Hierarchical penetration test effect evaluation method and device

By constructing a hierarchical set of penetration test effect evaluation indicators, and processing and integrating the effects of different penetration test methods, methods and tools, the problem of difficulty in comparative analysis of penetration test effects in the existing technology is solved, and a more accurate and reliable network security assessment is achieved.

CN120050062APending Publication Date: 2025-05-27NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202411994626.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

It is difficult for the prior art to compare and analyze the differences in the effects of different penetration testing methods, methods and tools on the same penetration testing target.

Method used

The hierarchical penetration test effect evaluation method is adopted to construct a hierarchical penetration test effect evaluation index set, including a subset of penetration test performance evaluation index and a subset of social impact effect evaluation index, and process and integrate the results of the hierarchical penetration test effect evaluation.

Benefits of technology

It can effectively compare and analyze the effects of different penetration testing methods, methods and tools, help formulate penetration testing task plans, and improve the accuracy and reliability of network security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050062A_ABST
    Figure CN120050062A_ABST
Patent Text Reader

Abstract

The invention discloses a hierarchical penetration test effect evaluation method and device, and the method comprises the steps: constructing a hierarchical penetration test effect evaluation index set according to an evaluation object, and the hierarchical penetration test effect evaluation index set comprises a penetration test performance evaluation index subset and a social influence effect evaluation index subset; processing the hierarchical penetration test effect evaluation index set to obtain a penetration test performance evaluation result and a social influence effect evaluation result; and integrating the penetration test performance evaluation result and the social influence effect evaluation result to obtain a hierarchical penetration test effect evaluation result. According to the method, the final result of the network penetration test is taken as an index division basis, different penetration test means, penetration test modes and penetration test tools are adopted for performing penetration test effect difference analysis aiming at the same penetration test target, and auxiliary formulation of a penetration test task scheme is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of effect evaluation, and in particular to a hierarchical penetration test effect evaluation method and device. Background Art

[0002] With the continuous development of network and information technologies, computer networks play an increasingly important role in various fields of people's work and life. Along with the development of the network, various network security problems have also emerged. Understanding and mastering various security threats faced by the network, preventing and eliminating these threats, and ensuring network security have become the focus of attention in various fields. Penetration testing simulates real network penetration testing by using relevant technical methods and some professional tools to detect security vulnerabilities and weaknesses of the target system, so as to evaluate the security of the network system. Network penetration test effect evaluation is based on the final results of network penetration testing as the index division basis, which helps to assist in formulating penetration test task plans. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a hierarchical penetration test effect evaluation method and device, which takes the final results of penetration testing as the effect evaluation index, and can compare and analyze the differences in penetration test effects of different penetration test means, penetration test methods, and penetration test tools for the same penetration test target.

[0004] To solve the above technical problem, a first aspect of an embodiment of the present invention discloses a hierarchical penetration test effect evaluation method, and the method includes:

[0005] S1, constructing a hierarchical penetration test effect evaluation index set according to the evaluation object; the hierarchical penetration test effect evaluation index set includes a penetration test performance evaluation index subset and a social impact effect evaluation index subset;

[0006] The penetration test performance evaluation index subset includes a first penetration test performance index, a second penetration test performance index, a third penetration test performance index, a fourth penetration test performance index, a fifth penetration test performance index, and a sixth penetration test performance index;

[0007] The social impact effect evaluation index subset includes a first social impact index, a second social impact index, a third social impact index, a fourth social impact index, a fifth social impact index, and a sixth social impact index;

[0008] S2, processing the hierarchical penetration test effect evaluation index set to obtain a penetration test performance evaluation result and a social impact effect evaluation result;

[0009] S3. Integrate the penetration test performance evaluation results and the social impact evaluation results to obtain hierarchical penetration test effectiveness evaluation results.

[0010] As an alternative implementation, in the first aspect of the embodiments of the present invention, the processing of the hierarchical penetration test effectiveness evaluation index set to obtain penetration test performance evaluation results and social impact evaluation results includes:

[0011] S21. Process the subset of penetration test performance evaluation indexes to obtain penetration test performance evaluation results;

[0012] S22. Process the subset of social impact evaluation indexes to obtain social impact evaluation results.

[0013] As an alternative implementation, in the first aspect of the embodiments of the present invention, the processing of the subset of penetration test performance evaluation indexes to obtain penetration test performance evaluation results includes:

[0014] S211. Process the first penetration test performance index to obtain the first penetration test performance judgment matrix A and the weight vector w a ;

[0015] S212. Process the second penetration test performance index to obtain the second penetration test performance judgment matrix B and the weight vector w b ;

[0016] S213. Process the third penetration test performance index to obtain the third penetration test performance judgment matrix C and the weight vector w c ;

[0017] S214. Process the fourth penetration test performance index to obtain the fourth penetration test performance judgment matrix D and the weight vector w d ;

[0018] S215. Process the fifth penetration test performance index to obtain the fifth penetration test performance judgment matrix E and the weight vector w e ;

[0019] S216. Process the sixth penetration test performance index to obtain the fifth penetration test performance judgment matrix F and the weight vector w f ;

[0020] S217. Process the weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d, the weight vector w e and the weight vector w f are processed to obtain the evaluation result of the penetration test performance evaluation.

[0021] As an alternative implementation, in the first aspect of the embodiments of the present invention, the processing of the first penetration test performance index to obtain the first penetration test performance judgment matrix A and the weight vector w a , includes:

[0022] S2111, preprocess the first penetration test performance index to obtain the preprocessed first penetration test performance index;

[0023] S2112, perform standardization processing on the preprocessed first penetration test performance index to obtain the standardized first penetration test performance index;

[0024] S2113, process the standardized first penetration test performance index to obtain the first penetration test performance judgment matrix A;

[0025] The expression of the first penetration test performance judgment matrix A is:

[0026]

[0027] where the standardized first penetration test performance index is x = {x 1 x 2 …x p}, there are p indicators in total, a ij is the element in the i-th row and j-th column of the judgment matrix A, a ij is the correlation coefficient between x i and x j , i = 1, 2, …, p, j = 1, 2, …, p;

[0028] S2114, perform eigenvalue decomposition on the judgment matrix A to obtain the eigenvalues of the judgment matrix A, and sort the eigenvalues of the judgment matrix A λ 1 ≥λ 2 …≥λ p ≥0, and find the eigenvectors e i , i = 1, 2, …, p;

[0029] S2115, process the eigenvalues of the judgment matrix A to obtain the cumulative contribution rate;

[0030] The expression of the cumulative contribution rate is:

[0031]

[0032] S2116, select the eigenvalues λ with a cumulative contribution rate exceeding 95% 1 , λ 2 … λ m ;

[0033] S2117, process the eigenvalues λ with a cumulative contribution rate exceeding 95% 1 , λ 2 … λ m to obtain the cumulative coefficient l ij :

[0034]

[0035] where e ij is the correlation coefficient of the i-th eigenvalue with the original index x j , i = 1, 2, …, m, j = 1, 2, …, p;

