Information system access risk assessment method based on access context logical reasoning
By adopting access context-based logical reasoning methods in the information system, combining trust calculation and fuzzy reasoning, the problem of difficulty in dynamically evaluating access risks in the existing technology is solved, and dynamic assessment and management of session access risks in the information system are realized.
Patent Information
- Application Number
- CN202311511090.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-11-14
AI Technical Summary
It is difficult for the prior art to dynamically calculate and analyze the access risks of information systems caused by changes in relevant security elements such as the access context and environment.
The access context logical reasoning method is adopted to obtain the access authority of the access subject through trust calculation and logical reasoning, and introduce the access context and reasoning mechanism into risk assessment, combining fuzzy reasoning and integration to achieve a comprehensive assessment of the risk of session access in the information system.
It realizes dynamic assessment of the risk of session access in the information system, and can evaluate the current access session security situation of the system, providing a beneficial supplement to conventional information security risk management.
Smart Images

Figure CN120017288A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a technology in the field of information security, in particular to an information system access risk assessment method based on access context logical reasoning. Background Art
[0002] At present, common information security risk assessment methods mainly focus on the risks caused by information system threats and vulnerabilities, and it is difficult to directly evaluate the security level of sessions. The present invention provides an access risk assessment method based on access context, which can provide assistance for conventional information system security risk management. Summary of the invention
[0003] In view of the deficiency of the prior art that the risks cannot be dynamically calculated and analyzed according to the changes of relevant security factors such as access context and environment, the present invention proposes an information system access risk assessment method based on access context logical reasoning, which obtains the access rights of the access subject by using trust calculation and logical reasoning, introduces the access context and reasoning mechanism into the risk assessment, and performs fuzzy processing on the access-related contexts such as the degree of environmental risk and the degree of asset value. By quantifying the various elements of the access context process in the information system and combining logical reasoning and fuzzy reasoning, a comprehensive assessment of the information system session access risk is achieved.
[0004] The present invention is achieved through the following technical solutions:
[0005] The present invention relates to an information system access risk assessment method based on access context logical reasoning. According to the security elements of the access subject context, after the accessible asset set of the access subject is obtained through trust calculation and access policy set logical reasoning, the comprehensive trust level of a single access subject, the risk level of the access environment and the value level of the actual access assets are fuzzified, fuzzy reasoned and defuzzified to obtain the session access risk of a single subject, and the session access risk of the entire information system is obtained through summary processing.
[0006] The present invention relates to an information system access risk assessment system for implementing the above method, comprising: a subject trust value calculation and logical reasoning module, an access environment risk degree calculation module, an access asset value calculation module, and a subject risk fuzzy calculation and access risk integration module, wherein: the subject trust value calculation and logical reasoning module calculates the asset set accessible to the access subject according to the access subject's long-term trust value, the access subject trust factor weight vector and the trust score threshold, the access environment risk degree calculation module calculates the access risk degree fuzzy calculation value according to the environmental threat degree and environmental protection measure level of the information system security situation perception, the access asset value calculation module calculates the access asset value fuzzy calculation value according to the security level of the accessed asset and the importance of the accessed asset from the access asset database of the information system, and the subject risk fuzzy calculation and access risk integration module calculates the access risk of the entire system according to the access subject trust value from the subject trust value calculation and logical reasoning, the access environment risk fuzzy calculation value from the access environment risk degree calculation and the multi-asset value fuzzy calculation value from the access asset value calculation. The access subject trust factor vector is derived from various information related to the access subject during the access process, including the identity of the access subject, the access time, the device used for access, and the certificate carried during the access.
[0007] The long-term trust value of the access subject is stored in the access subject database and is obtained in the following way:
[0008] 1) Calculate the switch coefficient vector: assign values to the switch coefficient vector (r1, r2, r3, r4) based on whether the identity of the input access subject is legal, whether the access time is compliant, whether the device used for access is compliant, and whether the certificate carried during access is credible. When a value meets the regulations, the corresponding switch coefficient value is 1, otherwise it is -1.
[0009] 2) Calculate the modified trust value of the access subject: TrustAdjust = LongtermTrust + k*(x1,x2,x3,x4)*(r1,r2,r3,r4) T , where: TrustAdjust is the modified trust value of the access subject, LongtermTrust is the long-term trust value of the access subject, (x1,x2,x3,x4) is the weight vector of the input access subject trust factor, where each value is between 0 and 1 and satisfies x1+x2+x3+x4=1, (r1,r2,r3,r4) is the switching coefficient corresponding to each trust factor dimension, and the value range is {-1,1}, and k is the discount coefficient, and the value range is (0,1).
[0010] 3) Calculate the instant session trust value of the access subject: After calculating the modified trust value, the trust value is normalized using the following Sigmoid formula: Among them: CurrentTrust is the normalized result, and CurrentTrust is mapped to between 0 and 100 as the instant session trust value SessionTrust = CurrentTrust*100 of the access subject.
[0011] 4) Determine the ticket status of the access subject in the current session, that is, whether the access subject can obtain a ticket in the current session and what level of ticket can be obtained:
[0012] By classifying the instant session trust value output in the previous step, the level of the ticket obtained is determined by combining the trust score threshold. The trust score threshold includes ordinary_score and special_score, which represent the ordinary access trust score and privileged trust score required by the system respectively. When the trust value is less than ordinary_score, it is considered that the access subject has not obtained any ticket; when the trust value is greater than or equal to ordinary_score and less than special_score, it is considered that the access subject has obtained an ordinary-level ticket; when the trust value is greater than or equal to special_score, it is considered that the access subject has obtained a privileged-level ticket.
[0013] 5) Determine the set of assets that the access subject can access, that is, determine the range of the asset set that the access subject can access in the current session through a set of logical reasoning rules: input the identity of the access subject and the ticket it obtains, and through logical reasoning of the set of logical reasoning rules, obtain the security level of the assets that the access subject can access, and then obtain the set of assets that the access subject can access.
