Computer network security test and evaluation system and method

By providing a computer network security test and evaluation system, the neglected problems in network security testing and evaluation of the Internet of Things system and computer servers are solved, and a comprehensive security assessment of the internal and external networks of the Internet of Things system is achieved, thereby improving network security.

CN119996014APending Publication Date: 2025-05-13XUZHOU FIRST PEOPLES HOSPITAL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510201432.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the computer network security testing and evaluation, the prior art ignores the security testing of the internal network of the Internet of Things system and the data security testing during the connection between the Internet of Things system and the computer server, resulting in network security risks in the Internet of Things system and the computer server.

Method used

Provide a computer network security testing and evaluation system, including information acquisition module, IoT system internal testing module, IoT system external testing module, network security comprehensive evaluation module, early warning display terminal and database. The system obtains monitoring parameters of the IoT system, conducts internal and external network testing, evaluates security levels, and conducts comprehensive security assessments.

Benefits of technology

By conducting detailed testing and evaluation of the internal and external networks of the Internet of Things system, security risks can be discovered in a timely manner, network security between the Internet of Things system and the computer server, and the risks of information leakage and network attacks can be reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996014A_ABST
    Figure CN119996014A_ABST
Patent Text Reader

Abstract

The invention discloses a computer network security test and evaluation system and method, and particularly relates to the technical field of computer network security test, the system comprises an information acquisition module, an IoT system internal test module, an IoT system external test module, a network security comprehensive evaluation module, an early warning display terminal and a database. According to the invention, on one hand, the internal network of the Internet of Things system is subjected to security test evaluation, on the other hand, the connection process of the Internet of Things system and the computer server is subjected to security test evaluation, and the security level of the computer network is comprehensively evaluated by analyzing the security coefficient of the internal network of each Internet of Things system and the connection security coefficient of the external network. The computer network is analyzed and evaluated in multiple modes, the accuracy of safety test and evaluation of the computer network is improved, potential safety hazards of the computer network can be found and solved in time, and safe and stable operation of the computer network is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network security testing, and in particular to a computer network security testing and evaluation system and method. Background Art

[0002] With the widespread application of IoT devices in daily life and industrial fields, computer servers are often connected to many IoT systems, and each IoT system is often connected to a large number of devices and sensors. These devices not only process sensitive data, but also control key physical assets. A large number of devices and sensors are usually installed in outdoor environments. Environmental risks and working parameter risks will threaten the internal network of the IoT system, thereby causing network security on the computer server. Therefore, it is necessary to conduct research on network security testing and evaluation of computer servers connected to IoT systems.

[0003] The prior art is a computer network security testing and inspection method disclosed in the invention patent application announced as CN113132412B, the method includes: its testing and inspection process includes collecting device information → checking network topology → checking network configuration → scanning server vulnerabilities → hidden dangers and vulnerability rectification → preventing computer viruses, including the following six steps. The present invention can timely discover network attack behaviors, viruses, improper content, or internal personnel's cross-border behaviors through firewalls, traffic audit systems, intrusion system detection IDS, information encryption, security authentication, and regular system detection, so as to assist network administrators in comprehensively and effectively analyzing traffic data, and supplemented by intelligent association, deep mining and other analyses that are difficult to perform manually, quickly discover system abnormal conditions or potential attack behaviors or attack results from massive data, so as to ensure the confidentiality, integrity and availability of network system resources, and effectively help the system respond to emergencies, so that the system can remain in a safe and reliable state for a long time.

[0004] The prior art, such as the network test system based on industrial Internet security disclosed in the invention patent application announced as CN115801634B, includes: self-reset button, motor indicator light, variable resistance adjustment knob, temperature and humidity sensor, digital tube and camera, to build a field equipment layer; with programmable logic controller as the control layer and human-machine interface display terminal as the monitoring layer, an industrial control network system is built according to the above field equipment layer, mirror switch, Internet of Things gateway and industrial Internet cloud platform; the network attack server is used to perform network attack tests on the above industrial control network system; the industrial control security monitoring and auditing system is connected to the above industrial control network system, and the above industrial control security monitoring and auditing system is used to record the communication information of the above industrial control network system, and to warn of abnormal communication information of the above industrial control network system. This implementation method can reduce the network security vulnerabilities of the industrial control network system to improve the security of the industrial control network system.

