An Industrial Internet Data Security Capability Maturity Assessment Method and System
Through comprehensive vulnerability scanning, CVSS scoring and Bayesian network modeling, the vulnerability identification and risk assessment in the maturity assessment of industrial Internet data security capabilities are solved, and detailed digital representation of nodes and connection relationships are realized and protection strategies are optimized, which improves the accuracy of risk assessment and the targetedness of protection strategies.
Patent Information
- Application Number
- CN202510450415.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing technology has the problem of incomplete vulnerability scanning in the assessment of industrial Internet data security capabilities, and the inability to accurately evaluate the severity of vulnerabilities, neglecting node connectivity and dependencies, resulting in inaccurate risk assessment and affecting the effectiveness of decision-making and protection strategies.
A comprehensive vulnerability scanning was carried out using OpenVAS tool, combining CVSS scores and node connectivity weights, node dependencies were represented through Bayesian network modeling, an attack path probability matrix was constructed, an attack script was generated using the ATT&CK framework, simulation attack tests were conducted, and a calculation ability maturity score was combined with the entropy weight method, and visual display was performed.
It realizes comprehensive vulnerability identification and quantitative risk assessment of industrial Internet systems, accurately reflects the dependence and connectivity between nodes, provides detailed digital representation and optimized protection strategies, and improves the accuracy of risk assessment and targeted protection strategies.
Smart Images

Figure CN119996078B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and more particularly, to a method and system for evaluating the capability maturity of industrial Internet data security. Background Art
[0002] A patent with the publication number CN103077426A discloses a method and system for assisting in evaluating the information security capability maturity. The method includes the steps of: pre-defining a maturity evaluation database, which includes: an information security construction maturity model, model construction fields, construction directions of the construction fields, specific evaluation indicators of the construction directions, specific value ranges and satisfaction conditions of the construction indicators; establishing a customer information security maturity evaluation model according to customer requirements and the maturity evaluation database; maintaining customer information, and setting and optimizing indicator values; and outputting an evaluation report by combining the obtained specific evaluation indicator information with various maintained data information, thereby realizing unified collection and classification of customer information security information, and automatic inheritance, scientifically defining the capability maturity evaluation model, reducing the dependence on experts, and providing convenience for evaluating the information security capability maturity.
[0003] The following main problems exist in the traditional method for evaluating the capability maturity of industrial Internet data security:
[0004] Without using a tool similar to OpenVAS for a comprehensive vulnerability scan, only some of the security vulnerabilities of the nodes may be identified, and other potential vulnerabilities may be missed. In this case, the security vulnerabilities in the digital twin may be underestimated, resulting in the failure to detect and repair security hazards in a timely manner. Especially in a large-scale digital twin system, there may be multiple interacting nodes, and incomplete vulnerability scanning will increase the risk of the system being attacked; if the CVSS score is not assigned to the vulnerabilities, the severity assessment of the vulnerabilities may be affected by human subjective factors, leading to an incorrect risk judgment. Without a quantitative vulnerability assessment standard, it is difficult to reasonably assign priorities to the vulnerabilities, resulting in the failure to repair the most serious vulnerabilities in a timely manner, affecting the security of the entire system; simple risk assessment methods can only focus on the vulnerability situation of the nodes themselves, while ignoring the connectivity between the nodes and other nodes. For highly connected nodes, their potential impact may be greater than that of isolated nodes. The lack of a comprehensive risk analysis may lead to the same assessment results for low-risk nodes and high-risk nodes, affecting the accuracy of decision-making; the connection relationships between the nodes are not included in the risk assessment, which may ignore the importance of some nodes; due to the lack of quantitative data support, the priority arrangement of vulnerability repair may be unreasonable, thus affecting the repair efficiency. The system may waste resources on low-priority vulnerabilities while ignoring high-priority and more influential vulnerabilities; security decisions often rely on manual judgment. Due to the limited knowledge of personnel, the accuracy and efficiency of decision-making may be affected. Manual judgment is easily restricted by personal experience and understanding, which may lead to misjudgment, thus affecting the security of the entire system;
[0005] The failure to represent the dependency relationships between the nodes may overlook the potential impacts between different nodes. The relationships between the nodes may be complex and uncertain, and the lack of Bayesian network modeling cannot clearly reflect these dependencies, resulting in insufficient accuracy of security analysis and decision-making. Especially when facing complex attack paths, this dependency is very likely to be ignored, ultimately making the security assessment incomplete; the occurrence of attack paths is usually accompanied by a high degree of uncertainty, especially when facing new types of attacks. Without Bayesian network modeling, it is impossible to quantify the occurrence probabilities of different events in the attack path, and thus it is impossible to effectively assess the risk of the attack, resulting in the defense strategy being unable to effectively adapt to different attack scenarios and reducing the flexibility and effectiveness of protection; the lack of priority ranking of attack paths will lead to a lack of pertinence in the design of the protection strategy, which may be too broad or too narrow. Unable to adjust resource allocation and security control according to the probability of the attack and the priority of the path, the defense strategy may fail to effectively intercept high-risk attack paths at critical moments.