[0014] The logical reasoning rule set includes:
[0015] A) Any subject who obtains a general-level or privileged-level ticket can access assets with a low security level;
[0016] B) A common subject or administrator subject within the system who obtains a privileged level ticket can access assets with a medium security level;
[0017] C) An administrator who is an internal administrator of the system and has obtained a normal-level ticket can access assets with a medium security level;
[0018] D) An administrator who is inside the system and has obtained a privileged level ticket can access assets with a high security level.
[0019] The access risk level fuzzy calculation value is obtained by the following steps:
[0020] 1) Fuzzy processing of the environmental threat level: Calculate and obtain the membership of the access environment to each threat level class, and divide the access environment threat level into three categories: Low_Threat, Medium_Threat and High_Threat, which represent the access environment threat "low", "average" and "high" respectively. Specifically: Where x represents the threat level of the access environment, ranging from 0 to 100.
[0021] 2) Fuzzy processing of the environmental protection level: Calculate and obtain the membership of the access environment protection level to each fuzzy class, and divide the access environment protection level into three categories: Low_Protection, Medium_Protection and High_Protection, which represent the access environment protection level "low", "general" and "high", respectively. Specifically: Where: x represents the protection level of the access environment, which ranges from 0 to 100.
[0022] 3) Implement fuzzy reasoning according to fuzzy rules, calculate and obtain the output membership corresponding to each rule, including:
[0023] 3.1) According to the membership of each fuzzy class corresponding to the threat level of the access environment and the level of environmental protection measures, the risk level of the access environment is further divided into three categories: Low_Env_Risk, Medium_Env_Risk and High_Env_Risk, which represent the three categories of access environment risk levels of "low", "average" and "high", respectively. Specifically: Where x represents the risk level of the access environment, ranging from 0 to 100.
[0024] 3.2) According to the membership of the three fuzzy classes of low environmental threat level, medium environmental threat level and high environmental threat level, and the membership of the three fuzzy classes of low environmental protection measure level, medium environmental protection measure level and high environmental protection measure level, based on the access environment risk level rule set, the access environment threat level class and the access environment protection measure level class, fuzzy reasoning is implemented, and the 9 rules in the table are traversed. The membership of the access environment risk fuzzy class is calculated for the ignited rules respectively, which is: μ(env_risk∈Env_Risk)=min[μ(threat∈Threat),μ(protection∈Protection)], where: , μ( threat∈Threat) indicates the degree of membership of the environmental threat level to a certain fuzzy class (Low_Threat, Medium_Threat or High_Threat), μ(protection∈Protection) indicates the degree of membership of the environmental protection measure level to a certain fuzzy class (Low_Protection, Medium_Protection or High_Protection), and μ(env_risk∈Env_Risk) indicates the degree of membership of the environmental risk level to a certain fuzzy class (Low_Env_Risk, Medium_Env_Risk or High_Env_Risk).
[0025] The access environment risk level rule set is shown in Table 1.
[0026] Table 1
[0027] 4) Calculate the membership of the risk level of the access environment to each fuzzy class: Combine the output membership results corresponding to each rule, and take the maximum value of the membership of the same fuzzy class output by each rule as the membership of the risk level of the access environment to each fuzzy class, specifically: Low_Env_Risk_Deg = max{μ(env_risk∈Low_Env_Risk)infired rules}, Medium_Env_Risk_Deg = max{μ(env_risk∈Medium_Env_Risk)infired rules}, High_Env_Risk_Deg = max{μ(env_risk∈High_Env_Risk)infired rules}, where: Low_Env_Risk_Deg indicates that the risk level of the access environment belongs to the membership of the access environment risk level "low", Medium_Env_Risk_Deg indicates that the risk level of the access environment belongs to the membership of the access environment risk level "average", and High_Env_Risk_Deg indicates that the risk level of the access environment belongs to the membership of the access environment risk level "high".
[0028] The fuzzy calculated value of the accessed asset value is obtained in the following way:
[0029] 1) Perform fuzzy processing on the importance of access assets: Calculate and obtain the membership of the importance of access assets to each fuzzy class, and divide the importance of access assets into three categories: Low_Importance, Medium_Importance and High_Importance, which represent the importance of access assets "low", "average" and "high", respectively. Specifically: Where: x represents the importance of accessing the asset, ranging from 0 to 100.
[0030] The security level of accessing assets is a precise concept and does not need to be fuzzy. The present invention divides the security level of accessing assets into three categories: Low_SecurityLevel, Medium_SecurityLevel and High_SecurityLevel, which represent asset security levels "low", "normal" and "high" respectively.
[0031] 2) Implement fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule, including:
[0032] 2.1) The asset value is divided into three categories: Low_Value, Medium_Value and High_Value, which represent the access asset value "low", "average" and "high" respectively. Specifically: Where: x represents the value of the access asset, ranging from 0 to 100.
[0033] 2.2) According to the membership of the three classes of low security level, medium security level and high security level of the access asset security level and the membership of the three fuzzy classes of low importance, medium importance and high importance of the access asset importance; then according to the access asset value level rule set, combined with the access asset security level and the access asset importance class, fuzzy reasoning is implemented, and the 9 rules in the table are traversed to calculate the membership of the access asset value respectively, which is: μ(Value∈Value)=min[μ(securitylevel∈SecurityLevel),μ(importance∈Importance)], where: μ(securitylevel∈SecurityLevel)=min[μ(securitylevel∈SecurityLevel),μ(importance∈Importance)] ityLevel) indicates the membership of the asset security level to a certain class (Low_SecurityLevel, Medium_SecurityLevel or High_SecurityLevel), μ(importance∈Importance) indicates the membership of the asset importance to a certain fuzzy class (Low_Importance, Medium_Importance or High_Importance), and μ(value∈Value) indicates the membership of the value of accessing the asset to a certain fuzzy class (Low_Value, Medium_Value or High_Value).
[0034] The set of rules for accessing asset value levels is shown in Table 2.
