Security protection efficiency evaluation method and system based on intelligent calculation data security analysis, and electronic equipment
Through the method based on intelligent computing data security analysis, the functions of network security equipment are verified, attack detection capabilities are tested, and advanced persistent threat scenarios are simulated, which solves the problem that the existing technology cannot comprehensively evaluate the dynamic capabilities of the defense system, and comprehensive evaluation and optimization of the network security defense system are achieved.
Patent Information
- Application Number
- CN202510537824.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing technology has shortcomings in comprehensively assessing the dynamic capabilities of defense systems to effectively respond to complex cybersecurity threats such as Advanced Persistent Threats (APTs) and ransomware.
The security protection efficiency evaluation method based on intelligent computing data security analysis is adopted. By verifying the basic functions of network security equipment, testing its ability to detect network attacks, and combining advanced persistent threat scenario simulation, a comprehensive security evaluation of the SIEM/SOC system is carried out, incident response and recovery time indicators are measured, and security protection efficiency evaluation results are generated.
It has achieved a comprehensive and systematic assessment of the network security defense system, improved the overall effectiveness of the network security system and its ability to deal with complex attacks, and provided a scientific basis for optimizing network security strategies.
Smart Images

Figure CN120090871A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of network security, and in particular, to a security protection effectiveness evaluation method, system, and electronic device based on intelligent computing data security analysis. Background Art
[0002] With the acceleration of digital transformation, network security threats have become increasingly complex, and traditional static evaluation methods are difficult to comprehensively reflect the dynamic protection capabilities of the defense system. Currently, network security protection faces severe challenges from new types of attacks such as advanced persistent threats (APTs) and ransomware. The above-mentioned attack methods not only have high concealment but also can lurk for a long time and gradually penetrate the target system, and traditional vulnerability scanning and compliance checking methods can no longer meet the needs of dynamic defense.
[0003] Existing technologies attempt to solve this problem through dynamic risk assessment models. For example, existing technologies have proposed a method for monitoring and repairing internal risks in a computer based on dynamic risk assessment, which can automatically identify and repair internal risks by real-time monitoring, dynamic assessment, and combining historical and real-time data. However, most of the above technical content focuses on the risk assessment of a single device or system, lacking systematic verification of the dynamic capabilities of the overall defense system.
[0004] In addition, the MITRE ATT&CK framework provides an important reference for the standardization of attack behaviors. By describing the tactics, techniques, and execution processes of attackers, the MITRE ATT&CK framework provides a common language for security personnel to analyze and respond to attacks. The ATT&CK framework has been widely applied in multiple scenarios such as red team testing, security operation maturity assessment, and threat intelligence collection. Nevertheless, there are still deficiencies in the application of the MITRE ATT&CK framework in the evaluation system, especially in the quantitative analysis of attack behaviors and defense capabilities, which still need to be further improved.
[0005] In summary, although existing technologies have made certain progress in dynamic risk assessment and attack behavior standardization, there are still deficiencies in comprehensively evaluating the dynamic capabilities of the defense system, which can no longer meet people's requirements and urgently need to be improved. Summary of the Invention
[0006] The purpose of the embodiments of the present application is to provide a security protection effectiveness evaluation method, system, and electronic device based on intelligent computing data security analysis, which can comprehensively and systematically evaluate the network security defense system by combining dynamic risk assessment and attack behavior standardization, cope with increasingly complex network security threats, and solve the deficiencies existing in the prior art.
[0007] The embodiments of the present application provide the following solutions: According to one aspect of the embodiments of the present application, a security protection effectiveness evaluation method based on intelligent computing data security analysis is provided, including: verifying whether the basic functions of network security devices are enabled normally, and during the verification process, including whether the log synchronization and alarm mechanism of network security devices are enabled normally, and the network security devices at least include firewalls, unified threat management devices, and intrusion detection and prevention systems; when the basic functions of network security devices are enabled normally, performing a mixed test of old and new attack actions on network security devices to obtain the detection ability of network security devices against network attacks; verifying the detection ability of network attacks, and based on the advanced persistent threat scenario, simulating a security assessment of the SIEM / SOC system, and the security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources; based on the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits, measuring the event response and recovery time indicators, and generating a security protection effectiveness evaluation result according to the event response and recovery time indicators.
[0008] According to at least one specific implementation manner of the embodiments of the present application, verifying whether the basic functions of network security devices are enabled normally further includes: the basic functions of the network security devices are designed based on a network security defense system, including the rule enabling status of detecting firewalls, intrusion prevention systems, and Web application firewalls; verifying whether the log synchronization and alarm mechanism of honeypots and endpoint detection and response devices can trigger an alarm when an abnormal event is detected; evaluating whether the log synchronization and alarm mechanism of honeypots and endpoint detection and response devices cover key nodes and security areas in the network.
