Method and system for evaluating capability maturity of industrial internet data security

By identifying multi-dimensional security data at edge nodes of the industrial Internet, using OpenVAS tools to conduct comprehensive vulnerability scanning and Bayesian network to build an attack path probability matrix, the problem of incomplete vulnerability identification and risk assessment in the existing technology is solved, and a comprehensive vulnerability identification and risk assessment of the industrial Internet system is achieved, and the system's security and protection efficiency are improved.

CN119996078AActive Publication Date: 2025-05-13SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD

Patent Information

Application Number
CN202510450415.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-05-13
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

The existing industrial Internet data security capabilities maturity assessment methods lack comprehensive vulnerability scanning and risk assessment, and cannot effectively identify and evaluate potential security vulnerabilities and attack paths, resulting in failure to detect and repair security risks in a timely manner.

Method used

By identifying multi-dimensional security data at edge nodes of the industrial Internet, integrating and mapping relationship analysis, obtaining digital twins, using OpenVAS tool to perform comprehensive vulnerability scanning, calculating CVSS scores, dynamically quantifying node connectivity weights, building an attack path probability matrix based on Bayesian network, generating an attack script, conducting simulation attack tests, building a five-dimensional evaluation matrix, and computing power maturity scores.

Benefits of technology

It realizes comprehensive vulnerability identification and risk assessment of industrial Internet systems, provides accurate security risk attributes and attack path probability, helps to formulate targeted protection strategies, and improves the security and protection efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996078A_ABST
    Figure CN119996078A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data processing, and discloses an industrial internet data security capability maturity evaluation method and system, and the method comprises the steps: recognizing multi-dimensional security data at an industrial internet edge node; integrating the multi-dimensional security data and carrying out mapping relation analysis to obtain a digital twinborn body; scanning the digital twin by using a vulnerability scanning tool to obtain node vulnerability data, and calculating a CVSS score; dynamically quantifying node connectivity weights based on connectivity and vulnerability heterogeneity of the nodes; performing risk assessment based on the node connectivity weight in combination with the CVSS score to obtain a node risk attribute of each node; constructing an attack path probability matrix of the digital twin through a Bayesian network; embedding the obtained node risk attribute and the attack path probability matrix into a digital twinborn body to obtain a digital twinborn simulation model; through the combination of a plurality of technical links, the capability maturity of industrial internet data security is effectively evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and more specifically, to a capability maturity assessment method and system for industrial Internet data security. Background Art

[0002] The patent with patent publication number CN103077426A discloses a method and system for assisting in evaluating the maturity of information security capabilities. The method includes the steps of: pre-defining a maturity assessment database, which includes: an information security construction maturity model, a model construction field, a construction direction of the construction field, specific assessment indicators of the construction direction, and specific value ranges and satisfaction conditions of the construction indicators; establishing a customer information security maturity assessment model based on customer needs and the maturity assessment database; maintaining customer information, and setting and optimizing indicator values; outputting an assessment report by obtaining specific assessment indicator information and combining various maintained data information, thereby realizing unified customer information security information collection, classification, and automatic inheritance, scientifically defining a capability maturity assessment model, reducing dependence on experts, and providing convenience for evaluating information security capability maturity.

[0003] The traditional capability maturity assessment method for industrial Internet data security has the following main problems: Without using tools like OpenVAS for comprehensive vulnerability scanning, only security vulnerabilities of some nodes may be identified, and other potential vulnerabilities may be missed. In this case, security vulnerabilities in digital twins may be underestimated, resulting in the failure to discover and repair security risks in a timely manner. Especially in large-scale digital twin systems, there may be multiple interactive nodes, and incomplete vulnerability scanning will increase the risk of system attacks; if vulnerabilities are not scored by CVSS, the severity assessment of vulnerabilities may be affected by human subjective factors, resulting in incorrect risk judgment. Without quantitative vulnerability assessment standards, it is difficult to reasonably assign priorities to vulnerabilities, resulting in the most serious vulnerabilities not being repaired in time, affecting the security of the entire system; simple risk assessment methods can only focus on the vulnerability of the node itself, while ignoring the connectivity of the node with other nodes. For nodes with high connectivity, their potential impact may be greater than that of isolated nodes. The lack of comprehensive risk analysis may result in the same assessment results for low-risk nodes and high-risk nodes, affecting the accuracy of decision-making; the connection relationship between nodes is not included in the risk assessment, and the importance of some nodes may be ignored; due to the lack of quantitative data support, the priority arrangement of vulnerability repair may be unreasonable, thus affecting the repair efficiency. The system may waste resources on low-priority vulnerabilities while ignoring high-priority and high-impact vulnerabilities; security decisions often rely on human judgment. Due to the limited knowledge of personnel, the accuracy and efficiency of decisions may be affected. Human judgment is easily limited by personal experience and understanding, which may lead to misjudgment and thus affect the security of the entire system; Without the representation of dependencies between nodes, the potential impact between different nodes may be ignored. The relationship between nodes may be complex and uncertain. The lack of Bayesian network modeling cannot clearly reflect these dependencies, resulting in insufficient accuracy in security analysis and decision-making. Especially when facing complex attack paths, this dependency is likely to be ignored, which ultimately makes the security assessment incomplete; the occurrence of attack paths is usually accompanied by a high degree of uncertainty, especially when facing new types of attacks. The lack of Bayesian network-based modeling makes it impossible to quantify the probability of occurrence of different events in the attack path, and it is also impossible to effectively assess the risk of the attack, resulting in the defense strategy being unable to effectively adapt to different attack scenarios, reducing the flexibility and effectiveness of protection; the lack of priority sorting of attack paths will lead to a lack of targeted protection strategy design, which may be too broad or too narrow. Unable to adjust resource allocation and security control based on the probability of attack and the priority of the path, the defense strategy may fail to effectively intercept high-risk attack paths at critical moments.

