Data security risk assessment method and device, equipment and storage medium

By simulating different attack strengths and methods to carry out multiple attacks on the target device, obtain vulnerability information and evaluate its severity, the problem of insufficient accuracy in a security environment is solved, and higher evaluation accuracy and reliability are achieved.

CN120046161AActive Publication Date: 2025-05-27TANGSHAN CAOFEIDIAN LIANCHENG TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510533733.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-05-27
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

Traditional data security risk assessment methods are insufficient in a secure environment, making it difficult to fully reflect the security risks faced by data.

Method used

By simulating different attack strengths and methods, multiple attacks are carried out on the target device, vulnerability information is obtained, and the vulnerability serious score is determined based on this information, and data security risks are evaluated based on the attack strength.

Benefits of technology

It improves the accuracy and reliability of data security risk assessment, allowing users to more accurately understand the data security situation, formulate targeted risk control measures, and improve data security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046161A_ABST
    Figure CN120046161A_ABST
Patent Text Reader

Abstract

The invention provides a data security risk assessment method and device, equipment and a storage medium, and belongs to the technical field of data security, and the method comprises the following steps: carrying out simulation attacks on target equipment storing target data for multiple times with different attack intensities and / or different attack modes to obtain multiple pieces of vulnerability information; determining a plurality of vulnerability severity scores based on the multiple pieces of vulnerability information; each piece of vulnerability information corresponds to one vulnerability severity score; and evaluating the security risk of the target data based on the attack intensity and the plurality of vulnerability severity scores to obtain a target security risk evaluation value. According to the data security risk assessment method and device, the equipment and the storage medium provided by the invention, the accuracy and reliability of data security risk assessment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the technical field of data security, and more specifically, relates to a data security risk assessment method, device, equipment, and storage medium. Background Art

[0002] Traditional data security risk assessments, for example, mostly evaluate attributes such as the confidentiality, integrity, and availability of data, identify threats faced by the data and existing vulnerabilities, assess the likelihood of security incidents occurring and the possible impacts, thereby determining the risk level, and proposing corresponding risk control measures.

[0003] However, the accuracy and reliability of evaluating data security risks only in a secure environment are insufficient, and an accurate and reliable data security risk assessment method is needed. Summary of the Invention

[0004] The purpose of the present disclosure is to provide a data security risk assessment method, device, equipment, and storage medium to improve the accuracy and reliability of data security risk assessment.

[0005] In the first aspect of the embodiments of the present disclosure, a data security risk assessment method is provided, including: Performing multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; Determining multiple vulnerability severity scores based on the multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score; Evaluating the security risk of the target data based on the attack intensity and the multiple vulnerability severity scores to obtain a target security risk assessment value.

[0006] In the second aspect of the embodiments of the present disclosure, a data security risk assessment device is provided, including: A simulated attack module for performing multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; A score determination module for determining multiple vulnerability severity scores based on the multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score; A risk assessment module for evaluating the security risk of the target data based on the attack intensity and the multiple vulnerability severity scores to obtain a target security risk assessment value.

[0007] In the third aspect of the embodiments of the present disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the above data security risk assessment method are implemented.

[0008] In the fourth aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned data security risk assessment method are implemented.

[0009] The beneficial effects of the data security risk assessment method, apparatus, device, and storage medium provided by the embodiments of the present disclosure are as follows: By simulating actual attack scenarios, the present disclosure takes into account different attack intensities and different attack methods. Compared with traditional assessment methods, it can more comprehensively and realistically reflect the security risks faced by target data. The assessment results in the present disclosure are obtained based on a comprehensive analysis of the attack intensities and vulnerability severity scores of multiple simulated attacks, with higher accuracy and reliability, enabling users to more accurately understand the security status of their own data, formulate risk control measures targeted, effectively improve the data security protection ability, and ensure the security of data assets. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0011] Figure 1 It is a schematic flowchart of the data security risk assessment method provided by an embodiment of the present disclosure; Figure 2 It is a structural block diagram of the data security risk assessment apparatus provided by an embodiment of the present disclosure; Figure 3 It is a schematic block diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0012] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present disclosure. However, those skilled in the art should clearly understand that the present disclosure can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present disclosure.