[0036] S2118, process the eigenvalues λ with a cumulative contribution rate exceeding 95% 1 , λ 2 … λ m to obtain the cumulative contribution rate u i :

[0037]

[0038] S2119, process the cumulative contribution rate u i to obtain the weight vector w a ;

[0039] The expression of the weight vector w a is:

[0040] w a = [w a1 w a2 … w ap

[0041] where,

[0042] As an optional implementation manner, in the first aspect of the embodiments of the present invention, processing the weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d , the weight vector w e and the weight vector w f to obtain the penetration test performance evaluation result, including:

[0043] ​S2171. Process the subset of the penetration test performance evaluation metrics to obtain the first membership degree set of penetration test performance metrics, the second membership degree set of penetration test performance metrics, the third membership degree set of penetration test performance metrics, the fourth membership degree set of penetration test performance metrics, the fifth membership degree set of penetration test performance metrics, and the sixth membership degree set of penetration test performance metrics;

[0044] S2172. Process the weight vector w a and the first membership degree set of penetration test performance metrics to obtain the first penetration test performance judgment result;

[0045] S2173. Process the weight vector w b and the second membership degree set of penetration test performance metrics to obtain the second penetration test performance judgment result;

[0046] S2174. Process the weight vector w c and the third membership degree set of penetration test performance metrics to obtain the third penetration test performance judgment result;

[0047] S2175. Process the weight vector w d and the fourth membership degree set of penetration test performance metrics to obtain the fourth penetration test performance judgment result;

[0048] S2176. Process the weight vector w e and the fifth membership degree set of penetration test performance metrics to obtain the fifth penetration test performance judgment result;

[0049] S2177. Process the weight vector w f and the sixth membership degree set of penetration test performance metrics to obtain the sixth penetration test performance judgment result;

[0050] S2178. Process the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain the penetration test performance evaluation result.

[0051] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the process of processing the weight vector w a and the first membership degree set of penetration test performance metrics to obtain the first penetration test performance judgment result includes:

[0052] Using the first penetration test evaluation model, process the weight vector w aProcess it with the membership degree set of the first penetration test performance index to obtain the first penetration test performance judgment result S 1 ;

[0053] The expression of the first penetration test evaluation model is:

[0054]

[0055] where, w ak is the k-th element in the weight vector w a =(w a1 , w a2 ,... w ap ), and u k (x) is the corresponding element in the membership degree set of the first penetration test performance index.

[0056] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the processing of the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain the penetration test performance evaluation result includes:

[0057] S21781, process the penetration test performance evaluation index subset to obtain the penetration test performance evaluation index evaluation matrix E;

[0058] The expression of the penetration test performance evaluation index evaluation matrix E is:

[0059] E = [w 1 , w 2 , w 3 , w 4 , w 5 , w 6

[0060] where, w 1 is the weight of the first penetration test performance index, w 2 is the weight of the second penetration test performance index, w 3 is the weight of the third penetration test performance index, w 4 is the weight of the fourth penetration test performance index, w 5 is the weight of the fifth penetration test performance index, w 6 is the weight of the sixth penetration test performance index, w 1 + w 2 + w 3 + w 4 + w 5 + w 6 = 1;​

[0061] S21782, process the penetration test performance evaluation index evaluation matrix E, the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result.

[0062] The second aspect of the embodiments of the present invention discloses a hierarchical penetration test effect evaluation device, and the device includes:

[0063] An index construction module, configured to construct a hierarchical penetration test effect evaluation index set according to an evaluation object; the hierarchical penetration test effect evaluation index set includes a penetration test performance evaluation index subset and a social impact effect evaluation index subset;

[0064] The penetration test performance evaluation index subset includes a first penetration test performance index, a second penetration test performance index, a third penetration test performance index, a fourth penetration test performance index, a fifth penetration test performance index, and a sixth penetration test performance index;

[0065] The social impact effect evaluation index subset includes a first social impact index, a second social impact index, a third social impact index, a fourth social impact index, a fifth social impact index, and a sixth social impact index;

[0066] An index set processing module, configured to process the hierarchical penetration test effect evaluation index set to obtain a penetration test performance evaluation result and a social impact effect evaluation result;

[0067] A comprehensive evaluation module, configured to integrate the penetration test performance evaluation result and the social impact effect evaluation result to obtain a hierarchical penetration test effect evaluation result.

[0068] As an optional implementation manner, in the second aspect of the embodiments of the present invention, the processing of the hierarchical penetration test effect evaluation index set to obtain a penetration test performance evaluation result and a social impact effect evaluation result includes:

[0069] S21, process the penetration test performance evaluation index subset to obtain a penetration test performance evaluation result;

[0070] S22, process the social impact effect evaluation index subset to obtain a social impact effect evaluation result.

[0071] As an alternative implementation, in the second aspect of the embodiments of the present invention, the processing of the subset of penetration test performance evaluation indicators to obtain the penetration test performance evaluation result includes:

[0072] S211, process the first penetration test performance indicator to obtain the first penetration test performance judgment matrix A and the weight vector w a ;

[0073] S212, process the second penetration test performance indicator to obtain the second penetration test performance judgment matrix B and the weight vector w b ;

[0074] S213, process the third penetration test performance indicator to obtain the third penetration test performance judgment matrix C and the weight vector w c ;

[0075] S214, process the fourth penetration test performance indicator to obtain the fourth penetration test performance judgment matrix D and the weight vector w d ;

[0076] S215, process the fifth penetration test performance indicator to obtain the fifth penetration test performance judgment matrix E and the weight vector w e ;

[0077] S216, process the sixth penetration test performance indicator to obtain the fifth penetration test performance judgment matrix F and the weight vector w f ;

[0078] S217, process the weight vector w a 、the weight vector w b 、the weight vector w c 、the weight vector w d 、the weight vector w e and the weight vector w f to obtain the penetration test performance evaluation result.

[0079] As an alternative implementation, in the second aspect of the embodiments of the present invention, the processing of the first penetration test performance indicator to obtain the first penetration test performance judgment matrix A and the weight vector w a , includes:

[0080] S2111, preprocess the first penetration test performance indicator to obtain the preprocessed first penetration test performance indicator;

[0081] S2112, perform standardization processing on the preprocessed first penetration test performance indicator to obtain the standardized first penetration test performance indicator;

[0082] S2113. Process the standardized first penetration test performance metrics to obtain the first penetration test performance judgment matrix A;

[0083] The expression of the first penetration test performance judgment matrix A is:

[0084]

[0085] where the standardized first penetration test performance metrics are x = {x 1 x 2 …x p}, there are p metrics in total, a ij is the element in the i-th row and j-th column of the judgment matrix A, and a ij is the correlation coefficient between x i and x j . i = 1, 2, …, p, j = 1, 2, …, p;

[0086] S2114. Perform eigenvalue decomposition on the judgment matrix A to obtain the eigenvalues of the judgment matrix A, and sort the eigenvalues of the judgment matrix A as λ 1 ≥λ 2 …≥λ p ≥0, and find the eigenvectors e i corresponding to the eigenvalues, i = 1, 2, …, p;