[0006] In view of this, the present invention proposes a method and system for assessing the capability maturity of industrial Internet data security to solve the above problems. Summary of the Invention
[0007] To overcome the above defects of the prior art and to achieve the above object, the present invention provides the following technical solutions: A method for evaluating the capability maturity of industrial Internet data security, comprising:
[0008] S1. Identify multi-dimensional security data at the edge nodes of the industrial Internet;
[0009] S2. Integrate the multi-dimensional security data and perform mapping relationship analysis to obtain a digital twin; Use a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data and calculate the CVSS score; Based on the connectivity and vulnerability heterogeneity of the nodes, dynamically quantify the node connectivity weight; Based on the node connectivity weight and the CVSS score, perform risk assessment to obtain the node risk attributes of each node; Construct an attack path probability matrix of the digital twin through a Bayesian network; Embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model;
[0010] S3. Use the ATT&CK framework to construct attack paths for each node of the digital twin simulation model and generate an attack scenario; Conduct a simulation attack test on the digital twin simulation model according to the attack scenario, and collect simulation test data through the ELK technology stack;
[0011] S4. Construct a five-dimensional evaluation matrix according to the simulation test data, use the entropy weight method to calculate the information entropy of each dimension in the five-dimensional evaluation matrix, and obtain the weight of each evaluation dimension; Perform comprehensive calculation on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score;
[0012] S5. Perform visual display based on the scenario defense scores and capability maturity scores under different attack chains.
[0013] Further, the multi-dimensional security data includes physical layer data, logical layer data, and business layer data; The physical layer data includes device data, network topology data, and communication protocol data; The logical layer data includes access control data, identity authentication data, and security policy data; The business layer data includes production process data, business dependency data, and critical business chain data.
[0014] Further, the method for obtaining the digital twin includes:
[0015] Use a graph database to integrate the obtained physical layer data, logical layer data, and business layer data, and establish a mapping relationship between the physical layer data, logical layer data, and business layer data through association analysis; Use the entities included in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationship between different nodes as edges to construct a digital twin.
[0016] Further, the method for obtaining the node risk attribute includes:
[0017] Use the OpenVAS vulnerability scanning tool to scan the nodes included in the digital twin, obtain node vulnerability data, and calculate the CVSS score for each vulnerability; perform a weighted average on the CVSS scores of all vulnerabilities of the node to obtain the node vulnerability score of the node; based on the obtained node vulnerability score, quantify the node risk attribute through a risk assessment formula to obtain a risk attribute score; collect the risk attribute scores of all nodes in the digital twin, and then obtain the node risk attribute of each node.
[0018] Further, the method for obtaining the attack path probability matrix includes:
[0019] Build a model through a Bayesian network to represent the dependency relationship between each node and the attack path; define each node in the digital twin simulation model as an attack step, and define the connection relationship between nodes as the dependency relationship between attack steps. Through the Bayesian network, obtain the conditional probability of each node according to the risk attribute scores of each node; based on the conditional probability of each node, obtain the attack path probability; collect the attack path probabilities of each attack path to construct an attack path probability matrix; each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path; the element of the attack path probability matrix is the probability of successful occurrence of this attack step.
[0020] Further, the method for generating an attack scenario includes:
[0021] Use the tactics and technology classification of the ATT&CK framework to define typical attack scenarios for the industrial Internet of Things; define attack targets, attack technologies, attack methods, and expected impacts for each typical attack scenario to form a structured attack template, and then obtain a scenario library;
[0022] Based on the obtained node risk attribute and the attack path probability matrix, generate different attack paths through the A* algorithm; match the typical attack scenarios in the scenario library obtained by combining the ATT&CK framework for each attack path to obtain an attack chain; collect all attack chains to obtain an attack scenario.
[0023] Further, the simulation test data includes vulnerability exploitation success rate, response handling time, business recovery time, detection success rate, and node status.
[0024] Further, the method for obtaining the capability maturity score includes:
[0025] The obtained simulation test data is subjected to range normalization processing and mapped to five evaluation dimensions to form a five-dimensional evaluation matrix. The five evaluation dimensions include defense strength, response efficiency, recovery ability, detection accuracy, and business continuity. Each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension. The information entropy of each dimension in the five-dimensional evaluation matrix is calculated using the entropy weight method to obtain the weights of each evaluation dimension. There are groups of simulation test data, and each group of simulation test data corresponds to a different attack chain. Based on the five-dimensional evaluation matrix and the weights of each evaluation dimension, comprehensive calculations are performed to obtain the scenario defense scores under different attack chains. The scenario defense scores under different attack chains are weighted and averaged to further obtain the capability maturity scores.
