System for collecting and evaluating network security information of various countries

By building a multi-level network security assessment index system and fuzzy assessment method, the problem of failure to effectively consider the fuzzy characteristics of the indicators in the existing technology is solved, and the accuracy and reliability of network security information assessment are improved.

CN119996005APending Publication Date: 2025-05-13ZHONGAN ZHISHANG (BEIJING) DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510161376.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing network security information assessment methods fail to effectively consider the fuzzy characteristics between indicators, resulting in a high error rate in risk assessment.

Method used

A network security information collection and evaluation system for various countries was designed, and data collection from multiple sources (domestic and foreign) was collected through data source collection units. The data analysis unit built a multi-level network security evaluation index system, and used fuzzy evaluation methods to evaluate the indicators.

Benefits of technology

It improves the accuracy and reliability of network data evaluation, reduces the evaluation error rate, and enhances the security of network systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996005A_ABST
    Figure CN119996005A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network information collection and evaluation, and discloses a country network security information collection and evaluation system, which comprises a data source collection unit used for collecting data sources of a plurality of sources, the data sources comprise network flow, log data, user data and external data, and the data source collection unit is used for collecting the data sources of the plurality of sources; the source comprises a domestic source and / or a foreign source; the data analysis unit comprises a data processing module used for preprocessing the data sources of the multiple sources to obtain target data of the multiple sources; the index construction module is used for constructing a multi-level network security assessment index system based on the target data of the multiple sources; and the index evaluation module is used for performing fuzzy evaluation on each network security evaluation index of the multi-level network security evaluation index system to obtain a fuzzy evaluation result. The method has a relatively low error rate, and the evaluation accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network information collection and evaluation, and in particular relates to a network security information collection and evaluation system for various countries. Background Art

[0002] With the development of informatization and economic globalization, the Internet has penetrated into all aspects of people's lives and brought tremendous changes to people's lives. On the one hand, due to the openness of the Internet, the defects of the information system itself, the leakage of sensitive information, the proliferation of computer viruses and hacker intrusions, various information systems and platforms are facing huge security risks, and information security issues are becoming increasingly prominent. On the other hand, new network environments are constantly emerging, such as big data and cloud computing, which further aggravates information security issues.

[0003] Therefore, it is particularly important to evaluate network information. By evaluating network security information, we can more accurately identify and evaluate the security vulnerabilities and threats of network systems, thereby strengthening security protection measures in a targeted manner and improving the overall security of network systems. At the same time, network security information evaluation helps enterprises and organizations to promptly discover potential security risks, take preventive measures, avoid or reduce the losses that may be caused by network attacks; and when enterprises and organizations are faced with decisions such as network security investment and resource allocation, the research results of network security information evaluation can provide important references.

[0004] However, the existing assessment methods do not consider the fuzzy characteristics between indicators during the assessment process, resulting in a high error rate in risk assessment. Summary of the invention

[0005] The purpose of the present invention is to provide a network security information collection and evaluation system for various countries, so as to solve the problem that the existing evaluation method does not consider the fuzzy characteristics between indicators during the evaluation process, resulting in a high error rate in risk evaluation.

[0006] In order to achieve the above-mentioned purpose, the present invention adopts the following technical scheme: a system for collecting and evaluating network security information of various countries, the system comprising: A data source collection unit, used to collect data sources from multiple sources, the data sources include: network traffic, log data, user data and external data, the sources include: domestic sources and / or foreign sources; A data analysis unit, the data analysis unit comprising: A data processing module is used to pre-process data sources from multiple sources to obtain target data from multiple sources; An indicator construction module, used to construct a multi-level network security evaluation indicator system based on target data from multiple sources, each level of the network security evaluation indicator system includes at least one network security evaluation indicator, at least one network security evaluation indicator has multiple evaluation items, the network security evaluation indicators of the lower level are used as the evaluation items of the network security evaluation indicators of the upper level, and the target data from multiple sources are used as the network security evaluation indicators of the lower level; The indicator evaluation module is used to perform fuzzy evaluation on each network security evaluation indicator of the multi-level network security evaluation indicator system to obtain a fuzzy evaluation result.

