Network security index assessment method for multi-data comprehensive processing
By acquiring the administrator's processing sensitivity and performing real-time weight adjustments, the problem of failure to effectively consider manual operation errors in the prior art is solved, and the accuracy of IoT network security index evaluation is improved.
Patent Information
- Application Number
- CN202510261922.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The existing IoT network security index evaluation method fails to effectively consider manual operation errors, resulting in a decrease in the accuracy of the evaluation results.
By collecting computer cluster historical security processing data, the administrator's processing sensitivity of the evaluation project for different security indexes is obtained, and real-time weight adjustments are made based on this to match the administrator's processing behavior habits.
It improves the accuracy of network security index evaluation, avoids evaluation errors caused by different manual processing, and enhances the evaluation accuracy of the system.
Smart Images

Figure CN119996037A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security assessment, and in particular to a network security index assessment method for comprehensive processing of multiple data. Background Art
[0002] Nowadays, with the popularization of the Internet of Things, more and more industrial management, commercial management and mechanical equipment management use the Internet of Things for centralized network control. Due to the large amount of operation, multiple computer groups are required to realize distributed network management. Although the Internet of Things network management can automatically realize some control functions, it still requires human managers to control in real time and cooperate with the network protection system to maintain the security of the Internet of Things network.
[0003] Among them, the Internet of Things Network Security Index Assessment is an important criterion for obtaining the current Internet of Things network security status. The network security index assessment is a method of conducting a multi-dimensional evaluation of the security status of a specific network environment or digital system through a quantitative indicator system. Its core lies in converting complex network security elements into measurable values, thereby providing a scientific basis for risk identification and defense strategy optimization.
[0004] The traditional evaluation method of IoT cybersecurity index evaluation mainly includes the following steps:
[0005] The first step is to build a network security indicator evaluation system and locate different types of indicators, including primary indicators and secondary indicators. These indicators are composed of corresponding evaluation items, such as the ability to perceive viruses, the speed of discovering threats, and the success rate of resolving threats.
[0006] The second step is to formulate the evaluation weights of various indicators according to their impact on the network;
[0007] The third step is to obtain the current network security index based on the evaluation weights and the monitoring values of the actual evaluation items.
[0008] The above-mentioned evaluation method of the Internet of Things Network Security Index only considers the security assessment of the network system. However, in actual situations, although most of the data processing work is handled by the network system, such as discovering virus threats, in the security management process of large-scale computing clusters, manual operation is required. At this time, the sensitivity of manual operations to various security indicators also indirectly reflects the network security at this time. Different manual operations have different sensitivities to different assessments. Therefore, the processing speed, processing method and processing results in different situations will be different. Therefore, if manual operation is not used as a non-directional factor in the current network assessment, the accuracy of the corresponding assessment results will be greatly reduced.
[0009] In order to address the above problems, there is an urgent need for an IoT network security index evaluation method that can comprehensively process multiple data and take into account human operation errors. Summary of the invention
[0010] The purpose of the present invention is to provide a network security index evaluation method for comprehensive processing of multiple data to solve the problems raised in the above background technology.
[0011] To achieve the above purpose, a network security index evaluation method based on multi-data comprehensive processing is provided, which includes the following steps:
[0012] S1. Collect historical security processing data of computer groups and obtain various security index assessment items And formulate various safety index assessment projects according to the industry's safety operation specifications The initial weight and evaluation metrics;
[0013] S2. Monitor different administrators’ responses to security index assessment items Behavioral habits at the time of use, and obtain administrators' evaluation items for different security indexes Processing sensitivity Hd sensitivity ;
[0014] S3, according to the processing sensitivity Hd sensitivity The numerical value of the administrator's security index assessment project Perform sorting processing;
[0015] S4. Establishing a processing sensitivity threshold Tag Admin Processing Sensitivity Hd sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Mark as risk assessment item
[0016] S5. Obtain various risk assessment items middle
[0017] S6. Establish unit change weights Combined processing sensitivity difference Hs differences Security Index Assessment Project for Administrators The initial weights in Make adaptive changes and obtain real-time weights
[0018] S7, combined with real-time weight And the evaluation indicators obtain the network security status under the current administrator's management status.
[0019] As a further improvement of this technical solution, the safety index evaluation item in S1 is Including threat response capabilities, threat response capabilities, system feedback efficiency, and the completion rate of instructions sent by administrators.