[0026] Furthermore, the method for visualizing the scenario defense scores and capability maturity scores under different attack chains includes:
[0027] Associate the scenario defense score corresponding to each group of simulation test data with the attack chain and map it to the corresponding digital twin simulation model nodes and edges. Use a visualization tool to construct a capability maturity visualization display interface, display the capability maturity score in the form of a dashboard, and dynamically load the simulation test data and scenario defense scores under different attack chains.
[0028] Furthermore, a capability maturity assessment system for industrial Internet data security includes:
[0029] A data perception unit for identifying multi-dimensional security data at the industrial Internet edge nodes;
[0030] A digital twin unit for integrating multi-dimensional security data and performing mapping relationship analysis to obtain digital twins; using a vulnerability scanning tool to scan the digital twins to obtain node vulnerability data and calculate the CVSS score; dynamically quantifying the node connectivity weights based on the connectivity and vulnerability heterogeneity of the nodes; performing risk assessment based on the node connectivity weights combined with the CVSS score to obtain the node risk attributes of each node; constructing an attack path probability matrix of the digital twins through a Bayesian network; embedding the obtained node risk attributes and attack path probability matrix into the digital twins to obtain a digital twin simulation model;
[0031] A simulation response unit that uses the ATT&CK framework to construct attack paths for each node of the digital twin simulation model and generate attack scenarios; perform simulation attack tests on the digital twin simulation model according to the attack scenarios, and collect simulation test data through the ELK technology stack;
[0032] A maturity quantification unit, which is used to construct a five-dimensional evaluation matrix based on simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method, and obtain the weights of each evaluation dimension; comprehensively calculate the five-dimensional evaluation matrix and the weights of each evaluation dimension, obtain the scenario defense scores under different attack chains, and perform weighted averaging to obtain the capability maturity scores.
[0033] A visualization unit, which performs visual display based on the scenario defense scores and capability maturity scores under different attack chains.
[0034] The technical effects and advantages of an industrial Internet data security capability maturity evaluation method and system of the present invention:
[0035] By using the OpenVAS tool to comprehensively scan each node in the digital twin, potential security vulnerabilities of each node can be identified, detailed vulnerability data can be obtained, and the severity of the vulnerabilities can be quantitatively evaluated according to the CVSS score, providing a solid foundation for subsequent risk analysis and decision-making; more accurate risk assessment of nodes can be carried out according to the severity and importance of the vulnerabilities; the introduction of the risk assessment formula, by comprehensively considering the connectivity of the nodes, the number of node vulnerabilities, and the CVSS scores of each vulnerability, provides a quantitative score for the risk attributes of the nodes, which can intuitively reflect the security risks of the nodes; the introduction of the node connectivity weight coefficient takes into account the importance of the node itself and its connection relationship with other nodes, not only considering the vulnerability situation of the node itself, but also considering the relationship between the node and other nodes, making the risk assessment more comprehensive.
[0036] Through the Bayesian network, the dependency relationship between nodes can be clearly represented, and the conditional probability of each node can be calculated according to the risk attribute scores of the nodes. This modeling method can accurately capture the mutual dependencies between different attack steps and reflect the uncertainty in the attack process; by constructing the attack path probability matrix, the occurrence probability of each step in each attack path can be quantified. This provides data support for the priority ranking of attack paths and the optimization of attack prevention strategies; based on the three-level simulation model, the relationship between the physical environment and the digital model can be accurately mapped, and different security scenarios can be simulated and analyzed, which enables a detailed digital representation of each node, connection, and their interaction relationships in the industrial Internet system. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 It is a schematic flowchart of an industrial Internet data security capability maturity evaluation method of the present invention;
[0038] Figure 2 It is a schematic structural diagram of an industrial Internet data security capability maturity evaluation system of the present invention;
[0039] Figure 3 The flowchart for constructing the digital twin simulation model provided by the present invention. Specific implementation manners
[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0041] Embodiment 1
[0042] Please refer to Figure 1 and Figure 3 As shown, a method for evaluating the capability maturity of industrial Internet data security in this embodiment includes:
[0043] S1. Identify multi-dimensional security data at the edge nodes of the industrial Internet;
[0044] S2. Integrate the multi-dimensional security data and perform mapping relationship analysis to obtain a digital twin; use a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data, and calculate the CVSS score; dynamically quantify the node connectivity weight based on the connectivity and vulnerability heterogeneity of the nodes; perform risk assessment based on the node connectivity weight combined with the CVSS score to obtain the node risk attribute of each node; construct an attack path probability matrix of the digital twin through a Bayesian network; embed the obtained node risk attribute and attack path probability matrix into the digital twin to obtain a digital twin simulation model;
[0045] S3. Use the ATT&CK framework to construct attack paths for each node of the digital twin simulation model and generate an attack scenario; perform simulation attack testing on the digital twin simulation model according to the attack scenario, and collect simulation test data through the ELK technology stack;
[0046] S4. Construct a five-dimensional evaluation matrix based on the simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method to obtain the weight of each evaluation dimension; perform comprehensive calculation on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score;
[0047] S5. Perform visual display based on the scenario defense score and capability maturity score under different attack chains.