[0007] Preferably, the multi-level network security evaluation index system has three levels, the network security evaluation index of the first level is a primary index, the network security evaluation index of the second level is a secondary index, and the network security evaluation index of the third level is a tertiary index, with target data from multiple sources as evaluation items for the tertiary indicators.

[0008] Preferably, the indicator evaluation module is specifically used for: Construct a set of network risk factors at each level based on the network security assessment indicators of the multi-level network security assessment indicator system; Based on the expert evaluation method, determine the weight set of network risk factors at each level; Construct an assessment set based on pre-classified risk levels; Determine the membership of each factor in the network risk factor set at each level in the evaluation set; Based on the weight set of the network risk factor set at each level and the membership degree of each factor in the network risk factor set at this level in the evaluation set, fuzzy synthesis is performed to obtain the fuzzy evaluation value of each network security evaluation indicator at this level.

[0009] Preferably, the risk levels include: high risk, relatively high risk, general risk, relatively low risk and no risk, and the assessment set has 5 elements, which represent high risk, relatively high risk, general risk, relatively low risk and no risk respectively.

[0010] Preferably, the calculation expression of the membership degree of each factor in the bottom-level network risk factor set in the evaluation set is: ; In the formula, The first in the set of bottom-level network risk factors i The element in the evaluation set j The membership degree of an element, The first one in the set of network risk factors at the bottom level i The evaluation set corresponding to the element j elements,J To evaluate the total number of elements in the set, J =5.

[0011] Preferably, when the indicator evaluation module performs fuzzy synthesis based on the weight set of the network risk factor set of each level and the membership of each factor in the network risk factor set of the level in the evaluation set, it is specifically used to: Construct a bottom-level fuzzy membership matrix based on the membership of each factor in the evaluation set in the bottom-level network risk factor set; Based on the product fuzzy operator, the fuzzy membership matrix of the bottom level and the weight set of the bottom level are fuzzily synthesized to obtain the fuzzy evaluation values ​​of each network security evaluation index of the bottom level.

[0012] Preferably, the indicator evaluation module is also used for: The fuzzy membership matrix of the upper level is synthesized based on the fuzzy evaluation values ​​of each network security evaluation index of the lower level; Based on the product fuzzy operator, the fuzzy membership matrix of the upper level and the weight set of the upper level are fuzzy synthesized to obtain the fuzzy evaluation values ​​of each network security evaluation index of the upper level.

[0013] Preferably, the system further comprises: a visualization unit for visually displaying the fuzzy evaluation result.

[0014] Preferably, the data source collection unit includes: Log management module, used to collect and centrally manage log data from multiple sources; The data collection agent module is used to collect log data and send the log data to the log management module; Network collector module, used to collect network traffic; A user behavior collection module, used to collect user data, wherein the user data is user operation behavior data; The external data collection module is used to collect external data, and the external data at least includes: industry organization intelligence information.

[0015] Preferably, the system further comprises: a data storage unit for storing data sources from multiple sources, a multi-level network security assessment indicator system, and risk fuzzy assessment results.

[0016] Beneficial effects: 1. The present invention collects data sources from multiple different sources through a data source collection unit, including domestic data sources and foreign data sources, which can provide more abundant data sources for later network data evaluation and analysis, and improve the accuracy and reliability of data evaluation; 2. When evaluating network data, the present invention improves the evaluation efficiency of network data by constructing a multi-level network security evaluation index system; and during the evaluation process, a fuzzy evaluation is performed on the network security evaluation index, and the obtained fuzzy evaluation result has a lower error rate, thereby improving the evaluation accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present invention, but do not constitute a limitation on the embodiments of the present invention. In the accompanying drawings: Figure 1 It is a block diagram of a system for collecting and evaluating network security information of various countries provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the drawings is only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.

[0019] Figure 1 is a block diagram of a national network security information collection and evaluation system provided by an embodiment of the present invention, such as Figure 1 As shown, this embodiment provides a system for collecting and evaluating network security information of various countries, and the system includes: a data source collection unit, a data analysis unit, a visualization unit, and a data storage unit.

[0020] The data source collection unit is used to collect data sources from multiple sources, the data sources include: network traffic, log data, user data and external data, and the sources include: domestic sources and / or foreign sources.

