risk of vehicle network security, especially when the intelligent networking function is complex.
By embedded network security risk evaluator in the network security middleware architecture of the central computing platform, a method of combining threat analysis with risk assessment system and vulnerability scoring system is adopted to dynamically evaluate network security risks and determine risk ratings and risk scores.
It realizes dynamic assessment of network security risks, improves the accuracy and stability of assessment, and can detect high-risk matters online in real time, which is suitable for the current situation of the automotive industry.
Smart Images

Figure CN119996003A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic and electrical architecture, and in particular to a network security risk assessment method, device, electronic device and storage medium. Background Art
[0002] As the automotive electronic and electrical architecture enters the stage of domain integration and cloud computing, the design and deployment of middleware and risk assessors for vehicle network security development has become a core issue in the industry. Middleware serves as a bridge to connect the underlying hardware and high-level applications of the vehicle, thereby providing developers with standardized interfaces and security services to meet the needs of unified security services, dynamic adaptation capabilities, high performance and real-time performance.
[0003] In related technologies, since the traditional network security TARA (Threat Analysis and Risk Assessment) solution is a static analysis, as intelligent connected functions become increasingly complex, it is difficult for traditional security operation methods to dynamically judge vehicle risks. Summary of the invention
[0004] The problem solved by the present invention is how to effectively realize dynamic assessment of network security risks.
[0005] To solve the above problems, the present invention provides a network security risk assessment method, device, electronic device and storage medium.
[0006] In a first aspect, the present invention provides a network security risk assessment method, which is applied to a network security risk assessor, wherein the network security risk assessor is located in a network security middleware architecture of a central computing platform, and the network security risk assessment method comprises:
[0007] Determining a risk rating for network security by means of the network security risk assessor;
[0008] A corresponding risk score is determined according to the risk rating.
[0009] Optionally, determining the network security risk rating by the network security risk assessor includes:
[0010] Determine risk classification;
[0011] A risk rating method is determined according to the risk classification, so as to determine the risk rating according to the risk rating method.
[0012] Optionally, determining a risk rating method according to the risk classification, so as to determine the risk rating according to the risk rating method, comprises:
[0013] When the risk is classified as an event or situation risk, the risk rating is determined according to the threat analysis and risk assessment system;
[0014] When the risk is classified as a vulnerability or vulnerability intelligence risk, determining the risk rating according to a vulnerability scoring system;
[0015] When the risk is classified as a mixed risk, the risk rating is determined according to the threat analysis and risk assessment system and / or the vulnerability scoring system.
[0016] Optionally, determining the risk rating according to a threat analysis and risk assessment system includes:
[0017] When the threat analysis and risk assessment system determines that the risk level is level four or level five, determining the risk rating as a high risk rating;
[0018] When the threat analysis and risk assessment system determines that the risk level is level 2 or level 3, determining the risk rating as a medium risk rating;
[0019] When the threat analysis and risk assessment system determines that the risk level is level one, determining the risk rating as a low risk rating;
[0020] Among them, the network security risks corresponding to the risk levels increase successively from level one to level five.
[0021] Optionally, determining the risk rating according to a vulnerability scoring system includes:
[0022] When the basic score of the vulnerability scoring system is in the first interval or the second interval, determining that the risk rating is a high risk rating;
[0023] When the basic score of the vulnerability scoring system is in the third interval or the fourth interval, determining the risk rating as a medium risk rating;
[0024] When the base score of the vulnerability scoring system is zero, determining the risk rating to be a low risk rating;
[0025] The minimum value of the first interval is greater than the maximum value of the second interval, the minimum value of the second interval is greater than the maximum value of the third interval, the minimum value of the third interval is greater than the maximum value of the fourth interval, and the minimum value of the fourth interval is greater than zero.
[0026] Optionally, determining a corresponding risk score according to the risk rating includes:
[0027] When the risk rating is a high risk rating, determining the risk score according to a first basic score and a first floating item corresponding to a basic score of the vulnerability scoring system;
[0028] When the risk rating is a medium risk rating, determining the risk score according to the second basic score and the first floating item;
[0029] When the risk rating is a low risk rating, the risk score is determined according to a second floating item corresponding to a base score of the vulnerability scoring system.