[0004] In view of this, the present invention proposes a capability maturity assessment method and system for industrial Internet data security to solve the above problems. Summary of the invention

[0005] In order to overcome the above-mentioned defects of the prior art and to achieve the above-mentioned purpose, the present invention provides the following technical solution: a method for evaluating the capability maturity of industrial Internet data security, comprising: S1. Identify multi-dimensional security data at the edge nodes of the Industrial Internet; S2. Integrate multi-dimensional security data and perform mapping relationship analysis to obtain digital twins; use vulnerability scanning tools to scan digital twins, obtain node vulnerability data, and calculate CVSS scores; dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; construct an attack path probability matrix for digital twins through a Bayesian network; embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; S3. Use the ATT&CK framework to build attack paths for each node of the digital twin simulation model and generate attack scripts. Perform simulation attack tests on the digital twin simulation model according to the attack scripts and collect simulation test data through the ELK technology stack. S4. Construct a five-dimensional evaluation matrix based on the simulation test data, use the entropy weight method to calculate the information entropy of each dimension in the five-dimensional evaluation matrix, and obtain the weight of each evaluation dimension; perform a comprehensive calculation of the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform a weighted average to obtain the capability maturity score; S5. Visualize the scenario defense scores and capability maturity scores based on different attack chains.

[0006] Furthermore, the multi-dimensional security data includes physical layer data, logical layer data and business layer data; the physical layer data includes equipment data, network topology data and communication protocol data; the logical layer data includes access control data, identity authentication data and security policy data; the business layer data includes production process data, business dependency data and key business chain data.

[0007] Furthermore, the method for acquiring the digital twin includes: Use a graph database to integrate the acquired physical layer data, logical layer data, and business layer data, and establish a mapping relationship between the physical layer data, logical layer data, and business layer data through association analysis; use the entities contained in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationship between different nodes as edges to build a digital twin.

[0008] Furthermore, the method for obtaining the node risk attribute includes: Use the OpenVAS vulnerability scanning tool to scan the nodes contained in the digital twin, obtain node vulnerability data, and calculate the CVSS score of each vulnerability; perform a weighted average on the CVSS scores of all node vulnerabilities to obtain the node vulnerability score of the node; based on the obtained node vulnerability score, quantify the node risk attributes through the risk assessment formula to obtain the risk attribute score; collect the risk attribute scores of all nodes in the digital twin, and then obtain the node risk attributes of each node.

[0009] Furthermore, the method for obtaining the attack path probability matrix includes: The Bayesian network is used for modeling to represent the dependency relationship between each node and the attack path. Each node in the digital twin simulation model is defined as an attack step, and the connection relationship between the nodes is defined as the dependency relationship between the attack steps. The conditional probability of each node is obtained according to the risk attribute score of each node through the Bayesian network. The attack path probability is obtained based on the conditional probability of each node. The attack path probability of each attack path is collected to construct an attack path probability matrix. Each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path. The elements of the attack path probability matrix are the probabilities of the attack step occurring successfully.

[0010] Furthermore, the method for generating an attack script includes: Use the tactics and technical classification of the ATT&CK framework to define typical attack scenarios for the Industrial Internet; define the attack target, attack technology, attack method, and expected impact for each typical attack scenario to form a structured attack template and obtain a scenario library; Based on the acquired node risk attributes and attack path probability matrix, different attack paths are generated through the A* algorithm. The scenario library obtained by combining the ATT&CK framework is used to match typical attack scenarios for each attack path, and then the attack chain is obtained. All attack chains are collected to obtain the attack script.