[0009] According to at least one specific implementation manner of the embodiments of the present application, the firewall intrusion prevention system is used to detect and block malicious traffic, attack behaviors, and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network; identify malicious traffic and network attack behaviors through a signature database and an anomaly detection database, and if malicious traffic and network attack behaviors are identified, perform automatic measures to block the attacks; the Web application firewall is used to prevent network attacks against the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, and perform alarm processing on malicious requests and attack events; detect whether the log synchronization function of honeypots and endpoint detection and response devices is running normally, verify whether the corresponding log information can be synchronized to the network security centralized management platform, detect whether the synchronization trigger alarm of the log synchronization and alarm mechanism is successful, and evaluate whether honeypots and endpoint detection and response devices cover key nodes and security areas in the network.
[0010] According to at least one specific implementation manner of the embodiments of the present application, when the basic functions of the network security device are normally enabled, a mixed test of new and old attack actions is performed on the network security device to obtain the detection ability of the network security device against network attacks, which further includes: constructing a test library including a mixture of new and old attack actions, configuring the new and old attack actions in the test library, and randomly or according to a preset strategy selecting corresponding attack actions; performing a mixed attack test of new and old actions on the network security device, where the mixed attack test of new and old actions is set in an isolated test environment; setting up a simulated attacker to perform a mixed attack of new and old actions, where the mixed attack of new and old actions includes: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, cross-site scripting attack; obtaining the log data and alarm information generated during the test of the mixed attack of new and old actions, analyzing the detection data metrics of the network security device against different mixed attacks of new and old actions, and evaluating the detection ability of the corresponding network security device against network attacks.
[0011] According to at least one specific implementation manner of the embodiments of the present application, to verify the detection ability against network attacks, based on the advanced persistent threat scenario, a security assessment of the SIEM / SOC system is simulated, and the security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct a threat profile when processing log data from multiple sources, which further includes: constructing an advanced persistent threat scenario for simulating the life cycle of the real advanced persistent threat scenario, where the advanced persistent threat scenario includes data reconnaissance, initial access, and privilege escalation; obtaining log data from multiple sources in the advanced persistent threat scenario, performing normalization processing on the obtained multi-source log data, and using preset data association rules and algorithms to perform correlation analysis on the normalized multi-source log data to identify potential security events and attack behaviors in the multi-source log data; constructing a threat profile of the attacker according to the results of the correlation analysis, where the threat profile includes the attack path, attack pattern, attack tool, and attack target, and evaluating and generating the threat level of the attack under the advanced persistent threat scenario.
[0012] According to at least one specific implementation manner of the embodiments of the present application, for the ability of the SIEM / SOC system to perform correlation analysis on multi-source logs and construct threat portraits, measure the incident response and recovery time metrics, and generate a security protection effectiveness evaluation result based on the incident response and recovery time metrics, it further includes: measuring the incident response time and incident recovery time of the network security device when detecting a security incident according to the threat level of the attack in the advanced persistent threat scenario, where the incident response time is specifically the time from the occurrence of the security incident to the start of the response, and the incident recovery time is specifically the time from the occurrence of the security incident to the time when the network resumes normal operation; generating a security protection effectiveness evaluation report for the network security device according to the correlation analysis result of the multi-source log data, the threat portrait, and the incident response time and incident recovery time, and the security protection effectiveness evaluation report is used for the detection ability evaluation of security incidents, false alarm rate analysis, response time evaluation, and an overview of improvement suggestions.
[0013] According to at least one specific implementation manner of the embodiments of the present application, in the process of generating a security protection effectiveness evaluation report for the network security device, the EFFECT weighting method is used to calculate the network security effectiveness evaluation value and generate a security protection effectiveness evaluation report, and the EFFECT weighting method satisfies the following formula:
[0014] Where: β 1 、β 2 、β 3 、β 4 are the weights of the measurement factors, satisfying β 1 +β 2 +β 3 +β 4 = 1, NET is the network performance impact evaluation value, PASSET is the asset defense evaluation value, DP is the system protection ability, and Service is the business impact evaluation value.
