A network security index evaluation method based on multi-data comprehensive processing
By adjusting the real-time weights of the cybersecurity index assessment based on the administrator's processing sensitivity, the problem of inaccurate assessment caused by human error is solved, achieving higher assessment accuracy.
Patent Information
- Application Number
- CN202510261922.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-03-06
AI Technical Summary
Existing methods for evaluating IoT network security indices fail to effectively account for human error, resulting in reduced accuracy of evaluation results.
By collecting historical security processing data of computer clusters, we can obtain the administrator's sensitivity to the security index assessment items, formulate initial weights, adjust real-time weights based on processing sensitivity, and conduct network security status assessments in conjunction with administrator behavior habits.
This improves the accuracy of cybersecurity index assessments, avoids errors caused by different administrator processing methods, and enhances the reliability of assessment results.
Smart Images

Figure CN119996037B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity assessment technology, and more specifically, to a method for assessing cybersecurity index through comprehensive data processing. Background Technology
[0002] With the popularization of the Internet of Things (IoT), more and more industrial management, business management, and machinery equipment management are using IoT for centralized network control. Due to the large amount of operation, multiple computer clusters are needed to achieve distributed network management. Although IoT network management can automatically realize some control functions, it still requires human managers to monitor in real time and work with network protection systems to maintain IoT network security.
[0003] Among them, the Internet of Things (IoT) network security index assessment is an important standard for obtaining the current network security status of IoT. The network security index assessment is a method to evaluate the security status of a specific network environment or digital system in multiple dimensions through a quantitative indicator system. Its core is to transform complex network security elements into measurable values, thereby providing a scientific basis for risk identification and defense strategy optimization.
[0004] The traditional assessment method for IoT network security index mainly includes the following steps:
[0005] The first step is to build a cybersecurity indicator evaluation system, identifying different types of indicators, including primary and secondary indicators. These indicators consist of corresponding evaluation items, such as the ability to detect viruses, the speed of threat detection, and the success rate of threat resolution.
[0006] The second step is to determine the evaluation weights of each indicator based on its impact on the network.
[0007] The third step is to obtain the cybersecurity index under the current state based on the evaluation weights and the monitoring values of the actual evaluation items.
[0008] The aforementioned IoT network security index assessment only considers the security assessment of the network system. However, in reality, although most data processing is handled by the network system, such as detecting virus threats, human intervention is required in the security management of large-scale computing clusters. In this case, the sensitivity of humans to various security indicators indirectly reflects the network security situation. Different humans have different sensitivities to different assessments, so the processing speed, processing methods, and processing results will vary in different situations. Therefore, if human operation is not considered as an undefined factor in the current network assessment, the accuracy of the corresponding assessment results will be greatly reduced.
[0009] To address the aforementioned issues, there is an urgent need for an IoT network security index evaluation method that can take into account the error of human operation through comprehensive processing of multiple data. Summary of the Invention
[0010] The purpose of this invention is to provide a method for evaluating network security index through comprehensive multi-data processing, so as to solve the problems mentioned in the background art.
[0011] To achieve the above objectives, a method for evaluating a network security index through comprehensive multi-data processing is provided, comprising the following steps:
[0012] S1. Collect historical security processing data of the computer cluster and obtain various security index assessment items. In accordance with industry safety operation standards, various safety index assessment items were formulated. initial weights And evaluation indicators;
[0013] S2. Monitor different administrators' responses to security index assessment items. Real-time behavioral habits, obtain administrator assessment items for different security indices. Processing sensitivity Hd sensitivity ;
[0014] S3, according to processing sensitivity Hd sensitivity The numerical value affects the administrator's security index assessment project. Perform sorting processing;
[0015] S4. Define the sensitivity threshold for processing. Handling sensitivity Hd in the tag administrator sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Marked as a risk assessment project
[0016] S5. Obtain various risk assessment items middle
[0017] S6. Determine the weighting of unit changes. Combined with the sensitivity difference Hs differences Security Index Assessment Project for Administrators Initial weights in Make adaptive changes and obtain real-time weights
[0018] S7, Combining Real-Time Weights And the evaluation metrics obtain the network security status under the current administrator's management status.
[0019] As a further improvement to this technical solution, the safety index assessment item in S1 This includes threat response capabilities, threat handling capabilities, system feedback efficiency, and the completion rate of instructions sent by administrators.