[0020] As a further improvement of the technical solution, the evaluation indicators of the threat response capability include threat discovery speed, threat differentiation speed and threat processing method matching speed;
[0021] The evaluation indicators of the threat response capability include processing speed and processing success rate;
[0022] The evaluation index of the system feedback efficiency includes the real-time feedback speed of the processing results;
[0023] The evaluation index of the completion degree of the instructions sent by the administrator is the ratio of the number of instructions completed to the number of instructions sent by the administrator.
[0024] As a further improvement of this technical solution, the initial weights corresponding to the threat response capability, threat response capability, system feedback efficiency and the completion degree of the administrator's instructions are They are 30%, 35%, 20% and 15% respectively.
[0025] As a further improvement of this technical solution, the administrator obtains the evaluation items for different security indexes in S2. Processing sensitivity Hd sensitivity The method comprises the following steps:
[0026] S2.1、Get administrators to respond to different security index assessment items The results of manual processing;
[0027] S2.2. Through manual review and evaluation by management, the administrator's historical processing process is evaluated for different security indexes. Score the processing results;
[0028] S2.3. Combine the scoring results to obtain the final processing sensitivity Hd sensitivity .
[0029] As a further improvement of the technical solution, the processing sensitivity threshold is formulated in S4 The method comprises the following steps:
[0030] S4.1. Obtain security index assessment items for each administrator Processing sensitivity Hd sensitivity ;
[0031] S4.2. Calculate each safety index assessment item The corresponding average processing sensitivity is the processing sensitivity threshold Where Hd 1 To Hdn for different administrators to evaluate the same security index project Processing sensitivity Hd sensitivity , n is the number of administrators participating in the evaluation.
[0032] As a further improvement of this technical solution, the real-time weight is obtained in S6 The method comprises the following steps:
[0033] S6.1. Obtain each risk assessment item The corresponding processing sensitivity difference Hs differences , the processing sensitivity difference Hs with the largest value differences Mark as target weight change object;
[0034] S6.2. Obtain the processing sensitivity difference Hs corresponding to the target weight change object differences , and calculate and process the sensitivity Hd sensitivity The ratio of is marked as weight change ratio;
[0035] S6.3. Change the real-time weight of the target weight change object according to the weight change ratio According to the corresponding processing sensitivity difference Hs differences Sorting, adding the weight difference after the target weight change object is changed to the processing sensitivity Hd sensitivity Highest ranking safety index assessment items or risk assessment project
[0036] As a further improvement of the technical solution, the unit change weight in S6 The corresponding weight change ratio is 10%.
[0037] As a further improvement of the technical solution, the method for obtaining the network security status under the current administrator management status in S7 includes the following steps:
[0038] S7.1. Assessment of various safety index items The actual numerical values of the corresponding evaluation indicators are obtained;
[0039] S7.2. Calculate the probability of successful events corresponding to each evaluation indicator = number of successful events / total number of events;
[0040] S7.3 Safety index assessment items The success event probabilities corresponding to the various evaluation indicators are superimposed and marked as the total success event probability;
[0041] S7.4. Combined with the corresponding real-time weight Calculate the current administrator's management of the computing group status
[0042] Compared with the prior art, the present invention has the following beneficial effects:
[0043] In the network security index evaluation method of multi-data comprehensive processing, the processing sensitivity of the administrator for different security index evaluation items is obtained, and the real-time weights of different administrators for different security index evaluation items are updated according to the processing sensitivity to match the processing behavior habits of the administrator. Through multi-data comprehensive processing, the network security index of different administrators when performing management work is adaptively evaluated, avoiding evaluation errors caused by different manual processing and improving the evaluation accuracy of the overall system. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is a flow chart of the overall method of the present invention;
[0045] Figure 2 A step diagram of a method for obtaining the processing sensitivity of an administrator for different security index assessment items according to the present invention;
[0046] Figure 3 A diagram of the steps of the method for formulating a processing sensitivity threshold of the present invention;
[0047] Figure 4 A step diagram of a method for obtaining real-time weights according to the present invention;
[0048] Figure 5 This is a step diagram of the method for obtaining the network security status under the current administrator management status of the present invention. DETAILED DESCRIPTION
[0049] The following will be combined with the accompanying drawings in the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] See also Figure 1 As shown, a network security index evaluation method for comprehensive processing of multiple data is provided, comprising the following steps:
[0051] S1. Collect historical security processing data of computer groups and obtain various security index assessment items And formulate various safety index assessment projects according to the industry's safety operation specifications The initial weight and evaluation metrics;
[0052] S2. Monitor different administrators’ responses to security index assessment items Behavioral habits at the time of use, and obtain administrators' evaluation items for different security indexes Processing sensitivity Hd sensitivity ;
[0053] S3, according to the processing sensitivity Hd sensitivity The numerical value of the administrator's security index assessment project Perform sorting processing;
[0054] S4. Establishing a processing sensitivity threshold Tag Admin Processing Sensitivity Hd sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Mark as risk assessment item
[0055] S5. Obtain various risk assessment items middle
[0056] S6. Establish unit change weights Combined processing sensitivity difference Hs differences Security Index Assessment Project for Administrators The initial weights in Make adaptive changes and obtain real-time weights
[0057] S7, combined with real-time weight And the evaluation indicators obtain the network security status under the current administrator's management status.