[0015] According to another aspect of the embodiments of the present application, there is provided a security protection effectiveness evaluation system based on intelligent computing data security analysis for implementing the security protection effectiveness evaluation method based on intelligent computing data security analysis, including: a basic function verification module for network security devices to verify whether the basic functions of network security devices are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of network security devices are enabled normally. The network security devices at least include firewalls, unified threat management devices, and intrusion detection and prevention systems; an attack detection ability module for network security devices to perform a mixed test of old and new attack actions on network security devices when the basic functions of network security devices are enabled normally, and obtain the detection ability of network security devices for network attacks; a multi-source log correlation analysis and threat portrait construction module to verify the detection ability of network attacks, and simulate a security assessment of the SIEM / SOC system based on the advanced persistent threat scenario. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources; a security protection traffic assessment result generation module to measure the event response and recovery time metrics based on the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits, and generate a security protection effectiveness evaluation result according to the event response and recovery time metrics.
[0016] According to still another aspect of the embodiments of the present application, there is provided an electronic device, including: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; a computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the method.
[0017] According to other aspects of the embodiments of the present application, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, the method is implemented.
[0018] The embodiments of the present application have the following advantages compared with the prior art: The security protection effectiveness evaluation solution based on intelligent computing data security analysis proposed in the embodiments of the present application can comprehensively evaluate the SIEM / SOC system through verifying the basic functions of network security devices, testing their detection ability for network attacks, and combining the simulation of the advanced persistent threat (APT) scenario. The embodiments of the present application not only focus on the static functions of devices, but also evaluate the overall effectiveness of the network security system in the face of complex attacks through dynamic testing and multi-source log analysis. By measuring the event response and recovery time metrics, a comprehensive security protection effectiveness evaluation result is generated, providing a scientific basis for optimizing network security policies, thereby enhancing the overall effectiveness of the network security system and its ability to respond to complex attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the specific implementation manners or the description of the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0020] Figure 1 It is a flowchart of the method from step S1 to step S3 in the embodiment of the present application.
[0021] Figure 2 It is a flowchart of the method from step S11 to step S13 in the embodiment of the present application.
[0022] Figure 3 It is a flowchart of the method from step S21 to step S23 in the embodiment of the present application.
[0023] Figure 4 It is a flowchart of the method from step S31 to step S33 in the embodiment of the present application.
[0024] Figure 5 It is a flowchart of the method from step S41 to step S42 in the embodiment of the present application.
[0025] Figure 6 It is the system architecture diagram of the embodiment of the present application.
[0026] Figure 7 It is the structural schematic diagram of the electronic device. Specific implementation manners
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the specific implementation manners of the embodiments of the present application, rather than all of the specific implementation manners. Based on the specific implementation manners in the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the embodiments of the present application.
[0028] Explanation of reference numerals: 800 - device, 801 - processor, 802 - memory, 803 - communication interface, 8021 - program code, 804 - bus.
[0029] As Figure 1 shown, the embodiment of the present application provides a security protection efficiency evaluation method based on intelligent computing data security analysis, including: Step S1: Verify whether the basic functions of the network security device are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of the network security device are enabled normally. The network security device includes at least a firewall, a unified threat management device UTM, and an intrusion detection and prevention system IDS / IPS. Among them, the firewall includes a traditional firewall FW, a next-generation firewall NGFW, and a web application firewall WAF.
[0030] In step S1, the basic functions of the network device refer to the core functions and basic capabilities that the network security device must possess to ensure the security of the network environment. In the embodiments of the present application, the basic functions of the network device involve the monitoring and response capabilities of the network security device, as well as its integration and management in the security defense system, which is of great significance for implementing the embodiments of the present application. The firewall includes a traditional firewall FW, a next-generation firewall NGFW, and a web application firewall WAF. Among them, the traditional firewall is a rule-based device used to control the in and out of network traffic, usually performing access control based on IP addresses, port numbers, and protocol types. The next-generation firewall adds functions such as application identification, user identity identification, intrusion prevention IPS, and content filtering on the basis of the traditional firewall, and can control network traffic more precisely. The web application firewall WAF provides the function of protecting web applications and prevents application layer attacks such as SQL injection, cross-site scripting XSS, and webshell upload. The unified threat management device UTM integrates multiple security functions, such as a firewall, intrusion detection and prevention IDS / IPS, antivirus, anti-spam, content filtering, etc., and can provide a one-stop security solution.
[0031] Step S2: When the basic functions of the network security device are enabled normally, perform a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks. The purpose of performing the mixed test of new and old attack actions in step S2 is to detect network access control and security protection devices and examine their blocking rates against known and unknown threats.
[0032] Step S3: Verify the detection ability of network attacks, and perform a security assessment on the SIEM / SOC system based on the simulation of an advanced persistent threat scenario APT. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources.