[0035] Table 2
[0036] 3) Calculate the membership of the access asset value to each fuzzy class: According to the inference results of multiple fuzzy rules that are fired, take the maximum value of the membership of the same fuzzy class output by each rule as the membership of the access asset value to each fuzzy class, specifically: Low_Value_Deg = max{μ(value∈Low_Value)infiredrules}, Medium_Value_Deg = max{μ(value∈Medium_Value)in fired rules}, High_Value_Deg = maxμ(value∈High_Value)in fired rules}, where: Low_Value_Deg indicates the membership of the access asset value to the "low" access asset value, Medium_Value_Deg indicates the membership of the access asset value to the "general" access asset value, and High_Value_Deg indicates the membership of the access asset value to the "high" access asset value.
[0037] The access risk of the entire system is obtained in the following ways:
[0038] 1) Fuzzify the trust level of the access subject: Combined with the instant session trust value obtained in step 1, calculate and obtain the membership of the access subject to each class of the fuzzy trust level, and divide the trust level of the subject into three categories: Low_Trust, Medium_Trust and High_Trust, which represent the three categories of user subject security "low", "average" and "high", respectively. Specifically: Where: x represents the session trust score of the access subject, which ranges from 0 to 100.
[0039] 2) Implement fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule, including:
[0040] 2.1) The risks that a single entity brings to the entire system are divided into five categories: Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk, and Very_High_Risk classes represent the risks that the subject brings to the entire system, respectively: Where x represents the threat level of the access environment, ranging from 0 to 100.
[0041] 2.2) According to the membership of the subject trust level, it belongs to the three fuzzy classes of low trust level, medium trust level and high trust level; the membership of the environmental risk level, it belongs to the three fuzzy classes of low environmental risk level, medium environmental risk level and high environmental risk level; and the membership of the asset value, it belongs to the three fuzzy classes of low asset value, medium asset value and high asset value. According to the fuzzy rule set of subject access risk, fuzzy reasoning is implemented to calculate the output membership of each ignited rule: μ(risk∈Risk)=min[μ(trust∈Trust),μ(env_rish∈Env_Risk),μ(value∈Value)], where: μ(trust∈Trust) indicates the membership of the subject trust level to a certain class (Low_Trust, Medium_Trust or High_Trust class), μ(env_risk∈Env_Risk) indicates the membership of the environmental risk level to a certain fuzzy class (Low_Env_Risk, Medium_Env_Risk or High_Env_Risk), μ(value∈Value) indicates the membership of the value of the access asset to a certain fuzzy class (Low_Value, Medium_Value or High_Value), and μ(risk∈Risk) indicates the membership of the access risk to a certain fuzzy class (Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk or Very_High_Risk class).
[0042] The subject access risk fuzzy rule set is shown in Table 3.
[0043] Table 3
[0044] 3) Defuzzification is achieved using the centroid method to obtain the access risks associated with a single subject and a single access asset, including:
[0045] 3.1) Combine the reasoning results of multiple ignited fuzzy rules and merge the membership of the same fuzzy class: divide the access risk into five categories: Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk and Very_High_Risk. According to the results calculated by each rule in the previous step, merge the membership of the three categories respectively to obtain the total membership of each category, specifically: Very_Low_Risk_Sum=∑μ(risk∈Very_Low_Risk), Low_Risk_Sum=∑μ(risk∈Low_Risk), Medium_Risk_Sum=∑μ(risk∈Medium_Risk), High_Risk_Sum=∑μ(risk∈High_Risk), Very_High_Risk_Sum=∑μ(risk∈Very_High_Risk).
[0046] 3.2) Combined with the total membership of each category, the centroid method is used to calculate the asset value: the centroid value Very_Low_Risk_Center of the Very_Low_Risk category is 10; the centroid value Low_Risk_Center of the Low_Risk category is 30; the centroid value Medium_Risk_Center of the Medium_Risk category is 50; the centroid value High_Risk_Center of the High_Risk category is 70; the centroid value Very_High_Risk_Center of the Very_High_Risk category is 90; Calculate the asset value from an overall perspective and obtain the access risk associated with a single subject and a single access asset, specifically:
[0047] 4) Construct an access risk matrix to calculate the access risk of the entire system: The access risk of the entire system is calculated based on the access risk calculation values of all current subjects in the system and all the access assets they can access, specifically:
[0048] 4.1) Constructing the access risk matrix: Each access subject in the system corresponds to a row in the access risk matrix. For all access subjects in the system, the asset sets that they can access must be traversed and the access risk values are calculated pairwise. When an access subject cannot access an asset, the access risk between the two is considered to be 0. After obtaining the access risks of all subjects and all access assets, the following access risk matrix is constructed: Where: m represents the number of access entities, n represents the number of access assets, r ijAccessRisk(IS) = ∑ 0<i≤m,0<j≤n r ij .
[0049] 4.2) Calculate the overall access risk of the system. By summing up the elements in the access risk matrix, we can get the access risk of the entire system AccessRisk (IS). Technical Effects
[0050] The never-before-published technical means disclosed by the present invention are: introducing four dimensions of access context security elements, combining the fuzzy security level of the access environment and the fuzzy importance of the access assets for fuzzy reasoning and calculation, so as to realize dynamic assessment of the security risk of system access sessions.
[0051] The technical effect brought about by the above-mentioned technical means, which has never been made public, is: according to the current access session security situation of the system, a dynamic assessment of the system access security risk is achieved, providing a useful supplement to conventional information security risk management.
[0052] The access rights of the access subject are obtained by trust calculation and logical reasoning, and the access context-related factors such as the degree of environmental risk and the degree of asset value are fuzzy processed. Through fuzzy reasoning and integration, the session access risks of each access subject are finally integrated, thereby realizing the assessment of the access risk of the entire system.
[0053] The present invention can apply corresponding calculation and reasoning methods to information systems, and realize access risk assessment of information systems by combining access context and reasoning mechanism, thereby providing assistance for deployment, implementation and risk resistance of information systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is a flow chart of the present invention;
[0055] Figure 2 This is a relationship diagram of an embodiment. DETAILED DESCRIPTION
[0056] like Figure 1 and Figure 2 As shown, this embodiment involves an information system access risk assessment system based on access context logical reasoning, including: a subject trust value calculation and logical reasoning module, an access environment risk degree calculation module, an access asset value calculation module, and a subject risk fuzzy calculation and access risk integration module.