[0087] S2115. Process the eigenvalues of the judgment matrix A to obtain the cumulative contribution rate;

[0088] The expression of the cumulative contribution rate is:

[0089]

[0090] S2116. Select the eigenvalues λ 1 , λ 2 …λ m whose cumulative contribution rate exceeds 95%;

[0091] S2117. Process the eigenvalues λ 1 , λ 2 …λ m whose cumulative contribution rate exceeds 95% to obtain the cumulative coefficients l ij :

[0092]

[0093] where e ij is the correlation coefficient of the i-th eigenvalue with respect to the original metric x j . i = 1, 2, …, m, j = 1, 2, …, p;

[0094] S2118. Process the eigenvalues λ 1 , λ 2 … λ m whose cumulative contribution rate exceeds 95% to obtain a cumulative contribution rate u i :

[0095]

[0096] S2119. Process the cumulative contribution rate u i to obtain a weight vector w a ;

[0097] The expression of the weight vector w a is:

[0098] w a = [w a1 w a2 … w ap

[0099] where

[0100] As an optional implementation manner, in the second aspect of the embodiments of the present invention, the processing of the weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d , the weight vector w e and the weight vector w f to obtain a penetration test performance evaluation result includes:

[0101] S2171. Process the subset of penetration test performance evaluation indicators to obtain a first penetration test performance index membership degree set, a second penetration test performance index membership degree set, a third penetration test performance index membership degree set, a fourth penetration test performance index membership degree set, a fifth penetration test performance index membership degree set, and a sixth penetration test performance index membership degree set;

[0102] S2172. Process the weight vector w a and the first penetration test performance index membership degree set to obtain a first penetration test performance judgment result;

[0103] S2173. Process the weight vector w b and the second penetration test performance index membership degree set to obtain a second penetration test performance judgment result;

[0104] S2174. Process the weight vector w cProcess it with the membership degree set of the third penetration test performance index to obtain the third penetration test performance judgment result;

[0105] S2175. Process the weight vector w d and the membership degree set of the fourth penetration test performance index to obtain the fourth penetration test performance judgment result;

[0106] S2176. Process the weight vector w e and the membership degree set of the fifth penetration test performance index to obtain the fifth penetration test performance judgment result;

[0107] S2177. Process the weight vector w f and the membership degree set of the sixth penetration test performance index to obtain the sixth penetration test performance judgment result;

[0108] S2178. Process the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain the penetration test performance evaluation result.

[0109] As an optional implementation manner, in the second aspect of the embodiments of the present invention, the process of the weight vector w a and the membership degree set of the first penetration test performance index to obtain the first penetration test performance judgment result includes:

[0110] Use the first penetration test evaluation model to process the weight vector w a and the membership degree set of the first penetration test performance index to obtain the first penetration test performance judgment result S 1 ;

[0111] The expression of the first penetration test evaluation model is:

[0112]

[0113] where w ak is the k-th element in the weight vector w a =(w a1 , w a2 ,... w ap ), and u k (x) is the corresponding element in the membership degree set of the first penetration test performance index.

[0114] As an alternative implementation, in the second aspect of the embodiments of the present invention, processing the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result includes:

[0115] S21781. Processing the subset of penetration test performance evaluation indicators to obtain a penetration test performance evaluation index evaluation matrix E;

[0116] The expression of the penetration test performance evaluation index evaluation matrix E is:

[0117] E = [w 1 , w 2 , w 3 , w 4 , w 5 , w 6

[0118] where w 1 is the weight of the first penetration test performance index, w 2 is the weight of the second penetration test performance index, w 3 is the weight of the third penetration test performance index, w 4 is the weight of the fourth penetration test performance index, w 5 is the weight of the fifth penetration test performance index, w 6 is the weight of the sixth penetration test performance index, w 1 + w 2 + w 3 + w 4 + w 5 + w 6 = 1;

[0119] S21782. Processing the penetration test performance evaluation index evaluation matrix E and the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result.

[0120] The third aspect of the present invention discloses another hierarchical penetration test effect evaluation device, and the device includes:

[0121] A memory storing executable program code;

[0122] A processor coupled to the memory;

[0123] ​The processor calls the executable program code stored in the memory and executes some or all of the steps in the hierarchical penetration test effect evaluation method disclosed in the first aspect of the embodiments of the present invention.

[0124] The fourth aspect of the present invention discloses a computer-readable storage medium storing computer instructions, which are used to execute some or all of the steps in the hierarchical penetration test effect evaluation method disclosed in the first aspect of the embodiments of the present invention when the computer instructions are called.

[0125] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0126] The present invention provides a hierarchical penetration test effect evaluation method. Based on the final results of network penetration tests as the index division basis, it analyzes the differences in penetration test effects by using different penetration test means, penetration test methods, and penetration test tools for the same penetration test target, which helps assist combat personnel in formulating mission operation plans. BRIEF DESCRIPTION OF THE DRAWINGS

[0127] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0128] Figure 1 is a schematic flowchart of a hierarchical penetration test effect evaluation method disclosed in the embodiments of the present invention;

[0129] Figure 2 is a schematic structural diagram of a hierarchical penetration test effect evaluation device disclosed in the embodiments of the present invention;

[0130] Figure 3 is a schematic structural diagram of another hierarchical penetration test effect evaluation device disclosed in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0131] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0132] In the description, claims and the above drawings of the present invention, terms such as "first", "second", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or equipment.

[0133] Reference to "embodiment" herein means that a particular feature, structure or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0134] The present invention discloses a hierarchical penetration testing effect evaluation method and device. The method includes: constructing a hierarchical penetration testing effect evaluation index set according to the evaluation object, including a penetration testing performance evaluation index subset and a social impact effect evaluation index subset; processing the hierarchical penetration testing effect evaluation index set to obtain a penetration testing performance evaluation result and a social impact effect evaluation result; integrating the penetration testing performance evaluation result and the social impact effect evaluation result to obtain a hierarchical penetration testing effect evaluation result. The present invention takes the final result of network penetration testing as the basis for index division, and analyzes the differences in penetration testing effects by using different penetration testing means, penetration testing methods, and penetration testing tools for the same penetration testing target, which helps to assist in formulating a penetration testing task plan. The following will be described in detail respectively.