[0048] Deploy sensors and monitoring devices at the edge of the industrial Internet to identify multi-dimensional security data.
[0049] Multi-dimensional security data includes physical layer data, logical layer data, and business layer data; physical layer data includes device data, network topology data, and communication protocol data; logical layer data includes access control data, identity authentication data, and security policy data; business layer data includes production process data, business dependency data, and critical business chain data.
[0050] Device data includes device type, device model, device status, and device location; network topology data includes network device connection information, network link bandwidth, network link latency, network packet loss rate, and IP addresses; communication protocol data includes communication protocol type, communication protocol configuration parameters, and communication protocol traffic characteristics;
[0051] Access control data includes access control lists, user permissions, and firewall rules; identity authentication data includes user account information and authentication logs; security policy data includes security policy documents (such as password complexity requirements, session timeout settings) and security event response processes (such as vulnerability repair processes, emergency response plans);
[0052] Production process data includes production process steps, process dependencies, and process critical nodes; business dependency data includes the dependencies between devices and business (such as whether a device failure affects production) and the dependencies between business and network (such as whether a network link interruption affects business); critical business chain data includes critical business chains (such as core production lines, critical control systems) and SLAs of critical business chains (such as availability, response time).
[0053] The acquisition methods of digital twins include:
[0054] Integrate the obtained physical layer data, logical layer data, and business layer data using a graph database, and establish mapping relationships between the physical layer data, logical layer data, and business layer data through association analysis; use the entities included in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationships between different nodes as edges to construct a digital twin.
[0055] It should be noted that: analyze the mapping relationships between the physical layer data, logical layer data, and business layer data through association analysis algorithms (such as Apriori). For example, the relationship between device data and access control data, the relationship between business dependency data and network topology data, etc. Use the relationship modeling characteristics of the graph database to construct a digital twin, and use nodes and edges to represent the associations between data;
[0056] Each node in the digital twin represents an entity, including but not limited to physical layer entities such as devices, sensors, and network devices; logical layer entities such as access control lists, identity authentication policies, and firewall rules; business layer entities such as business processes, critical business chains, and production processes; the edges represent the mapping relationships between each node in the digital twin, such as communication between devices, dependencies between devices and business processes, and the impact of access control policies on business, etc.
[0057] The methods for obtaining the node risk attributes include:
[0058] Use the OpenVAS vulnerability scanning tool to scan the nodes included in the digital twin, obtain the node vulnerability data, and calculate the CVSS score for each vulnerability; perform a weighted average of the CVSS scores of all vulnerabilities of the node to obtain the node vulnerability score of the node; based on the obtained node vulnerability score, quantify the node risk attributes through the risk assessment formula to obtain the risk attribute score; collect the risk attribute scores of all nodes in the digital twin, and then obtain the node risk attributes of each node.
[0059] The CVSS score is an internationally recognized quantitative standard for vulnerability severity, consisting of multiple metrics and divided into a base score, a temporal score, and an environmental score; as an open-source vulnerability scanning tool, OpenVAS will identify the vulnerabilities of each node in the digital twin during the scanning process and provide a CVSS score for each vulnerability.
[0060] The risk assessment formula is: ; where is the risk attribute score; is the node connectivity weight coefficient; is the number of edges connected to the node; is the total number of edges in the digital twin; is the total number of node vulnerabilities; is the th CVSS score of the node's is the th weight factor of the node's is the index of the node vulnerability category.
[0061] It should be noted that: the risk assessment formula is based on the security data collected by the OpenVAS vulnerability scanning tool and combines the CVSS score (Common Vulnerability Scoring System) for quantitative assessment, comprehensively considering the severity of the node's vulnerabilities and its connectivity in the network; quantifies the severity of the vulnerabilities existing in each node through the CVSS score, and through the weight factor Adjustments are made to reflect the impact degrees of different types of vulnerabilities. Meanwhile, a node connectivity weight coefficient is introduced to reflect the importance of a node in the network. Nodes with high connectivity usually undertake more data transmission or control functions, and once attacked, they will have a greater impact on the security of the overall network.