[0005] In combination with the above technical solutions, it is found that the existing technology for computer network security testing and evaluation, on the one hand, ignores the security testing and evaluation of the internal network of each Internet of Things system connected to the computer server, and there is an invisible trust relationship between the various IoT devices in the IoT system. By injecting data into one of the target devices, the attacker will cause other devices in the IoT system to break the network isolation, increase the risk of illegal data acquisition, and cause security threats to the internal network of each IoT system; on the other hand, the existing technology ignores the security testing of data upload of each IoT system and data distribution of the computer server during the connection between each IoT system and the computer server, resulting in the risk of being attacked during the computer server receiving data and the computer server receiving data, thereby increasing the network security risk between each IoT system and the computer server, resulting in the leakage of information privacy, and threatening the security of the IoT system and the computer server. Summary of the invention

[0006] The purpose of the present invention is to provide a computer network security testing and evaluation system and method, which solves the problems existing in the background technology.

[0007] In order to solve the above technical problems, the first aspect of the present invention provides a computer network security testing and evaluation system, which includes: an information acquisition module, an IoT system internal testing module, an IoT system external testing module, a network security comprehensive evaluation module, an early warning display terminal and a database.

[0008] The information acquisition module is used to obtain monitoring parameter sets of each Internet of Things system, including: network topology diagrams of each Internet of Things system, environmental parameters of each Internet of Things device in each Internet of Things system, and historical working parameters.

[0009] The IoT system internal test module selects the main device for internal testing of each IoT system based on the monitoring parameter sets of each IoT system, performs internal network testing of each IoT system, obtains internal network test data of each IoT system, calculates the security factor of the internal network of each IoT system, and evaluates the security level of the internal network of each IoT system.

[0010] The IoT system external test module sets the external network test parameters of each IoT system based on the security level of the internal network of each IoT system, and calculates the external network connection security factor of each IoT system.

[0011] The network security comprehensive assessment module comprehensively assesses the security level of the computer network based on the security factor of the internal network of each Internet of Things system and the security factor of the external network connection.

[0012] The early warning display terminal is used to display the comprehensive security level of the computer network and issue early warnings to users.

[0013] A second aspect of the present invention provides a method for computer network security testing and evaluation, the method comprising: step 1, obtaining monitoring parameter sets of each Internet of Things system.

[0014] Step 2: Conduct internal network tests on each IoT system to assess the security level of the internal network of each IoT system.

[0015] Step 3: Set the external network test parameters of each IoT system.

[0016] Step 4: Calculate the external network connection security factor of each IoT system.

[0017] Step 5: Comprehensively evaluate the security level of the computer network and display the security level of the computer network on the terminal device.

[0018] Compared with the prior art, the benefits of the present invention are as follows: 1. The present invention analyzes the environmental parameters and historical working parameters of each IoT device in each IoT system to obtain the risk factor of each IoT device in each IoT system, thereby determining the main device for internal testing of each IoT system, which helps to find devices in each IoT system that are vulnerable to network attacks, thereby performing internal testing of the IoT system, improving the accuracy of internal testing of the IoT system, and promptly discovering security issues within the IoT system.

[0019] 2. The present invention is based on the main device for internal testing of each Internet of Things system, sets the parameters of the internal testing of each Internet of Things system, analyzes the test data packet reception rate of each slave device adjacent to the main device for internal testing of each Internet of Things system, and thus evaluates the security level of the internal network of each Internet of Things system. The accuracy of the security assessment of the internal network of the Internet of Things system can be improved, the hidden dangers of the internal network of the Internet of Things system can be eliminated in advance, the security and stability of the operation of the internal network of the Internet of Things system can be improved, and the threat of the internal network risk of the Internet of Things system to the network security of the computer server can be reduced.

[0020] 3. The present invention sets the number of test data packets according to the security level of the internal network of each Internet of Things system, performs network security tests on data upload of each Internet of Things system and data delivery of the computer server, evaluates whether there are identity authentication problems and access timeouts, and analyzes the security factor of the external network connection of the Internet of Things system, thereby ensuring the scientific nature of the network security test in the process of connection between each Internet of Things system and the computer server, and setting the number of test data packets in a graded manner, thereby improving the efficiency of the network security test of the computer server.