[0030] Optionally, the network security risk assessment method further includes:
[0031] When the risk score is in the first score range, repairing and processing the risk;
[0032] When the risk score is in the second score range, processing is performed according to the cost;
[0033] When the risk score is in the third score range, the risk is processed or ignored;
[0034] The minimum value of the first scoring interval is greater than the maximum value of the second scoring interval, and the minimum value of the second scoring interval is greater than the maximum value of the third scoring interval.
[0035] In a second aspect, the present invention provides a network security risk assessment device, which is applied to a network security risk assessor, wherein the network security risk assessor is located in a network security middleware architecture of a central computing platform, and the network security risk assessment device comprises:
[0036] A first module is used to determine a risk rating of network security through the network security risk assessor;
[0037] The second module is used to determine a corresponding risk score according to the risk rating.
[0038] In a third aspect, the present invention provides an electronic device, including a memory and a processor;
[0039] The memory is used to store computer programs;
[0040] The processor is used to implement the network security risk assessment method as described in the first aspect when executing the computer program.
[0041] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the network security risk assessment method as described in the first aspect is implemented.
[0042] The beneficial effects of the network security risk assessment method of the present invention are: using a network security risk assessor embedded in the network security middleware architecture of the central computing platform to perform risk assessment has higher accuracy and better stability; after determining the risk rating, determining the corresponding risk score based on the risk rating, effectively realizing dynamic assessment of network security risks, and detecting high-risk items in real time online, which is in line with the current situation of the automotive industry and perfectly conforms to the laws of R&D engineering. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 A schematic diagram of a process flow of a network security risk assessment method according to an embodiment of the present invention;
[0044] Figure 2 A schematic diagram of the central computing platform architecture of an embodiment of the present invention;
[0045] Figure 3 A schematic diagram of a security middleware architecture according to an embodiment of the present invention;
[0046] Figure 4 The process of determining risk rating according to an embodiment of the present invention is shown as follows Figure 1 ;
[0047] Figure 5 The process of determining risk rating according to an embodiment of the present invention is shown as follows Figure 2 ;
[0048] Figure 6 The process of determining risk rating according to an embodiment of the present invention is shown as follows Figure 3 ;
[0049] Figure 7 The process of determining risk rating according to an embodiment of the present invention is shown as follows Figure 4 ;
[0050] Figure 8 A schematic diagram of a process for determining a risk score according to an embodiment of the present invention;
[0051] Fig. 9 This is a schematic diagram of TARA scoring according to an embodiment of the present invention;
[0052] Fig.10 A schematic diagram of risk management according to an embodiment of the present invention;
[0053] Fig.11 A system architecture diagram of a network security risk assessment device according to an embodiment of the present invention;
[0054] Fig.12 FIG. 4 is a diagram of an electronic device system architecture according to an embodiment of the present invention. DETAILED DESCRIPTION
[0055] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below in conjunction with the accompanying drawings. Although certain embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be interpreted as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not intended to limit the scope of protection of the present invention.
[0056] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.
[0057] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to"; the term "based on" means "based at least in part on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0058] It should be noted that the modifications of "one" and "plurality" mentioned in the present invention are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0059] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only used for illustrative purposes, and are not used to limit the scope of these messages or information.
[0060] like Figure 1 As shown, a network security risk assessment method provided by an embodiment of the present invention is applied to a network security risk assessor, wherein the network security risk assessor is located in a network security middleware architecture of a central computing platform (e.g. Figure 2 The network security risk assessment method includes:
[0061] S100: Determine a network security risk rating through the network security risk assessor.
[0062] Specifically, after the risk classification is determined, the risk rating method can be determined according to the risk classification, thereby determining the risk rating.
[0063] Among them, combined Figure 2 and Figure 3 As shown, the cybersecurity middleware architecture of the central computing platform includes a cybersecurity risk assessor to achieve real-time risk value sharing at the vehicle level and user visualization.