[0062] The technical effects of the risk assessment formula are mainly reflected in the following aspects:
[0063] Reliable and scientific data sources: Security data is collected based on the OpenVAS vulnerability scanning tool and quantitatively evaluated in combination with CVSS scores, ensuring the reliability of data sources and the scientific nature of the evaluation method, providing a solid data foundation for risk assessment;
[0064] Comprehensive consideration of multiple factors: The severity of vulnerabilities of nodes and their connectivity in the network are comprehensively considered. It not only pays attention to the vulnerability situations of nodes themselves but also takes into account the positions and roles of nodes in the network topology structure, making the risk assessment more comprehensive and objective and avoiding the one-sidedness of evaluating risks based on a single factor;
[0065] Accurate quantification of vulnerability severity: The severity of vulnerabilities existing in each node is quantified through CVSS scores and adjusted using weight factors, which can accurately reflect the actual impact degrees of different types of vulnerabilities. Different types of vulnerabilities have different harm degrees to the system, and this quantification and adjustment method makes the evaluation results more in line with the actual situation, helping to accurately identify high-risk vulnerabilities;
[0066] Reflecting the importance of nodes in the network: Introducing the node connectivity weight coefficient can effectively reflect the importance of nodes in the network. Nodes with high connectivity undertake more data transmission or control functions, and their security status has a greater impact on the security of the overall network. The introduction of this coefficient enables the evaluation results to highlight the risks of such key nodes, facilitating network security managers to prioritize attention to and handle the security issues of these important nodes.
[0067] Through the node connectivity weight adjustment formula for the node connectivity weight coefficient Adjustment and constraint are carried out to more comprehensively and accurately evaluate the risk degree of nodes in the network. For example, in a complex network, for nodes with many connections and many types of vulnerabilities, the weight coefficient increases after being adjusted by the node connectivity weight adjustment formula, highlighting their high risks and providing a reliable basis for risk assessment.
[0068] The node connectivity weight adjustment formula is: ; where is the adjusted node connectivity weight coefficient; is the number of node connections, indicating the direct connection quantity between this node and other nodes, reflecting the connectivity of the node; The number of vulnerability categories of a node, which represents the number of different types of vulnerabilities existing in the node; Is the maximum number of node connections; Is the exponential factor of the node connection number;
[0069] It should be noted that:
[0070] The stronger the connectivity of a node, the more active or important the node is in the network structure, with frequent information flow and data interaction. At the same time, it also means that the node may become a key channel for attackers to invade or exploit. Therefore, the connectivity of a node is one of the important factors for measuring the potential risk of a node.
[0071] The vulnerability heterogeneity of a node refers to the number of different types of vulnerabilities existing in a node. The more types of vulnerabilities, the more complex and diverse the threat paths faced by the node, and the more means that attackers can use, thus increasing the overall risk level of the node. Vulnerability heterogeneity reflects the diversity of the security weak points of a node and is an important supplementary indicator for measuring the security risk of a node.
[0072] Reflects the connection relationship between a node and other nodes. By introducing an exponential factor , the influence degree of the node connection number on the node connectivity weight coefficient can be controlled. For example, in some scenarios, the growth of the node connection number may have an exponential impact on the node risk attribute, while in some scenarios it may be linear. Therefore, using an exponential factor allows adjusting the influence of these factors according to different situations. By introducing a logarithmic function to adjust the number of vulnerability categories of a node, it is ensured that the influence of the number of vulnerability categories of a node gradually flattens as the number increases. Adding 2 is to avoid calculation problems when the number of vulnerability categories of a node is 0 and to make the logarithmic function still sensitive when the number of vulnerability categories of a node is a small number.
[0073] The methods for obtaining the attack path probability matrix include:
[0074] Modeling through a Bayesian network, which is used to represent the dependency relationship between each node and the attack path; defining each node in the digital twin simulation model as an attack step, and the connection relationship between nodes as the dependency relationship between attack steps. According to the risk attribute scores of each node through the Bayesian network, obtain the conditional probability of each node; based on the conditional probability of each node, obtain the attack path probability; collect the attack path probabilities of each attack path and construct the attack path probability matrix; each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path; the elements of the attack path probability matrix are the probabilities of the successful occurrence of this attack step;
[0075] Let the attack path , where is the attack path from the initial attack step to the final attack step; is the initial attack step, is the final attack step; is the index of the attack step sequence, ; The occurrence probability of each attack step is determined by the occurrence probability of its parent node ; The attack path probability is ; where is the occurrence probability of the initial attack step ; is the occurrence probability of the attack step after the initial attack step is completed; is the occurrence probability of the attack step after the attack step is completed.