[0057] The subject trust value calculation and logical reasoning module includes: a switch coefficient vector calculation unit, a modified trust value calculation unit, an instant session trust value calculation unit and an access ticket granting unit, wherein: the switch coefficient vector calculation unit performs judgment and classification processing according to the security element information of the access context to obtain the result after the switch coefficient vector is assigned; the modified trust value calculation unit performs corresponding vector multiplication and addition processing according to the long-term trust of the access subject, the weight vector of the access context security element, and the output result information of the switch coefficient vector calculation unit to obtain the modified trust value of the access subject; the instant session trust value calculation unit performs normalization processing according to the output information of the modified trust value calculation unit to obtain the instant session trust value of the access subject; the access ticket granting unit performs judgment and classification processing according to the output information of the instant session trust value calculation unit to obtain the ticket that can be granted to the access subject.
[0058] The access environment risk level calculation module includes: an access environment threat fuzzification processing unit, an access environment protection measure fuzzification processing unit, and an access environment risk fuzzy reasoning unit, wherein: the access environment threat fuzzification processing unit performs fuzzification processing according to the threat level information of the access environment to obtain a fuzzy category of the access environment threat; the access environment protection measure fuzzification processing unit performs fuzzification processing according to the access environment protection measure level information to obtain a fuzzy classification of the access environment protection measures; the access environment risk fuzzy reasoning unit performs fuzzy reasoning according to the output information of the access environment threat fuzzification processing unit and the output information of the access environment protection measures fuzzification processing unit to obtain a fuzzy classification result of the access environment risk.
[0059] The access asset value calculation module includes: an access asset importance fuzzy processing unit and an access asset value fuzzy reasoning unit, wherein: the access asset importance fuzzy processing unit performs fuzzy processing according to the access asset importance value information to obtain the access asset importance fuzzy classification result, and the access unit asset value fuzzy reasoning performs fuzzy reasoning according to the access asset importance fuzzy processing unit information and the access asset security level to obtain the access asset value fuzzy classification result.
[0060] The subject risk fuzzy calculation and access risk integration module includes: an access subject trust fuzzy processing unit, a single subject access risk fuzzy reasoning unit, a centroid method defuzzification unit and an access risk calculation unit for the entire system, wherein: the access subject trust fuzzy processing unit performs fuzzification processing based on the instant session trust value information output by the instant session trust value calculation unit to obtain the fuzzy trust class to which the access subject belongs; the single subject access risk fuzzy reasoning unit performs fuzzy reasoning processing according to the fuzzy trust class to which the access subject belongs output by the access subject trust fuzzy processing unit, the access environment risk fuzzy class output by the access environment risk fuzzy reasoning unit, and the access asset value classification information output by the access asset value fuzzy reasoning unit, according to the provided fuzzy rule set to obtain the single subject access risk fuzzy class; the centroid method defuzzification unit performs centroid method defuzzification processing based on the single subject access risk fuzzy class information output by the single subject access risk fuzzy reasoning unit to obtain the access security risk value of the single subject; the access risk calculation unit for the entire system constructs an access risk matrix and performs summary calculation processing based on the access security risk value of the single subject output by the centroid method defuzzification unit information to obtain the overall system access security risk value.
[0061] After specific actual experiments, under the settings of two types of access subjects, three types of access assets and access environment simulating the real information system, the above method was run with the system configuration parameters of two types of access subjects, three types of access assets and access environment, with the long-term trust value of the access subject being 0.5, the weight vector of the access context trust factor being (0.3, 0.3, 0.25, 0.15), the discount coefficient being 1, the ordinary_score being 60 points, the special_score being 75 points, the access environment threat level being 45, and the environmental protection measures level being 75. The experimental data obtained is: the access security risk value of the entire system is 92.95.
[0062] In this embodiment, the long-term trust value of the access subject is 0.5, the corresponding weight vector of the trust factor is (0.3, 0.3, 0.25, 0.15), and the discount coefficient is 1. Set ordinary_score to 60 points and special_score to 75 points.
[0063] Without loss of generality, in this embodiment, two access subjects, subjectA and subjectB, and three access assets, asset1, asset2, and asset3, are used as examples.
[0064] Suppose subjectA is a legitimate administrator user within the enterprise, who accesses the system within the specified time, uses a legitimate device to access the system, and does not carry a trusted certificate; suppose subjectB is a legitimate ordinary user within the enterprise, who does not access the system within the specified time, does not use a legitimate device to access the system, and carries a trusted certificate.
[0065] Set the security level of asset1 to medium and the importance to 60; set the security level of asset2 to high and the importance to 80; set the security level of asset3 to low and the importance to 30;
[0066] Set the access environment threat level to 45 and the environmental protection measure level to 75.
[0067] Step 1: Subject trust value calculation and logical reasoning module
[0068] Step 1.1 Calculate the switching coefficient vector.
[0069] The switching coefficient vector of subjectA is (1,1,1,-1) T ; The switching coefficient vector of subject B is (1,-1,-1,1) T ;
[0070] Step 1.2 calculates the modified trust value of the access subject.
[0071] The modified trust value of subjectA is 0.5+1*(0.3,0.3,0.25,0.15)*(1,1,1,-1) T =1.2; the modified trust value of subject B is 0.5+1*(0.3,0.3,0.25,0.15)*(1,-1,-1,1) T =0.4.
[0072] Step 1.3 calculates the instant session trust value of the access subject.
[0073] The normalized trust value of subjectA is The instant session trust value is 76.9; the normalized trust value of subject B is The instant session trust value is 59.9.
[0074] Step 1.4 determines the ticket status obtained by the access subject in the current session.
[0075] The instant session trust value of subjectA is greater than special_score, so it can obtain a privileged ticket. The instant session trust value of subjectB is less than ordinary_score, so it cannot obtain any ticket.
[0076] Step 1.5 determines the set of assets that the access subject can access.