[0021] The data source collection unit mainly includes five sub-functional modules, namely: log management module, data collection agent module, network collector module, user behavior collection module and external data collection module; The log management module is used to collect and centrally manage log data from multiple sources of data sources; The data collection agent module is used to collect log data and send the log data to the log management module; The network collector module is used to collect network traffic; The user behavior collection module is used to collect user data, and the user data is the user's operation behavior data; The external data collection module is used to collect external data, and the external data includes at least: industry organization intelligence information, and the industry organization intelligence information is divided into: domestic industry organization intelligence information and domestic industry organization intelligence information according to the source; the present invention collects data sources from multiple different sources through a data source collection unit, including domestic data sources and foreign data sources, which can provide richer data sources for subsequent network data evaluation and analysis, and improve the accuracy and reliability of data evaluation.

[0022] The data analysis unit is mainly used to analyze and evaluate the data source. The data analysis unit has three functional sub-modules, namely: a data processing module, an indicator construction module and an indicator evaluation module.

[0023] The data processing module is used to pre-process data sources from multiple sources to obtain target data from multiple sources; Preprocessing of data sources from multiple sources includes: data cleaning, data conversion, etc., among which data cleaning is used to delete non-content elements such as advertisements, style sheets, scripts, etc., fill in or delete records with missing values, delete duplicate records or data rows, and unify the formats of dates, numbers, and texts; among which data conversion is used to unify character encoding, scale data to a small specific interval, and scale data proportionally to fall into a fixed interval, etc.

[0024] The indicator construction module is used to construct a multi-level network security evaluation indicator system based on target data from multiple sources. Each level of the network security evaluation indicator system includes at least one network security evaluation indicator, and at least one network security evaluation indicator has multiple evaluation items. The network security evaluation indicators of the lower level are used as evaluation items of the network security evaluation indicators of the upper level, and the target data from multiple sources are used as the network security evaluation indicators of the lower level.

[0025] In this embodiment, the multi-level network security assessment index system has four levels, the network security assessment index of the first level is a four-level index, the network security assessment index of the second level is a three-level index, the network security assessment index of the third level is a two-level index, and the network security assessment index of the fourth level is a first-level index. The first level is the bottom level, and the security assessment indicator body of the bottom level is target data from multiple sources. The fourth level is the top level.

[0026] In this embodiment, the first-level indicators include: the total network security risk index; the second-level indicators include: network infrastructure security risk index, network information content security risk index, network technology security risk index and network security management index; The three-level indicators are: Computer facilities and equipment, the corresponding four-level indicators are: computer network infrastructure data, etc.; Natural threat conditions, corresponding to the four-level indicators are: vulnerability scanning capability, third-party security index, etc.; The authenticity of online information content, corresponding to the four-level indicators: information fraud security index, network tampering security index, etc.; Information controllability, corresponding to the four-level indicators: information sharing degree, Trojan safety factor, etc. Information privacy, the corresponding four-level indicators are: phishing server security index, etc.; The value of network resources,corresponding to the four-level indicators are: the security index of valuable resources under attack,state; Network vulnerability, the corresponding four-level indicators are: the number of malicious programs in the computer, the proportion of weak passwords, etc.; The four-level indicators corresponding to the reliance of information on technical support are: whether the information belongs to patent content, the level of computer network informatization and intelligence, etc. Information security emergency response degree, the corresponding four-level indicators are: special emergency plans, etc.; The four-level indicators corresponding to the completeness of the safety system are: the degree of implementation and execution of the auxiliary management system; Safety awareness, the corresponding four-level indicators are: active protection awareness, etc.

[0027] The indicator evaluation module is used to perform fuzzy evaluation on each network security evaluation indicator of the multi-level network security evaluation indicator system to obtain fuzzy evaluation results.

[0028] When evaluating network data, the present invention improves the evaluation efficiency of network data by constructing a multi-level network security evaluation index system.