[0076] The method for generating an attack scenario script includes:
[0077] Using the tactics (such as initial access, execution, persistence) and techniques (such as malicious code injection, protocol tampering) classification of the ATT&CK framework, define typical attack scenarios for the industrial Internet of Things (such as PLC logic bomb injection, OPC data tampering); Define attack targets, attack techniques, attack methods, and expected impacts for each typical attack scenario to form a structured attack template, and then obtain a scenario library;
[0078] It should be noted that: In the industrial Internet of Things environment, a series of typical attack scenarios can be defined using the ATT&CK framework. These typical attack scenarios describe the tactics and techniques that an attacker may adopt to target industrial control systems (ICS) and networks. The following are several defined typical attack scenarios, including attack targets, attack techniques, attack methods, and expected impacts:
[0079] Attack scenario one: PLC logic bomb injection: Attack target: PLC device; Attack techniques: Malicious code injection, persistence; Attack method: Write time-triggered malicious logic inside the PLC to disrupt the operation of industrial equipment; Expected impact: Abnormal production line, equipment out of control;
[0080] Attack scenario two: OPC data tampering: Attack target: SCADA server; Attack techniques: Protocol tampering, man-in-the-middle attack; Attack method: Intercept OPC UA communication, modify sensor data, resulting in incorrect control instructions; Expected impact: Trigger incorrect operations, such as incorrect temperature control or valve operations;
[0081] Attack Scenario 3: Firmware Backdoor Implantation: Target of Attack: RTU / Industrial Control Equipment; Attack Techniques: Firmware Tampering, Persistence; Attack Method: Malicious code is implanted during the firmware update process to obtain long-term access rights; Anticipated Impact: The attacker can maintain control even after the device restarts;
[0082] Based on the obtained node risk attributes and attack path probability matrix, different attack paths are generated through the A* algorithm; each attack path is matched with a typical attack scenario from the ATT&CK framework scenario library to obtain the attack chain; all attack chains are collected to obtain the attack scenario script.
[0083] For example: Attack Path 1: SCADA Server (RCE Vulnerability) PLC (Modbus TCP Hijacking) Logic Bomb Injection;
[0084] Attack Path 2: HMI (Phishing Attack) SCADA (Remote Service Abuse) OPC Server (Data Tampering).
[0085] The simulation test data includes vulnerability exploitation success rate, response handling time, business recovery time, detection success rate, and node status; node status includes attacked and paralyzed nodes and normally operating nodes; the response handling time specifically refers to the time required from the detection of an attack to the successful implementation of defense measures (such as blocking attack traffic, fixing vulnerabilities, isolating the infected system); the business recovery time is the time required for the node to recover from paralysis to normal operation after being attacked.
[0086] The method for obtaining the capability maturity score includes:
[0087] The obtained simulation test data is subjected to range normalization processing and mapped to five evaluation dimensions to form a five-dimensional evaluation matrix; the five evaluation dimensions include defense strength, response efficiency, recovery ability, detection accuracy, and business continuity; each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension; the information entropy of each dimension in the five-dimensional evaluation matrix is calculated using the entropy weight method to obtain the weights of each evaluation dimension; there are groups of simulation test data, and each group of simulation test data corresponds to a different attack chain; based on the five-dimensional evaluation matrix and the weights of each evaluation dimension, comprehensive calculations are performed to obtain the scenario defense scores under different attack chains ; where is the capability maturity score obtained based on the th group of simulation test data; is the index of the simulation test data category; is the weight of the evaluation dimension ; is the index of the evaluation dimension, ; is the normalized score of the group of simulation test data on the evaluation dimension; the scenario defense scores under different attack chains are weighted and averaged to obtain the capability maturity score.
[0088] The method for visual display based on the scenario defense scores and capability maturity scores under different attack chains includes:
[0089] Associate the scenario defense score corresponding to each group of simulation test data with the attack chain, and map it to the corresponding digital twin simulation model nodes and edges. Build a capability maturity visualization display interface through a visualization tool, display the capability maturity score in the form of a dashboard, and dynamically load the simulation test data and scenario defense scores under different attack chains.
[0090] In this embodiment, a comprehensive vulnerability scan is performed on each node in the digital twin through the OpenVAS tool, which can identify potential security vulnerabilities in each node, obtain detailed vulnerability data, and quantitatively evaluate the severity of the vulnerabilities according to the CVSS score, providing a solid foundation for subsequent risk analysis and decision-making; based on the severity and importance of the vulnerabilities, a more accurate risk assessment of the nodes is carried out; the introduction of the risk assessment formula, by comprehensively considering the node connectivity, the number of node vulnerabilities, and the CVSS scores of each vulnerability, provides a quantitative score for the risk attributes of the nodes, which can intuitively reflect the security risks of the nodes; the introduction of the node connectivity weight coefficient takes into account the importance of the node itself and its connection relationship with other nodes, not only considering the vulnerability situation of the node itself, but also considering the relationship between the node and other nodes, making the risk assessment more comprehensive;
[0091] Through the Bayesian network, the dependence relationship between nodes can be clearly represented, and the conditional probability of each node can be calculated according to the risk attribute score of the node. This modeling method can accurately capture the mutual dependence between different attack steps and reflect the uncertainty in the attack process; by constructing the attack path probability matrix, the occurrence probability of each step in each attack path can be quantified. This provides data support for the priority ranking of attack paths and the optimization of attack protection strategies; based on the three-level simulation model, the relationship between the physical environment and the digital model can be accurately mapped, and different security scenarios can be simulated and analyzed, which enables a detailed digital representation of each node, connection, and their interaction relationships in the industrial Internet system.