[0013] To make the objectives, technical solutions, and advantages of the present disclosure clearer, the following will be described through specific embodiments with reference to the drawings.

[0014] Please refer to Figure 1 , Figure 1The flowchart of the data security risk assessment method provided by an embodiment of the present disclosure, the method includes: S101: Perform multiple simulated attacks on the target device storing the target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information.

[0015] In this embodiment, the target device refers to the device storing the target data, which can be any device that stores and processes data, such as a server, a personal computer, a mobile terminal, etc. The target data refers to the data that needs to be subjected to security risk assessment. Multiple simulated attacks refer to repeatedly performing operations on the target device that simulate real attack scenarios, aiming to detect the security protection ability of the target device and discover security vulnerabilities. The ways of simulated attacks can include attacks at the network level (such as port scanning, denial-of-service attacks, etc.), attacks at the application level (such as injection attacks using application vulnerabilities, etc.), and attacks at the system level (such as privilege escalation attacks using operating system vulnerabilities, etc.). Vulnerability information refers to the relevant information about the defects or weak links existing in the security of the target device discovered through simulated attacks, such as the type of vulnerability, the location of the vulnerability, the severity of the vulnerability, vulnerability association information, etc. Vulnerability information can be obtained by scanning and detecting the system, application programs, network services, etc. of the target device with a vulnerability scanning tool.

[0016] In this embodiment, the target data refers to the data that needs to be protected and stored in the target device, which can include personal privacy data, user order information, customer personal information, etc., or some relatively conventional data, for example, the attendance records, salary data of enterprise employees, and some conventional project documents, etc.

[0017] In this embodiment, different attack intensities and / or different attack methods specifically can refer to different attack intensities and the same attack method, or the same attack intensity and different attack methods, or different attack intensities and different attack methods. To ensure the accuracy of data security risk assessment, it is preferably to perform multiple simulated attacks on the target device storing the target data with different attack intensities and different attack methods to obtain multiple vulnerability information.

[0018] It should be noted that in this embodiment, before each execution of the simulated attack, the target device is in an initial state; each simulated attack corresponds to one piece of vulnerability information, that is, the target device returns to a standard state that is not affected by the previous simulated attack before each simulated attack to ensure the independence and fairness of each simulated attack and avoid the system changes caused by the previous attack from interfering with the subsequent attack results. For example, restore the system configuration of the target device to the default settings and clear the malware, modified files, etc. left by the previous simulated attack.

[0019] In this embodiment, each simulated attack generates vulnerability information corresponding to this simulated attack. This vulnerability information is caused by this simulated attack. It can be understood that a single simulated attack may generate multiple vulnerabilities. The vulnerability information in this embodiment includes a summary of all vulnerabilities generated by a single simulated attack.

[0020] S102: Determine multiple vulnerability severity scores based on multiple pieces of vulnerability information; each piece of vulnerability information corresponds to a vulnerability severity score.

[0021] In this embodiment, the vulnerability information includes: vulnerability association information; Determining multiple vulnerability severity scores based on multiple pieces of vulnerability information includes: Adjust the general score of the vulnerability corresponding to this simulated attack based on the vulnerability association information after each simulated attack to obtain multiple vulnerability severity scores; among them, each piece of vulnerability association information is determined based on the vulnerability relationship graph.

[0022] In this embodiment, the Common Vulnerability Scoring System (CVSS) is used to score all vulnerabilities that appear in the target device after each simulated attack, and the sum of the scores is the general score.

[0023] Considering that CVSS usually mainly evaluates and scores individual vulnerabilities and does not directly consider the correlation between vulnerabilities. Therefore, in this embodiment, the general score of the vulnerability corresponding to this simulated attack is adjusted based on the vulnerability association information obtained after each simulated attack. For example, when a feature indicating a strong vulnerability association appears in the vulnerability association information, the general score of the vulnerability corresponding to this simulated attack can be increased to obtain the vulnerability severity score corresponding to this simulated attack.

[0024] It should be noted that the vulnerability association information is not limited to the vulnerability association information of a single vulnerability, that is, it can be understood that the general score of the vulnerability corresponding to this simulated attack is adjusted based on the vulnerability association information of all vulnerabilities obtained after each simulated attack, and the general score is not limited to a single vulnerability.