[0021] 4. The present invention comprehensively evaluates the security level of computer networks based on the security factor of the internal network of each Internet of Things system and the security factor of the external network connection, taking into account the risks within the Internet of Things system and the risks in the process of connecting the Internet of Things system with the computer server. It analyzes and evaluates computer networks in multiple modes, improves the accuracy of security testing and evaluation of computer networks, helps to promptly discover potential security risks in computer networks and solve them in a timely manner, and ensures the safe operation of computer networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0023] Figure 1 It is a system structure connection diagram of the present invention.

[0024] Figure 2 It is a schematic diagram of the method flow of the present invention. DETAILED DESCRIPTION

[0025] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0026] For ease of understanding, some professional terms involved in the present invention are explained below: A network topology diagram is a diagram used to represent the various devices in a computer network and the connections between them. It is an important tool for network design and analysis, which can help understand the network structure, data flow path, and how to manage and maintain the network.

[0027] IoT devices refer to physical devices that are connected via the Internet and capable of exchanging data. These devices are usually equipped with sensors, software and other technologies to communicate and interact with other devices or systems.

[0028] A token is a method of identity authentication during network data transmission. It is commonly found in cloud platforms and large-scale distributed IoT systems. Tokens usually contain encrypted information such as user identification, permissions, and validity period.

[0029] Reference Figure 1As shown, the first aspect of the present invention is a computer network security testing and evaluation system, which includes: an information acquisition module, an IoT system internal testing module, an IoT system external testing module, a network security comprehensive evaluation module, an early warning display terminal and a database.

[0030] The information acquisition module is used to obtain monitoring parameter sets of each Internet of Things system, including: network topology diagrams of each Internet of Things system, environmental parameters of each Internet of Things device in each Internet of Things system, and historical working parameters.

[0031] The IoT system internal test module selects the main device for internal testing of each IoT system based on the monitoring parameter sets of each IoT system, performs internal network testing of each IoT system, obtains internal network test data of each IoT system, calculates the security factor of the internal network of each IoT system, and evaluates the security level of the internal network of each IoT system.

[0032] The IoT system external test module sets the external network test parameters of each IoT system based on the security level of the internal network of each IoT system, and calculates the external network connection security factor of each IoT system.

[0033] The network security comprehensive assessment module comprehensively assesses the security level of the computer network based on the security factor of the internal network of each Internet of Things system and the security factor of the external network connection.

[0034] The early warning display terminal is used to display the comprehensive security level of the computer network and issue early warnings to users.

[0035] The database is used to store various historical working parameters of each IoT device in each IoT system, store the influencing factors of the number of adjacent IoT devices per unit, the standard magnetic field strength that the IoT device can withstand for normal operation, the standard ambient temperature range of the IoT device, the packet loss rate allowed for normal operation of the IoT device, and the bit error rate allowed for normal operation of the IoT device, store the influencing factors of the number of data unit receptions, the influencing factors of the number of data unit transmissions, store the influencing factors of the number of slave devices that are not adjacent to the master device and receive test data packets, store the judgment thresholds for first-class security and second-class security of the internal network of the IoT system, and store various judgment intervals for the security of the computer network.

[0036] It should be noted that, in a specific embodiment, the information acquisition module is connected to the internal test module of the IoT system, the internal test module of the IoT system is connected to the external test module of the IoT system, the external test module of the IoT system is connected to the network security comprehensive evaluation module, the network security comprehensive evaluation module is connected to the early warning display terminal, and the database is connected to the information acquisition module, the internal test module of the IoT system, the external test module of the IoT system, and the network security comprehensive evaluation module.

[0037] In a specific embodiment of the present invention, the specific acquisition method for obtaining the monitoring parameter sets of each Internet of Things system is: obtaining the network topology diagram of each Internet of Things system connected to the computer server through a computer network scanning tool.

[0038] The magnetic field strength of each IoT device in each IoT system is obtained through fluxmeter detection ,in , Indicates the number of each IoT system, represents the total number of IoT systems, , Indicates the number of each IoT device in the IoT system. Represents the total number of IoT devices in the IoT system.