[0011] Furthermore, the simulation test data includes vulnerability exploitation success rate, response handling time, service recovery time, detection success rate and node status.

[0012] Furthermore, the method for obtaining the capability maturity score includes: The obtained simulation test data is processed by range normalization and mapped to five evaluation dimensions to form a five-dimensional evaluation matrix; the five evaluation dimensions include defense strength, response efficiency, recovery capability, detection accuracy and business continuity; each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension; the entropy weight method is used to calculate the information entropy of each dimension in the five-dimensional evaluation matrix to obtain the weight of each evaluation dimension; there are preset Groups of simulation test data, each group of simulation test data corresponds to a different attack chain; comprehensive calculation is performed based on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense scores under different attack chains; the scenario defense scores under different attack chains are weighted averaged to obtain the capability maturity score.

[0013] Furthermore, the method for visually displaying scenario defense scores and capability maturity scores based on different attack chains includes: The scenario defense score corresponding to each set of simulation test data is associated with the attack chain and mapped to the corresponding digital twin simulation model nodes and edges. A capability maturity visualization display interface is built through visualization tools, and the capability maturity score is displayed in the form of a dashboard. The simulation test data and scenario defense scores under different attack chains are dynamically loaded.

[0014] Furthermore, a capability maturity assessment system for industrial Internet data security includes: Data perception unit, used to identify multi-dimensional security data at the edge nodes of the Industrial Internet; The digital twin unit is used to integrate multi-dimensional security data and perform mapping relationship analysis to obtain a digital twin; use vulnerability scanning tools to scan the digital twin, obtain node vulnerability data, and calculate CVSS scores; dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; construct an attack path probability matrix for the digital twin through a Bayesian network; embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; The simulation response unit uses the ATT&CK framework to build attack paths for each node of the digital twin simulation model and generate attack scripts. It performs simulation attack tests on the digital twin simulation model based on the attack scripts and collects simulation test data through the ELK technology stack. The maturity quantification unit is used to construct a five-dimensional evaluation matrix based on simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method, and obtain the weight of each evaluation dimension; comprehensively calculate the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score; The visualization unit provides a visual display of scenario defense scores and capability maturity scores based on different attack chains.

[0015] The technical effects and advantages of the method and system for evaluating the capability maturity of industrial Internet data security provided by the present invention are as follows: Through the OpenVAS tool, a comprehensive vulnerability scan is performed on each node in the digital twin. It is possible to identify the possible security vulnerabilities of each node, obtain detailed vulnerability data, and quantitatively evaluate the severity of the vulnerability based on the CVSS score, providing a solid foundation for subsequent risk analysis and decision-making; a more accurate risk assessment of the node is performed based on the severity and importance of the vulnerability; the introduction of the risk assessment formula provides a quantitative score for the risk attribute of the node by comprehensively considering the node's connectivity, the number of node vulnerabilities, and the CVSS score of each vulnerability, which can intuitively reflect the security risk of the node; the introduction of the node connectivity weight coefficient takes into account the importance of the node itself and the connection relationship with other nodes, taking into account not only the vulnerability of the node itself, but also the relationship between the node and other nodes, making the risk assessment more comprehensive; Through the Bayesian network, the dependencies between nodes can be clearly represented, and the conditional probability of each node can be calculated based on the risk attribute score of the node. This modeling method can accurately capture the interdependence between different attack steps and reflect the uncertainty in the attack process; by constructing the attack path probability matrix, the probability of occurrence of each step in each attack path can be quantified. This provides data support for the priority sorting of attack paths and the optimization of attack protection strategies; based on the three-level simulation model, the relationship between the physical environment and the digital model can be accurately mapped, and different security scenarios can be simulated and analyzed, which enables a detailed digital representation of each node, connection and its interactive relationship in the industrial Internet system. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A flowchart of a method for evaluating the capability maturity of industrial Internet data security according to the present invention; Figure 2 A schematic diagram of the structure of a capability maturity assessment system for industrial Internet data security according to the present invention; Figure 3 A flow chart for constructing the digital twin simulation model provided by the present invention. DETAILED DESCRIPTION