[0092] Embodiment 2
[0093] Please refer to Figure 2 as shown. An industrial Internet data security capability maturity evaluation system in this embodiment includes:
[0094] A data perception unit, configured to identify multi-dimensional security data at an industrial Internet edge node;
[0095] A digital twin unit, configured to integrate multi-dimensional security data, perform mapping relationship analysis to obtain a digital twin; use a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data, and calculate the CVSS score; dynamically quantify the node connection degree weight based on the connectivity and vulnerability heterogeneity of the node; perform risk assessment based on the node connection degree weight combined with the CVSS score to obtain the node risk attribute of each node; construct an attack path probability matrix of the digital twin through a Bayesian network; embed the obtained node risk attribute and attack path probability matrix into the digital twin to obtain a digital twin simulation model;
[0096] A maturity quantification unit, configured to construct a five-dimensional evaluation matrix according to simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method to obtain the weight of each evaluation dimension; perform comprehensive calculation on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense score under different attack chains, and perform weighted average to obtain the capability maturity score;
[0097] A visualization unit, configured to perform visualization display based on the scenario defense score and the capability maturity score under different attack chains.
[0098] Since the electronic device introduced in this embodiment is the electronic device adopted for implementing the method and system for evaluating the capability maturity of industrial Internet data security in the embodiments of the present application, based on the method and system for evaluating the capability maturity of industrial Internet data security introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as the electronic device adopted by those skilled in the art to implement the method and system for evaluating the capability maturity of industrial Internet data security in the embodiments of the present application belongs to the scope protected by the present application.
[0099] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain a formula that is closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0100] The above are only the preferred embodiments of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.
Claims
1. A method for evaluating the capability maturity of industrial Internet data security, characterized in that Including: S1. Identify multi-dimensional security data at the edge nodes of the industrial Internet; S2. Integrate the multi-dimensional security data and conduct mapping relationship analysis to obtain a digital twin; Use a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data, and calculate the CVSS score; Dynamically quantify the node connectivity weight based on the connectivity and vulnerability heterogeneity of the nodes; Conduct risk assessment based on the node connectivity weight combined with the CVSS score to obtain the node risk attribute of each node; Construct an attack path probability matrix of the digital twin through a Bayesian network; Embed the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; S3. Use the ATT&CK framework to construct attack paths for each node of the digital twin simulation model and generate an attack playbook; Conduct a simulation attack test on the digital twin simulation model according to the attack playbook, and collect simulation test data through the ELK technology stack; S4. Construct a five-dimensional evaluation matrix based on the simulation test data, use the entropy weight method to calculate the information entropy of each dimension in the five-dimensional evaluation matrix to obtain the weight of each evaluation dimension; Conduct a comprehensive calculation on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense score under different attack chains, and conduct a weighted average to obtain the capability maturity score; S5. Conduct visual display based on the scenario defense score and capability maturity score under different attack chains.
2. The method for evaluating the capability maturity of industrial Internet data security according to claim 1, wherein The multi-dimensional security data includes physical layer data, logical layer data, and business layer data; The physical layer data includes device data, network topology data, and communication protocol data; The logical layer data includes access control data, identity authentication data, and security policy data; The business layer data includes production process data, business dependency data, and critical business chain data.
3. The method for evaluating the capability maturity of industrial Internet data security according to claim 2, wherein The method for obtaining the digital twin includes: Use a graph database to integrate the obtained physical layer data, logical layer data, and business layer data, and establish a mapping relationship between the physical layer data, logical layer data, and business layer data through correlation analysis; Use the entities included in the physical layer data, logical layer data, and business layer data as nodes, and the mapping relationship between different nodes as edges to construct a digital twin.
4. The method for evaluating the capability maturity of industrial Internet data security according to claim 3, wherein The method for obtaining the node risk attribute includes: Use the OpenVAS vulnerability scanning tool to scan the nodes included in the digital twin to obtain node vulnerability data, and calculate the CVSS score of each vulnerability; Conduct a weighted average on the CVSS scores of all vulnerabilities of the node to obtain the node vulnerability score of the node; Based on the obtained node vulnerability score, quantify the node risk attribute through a risk assessment formula to obtain a risk attribute score; Collect the risk attribute scores of all nodes in the digital twin, and further obtain the node risk attribute of each node.