[0039] Use camera equipment to take pictures of the installation locations of each IoT device in each IoT system, and use image recognition technology to determine the location of the first The first Check whether there is an interface feature area in the picture of the installation location of the IoT device. If so, The first The interface security value of each IoT device is set to , otherwise, The first The interface security value of each IoT device is set to , get the interface security value of each IoT device in each IoT system .

[0040] It should be noted that, in a specific embodiment, the interface feature area refers to: a pre-collected interface image of each IoT device in each IoT system, based on the taken images of the installation location of each IoT device in each IoT system, by using computer image recognition technology to determine whether there is an interface exposed to the outside, so as to set the interface security value of each IoT device in each IoT system.

[0041] The ambient temperature of each IoT device in each IoT system is collected through temperature sensors .

[0042] The magnetic field strength, interface security value and ambient temperature of each IoT device in each IoT system are summarized to form the environmental parameters of each IoT device in each IoT system.

[0043] The historical working parameters of each IoT device in each IoT system are obtained from the database, including the total data received, the total data sent, the packet loss rate and the bit error rate during the monitoring period.

[0044] In a specific embodiment of the present invention, the specific analysis method for selecting the main device for internal testing of each IoT system is as follows: based on the network topology diagram of each IoT system, the total number of adjacent devices of each IoT device in each IoT system is counted. .

[0045] By analyzing the environmental parameters and historical working parameters of each IoT device in each IoT system, the environmental risk coefficient and working risk coefficient of each IoT device in each IoT system are obtained respectively, and the formula is: , calculate the risk coefficient of each IoT device in each IoT system ,in Represents the impact factor of the number of adjacent IoT devices extracted from the database, Indicates the environmental risk factor of each IoT device in each IoT system. It represents the working risk coefficient of each IoT device in each IoT system.

[0046] Based on The risk factor of each IoT device in the IoT system is extracted. The IoT device with the largest risk factor in the IoT system is denoted as The main device for internal testing of the IoT system will The remaining IoT devices in the IoT system are denoted as The slave devices tested internally in each IoT system are used to obtain the master device and the slave devices tested internally in each IoT system.

[0047] The present invention analyzes various environmental parameters and historical working parameters of each IoT device in each IoT system to obtain the risk coefficient of each IoT device in each IoT system, thereby determining the main device for internal testing of each IoT system, which helps to find devices in each IoT system that are vulnerable to network attacks, thereby performing internal testing of the IoT system, improving the accuracy of internal testing of the IoT system, and promptly discovering security issues within the IoT system.

[0048] In a specific embodiment of the present invention, the environmental risk coefficient and the working risk coefficient of each IoT device in each IoT system are specifically analyzed by: based on the magnetic field strength of each IoT device in each IoT system , Interface security value and ambient temperature , through the formula: , calculate the abnormal judgment value of the ambient temperature of each IoT device in each IoT system ,in Represents the standard ambient temperature range of IoT devices extracted from the database, through the formula: , calculate the environmental risk coefficient of each IoT device in each IoT system ,in It indicates the standard magnetic field strength that the IoT device can withstand for normal operation extracted from the database. Represents a natural constant.

[0049] The total amount of data received during the monitoring period of each IoT device in each IoT system , Total data sent , Packet loss rate and bit error rate , through the formula: , calculate the working risk coefficient of each IoT device in each IoT system ,in Indicates the packet loss rate allowed for normal operation of IoT devices extracted from the database. It indicates the bit error rate allowed for normal operation of IoT devices extracted from the database. Indicates the impact factor of the number of times a data unit is received from the database, Indicates the impact factor of the number of times a data unit extracted from the database is sent.

[0050] In a specific embodiment of the present invention, the internal network test of each Internet of Things system is performed to obtain the internal network test data of each Internet of Things system. The specific method is: based on the main device of the internal test of each Internet of Things system, a network test data is sent to each Internet of Things system. The number of test packets with the correct token and Number of error token test packets.

[0051] Based on the network topology of each IoT system, the network packet capture technology is used to obtain the test data packet information received by each slave device in the internal test of each IoT system, and the number of slave devices that are not adjacent to the master device and receive the test data packet in each IoT system is counted. .