[0033] In step S3, SIEM / SOC refers to Security Information and Event Management (SIEM) / Security Operations Center (SOC). SIEM / SOC is a core component of modern network security systems. By integrating people, processes, and technologies, SIEM / SOC provides comprehensive security monitoring, threat detection, and incident response capabilities. The SIEM system collects log data from multiple sources such as network devices, applications, and user activities, and conducts centralized management and analysis. Through real-time monitoring and analysis of log data, the SIEM system can identify abnormal behaviors and potential threats, issue alerts in a timely manner, perform correlation analysis on multi-source logs, and identify complex attack patterns. The SOC, through the SIEM system and other tools, monitors network and system activities in real time, detects potential threats, classifies, investigates, and responds to detected security incidents, reduces the impact of incidents on the business, identifies and responds to new threats, optimizes security policies and processes based on incident handling results, and enhances the overall defense capabilities. SIEM / SOC provides a comprehensive security operation framework, which can significantly enhance network security protection capabilities through real-time monitoring, threat detection, incident response, and compliance management.
[0034] Step S4: Based on the correlation analysis of multi-source logs and the ability to construct threat profiles by the SIEM / SOC system, measure the incident response and recovery time metrics, and generate a security protection effectiveness evaluation result according to the incident response and recovery time metrics.
[0035] In step S4, the incident response and recovery time metrics can be the Mean Time to Detect (MTTD) and the Mean Time to Repair (MTTR). The compliance rates of MTTD and MTTR are used as evaluation metrics for operational response effectiveness. Step S4 measures the incident response and recovery time metrics (such as MTTD and MTTR) through the correlation analysis of multi-source logs and the threat profiling ability of network security devices, and generates a security protection effectiveness evaluation result based on these metrics. Step S4 also verifies the efficiency of work order flow and the personnel response ability, uses the compliance rates of MTTD and MTTR as evaluation metrics for operational response effectiveness. Step S4 can comprehensively evaluate the detection, response, and recovery capabilities of the network security system in the face of threats, ensure the efficiency and effectiveness of security operations, optimize the security operation process, enhance the security protection effectiveness, and also enhance the utilization of threat intelligence, improve the transparency and manageability of security operations.
[0036] The technical solutions provided by steps S1 to S4 can comprehensively verify the functions of network security devices and the overall effectiveness of network security. Through systematic verification and dynamic testing, the functions of network security devices and the overall effectiveness of the network security system are comprehensively evaluated. The technical solutions provided by steps S1 to S4 not only focus on the static functions of devices, but also evaluate the dynamic protection capabilities of the network security system in the face of complex attacks through APT scenario simulation and multi-source log analysis. By quantifying the event response and recovery time metrics, detailed security protection effectiveness evaluation results are generated, providing a scientific basis for optimizing network security policies and significantly enhancing the network security protection capabilities of network security devices.
[0037] As Figure 2 shown, in step S1, it is verified whether the basic functions of the network security device are enabled normally, which further includes: Step S11, the basic functions of the network security device are designed based on the network security defense system, including the rule enabling status of the detection firewall intrusion prevention system IPS and the Web application firewall WAF; Step S12, verify whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response EDR device can trigger an alarm when an abnormal event is detected; Step S13, evaluate whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response EDR device cover the key nodes and security areas in the network.
[0038] In step S13, a key node refers to a device, system, or location in the network that has important functions or stores key data. Key nodes are usually the core parts of network operation and are crucial for business continuity and data security. If a key node is attacked or fails, it may lead to serious business interruptions or data leaks. A security area refers to different areas in the network divided according to security requirements and functions. Each security area has clear security policies and access control rules to isolate different security-level network parts and prevent attacks from spreading from one area to another. By evaluating whether the log synchronization and alarm mechanism of the honeypot and the EDR device cover the key nodes and security areas in the network, step S13 can timely discover potential threats, reduce the impact of network attacks on the business, optimize security policies and access control rules according to the monitoring results of network optimization security policies, conduct unified analysis of logs through a centralized management platform, reduce manual intervention, improve security operation efficiency, ensure that key nodes and security areas are effectively monitored, and reduce the risk of network being attacked.