[0029] As a further optimization of this embodiment, the indicator evaluation module is specifically used for: Construct a set of network risk factors at each level based on the network security assessment indicators of the multi-level network security assessment indicator system; determine the weight set of the network risk factor set at each level based on the expert assessment method; construct an assessment set based on the pre-divided risk levels, wherein the risk levels include: high risk, relatively high risk, general risk, relatively low risk and no risk, and the assessment set has 5 elements, and the 5 elements in the assessment set represent high risk, relatively high risk, general risk, relatively low risk and no risk respectively. Determine the membership of each factor in the network risk factor set at each level in the assessment set; perform fuzzy synthesis based on the weight set of the network risk factor set at each level and the membership of each factor in the network risk factor set at this level in the assessment set, and obtain the fuzzy assessment value of each network security assessment indicator at this level.

[0030] In this embodiment, the network risk factor set at each level is ,in, l For the l Level, For the l Level i Network security evaluation indicators, including l =1,2,..., L ,Since the multi-level network security evaluation index system has four levels, L =4.

[0031] In this embodiment, an element in the network risk factor set of each layer corresponds to a network security assessment indicator, and each network security assessment indicator corresponds to a weight. Then, the weight set of the network risk factor set of each level is: , then the calculation expression of each element in the weight set is: (1); In formula (1), For the l The weight of the level is concentrated i The weight of the elements, i =1,2,..., I , I is the total number of elements in the weight set, For the l Level k Expert evaluation of i The weight of the elements, k =1,2,..., K , K is the total number of experts.

[0032] In this example, the evaluation set is ,Since the risk levels include: high risk, higher risk, average risk, lower risk and no risk, the assessment set has 5 elements; but ,in, Indicates high risk, Indicates a higher risk, Characterize general risks, Represents lower risk, Characterizes no risk.

[0033] In this embodiment, the calculation expression of the membership degree of each factor in the bottom-level network risk factor set in the evaluation set is: (2); In formula (3), The first in the set of bottom-level network risk factorsi The element in the evaluation set j The membership degree of an element, The first one in the set of network risk factors at the bottom level i The evaluation set corresponding to the element j elements, j =1,2,..., J , J is the total number of elements in the evaluation set. Since there are 5 elements in the evaluation set, J =5.

[0034] As a further optimization of this embodiment, when the indicator evaluation module performs fuzzy synthesis based on the weight set of the network risk factor set of each level and the membership of each factor in the network risk factor set of this level in the evaluation set, it is specifically used to: The fuzzy membership matrix of the bottom level is constructed based on the membership degree of each factor in the evaluation set in the bottom level network risk factor set. In the same level, the fuzzy membership matrix is , the fuzzy membership matrix for the bottom level is , the top-level fuzzy membership matrix is .

[0035] Based on the product fuzzy operator, the fuzzy membership matrix of the bottom level and the weight set of the bottom level are fuzzily synthesized to obtain the fuzzy evaluation values ​​of each network security evaluation index of the bottom level.

[0036] In this embodiment, the fuzzy evaluation values ​​of each network security evaluation index at the bottom level are evaluated according to different risk levels of different evaluation indicators. The fuzzy membership matrix at the bottom level is: , the weight set of the bottom-level network risk factor set is , then the bottom-level fuzzy evaluation vector is ; Wherein, * is the product fuzzy operator; the fuzzy evaluation vector of the bottom level is composed of the fuzzy evaluation values ​​of each network security evaluation index at the bottom level.

[0037] The underlying fuzzy evaluation vector for , then the calculation expression of the fuzzy evaluation value of each network security evaluation index at the bottom level is: (4); In formula (4), For the bottom level i The fuzzy evaluation value of the network security evaluation index.

[0038] As a further optimization of this embodiment, the indicator evaluation module is also used for: The fuzzy membership matrix of the upper level is synthesized based on the fuzzy evaluation values ​​of each network security evaluation index of the lower level. In this embodiment, the fuzzy evaluation values ​​of each network security evaluation index of the lower level are normalized to synthesize a new fuzzy membership matrix, and the synthesized new fuzzy membership matrix is ​​used as the fuzzy membership matrix of the upper level. The weight set of the network risk factor set of the upper level can be calculated by using formula (1).