[0077] SubjectA can access assets of all security levels, that is, the asset set it can access is {asset1, asset2, asset3}. However, the asset set that subjectB can access is an empty set.
[0078] Step 2 Access the environmental risk calculation module
[0079] Step 2.1: Fuzzify the degree of environmental threat.
[0080] In this embodiment, the degree of membership of the environmental threat level belonging to a high threat level is 0, the degree of membership of the environmental threat level belonging to a medium threat level is 1, and the degree of membership of the environmental threat level belonging to a low threat level is 0.
[0081] Step 2.2: Fuzzify the level of environmental protection measures.
[0082] In this embodiment, the degree of membership of the environmental protection measure level belonging to the high protection level is 0.25, the degree of membership belonging to the medium protection level is 0.25, and the degree of membership belonging to the low protection level is 0.
[0083] Step 2.3 implements fuzzy reasoning according to the fuzzy rules to obtain the output membership corresponding to each rule.
[0084] In this embodiment, only rule 3 and rule 4 are activated, and the corresponding output memberships are 0.25 and 0.25 respectively.
[0085] Step 2.4 calculates the degree of membership of the risk level of the access environment to each fuzzy class.
[0086] In this embodiment, the values of Low_Env_Risk_Deg, Medium_Env_Risk_Deg and High_Env_Risk_Deg are respectively 0, 0.25 and 0. That is, the membership degrees of the risk levels of the access environment belonging to the risk levels of the access environment "low", "average" and "high" are respectively 0, 0.25 and 0.
[0087] Step 3: Access the asset value fuzzy calculation module
[0088] Step 3.1: Obfuscate the importance of accessing the asset.
[0089] In this embodiment, the importance of asset1 is 60, its membership in high importance is 0, its membership in medium importance is 1, and its membership in low importance is 0. The importance of asset2 is 80, its membership in high importance is 0.5, its membership in medium importance is 0, and its membership in low importance is 0. The importance of asset3 is 30, its membership in high importance is 0, its membership in medium importance is 0.5, and its membership in low importance is 0.
[0090] Step 3.2 implements fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule.
[0091] For asset1, only rule 4 is fired, and its corresponding output membership is 1; for asset2, only rule 1 is fired, and its corresponding output membership is 0.5; for asset3, only rule 5 is fired, and its corresponding output membership is 0.5.
[0092] Step 3.3 calculates the membership of the access asset value to each fuzzy class.
[0093] For asset1, the values of Low_Value_Deg, Medium_Value_Deg, and High_Value_Deg are 0, 1, and 0, respectively. That is, its membership of the access asset value "low", "average", and "high" are 0, 1, and 0, respectively.
[0094] For asset2, the values of Low_Value_Deg, Medium_Value_Deg, and High_Value_Deg are 0, 0, and 0.5, respectively. That is, its membership of the access asset value "low", "average", and "high" are 0, 0, and 0.5, respectively.
[0095] For asset3, the values of Low_Value_Deg, Medium_Value_Deg, and High_Value_Deg are 0.5, 0, and 0, respectively. That is, its membership of the access asset values "low", "average", and "high" are 0.5, 0, and 0, respectively.
[0096] Step 4: Subject risk fuzzy calculation and access risk integration module
[0097] According to step 1.5, the set of assets that subject B can access is an empty set, that is, the row of the access risk matrix corresponding to subject B is all zeros, so the calculation related to subject B is not considered in this embodiment.
[0098] Step 4.1 Fuzzify the trust level of the access subject
[0099] The trust value of subjectA is 76.9, its membership in the high trust level is 0.345, its membership in the medium trust level is 0.155, and its membership in the low trust level is 0.
[0100] Step 4.2 implements fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule.
[0101] For subjectA and asset1, rules 14 and 23 are fired, and their corresponding output memberships are 0.155 and 0.25 respectively; for subjectA and asset2, rules 13 and 22 are fired, and their corresponding output memberships are 0.155 and 0.25 respectively; for subjectA and asset2, rules 15 and 24 are fired, and their corresponding output memberships are 0.155 and 0.25 respectively.
[0102] Step 4.3 uses the centroid method to achieve defuzzification and obtain the access risk associated with a single subject and a single access asset.
[0103] For subjectA and asset1, the values of Very_Low_Risk_Sum, Low_Risk_Sum, Medium_Risk_Sum, High_Risk_Sum and Very_High_Risk_Sum are 0, 0.25, 0.155, 0, 0 respectively. The value of Risk_Center is (0*10+0.25*30+0.155*50+0*70+0*90) / (0+0.25+0.155+0+0)=37.65. That is, the output access risk is 37.65.
[0104] For subjectA and asset2, the values of Very_Low_Risk_Sum, Low_Risk_Sum, Medium_Risk_Sum, High_Risk_Sum and Very_High_Risk_Sum are 0, 0.25, 0.155, 0, 0 respectively. The value of Risk_Center is (0*10+0.25*30+0.155*50+0*70+0*90) / (0+0.25+0.155+0+0)=37.65. That is, the output access risk is 37.65.
[0105] For subjectA and asset3, the values of Very_Low_Risk_Sum, Low_Risk_Sum, Medium_Risk_Sum, High_Risk_Sum and Very_High_Risk_Sum are 0.25, 0.155, 0, 0, 0 respectively. The value of Risk_Center is (0.25*10+0.155*30+0*50+0*70+0*90) / (0.25+0.155+0+0+0)=17.65. That is, the output access risk is 17.65.
[0106] Step 4.5 Build an access risk matrix to calculate the access risk of the entire system: The calculated access risk matrix Summing all the values in the access risk matrix, we get the access risk of the entire information system to be 92.95.
[0107] Compared with the existing technology, this method starts from the perspective of user access security, combines access context security factors, the threat level and protection measures of the access environment, the value of the accessed assets and other factors in the form of fuzzy reasoning, and deduces and calculates the access security risk of the information system, filling the gap of the previous lack of dedicated system access security risk assessment methods.
