Data security risk assessment method, device, equipment, and storage medium

By obtaining vulnerability information and correlation evaluation through simulated attacks, the problem of insufficient accuracy of traditional evaluation methods is solved, more accurate data security risk assessment is achieved, and data protection capabilities are enhanced.

CN120046161BActive Publication Date: 2025-08-15TANGSHAN CAOFEIDIAN LIANCHENG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510533733.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-15
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

Traditional data security risk assessment methods are insufficient in a secure environment, making it difficult to fully reflect the actual security risks faced by data.

Method used

By simulating different attack strengths and methods, multiple attacks are carried out on the target device, vulnerability information is obtained, the security risks of the target data are evaluated based on vulnerability severity scores and attack strengths, a vulnerability relationship diagram is built to consider vulnerability correlation, and a general score is adjusted to improve assessment accuracy.

Benefits of technology

A more comprehensive and authentic data security risk assessment has been achieved, the accuracy and reliability of the assessment has been improved, and users have helped to formulate targeted risk control measures and improve data security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046161B_ABST
    Figure CN120046161B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data security risk assessment method, apparatus, device, and storage medium, belonging to the field of data security technology. The method comprises: performing multiple simulated attacks on a target device storing target data with varying attack intensities and / or attack methods to obtain multiple vulnerability information; determining multiple vulnerability severity scores based on the multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score; and assessing the security risk of the target data based on the attack intensity and the multiple vulnerability severity scores to obtain a target security risk assessment value. The data security risk assessment method, apparatus, device, and storage medium provided by the present disclosure can improve the accuracy and reliability of data security risk assessments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the field of data security technology, and more specifically, relates to a data security risk assessment method and apparatus, equipment, and storage medium. Background Art

[0002] Traditional data security risk assessments, for example, mostly evaluate data attributes such as confidentiality, integrity, and availability, identify threats and vulnerabilities faced by data, assess the possibility of security incidents and their potential impact, thereby determining the risk level and proposing corresponding risk control measures.

[0003] However, the accuracy and reliability of data security risk assessment performed only in a secure environment are insufficient, and an accurate and reliable data security risk assessment method is needed. Summary of the Invention

[0004] The purpose of the present disclosure is to provide a data security risk assessment method and apparatus, equipment, and storage medium to improve the accuracy and reliability of data security risk assessment.

[0005] A first aspect of the embodiments of the present disclosure provides a data security risk assessment method, comprising:

[0006] Conduct multiple simulated attacks on the target device storing the target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information;

[0007] Determine multiple vulnerability severity scores based on multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score;

[0008] The security risk of the target data is assessed based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value.

[0009] A second aspect of the embodiments of the present disclosure provides a data security risk assessment device, comprising:

[0010] A simulated attack module is used to perform multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information;

[0011] A score determination module, configured to determine a plurality of vulnerability severity scores based on the plurality of vulnerability information; each vulnerability information corresponds to a vulnerability severity score;

[0012] The risk assessment module is used to assess the security risk of target data based on attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value.

[0013] According to a third aspect of an embodiment of the present disclosure, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the above-mentioned data security risk assessment method when executing the computer program.

[0014] According to a fourth aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned data security risk assessment method are implemented.

[0015] The data security risk assessment method, apparatus, device, and storage medium provided by the embodiments of the present disclosure have the following beneficial effects:

[0016] This disclosure simulates actual attack scenarios, taking into account varying attack intensities and attack methods. Compared to traditional assessment methods, it can more comprehensively and realistically reflect the security risks faced by target data. The assessment results in this disclosure are derived from a comprehensive analysis of the attack intensities and vulnerability severity scores of multiple simulated attacks, resulting in higher accuracy and reliability. This allows users to more accurately understand the security status of their data, formulate targeted risk control measures, effectively enhance data security protection capabilities, and safeguard the security of data assets. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0018] Figure 1 A flowchart of a data security risk assessment method provided in one embodiment of the present disclosure;

[0019] Figure 2 A structural block diagram of a data security risk assessment device provided in one embodiment of the present disclosure;

[0020] Figure 3 A schematic block diagram of an electronic device provided in one embodiment of the present disclosure. DETAILED DESCRIPTION

[0021] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present disclosure with unnecessary detail.