[0064] Among them, combined Figure 2 As shown in the figure, the central computing platform has the following characteristics: (1) acts as an in-vehicle application server supporting service-oriented architecture (SOA); (2) SoC-based multi-control unit with Multi GiG interface; (3) dedicated system-level chip (such as AI chip); (4) fully scalable and upgradeable platform; (5) connected to Edge and Cloud backend; (6) used as a regional gateway.
[0065] Among them, combined Figure 3 As shown, the middleware model can be adopted to embed the network security risk assessor into the security middleware. The security middleware can be composed of the following modules:
[0066] (1) Key management module: responsible for a series of management activities including key generation, export, import, signature, signature verification, and derivation.
[0067] (2) SeCoC module: responsible for fresh value synchronization, acquisition, setting, MAC generation, MAC verification, data sending, and data receiving activities.
[0068] (3) X.509 certificate management module: responsible for certificate import, certificate export, CSR file generation, certificate status query, certificate verification, and certificate chain verification.
[0069] (4) UDS module: responsible for seed application, seed generation, seed sending, seed receiving, key generation, key sending, key receiving, key verification, and verification result reception.
[0070] (5) Algorithm application module: responsible for the generation and update of various encryption algorithms.
[0071] (6) Secure storage module: responsible for storing key correspondence, storing integer correspondence, certificate reading, key reading, storage encryption, storage decryption, etc.
[0072] (7) Random number module: responsible for random number generation.
[0073] (8) Risk assessor: responsible for collecting multi-dimensional data such as network security attack paths, intelligence, and vulnerabilities, uploading them to the cloud, and supporting the final risk level assessment and generation on the cloud.
[0074] S200: Determine a corresponding risk score according to the risk rating.
[0075] Specifically, after determining the risk rating, the corresponding risk score can be calculated according to the risk scoring formula corresponding to different risk ratings. For example, under a high risk rating, the risk score ranges from 75-100 points, under a medium risk rating, the risk score ranges from 50-75 points, and under a low risk rating, the risk score ranges from 0-50 points.
[0076] In this embodiment, a network security risk assessor embedded in the network security middleware architecture of the central computing platform is used to perform risk assessment, which has higher accuracy and better stability. After determining the risk rating, the corresponding risk score is determined according to the risk rating, effectively realizing dynamic assessment of network security risks and real-time online detection of high-risk items, which conforms to the current situation of the automotive industry and perfectly fits the laws of R&D engineering.
[0077] Optionally, determining the network security risk rating by the network security risk assessor includes:
[0078] S110: Determine risk classification.
[0079] Specifically, combined Figure 4 As shown, different risk types correspond to different risk rating methods. For example, for event and situation risk assessment only, TARA risk rating can be used, which does not involve vulnerability and vulnerability intelligence risk rating.
[0080] S120: Determine a risk rating method according to the risk classification, and determine a risk rating according to the risk rating method.
[0081] Specifically, combined Figure 4 As shown, for example, for risk assessment of events and situations only, TARA risk rating can be used, and for risk assessment of vulnerabilities and vulnerability intelligence only, vulnerability and vulnerability intelligence risk rating can be used.
[0082] In this optional embodiment, a risk rating method is determined based on risk classification, thereby determining a risk rating, effectively identifying threats and assessing risks.
[0083] Optionally, determining a risk rating method according to the risk classification, so as to determine the risk rating according to the risk rating method, comprises:
[0084] S121: When the risk is classified as an event or situation risk, the risk rating is determined according to a threat analysis and risk assessment system.
[0085] Specifically, combined Figure 5As shown, for risk assessment of events and situations only, TARA risk rating can be used, that is, risk rating is determined according to the threat analysis and risk assessment system (TARA score for short). For example, risk rating is determined based on the attack path score defined by TARA in VTA (Vehicle Threat Analysis). That is, according to the difficulty of the attack path and its potential impact, the scoring model will generate an attack path score by integrating relevant dimensions (such as attack exploitability score and impact score, etc.).