[0017] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0018] Example 1 See also Figure 1 and Figure 3As shown, the present embodiment provides a method for assessing the capability maturity of industrial Internet data security, including: S1. Identify multi-dimensional security data at the edge nodes of the Industrial Internet; S2. Integrate multi-dimensional security data and perform mapping relationship analysis to obtain digital twins; use vulnerability scanning tools to scan digital twins, obtain node vulnerability data, and calculate CVSS scores; dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; construct an attack path probability matrix for digital twins through a Bayesian network; embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; S3. Use the ATT&CK framework to build attack paths for each node of the digital twin simulation model and generate attack scripts. Perform simulation attack tests on the digital twin simulation model according to the attack scripts and collect simulation test data through the ELK technology stack. S4. Construct a five-dimensional evaluation matrix based on the simulation test data, use the entropy weight method to calculate the information entropy of each dimension in the five-dimensional evaluation matrix, and obtain the weight of each evaluation dimension; perform a comprehensive calculation of the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform a weighted average to obtain the capability maturity score; S5. Visualize the scenario defense scores and capability maturity scores based on different attack chains.

[0019] Sensors and monitoring devices are deployed at the edge of the Industrial Internet to identify multi-dimensional security data.

[0020] Multidimensional security data includes physical layer data, logical layer data and business layer data; physical layer data includes equipment data, network topology data and communication protocol data; logical layer data includes access control data, identity authentication data and security policy data; business layer data includes production process data, business dependency data and key business chain data.

[0021] Device data includes device type, device model, device status and device location; network topology data includes network device connection information, network link bandwidth, network link delay, network packet loss rate and IP address; communication protocol data includes communication protocol type, communication protocol configuration parameters and communication protocol traffic characteristics; Access control data includes access control lists, user permissions, and firewall rules; identity authentication data includes user account information and authentication logs; security policy data includes security policy documents (such as password complexity requirements, session timeout settings) and security incident response processes (such as vulnerability remediation processes, emergency response plans); Production process data includes production process steps, process dependencies and key process nodes; business dependency data includes the dependency between equipment and business (such as whether a certain equipment failure affects production) and the dependency between business and network (such as whether a certain network link interruption affects business); key business chain data includes key business chains (such as core production lines, key control systems) and the SLA of key business chains (such as availability, response time).

[0022] Methods for obtaining digital twins include: Use a graph database to integrate the acquired physical layer data, logical layer data, and business layer data, and establish a mapping relationship between the physical layer data, logical layer data, and business layer data through association analysis; use the entities contained in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationship between different nodes as edges to build a digital twin.

[0023] It should be noted that: the mapping relationship between physical layer data, logical layer data and business layer data is analyzed through association analysis algorithms (such as Apriori). For example, the relationship between device data and access control data, the relationship between business dependency data and network topology data, etc. The digital twin is constructed by using the relational modeling characteristics of the graph database, and the relationship between data is represented by nodes and edges; Each node in the digital twin represents an entity, which includes but is not limited to physical layer entities: such as devices, sensors, and network devices; logical layer entities: such as access control lists, identity authentication policies, and firewall rules; business layer entities: such as business processes, key business chains, and production processes; edges represent the mapping relationship between each node in the digital twin, such as communication between devices, dependency between devices and business processes, and the impact of access control policies on the business.

[0024] Methods for obtaining node risk attributes include: Use the OpenVAS vulnerability scanning tool to scan the nodes contained in the digital twin, obtain node vulnerability data, and calculate the CVSS score of each vulnerability; perform weighted average of the CVSS scores of all node vulnerabilities to obtain the node vulnerability score of the node; based on the obtained node vulnerability score, quantify the node risk attribute through the risk assessment formula to obtain the risk attribute score; collect the risk attribute scores of all nodes in the digital twin, and then obtain the node risk attribute of each node; CVSS score is an internationally accepted quantitative standard for vulnerability severity, which is composed of multiple indicators and divided into basic score, time score and environment score. As an open source vulnerability scanning tool, OpenVAS will identify the vulnerabilities of each node in the digital twin during the scanning process and provide a CVSS score for each vulnerability. The risk assessment formula is: ;in, scoring risk attributes; is the node connectivity weight coefficient; is the number of edges connected to the node; is the total number of edges in the digital twin; is the total number of node vulnerabilities; The node CVSS score of the vulnerability; The node The weight factor of each vulnerability; The index of the node vulnerability category.

[0025] It should be noted that the risk assessment formula is based on the security data collected by the OpenVAS vulnerability scanning tool, and is quantitatively evaluated in combination with the CVSS score (Common Vulnerability Scoring System), which comprehensively considers the severity of the node's vulnerability and its connectivity in the network; the severity of the vulnerability of each node is quantified through the CVSS score, and the weight factor is used to quantify the severity of the vulnerability of each node. Adjustments are made to reflect the impact of different types of vulnerabilities, and a node connectivity weight coefficient is introduced to reflect the importance of the node in the network. Nodes with high connectivity usually undertake more data transmission or control functions, and once attacked, they will have a greater impact on the security of the overall network.