[0108] The above-mentioned specific implementation can be partially adjusted in different ways by those skilled in the art without departing from the principle and purpose of the present invention. The protection scope of the present invention shall be based on the claims and shall not be limited by the above-mentioned specific implementation. Each implementation scheme within its scope shall be subject to the constraints of the present invention.
Claims
1. A method for assessing information system access risk based on access context logic reasoning, characterized in that: According to the security factors of the access subject's context, after obtaining the set of accessible assets of the access subject through logical reasoning through trust calculation and access policy set, the comprehensive trust level of the individual access subject, the risk level of the access environment and the value of the assets actually accessed are fuzzified, fuzzy reasoned and defuzzified to obtain the session access risk of the individual subject. After summary processing, the session access risk of the entire information system is obtained.
2. An information system access risk assessment system implementing the method of claim 1, characterized in that: include: A subject trust value calculation and logical reasoning module, an access environment risk degree calculation module, an access asset value calculation module, and a subject risk fuzzy calculation and access risk integration module, wherein: the subject trust value calculation and logical reasoning module calculates the set of assets accessible to the access subject based on the access subject's long-term trust value, the weight vector of the access subject's trust factors, and the trust score threshold; the access environment risk degree calculation module calculates the access risk degree fuzzy calculation value based on the environmental threat level and environmental protection measure level perceived by the information system security situation; the access asset value calculation module calculates the access asset value fuzzy calculation value based on the security level of the accessed asset and the importance of the accessed asset from the access asset database of the information system; the subject risk fuzzy calculation and access risk integration module calculates the access risk of the entire system based on the access subject trust value from the subject trust value calculation and logical reasoning, the access environment risk fuzzy calculation value from the access environment risk degree calculation, and the multi-asset value fuzzy calculation value from the access asset value calculation; The access subject trust factor vector is derived from various information related to the access subject during the access process, including the access subject's identity, access time, the device used for the access, and the certificate carried during the access.
3. The information system access risk assessment system according to claim 2, characterized in that: The subject trust value calculation and logical reasoning module includes: a switch coefficient vector calculation unit, a modified trust value calculation unit, an instant session trust value calculation unit and an access ticket granting unit, wherein: the switch coefficient vector calculation unit performs judgment and classification processing according to the security element information of the access context to obtain the result after the switch coefficient vector is assigned; the modified trust value calculation unit performs corresponding vector multiplication and addition processing according to the long-term trust of the access subject, the weight vector of the access context security element, and the output result information of the switch coefficient vector calculation unit to obtain the modified trust value of the access subject; the instant session trust value calculation unit performs normalization processing according to the output information of the modified trust value calculation unit to obtain the instant session trust value of the access subject; the access ticket granting unit performs judgment and classification processing according to the output information of the instant session trust value calculation unit to obtain the ticket that can be granted to the access subject.
4. The information system access risk assessment system according to claim 2, characterized in that: The access environment risk level calculation module includes: an access environment threat fuzzification processing unit, an access environment protection measure fuzzification processing unit, and an access environment risk fuzzy reasoning unit, wherein: the access environment threat fuzzification processing unit performs fuzzification processing according to the threat level information of the access environment to obtain a fuzzy category of the access environment threat; the access environment protection measure fuzzification processing unit performs fuzzification processing according to the access environment protection measure level information to obtain a fuzzy classification of the access environment protection measures; the access environment risk fuzzy reasoning unit performs fuzzy reasoning according to the output information of the access environment threat fuzzification processing unit and the output information of the access environment protection measures fuzzification processing unit to obtain a fuzzy classification result of the access environment risk.
5. The information system access risk assessment system according to claim 2, characterized in that: The access asset value calculation module includes: an access asset importance fuzzy processing unit and an access asset value fuzzy reasoning unit, wherein: the access asset importance fuzzy processing unit performs fuzzy processing according to the access asset importance value information to obtain the access asset importance fuzzy classification result, and the access unit asset value fuzzy reasoning performs fuzzy reasoning according to the access asset importance fuzzy processing unit information and the access asset security level to obtain the access asset value fuzzy classification result.
6. The information system access risk assessment system according to claim 2, characterized in that: The subject risk fuzzy calculation and access risk integration module includes: an access subject trust fuzzy processing unit, a single subject access risk fuzzy reasoning unit, a centroid method defuzzification unit and an access risk calculation unit for the entire system, wherein: the access subject trust fuzzy processing unit performs fuzzification processing based on the instant session trust value information output by the instant session trust value calculation unit to obtain the fuzzy trust class to which the access subject belongs; the single subject access risk fuzzy reasoning unit performs fuzzy reasoning processing according to the fuzzy trust class to which the access subject belongs output by the access subject trust fuzzy processing unit, the access environment risk fuzzy class output by the access environment risk fuzzy reasoning unit, and the access asset value classification information output by the access asset value fuzzy reasoning unit, according to the provided fuzzy rule set to obtain the single subject access risk fuzzy class; the centroid method defuzzification unit performs centroid method defuzzification processing based on the single subject access risk fuzzy class information output by the single subject access risk fuzzy reasoning unit to obtain the access security risk value of the single subject; the access risk calculation unit for the entire system constructs an access risk matrix and performs summary calculation processing based on the access security risk value of the single subject output by the centroid method defuzzification unit information to obtain the overall system access security risk value.