[0022] In order to make the purpose, technical solutions and advantages of the present disclosure more clear, specific embodiments will be described below with reference to the accompanying drawings.

[0023] Please refer to Figure 1 , Figure 1 This is a flow chart of a data security risk assessment method provided in one embodiment of the present disclosure, which includes:

[0024] S101: Perform multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information.

[0025] In this embodiment, the target device refers to a device that stores target data and can be any device that stores and processes data, such as a server, personal computer, or mobile terminal. Target data refers to data subject to security risk assessment. Multiple simulated attacks involve repeatedly simulating operations on the target device that resemble real-world attack scenarios. The purpose is to test the target device's security capabilities and identify security vulnerabilities. Simulated attack methods can include network-level attacks (such as port scanning and denial of service attacks), application-level attacks (such as injection attacks exploiting application vulnerabilities), and system-level attacks (such as privilege escalation attacks exploiting operating system vulnerabilities). Vulnerability information refers to information about security flaws or weaknesses in the target device discovered through simulated attacks, such as vulnerability type, location, severity, and vulnerability associations. Vulnerability information can be obtained by scanning the target device's system, applications, network services, and other systems using vulnerability scanning tools.

[0026] In this embodiment, the target data refers to the data stored in the target device that needs to be securely protected, which may include personal privacy data, user order information, customer personal information, etc., or it may be some more conventional data, such as corporate employee attendance records, salary data, and some conventional project documents.

[0027] In this embodiment, different attack intensities and / or different attack methods may specifically refer to different attack intensities and the same attack methods, or the same attack intensities and different attack methods, or different attack intensities and different attack methods. In order to ensure the accuracy of data security risk assessment, it is preferred to perform multiple simulated attacks on the target device storing the target data with different attack intensities and different attack methods to obtain multiple vulnerability information.

[0028] It should be noted that in this embodiment, before each simulated attack, the target device is in its initial state. Each simulated attack corresponds to a vulnerability. This means that before each simulated attack, the target device is restored to a standard state, unaffected by the previous simulated attack. This ensures the independence and fairness of each simulated attack and prevents system changes caused by previous attacks from interfering with the results of subsequent attacks. For example, the target device's system configuration is restored to its default settings, and malware and modified files left behind by the previous simulated attack are cleared.

[0029] In this embodiment, each simulated attack will generate vulnerability information corresponding to the simulated attack. This vulnerability information is caused by the simulated attack. It can be understood that a simulated attack may generate multiple vulnerabilities. The vulnerability information of this embodiment includes a summary of all vulnerabilities generated by a simulated attack.

[0030] S102: Determine multiple vulnerability severity scores based on the multiple vulnerability information; each vulnerability information corresponds to a vulnerability severity score.

[0031] In this embodiment, vulnerability information includes: vulnerability association information;

[0032] Determining multiple vulnerability severity scores based on multiple vulnerability information includes:

[0033] Based on the vulnerability correlation information after each simulated attack, the general score of the vulnerability corresponding to the simulated attack is adjusted to obtain multiple vulnerability severity scores; wherein each vulnerability correlation information is determined based on the vulnerability relationship graph.

[0034] In this embodiment, all vulnerabilities present in the target device after each simulated attack are scored using the Common Vulnerability Scoring System (CVSS), and the sum of the scores is the common score.

[0035] Considering that CVSS typically evaluates and scores individual vulnerabilities and does not directly consider the correlation between vulnerabilities, this embodiment adjusts the general score of the vulnerabilities corresponding to each simulated attack based on the vulnerability correlation information obtained after each simulated attack. For example, if the vulnerability correlation information contains features indicating a strong vulnerability correlation, the general score of the vulnerabilities corresponding to the simulated attack can be increased to obtain the vulnerability severity score corresponding to the simulated attack.

[0036] It should be noted that vulnerability association information is not limited to the vulnerability association information of a single vulnerability. That is, it can be understood as adjusting the universal score of the vulnerability corresponding to the simulated attack based on the vulnerability association information of all vulnerabilities obtained after each simulated attack. The universal score is also not limited to a single vulnerability.

[0037] Similarly, in this embodiment, the vulnerability severity score is the result of a comprehensive score of all vulnerabilities that appear after the target device undergoes a simulated attack each time. It can be understood that the vulnerability severity score is not limited to the score of a single vulnerability, but can also be the sum of the scores obtained by adjusting the common scores of multiple vulnerabilities.