[0039] The optimized technical solutions provided by steps S11 to S13 ensure the normal operation of the basic functions of network security devices by verifying the rule enabling status of IPS and WAF, execute their basic design functions, and ensure the reliability of the basic functions of the network security defense system. By verifying the log synchronization and alarm mechanisms of honeypot and EDR devices, it is ensured that alarms can be triggered in a timely manner when abnormal events are detected, enhancing the detection and response capabilities for abnormal events, quickly discovering potential threats, reducing the impact of attacks on the network environment, and improving the overall response speed. By evaluating whether the log synchronization and alarm mechanisms of honeypot and EDR devices cover key nodes and security areas, it is ensured that there are no blind spots in network security monitoring, optimizing the coverage of security monitoring, ensuring the overall security of the network environment, ensuring that the basic functions of network security devices match the overall defense system design, and realizing the collaborative work between devices on the basis of verifying and ensuring the independent functions of network security devices, improving the reliability of the entire network security defense system, and providing basic data for subsequent security assessments.
[0040] Exemplarily, a firewall intrusion prevention system (IPS) is used to detect and block malicious traffic, attack behaviors, and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network. Attack patterns include known attack patterns and unknown attack patterns. Known attack patterns refer to attack behaviors and patterns that have been identified and recorded by security researchers. Known attack patterns usually have clear characteristics and can be detected through a signature database. The IPS can use a preset signature rule library to identify known attack patterns. The signature rule library is a collection of known attack characteristics. By matching the packet characteristics in network traffic, the IPS can quickly identify and block network attacks, such as DDoS attacks, SQL injection attacks, cross-site scripting attacks (XSS), and so on. Unknown attack patterns refer to attack behaviors and patterns that have not been identified or recorded. Unknown attack patterns usually have a high degree of concealment and innovation and are difficult to detect through traditional signature matching methods. For example, zero-day attacks, which use vulnerabilities that have not been made public for attacks; advanced persistent threats (APT), which gradually penetrate the target system through a multi-stage attack path; fileless attacks, which use malicious code in memory to execute attacks and do not rely on the file system.
[0041] The optimized technical solutions provided by steps S11 to S13 can identify malicious traffic and network attack behaviors through a signature database and an anomaly detection database. The anomaly detection database is a system for storing and managing data related to anomaly detection. The core function of the anomaly detection database is to help identify and analyze data patterns that do not conform to expected behaviors, so as to detect anomaly events through artificial intelligence technologies such as machine learning and statistical analysis. If malicious traffic and network attack behaviors are identified, automatic measures are taken to block the attacks. The automatic measures to block the attacks can include: discarding malicious data packets, blocking connections, or reconfiguring firewall rules, recording the detected threats and attack behaviors, providing data support for subsequent data analysis. IPS is mainly applied to network boundary protection to prevent external attacks from entering the internal network.
[0042] The Web Application Firewall (WAF) is used to prevent network attacks against the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, perform alarm processing on malicious requests and attack events, and detect whether the log synchronization function of the honeypot and the Endpoint Detection and Response (EDR) device is running normally, and verify whether the corresponding log information can be synchronized to the network security centralized management platform to ensure the integrity of the network security protection system.
[0043] The protection function of the Web Application Firewall (WAF) and the log synchronization function of the honeypot and EDR device build a complete network security protection system. The Web Application Firewall (WAF) can effectively prevent attacks against Web applications, while the log synchronization function ensures the integrity and coordination ability of the security protection system, not only enhancing the security of Web applications, but also improving the overall efficiency of the security protection system, optimizing the security operation efficiency, and providing network security guarantee for the security and stability of the network environment.
[0044] As Figure 3 shown, in step S2, when the basic functions of the network security device are enabled normally, a mixed test of new and old attack actions is performed on the network security device to obtain the detection ability of the network security device against network attacks, which further includes: Step S21, construct a test library including a mixture of new and old attack actions, configure the new and old attack actions in the test library, and randomly or according to a preset strategy select the corresponding attack actions.
[0045] Step S22, perform a mixed attack test of new and old actions in the network security device. The mixed attack test of new and old actions is set in an isolated test environment.
[0046] Step S23: Set up a simulated attacker to perform a mixed attack of old and new actions. The mixed attack of old and new actions includes: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, and cross-site scripting attack.
[0047] Step S24: Obtain the log data and warning information generated during the test of the mixed attack of old and new actions, analyze the detection data metrics of different mixed attacks of old and new actions by the network security device, and evaluate the detection ability of the corresponding network security device against network attacks. Among them, the detection data metrics include: detection rate, false alarm rate, and response time.