[0039] Based on the product fuzzy operator, the fuzzy membership matrix of the upper level and the weight set of the upper level are fuzzy synthesized to obtain the fuzzy evaluation value of each network security evaluation indicator of the upper level; that is, the fuzzy evaluation value of each network security evaluation indicator of the upper level can be calculated by referring to formula (3); each level is calculated in the above manner until the fuzzy evaluation value of the network security evaluation indicator of the top level is calculated; the fuzzy evaluation value of each network security evaluation indicator of each level is taken as the fuzzy evaluation result.

[0040] The visualization unit is used to visualize the fuzzy evaluation results. The visualization unit is used to visualize the fuzzy evaluation results as follows: Perform semantic recognition on each network security assessment indicator at each level, select color values ​​from the color library based on the semantic understanding of the network security assessment indicators, and assign non-repetitive color values ​​to each network security assessment indicator at each level; construct visualization elements, which include: visualization shape, size, position, trend, and layout, etc., and perform data coupling on the visualization elements, the fuzzy assessment values ​​of each network security assessment indicator, and the color values ​​assigned to each network security assessment indicator, and then perform visualization display on the coupled data.

[0041] In this embodiment, the visualization graphics for visually displaying the fuzzy evaluation results include: a visualization analysis chart, a trend comparison analysis chart, a comprehensive comparison analysis chart and a panel interface; the trend comparison analysis chart and the comprehensive comparison analysis chart can be combined into an integrated visualization analysis chart for display, or they can be displayed separately.

[0042] Among them, the data storage unit is used to store data sources from multiple sources, a multi-level network security assessment indicator system, and risk fuzzy assessment results.

[0043] The data storage unit uses a database, which can be a relational database such as MySQL, PostgreSQL, SQL Server, Oracle, etc. These relational databases have the following advantages: Structured Query Language (SQL): Relational databases use SQL as the language for data query and manipulation. SQL is a powerful, flexible, and easy-to-learn language that supports complex queries and data manipulation.

[0044] Data integrity: Relational databases can enforce data integrity constraints, such as primary keys, foreign keys, unique constraints, and check constraints, which help maintain data accuracy and consistency; Data consistency: Through transaction management, relational databases can ensure that a series of operations are either completed or not done at all, thus maintaining data consistency; Data security: Relational databases provide sophisticated access control mechanisms that can limit user access to specific data and protect data from unauthorized access; Standardization: Relational databases follow standardization theories, such as the third normal form (3NF), which helps reduce data redundancy and dependency and improve the efficiency of data storage; Data independence: Relational databases provide two levels of data independence, namely physical independence and logical independence. Users and applications do not need to care about how data is actually stored on disk, but only need to interact with the database through SQL. Mature ecosystem: Relational databases have rich tools, libraries, and community support, which makes it easier to develop, maintain, and optimize databases; Scalability: Relational databases support both vertical scaling (increasing server resources) and horizontal scaling (adding more servers). Although they may not be as scalable as some NoSQL databases, modern relational database management systems such as PostgreSQL and MySQL provide good scaling solutions.

[0045] Backup and recovery: Relational databases usually provide sophisticated backup and recovery mechanisms to ensure that data can be restored in the event of data loss or system failure; Transaction support: Relational databases typically provide ACID (atomicity, consistency, isolation, durability) transaction properties, which are critical for applications that require high reliability.

[0046] The present invention collects data sources from multiple different sources through a data source collection unit, including domestic data sources and foreign data sources, which can provide more abundant data sources for subsequent network data evaluation and analysis, and improve the accuracy and reliability of data evaluation; and when evaluating network data, by constructing a multi-level network security evaluation indicator system, the evaluation efficiency of network data is improved; and in the evaluation process, the network security evaluation indicator is fuzzy evaluated, and the obtained fuzzy evaluation result has a lower error rate, thereby improving the evaluation accuracy.