5. The method for evaluating the capability maturity of industrial Internet data security according to claim 4, wherein, The method for obtaining the attack path probability matrix includes: Modeled through a Bayesian network to represent the dependencies between each node and the attack path; each node in the digital twin simulation model is defined as an attack step, and the connection relationship between nodes is defined as the dependency between attack steps. The conditional probability of each node is obtained through the Bayesian network based on the risk attribute scores of each node; based on the conditional probability of each node, the attack path probability is obtained; the attack path probabilities of each attack path are collected to construct an attack path probability matrix; each row of the attack path probability matrix represents an attack path, and each column represents a specific attack step in the attack path; the elements of the attack path probability matrix are the probabilities of the successful occurrence of the attack step.
6. The method for evaluating the capability maturity of industrial Internet data security according to claim 5, wherein The method for generating an attack scenario includes: Using the tactics and technology classifications of the ATT&CK framework to define typical attack scenarios for the industrial Internet; defining attack targets, attack technologies, attack methods, and expected impacts for each typical attack scenario to form a structured attack template, and then obtaining a scenario library; Based on the obtained node risk attributes and attack path probability matrix, different attack paths are generated through the A* algorithm; the scenario library obtained by combining the ATT&CK framework is used to match typical attack scenarios for each attack path, and then an attack chain is obtained; all attack chains are collected to obtain an attack scenario.
7. The method for evaluating the capability maturity of industrial Internet data security according to claim 6, wherein The simulation test data includes vulnerability exploitation success rate, response handling time, business recovery time, detection success rate, and node status.
8. The method for evaluating the capability maturity of industrial Internet data security according to claim 7, wherein The method for obtaining the capability maturity score includes: Performing range standardization processing on the obtained simulation test data and mapping it to five evaluation dimensions to form a five-dimensional evaluation matrix; the five evaluation dimensions include defense intensity, response efficiency, recovery ability, detection accuracy, and business continuity; each row of the five-dimensional evaluation matrix represents a sample, and each column represents an evaluation dimension; Calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method to obtain the weights of each evaluation dimension; assume there are groups of simulation test data, and each group of simulation test data corresponds to a different attack chain; perform comprehensive calculations based on the five-dimensional evaluation matrix and the weights of each evaluation dimension to obtain the scenario defense scores under different attack chains; perform a weighted average on the scenario defense scores under different attack chains to further obtain the capability maturity scores.
9. The method for evaluating the capability maturity of industrial Internet data security according to claim 8, wherein The method for visually displaying the scenario defense score and capability maturity score based on different attack chains includes: Associating the scenario defense score corresponding to each group of simulation test data with the attack chain and mapping it to the corresponding nodes and edges of the digital twin simulation model. A capability maturity visualization display interface is constructed through a visualization tool, and the capability maturity score is displayed in the form of a dashboard, and the simulation test data and scenario defense score under different attack chains are dynamically loaded.
10. An industrial Internet data security capability maturity assessment system for implementing the industrial Internet data security capability maturity assessment method according to any one of claims 1 to 9, characterized in that, Includes: A data perception unit for identifying multi-dimensional security data at the edge nodes of the industrial Internet; A digital twin unit for integrating multi-dimensional security data and performing mapping relationship analysis to obtain a digital twin; using a vulnerability scanning tool to scan the digital twin to obtain node vulnerability data and calculate the CVSS score; Dynamically quantifying the node connectivity weight based on the connectivity and vulnerability heterogeneity of the nodes; Performing risk assessment based on the node connectivity weight combined with the CVSS score to obtain the node risk attribute of each node; Constructing an attack path probability matrix of the digital twin through a Bayesian network; embedding the obtained node risk attributes and attack path probability matrix into the digital twin to obtain a digital twin simulation model; The simulation response unit uses the ATT&CK framework to construct attack paths for each node of the digital twin simulation model and generate attack scenarios; it conducts simulation attack tests on the digital twin simulation model according to the attack scenarios and collects simulation test data through the ELK technology stack; The maturity quantification unit is used to construct a five-dimensional evaluation matrix based on the simulation test data, calculate the information entropy of each dimension in the five-dimensional evaluation matrix using the entropy weight method, and obtain the weights of each evaluation dimension; it comprehensively calculates the five-dimensional evaluation matrix and the weights of each evaluation dimension, obtains the scenario defense scores under different attack chains, and performs weighted averaging to obtain the capability maturity scores; The visualization unit conducts visual displays based on the scenario defense scores and capability maturity scores under different attack chains.
Citation Information
Patent Citations
Method and system for assisted assessment of information security capacity maturity
CN103077426A
Multi-target network security dynamic evaluation method based on Bayesian network attack graph
CN114519190A
EPSS-based vulnerability accessibility rating method
CN119484153A