[0052] It should be noted that, in a specific embodiment, in the process of counting the number of slave devices that are not adjacent to the master device and that receive test data packets in each IoT system, the test data packets include test data packets with correct tokens and data packets with incorrect tokens. The purpose of the statistics is to ensure network isolation between the IoT devices of each IoT system to avoid the existence of IoT devices with illegal access.

[0053] Count the number of test packets with correct tokens received by each slave device adjacent to the master device under test in each IoT system ,in , Indicates the number of each slave device adjacent to the master device tested within the IoT system. Indicates the total number of slave devices adjacent to the master device under test in the IoT system.

[0054] In a specific embodiment of the present invention, the security level of the internal network of each IoT system is evaluated by a specific analysis method: based on the number of slave devices that are not adjacent to the master device and receive the test data packet in each IoT system, , the number of test packets with correct tokens received by each slave device adjacent to the master device tested within each IoT system , through the formula: , calculate the security factor of the internal network of each IoT system ,in The influence factor representing the number of units of slave devices that are not adjacent to the master device and receive the test data packet extracted from the database.

[0055] like , then determine the The security level of the internal network of the IoT system is first-class, among which It represents the judgment threshold of first-class security of the internal network of the Internet of Things system extracted from the database.

[0056] like , then determine the The security level of the internal network of the IoT system is second-class, among which It represents the judgment threshold of the second-class security of the internal network of the IoT system extracted from the database.

[0057] like , then determine the The security level of the internal network of each IoT system is third, and the security level of the internal network of each IoT system is obtained.

[0058] It should be noted that, in a specific embodiment, the judgment thresholds of the various levels of security of the internal network of the Internet of Things system are manually set and stored in a database by technical personnel based on a comprehensive analysis of the security systems of the internal networks of the Internet of Things systems in history and the actual working conditions of each Internet of Things system.

[0059] The present invention is based on a main device for internal testing of each Internet of Things system, sets parameters for internal testing of each Internet of Things system, analyzes the test data packet reception rate of each slave device adjacent to the main device for internal testing of each Internet of Things system, thereby evaluating the security level of the internal network of each Internet of Things system, and can improve the accuracy of security evaluation of the internal network of the Internet of Things system, eliminate hidden dangers of the internal network of the Internet of Things system in advance, improve the security and stability of the operation of the internal network of the Internet of Things system, and reduce the threat of the internal network risk of the Internet of Things system to the network security of the computer server.

[0060] In a specific embodiment of the present invention, the external network test parameters of each IoT system are set, and the specific analysis method is as follows: based on the security level of the internal network of each IoT system, the number of test data packets of the correct token uploaded by each IoT system is extracted from the database. , the number of test packets uploaded with incorrect tokens ,in , A number that indicates each security level within the IoT system.

[0061] Extract the number of test packets with the correct token sent by the computer server from the database , the number of test packets with error tokens sent .

[0062] In a specific embodiment of the present invention, the calculation of the external network connection security factor of each IoT system is performed by capturing packets on the network to obtain the number of test packets of the correct token uploaded by each IoT system received by the computer server. , the time it takes for the computer server to receive and complete the test data packets uploaded by each IoT system , through the formula: , calculate the compliance judgment value of the time it takes for the computer server to receive and complete the test data packets uploaded by each IoT system ,in, It represents the standard time interval for the computer server to receive the test data packets uploaded by each IoT system extracted from the database, through the formula: , calculate the compliance coefficient of external network data upload of each IoT system .

[0063] According to the analysis method of the compliance coefficient of external network data upload of each IoT system, each test data packet sent by the computer server received by each IoT system is analyzed to obtain the compliance coefficient of external network data reception of each IoT system. .

[0064] It should be noted that, in a specific embodiment, the specific analysis method of the external network data reception compliance coefficient of each IoT system is: by capturing network packets, the number of test data packets of the correct token sent by the computer server end received by each IoT system is obtained. , the number of test packets of error tokens sent by the computer server received by each IoT system , the time it takes for each IoT system to receive the test data packet sent by the computer server , through the formula: , calculate the compliance judgment value of the time taken by each IoT system to receive the test data packet sent by the computer server ,in It represents the standard time interval extracted from the database for each IoT system to receive the test data packet sent by the computer server, through the formula: , calculate the external network data reception compliance coefficient of each IoT system ,in The impact factor of the test data packet representing the unit number of the error tokens sent by the computer server received by each IoT system extracted from the database.