[0086] S122: When the risk is classified as a vulnerability or vulnerability intelligence risk, determine the risk rating according to a vulnerability scoring system.
[0087] Specifically, combined Figure 5 As shown, for vulnerability and vulnerability intelligence risk assessment only, the vulnerability and vulnerability intelligence risk rating can be adopted, that is, the risk rating is determined according to the vulnerability scoring system.
[0088] S123: When the risk is classified as a mixed risk, determining the risk rating according to the threat analysis and risk assessment system and / or the vulnerability scoring system.
[0089] Specifically, combined Figure 5 As shown, for mixed risks involving TARA, vulnerability and vulnerability intelligence risk ratings, TARA scoring can be used to determine the high, medium and low risk levels, or TARA, vulnerability and vulnerability intelligence can be combined to determine the risk rating.
[0090] For example, a risk assessment combining TARA and vulnerability (for the same asset):
[0091]
[0092] That is, when mixed risks include event or situation risks and vulnerability risks, the corresponding risk rating is determined according to the above table.
[0093] For example, a risk assessment combining vulnerability and vulnerability intelligence (for the same asset):
[0094]
[0095] That is, when the mixed risk includes vulnerability risk and vulnerability intelligence risk, the corresponding risk rating is determined according to the above table.
[0096] For example, a risk assessment combining TARA and vulnerability intelligence (for the same asset):
[0097]
[0098] That is, when mixed risks include event or situation risks and vulnerability intelligence risks, the corresponding risk rating is determined according to the above table.
[0099] In this optional embodiment, the corresponding risk rating method is determined according to the risk type, and the difficulty of the attack path, vulnerabilities and vulnerability intelligence can be combined to give a risk assessment value, forming a closed-loop logic and implementation path.
[0100] Optionally, determining the risk rating according to a threat analysis and risk assessment system includes:
[0101] S1211: When the threat analysis and risk assessment system determines that the risk level is level 4 or level 5, determine that the risk rating is a high risk rating.
[0102] Specifically, combined Figure 6 As shown, the risk level 4 and 5 in TARA have a high risk rating.
[0103] S1212: When the threat analysis and risk assessment system determines that the risk level is level 2 or level 3, determine that the risk rating is a medium risk rating.
[0104] Specifically, combined Figure 6 As shown, the risk level 2 and 3 in TARA have a medium risk rating.
[0105] S1213: When the threat analysis and risk assessment system determines that the risk level is level one, the risk rating is determined to be a low risk rating; wherein the network security risks corresponding to the risk levels from level one to level five increase in sequence.
[0106] Specifically, combined Figure 6 As shown, the risk level in TARA is Risk level 1 and the risk rating is low.
[0107] In this optional embodiment, the corresponding risk rating is determined according to the TARA risk level, threats are effectively identified and risks are assessed, resources can be concentrated on solving high-risk and severe risk threats, moderate measures can be taken for low-risk issues, and excessive protection against insignificant threats can be avoided.
[0108] Optionally, determining the risk rating according to a vulnerability scoring system includes:
[0109] S1221: When the basic score of the vulnerability scoring system is in the first interval or the second interval, determining that the risk rating is a high risk rating.
[0110] Specifically, combined Figure 7As shown, the Risk levels 1-5 of vulnerabilities and vulnerability intelligence are defined as follows:
[0111]
[0112] When the base score of the vulnerability scoring system is in the first interval (9.0-10) or the second interval (7.0-8.9), the risk rating is a high risk rating.
[0113] Among them, the basic score depends only on the inherent characteristics of the vulnerability itself and will not change with changes in the environment.
[0114] Among them, the definitions of Risk level 1-5 are consistent with those on the TARA side, all referring to risk levels, that is, Risk level 4, 5 are called high risk; Risk level 2, 3 are called medium risk; Risk level 1 is called low risk.