[0038] S103: Evaluate the security risk of the target data based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value.

[0039] In this embodiment, attack intensity is used to measure the strength and complexity of each simulated attack, or the extent of the potential impact on the target device. The attack intensity can be determined based on the duration, complexity, and resource investment of each simulated attack. In other words, different attack intensities can be achieved by adjusting at least one of the following parameters:

[0040] Attack duration, attack complexity, and resource investment.

[0041] In this embodiment, the simulated attack intensity of each simulated attack may be obtained based on weighted calculation. For example, the simulated attack intensity of each simulated attack may be determined based on a first formula. The first formula may be:

[0042] ,in, Indicates the The attack intensity of the simulated attack, Indicates the The attack duration coefficient of the simulated attack, Indicates the The attack complexity coefficient of the simulated attack, Indicates the The quantified value of resource input for the simulated attack, is the weight coefficient, which can be set based on experience or actual needs. 、 and / or , you can get different attack strengths.

[0043] It should be noted that 、 and All values are between 0 and 1, which means they have been normalized. The acquisition and normalization of attack duration will not be described in detail. Attack complexity coefficient The method of obtaining it can be to divide common attack techniques into multiple levels according to difficulty, such as simple, medium, difficult, and extremely difficult, and assign corresponding numerical values.

[0044] Specifically, simple attack techniques such as basic port scanning can be completed using only common scanning tools, and their corresponding complexity level is set to level 1. Medium-difficulty attack techniques such as ordinary structured query language injection attacks require attackers to have certain database knowledge and the ability to analyze application vulnerabilities, and their complexity level is set to level 2. Difficult attack techniques such as exploiting complex operating system kernel vulnerabilities require a deep understanding of the underlying principles of the operating system and superb vulnerability exploitation skills, and are set to level 3. Extremely difficult attack techniques such as cracking attacks against new encryption algorithms involve cutting-edge cryptographic knowledge and a large amount of computing resources, and are set to level 4. Secondly, each level is pre-assigned a value between 0 and 1.

[0045] In this embodiment, the resource input quantification value It can be obtained by calculating the network bandwidth consumed by the simulated attack. For example, if a baseline bandwidth is set, the resource investment quantification value It can be the ratio of the bandwidth used in the simulated attack to the baseline bandwidth.

[0046] It should be noted that the simulated attack in this embodiment is not an external malicious attack, but an attack using known attack means and numerical values such as attack complexity and resource investment using existing technologies. Therefore, in this embodiment, various parameters of the simulated attack can be obtained and calculated.

[0047] In this embodiment, the security risk of the target data may be evaluated through mapping relationships or weighted calculations.

[0048] As can be seen from the above, this disclosure simulates actual attack scenarios and considers different attack intensities and attack methods. Compared with traditional assessment methods, it can more comprehensively and realistically reflect the security risks faced by target data. The assessment results in this disclosure are derived from a comprehensive analysis of the attack intensity and vulnerability severity scores of multiple simulated attacks. This has higher accuracy and reliability, allowing users to more accurately understand the security status of their own data, formulate targeted risk control measures, effectively improve data security protection capabilities, and ensure the security of data assets.

[0049] In one embodiment of the present disclosure, different attack methods include network simulation attacks, application simulation attacks, and system simulation attacks;

[0050] Conduct multiple simulated attacks on the target device storing the target data with different attack intensities and / or attack methods to obtain multiple vulnerability information, including:

[0051] Conduct M network simulation attacks on the target device storing the target data with different attack intensities to obtain M vulnerability information;

[0052] Perform N application simulation attacks on the target device storing the target data with different attack intensities to obtain N vulnerability information;

[0053] Perform L system simulation attacks on the target device storing the target data with different attack intensities to obtain L vulnerability information;

[0054] Among them, M, N, and L are positive integers. The sum of M, N, and L is the total number of simulated attacks. The values of M, N, and L are determined based on the historical attack data of the target device.