[0065] It should be noted that, in a specific embodiment, during the external network connection test process of the Internet of Things system, the data upload process of the Internet of Things system specifically refers to controlling the gateway device of the Internet of Things system, injecting a large number of test data packets and sending them to the computer server, and the data sending process of the computer server specifically refers to controlling the computer server to generate a large number of test data packets, and performing test data packet analysis on the gateway device of the Internet of Things system.

[0066] By formula: , calculate the external network connection security factor of each IoT system .

[0067] The present invention sets the number of test data packets according to the security level of the internal network of each Internet of Things system, performs network security tests on data upload of each Internet of Things system and data delivery of a computer server, evaluates whether there are identity authentication problems and access timeouts, and analyzes the security factor of the external network connection of the Internet of Things system, thereby ensuring the scientific nature of the network security test in the process of connection between each Internet of Things system and the computer server, setting the number of test data packets in a graded manner, and improving the efficiency of the network security test of the computer server.

[0068] In a specific embodiment of the present invention, the security level of the computer network is comprehensively evaluated, and the specific analysis method is as follows: based on the security level of the internal network of each Internet of Things system, the influencing factors corresponding to the security level of the internal network of each Internet of Things system are extracted from the database. .

[0069] It should be noted that, in a specific embodiment, the specific analysis method of the influencing factors corresponding to the security level of the internal network of each Internet of Things system is: If the security level of the internal network of an IoT system is first, The impact factor of the internal network of the IoT system is set as .

[0070] Jordi If the security level of the internal network of an IoT system is second class, The impact factor of the internal network of the IoT system is set as .

[0071] Jordi If the security level of the internal network of an IoT system is level three, The impact factor of the internal network of the IoT system is set as .

[0072] External network connection security factor based on each IoT system , through the formula: , calculate the computer network security coefficient .

[0073] like If the computer network is in the first security zone extracted from the database, the security level of the computer network is determined to be excellent.

[0074] like If the computer network is in the second security zone extracted from the database, the security level of the computer network is determined to be good.

[0075] like If the computer network is in the third security zone extracted from the database, the security level of the computer network is determined to be unqualified.

[0076] It should be noted that, in a specific embodiment, the security intervals of the computer network are manually set by technical personnel based on historical computer network security factors and actual operation conditions of the computer network, and stored in a database.

[0077] The present invention comprehensively evaluates the security level of computer networks based on the security factor of the internal network of each Internet of Things system and the security factor of the external network connection, taking into account the risks within the Internet of Things system and the risks in the process of connecting the Internet of Things system with the computer server, and analyzing and evaluating the computer network in multiple modes, thereby improving the accuracy of security testing and evaluation of computer networks, helping to promptly discover potential security risks in computer networks and solve them in a timely manner, thereby ensuring the safe operation of computer networks.

[0078] Embodiment 2 Reference Figure 2 As shown, the second aspect of the present invention provides a method for computer network security testing and evaluation, and the method is specifically as follows: Step 1, obtaining each monitoring parameter set of each Internet of Things system.

[0079] Step 2: Conduct internal network tests on each IoT system to assess the security level of the internal network of each IoT system.

[0080] Step 3: Set the external network test parameters of each IoT system.

[0081] Step 4: Calculate the external network connection security factor of each IoT system.

[0082] Step 5: Comprehensively evaluate the security level of the computer network and display the security level of the computer network on the terminal device.

[0083] The above contents are merely examples and explanations of the concept of the present invention. Those skilled in the art may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they shall all fall within the protection scope of the present invention.