[0048] The optimization technical solution provided in Steps S21 to S24 comprehensively evaluates the detection ability of network security devices against network attacks when the basic functions are enabled normally by constructing a test library, conducting mixed attack tests in an isolated environment, and analyzing detection data metrics. It can provide detailed evaluation results to assist in optimizing security policies and device configurations, can adjust device rules specifically to enhance the overall protection ability. Conducting attack tests in an isolated test environment (such as a sandbox) can ensure the security of the test process and avoid affecting the production environment. It can not only identify the potential weaknesses of the device when facing complex attacks, but also provide a scientific basis for optimizing security policies and improving security operation efficiency, significantly enhancing the overall effectiveness of the network security protection system. The evaluation results can assist in decision-making and make reasonable decisions during device selection and network security policy adjustment to ensure the overall effectiveness of the network security protection system.
[0049] As Figure 4 shown, in Step S3, verify the detection ability against network attacks, and conduct a security assessment of the SIEM / SOC system based on the simulation of the advanced persistent threat scenario APT. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct a threat profile when processing log data from multiple sources, and further includes: Step S31: Construct an advanced persistent threat scenario to simulate the life cycle of the real advanced persistent threat scenario, which includes data reconnaissance, initial access, and privilege escalation; Step S32: Obtain log data from multiple sources in the advanced persistent threat scenario, perform normalization processing on the obtained multi-source log data, and use preset data correlation rules and algorithms to perform correlation analysis on the normalized multi-source log data to identify potential security events and attack behaviors in the multi-source log data; Step S33: Construct a threat profile of the attacker based on the results of the correlation analysis. The threat profile includes the attack path, attack pattern, attack tool, and attack target, and evaluate and generate the threat level of the attack under the advanced persistent threat scenario.
[0050] The optimization technical solutions provided by steps S31 to S33 can construct APT scenarios, perform multi-source log correlation analysis, and construct threat portraits, which can more accurately evaluate the detection capabilities of SIEM / SOC systems in the face of complex attacks. The correlation analysis of multi-source logs helps identify attack behaviors across devices and systems, reduce false alarms, and improve detection accuracy, providing a comprehensive perspective for the security assessment of SIEM / SOC systems, ensuring that the systems can cope with complex APT attacks, enhancing the accuracy of APT detection, and also enhancing the utilization efficiency of processing network threat intelligence by constructing threat portraits, optimizing the security operation process, and providing a comprehensive basis for network security assessment and optimization.
[0051] As Figure 5 shown, in step S4, based on the correlation analysis of multi-source logs and the ability to construct threat portraits of the SIEM / SOC system, measure the event response and recovery time metrics, and generate a security protection effectiveness evaluation result according to the event response and recovery time metrics, further including: Step S41, according to the threat level of attacks in the advanced persistent threat scenario, measure the mean time to respond (MTTR) and mean time to detect (MTTD) of network security devices when detecting security events. The event response time is specifically the time from the occurrence of a security event to the start of response, and the event recovery time is specifically the time from the occurrence of a security event to the network returning to normal operation; Step S42, generate a security protection effectiveness evaluation report for network security devices according to the correlation analysis results of multi-source log data, threat portraits, event response time, and event recovery time. The security protection effectiveness evaluation report is used for the detection capability evaluation, false alarm rate analysis, response time evaluation, and summary of improvement suggestions of security events.
[0052] Exemplarily, in the process of generating the security protection effectiveness evaluation report for network security devices, the EFFECT weighting method is used to calculate the network security effectiveness evaluation value and generate the security protection effectiveness evaluation report. The EFFECT weighting method satisfies the following formula:
[0053] where: β 1 、β 2 、β 3 、β 4 are the weights of the measurement factors, satisfying β 1 +β 2 +β 3 +β 4 =1, NET is the network performance impact evaluation value (average value), PASSET is the asset defense evaluation value (average value), DP is the system protection ability, and Service is the business impact evaluation value.
[0054] The optimization technical solution provided by steps S41 to S42 comprehensively evaluates the security protection effectiveness of network security devices through the correlation analysis of multi-source logs and the construction of threat portraits, combines event response and recovery time metrics, conducts a quantitative analysis of the network security protection effectiveness, optimizes the network security policy and resource allocation policy, increases the utilization efficiency of network security threat intelligence, improves the security operation effect, and provides a comprehensive perspective for the security assessment of network security devices by combining APT scenario simulation and multi-source log analysis, ensuring that the system can cope with complex APT attacks. The optimization technical solution provided by steps S41 to S42 not only quantifies the detection and response capabilities of the device, but also provides a basis for optimizing security policies and resource allocation, significantly improving the overall effectiveness of the network security protection system. In the EFFECT formula, through quantitative evaluation, key problems can be quickly identified, the time for manual troubleshooting and analysis can be reduced, and the security operation efficiency can be improved. Through clear weight assignment and quantitative indicators, the evaluation process of network security effectiveness becomes more transparent and manageable. By comprehensively evaluating multiple key indicators, the overall effectiveness of evaluating network security devices or systems is quantified, significantly improving the transparency, manageability, and overall response capabilities of the network security system.