[0055] In this embodiment, a network simulation attack simulates various possible attack behaviors at the network level, such as port scanning, network sniffing, denial of service attacks, or distributed denial of service attacks, to detect security vulnerabilities in the target device's network communications and network configuration. An application simulation attack simulates attacks against applications running on the target device, for example, exploiting input validation vulnerabilities (such as structured query language injection attacks and command injection) or authentication vulnerabilities to uncover security risks within the application. A system simulation attack targets the target device's operating system, such as exploiting kernel vulnerabilities or permission management vulnerabilities in the operating system to identify security vulnerabilities at the operating system level.

[0056] In this embodiment, the number of network simulated attacks (M), the number of application simulated attacks (N), and the number of system simulated attacks (L) are determined by referring to relevant data of various attacks that the target device has suffered in the past, such as the type of attack, frequency, and successful attack cases.

[0057] For example, if the target device has frequently been attacked at the network level, M can be set relatively high to more comprehensively detect network-related vulnerabilities. More specifically, if the number of network attacks on the target device accounts for half of the total number of attacks, then the value of M can be half of the total number of simulated attacks. That is, the proportion of each type of simulated attack is the same as the proportion of real attacks of the same type. A total number of simulated attacks can be preset, for example, 100.

[0058] As can be seen from the above, by segmenting simulated attacks into three levels: network, application, and system, this disclosure comprehensively covers all security threats that target devices may face, enhancing the authenticity of simulated attacks. This disclosure determines the number of simulated attacks based on the proportion of each type of attack in historical attacks, ensuring that the distribution of simulated attacks is consistent with the actual attack distribution. This ensures that the assessment method always matches the actual attack situation, thereby enhancing the reliability of the assessment results.

[0059] In one embodiment of the present disclosure, the security risk of target data is evaluated based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value, including: substituting the attack intensity and multiple vulnerability severity scores during multiple simulated attacks into a second formula to evaluate the security risk of the target data; the second formula may be:

[0060] ,in, Represents the security risk assessment value of the target data, Indicates the The simulated attack intensity of the simulated attack, Indicates the total number of simulated attacks, Indicates the The number of vulnerabilities after the simulated attack, Indicates the In the simulated attack The severity score of the vulnerability.

[0061] The second formula can be understood as, Indicates the The sum of the severity scores of all vulnerabilities discovered in the simulated attack reflects the overall severity of the target device vulnerabilities revealed by the simulated attack. The amplification effect of attack intensity on vulnerability severity is taken into account. For example, if a high-intensity attack discovers multiple serious vulnerabilities, the threat to the target data security will be greater.

[0062] The larger the security risk assessment value of the target data is, the higher the security risk faced by the target data is.

[0063] In this embodiment, a method for adjusting the general score is provided:

[0064] Based on the vulnerability correlation information after each simulated attack, the general score of the vulnerability corresponding to the simulated attack is adjusted to obtain multiple vulnerability severity scores, including:

[0065] In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being less than a target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the first step to obtain a vulnerability severity score; wherein the first vulnerability is a vulnerability that affects the security of preset data, the preset data being data in the target data; and the second vulnerability is a vulnerability that depends on the dependent vulnerability;

[0066] In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being less than or equal to the target threshold, and the number of second vulnerabilities being greater than or equal to the target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the second step size to obtain a vulnerability severity score.

[0067] In one embodiment of the present disclosure, based on the vulnerability association information after each simulated attack, the general score of the vulnerability corresponding to the simulated attack is adjusted to obtain multiple vulnerability severity scores, further comprising:

[0068] In response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being greater than or equal to a target number, increasing the general score of the vulnerability corresponding to the simulated attack based on a third step size;

[0069] Among them, the third step length is greater than the first step length and the second step length.

[0070] In this embodiment, the preset data refers to important data preset in the target data, such as confidential information of the enterprise, project quotation, tender information, etc. A dependent vulnerability refers to a vulnerability that serves as a prerequisite for the exploitation of other vulnerabilities during the vulnerability exploitation process. For example, in a system, vulnerability A can enable an attacker to obtain ordinary user permissions, while vulnerability B can only be exploited on the basis of ordinary user permissions to further obtain administrator permissions. Here, vulnerability A is a dependent vulnerability, because the exploitation of vulnerability B depends on the successful exploitation of vulnerability A before the attacker can meet the conditions for exploiting vulnerability B. Dependent vulnerabilities are generally at an earlier position in the attack path, providing the necessary environment or conditions for the subsequent exploitation of other vulnerabilities. By exploiting dependent vulnerabilities, attackers can create scenarios that can trigger other vulnerabilities, thereby achieving the purpose of gradually deepening the attack on the system, elevating permissions or obtaining sensitive information. The second vulnerability refers to other vulnerabilities that depend on the dependent vulnerability.