[0020] As a further improvement to this technical solution, the evaluation indicators of the threat response capability include threat detection speed, threat differentiation speed, and threat handling method matching speed.
[0021] The assessment indicators for threat response capabilities include processing speed and processing success rate;
[0022] The evaluation indicators for the system feedback efficiency include the real-time feedback speed of the processing results;
[0023] The evaluation metric for the completion rate of instructions sent by the administrator is the ratio of the number of completed instructions to the number of instructions sent by the administrator.
[0024] As a further improvement to this technical solution, the initial weights corresponding to the threat response capability, threat handling capability, system feedback efficiency, and the completion rate of administrator-sent instructions are... The percentages are 30%, 35%, 20%, and 15%, respectively.
[0025] As a further improvement to this technical solution, step S2 involves obtaining the administrator's evaluation items for different security indices. Processing sensitivity Hd sensitivity The method includes the following steps:
[0026] S2.1 Obtain administrator responses to different security index assessment items The result of manual processing;
[0027] S2.2 The management team conducts manual review and evaluation of the administrator's historical processing of different security index items. The processing results are scored;
[0028] S2.3. Based on the scoring results, obtain the final processing sensitivity Hd. sensitivity .
[0029] As a further improvement to this technical solution, a processing sensitivity threshold is defined in step S4. The method includes the following steps:
[0030] S4.1 Obtain the security index assessment items from each administrator. Time-sensitive Hd sensitivity ;
[0031] S4.2 Calculate each safety index assessment item The corresponding average processing sensitivity is the processing sensitivity threshold. Hd1 to Hdn represent different administrators evaluating the same security index. Processing sensitivity Hd sensitivity , where n is the number of administrators participating in the evaluation.
[0032] As a further improvement to this technical solution, the real-time weight is obtained in step S6. The method includes the following steps:
[0033] S6.1 Obtain each risk assessment item The corresponding processing sensitivity difference Hs differences The largest value among them is the difference in processing sensitivity, Hs. differences Mark as the target weight change object;
[0034] S6.2 Obtain the processing sensitivity difference Hs corresponding to the target weight change object. differences And with computational and processing sensitivity Hd sensitivity The ratio is denoted as the weight change ratio;
[0035] S6.3 Change the real-time weight of the target weight according to the weight change ratio. Based on its corresponding processing sensitivity difference Hs differences Sort the data and add the weight difference after the target weight change to the processing sensitivity Hd. sensitivity The highest-ranked security index assessment item Or risk assessment project
[0036] As a further improvement to this technical solution, the unit change weight in S6 The value is 1%, corresponding to a weight change ratio of 10%.
[0037] As a further improvement to this technical solution, the method for obtaining the network security status under the current administrator's management state in S7 includes the following steps:
[0038] S7.1 Assessment of various safety index items The corresponding evaluation indicators were obtained in actual numerical values.
[0039] S7.2 Calculate the probability of success for each evaluation indicator = number of success events / total number of events;
[0040] S7.3, Safety Index Assessment Items The probabilities of success events corresponding to each evaluation indicator are summed and labeled as the total probability of success events.
[0041] S7.4, Combine with the corresponding real-time weights Calculate the current administrator's management status of the computing group.
[0042] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0043] This multi-data integrated processing method for network security index assessment obtains the administrator's processing sensitivity for different security index assessment items, updates the real-time weights of different administrators for different security index assessment items based on the processing sensitivity, matches the administrator's processing behavior habits, and adapts the network security index assessment for different administrators when performing management tasks through multi-data integrated processing, avoiding assessment errors caused by different manual processing and improving the overall system's assessment accuracy. Attached Figure Description
[0044] Figure 1 This is a flowchart illustrating the overall method of the present invention;
[0045] Figure 2 This is a step diagram illustrating the method for obtaining the administrator's processing sensitivity for different security index assessment items according to the present invention;
[0046] Figure 3 This is a flowchart illustrating the steps of the method for setting the sensitivity threshold in this invention.
[0047] Figure 4 This is a flowchart illustrating the method steps for obtaining real-time weights according to the present invention.