[0025] Similarly, in this embodiment, the vulnerability severity score is the result of comprehensively scoring all vulnerabilities that appear in the target device after each simulated attack. It can be understood that the vulnerability severity score is not limited to the score of a single vulnerability, but can also be the sum of the scores obtained by adjusting the general scores of multiple vulnerabilities.

[0026] S103: Evaluate the security risk of the target data based on the attack intensity and multiple vulnerability severity scores to obtain the target security risk assessment value.

[0027] In this embodiment, the attack intensity is used to measure the strength, complexity, or the degree of possible impact on the target device of each simulated attack. The attack intensity can be determined based on the attack duration, attack complexity, and resource investment of each simulated attack, that is, different attack intensities can be obtained by adjusting at least one of the following parameters: Attack duration, attack complexity, and resource investment.

[0028] In this embodiment, the simulated attack intensity of each simulated attack can be obtained based on weighted calculation. For example, the simulated attack intensity at the time of each simulated attack is determined based on the first formula, and the first formula can be: , where represents the attack intensity of the th simulated attack, represents the attack duration coefficient of the th simulated attack, represents the attack complexity coefficient of the th simulated attack, represents the quantified value of the resource investment of the th simulated attack, is the weight coefficient, which can be set based on experience or actual requirements. By adjusting the , and / or in the first formula, different attack intensities can be obtained.

[0029] It should be noted that , and are all values between 0 and 1, that is, they have been normalized. The acquisition and normalization of the attack duration will not be elaborated here. The acquisition method of the attack complexity coefficient can be to divide common attack techniques into multiple levels according to difficulty, such as simple, medium, difficult, and extremely difficult, and assign corresponding numerical values.

[0030] Specifically, simple attack techniques such as basic port scanning can be completed only by using common scanning tools, and its corresponding complexity level is set to level 1. Medium-difficulty attack techniques such as ordinary structured query language injection attacks require the attacker to have certain database knowledge and the ability to analyze application program vulnerabilities, and its complexity level is set to level 2. Difficult-level attack techniques such as attacking using complex operating system kernel vulnerabilities require in-depth understanding of the underlying principles of the operating system and excellent vulnerability exploitation skills, and are set to level 3. Extremely difficult attack techniques such as cracking attacks against new encryption algorithms involve cutting-edge cryptography knowledge and a large amount of computing resource investment, and are set to level 4. Secondly, a numerical value between 0 and 1 is pre-assigned to each level.

[0031] In this embodiment, the quantified value of resource input can be obtained by calculating the network bandwidth consumed by the simulated attack. For example, setting a benchmark bandwidth, the quantified value of resource input can be the ratio of the bandwidth used in the simulated attack to the benchmark bandwidth.

[0032] It should be noted that the simulated attack in this embodiment is not an external malicious attack, but an attack using known attack means, attack complexity, and resource input values in the prior art. Therefore, in this embodiment, various parameters of the simulated attack can be obtained and calculated.

[0033] In this embodiment, the security risk of the target data can be evaluated by means of mapping relationship or weighted calculation, etc.

[0034] It can be concluded from the above that by simulating the actual attack scenario, the present disclosure considers different attack intensities and different attack methods. Compared with the traditional evaluation method, it can more comprehensively and realistically reflect the security risks faced by the target data. The evaluation results in the present disclosure are obtained based on the comprehensive analysis of the attack intensities and vulnerability severity scores of multiple simulated attacks, with higher accuracy and reliability, enabling users to more accurately understand the security status of their own data, formulate risk control measures in a targeted manner, effectively improve the data security protection ability, and ensure the security of data assets.

[0035] In an embodiment of the present disclosure, different attack methods include network simulation attack, application simulation attack, and system simulation attack; Perform multiple simulated attacks on the target device storing the target data with different attack intensities and / or different attack methods to obtain a plurality of vulnerability information, including: Perform M network simulation attacks on the target device storing the target data with different attack intensities to obtain M pieces of vulnerability information; Perform N application simulation attacks on the target device storing the target data with different attack intensities to obtain N pieces of vulnerability information; Perform L system simulation attacks on the target device storing the target data with different attack intensities to obtain L pieces of vulnerability information; wherein, M, N, and L are positive integers, and the sum of M, N, and L is the total number of simulated attacks. The values of M, N, and L are determined based on the historical attack data of the target device.