[0071] Specifically, in the first case: when the vulnerability association information after the simulated attack shows that the existing vulnerability is a dependent vulnerability, and its correlation with the first vulnerability is greater than the target threshold, and the number of second vulnerabilities that depend on it is less than the target number, then the general score of the vulnerability corresponding to the simulated attack can be increased according to the first step. This indicates that in this case, the dependent vulnerability is closely related to the first vulnerability (i.e., the vulnerability that affects the security of the preset data), but the number of other vulnerabilities that depend on it is small, so a certain degree (the first step) of score improvement is given.

[0072] Case 2: If the vulnerability association information indicates that the vulnerability is a dependent vulnerability, and its correlation with the first vulnerability is less than or equal to the target threshold, and the number of dependent second vulnerabilities is greater than or equal to the target number, the second step is used to increase the common score of the vulnerability corresponding to the simulated attack, thereby obtaining the severity score of the vulnerability. In this case, the dependent vulnerability is relatively loosely related to the first vulnerability, but has a large number of other dependent vulnerabilities, so the score is increased according to the second step.

[0073] Case 3: When vulnerability association information indicates that the vulnerability is a dependent vulnerability, its correlation with the first vulnerability exceeds the target threshold, and the number of dependent second vulnerabilities is greater than or equal to the target number, the general score of the vulnerability corresponding to the simulated attack is increased according to the third step. Because the dependent vulnerability in this case is closely related to the first vulnerability and has a large number of other dependent vulnerabilities, it is given the largest third step score increase.

[0074] The first step length, the second step length and the third step length can be determined based on experience or experimental process. There is no clear size relationship between the first step length and the second step length, but the third step length is larger than the first step length, and the third step length is larger than the second step length.

[0075] In this embodiment, when the vulnerability association information after the simulated attack does not meet the aforementioned three situations or conditions, the general score of the vulnerability corresponding to the simulated attack may not be adjusted, and the general score of the vulnerability corresponding to the simulated attack may be directly used as the vulnerability severity score.

[0076] It should be noted that in this embodiment, the first vulnerability and the second vulnerability are not mutually exclusive concepts. Therefore, a vulnerability can be both a first vulnerability and a second vulnerability. A vulnerability can be a dependency of other vulnerabilities, and can also be a vulnerability that depends on other vulnerabilities. In this embodiment, the target threshold and target number can be determined based on experience.

[0077] Since the aforementioned vulnerability association information is not limited to the vulnerability association information of one vulnerability, the "vulnerability association information after responding to the simulated attack is" in this embodiment can be understood as "exists in the vulnerability association information after responding to the simulated attack", that is, as long as there is a vulnerability in the vulnerabilities obtained by the target device after being subjected to the simulated attack that meets one of the above three conditions, it means that the general score of the vulnerability corresponding to this simulated attack needs to be adjusted accordingly.

[0078] As can be seen from the above, this disclosure incorporates simulated attack intensity and vulnerability severity scores into the evaluation formula, comprehensively considering the amplifying effect of attack intensity on the severity of a vulnerability. This allows for a more accurate assessment of the security risks facing the target data, avoiding the inaccurate assessments that result from simply considering the number of vulnerabilities or attack intensity. This disclosure also considers the correlation between vulnerabilities and adjusts the general score based on this information, enabling a more realistic reflection of the actual severity of the vulnerabilities and enhancing the reliability of the evaluation results.

[0079] The aforementioned vulnerability association information is determined based on the vulnerability relationship graph. Specifically, before adjusting the general score of the vulnerability corresponding to each simulated attack based on the vulnerability association information after each simulated attack to obtain multiple vulnerability severity scores, the following is also included:

[0080] Each vulnerability is processed based on a graph theory algorithm to obtain a vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the degree of association between the two nodes of the edge.