[0026] The technical effects of the risk assessment formula are mainly reflected in the following aspects: Reliable and scientific data sources: Security data is collected based on the OpenVAS vulnerability scanning tool, and quantitative evaluation is performed in combination with CVSS scores to ensure the reliability of data sources and the scientific nature of evaluation methods, providing a solid data foundation for risk assessment; Comprehensive consideration of multiple factors: The severity of the node's vulnerability and its connectivity in the network are comprehensively considered. It not only focuses on the vulnerability of the node itself, but also takes into account the position and role of the node in the network topology, making the risk assessment more comprehensive and objective, and avoiding the one-sidedness of risk assessment based on only a single factor; Accurate quantification of vulnerability severity: The severity of the vulnerability in each node is quantified through CVSS scoring, and adjusted using weight factors to accurately reflect the actual impact of different types of vulnerabilities. Different types of vulnerabilities have different degrees of harm to the system. This quantification and adjustment method makes the evaluation results more in line with the actual situation and helps to accurately identify high-risk vulnerabilities; Reflecting the importance of node network: Introducing the node connectivity weight coefficient can effectively reflect the importance of nodes in the network. Nodes with high connectivity have more data transmission or control functions, and their security status has a greater impact on the overall network security. The introduction of this coefficient enables the evaluation results to highlight the risks of such key nodes, making it easier for network security managers to give priority to and deal with the security issues of these important nodes.

[0027] The node connectivity weight coefficient is adjusted by the node connectivity weight adjustment formula Adjusting constraints can more comprehensively and accurately assess the risk level of nodes in the network. For example, in a complex network, nodes with many connections and many vulnerability categories will have their weight coefficients increased after being adjusted by the node connectivity weight adjustment formula, highlighting their high risk and providing a reliable basis for risk assessment.

[0028] The node connectivity weight adjustment formula is: ;in, is the adjusted node connectivity weight coefficient; is the number of node connections, indicating the number of direct connections between the node and other nodes, reflecting the connectivity of the node; is the number of vulnerability categories of the node, indicating the number of different types of vulnerabilities existing in the node; is the maximum number of node connections; is the exponential factor of the number of node connections; It should be noted that: The stronger the connectivity of a node, the more active or important the node is in the network structure, and the more frequent the information flow and data interaction are. It also means that the node may become a key channel for attackers to invade or exploit. Therefore, the connectivity of a node is one of the important factors in measuring the potential risk of a node.

[0029] The heterogeneity of node vulnerabilities refers to the number of different types of vulnerabilities that exist in a node. The more types of vulnerabilities there are, the more complex and diverse the threat paths faced by the node are, and the more means attackers can use, thereby increasing the overall risk level of the node. Vulnerability heterogeneity reflects the diversity of node security weaknesses and is an important supplementary indicator for measuring node security risks.

[0030] It reflects the connectivity relationship between nodes and other nodes by introducing an exponential factor , which can control the degree of influence of the number of node connections on the node connectivity weight coefficient. For example, in some scenarios, the growth of the number of node connections may have an exponential impact on the node risk attribute, while in some scenarios it may be linear. Therefore, the use of exponential factors allows the impact of these factors to be adjusted according to different situations. By introducing a logarithmic function to adjust the number of vulnerability categories of the node, it is ensured that the impact of the number of vulnerability categories of the node gradually flattens as the number increases. 2 is added to avoid calculation problems when the number of vulnerability categories of the node is 0, and to make the logarithmic function still sensitive when the number of vulnerability categories of the node is small.

[0031] The methods for obtaining the attack path probability matrix include:

[0032] Modeling is performed through Bayesian networks to represent the dependency between each node and the attack path; each node in the digital twin simulation model is defined as an attack step, and the connection relationship between nodes is defined as the dependency between the attack steps. The conditional probability of each node is obtained according to the risk attribute score of each node through the Bayesian network; the attack path probability is obtained based on the conditional probability of each node; the attack path probability of each attack path is collected to construct an attack path probability matrix; each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path; the elements of the attack path probability matrix are the probabilities of the attack step occurring successfully;

[0033] Set attack path ,in, is the attack path from the initial attack step to the final attack step; is the initial attack step, This is the final attack step; is the index of the attack step sequence, ; Each attack step The probability of occurrence of The probability of the attack path is determined by ;in, Initial attack step The probability of occurrence; Initial attack step After completion, the attack steps The probability of occurrence; Attack Steps After completion, the attack steps probability of occurrence.