Claims

1. A computer network security testing and evaluation system, characterized in that: The system comprises: The information acquisition module is used to obtain the monitoring parameter sets of each IoT system, including: the network topology of each IoT system, the environmental parameters of each IoT device in each IoT system, and the historical working parameters; The IoT system internal test module selects the main equipment for internal testing of each IoT system based on the monitoring parameter sets of each IoT system, performs internal network testing of each IoT system, obtains internal network test data of each IoT system, calculates the security factor of the internal network of each IoT system, and evaluates the security level of the internal network of each IoT system; The IoT system external test module sets the external network test parameters of each IoT system based on the security level of the internal network of each IoT system, and calculates the external network connection security factor of each IoT system; The network security comprehensive assessment module comprehensively assesses the security level of computer networks based on the security factor of the internal network and the security factor of external network connections of each IoT system; The early warning display terminal is used to display the comprehensive security level of computer network and issue early warnings to users.

2. A computer network security testing and evaluation system according to claim 1, characterized in that: The specific acquisition method of obtaining the monitoring parameter sets of each Internet of Things system is as follows: Use computer network scanning tools to obtain the network topology diagram of each IoT system connected to the computer server; The magnetic field strength of each IoT device in each IoT system is obtained through fluxmeter detection ,in , Indicates the number of each IoT system, represents the total number of IoT systems, , Indicates the number of each IoT device in the IoT system. Indicates the total number of IoT devices in the IoT system; Use camera equipment to take pictures of the installation locations of each IoT device in each IoT system, and use image recognition technology to determine the location of the first The first Check whether there is an interface feature area in the picture of the installation location of the IoT device. If so, The first The interface security value of each IoT device is set to , otherwise, The first The interface security value of each IoT device is set to , get the interface security value of each IoT device in each IoT system ; The ambient temperature of each IoT device in each IoT system is collected through temperature sensors ; Summarize the magnetic field strength, interface security value and ambient temperature of each IoT device in each IoT system to form the environmental parameters of each IoT device in each IoT system; The historical working parameters of each IoT device in each IoT system are obtained from the database, including the total data received, the total data sent, the packet loss rate and the bit error rate during the monitoring period.

3. A computer network security testing and evaluation system according to claim 2, characterized in that: The specific analysis method for selecting the main device for internal testing of each IoT system is as follows: Based on the network topology of each IoT system, count the total number of adjacent devices of each IoT device in each IoT system ; By analyzing the environmental parameters and historical working parameters of each IoT device in each IoT system, the environmental risk coefficient and working risk coefficient of each IoT device in each IoT system are obtained respectively, and the formula is: , calculate the risk coefficient of each IoT device in each IoT system ,in Represents the impact factor of the number of adjacent IoT devices extracted from the database, Indicates the environmental risk factor of each IoT device in each IoT system. Indicates the working risk coefficient of each IoT device in each IoT system; Based on The risk factor of each IoT device in the IoT system is extracted. The IoT device with the largest risk factor in the IoT system is denoted as The main device for internal testing of the IoT system will The remaining IoT devices in the IoT system are denoted as The slave devices tested internally in each IoT system are used to obtain the master device and the slave devices tested internally in each IoT system.

4. A computer network security testing and evaluation system according to claim 3, characterized in that: The specific analysis method of the environmental risk coefficient and the working risk coefficient of each IoT device in each IoT system is as follows: Based on the magnetic field strength of each IoT device in each IoT system , Interface security value and ambient temperature , through the formula: , calculate the abnormal judgment value of the ambient temperature of each IoT device in each IoT system ,in Represents the standard ambient temperature range of IoT devices extracted from the database, through the formula: , calculate the environmental risk coefficient of each IoT device in each IoT system ,in It indicates the standard magnetic field strength that the IoT device can withstand for normal operation extracted from the database. represents a natural constant; The total amount of data received during the monitoring period of each IoT device in each IoT system , Total data sent , Packet loss rate and bit error rate , through the formula: , calculate the working risk coefficient of each IoT device in each IoT system ,in Indicates the packet loss rate allowed for normal operation of IoT devices extracted from the database. It indicates the bit error rate allowed for normal operation of IoT devices extracted from the database. Indicates the impact factor of the number of times a data unit is received from the database, Indicates the impact factor of the number of times a data unit extracted from the database is sent.