[0048] Figure 5 This is a flowchart illustrating the method steps for obtaining the network security status under the current administrator's management state according to the present invention. Detailed Implementation
[0049] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] Please see Figure 1 As shown, a method for evaluating a network security index through comprehensive data processing is provided, including the following steps:
[0051] S1. Collect historical security processing data of the computer cluster and obtain various security index assessment items. In accordance with industry safety operation standards, various safety index assessment items were formulated. initial weights And evaluation indicators;
[0052] S2. Monitor different administrators' responses to security index assessment items. Real-time behavioral habits, obtain administrator assessment items for different security indices. Processing sensitivity Hd sensitivity ;
[0053] S3, according to processing sensitivity Hd sensitivity The numerical value affects the administrator's security index assessment project. Perform sorting processing;
[0054] S4. Define the sensitivity threshold for processing. Handling sensitivity Hd in the tag administrator sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Marked as a risk assessment project
[0055] S5. Obtain various risk assessment items middle
[0056] S6. Determine the weighting of unit changes. Combined with the sensitivity difference Hs differences Security Index Assessment Project for Administrators Initial weights in Make adaptive changes and obtain real-time weights
[0057] S7, Combining Real-Time Weights And the evaluation metrics obtain the network security status under the current administrator's management status.
[0058] In practical use, when evaluating network security indices, and to provide a reference for adjustments made for different administrators, the first step is to collect historical security processing data from the computer cluster to obtain the various security index evaluation items. In this invention, the safety index assessment items This includes threat response capabilities, threat handling capabilities, system feedback efficiency, and the completion rate of instructions issued by administrators;
[0059] The evaluation indicators for threat response capability include threat detection speed, threat differentiation speed, and threat handling method matching speed. That is, from the discovery of a threat, to the differentiation of the threat type, and finally to matching the corresponding handling method according to the differentiated threat type, the time spent is considered. The shorter the time, the stronger the threat response capability.
[0060] Threat response capability assessment metrics include processing speed and success rate;
[0061] Evaluation metrics for system feedback efficiency include the speed of real-time feedback of processing results;
[0062] The evaluation metric for the completion rate of instructions sent by the administrator is the ratio of the number of instructions completed to the number of instructions sent by the administrator.
[0063] After completing the planning of the evaluation indicators, various safety index evaluation items are formulated in accordance with industry safety operation standards. initial weights That is, combining historical cybersecurity assessment data and evaluating various security index items. Based on the degree of impact on cybersecurity, plan the corresponding initial weights. In this scheme, the initial weights correspond to threat response capability, threat handling capability, system feedback efficiency, and the completion rate of administrator-issued commands. The percentages are 30%, 35%, 20%, and 15%, respectively.
[0064] Because different managers have different behavioral habits and approaches to cybersecurity, the varying manual operations required by administrators during the cybersecurity management process will lead to different results, affecting subsequent cybersecurity index assessments. Therefore, it is necessary to monitor different administrators' responses to security index assessment items. The system's behavioral habits at the time, such as matching multiple solutions based on threat type, require manual selection. Since different situations necessitate different approaches, operators must choose based on the actual circumstances. The selected approach will affect the final outcome; therefore, it's necessary to obtain the administrator's historical processing results for different security index assessment items. Processing sensitivity Hd sensitivity ,like Figure 2 As shown, the processing method is as follows:
[0065] First, obtain the administrator's response to different security index assessment projects. The results of manual processing, such as the success rate of selecting appropriate threat handling methods, are subject to manual review and evaluation by management. This includes reviewing the historical processing by administrators for different security index evaluation items. The processing results are scored, and the final processing sensitivity Hd is obtained by combining the scoring results. sensitivity For example, in the assessment of threat response capability, the administrator's final evaluation score is 90 out of 100. In this case, the administrator's performance in the threat response capability security index assessment item... The obtained processing sensitivity Hd sensitivity The initial weight is set at 0.9 for later adjustments. The basis;
[0066] Complete processing sensitivity Hd sensitivity After the determination of the work, in order to facilitate the initial weights later. Adjust and determine initial weights The adjustment method first needs to be based on the processing sensitivity Hd. sensitivity The numerical value affects the administrator's security index assessment project. Perform sorting processing, i.e., process sensitivity Hd sensitivity A higher value indicates that the administrator has achieved the best performance in this security index assessment item. The better the performance and the more outstanding the processing results, the more it will affect the final cybersecurity index assessment.