[0034] Methods for generating attack scripts include: Use the tactics (such as initial access, execution, persistence) and techniques (such as malicious code injection, protocol tampering) of the ATT&CK framework to define typical attack scenarios of the Industrial Internet (such as PLC logic bomb injection, OPC data tampering); define the attack target, attack technology, attack method and expected impact for each typical attack scenario, form a structured attack template, and then obtain a scenario library; It should be noted that in the industrial Internet environment, the ATT&CK framework can be used to define a series of typical attack scenarios, which describe the tactics and techniques that attackers may use to target industrial control systems (ICS) and networks. The following are several defined typical attack scenarios, including attack targets, attack techniques, attack methods, and expected impacts: Attack scenario 1: PLC logic bomb injection: Attack target: PLC equipment; Attack technology: malicious code injection and persistence; Attack method: write time-triggered malicious logic inside the PLC to disrupt the operation of industrial equipment; Expected impact: production line abnormality, equipment out of control; Attack scenario 2: OPC data tampering: Attack target: SCADA server; Attack technology: protocol tampering, man-in-the-middle attack; Attack method: intercept OPC UA communication, modify sensor data, and cause wrong control instructions; Expected impact: cause erroneous operation, such as wrong temperature control or valve operation; Attack scenario three: firmware backdoor implantation: Attack target: RTU / industrial control equipment; Attack technology: firmware tampering and persistence; Attack method: implant malicious code during the firmware update process to obtain long-term access rights; Expected impact: The attacker can maintain control after the device is restarted; Based on the acquired node risk attributes and attack path probability matrix, different attack paths are generated through the A* algorithm. The scenario library obtained by combining the ATT&CK framework is used to match typical attack scenarios for each attack path, and then the attack chain is obtained. All attack chains are collected to obtain the attack script.

[0035] Example: Attack Path 1: SCADA Server (RCE Vulnerability) PLC (Modbus TCP hijacking) Logic bomb injection; Attack Path 2: HMI (Phishing Attack) SCADA (Remote Services Abuse) OPC server (data tampering).

[0036] The simulation test data includes vulnerability exploitation success rate, response and disposal time, business recovery time, detection success rate and node status; node status includes attacked and paralyzed nodes and normal operating nodes; response and disposal time refers to the time required from the detection of the attack to the successful implementation of defensive measures (such as blocking attack traffic, repairing vulnerabilities, and isolating infected systems); business recovery time refers to the time required for the node to be paralyzed after being attacked to resume normal operation.

[0037] The methods for obtaining capability maturity scores include: The obtained simulation test data is processed by range normalization and mapped to five evaluation dimensions to form a five-dimensional evaluation matrix; the five evaluation dimensions include defense strength, response efficiency, recovery capability, detection accuracy and business continuity; each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension; the entropy weight method is used to calculate the information entropy of each dimension in the five-dimensional evaluation matrix to obtain the weight of each evaluation dimension; there are preset A set of simulation test data, each set of simulation test data corresponds to a different attack chain; based on the five-dimensional evaluation matrix and the weight of each evaluation dimension, a comprehensive calculation is performed to obtain the scenario defense score under different attack chains ;in, Based on Capability maturity score for group simulation test data acquisition; is the index of the simulation test data category; To evaluate the dimension The weight of To evaluate the index of the dimension, ; For the Group simulation test data in the evaluation dimension The normalized score on the attack chain is obtained by weighted averaging the scenario defense scores under different attack chains to obtain the capability maturity score.

[0038] Methods for visualizing scenario defense scores and capability maturity scores based on different attack chains include: The scenario defense score corresponding to each set of simulation test data is associated with the attack chain and mapped to the corresponding digital twin simulation model nodes and edges. A capability maturity visualization display interface is built through visualization tools, and the capability maturity score is displayed in the form of a dashboard. The simulation test data and scenario defense scores under different attack chains are dynamically loaded.

[0039] In this embodiment, the OpenVAS tool is used to perform a comprehensive vulnerability scan on each node in the digital twin, which can identify the possible security vulnerabilities of each node, obtain detailed vulnerability data, and quantitatively evaluate the severity of the vulnerability according to the CVSS score, providing a solid foundation for subsequent risk analysis and decision-making; a more accurate risk assessment of the node is performed according to the severity and importance of the vulnerability; the introduction of the risk assessment formula provides a quantitative score for the risk attribute of the node by comprehensively considering the node's connectivity, the number of node vulnerabilities, and the CVSS score of each vulnerability, which can intuitively reflect the security risk of the node; the introduction of the node connectivity weight coefficient takes into account the importance of the node itself and the connection relationship with other nodes, and not only takes into account the vulnerability of the node itself, but also takes into account the relationship between the node and other nodes, making the risk assessment more comprehensive; Through the Bayesian network, the dependencies between nodes can be clearly represented, and the conditional probability of each node can be calculated based on the risk attribute score of the node. This modeling method can accurately capture the interdependence between different attack steps and reflect the uncertainty in the attack process; by constructing the attack path probability matrix, the probability of occurrence of each step in each attack path can be quantified. This provides data support for the priority sorting of attack paths and the optimization of attack protection strategies; based on the three-level simulation model, the relationship between the physical environment and the digital model can be accurately mapped, and different security scenarios can be simulated and analyzed, which enables a detailed digital representation of each node, connection and its interactive relationship in the industrial Internet system.