[0115] Among them, the Common Vulnerability Scoring System (CVSS) can be composed of three main indicator groups. The scores of each indicator group are combined to generate the overall score of the vulnerability, as follows:
[0116] (1) Basic indicator group: The basic indicator group is used to measure the characteristics of the vulnerability itself and is the core part of the CVSS score. It usually includes attack vector (the way the vulnerability is exploited, divided into: network (N), neighborhood (A), local (L), physical (P)), attack complexity (the difficulty for attackers to exploit the vulnerability, divided into: low (L), high (H)), permission requirement (the permission level required for attackers to exploit the vulnerability, divided into: none (N), low (L), high (H)), user interaction (whether user participation is required, divided into: required (R) and not required (N)), impact scope (whether the vulnerability impact crosses system boundaries, divided into: unchanged (U) and changed (C)) and impact degree (the impact on the confidentiality (C), integrity (I) and availability (A) of the system, divided into: none (N), low (L), high (H)).
[0117] (2) Time indicator group: The time indicator group reflects the factors that affect the change of vulnerabilities over time, such as the availability of patch releases or vulnerability exploitation tools. It usually includes the following parameters: exploitation maturity (the feasibility of vulnerability exploitation, divided into: undefined (X), theoretical (U), proof of concept (P), functional (F), mature (H)), repair status (whether there is a patch or solution, divided into: undefined (X), official fix (O), temporary fix (T), no fix (W)) and report credibility (the reliability of vulnerability reports, divided into: undefined (X), unknown (U), reasonable (R), confirmed (C)).
[0118] (3) Environmental indicator group: The environmental indicator group is used to assess the impact of vulnerabilities on a specific organization or environment. The score is adjusted according to the specific usage scenario. It usually includes the following parameters: security requirements (the importance of the system to confidentiality (C), integrity (I) and availability (A), which are divided into: low (L), medium (M), high (H)) and modified attack vectors (the values of attack vectors, permission requirements, etc. in the basic indicators are adjusted according to the environment).
[0119] S1222: When the basic score of the vulnerability scoring system is in the third interval or the fourth interval, determine that the risk rating is a medium risk rating.
[0120] Specifically, combined Figure 7 As shown above, when the basic score of the vulnerability scoring system is in the third interval (4.0-6.9) or the fourth interval (0.1-3.9), the risk rating is a medium risk rating.
[0121] S1223: When the basic score of the vulnerability scoring system is zero, the risk rating is determined to be a low risk rating; wherein the minimum value of the first interval is greater than the maximum value of the second interval, the minimum value of the second interval is greater than the maximum value of the third interval, the minimum value of the third interval is greater than the maximum value of the fourth interval, and the minimum value of the fourth interval is greater than zero.
[0122] Specifically, combined Figure 7 As shown above, when the base score of the vulnerability scoring system is zero, the risk rating is a low risk rating.
[0123] In this optional embodiment, the risk rating is determined based on the basic score of the vulnerability scoring system, and the potential threats of the vulnerabilities can be standardized and quantified, so that threats can be effectively identified and risks can be assessed. Vulnerabilities with high scores are repaired first, and vulnerabilities with low scores can be processed later, thereby optimizing resource utilization. Through graded protection measures, more resources can be invested in high-risk vulnerabilities, while the minimum necessary protection can be taken for low-risk vulnerabilities.
[0124] Optionally, determining a corresponding risk score according to the risk rating includes:
[0125] S210: When the risk rating is a high risk rating, determining the risk score according to a first basic score and a first floating item corresponding to a basic score of the vulnerability scoring system.
[0126] Specifically, combined Figure 8 As shown, under high risk rating, the risk score can be expressed as:
[0127] Risk Scoring = 75 + 25 * {(CVSS score - 0) / 10};
[0128] S220: When the risk rating is a medium risk rating, determining the risk score according to a second basic score and the first floating item.
[0129] Specifically, combined Figure 8 As shown, under the medium risk rating, the risk score can be expressed as:
[0130] Risk Scoring = 50 + 25 * {(CVSS score - 0) / 10};
[0131] S230: When the risk rating is a low risk rating, determining the risk score according to a second floating item corresponding to a basic score of the vulnerability scoring system.