[0055] For the method steps disclosed in the above embodiments, for the purpose of simple description, the method steps are expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present application are not limited by the described action sequence, because according to the embodiments of the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present application.
[0056] Any process or method description presented in a flowchart or otherwise can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred implementation of the embodiments of the present application includes additional implementations, where the functions can be executed and implemented in a substantially simultaneous manner or in the reverse order according to the functions involved, without following the order shown or discussed, or by executing computer instructions according to program structures such as loops and branches to implement the corresponding functions. This is naturally understandable to those skilled in the art when implementing the embodiments of the present application.
[0057] As Figure 6 shown, the embodiments of the present application also provide a security protection effectiveness evaluation system based on intelligent computing data security analysis for implementing the security protection effectiveness evaluation method based on intelligent computing data security analysis described in any specific implementation manner in the specification of the present application, including: The basic function verification module of the network security device verifies whether the basic functions of the network security device are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of the network security device are enabled normally. The network security device at least includes a firewall, a unified threat management device, and an intrusion detection and prevention system; The attack detection ability module of the network security device, when the basic functions of the network security device are enabled normally, conducts a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks; The multi-source log correlation analysis and threat portrait construction module verifies the detection ability of network attacks. Based on the advanced persistent threat scenario, it simulates a security assessment of the SIEM / SOC system. The security assessment includes the correlation analysis of multi-source logs and the ability to construct threat portraits when the SIEM / SOC system processes log data from multiple sources; The security protection traffic assessment result generation module measures the event response and recovery time indicators based on the correlation analysis of multi-source logs and the ability to construct threat portraits of the SIEM / SOC system, and generates a security protection effectiveness assessment result according to the event response and recovery time indicators.
[0058] The implementation manners of the system described above are only illustrative. For example: Each functional module, unit, or subsystem in the system can be physically separated or not, or can be a physical unit or not, that is, it can be located in the same place or distributed to multiple different systems and their subsystems or modules. Those skilled in the art can select some or all of the functional modules, units, or subsystems according to actual needs to achieve the purpose of the embodiments of the present application. For the above situations, those of ordinary skill in the art can understand and implement them without creative labor.
[0059] The following starts from the perspectives of verifying the operation mechanism and algorithm model design, and evaluates the specific implementation manners disclosed in the embodiments of the present application from the perspectives of evaluation dimensions and weights, score calculation and model comparison, algorithm optimization and innovation points, and model limitations: When verifying the operation mechanism of each specific implementation manner of the embodiments of the present application, a periodic task and a dynamic trigger mechanism are established for verification, including: Periodic tasks: daily basic verification (phase one), weekly ability re-evaluation (phase two), monthly association rule optimization (phase three), quarterly response process test (phase four).
[0060] Dynamic trigger mechanism: Instant verification is performed for vulnerability scan results or policy changes to ensure the timeliness of evaluation.
[0061] Evaluation dimensions and weights: The model includes five core dimensions (Table 1) and realizes multi-dimensional quantitative evaluation through a dynamic weight mechanism
[0062] Score calculation and model comparison: Score calculation method, basic score calculation: 1. Each boundary verification score = (number of passed verification items / total number of verification items) Boundary weight Basic assigned score.
[0063] Total functional verification score = Σ(boundary verification scores) / Σ(boundary weights) Basic score assignment.
[0064] Coverage score = (number of covered boundaries / total number of boundaries to be covered) Coverage score assignment.
[0065] 2. Protection ability calculation: Single protection ability score = basic score Σ(pass rate of boundary verification boundary weight) / Σ(boundary weights).
[0066] 3. Business protection calculation: Business protection score = Σ(verification item scores business importance weight) / total number of businesses.
[0067] 4. Scenario verification calculation: Effectiveness score = (accuracy of correlation analysis score assignment + multi-source data analysis score score assignment + scenario recognition score score assignment).
[0068] 5. Operation response calculation: MTTD effectiveness = Σ(attainment rates of each level score assignment).
[0069] MTTR effectiveness = Σ(attainment rates of each level score assignment).
[0070] 6. Free verification calculation: Verification action score = basic score threat level weight boundary weight verification result weight.
[0071] 7. Aggregation of Multiple Identical Verification Results: If the overall evaluation occurs over a period of time, there will definitely be multiple executions of the same verification. Therefore, it is necessary to aggregate the multiple results: take the most recent N verification results (N = 5).