[0067] To further improve the accuracy of the assessment, this scheme establishes a processing sensitivity threshold. Handling sensitivity Hd in the tag administrator sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Marked as a risk assessment project like Figure 3 As shown, its specific content is as follows:
[0068] First, the corresponding processing sensitivity threshold. The decision is made jointly by all administrators currently serving the computer cluster, obtaining information from each administrator regarding the security index assessment items. Time-sensitive Hd sensitivity Calculate each safety index assessment item The corresponding average processing sensitivity is the processing sensitivity threshold. Hd1 to Hdn represent different administrators evaluating the same security index. Processing sensitivity Hd sensitivity Where n is the number of administrators participating in the evaluation, and after the evaluation, the number of administrators will fall below the sensitivity threshold. In this situation, the administrator handles the sensitivity Hd. sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Marked as a risk assessment project And calculate
[0069] When administrators deal with security index assessment projects Risk assessment projects have emerged. At this point, it is necessary to set its initial weights. Changes were made due to a risk assessment project. Initial weights appeared Changes to the remaining safety index assessment items Or risk assessment project Adjustments will also be sent accordingly, therefore the weighting will be changed by the designating unit. The unit change weight in this plan The value is 1%, meaning the minimum change value is 1%. Figure 4 As shown, the specific changes are as follows:
[0070] First, obtain the various risk assessment projects. The corresponding processing sensitivity difference Hs differences The size of the value, and the processing sensitivity difference Hs with the largest value. differences Mark the target weight change object and obtain the processing sensitivity difference Hs corresponding to the target weight change object. differences And with computational and processing sensitivity Hd sensitivity The ratio, denoted as the weight change ratio, is the unit change in weight. The corresponding weight change ratio is 10%, meaning that when the weight change ratio ranges from [10%, 20%), the current risk assessment project... initial weights A 1% reduction, when the weight change ratio ranges from [20%, 30%), in the current risk assessment project. initial weights Reduce by 2%, and so on. At this point, it is necessary to evaluate the remaining safety index items. Or risk assessment project Perform initial weights Adjust according to the corresponding processing sensitivity difference Hd differences Sort the data and add the weight difference after the target weight change to the processing sensitivity Hd. sensitivity The highest-ranked security index assessment item Or risk assessment project For example, threat response capability, threat handling capability, system feedback efficiency, and the processing sensitivity corresponding to the completion rate of administrator-issued instructions (Hd). sensitivity The values are Hd3, Hd4, Hd5, and Hd6, with the order of magnitude being Hd5 > Hd6 > Hd3 > Hd4. In this case, the system feedback efficiency is considered a security index evaluation item. Processing sensitivity Hd sensitivity The highest level of security index assessment is the completion rate of commands sent by the administrator. Processing sensitivity Hd sensitivity The lowest, and below the processing sensitivity threshold. Marked as a risk assessment project The final weight change ratio is 15%, which falls within the range of [10%, 20%). The weight of the change is 1%. Therefore, the real-time weight of the administrator's command completion rate at this point is... The ranking of administrator command completion rates is opposite to the ranking of system feedback efficiency, where the real-time weight of system feedback efficiency is... Complete the final real-time weighting renew;
[0071] Finally, combine real-time weights And evaluation metrics to obtain the network security status under the current administrator's management status, such as Figure 5 As shown, its specific content is as follows:
[0072] First, it is necessary to evaluate each safety index item. The corresponding evaluation indicators are obtained with actual values. The success probability for each evaluation indicator is calculated as: Number of successful events / Total number of events. For example, in threat response capability, there are 900 events where the corresponding solution was successfully matched, while the total number of threat events is 950. Therefore, the success probability for this indicator is 900 / 950 = 95%. Finally, the security index evaluation items are... The probabilities of success events corresponding to various evaluation indicators are summed and labeled as the total probability of success events, combined with the corresponding real-time weights. Calculate the current administrator's management status of the computing group.
[0073] This invention monitors the behavioral habits of different administrators when dealing with security index assessment items, obtains the sensitivity of administrators to different security index assessment items, updates the real-time weights of different administrators for different security index assessment items based on the processing sensitivity, matches the administrators' processing behavior habits, and performs adaptive assessment of network security index when different administrators perform management work through comprehensive processing of multiple data, avoiding assessment errors caused by different manual processing and improving the overall system assessment accuracy.