5. A computer network security testing and evaluation system according to claim 4, characterized in that: The internal network test of each Internet of Things system is performed to obtain the internal network test data of each Internet of Things system, and the specific method is: Based on the main device tested within each IoT system, send The number of test packets with the correct token and Number of test packets with wrong tokens; Based on the network topology of each IoT system, the network packet capture technology is used to obtain the test data packet information received by each slave device in the internal test of each IoT system, and the number of slave devices that are not adjacent to the master device and receive the test data packet in each IoT system is counted. ; Count the number of test packets with correct tokens received by each slave device adjacent to the master device under test in each IoT system ,in , Indicates the number of each slave device adjacent to the master device tested within the IoT system. Indicates the total number of slave devices adjacent to the master device under test in the IoT system.

6. A computer network security testing and evaluation system according to claim 5, characterized in that: The specific analysis method for evaluating the security level of the internal network of each IoT system is as follows: The number of slave devices that are not adjacent to the master device and receive the test data packets based on each IoT system , the number of test packets with correct tokens received by each slave device adjacent to the master device tested within each IoT system , through the formula: , calculate the security factor of the internal network of each IoT system ,in The influence factor representing the number of units of slave devices that are not adjacent to the master device and receive the test data packet extracted from the database; like , then determine the The security level of the internal network of the IoT system is first-class, among which It represents the judgment threshold of first-class security of the internal network of the IoT system extracted from the database; like , then determine the The security level of the internal network of the IoT system is second-class, among which represents the judgment threshold of the second-class security of the internal network of the IoT system extracted from the database; like , then determine the The security level of the internal network of each IoT system is third, and the security level of the internal network of each IoT system is obtained.

7. A computer network security testing and evaluation system according to claim 6, characterized in that: The specific analysis method for setting the external network test parameters of each IoT system is as follows: Based on the security level of the internal network of each IoT system, the number of test data packets of the correct token uploaded by each IoT system is extracted from the database. , the number of test packets uploaded with incorrect tokens ,in , Numbers representing the various security levels within the IoT system; Extract the number of test packets with the correct token sent by the computer server from the database , the number of test packets with error tokens sent .

8. A computer network security testing and evaluation system according to claim 7, characterized in that: The specific analysis method for calculating the external network connection security factor of each IoT system is as follows: By capturing packets on the network, we can obtain the number of test packets of correct tokens uploaded by each IoT system received by the computer server. , the time it takes for the computer server to receive and complete the test data packets uploaded by each IoT system , through the formula: , calculate the compliance judgment value of the time it takes for the computer server to receive and complete the test data packets uploaded by each IoT system ,in, It represents the standard time interval for the computer server to receive the test data packets uploaded by each IoT system extracted from the database, through the formula: , calculate the compliance coefficient of external network data upload of each IoT system ; According to the analysis method of the compliance coefficient of external network data upload of each IoT system, each test data packet sent by the computer server received by each IoT system is analyzed to obtain the compliance coefficient of external network data reception of each IoT system. ; By formula: , calculate the external network connection security factor of each IoT system .

9. A computer network security testing and evaluation system according to claim 8, characterized in that: The specific analysis method of the comprehensive evaluation of the security level of the computer network is as follows: Based on the security level of the internal network of each IoT system, the influencing factors corresponding to the security level of the internal network of each IoT system are extracted from the database ; External network connection security factor based on each IoT system , through the formula: , calculate the computer network security coefficient ; like If the computer network is in the first security interval extracted from the database, the security level of the computer network is determined to be excellent; like If the computer network is in the second security interval extracted from the database, the security level of the computer network is determined to be good; like If the computer network is in the third security zone extracted from the database, the security level of the computer network is determined to be unqualified.

10. A method for executing the computer network security test and evaluation system according to any one of claims 1 to 9, characterized in that: The method is specifically as follows: Step 1: Obtain monitoring parameter sets of each IoT system; Step 2: Conduct internal network tests on each IoT system to assess the security level of the internal network of each IoT system; Step 3: Set the external network test parameters of each IoT system; Step 4: Calculate the external network connection security factor of each IoT system; Step 5: Comprehensively evaluate the security level of the computer network and display the security level of the computer network on the terminal device.

Citation Information

Patent Citations

  • A Computer Network Security Testing and Verification Method

    CN113132412B

  • Network Testing System Based on Industrial Internet Security

    CN115801634B