[0036] In this embodiment, network simulation attacks refer to simulating various possible attack behaviors at the network level, such as port scanning, network sniffing, denial-of-service attacks or distributed denial-of-service attacks, etc., to detect security vulnerabilities in the network communication and network configuration of the target device. Application simulation attacks are targeted at the application programs running on the target device, for example, by exploiting input validation vulnerabilities of the application programs (such as structured query language injection attacks, command injection), authentication vulnerabilities, etc., to discover security risks existing in the application programs. System simulation attacks are targeted at the operating system of the target device, such as attempting to attack by exploiting kernel vulnerabilities, privilege management vulnerabilities, etc., of the operating system to find security vulnerabilities at the operating system level.

[0037] In this embodiment, relevant data on various attacks that the target device has suffered in the past are referred to, such as the types of attacks, frequencies, successful attack cases, etc., to determine the number of network simulation attacks (M), the number of application simulation attacks (N), and the number of system simulation attacks (L).

[0038] For example, if the target device has often suffered network-level attacks in the past, then M can be set relatively large to more comprehensively detect the security vulnerabilities of the device in terms of the network. More specifically, if the number of times the target device has been attacked by the network accounts for one-half of the total number of times, then the value of M can account for one-half of the total number of simulation attacks, that is, the proportion of the number of simulation attacks of each type is the same as the proportion of the number of real attacks of the same type. A total number of simulation attacks can be preset, for example, it can be 100 times.

[0039] From the above, it can be concluded that by subdividing the simulation attacks into three levels: network, application, and system, the present disclosure can comprehensively cover various security threats that the target device may face and improve the authenticity of the simulation attacks. The present disclosure determines the number of simulation attacks according to the proportion of each type of attack in the historical attacks, so that the distribution of the simulation attacks is consistent with the actual attack distribution, ensuring that the evaluation method always matches the actual attack situation, thereby enhancing the reliability of the evaluation results.

[0040] In an embodiment of the present disclosure, the security risk of the target data is evaluated based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk evaluation value, including: substituting the attack intensity and multiple vulnerability severity scores during multiple simulation attacks into the second formula to evaluate the security risk of the target data; the second formula can be: , where represents the target security risk evaluation value, represents the simulation attack intensity of the th simulation attack, represents the total number of simulation attacks, represents the The number of vulnerabilities after the n-th simulated attack, represents the severity score of the

[0041] The second formula can be understood as the sum of the severity scores of all vulnerabilities found in the n-th simulated attack, reflecting the overall severity of the vulnerabilities of the target device revealed by this simulated attack. It takes into account the amplification effect of the attack intensity on the vulnerability hazard level. For example, if a high-intensity attack discovers multiple severe vulnerabilities, then its threat to the target data security will be greater.

[0042] The larger the finally obtained security risk assessment value of the target data, the higher the security risk faced by the target data.

[0043] In this embodiment, a method for adjusting the general score is provided: Based on the vulnerability association information after each simulated attack, adjust the general score of the corresponding vulnerability of this simulated attack to obtain multiple vulnerability severity scores, including: In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the association degree with the first vulnerability being greater than the target threshold, and the number of the second vulnerabilities being less than the target number, increase the general score of the corresponding vulnerability of this simulated attack based on the first step length to obtain the vulnerability severity score; wherein, the first vulnerability is a vulnerability affecting the preset data security, and the preset data is the data in the target data; the second vulnerability is a vulnerability that depends on the dependent vulnerability; In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the association degree with the first vulnerability being less than or equal to the target threshold, and the number of the second vulnerabilities being greater than or equal to the target number, increase the general score of the corresponding vulnerability of this simulated attack based on the second step length to obtain the vulnerability severity score.

[0044] In an embodiment of the present disclosure, based on the vulnerability association information after each simulated attack, adjust the general score of the corresponding vulnerability of this simulated attack to obtain multiple vulnerability severity scores, further including: In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the association degree with the first vulnerability being greater than the target threshold, and the number of the second vulnerabilities being greater than or equal to the target number, increase the general score of the corresponding vulnerability of this simulated attack based on the third step length; wherein, the third step length is greater than the first step length and the second step length.