7. The information system access risk assessment system according to any one of claims 2 to 6, characterized in that: The long-term trust value of the access subject is stored in the access subject database and is obtained in the following way: 1) Calculate the switch coefficient vector: assign values to the switch coefficient vector (r1, r2, r3, r4) based on whether the identity of the input access subject is legal, whether the access time is compliant, whether the device used for access is compliant, and whether the certificate carried during access is credible. When a value meets the requirements, the corresponding switch coefficient value is 1, otherwise it is -1; 2) Calculate the modified trust value of the access subject: TrustAdjust = LongtermTrust + k*(x1, x2, x3, x4)*(r1, r2, r3, r4) T , where: TrustAdjust is the modified trust value of the access subject, LongtermTrust is the long-term trust value of the access subject, (x1, x2, x3, x4) is the weight vector of the input access subject trust factor, where each value is between 0 and 1 and satisfies x1+x2+x3+x4=1, (r1, r2, r3, r4) is the switch coefficient corresponding to each trust factor dimension, and the value range is {-1, 1}, and k is the discount coefficient, and the value range is (0, 1); 3) Calculate the instant session trust value of the access subject: After calculating the modified trust value, the trust value is normalized using the following Sigmoid formula: Among them: CurrentTrust is the normalized result, and CurrentTrust is mapped to between 0 and 100 as the instant session trust value of the access subject SessionTrust = CurrentTrust * 100; 4) Determine the ticket status of the access subject in the current session, that is, whether the access subject can obtain a ticket in the current session and what level of ticket can be obtained: By classifying the instant session trust value output in the previous step, the level of the ticket obtained is determined in combination with the trust score threshold. The trust score threshold includes ordinary_score and special_score, which represent the ordinary access trust score and privileged trust score required by the system respectively. When the trust value is less than ordinary_score, it is considered that the access subject has not obtained any ticket; when the trust value is greater than or equal to ordinary_score and less than special_score, it is considered that the access subject has obtained an ordinary-level ticket; when the trust value is greater than or equal to special_score, it is considered that the access subject has obtained a privileged-level ticket; 5) Determine the set of assets that the access subject can access, that is, determine the range of the asset set that the access subject can access in the current session through a set of logical reasoning rules: input the identity of the access subject and the ticket it obtains, and through logical reasoning of the set of logical reasoning rules, obtain the security level of the assets that the access subject can access, and then obtain the set of assets that the access subject can access.
8. The information system access risk assessment system according to any one of claims 2 to 6, characterized in that: The access risk level fuzzy calculation value is obtained by the following steps: 1) Fuzzy processing of the environmental threat level: Calculate and obtain the membership of the access environment to each threat level class, and divide the access environment threat level into three categories: Low_Threat, Medium_Threat and High_Threat, which represent the access environment threats: low, medium and high, respectively. Specifically: Where: x represents the threat level of the access environment, ranging from 0 to 100. 2) Fuzzy processing of the environmental protection level: Calculate and obtain the membership of the access environment protection level to each fuzzy class, and divide the access environment protection level into three categories: Low_Protection, Medium_Protection and High_Protection, which represent the access environment protection level: low, medium and high, respectively. Specifically: Where: x represents the protection level of the access environment, ranging from 0 to 100. 3) Implement fuzzy reasoning according to fuzzy rules, calculate and obtain the output membership corresponding to each rule, including: 3.1) According to the membership of each fuzzy class corresponding to the threat level of the access environment and the level of environmental protection measures, the risk level of the access environment is further divided into three categories: Low_Env_Risk, Medium_Env_Risk and High_Env_Risk, which represent the risk level of the access environment: low, medium and high. Specifically: Where: x represents the risk level of the access environment, ranging from 0 to 100. 3.2) According to the membership of the three fuzzy classes of low environmental threat level, medium environmental threat level and high environmental threat level, and the membership of the three fuzzy classes of low environmental protection measure level, medium environmental protection measure level and high environmental protection measure level, based on the access environment risk level rule set, the access environment threat level class and the access environment protection measure level class, fuzzy reasoning is implemented, and the 9 rules in the table are traversed. The membership of the access environment risk fuzzy class is calculated for the ignited rules respectively, specifically: μ(env_risk∈Env-Risk)=min[μ(threat∈Threat),μ(protection∈Protection)], where : , μ(threat∈Threat) indicates the degree of membership of the environmental threat level to a certain fuzzy class (Low_Threat, Medium_Threat or High_Threat), μ(protection∈Protection) indicates the degree of membership of the environmental protection measure level to a certain fuzzy class (Low_Protection, Medium_Protection or High_Protection), μ(env_risk∈Env_Risk) indicates the degree of membership of the environmental risk level to a certain fuzzy class (Low_Env_Risk, Medium_Env_Risk or High_Env_Risk); 4) Calculate the membership of the risk level of the access environment to each fuzzy class: Combined with the output membership results corresponding to each rule, take the maximum value of the membership of the same fuzzy class output by each rule as the membership of the risk level of the access environment to each fuzzy class, specifically: Low_Env_Risk_Deg = max{μ(env_risk∈Low_Env_Risk)in fired rules}, Medium_Env_Risk_Deg = max{μ(env_risk∈Medium_Env_Risk)in fired rules}, High_Env_Risk_Deg = max{μ(env_risk∈High_Env_Risk)in fired rules}, where: Low_Env_Risk_Deg indicates that the risk level of the access environment belongs to the low risk level of the access environment, Medium_Env_Risk_Deg indicates that the risk level of the access environment belongs to the average risk level of the access environment, and High_Env_Risk_Deg indicates that the risk level of the access environment belongs to the high risk level of the access environment.