[0135] Embodiment 1

[0136] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a hierarchical penetration testing effect evaluation method disclosed in an embodiment of the present invention. Among them, Figure 1 The described hierarchical penetration testing effect evaluation method is applied to the field of effect evaluation technology, and the embodiments of the present invention do not make limitations. As Figure 1 shown, the hierarchical penetration testing effect evaluation method may include the following operations:

[0137] S1. Construct a hierarchical penetration testing effect evaluation index set according to the evaluation object; the hierarchical penetration testing effect evaluation index set includes a penetration testing performance evaluation index subset and a social impact effect evaluation index subset;

[0138] Optionally, the method for constructing a hierarchical penetration testing effect evaluation index set is to use plug-in data collection tools and data collection agents to collect network performance, service performance, basic operation data, etc. of the target system under penetration testing to form a subset of penetration testing performance evaluation indicators; use methods such as web intelligence data scraping and analysis to collect a subset of social impact effect evaluation indicators;

[0139] The subset of penetration testing performance evaluation indicators includes the first penetration testing performance indicator, the second penetration testing performance indicator, the third penetration testing performance indicator, the fourth penetration testing performance indicator, the fifth penetration testing performance indicator, and the sixth penetration testing performance indicator;

[0140] Optionally, the first penetration testing performance indicator is a network intelligence acquisition indicator, the second penetration testing performance indicator is a network breakthrough indicator, the third penetration testing performance indicator is a network control indicator, the fourth penetration testing performance indicator is a business disruption indicator, the fifth penetration testing performance indicator is an information deception indicator, and the sixth penetration testing performance indicator is a business paralysis indicator;

[0141] (1) Network intelligence acquisition indicator

[0142] Types of information obtained: Defined as the type of information obtained, including target network assets, configuration information, sensitive data, target person data, target city data, target service data. Different types of information have different values and different weights in the evaluation calculation.

[0143] Proportion of the amount of information obtained: Defined as the ratio of the amount of information data obtained to the total amount of expected information obtained.

[0144] Penetration testing time: Defined as the ratio of the time required for penetration testing to the expected penetration testing time. The penetration testing time is defined as the time interval from the start of penetration testing to the end of penetration testing. The penetration testing time is a reverse indicator. The longer the time required for penetration testing, the greater the risk of exposure of the penetration testing behavior, and accordingly the penetration testing effect will be reduced.

[0145] Penetration testing success rate: Defined as the ratio of the number of penetration testing execution commands to the expected number of penetration testing command executions.

[0146] (2) Network breakthrough indicator

[0147] Network breakthrough indicators are used to evaluate the effect of breakthrough penetration testing, including obtaining control rights (superuser rights, ordinary user rights, hardware device control rights, operating system rights, application service access rights, service read rights, write rights, execution rights, etc.) of the target network, target nodes, devices, and services, the time required for penetration testing, the success rate, etc.

[0148] Breakthrough target types: Hardware (hosts, mobile intelligent terminals, IoT devices, servers, routers, switches, security devices, dedicated hardware devices (e.g., ATMs)), software services (office software, business application software (finance, government affairs, etc.), database services, mail services).

[0149] Proportion of breakthrough target data volume: The ratio of the quantity of each breakthrough target to the expected quantity.

[0150] Permission types: Hardware device operation rights, motherboard firmware editing and rewriting permissions, device configuration management permissions, operating system permissions, application system permissions, database permissions, data file read and write permissions, application program execution permissions.

[0151] Degree of permission escalation: Defined as the control permissions obtained for the target object through network penetration testing. This is a qualitative descriptive indicator. The higher the obtained permissions, the better the corresponding penetration testing effect is considered.

[0152] Penetration testing time: Defined as the ratio of the time spent on permission escalation penetration testing to the expected time. The longer the required time, the greater the risk of exposure of the penetration testing behavior, and correspondingly the lower the penetration testing effect.

[0153] Penetration testing success rate: Defined as the ratio of the number of obtained permissions to the total expected number of obtained permissions. The higher the penetration testing success rate, the better the penetration testing effect.

[0154] (3) Network control indicators

[0155] Network control type indicators are used to evaluate the long-term control and utilization capabilities of the target network / node / service, including indicators such as the type and quantity of controlled devices, control duration, penetration testing required time, penetration testing success rate, propagation rate, security product bypass rate, etc.

[0156] Types of latent nodes: Hosts, mobile intelligent terminals, IoT devices, servers, routers, switches, security devices, software services

[0157] Number of latent nodes: Defined as the quantity of each type of latent node.

[0158] Latent time: Defined as the survival time of the latent code, the time interval from the start of communication between the latent code and the control end to the last communication with the control end, and the time of the last communication with the control end.

[0159] Penetration testing time: Defined as the ratio of the time interval from the start of penetration testing to the completion of penetration testing to the expected penetration testing time.

[0160] Penetration testing success rate: Defined as the ratio of the number of successfully activated latent nodes to the total expected number.

[0161] (4) Business disruption indicators

[0162] Number of user connections: Defines the number of users connected to the target service.

[0163] Types of services exploited by deception: The business types include email services, DNS services, web services, database services, FTP services, and enterprise management.

[0164] Business recovery time: The time interval from the start of business disruption to the time when the business resumes normal operation.

[0165] Penetration testing time: The ratio of the time interval from the start of penetration testing to the end of penetration testing to the expected time.

[0166] Penetration testing success rate: Defined as the ratio of the number of instructions used in penetration testing to the expected number of instructions.

[0167] (5) Information deception indicators

[0168] The information deception indicator deceives target users by tampering with or deleting data or the configuration of devices and business systems, causing damage to the target business.

[0169] Types of data tampered with or deleted: User files, system configuration files, business application configuration files, database files

[0170] Proportion of tampered file information: Defined as the number of data file information successfully tampered with in network penetration testing to the expected number of tampered files.

[0171] Proportion of deleted file information: Defined as the number of data file information deleted in network penetration testing to the expected number of tampered files.

[0172] Penetration testing time: The ratio of the time interval from the start of penetration testing to the end of penetration testing to the expected time.

[0173] Penetration testing success rate: Defined as the ratio of the number of instructions used in penetration testing to the expected number of instructions.

[0174] (6) Business paralysis indicators

[0175] Service indicators: Network services, business application services, email services, DNS services, web services, database services, FTP services, enterprise management;

[0176] Devices causing paralysis: Terminals, servers, routers, switches, security devices, mobile intelligent terminals, IOT devices (cameras, electronic screens, electronic locks, elevator controls)

[0177] Target network availability: It is defined as the ratio of the number of data that can be normally transmitted in the target network system after a penetration test to all available amounts. The lower the network availability, the better the effect of the network penetration test, which is a negative indicator.

[0178] Target network bandwidth occupancy rate: It is defined as the ratio of the occupied amount of the network bandwidth of the target network system after a penetration test to all available bandwidths. When a penetration test occurs, the penetrator creates a large number of packets to occupy the limited network resources and block the network bandwidth, thus achieving the penetration test intention of the penetrator. Therefore, the network bandwidth occupancy rate will change greatly. The larger the value of the network bandwidth occupancy rate, the more the network bandwidth is occupied, the lower the ability of the target system to provide services to legitimate users, and the better the effect of the network penetration test, which is a positive indicator.