[0045] In this embodiment, the preset data refers to the important data preset in the target data, such as the confidential information of an enterprise, project quotations, tender information, etc. The dependent vulnerability refers to a vulnerability that serves as a prerequisite for exploiting other vulnerabilities during the vulnerability exploitation process. For example, in a system, vulnerability A allows an attacker to obtain ordinary user privileges, and vulnerability B can be exploited to further obtain administrator privileges only on the basis of having ordinary user privileges. Here, vulnerability A is the dependent vulnerability because the exploitation of vulnerability B depends on vulnerability A being successfully exploited first so that the attacker can meet the conditions for exploiting vulnerability B. Dependent vulnerabilities generally occupy a relatively early position in the attack path and provide the necessary environment or conditions for the exploitation of other subsequent vulnerabilities. By exploiting dependent vulnerabilities, an attacker can create scenarios that can trigger other vulnerabilities, thereby achieving purposes such as gradually penetrating the system, escalating privileges, or obtaining sensitive information. The second vulnerability refers to other vulnerabilities that depend on the dependent vulnerability.

[0046] Specifically, the first case: When the vulnerability association information after the simulated attack shows that there is a vulnerability that is a dependent vulnerability, and its association degree with the first vulnerability is greater than the target threshold, and at the same time the number of second vulnerabilities depending on it is less than the target number, then the general score of the vulnerability corresponding to this simulated attack can be increased by the first step length, indicating that in this case, this dependent vulnerability is closely related to the first vulnerability (i.e., the vulnerability affecting the security of the preset data), but the number of other vulnerabilities depending on it is small, so a certain range (the first step length) of score increase is given.

[0047] The second case: If the vulnerability association information indicates that this vulnerability is a dependent vulnerability, and its association degree with the first vulnerability is less than or equal to the target threshold, and at the same time the number of second vulnerabilities depending on it is greater than or equal to the target number, then the general score of the vulnerability corresponding to this simulated attack is increased by the second step length at this time, and then the severity score of this vulnerability is obtained. It shows that under this condition, this dependent vulnerability is relatively less closely related to the first vulnerability, but the number of other vulnerabilities depending on it is large, so the score is increased according to the second step length.

[0048] The third case: When the vulnerability association information shows that this vulnerability is a dependent vulnerability, and its association degree with the first vulnerability is greater than the target threshold, and at the same time the number of second vulnerabilities depending on it is greater than or equal to the target number, the general score of the vulnerability corresponding to this simulated attack is increased by the third step length. Since in this case this dependent vulnerability is both closely related to the first vulnerability and has many other vulnerabilities depending on it, the largest third step length is given for score increase.

[0049] The first step length, the second step length, and the third step length can be determined based on experience or during the experimental process. There is no clear limitation on the size relationship between the first step length and the second step length, but the third step length is greater than the first step length, and the third step length is greater than the second step length.

[0050] In this embodiment, when the vulnerability association information after the simulated attack does not meet the above three situations or conditions, the general score of the vulnerability corresponding to this simulated attack may not be adjusted, and the general score of the vulnerability corresponding to this simulated attack is directly used as the vulnerability severity score.

[0051] It should be noted that in this embodiment, the first vulnerability and the second vulnerability are not two conflicting concepts. Therefore, a vulnerability can be both the first vulnerability and the second vulnerability. A vulnerability can be a dependent vulnerability of other vulnerabilities, and at the same time, it can also be a vulnerability that depends on other vulnerabilities. The target threshold and target quantity in this embodiment can be determined based on experience.

[0052] Since the foregoing vulnerability association information is not limited to the vulnerability association information of one vulnerability, the "in response to the vulnerability association information after the simulated attack being" referred to in this embodiment can be understood as "there exists in the vulnerability association information after the simulated attack", that is, as long as there is one vulnerability among the vulnerabilities obtained by the target device after being subjected to the simulated attack that meets one of the above three conditions, it means that the general score of the vulnerability corresponding to this simulated attack needs to be adjusted accordingly.

[0053] It can be concluded from the above that the present disclosure incorporates the simulated attack intensity and the vulnerability severity score into the evaluation formula, comprehensively considers the amplification effect of the attack intensity on the vulnerability harm degree, can more accurately evaluate the security risk faced by the target data, and avoids the inaccurate evaluation caused by simply considering the number of vulnerabilities or the attack intensity. The present disclosure takes into account the correlation between vulnerabilities and adjusts the general score according to the vulnerability association information, which can more truly reflect the actual harm degree of the vulnerabilities and enhance the reliability of the evaluation result.