[0132] Specifically, combined Figure 8 As shown, under low risk rating, the risk score can be expressed as:
[0133] Risk Scoring = 50*{(CVSS score - 0) / 10};
[0134] Among them, combined Fig. 9 As shown in the figure, AP077 and AP078 are attack paths of Risk level 5. Taking AP077 as an example, the TARA risk rating is high, and the CVSS of CVE-2018-11478 is 8.8, which is the highest. Therefore, {AP077_Risk Scoring}=75+25*{(CVSS score-0) / 10}=97. It must be repaired and processed, and must be processed in the shortest OTA node. In addition, risk control of such problems needs to be focused on throughout the entire life cycle.
[0135] In this optional embodiment, the corresponding risk score is calculated according to the risk scoring formula corresponding to the different risk ratings, ensuring that threats can be identified and risks can be assessed in a timely manner, and risks can be quantified more clearly. Then, according to the different characteristics of the risk (such as attack difficulty, potential impact), a suitable scoring model can be applied to more flexibly reflect the actual risk status.
[0136] Optionally, the network security risk assessment method further includes:
[0137] S300: When the risk score is in the first score interval, the risk is repaired and processed.
[0138] Specifically, combined Fig.10 As shown, when the risk score is above 75 points, the risk needs to be repaired and processed, and updated and repaired within the shortest OTA update cycle.
[0139] S400: When the risk score is in the second score range, processing is performed according to the cost.
[0140] Specifically, combined Fig.10 As shown, when the risk score is 25-75 points, it can be repaired or not depending on the cost.
[0141] S500: When the risk score is in a third scoring interval, the risk is processed or ignored; wherein the minimum value of the first scoring interval is greater than the maximum value of the second scoring interval, and the minimum value of the second scoring interval is greater than the maximum value of the third scoring interval.
[0142] Specifically, combined Fig.10 As shown, when the risk score is 0-25 points, confirm whether to handle or directly accept the risk depending on the situation.
[0143] In this optional embodiment, corresponding processing measures are determined according to the different scoring intervals of the risk score to ensure that risks can be dealt with in a timely manner. For example, the processing measures corresponding to high-risk intervals usually require immediate response to ensure that limited resources are used to solve the most urgent and serious problems. Low risk scores correspond to lower priority processing measures to avoid excessive consumption of manpower and financial resources on unnecessary protection.
[0144] like Fig.11 As shown, a network security risk assessment device 1100 provided in an embodiment of the present invention is applied to a network security risk assessor, and the network security risk assessor is located in a network security middleware architecture of a central computing platform. The network security risk assessment device includes:
[0145] A first module 1110 is used to determine a risk rating of network security through the network security risk assessor;
[0146] The second module 1120 is used to determine a corresponding risk score according to the risk rating.
[0147] like Fig.12 As shown, an electronic device 1200 provided in an embodiment of the present invention includes a memory 1220 and a processor 1210; the memory 1220 is used to store a computer program; the processor 1210 is used to implement the network security risk assessment method as described above when executing the computer program.
[0148] In other words, an electronic device 1200 includes a memory 1220 and a processor 1210 coupled to the memory 1220; the memory 1220 is configured to store a computer program; and the processor 1210 is configured to perform the following operations when executing the computer program:
[0149] Determining a risk rating for network security by means of the network security risk assessor;
[0150] A corresponding risk score is determined according to the risk rating.
[0151] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the network security risk assessment method as described above is implemented.
[0152] In other words, a non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor performs the following operations:
[0153] Determining a risk rating for network security by means of the network security risk assessor;
[0154] A corresponding risk score is determined according to the risk rating.
[0155] An electronic device 1200 that can be used as a server or client of the present invention will now be described, which is an example of a hardware device that can be applied to various aspects of the present invention. Electronic device 1200 is intended to represent various forms of digital electronic computer equipment, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic device 1200 can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the present invention described and / or required herein.