[0179] Target network throughput: It is defined as the total amount of data successfully transmitted on the link per unit time (second) (usually expressed in bits, bytes or packets). When a penetration test occurs, the throughput of the penetrated network will necessarily decrease. The throughput can be obtained by monitoring the number of bytes transmitted on the link for a period of time. When obtaining it, an appropriate time interval must be selected, neither too long nor too short, otherwise the burst rate cannot be measured or the burst rate will be exaggerated. In order to obtain more comprehensive and objective throughput data, the impact of the network's own load on the network throughput also needs to be considered, and tests can be carried out at different time periods. The lower the network throughput, the better the effect of the network penetration test, which is a negative indicator.

[0180] Target network latency: It is defined as the time from when the data enters the network to when the data leaves the network, including the time spent on the link during data transmission and the time consumed for queuing and forwarding when passing through the router. When a penetration test occurs, the load of the network system will necessarily increase, and the network latency time will also necessarily increase. The longer the network latency time, the better the effect of the network penetration test, which is a positive indicator.

[0181] Target network latency variation: That is, delay jitter, which is defined as the variation of the delay time. The target network latency variation is an important evaluation indicator for multimedia communication networks. The larger the target network latency variation, the better the effect of the network penetration test, which is a positive indicator.

[0182] Target network average response time: It is defined as the average time interval from the start of requesting network services to the response to this request. The network average response time is also affected by the network load. When a penetration test occurs, the network load increases, and its response time also increases. The longer the network average response time, the better the effect of the network penetration test, which is a positive indicator.

[0183] Target network packet loss rate: It is defined as the ratio of the number of lost data packets to the total number of sent data packets within a unit time. Network congestion is one of the main reasons for data packet loss. When a penetration test occurs, the tester floods the network bandwidth with a large number of packets, which will inevitably increase the network packet loss rate. The higher the network packet loss rate, the better the effect of the network penetration test, which is a positive indicator.

[0184] Target network recovery time: It is defined as the time required for the network system to return to the state before the fault and resume providing services after the penetration test stops. When measuring the network recovery time, it is necessary to consider that it is highly related to the structure of the network system itself and the level of the operator. The longer the network recovery time, the more persistent the impact of the penetration test on the target network, and the better the effect of the network penetration test, which is a positive indicator.

[0185] Service response delay: It is defined as the time interval from the arrival of the service request signal at the target of the penetration test to the provision of the service by the target of the penetration test. When a penetration test occurs, the load on the target host system increases, resulting in a decrease in the ability to respond to normal service requests, and the service response delay increases accordingly. The greater the service response delay, the better the penetration test effect. It is an important indicator for evaluating the effectiveness of penetration tests that damage the availability of the host (especially denial-of-service penetration tests). The difference in service response delay before and after the penetration test intuitively reflects the penetration test effectiveness of this type of penetration test.

[0186] Ratio of legitimate connections rejected: It is defined as the ratio of the number of legitimate connections rejected by the target host system within a unit time to the total number of received legitimate connections. After a penetration test occurs, the ability of the target host to handle legitimate connections decreases, so legitimate connections are often rejected. The higher the ratio of legitimate connections rejected, the better the penetration test effect.

[0187] Host recovery time: It is defined as the time required for the target host to return to the state before the penetration test and resume providing normal services after the penetration test stops. After a penetration test occurs, it takes a certain amount of time for the penetration test target to recover to the state where it can provide normal services to legitimate users. The longer the recovery time, the more persistent the impact of the penetration test on the target, and the better the penetration test effect.

[0188] The subset of social impact effect evaluation indicators includes the first social impact indicator, the second social impact indicator, the third social impact indicator, the fourth social impact indicator, the fifth social impact indicator, and the sixth social impact indicator;

[0189] Optionally, the first social impact indicator is the economic impact indicator, the second social impact indicator is the audience impact indicator, the third social impact indicator is the public opinion impact indicator, the fourth social impact indicator is the diplomatic impact indicator, the fifth social impact indicator is the political impact indicator, and the sixth social impact indicator is the military impact indicator.

[0190] The economic impact indicators include direct economic losses, indirect economic losses, stock market impacts, and impact duration.

[0191] The audience impact indicators mainly reflect the impacts of penetration testing operations on the people in the target cities. The impact on the public is comprehensively evaluated from aspects such as the type of affected population (important target persons, military and government staff, public figures, ordinary people, etc.), the type of region (key cities / regions, ordinary cities / regions, rural areas, main roads, shopping malls and squares, office premises), and the type of industry (finance, government affairs, transportation, energy, healthcare, education).

[0192] The public opinion impact indicators mainly reflect the penetration testing effects from the perspective of public opinion reports. Different types of public opinion reports have different weights. For example, media reports at the national level have greater influence than those at the provincial and municipal levels, so they have a greater weight in the effect evaluation.

[0193] The diplomatic impact indicators are evaluated from aspects such as government spokespersons, international reports, and the international investment environment.

[0194] The political impact indicators are evaluated from two aspects: the impact of public opinion reports and the reactions of the public.

[0195] The military impact indicators are evaluated from two aspects: social mobilization and the speeches of military personnel.

[0196] S2. Process the hierarchical penetration testing effect evaluation indicator set to obtain the penetration testing performance evaluation result and the social impact effect evaluation result;

[0197] S3. Integrate the penetration testing performance evaluation result and the social impact effect evaluation result to obtain the hierarchical penetration testing effect evaluation result, including:

[0198] Hierarchical penetration testing effect evaluation result = n 1 × Penetration testing performance evaluation result + × Social impact effect evaluation result

[0199] n 1 Is the weight of the penetration testing performance evaluation result, n 2 Is the weight of the social impact effect evaluation result, n 1 + n 2 = 1.

[0200] Optionally, the process of processing the hierarchical penetration testing effect evaluation indicator set to obtain the penetration testing performance evaluation result and the social impact effect evaluation result includes:

[0201] S21. Process the penetration testing performance evaluation indicator subset to obtain the penetration testing performance evaluation result;

[0202] S22. Process the subset of social impact effect evaluation indicators to obtain the social impact effect evaluation result.

[0203] Optionally, the process of processing the subset of penetration test performance evaluation indicators to obtain the penetration test performance evaluation result includes:

[0204] S211. Process the first penetration test performance indicator to obtain the first penetration test performance judgment matrix A and the weight vector w a ;

[0205] S212. Process the second penetration test performance indicator to obtain the second penetration test performance judgment matrix B and the weight vector w b ;

[0206] S213. Process the third penetration test performance indicator to obtain the third penetration test performance judgment matrix C and the weight vector w c ;

[0207] S214. Process the fourth penetration test performance indicator to obtain the fourth penetration test performance judgment matrix D and the weight vector w d ;

[0208] S215. Process the fifth penetration test performance indicator to obtain the fifth penetration test performance judgment matrix E and the weight vector w e ;

[0209] S216. Process the sixth penetration test performance indicator to obtain the fifth penetration test performance judgment matrix F and the weight vector w f ;

[0210] S217. Process the weight vector w a and the weight vector w b and the weight vector w c and the weight vector w d and the weight vector w e and the weight vector w f to obtain the penetration test performance evaluation result.