[0054] The foregoing vulnerability association information is determined based on the vulnerability relationship graph. Specifically, before adjusting the general score of the vulnerability corresponding to each simulated attack according to the vulnerability association information after each simulated attack to obtain multiple vulnerability severity scores, it further includes: Processing each vulnerability based on the graph theory algorithm to obtain a vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the association degree of the two nodes of the edge.

[0055] In this embodiment, the graph theory algorithm is a mathematical method for processing graph-structured data. In this scenario, each vulnerability can be used as the processing object, and these vulnerabilities are analyzed and processed by applying the graph theory algorithm (such as depth-first search, breadth-first search, shortest path algorithm, etc.).

[0056] Specifically, based on the correlation relationships between vulnerabilities (such as the exploitation of vulnerability E making it easier to exploit vulnerability F, or vulnerabilities G and H often occurring simultaneously, etc.), the connection methods and tightness degrees between vulnerabilities are determined.

[0057] The constructed vulnerability relationship graph is a graph structure with vulnerabilities as nodes. Each vulnerability is represented by a node in the graph, and the node can contain some basic information about the vulnerability, such as vulnerability number, type, description, etc. The edges in the graph represent the correlation relationships between vulnerabilities, and the thickness of the edge is used to intuitively reflect the correlation degree between the two vulnerability nodes connected by the edge. The higher the correlation degree, the thicker the edge; the lower the correlation degree, the thinner the edge.

[0058] For example, if the correlation between vulnerability X and vulnerability Y is very tight and they often appear and cooperate with each other in many attack scenarios, then the edge connecting them will be relatively thick; conversely, if the correlation between vulnerability P and vulnerability Q is weak and they only occasionally have a connection in some specific situations, then the edge between them will be relatively thin.

[0059] In this embodiment, whether a vulnerability is a dependent vulnerability in the foregoing vulnerability correlation information can be determined based on the connection method of the vulnerability in the vulnerability relationship graph, and whether the correlation degree with the first vulnerability is greater than the target threshold can be determined by comparing the thickness of the connection line between this vulnerability and the first vulnerability, that is, the target threshold corresponds to a target thickness. When the thickness of the connection line is greater than the target thickness, the vulnerability correlation information is that the correlation degree with the first vulnerability is greater than the target threshold. Whether the number of the second vulnerabilities in the vulnerability correlation information is less than the target number can be determined based on the number of vulnerabilities connected to it in the vulnerability relationship graph.

[0060] It should be noted that the construction of the vulnerability relationship graph is based on a large amount of vulnerability data in the history of the target device or during the testing process, that is, the construction of the vulnerability relationship graph precedes the evaluation process of conducting simulated attacks.

[0061] From the above, it can be concluded that the present disclosure analyzes and processes each vulnerability through graph theory algorithms, constructs a vulnerability relationship graph with vulnerabilities as nodes, clarifies the correlation relationships between vulnerabilities, and makes the security risk assessment more in line with the actual situation.

[0062] Corresponding to the data security risk assessment method in the foregoing embodiment, Figure 2 is a structural block diagram of a data security risk assessment device provided by an embodiment of the present disclosure. For ease of illustration, only the parts related to the embodiments of the present disclosure are shown. Refer to Figure 2 The data security risk assessment device 20 includes: a simulated attack module 21, a score determination module 22, and a risk assessment module 23.

[0063] Among them, the simulation attack module 21 is configured to perform multiple simulation attacks on a target device storing target data with different attack intensities and / or different attack methods, so as to obtain multiple vulnerability information; The score determination module 22 is configured to determine multiple vulnerability severity scores based on the multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score; The risk assessment module 23 is configured to evaluate the security risk of the target data based on the attack intensity and the multiple vulnerability severity scores, so as to obtain a target security risk assessment value.