[0081] In this embodiment, graph theory algorithm is a mathematical method for processing graph structured data. In this scenario, each vulnerability can be taken as a processing object, and these vulnerabilities can be analyzed and processed by applying graph theory algorithms (such as depth-first search, breadth-first search, shortest path algorithm, etc.).

[0082] Specifically, it is to determine the connection method and closeness between vulnerabilities based on the correlation between them (such as the exploitation of vulnerability E will make vulnerability F easier to exploit, or vulnerability G and vulnerability H often appear at the same time, etc.).

[0083] The constructed vulnerability relationship graph is a graph structure with vulnerabilities as nodes. Each vulnerability is represented by a node in the graph, which can contain basic information about the vulnerability, such as vulnerability number, type, and description. The edges in the graph represent the relationships between vulnerabilities, and the thickness of the edge is used to intuitively reflect the degree of association between the two vulnerability nodes connected by the edge. The higher the degree of association, the thicker the edge; the lower the degree of association, the thinner the edge.

[0084] For example, if vulnerability X and vulnerability Y are closely related and appear simultaneously and cooperate with each other in many attack scenarios, then the edge connecting them will be thicker; conversely, if vulnerability P and vulnerability Q are weakly related and only occasionally connected in some specific situations, then the edge between them will be thinner.

[0085] In this embodiment, whether the vulnerability association information is a dependent vulnerability can be determined based on the connection pattern of the vulnerabilities in the vulnerability relationship graph. Whether the degree of association with the first vulnerability is greater than a target threshold can be determined by comparing the thickness of the line connecting the vulnerability and the first vulnerability. That is, the target threshold corresponds to a target thickness. When the thickness of the connecting line is greater than the target thickness, the vulnerability association information indicates that the degree of association with the first vulnerability is greater than the target threshold. Whether the number of second vulnerabilities in the vulnerability association information is less than the target number can be determined based on the number of vulnerabilities connected to it in the vulnerability relationship graph.

[0086] It should be noted that the construction of the vulnerability relationship graph is based on a large amount of vulnerability data from the target device history or the testing process, that is, the construction of the vulnerability relationship graph precedes the evaluation process of the simulated attack.

[0087] From the above, it can be concluded that the present disclosure analyzes and processes each vulnerability through a graph theory algorithm, constructs a vulnerability relationship graph with vulnerabilities as nodes, clarifies the correlation between vulnerabilities, and makes the security risk assessment more in line with the actual situation.

[0088] Corresponding to the data security risk assessment method of the above embodiment, Figure 2 This is a structural block diagram of a data security risk assessment device provided by an embodiment of the present disclosure. For ease of explanation, only the parts related to the embodiment of the present disclosure are shown. Figure 2 The data security risk assessment device 20 includes: an attack simulation module 21, a score determination module 22 and a risk assessment module 23.

[0089] The simulated attack module 21 is used to perform multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information;

[0090] A score determination module 22 is configured to determine a plurality of vulnerability severity scores based on the plurality of vulnerability information; each vulnerability information corresponds to a vulnerability severity score;

[0091] The risk assessment module 23 is used to assess the security risk of the target data based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value.

[0092] In one embodiment of the present disclosure, different attack methods include network simulation attacks, application simulation attacks, and system simulation attacks; the simulation attack module 21 is specifically configured to perform M network simulation attacks on a target device storing target data with different attack intensities to obtain M vulnerability information;

[0093] Perform N application simulation attacks on the target device storing the target data with different attack intensities to obtain N vulnerability information;

[0094] Perform L system simulation attacks on the target device storing the target data with different attack intensities to obtain L vulnerability information;

[0095] Among them, M, N, and L are positive integers. The sum of M, N, and L is the total number of simulated attacks. The values of M, N, and L are determined based on the historical attack data of the target device.

[0096] In one embodiment of the present disclosure, vulnerability information includes: vulnerability association information;

[0097] The data security risk assessment device 20 further includes:

[0098] The score determination module 22 is specifically configured to adjust the general score of the vulnerability corresponding to each simulated attack based on the vulnerability association information after the simulated attack to obtain multiple vulnerability severity scores; wherein each vulnerability association information is determined based on the vulnerability relationship graph.