[0211] Optionally, the process of processing the first penetration test performance indicator to obtain the first penetration test performance judgment matrix A and the weight vector w a , includes:

[0212] S2111. Preprocess the first penetration test performance indicator to obtain the preprocessed first penetration test performance indicator;

[0213] The preprocessing includes data parsing, data cleaning, element extraction, and data classification;

[0214] The data parsing module mainly targets the target web page data, parses the collected web page tags to generate the web page identifier docID, extracts information elements, and supports the parsing of data elements in multiple protocols such as Json, html, rdf, owl, atom, and cvs. Using the original web page as the data input, it outputs the data content of each tag data.

[0215] Data cleaning is responsible for checking and processing the parsed data, handling error values, duplicate values, missing values, outliers, etc., including data deduplication, missing item supplementation, etc. Missing item supplementation can be achieved through methods such as incomplete front and back data, inference from other data sources (such as supplementing age, gender, etc. through the ID number). The deduplication module will calculate a unique key value, such as the MD5 value, for the obtained effect evaluation data to eliminate duplicate effect evaluation data. At the same time, for formatted data, a field that can mark whether the data is repeated will be set. If the values of these fields are the same, it can also be determined that the data is repeated, and information fusion will be performed.

[0216] Element extraction is used to extract key elements from the data. For text data, the named entity recognition algorithm will be used to extract key elements from the data; for structured and semi-structured data, the pattern matching algorithm will be used to extract elements from the data.

[0217] Data classification will construct a hierarchical classification tree according to the content for classifying the obtained effect evaluation data. The system realizes the hierarchical classification of the effect evaluation data by training a classification model based on the support vector machine.

[0218] S2112, perform standardization processing on the first penetration test performance index of the preprocessing to obtain the standardized first penetration test performance index;

[0219] The standardization processing includes index dimensionless processing and index normalization processing;

[0220] There are three methods for index data dimensionless processing: linear dimensionless method, broken line dimensionless method, and curve dimensionless method.

[0221] The normalized result of the index exceeds the interval [0, 1], is distributed on both sides of zero, and values greater than the mean are normalized to positive values, otherwise they are normalized.

[0222] S2113, process the standardized first penetration test performance index to obtain the first penetration test performance judgment matrix A;

[0223] The expression of the first penetration test performance judgment matrix A is:

[0224]

[0225] Among them, the standardized first penetration test performance index is \(x = \{x 1 x 2 …x p \}\), there are \(p\) indicators in total, \(a ij is the element in the \(i\)-th row and \(j\)-th column of the judgment matrix \(A\), \(a ij is the correlation coefficient between \(x i and \(x j , \(i = 1, 2, \ldots, p\), \(j = 1, 2, \ldots, p\);

[0226] S2114, perform eigenvalue decomposition on the judgment matrix \(A\) to obtain the eigenvalues of the judgment matrix \(A\), and sort the eigenvalues of the judgment matrix \(A\) as \(\lambda 1 \geq\lambda 2 …\geq p \lambda_0\), and find the eigenvectors \(e i , \(i = 1, 2, \ldots, p\);

[0227] S2115, process the eigenvalues of the judgment matrix \(A\) to obtain the cumulative contribution rate;

[0228] The expression of the cumulative contribution rate is:

[0229]

[0230] S2116, select the eigenvalues \(\lambda 1 ,\lambda 2 …\lambda m whose cumulative contribution rate exceeds 95%;

[0231] S2117, process the eigenvalues \(\lambda 1 ,\lambda 2 …\lambda m whose cumulative contribution rate exceeds 95% to obtain the cumulative coefficient \(l ij :

[0232]

[0233] where \(e ij is the correlation coefficient of the \(i\)-th eigenvalue with the original indicator \(x j , \(i = 1, 2, \ldots, m\), \(j = 1, 2, \ldots, p\);

[0234] S2118, process the eigenvalues \(\lambda 1 ,\lambda 2 …\lambda m whose cumulative contribution rate exceeds 95% to obtain the cumulative contribution rate \(u i :

[0235]

[0236] S2119, process the cumulative contribution rate u i to obtain the weight vector w a ;

[0237] The weight vector w a has the following expression:

[0238] w a = [w a1 w a2 … w ap

[0239] where

[0240] the calculation methods of the weight vectors w b , w c , w d , w e and w f are the same as the calculation method of the weight vector w a .

[0241] Optionally, the calculation method of the weight vector w a is as follows:

[0242] Use the first geometric mean model to process the judgment matrix A to obtain the geometric mean of all elements in each row of the judgment matrix A;

[0243] The first geometric mean model is:

[0244]

[0245] where the geometric mean of all elements in each row of the judgment matrix A is a ij is the element in the i-th row and j-th column of the judgment matrix A, and n is the number of rows and columns of the judgment matrix A;

[0246] Normalize the geometric mean w a to obtain the weight vector w a ;

[0247] The normalization is:

[0248]

[0249] where the weight vector w a = (w a1 , w a2 ,... w an ​) The weight vector is an approximation of the relative weights of the eigenvectors corresponding to the maximum eigenvalue, that is, the relative weights of the elements in the next layer with respect to the previous layer. Calculate the maximum eigenvalue λ of the judgment matrix A amax , where (AW a ) i is the i-th element of the vector AW a , with a total of n elements, and W a is the eigenvector corresponding to the maximum eigenvalue.

[0250] Optionally, processing the weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d , the weight vector w e and the weight vector w f to obtain the penetration test performance evaluation result, including:

[0251] S2171. Processing the subset of penetration test performance evaluation indicators to obtain the first penetration test performance index membership degree set, the second penetration test performance index membership degree set, the third penetration test performance index membership degree set, the fourth penetration test performance index membership degree set, the fifth penetration test performance index membership degree set, and the sixth penetration test performance index membership degree set;

[0252] S2172. Processing the weight vector w a and the first penetration test performance index membership degree set to obtain the first penetration test performance judgment result;

[0253] S2173. Processing the weight vector w b and the second penetration test performance index membership degree set to obtain the second penetration test performance judgment result;

[0254] S2174. Processing the weight vector w c and the third penetration test performance index membership degree set to obtain the third penetration test performance judgment result;

[0255] S2175. Processing the weight vector w d and the fourth penetration test performance index membership degree set to obtain the fourth penetration test performance judgment result;

[0256] S2176. Processing the weight vector w e and the fifth penetration test performance index membership degree set to obtain the fifth penetration test performance judgment result;

[0257] S2177. Process the weight vector w f and the membership degree set of the sixth penetration test performance index to obtain the sixth penetration test performance judgment result;

[0258] S2178. Process the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain the penetration test performance evaluation result.

[0259] Optionally, the process of processing the weight vector w a and the membership degree set of the first penetration test performance index to obtain the first penetration test performance judgment result includes:

[0260] Using the first penetration test evaluation model, process the weight vector w a and the membership degree set of the first penetration test performance index to obtain the first penetration test performance judgment result S 1 ;

[0261] The expression of the first penetration test evaluation model is:

[0262]

[0263] where w ak is the k-th element in the weight vector w a =(w a1 , w a2 ,... w ap ), and u k (x) is the corresponding element in the membership degree set of the first penetration test performance index.