[0040] Example 2 See also Figure 2 As shown, this embodiment provides a capability maturity assessment system for industrial Internet data security, including: Data perception unit, used to identify multi-dimensional security data at the edge nodes of the Industrial Internet; The digital twin unit is used to integrate multi-dimensional security data and perform mapping relationship analysis to obtain a digital twin; use vulnerability scanning tools to scan the digital twin, obtain node vulnerability data, and calculate CVSS scores; dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; construct an attack path probability matrix for the digital twin through a Bayesian network; embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; The maturity quantification unit is used to construct a five-dimensional evaluation matrix based on simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method, and obtain the weight of each evaluation dimension; comprehensively calculate the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score; The visualization unit provides a visual display of scenario defense scores and capability maturity scores based on different attack chains.

[0041] Since the electronic device introduced in this embodiment is an electronic device used for implementing a capability maturity assessment method and system based on industrial Internet data security in the embodiment of this application, based on a capability maturity assessment method and system for industrial Internet data security introduced in the embodiment of this application, a person skilled in the art can understand the specific implementation of the electronic device of this embodiment and its various variations, so how the electronic device implements the method in the embodiment of this application is not described in detail here. As long as a person skilled in the art implements an electronic device used by a capability maturity assessment method and system for industrial Internet data security in the embodiment of this application, it belongs to the scope of protection of this application.

[0042] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters and thresholds in the formula are set by technicians in this field according to actual conditions.

[0043] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technical users in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A capability maturity assessment method for industrial Internet data security, characterized in that: include: S1. Identify multi-dimensional security data at the edge nodes of the Industrial Internet; S2. Integrate multi-dimensional security data and perform mapping relationship analysis to obtain digital twins; use vulnerability scanning tools to scan digital twins, obtain node vulnerability data, and calculate CVSS scores; Dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; Perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; The attack path probability matrix of the digital twin is constructed through the Bayesian network; the acquired node risk attributes and attack path probability matrix are embedded into the digital twin to obtain the digital twin simulation model; S3. Use the ATT&CK framework to build attack paths for each node of the digital twin simulation model and generate attack scripts. Perform simulation attack tests on the digital twin simulation model according to the attack scripts and collect simulation test data through the ELK technology stack. S4. Construct a five-dimensional evaluation matrix based on the simulation test data, use the entropy weight method to calculate the information entropy of each dimension in the five-dimensional evaluation matrix, and obtain the weight of each evaluation dimension; perform a comprehensive calculation of the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform a weighted average to obtain the capability maturity score; S5. Visualize the scenario defense scores and capability maturity scores based on different attack chains.

2. The capability maturity assessment method for industrial Internet data security according to claim 1 is characterized in that: The multi-dimensional security data includes physical layer data, logical layer data and business layer data; the physical layer data includes equipment data, network topology data and communication protocol data; the logical layer data includes access control data, identity authentication data and security policy data; the business layer data includes production process data, business dependency data and key business chain data.

3. The capability maturity assessment method for industrial Internet data security according to claim 2 is characterized in that: The method for obtaining the digital twin includes: Use a graph database to integrate the acquired physical layer data, logical layer data, and business layer data, and establish a mapping relationship between the physical layer data, logical layer data, and business layer data through association analysis; use the entities contained in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationship between different nodes as edges to build a digital twin.

4. The capability maturity assessment method for industrial Internet data security according to claim 3 is characterized in that: The method for obtaining the node risk attribute includes: Use the OpenVAS vulnerability scanning tool to scan the nodes contained in the digital twin, obtain node vulnerability data, and calculate the CVSS score of each vulnerability; perform a weighted average on the CVSS scores of all node vulnerabilities to obtain the node vulnerability score of the node; based on the obtained node vulnerability score, quantify the node risk attributes through the risk assessment formula to obtain the risk attribute score; collect the risk attribute scores of all nodes in the digital twin, and then obtain the node risk attributes of each node.