[0064] In an embodiment of the present disclosure, the different attack methods include network simulation attacks, application simulation attacks, and system simulation attacks; the simulation attack module 21 is specifically configured to perform M network simulation attacks on a target device storing target data with different attack intensities, so as to obtain M vulnerability information; Perform N application simulation attacks on a target device storing target data with different attack intensities, so as to obtain N vulnerability information; Perform L system simulation attacks on a target device storing target data with different attack intensities, so as to obtain L vulnerability information; Wherein, M, N, and L are positive integers, and the sum of M, N, and L is the total number of simulation attacks, and the values of M, N, and L are determined based on the historical attack data of the target device.

[0065] In an embodiment of the present disclosure, the vulnerability information includes: vulnerability association information; The data security risk assessment device 20 further includes: The score determination module 22 is specifically configured to adjust the general score of the vulnerability corresponding to the simulation attack based on the vulnerability association information after each simulation attack, so as to obtain multiple vulnerability severity scores; wherein, each vulnerability association information is determined based on a vulnerability relationship graph.

[0066] In an embodiment of the present disclosure, the score determination module 22 is specifically further configured to, in response to the vulnerability association information after the simulation attack being a dependent vulnerability, and the association degree with the first vulnerability being greater than a target threshold, and the number of the second vulnerabilities being less than the target number, increase the general score of the vulnerability corresponding to the simulation attack based on a first step length to obtain a vulnerability severity score; wherein, the first vulnerability is a vulnerability affecting the preset data security, and the preset data is the data in the target data; the second vulnerability is a vulnerability depending on the dependent vulnerability; In response to the vulnerability association information after the simulation attack being a dependent vulnerability, and the association degree with the first vulnerability being less than or equal to the target threshold, and the number of the second vulnerabilities being greater than or equal to the target number, increase the general score of the vulnerability corresponding to the simulation attack based on a second step length to obtain a vulnerability severity score.

[0067] In one embodiment of the present disclosure, the score determination module 22 is further specifically configured to, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the association degree with the first vulnerability being greater than the target threshold, and the number of second vulnerabilities being greater than or equal to the target number, increase the general score of the vulnerability corresponding to the simulated attack based on the third step length; Wherein, the third step length is greater than the first step length and the second step length.

[0068] In one embodiment of the present disclosure, the data security risk assessment device 20 further includes: A vulnerability relationship determination module, configured to process each vulnerability based on a graph theory algorithm to obtain a vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the association degree between the two nodes of the edge.

[0069] In one embodiment of the present disclosure, the data security risk assessment device 20 further includes: An attack intensity determination module, configured to obtain different attack intensities by adjusting at least one of the following parameters: Attack duration, attack complexity, and resource investment.

[0070] See Figure 3 , Figure 3 is a schematic block diagram of an electronic device provided in an embodiment of the present disclosure. As Figure 3 shown, the electronic device 300 in this embodiment may include: one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The above-mentioned processors 301, input devices 302, output devices 303, and memories 304 communicate with each other through a communication bus 305. The memory 304 is used to store a computer program, and the computer program includes program instructions. The processor 301 is configured to execute the program instructions stored in the memory 304. Among them, the processor 301 is configured to call the program instructions to execute the functions of each module / unit in the above-mentioned device embodiments, such as Figure 2 the functions of the simulated attack module 21 and the risk assessment module 22 shown.

[0071] It should be understood that in the embodiments of the present disclosure, the so-called processor 301 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0072] The input device 302 may include a touchpad, a fingerprint acquisition sensor (for acquiring the fingerprint information and the direction information of the fingerprint of the user), a microphone, etc., and the output device 303 may include a display (such as an LCD), a speaker, etc.

[0073] The memory 304 may include a read-only memory and a random access memory, and provide instructions and data to the processor 301. A part of the memory 304 may also include a non-volatile random access memory. For example, the memory 304 may also store information about the device type.

[0074] In specific implementation, the processor 301, the input device 302, and the output device 303 described in the embodiments of the present disclosure may implement the implementation manners described in the first embodiment and the second embodiment of the data security risk assessment method provided by the embodiments of the present disclosure, and may also implement the implementation manner of the electronic device described in the embodiments of the present disclosure, which will not be elaborated herein.

[0075] In another embodiment of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, all or part of the processes in the methods of the above embodiments are implemented. It can also be completed by instructing relevant hardware through the computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0076] The computer-readable storage medium can be an internal storage unit of the electronic device in any of the foregoing embodiments, such as the hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device. Further, the computer-readable storage medium can also include both the internal storage unit and the external storage device of the electronic device. The computer-readable storage medium is used to store the computer program and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store the data that has been output or will be output.