[0264] The calculation methods of the second penetration test performance judgment result S 2 , the third penetration test performance judgment result S 3 , the fourth penetration test performance judgment result S 4 , the fifth penetration test performance judgment result S 5 , and the sixth penetration test performance judgment result S 6 are the same as the calculation method of the first penetration test performance judgment result S 1 .

[0265] Optionally, the process of processing the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain the penetration test performance evaluation result includes:

[0266] S21781. Process the subset of penetration test performance evaluation metrics to obtain a penetration test performance evaluation metric evaluation matrix E;

[0267] The expression of the penetration test performance evaluation metric evaluation matrix E is:

[0268] E = [w 1 , w 2 , w 3 , w 4 , w 5 , w 6

[0269] where w 1 is the weight of the first penetration test performance metric, w 2 is the weight of the second penetration test performance metric, w 3 is the weight of the third penetration test performance metric, w 4 is the weight of the fourth penetration test performance metric, w 5 is the weight of the fifth penetration test performance metric, w 6 is the weight of the sixth penetration test performance metric, w 1 + w 2 + w 3 + w 4 + w 5 + w 6 = 1;

[0270] S21782. Process the penetration test performance evaluation metric evaluation matrix E and the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result.

[0271] Penetration test performance evaluation result = S 1 w 1 + S 2 w 2 + S 3 w 3 + S 4 w 4 + S 5 w 5 + S 6 w 6

[0272] Process the subset of social impact effect evaluation metrics according to the same calculation method as the penetration test performance evaluation result to obtain a social impact effect evaluation result. ​

[0273] It can be seen that the present invention provides a hierarchical penetration test effect evaluation method. Based on the final results of network penetration tests as the basis for index division, the differences in penetration test effects are analyzed by using different penetration test means, penetration test methods, and penetration test tools for the same penetration test target, which helps to assist combat personnel in formulating mission operation plans.

[0274] Embodiment 2

[0275] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of a hierarchical penetration test effect evaluation device disclosed in an embodiment of the present invention. Among them, Figure 2 the described hierarchical penetration test effect evaluation device is applied to the technical field of effect evaluation, and the embodiments of the present invention are not limited thereto. As Figure 2 shown, the hierarchical penetration test effect evaluation device may include the following operations:

[0276] S301, an index construction module, for constructing a hierarchical penetration test effect evaluation index set according to the evaluation object; the hierarchical penetration test effect evaluation index set includes a penetration test performance evaluation index subset and a social impact effect evaluation index subset;

[0277] The penetration test performance evaluation index subset includes a first penetration test performance index, a second penetration test performance index, a third penetration test performance index, a fourth penetration test performance index, a fifth penetration test performance index, and a sixth penetration test performance index;

[0278] The social impact effect evaluation index subset includes a first social impact index, a second social impact index, a third social impact index, a fourth social impact index, a fifth social impact index, and a sixth social impact index;

[0279] S302, an index set processing module, for processing the hierarchical penetration test effect evaluation index set to obtain a penetration test performance evaluation result and a social impact effect evaluation result;

[0280] S303, a comprehensive evaluation module, for integrating the penetration test performance evaluation result and the social impact effect evaluation result to obtain a hierarchical penetration test effect evaluation result.

[0281] It can be seen that the present invention provides a hierarchical penetration test effect evaluation method. Based on the final results of network penetration tests as the basis for index division, the differences in penetration test effects are analyzed by using different penetration test means, penetration test methods, and penetration test tools for the same penetration test target, which helps to assist combat personnel in formulating mission operation plans.

[0282] Embodiment 3

[0283] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of another hierarchical penetration test effect evaluation device disclosed in an embodiment of the present invention. Among them, Figure 3 the described hierarchical penetration test effect evaluation device is applied to the technical field of effect evaluation, and the embodiments of the present invention are not limited thereto. As Figure 3 shown, the hierarchical penetration test effect evaluation device may include the following operations:

[0284] A memory 401 storing executable program code;

[0285] A processor 402 coupled to the memory 401;

[0286] The processor 402 calls the executable program code stored in the memory 401 to execute the steps in the hierarchical penetration test effect evaluation method described in Embodiment 1.

[0287] Embodiment 4

[0288] An embodiment of the present invention discloses a computer-readable storage medium storing a computer program for electronic data exchange, wherein the computer program causes a computer to execute the steps in the hierarchical penetration test effect evaluation method described in Embodiment 1.

[0289] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0290] Through the specific descriptions of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, and the storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other medium that can be used to carry or store data and is computer-readable.

[0291] Finally, it should be noted that: What is disclosed in an evaluation method and device for hierarchical penetration testing effects disclosed in the embodiments of the present invention is only the preferred embodiments of the present invention, and is only used to illustrate the technical solutions of the present invention, rather than limiting it; Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A hierarchical penetration test effect evaluation method, characterized in that: The method comprises: S1, constructing a hierarchical penetration test effect evaluation indicator set according to the evaluation object; the hierarchical penetration test effect evaluation indicator set includes a penetration test performance evaluation indicator subset and a social impact effect evaluation indicator subset; The penetration test performance evaluation indicator subset includes a first penetration test performance indicator, a second penetration test performance indicator, a third penetration test performance indicator, a fourth penetration test performance indicator, a fifth penetration test performance indicator and a sixth penetration test performance indicator; The social impact effect evaluation indicator subset includes a first social impact indicator, a second social impact indicator, a third social impact indicator, a fourth social impact indicator, a fifth social impact indicator and a sixth social impact indicator; S2, processing the hierarchical penetration test effect evaluation indicator set to obtain a penetration test performance evaluation result and a social impact effect evaluation result; S3, integrating the penetration test performance evaluation results and the social impact effect evaluation results to obtain a hierarchical penetration test effect evaluation result.

2. The hierarchical penetration test effect evaluation method according to claim 1 is characterized in that: The hierarchical penetration test effect evaluation indicator set is processed to obtain a penetration test performance evaluation result and a social impact effect evaluation result, including: S21, processing the penetration test performance evaluation indicator subset to obtain a penetration test performance evaluation result; S22, processing the social impact effect evaluation indicator subset to obtain a social impact effect evaluation result.

3. The hierarchical penetration test effect evaluation method according to claim 2 is characterized in that: The processing of the penetration test performance evaluation indicator subset to obtain a penetration test performance evaluation result includes: S211, processing the first penetration test performance indicator to obtain a first penetration test performance judgment matrix A and a weight vector w a ; S212, processing the second penetration test performance indicator to obtain a second penetration test performance judgment matrix B and a weight vector w b ; S213, processing the third penetration test performance indicator to obtain a third penetration test performance judgment matrix C and a weight vector w c ; S214, processing the fourth penetration test performance indicator to obtain a fourth penetration test performance judgment matrix D and a weight vector w d ; S215, processing the fifth penetration test performance indicator to obtain a fifth penetration test performance judgment matrix E and a weight vector w e ; S216, processing the sixth penetration test performance indicator to obtain a fifth penetration test performance judgment matrix F and a weight vector w f ; S217, the weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d , the weight vector w e and the weight vector w f Processing is performed to obtain the penetration test performance evaluation results.