[0058] When evaluating the network security index, in order to make reference and adjust to different administrators, we first collect the historical security processing data of the computer group to obtain various security index evaluation items. In the present invention, the safety index evaluation items are Including threat response capabilities, threat response capabilities, system feedback efficiency, and the completion of instructions sent by administrators;
[0059] The evaluation indicators of threat response capability include threat discovery speed, threat differentiation speed, and threat handling method matching speed, that is, starting from threat discovery, then differentiating the threat type, and finally matching the corresponding handling method according to the differentiated threat type. The shorter the time spent, the stronger the threat response capability.
[0060] The evaluation indicators of threat response capabilities include processing speed and processing success rate;
[0061] Evaluation indicators of system feedback efficiency include real-time feedback speed of processing results;
[0062] The evaluation index of the completion of the instructions sent by the administrator is the ratio of the number of instructions completed to the number of instructions sent by the administrator;
[0063] After completing the planning of the evaluation indicators, formulate various safety index evaluation projects according to the industry safety operation specifications. The initial weight That is, combining historical network security assessment data and evaluating projects according to various security indexes Plan the corresponding initial weights according to the impact on network security In this solution, the initial weights of threat response capability, threat response capability, system feedback efficiency, and the completion degree of the administrator's instructions are They are 30%, 35%, 20% and 15% respectively.
[0064] Since different managers have different behavioral habits and ways of dealing with network security, when the entire network security management process requires manual operations by administrators, different results will be produced due to the diversity of manual operations, affecting the subsequent network security index evaluation results. Therefore, it is necessary to monitor the security index evaluation items of different administrators. For example, the system matches multiple solutions based on threat types, which need to be manually selected. Due to the different processing methods required in different situations, operators need to select them according to the actual situation. The selected processing method will affect the final processing result. Therefore, it is necessary to obtain the administrator's historical processing results for different security index assessment items. Processing sensitivity Hd sensitivity ,like Figure 2 As shown, the processing is as follows:
[0065] First, obtain the administrator's response to different security index assessment items The manual processing results, such as the success rate of selecting the appropriate threat handling method, are manually reviewed and evaluated by the management, and the administrator's historical processing process is evaluated for different security indexes. The processing results are scored, and the final processing sensitivity Hd is obtained by combining the scoring results. sensitivity For example, in the threat response capability assessment, the administrator's final assessment score is 90, with a full score of 100. At this time, the administrator has The obtained processing sensitivity Hd sensitivity0.9, used as the initial weight for later adjustment The basis for
[0066] Finished processing sensitivity Hd sensitivity After the determination of Adjust and set initial weights Adjustment method, first need to follow the processing sensitivity Hd sensitivity The numerical value of the administrator's security index assessment project Perform sorting processing, that is, processing sensitivity Hd sensitivity The higher the security index, the higher the administrator's security index. The better the performance, the more outstanding the processing results, which will affect the final evaluation of the network security index;
[0067] In order to further improve the accuracy of the evaluation, this scheme formulates the processing sensitivity threshold Tag Admin Processing Sensitivity Hd sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Mark as risk assessment item like Figure 3 The specific contents are as follows:
[0068] First, the corresponding processing sensitivity threshold The decision is made by all administrators currently serving the computer group, and each administrator is asked to evaluate the security index. Processing sensitivity Hd sensitivity , calculate each safety index assessment item The corresponding average processing sensitivity is the processing sensitivity threshold Where Hd 1 To Hdn for different administrators to evaluate the same security index project Processing sensitivity Hd sensitivity , n is the number of administrators participating in the evaluation. After the evaluation, there will be a threshold below the processing sensitivity threshold. In this case, the processing sensitivity Hd in the mark administrator sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Mark as risk assessment item And calculate
[0069] When administrators respond to security index assessment projects Risk assessment items appeared in At this point, we need to give its initial weight Make changes due to a risk assessment project Initial weights appear Change, remaining safety index assessment items or risk assessment project Adjustments will also be sent accordingly, so the unit change weights are set Unit change weights in this scheme 1%, that is, the minimum value of each change is 1%, such as Figure 4 The specific changes are as follows:
[0070] First obtain each risk assessment project The corresponding processing sensitivity difference Hs differences The largest value of the processing sensitivity difference Hs differences Mark as the target weight change object, and obtain the processing sensitivity difference Hs corresponding to the target weight change object differences , and calculate and process the sensitivity Hd sensitivity The ratio of , marked as the weight change ratio, where the unit change weight The corresponding weight change ratio is 10%, that is, when the weight change ratio range is [10%, 20%), the current risk assessment project The initial weight Reduce by 1%. When the weight change ratio is in the range of [20%, 30%), the current risk assessment project The initial weight Reduce by 2%, and so on, then the remaining safety index assessment items need to be or risk assessment project Initial weight Adjustment, according to its corresponding processing sensitivity difference Hd differences Sorting, adding the weight difference after the target weight change object is changed to the processing sensitivity Hd sensitivity Highest ranking safety index assessment items or risk assessment project For example, the processing sensitivity Hd corresponding to threat response capability, threat response capability, system feedback efficiency, and the completion degree of the administrator's instructions sensitivity Hd 3 、Hd 4 、Hd 5 And Hd 6 , the order of size is Hd 5 >Hd 6 >Hd 3 >Hd 4 At this time, the system feedback efficiency of this safety index evaluation project Processing sensitivity Hd sensitivity The highest level of completion of the instructions sent by the administrator is the security index evaluation item Processing sensitivity Hd sensitivity Minimum, and below the processing sensitivity threshold Mark as risk assessment item The final weight change ratio is 15%, which is within the range of [10%, 20%). The weight change is 1%. At this time, the real-time weight of the completion of the administrator's instructions is The ranking of the completion of the instructions sent by the administrator is opposite to the system feedback efficiency. At this time, the real-time weight of the system feedback efficiency is Complete the final real-time weight renew;
[0071] Finally, combined with real-time weight And the evaluation indicators obtain the network security status under the current administrator management status, such as Figure 5 The specific contents are as follows:
[0072] First, we need to evaluate the various safety index items The corresponding evaluation indicators are actually obtained, and the probability of successful events corresponding to each evaluation indicator is calculated = number of successful events / total number of events. For example, there are 900 events that successfully match the corresponding solutions in the threat response capability, and the total number of threat events is 950. Then the probability of successful events for this indicator = 900 / 950 = 95%. Finally, the security index evaluation project The success event probabilities corresponding to the various evaluation indicators in the sum are superimposed and marked as the total success event probability, combined with the corresponding real-time weights Calculate the current administrator's management of the computing group status
[0073] The present invention monitors the behavioral habits of different administrators when dealing with security index assessment items, obtains the administrators' processing sensitivity for different security index assessment items, updates the real-time weights of different administrators for different security index assessment items according to the processing sensitivity, matches the administrators' processing behavioral habits, and adaptively evaluates the network security index of different administrators when performing management work through multi-data comprehensive processing, thereby avoiding evaluation errors caused by different manual processing and improving the evaluation accuracy of the overall system.
[0074] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and descriptions are only preferred examples of the present invention and are not intended to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. A network security index evaluation method based on multi-data comprehensive processing, characterized in that: The steps include: S1. Collect historical security processing data of computer groups and obtain various security index assessment items And formulate various safety index assessment projects according to the industry's safety operation specifications The initial weight and evaluation metrics; S2. Monitor different administrators’ responses to security index assessment items Behavioral habits at the time of use, and obtain administrators' evaluation items for different security indexes Processing sensitivity Hd sensitivity ; S3, according to the processing sensitivity Hd sensitivity The numerical value of the administrator's security index assessment project Perform sorting processing; S4. Establishing a processing sensitivity threshold Tag Admin Processing Sensitivity Hd sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Mark as risk assessment item S5. Obtain various risk assessment items Medium processing sensitivity difference S6. Establish unit change weights Combined processing sensitivity difference Hs differences Security Index Assessment Project for Administrators The initial weights in Make adaptive changes and obtain real-time weights S7, combined with real-time weight And the evaluation indicators obtain the network security status under the current administrator's management status.