9. The information system access risk assessment system according to any one of claims 2 to 6, characterized in that: The fuzzy calculated value of the accessed asset value is obtained in the following way: 1) Fuzzy processing of the importance of access assets: Calculate and obtain the membership of the importance of access assets to each fuzzy class, and divide the importance of access assets into three categories: Low_Importance, Medium_Importance and High_Importance, which represent the importance of access assets: low, medium and high, respectively. Specifically: Where: x represents the importance of accessing assets, ranging from 0 to 100 in a closed interval; The security level for accessing assets is divided into three categories: Low_SecurityLevel, Medium_SecurityLevel and High_SecurityLevel, which represent asset security levels: low, medium and high respectively; 2) Implement fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule, including: 2.1) The asset value is divided into three categories: Low_Value, Medium_Value and High_Value, which represent the access asset value: low, medium and high, respectively. Specifically: Where: x represents the value of the access asset, ranging from 0 to 100; 2.2) According to the membership of the three classes of low security level, medium security level and high security level of the access asset security level and the membership of the three fuzzy classes of low importance, medium importance and high importance of the access asset importance; then according to the access asset value level rule set, combined with the access asset security level and the access asset importance class, fuzzy reasoning is implemented, and the 9 rules in the table are traversed to calculate the membership of the access asset value respectively, which is: μ(value∈Value)=min[μ(securitylevel∈SecurityLevel),μ(importance∈Importance)], where: ,μ(securitylevel∈SecurityLevel) ityLevel) indicates the membership of the asset security level to a certain class (Low_SecurityLevel, Medium_SecurityLevel or High_SecurityLevel), μ(importance∈Importance) indicates the membership of the asset importance to a certain fuzzy class (Low_Importance, Medium_Importance or High_Importance), μ(value∈Value) indicates the membership of the value of accessing the asset to a certain fuzzy class (Low_Value, Medium_Value or High_Value); 3) Calculate the membership of the access asset value to each fuzzy class: According to the inference results of multiple fuzzy rules that are fired, take the maximum value of the membership of the same fuzzy class output by each rule as the membership of the access asset value to each fuzzy class, specifically: Low_Value_Deg = max{μ(value∈Low_Value)in fired rules}, Medium_Value_Deg = max{μ(value∈Medium_Value)in fired rules}, High_Value_Deg = maxμ(value∈High_Value)in fired rules}, where: Low_Value_Deg indicates that the value of the access asset belongs to the low access asset value, Medium_Value_Deg indicates that the value of the access asset belongs to the average access asset value, and High_Value_Deg indicates that the value of the access asset belongs to the high access asset value.
10. The information system access risk assessment system according to any one of claims 2 to 6, characterized in that: The access risk of the entire system is obtained in the following ways: 1) Fuzzify the trust level of the access subject: Combined with the instant session trust value obtained in step 1, calculate and obtain the membership of the access subject to each class of the fuzzy trust level, and divide the trust level of the subject into three categories: Low_Trust, Medium_Trust and High_Trust, which represent the three categories of low, medium and high security of the user subject, respectively. Specifically: Where: x represents the session trust score of the access subject, ranging from 0 to 100. 2) Implement fuzzy reasoning according to fuzzy rules to obtain the output membership corresponding to each rule, including: 2.1) The risks brought by a single subject to the entire system are divided into five categories: Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk and Very_High_Risk, which respectively represent the very low, low, medium, high and very high risks brought by the subject to the entire system. Specifically: Where: x represents the threat level of the access environment, ranging from 0 to 100. 2.2) According to the membership of the subject trust level to the three fuzzy classes of low trust level, medium trust level and high trust level, the membership of the environmental risk level to the three fuzzy classes of low environmental risk level, medium environmental risk level and high environmental risk level, and the membership of the asset value to the three fuzzy classes of low asset value, medium asset value and high asset value, according to the subject access risk fuzzy rule set, fuzzy reasoning is implemented to calculate the output membership of each ignited rule: μ(risk∈Risk)=min[μ(trust∈Trust},μ(env_risk∈Env_Risk),μ(value∈Value)], where: ,μ(trust∈Trust) indicates that the subject trust level belongs to a certain class (Low_Trust,Mediu m_Trust or High_Trust class), μ(env_risk∈Env_Risk) indicates the degree of membership of the environmental risk level to a certain fuzzy class (Low_Env_Risk, Medium_Env_Risk or High_Env_Risk), μ(value∈Value) indicates the degree of membership of the value of the access asset to a certain fuzzy class (Low_Value, Medium_Value or High_Value), μ(risk∈Risk) indicates the degree of membership of the access risk to a certain fuzzy class (Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk or Very_High_Risk class); 3) Defuzzification is achieved using the centroid method to obtain the access risks associated with a single subject and a single access asset, including: 3.1) Combine the reasoning results of multiple ignited fuzzy rules and merge the membership of the same fuzzy class: divide the access risk into five categories: Very_Low_Risk, Low_Risk, Medium_Risk, High_Risk and Very_High_Risk. According to the results calculated by each rule in the previous step, merge the membership of the three categories respectively to obtain the total membership of each category, specifically: Very_Low_Risk_Sum=∑μ(risk∈Very_Low_Risk), Low_Risk_Sum=∑μ(risk∈Low_Risk), Medium_Risk_Sum=∑μ(risk∈Medium_Risk), High_Risk_Sum=∑μ(risk∈High_Risk), Very_High_Risk_Sum=∑μ(risk∈Very_High_Risk); 3.2) Combined with the total membership of each category, the centroid method is used to calculate the asset value: the centroid value Very_Low_Risk_Center of the Very_Low_Risk category is 10; the centroid value Low_Risk_Center of the Low_Risk category is 30; the centroid value Medium_Risk_Center of the Medium_Risk category is 50; the centroid value High_Risk_Center of the High_Risk category is 70; the centroid value Very_High_Risk_Center of the Very_High_Risk category is 90; Calculate the asset value from an overall perspective and obtain the access risk associated with a single subject and a single access asset, specifically: 4) Construct an access risk matrix to calculate the access risk of the entire system: The access risk of the entire system is calculated based on the access risk calculation values of all current subjects in the system and all the access assets they can access, specifically: 4.1) Constructing the access risk matrix: Each access subject in the system corresponds to a row in the access risk matrix. For all access subjects in the system, we need to traverse the asset sets that they can access and calculate the access risk values pairwise. When an access subject cannot access an asset, the access risk between the two is considered to be 0. After obtaining the access risks of all subjects and all access assets, we construct the following access risk matrix: Where: m represents the number of access entities, n represents the number of access assets, r ij AccessRisk(IS) = ∑ 0<i≤m,0<j≤n r ij ; 4.2) Calculate the overall access risk of the system. Sum up the elements in the access risk matrix to get the access risk of the entire system.
Citation Information
Patent Citations
Cloud data center real-time risk assessment method based on mainframe log analysis
CN104125217A
An information security risk assessment method and a system for an intelligent network connection vehicle
CN109146240A
Information security risk assessment method and device, equipment and storage medium
CN111444514A
5G data safety risk evaluation method and evaluation system
CN112769747A
Zero-trust system main body trust degree dynamic evaluation system based on fuzzy reasoning
CN116015769A