4. The hierarchical penetration test effect evaluation method according to claim 3 is characterized in that: The first penetration test performance indicator is processed to obtain a first penetration test performance judgment matrix A and a weight vector w a ,include: S2111, preprocessing the first penetration test performance indicator to obtain a preprocessed first penetration test performance indicator; S2112, performing standardization processing on the pre-processed first penetration test performance indicator to obtain a standardized first penetration test performance indicator; S2113, processing the standardized first penetration test performance indicator to obtain a first penetration test performance judgment matrix A; The first penetration test performance judgment matrix A is expressed as: Among them, the standardized first penetration test performance index is x = {x1 x2x p }, there are p indicators in total, a ij is the element in the i-th row and j-th column of the judgment matrix A, a ij For x i and x j Correlation coefficient, i = 1, 2, ..., p, j = 1, 2, ..., p; S2114, performing eigenvalue decomposition on the judgment matrix A to obtain eigenvalues ​​of the judgment matrix A, and sorting the eigenvalues ​​of the judgment matrix A by λ1≥λ2…≥λ p ≥0, find the eigenvector e corresponding to the eigenvalue i , i=1,2,…,p; S2115, processing the eigenvalues ​​of the judgment matrix A to obtain a cumulative contribution rate; The cumulative contribution rate expression is: S2116, select eigenvalues ​​λ1,λ2…λ whose contribution rate exceeds 95% m ; S2117, for the eigenvalues ​​λ1,λ2…λ whose cumulative contribution rate exceeds 95%, m Processing is performed to obtain the cumulative coefficient l ij : where e ij is the i-th eigenvalue for the original index x j Correlation coefficient, i = 1, 2, ..., m, j = 1, 2, ..., p; S2118, for the eigenvalues ​​λ1,λ2…λ whose cumulative contribution rate exceeds 95%, m Processing is performed to obtain the cumulative contribution rate u i : S2119, the cumulative contribution rate u i Processing to obtain the weight vector w a ; The weight vector w a The expression is: In a =[in a1 In a2 … In ap ] in, i=1,2,…,m, j=1,2,…,p.

5. The hierarchical penetration test effect evaluation method according to claim 3 is characterized in that: The weight vector w a , the weight vector w b , the weight vector w c , the weight vector w d , the weight vector w e and the weight vector w f Processing is performed to obtain the penetration test performance evaluation results, including: S2171, processing the penetration test performance evaluation indicator subset to obtain a first penetration test performance indicator membership set, a second penetration test performance indicator membership set, a third penetration test performance indicator membership set, a fourth penetration test performance indicator membership set, a fifth penetration test performance indicator membership set, and a sixth penetration test performance indicator membership set; S2172, the weight vector w a and the first penetration test performance indicator membership set to obtain a first penetration test performance judgment result; S2173, the weight vector w b and the second penetration test performance indicator membership set to obtain a second penetration test performance judgment result; S2174, the weight vector w c and the third penetration test performance indicator membership set to obtain a third penetration test performance judgment result; S2175, for the weight vector w d and the fourth penetration test performance indicator membership set to obtain a fourth penetration test performance judgment result; S2176, for the weight vector w e and the fifth penetration test performance indicator membership set to obtain a fifth penetration test performance judgment result; S2177, for the weight vector w f and the sixth penetration test performance indicator membership set to obtain a sixth penetration test performance judgment result; S2178, processing the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result.

6. The hierarchical penetration test effect evaluation method according to claim 5 is characterized in that: The weight vector w a and the first penetration test performance indicator membership set to obtain a first penetration test performance judgment result, including: Using the first penetration test evaluation model, the weight vector w a and the first penetration test performance indicator membership set to obtain a first penetration test performance judgment result S1; The first penetration test evaluation model expression is: Among them, w ak is the weight vector w a =(w a1 ,w a2 ,...w ap ), the kth element in k (x) is the corresponding element in the first penetration test performance indicator membership set.

7. The hierarchical penetration test effect evaluation method according to claim 5 is characterized in that: The processing of the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result, and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result includes: S23781, processing the penetration test performance evaluation indicator subset to obtain a penetration test performance evaluation indicator evaluation matrix E; The expression of the penetration test performance evaluation matrix E is: E=[w1,w2,w3,w4,w5,w6] Wherein, w1 is the weight of the first penetration test performance indicator, w2 is the weight of the second penetration test performance indicator, w3 is the weight of the third penetration test performance indicator, w4 is the weight of the fourth penetration test performance indicator, w5 is the weight of the fifth penetration test performance indicator, w6 is the weight of the sixth penetration test performance indicator, w1+w2+w3+w4+w5+w6=1; S23782, process the penetration test performance evaluation index evaluation matrix E and the first penetration test performance judgment result, the second penetration test performance judgment result, the third penetration test performance judgment result, the fourth penetration test performance judgment result, the fifth penetration test performance judgment result and the sixth penetration test performance judgment result to obtain a penetration test performance evaluation result.

8. A hierarchical penetration test effect evaluation device, characterized in that: The device comprises: An indicator construction module is used to construct a hierarchical penetration test effect evaluation indicator set according to the evaluation object; the hierarchical penetration test effect evaluation indicator set includes a penetration test performance evaluation indicator subset and a social impact effect evaluation indicator subset; The penetration test performance evaluation indicator subset includes a first penetration test performance indicator, a second penetration test performance indicator, a third penetration test performance indicator, a fourth penetration test performance indicator, a fifth penetration test performance indicator and a sixth penetration test performance indicator; The social impact effect evaluation indicator subset includes a first social impact indicator, a second social impact indicator, a third social impact indicator, a fourth social impact indicator, a fifth social impact indicator and a sixth social impact indicator; An indicator set processing module is used to process the hierarchical penetration test effect evaluation indicator set to obtain a penetration test performance evaluation result and a social impact effect evaluation result; The comprehensive evaluation module is used to integrate the penetration test performance evaluation results and the social impact effect evaluation results to obtain a hierarchical penetration test effect evaluation result.

9. A hierarchical penetration test effect evaluation device, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the hierarchical penetration testing effect evaluation method as described in any one of claims 1-7.

10. A computer storable medium, characterized in that: The computer storable medium stores computer instructions, which, when called, are used to execute the hierarchical penetration testing effect evaluation method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Water quality evaluation method and device

    CN107403188A

  • Aquaculture dissolved oxygen prediction method and device

    CN108665106A

  • Method and device for evaluating fighting capability of air defense and antimissile system

    CN108805430A

  • Method and device for dividing index area of agricultural land classification factors

    CN108985663A

  • Rail transit vehicle comprehensive evaluation method and device, electronic equipment and storage medium

    CN112183947A