[0047] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0048] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0049] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A national cybersecurity information collection and assessment system, characterized in that: The system comprises: A data source collection unit, used to collect data sources from multiple sources, the data sources include: network traffic, log data, user data and external data, the sources include: domestic sources and / or foreign sources; A data analysis unit, the data analysis unit comprising: A data processing module is used to pre-process data sources from multiple sources to obtain target data from multiple sources; An indicator construction module, used to construct a multi-level network security evaluation indicator system based on target data from multiple sources, each level of the network security evaluation indicator system includes at least one network security evaluation indicator, at least one network security evaluation indicator has multiple evaluation items, the network security evaluation indicators of the lower level are used as the evaluation items of the network security evaluation indicators of the upper level, and the target data from multiple sources are used as the network security evaluation indicators of the lower level; The indicator evaluation module is used to perform fuzzy evaluation on each network security evaluation indicator of the multi-level network security evaluation indicator system to obtain a fuzzy evaluation result.

2. The national network security information collection and evaluation system according to claim 1 is characterized in that: The multi-level network security evaluation index system has three levels. The network security evaluation index of the first level is the first-level index, the network security evaluation index of the second level is the second-level index, and the network security evaluation index of the third level is the third-level index. Target data from multiple sources are used as evaluation items of the third-level indicators.

3. The national network security information collection and evaluation system according to claim 2 is characterized in that: The indicator evaluation module is specifically used for: Construct a set of network risk factors at each level based on the network security assessment indicators of the multi-level network security assessment indicator system; Based on the expert evaluation method, determine the weight set of network risk factors at each level; Construct an assessment set based on pre-classified risk levels; Determine the membership of each factor in the network risk factor set at each level in the evaluation set; Based on the weight set of the network risk factor set at each level and the membership degree of each factor in the network risk factor set at this level in the evaluation set, fuzzy synthesis is performed to obtain the fuzzy evaluation value of each network security evaluation indicator at this level.

4. The national network security information collection and evaluation system according to claim 3 is characterized in that: The risk levels include: high risk, relatively high risk, general risk, relatively low risk and no risk. The assessment set has 5 elements, and the 5 elements in the assessment set represent high risk, relatively high risk, general risk, relatively low risk and no risk respectively.

5. The national network security information collection and evaluation system according to claim 4 is characterized in that: The calculation expression of the membership degree of each factor in the evaluation set in the bottom-level network risk factor set is: ; In the formula, The first in the set of bottom-level network risk factors i The element in the evaluation set j The membership degree of an element, The first one in the set of network risk factors at the bottom level i The evaluation set corresponding to the element j elements, J To evaluate the total number of elements in the set, J =5.

6. The national network security information collection and evaluation system according to claim 5 is characterized in that: When the indicator evaluation module performs fuzzy synthesis based on the weight set of each level of network risk factor set and the membership degree of each factor in the network risk factor set of this level in the evaluation set, it is specifically used to: Construct a bottom-level fuzzy membership matrix based on the membership of each factor in the evaluation set in the bottom-level network risk factor set; Based on the product fuzzy operator, the fuzzy membership matrix of the bottom level and the weight set of the bottom level are fuzzily synthesized to obtain the fuzzy evaluation values ​​of each network security evaluation index of the bottom level.

7. The national network security information collection and evaluation system according to claim 6 is characterized in that: The indicator evaluation module is also used for: The fuzzy membership matrix of the upper level is synthesized based on the fuzzy evaluation values ​​of each network security evaluation index of the lower level; Based on the product fuzzy operator, the fuzzy membership matrix of the upper level and the weight set of the upper level are fuzzy synthesized to obtain the fuzzy evaluation values ​​of each network security evaluation index of the upper level.

8. The national cybersecurity information collection and assessment system according to any one of claims 1 to 7, characterized in that: The system also includes: a visualization unit, which is used to visualize the fuzzy evaluation results.

9. The national cybersecurity information collection and evaluation system according to any one of claims 1 to 7, characterized in that: The data source collection unit comprises: Log management module, used to collect and centrally manage log data from multiple sources; The data collection agent module is used to collect log data and send the log data to the log management module; Network collector module, used to collect network traffic; A user behavior collection module, used to collect user data, wherein the user data is user operation behavior data; The external data collection module is used to collect external data, and the external data at least includes: industry organization intelligence information.

10. The national cybersecurity information collection and evaluation system according to any one of claims 1 to 7, characterized in that: The system also includes: a data storage unit for storing data sources from multiple sources, a multi-level network security assessment indicator system and risk fuzzy assessment results.