[0074] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for evaluating a network security index through comprehensive multi-data processing, characterized in that, Includes the following steps: S1. Collect historical security processing data of the computer cluster and obtain various security index assessment items. In accordance with industry safety operation standards, various safety index assessment items were formulated. initial weights And evaluation indicators; S2. Monitor different administrators' responses to security index assessment items. Real-time behavioral habits, obtain administrator assessment items for different security indices. Processing sensitivity Hd sensitivity ; S3, according to processing sensitivity Hd sensitivity The numerical value affects the administrator's security index assessment project. Perform sorting processing; S4. Define the sensitivity threshold for processing. Handling sensitivity Hd in the tag administrator sensitivity Below the processing sensitivity threshold Corresponding safety index assessment items Marked as a risk assessment project S5. Obtain various risk assessment items In the processing of sensitivity difference S6. Determine the weighting of unit changes. Combined with the sensitivity difference Hs differences Security Index Assessment Project for Administrators Initial weights in Make adaptive changes and obtain real-time weights S7, Combining Real-Time Weights And the evaluation metrics obtain the network security status under the current administrator's management status.
2. The network security index evaluation method for multi-data integrated processing according to claim 1, characterized in that: The safety index assessment items in S1 This includes threat response capabilities, threat handling capabilities, system feedback efficiency, and the completion rate of instructions sent by administrators.
3. The network security index evaluation method for multi-data integrated processing according to claim 2, characterized in that: The assessment metrics for threat response capabilities include threat detection speed, threat differentiation speed, and threat handling method matching speed. The assessment indicators for threat response capabilities include processing speed and processing success rate; The evaluation indicators for the system feedback efficiency include the real-time feedback speed of the processing results; The evaluation metric for the completion rate of instructions sent by the administrator is the ratio of the number of completed instructions to the number of instructions sent by the administrator.
4. The network security index evaluation method for multi-data integrated processing according to claim 3, characterized in that: The initial weights corresponding to threat response capability, threat handling capability, system feedback efficiency, and the completion rate of administrator-issued instructions are described. The percentages are 30%, 35%, 20%, and 15%, respectively.
5. The network security index evaluation method for multi-data integrated processing according to claim 1, characterized in that: S2 retrieves the administrator's evaluation items for different security indices. Processing sensitivity Hd sensitivity The method includes the following steps: S2.1 Obtain administrator responses to different security index assessment items The result of manual processing; S2.2 The management team conducts manual review and evaluation of the administrator's historical processing of different security index items. The processing results are scored; S2.
3. Based on the scoring results, obtain the final processing sensitivity Hd. sensitivity .
6. The network security index evaluation method for multi-data integrated processing according to claim 1, characterized in that: The processing sensitivity threshold is defined in S4. The method includes the following steps: S4.1 Obtain the security index assessment items from each administrator. Time-sensitive Hd sensitivity ; S4.2 Calculate each safety index assessment item The corresponding average processing sensitivity is the processing sensitivity threshold. Among them, Hd1 to Hd n For different administrators to evaluate the same security index project Processing sensitivity Hd sensitivity , where n is the number of administrators participating in the evaluation.
7. The network security index evaluation method for multi-data integrated processing according to claim 1, characterized in that: The real-time weight is obtained in S6. The method includes the following steps: S6.1 Obtain each risk assessment item The corresponding processing sensitivity difference Hs differences The largest value among them is the difference in processing sensitivity, Hs. differences Mark as the target weight change object; S6.2 Obtain the processing sensitivity difference Hs corresponding to the target weight change object. differences And calculate and process the sensitivity Hd sensitivity The ratio is denoted as the weight change ratio; S6.3 Change the real-time weight of the target weight according to the weight change ratio. Based on its corresponding processing sensitivity difference Hs differences Sort the data and add the weight difference after the target weight change to the processing sensitivity Hd. sensitivity The highest-ranked security index assessment item Or risk assessment project 8. The network security index evaluation method for multi-data integrated processing according to claim 7, characterized in that: The unit change weight in S6 The value is 1%, corresponding to a weight change ratio of 10%.
9. The network security index evaluation method for multi-data integrated processing according to claim 1, characterized in that: The method for obtaining the network security status under the current administrator management status in S7 includes the following steps: S7.1 Assessment of various safety index items The corresponding evaluation indicators were obtained in actual numerical values. S7.2 Calculate the probability of success for each evaluation indicator = number of success events / total number of events; S7.3, Safety Index Assessment Items The probabilities of success events corresponding to each evaluation indicator are summed and labeled as the total probability of success events. S7.4, Combine with the corresponding real-time weights Calculate the network security assessment score for the current administrator-managed computing group status = real-time weighting x. Total probability of successful events.
Citation Information
Patent Citations
Multi-attribute decision-making method for energy internet security assessment
CN109784732A
Hospital network security guarantee method and system based on comprehensive evaluation
CN118869350A