5. The method for evaluating the capability maturity of industrial Internet data security according to claim 4 is characterized in that: The method for obtaining the attack path probability matrix includes: The Bayesian network is used for modeling to represent the dependency relationship between each node and the attack path. Each node in the digital twin simulation model is defined as an attack step, and the connection relationship between the nodes is defined as the dependency relationship between the attack steps. The conditional probability of each node is obtained according to the risk attribute score of each node through the Bayesian network. The attack path probability is obtained based on the conditional probability of each node. The attack path probability of each attack path is collected to construct an attack path probability matrix. Each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path. The elements of the attack path probability matrix are the probabilities of the attack step occurring successfully.

6. The capability maturity assessment method for industrial Internet data security according to claim 5 is characterized in that: The method for generating an attack script includes: Use the tactics and technical classification of the ATT&CK framework to define typical attack scenarios for the Industrial Internet; define the attack target, attack technology, attack method, and expected impact for each typical attack scenario to form a structured attack template and obtain a scenario library; Based on the acquired node risk attributes and attack path probability matrix, different attack paths are generated through the A* algorithm. The scenario library obtained by combining the ATT&CK framework is used to match typical attack scenarios for each attack path, and then the attack chain is obtained. All attack chains are collected to obtain the attack script.

7. The method for evaluating the capability maturity of industrial Internet data security according to claim 6 is characterized in that: The simulation test data includes vulnerability exploitation success rate, response handling time, business recovery time, detection success rate and node status.

8. The capability maturity assessment method for industrial Internet data security according to claim 7 is characterized in that: The method for obtaining the capability maturity score includes: The acquired simulation test data is processed by range normalization and mapped to five evaluation dimensions to form a five-dimensional evaluation matrix; the five evaluation dimensions include defense strength, response efficiency, recovery capability, detection accuracy, and business continuity; each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension; The entropy weight method is used to calculate the information entropy of each dimension in the five-dimensional evaluation matrix to obtain the weight of each evaluation dimension; Groups of simulation test data, each group of simulation test data corresponds to a different attack chain; comprehensive calculation is performed based on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense scores under different attack chains; the scenario defense scores under different attack chains are weighted averaged to obtain the capability maturity score.

9. The capability maturity assessment method for industrial Internet data security according to claim 8 is characterized in that: The method for visually displaying scenario defense scores and capability maturity scores based on different attack chains includes: The scenario defense score corresponding to each set of simulation test data is associated with the attack chain and mapped to the corresponding digital twin simulation model nodes and edges. A capability maturity visualization display interface is built through visualization tools, and the capability maturity score is displayed in the form of a dashboard. The simulation test data and scenario defense scores under different attack chains are dynamically loaded.

10. A capability maturity assessment system for industrial Internet data security, used to implement the capability maturity assessment method for industrial Internet data security according to any one of claims 1 to 9, characterized in that: include: Data perception unit, used to identify multi-dimensional security data at the edge nodes of the Industrial Internet; The digital twin unit is used to integrate multi-dimensional security data and perform mapping relationship analysis to obtain the digital twin; the vulnerability scanning tool is used to scan the digital twin, obtain node vulnerability data, and calculate the CVSS score; Dynamically quantify node connectivity weights based on node connectivity and vulnerability heterogeneity; Perform risk assessment based on node connectivity weights combined with CVSS scores to obtain node risk attributes for each node; The attack path probability matrix of the digital twin is constructed through the Bayesian network; the acquired node risk attributes and attack path probability matrix are embedded into the digital twin to obtain the digital twin simulation model; The simulation response unit uses the ATT&CK framework to build attack paths for each node of the digital twin simulation model and generate attack scripts. It performs simulation attack tests on the digital twin simulation model based on the attack scripts and collects simulation test data through the ELK technology stack. The maturity quantification unit is used to construct a five-dimensional evaluation matrix based on simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method, and obtain the weight of each evaluation dimension; comprehensively calculate the five-dimensional evaluation matrix and the weight of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score; The visualization unit provides a visual display of scenario defense scores and capability maturity scores based on different attack chains.

Citation Information

Patent Citations

  • Method and system for assisted assessment of information security capacity maturity

    CN103077426A

  • Multi-target network security dynamic evaluation method based on Bayesian network attack graph

    CN114519190A

  • EPSS-based vulnerability accessibility rating method

    CN119484153A

  • Criticality analysis of attack graphs

    US20200137104A1

  • Generating attack graphs in agile security platforms

    US20200177618A1

Cited By

  • Intelligent operation platform operation monitoring method and system based on digital twinning

    CN120596340A

  • Data security monitoring and early warning method based on Internet of Things

    CN120956448A