[0156] The electronic device 1200 includes a computing unit, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) or a computer program loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for the operation of the device can also be stored. The computing unit, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0157] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc. In the present application, the unit described as a separate component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or it may be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present invention. In addition, each functional unit in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0158] Although the present invention is disclosed as above, the protection scope of the present invention is not limited thereto. Those skilled in the art may make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will fall within the protection scope of the present invention.
Claims
1. A network security risk assessment method, characterized in that: Applied to a network security risk assessor, the network security risk assessor is located in a network security middleware architecture of a central computing platform, and the network security risk assessment method includes: Determining a risk rating for network security by means of the network security risk assessor; A corresponding risk score is determined according to the risk rating.
2. The network security risk assessment method according to claim 1, characterized in that: Determining the risk rating of network security by the network security risk assessor includes: Determine risk classification; A risk rating method is determined according to the risk classification, so as to determine the risk rating according to the risk rating method.
3. The network security risk assessment method according to claim 2, characterized in that: The step of determining a risk rating method according to the risk classification, and determining a risk rating according to the risk rating method includes: When the risk is classified as an event or situation risk, the risk rating is determined according to the threat analysis and risk assessment system; When the risk is classified as a vulnerability or vulnerability intelligence risk, determining the risk rating according to a vulnerability scoring system; When the risk is classified as a mixed risk, the risk rating is determined according to the threat analysis and risk assessment system and / or the vulnerability scoring system.
4. The network security risk assessment method according to claim 3, characterized in that: Determining the risk rating according to the threat analysis and risk assessment system includes: When the threat analysis and risk assessment system determines that the risk level is level four or level five, determining the risk rating as a high risk rating; When the threat analysis and risk assessment system determines that the risk level is level 2 or level 3, determining the risk rating as a medium risk rating; When the threat analysis and risk assessment system determines that the risk level is level one, determining the risk rating as a low risk rating; Among them, the network security risks corresponding to the risk levels increase successively from level one to level five.
5. The network security risk assessment method according to claim 3, characterized in that: Determining the risk rating according to the vulnerability scoring system includes: When the basic score of the vulnerability scoring system is in the first interval or the second interval, determining that the risk rating is a high risk rating; When the basic score of the vulnerability scoring system is in the third interval or the fourth interval, determining the risk rating as a medium risk rating; When the base score of the vulnerability scoring system is zero, determining the risk rating to be a low risk rating; The minimum value of the first interval is greater than the maximum value of the second interval, the minimum value of the second interval is greater than the maximum value of the third interval, the minimum value of the third interval is greater than the maximum value of the fourth interval, and the minimum value of the fourth interval is greater than zero.
6. The network security risk assessment method according to claim 3, characterized in that: Determining the corresponding risk score according to the risk rating includes: When the risk rating is a high risk rating, determining the risk score according to a first basic score and a first floating item corresponding to a basic score of the vulnerability scoring system; When the risk rating is a medium risk rating, determining the risk score according to the second basic score and the first floating item; When the risk rating is a low risk rating, the risk score is determined according to a second floating item corresponding to a base score of the vulnerability scoring system.
7. The network security risk assessment method according to claim 6, characterized in that: Also includes: When the risk score is in the first score range, repairing and processing the risk; When the risk score is in the second score range, processing is performed according to the cost; When the risk score is in the third score range, the risk is processed or ignored; The minimum value of the first scoring interval is greater than the maximum value of the second scoring interval, and the minimum value of the second scoring interval is greater than the maximum value of the third scoring interval.
8. A network security risk assessment device, characterized in that: Applied to a network security risk assessor, the network security risk assessor is located in a network security middleware architecture of a central computing platform, and the network security risk assessment device includes: A first module is used to determine a risk rating of network security through the network security risk assessor; The second module is used to determine a corresponding risk score according to the risk rating.
9. An electronic device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is used to implement the network security risk assessment method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the network security risk assessment method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
An information security risk management system
CN109167786A
Analysis method for identifying automobile ECU (Electronic Control Unit) network security risk and countermeasures
CN118677698A
Network security risk assessment method and device
CN118784250A