[0099] In one embodiment of the present disclosure, the score determination module 22 is further configured to, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being less than a target number, increase the general score of the vulnerability corresponding to the simulated attack based on the first step to obtain a vulnerability severity score; wherein the first vulnerability is a vulnerability that affects the security of preset data, the preset data being data in the target data; and the second vulnerability is a vulnerability that depends on the dependent vulnerability;

[0100] In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being less than or equal to the target threshold, and the number of second vulnerabilities being greater than or equal to the target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the second step size to obtain a vulnerability severity score.

[0101] In one embodiment of the present disclosure, the score determination module 22 is further configured to, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being greater than or equal to a target number, increase the general score of the vulnerability corresponding to the simulated attack based on a third step size;

[0102] Among them, the third step length is greater than the first step length and the second step length.

[0103] In one embodiment of the present disclosure, the data security risk assessment device 20 further includes:

[0104] The vulnerability relationship determination module is used to process each vulnerability based on a graph theory algorithm to obtain a vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the degree of association between the two nodes of the edge.

[0105] In one embodiment of the present disclosure, the data security risk assessment device 20 further includes:

[0106] The attack strength determination module is configured to obtain different attack strengths by adjusting at least one of the following parameters:

[0107] Attack duration, attack complexity, and resource investment.

[0108] See also Figure 3 , Figure 3 This is a schematic block diagram of an electronic device provided by an embodiment of the present disclosure. Figure 3 The electronic device 300 in the embodiment shown may include: one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The processors 301, input devices 302, output devices 303, and memories 304 communicate with each other via a communication bus 305. The memory 304 is used to store computer programs, which include program instructions. The processor 301 is used to execute the program instructions stored in the memory 304. The processor 301 is configured to call the program instructions to execute the functions of the modules / units in the above-mentioned device embodiments, such as Figure 2 The functions of the attack simulation module 21 and the risk assessment module 22 are shown.

[0109] It should be understood that in the embodiments of the present disclosure, the processor 301 may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0110] The input device 302 may include a touchpad, a fingerprint collection sensor (for collecting user fingerprint information and fingerprint direction information), a microphone, etc. The output device 303 may include a display (LCD, etc.), a speaker, etc.

[0111] The memory 304 may include a read-only memory and a random access memory, and provides instructions and data to the processor 301. A portion of the memory 304 may also include a non-volatile random access memory. For example, the memory 304 may also store device type information.

[0112] In a specific implementation, the processor 301, input device 302, and output device 303 described in the embodiments of the present disclosure can execute the implementation methods described in the first and second embodiments of the data security risk assessment method provided in the embodiments of the present disclosure, and can also execute the implementation methods of the electronic device described in the embodiments of the present disclosure, which will not be repeated here.

[0113] In another embodiment of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, all or part of the process of the method in the above embodiment is implemented. The computer program can also be used to instruct related hardware to complete the process. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of each of the above method embodiments are implemented. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium.

[0114] The computer-readable storage medium can be an internal storage unit of the electronic device in any of the aforementioned embodiments, such as a hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. Furthermore, the computer-readable storage medium can include both an internal storage unit of the electronic device and an external storage device. The computer-readable storage medium is used to store computer programs and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store data that has been output or is about to be output.

[0115] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this disclosure.

[0116] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the electronic devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0117] In the several embodiments provided in this application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces or units, or can be an electrical, mechanical or other form of connection.

[0118] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of these units may be selected based on actual needs to achieve the objectives of the embodiments of the present disclosure.