[0077] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.

[0078] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described electronic devices and units can refer to the corresponding processes in the foregoing method embodiments and will not be described in detail here.

[0079] In several embodiments provided by the present application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be an indirect coupling or communication connection through some interfaces or units, or can also be an electrical, mechanical or other form of connection.

[0080] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present disclosure.

[0081] In addition, each functional unit in various embodiments of the present disclosure can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0082] The above is only the specific implementation manner of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of various equivalent modifications or replacements, and these modifications or replacements should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A data security risk assessment method, characterized in that: include: Conduct multiple simulated attacks on the target device storing the target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; Determine a plurality of vulnerability severity scores based on the plurality of vulnerability information; Each vulnerability information corresponds to a vulnerability severity score; The security risk of the target data is evaluated based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk evaluation value.

2. The data security risk assessment method according to claim 1, characterized in that: The different attack modes include network simulation attack, application simulation attack and system simulation attack; The target device storing the target data is subjected to multiple simulated attacks with different attack intensities and / or different attack methods to obtain multiple vulnerability information, including: Conduct M network simulation attacks on the target device storing the target data with different attack intensities to obtain M vulnerability information; Perform N application simulation attacks on the target device storing the target data with different attack intensities to obtain N vulnerability information; Perform L system simulation attacks on the target device storing the target data with different attack intensities to obtain L vulnerability information; Wherein, M, N, and L are positive integers, the sum of M, N, and L is the total number of simulated attacks, and the values ​​of M, N, and L are determined based on the historical attack data of the target device.

3. The data security risk assessment method according to claim 1, characterized in that: The vulnerability information includes: vulnerability association information; Determining a plurality of vulnerability severity scores based on the plurality of vulnerability information includes: Based on the vulnerability association information after each simulated attack, the general score of the vulnerability corresponding to the simulated attack is adjusted to obtain the multiple vulnerability severity scores; wherein each vulnerability association information is determined based on the vulnerability relationship graph.

4. The data security risk assessment method according to claim 3, characterized in that: The general score of the vulnerability corresponding to each simulated attack is adjusted based on the vulnerability association information after each simulated attack to obtain the multiple vulnerability severity scores, including: In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being less than a target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the first step to obtain the vulnerability severity score; wherein the first vulnerability is a vulnerability that affects the security of preset data, and the preset data is data in the target data; and the second vulnerability is a vulnerability that depends on the dependent vulnerability; In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability is less than or equal to the target threshold, and the number of second vulnerabilities is greater than or equal to the target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the second step size to obtain the vulnerability severity score.

5. The data security risk assessment method according to claim 4, characterized in that: The step of adjusting the general score of the vulnerability corresponding to each simulated attack based on the vulnerability association information after each simulated attack to obtain the plurality of vulnerability severity scores further includes: In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being greater than or equal to a target number, increasing a general score of the vulnerability corresponding to the simulated attack based on a third step length; The third step length is larger than the first step length and the second step length.

6. The data security risk assessment method according to claim 3, characterized in that: Before adjusting the general score of the vulnerability corresponding to each simulated attack based on the vulnerability association information after each simulated attack to obtain the multiple vulnerability severity scores, the method further includes: Each vulnerability is processed based on a graph theory algorithm to obtain the vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the degree of association between the two nodes of the edge.

7. The data security risk assessment method according to claim 1, characterized in that: Also includes: The different attack strengths are obtained by adjusting at least one of the following parameters: Attack duration, attack complexity, and resource investment.

8. A data security risk assessment device, characterized in that: include: A simulated attack module is used to perform multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; A score determination module, configured to determine a plurality of vulnerability severity scores based on the plurality of vulnerability information; Each vulnerability information corresponds to a vulnerability severity score; The risk assessment module is used to assess the security risk of the target data based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Risk assessment method and apparatus for software system vulnerability

    CN105046155A

  • Loophole finding method based on loophole correlation distribution model

    CN107526971A

  • Risk prediction information determination method and device, electronic equipment and storage medium

    CN116074029A

  • Vulnerability information processing method, device and equipment and readable storage medium

    CN117254920A

  • Method and system for evaluating security of host

    CN118503990A