2. The network security index evaluation method for multi-data comprehensive processing according to claim 1 is characterized by: The safety index evaluation items in S1 Including threat response capabilities, threat response capabilities, system feedback efficiency, and the completion rate of instructions sent by administrators.
3. The network security index evaluation method for multi-data comprehensive processing according to claim 2 is characterized by: The evaluation indicators of the threat response capability include threat discovery speed, threat differentiation speed and threat processing method matching speed; The evaluation indicators of the threat response capability include processing speed and processing success rate; The evaluation index of the system feedback efficiency includes the real-time feedback speed of the processing results; The evaluation index of the completion degree of the instructions sent by the administrator is the ratio of the number of instructions completed to the number of instructions sent by the administrator.
4. The network security index evaluation method for multi-data comprehensive processing according to claim 3 is characterized by: The initial weights corresponding to the threat response capability, threat response capability, system feedback efficiency, and the completion degree of the administrator's instructions They are 30%, 35%, 20% and 15% respectively.
5. The network security index evaluation method for multi-data comprehensive processing according to claim 1 is characterized by: S2 obtains the administrator's evaluation items for different security indexes Processing sensitivity Hd sensitivity The method comprises the following steps: S2.1、Get administrators to respond to different security index assessment items The results of manual processing; S2.
2. Through manual review and evaluation by management, the administrator's historical processing process is evaluated for different security indexes. Score the processing results; S2.
3. Combine the scoring results to obtain the final processing sensitivity Hd sensitivity .
6. The network security index evaluation method for multi-data comprehensive processing according to claim 1 is characterized by: The processing sensitivity threshold is formulated in S4 The method comprises the following steps: S4.
1. Obtain security index assessment items for each administrator Processing sensitivity Hd sensitivity ; S4.
2. Calculate each safety index assessment item The corresponding processing sensitivity average is the processing sensitivity threshold Among them, Hd1 to Hd n Evaluate projects for the same security index for different administrators Processing sensitivity Hd sensitivity , n is the number of administrators participating in the evaluation.
7. The network security index evaluation method for multi-data comprehensive processing according to claim 1 is characterized by: The S6 obtains the real-time weight The method comprises the following steps: S6.
1. Obtain each risk assessment item The corresponding processing sensitivity difference Hs differences , the processing sensitivity difference Hs with the largest value differences Mark as target weight change object; S6.
2. Obtain the processing sensitivity difference Hs corresponding to the target weight change object differences , and calculate and process the sensitivity Hd sensitivity The ratio of is marked as weight change ratio; S6.
3. Change the real-time weight of the target weight change object according to the weight change ratio According to the corresponding processing sensitivity difference Hs differences Sorting, adding the weight difference after the target weight change object is changed to the processing sensitivity Hd sensitivity Highest ranking safety index assessment items or risk assessment project 8. The network security index evaluation method for multi-data comprehensive processing according to claim 7 is characterized by: Unit weight changes in S6 The corresponding weight change ratio is 10%.
9. The network security index evaluation method for multi-data comprehensive processing according to claim 1 is characterized by: The method for obtaining the network security status under the current administrator management status in S7 comprises the following steps: S7.
1. Assessment of various safety index items The actual numerical values of the corresponding evaluation indicators are obtained; S7.
2. Calculate the probability of successful events corresponding to each evaluation indicator = number of successful events / total number of events; S7.3 Safety index assessment items The success event probabilities corresponding to the various evaluation indicators are superimposed and marked as the total success event probability; S7.
4. Combined with the corresponding real-time weight Calculate the current administrator's management of the computing group status
Citation Information
Patent Citations
Evaluation method of security management and control effectiveness of intranet service data streams
CN108449201A
Multi-attribute decision-making method for energy internet security assessment
CN109784732A
Hospital network security guarantee method and system based on comprehensive evaluation
CN118869350A
Dual network security assessment engine
US20200106799A1