[0119] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0120] The above are only specific embodiments of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or replacements within the technical scope disclosed in this disclosure, and such modifications or replacements should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. A data security risk assessment method, characterized in that: include: Conduct multiple simulated attacks on the target device storing the target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; Each vulnerability information corresponds to a vulnerability severity score; Vulnerability information, including: vulnerability-related information; In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being less than a target number, the general score of the vulnerability corresponding to the simulated attack is increased based on the first step to obtain a vulnerability severity score; wherein the first vulnerability is a vulnerability that affects the security of preset data, and the second vulnerability is a vulnerability that depends on the dependent vulnerability; the preset data refers to important data preset in the target data; In response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being less than or equal to the target threshold, and the number of second vulnerabilities being greater than or equal to the target number, increasing the general score of the vulnerability corresponding to the simulated attack based on the second step size to obtain a vulnerability severity score; In response to the vulnerability association information after the simulated attack being a dependent vulnerability, and the degree of association with the first vulnerability being greater than a target threshold, and the number of the second vulnerabilities being greater than or equal to the target number, the universal score of the vulnerability corresponding to the simulated attack is increased based on a third step length; wherein the third step length is greater than the first step length and the second step length; each vulnerability association information is determined based on the vulnerability relationship graph; Assess the security risk of the target data based on the attack intensity and multiple vulnerability severity scores to obtain a target security risk assessment value; The security risk of the target data is evaluated based on the attack intensity and the multiple vulnerability severity scores to obtain a target security risk evaluation value, including: substituting the attack intensity and the multiple vulnerability severity scores during multiple simulated attacks into a second formula to evaluate the security risk of the target data; the second formula is: ,in, Represents the security risk assessment value of the target data, Indicates the The simulated attack intensity of the simulated attack, Indicates the total number of simulated attacks, Indicates the The number of vulnerabilities after the simulated attack, Indicates the In the simulated attack The severity score of the vulnerability.

2. The data security risk assessment method according to claim 1, wherein: The different attack methods include network simulation attack, application simulation attack and system simulation attack; The target device storing the target data is subjected to multiple simulated attacks with different attack intensities and / or different attack methods to obtain multiple vulnerability information, including: Conduct M network simulation attacks on the target device storing the target data with different attack intensities to obtain M vulnerability information; Perform N application simulation attacks on the target device storing the target data with different attack intensities to obtain N vulnerability information; Perform L system simulation attacks on the target device storing the target data with different attack intensities to obtain L vulnerability information; Wherein, M, N, and L are positive integers, the sum of M, N, and L is the total number of simulated attacks, and the values of M, N, and L are determined based on the historical attack data of the target device.

3. The data security risk assessment method according to claim 1, wherein: Before adjusting the universal score of the vulnerability corresponding to each simulated attack based on the vulnerability association information after each simulated attack to obtain the multiple vulnerability severity scores, the method further includes: Each vulnerability is processed based on a graph theory algorithm to obtain the vulnerability relationship graph; the nodes in the vulnerability relationship graph are vulnerabilities, and the thickness of the edges in the vulnerability relationship graph is the degree of association between the two nodes of the edge.

4. The data security risk assessment method according to claim 1, wherein: Also includes: The different attack strengths are obtained by adjusting at least one of the following parameters: Attack duration, attack complexity, and resource investment.

5. A data security risk assessment device, characterized in that: include: A simulated attack module is used to perform multiple simulated attacks on a target device storing target data with different attack intensities and / or different attack methods to obtain multiple vulnerability information; Each vulnerability information corresponds to a vulnerability severity score; Vulnerability information, including: vulnerability-related information; a score determination module for, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being less than a target number, increasing the general score of the vulnerability corresponding to the simulated attack based on the first step to obtain a vulnerability severity score; wherein the first vulnerability is a vulnerability that affects the security of preset data, and the second vulnerability is a vulnerability that depends on the dependent vulnerability; and the preset data refers to important data preset in the target data; The score determination module is further configured to, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being less than or equal to a target threshold, and the number of second vulnerabilities being greater than or equal to a target number, increase the general score of the vulnerability corresponding to the simulated attack based on the second step size to obtain a vulnerability severity score; The score determination module is further configured to, in response to the vulnerability association information after the simulated attack being a dependent vulnerability, the degree of association with the first vulnerability being greater than a target threshold, and the number of second vulnerabilities being greater than or equal to a target number, increase the universal score of the vulnerability corresponding to the simulated attack based on a third step length; wherein the third step length is greater than the first step length and the second step length; and each vulnerability association information is determined based on the vulnerability relationship graph; The risk assessment module is used to substitute the attack intensity and multiple vulnerability severity scores during multiple simulated attacks into the second formula to assess the security risk of the target data; the second formula is: ,in, Represents the security risk assessment value of the target data, Indicates the The simulated attack intensity of the simulated attack, Indicates the total number of simulated attacks, Indicates the The number of vulnerabilities after the simulated attack, Indicates the In the simulated attack The severity score of the vulnerability.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.

7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Loophole finding method based on loophole correlation distribution model

    CN107526971A

  • Method and system for evaluating security of host

    CN118503990A