[0072] Apply time-decaying weights; Time-decaying weight formula: Time decay weight = e^(-λ(current_time - test_time)) Suggested value of λ: 0.1 Remove the highest and lowest scores; Weighted score = Σ(single score time weight) / Σ(time weight).
[0073] 8. Synthesis of Total Score: Final score = (basic score + protection ability score + business protection verification score + scenario verification bonus + operation response score + free verification) (1 + weighted by boundary coverage rate) verification pass rate.
[0074] Comparison and Analysis with Existing Models: To verify the multidimensionality and accuracy of this model, three types of typical models are selected for comparative experiments (Table 2):
[0075] Comparison of experimental data (Table 3):
[0076] Conclusion: It can be seen from Tables 1 to 3 that the technical solution provided by the embodiments of this application has multidimensionality and accuracy. This model covers device functions, protection capabilities, business protection, scenario verification, and response processes through five dimensions, which is more comprehensive than the static model (2 types) and the attack graph model (3 types). Both the ATT&CK coverage rate (88%) and the MTTR (4.2 hours) are better than the comparative models, and the false alarm rate (5.1%) is lower than that of the attack graph model (12.3%).
[0077] Algorithm Optimization and Innovation Points: 1. Dynamic weight matrix: Define the priority of the attack path between security regions (such as Internet → core area weight 1.5), which conforms to the high risk of external threats in actual attack and defense.
[0078] 2. Hierarchical scoring mechanism: Adopt the structure of "basic score + scenario bonus + operation score" to avoid deviation in a single dimension. For example, although an enterprise fails to meet the MTTR standard (operation score 180 / 250), its technical advantages can still be reflected by a high protection ability score (270 / 300).
[0079] 3. Adversarial verification design: In the second stage, mix new and old attack actions (ratio 7:3) to improve the adaptability to 0day attacks (detection rate 78%, higher than 52% of the machine learning model).
[0080] In some embodiments, the algorithm model provided by the embodiments of the present application can be further extended and improved. For example, in view of the limitations of the algorithm model such as strong data dependence, high demand for manual intervention, and high computational complexity, automated and intelligent means are adopted to continuously integrate the latest network security threat intelligence into the attack library, avoid subjective errors that may be introduced due to the dependence of the response process verification on manual participation, and use platform tools to support the efficient calculation of the weight matrix and attenuation factor.
[0081] Experiments and results: Single-case in-depth verification, taking a financial enterprise as the test object: Stage 1: EDR privilege operation detection is not enabled, deduct 30 points from the basic score; Stage 2: The blocking rate of the WAF for new injection attacks is 65%, and the protection ability score is 52 / 80; Stage 4: MTTR (high-risk event) is 6 hours, and the response score is 45 / 65; Total score: 872 (Grade B), indicating that the response process and terminal protection need to be optimized.
[0082] Multi-industry comparison experiment, extended to finance, healthcare, and manufacturing industries to verify the model generalization ability:
[0083] It can be seen from the above specific implementation manners that the security protection effectiveness evaluation method and the corresponding evaluation model proposed by the embodiments of the present application effectively improve the comprehensiveness and accuracy of security verification through dynamic weights and multi-dimensional quantitative analysis. Future work will explore AI-driven automated attack simulation and optimize the time decay factor parameters. At the same time, the applicability of the model in the cloud-native environment can be further verified to increase the implementation effect of the embodiments of the present application in different application scenarios.
[0084] As Figure 7 shown, on the basis of providing the security protection effectiveness evaluation method and system based on intelligent computing data security analysis, the embodiments of the present application also provide corresponding electronic devices and computer program products: An electronic device, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus; a computer program is stored in the memory, and when the computer program is executed by the processor, the processor is caused to execute the steps of a security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0085] A computer program product, comprising a computer program, which when executed by a processor implements a security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0086] Figure 7 This is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 7 shown, the device 800 includes a processor 801, a memory 802, a communication interface 803, and a bus 804. Among them, the processor 801, the memory 802, and the communication interface 803 communicate through the bus 804, and can also achieve communication through other means such as wireless transmission. The memory 802 is used to store instructions, and the processor 801 is used to execute the instructions stored in the memory 802. The memory 802 stores program code 8021, and the processor 801 can call the program code 8021 stored in the memory 802 to execute the steps of a security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0087] It should be understood that in the embodiment of the present application, the processor 801 may be a CPU, and the processor 801 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0088] The memory 802 may include a read-only memory (ROM) and a random access memory (RAM), and provide instructions and data to the processor 801. The memory 802 may also include a non-volatile random access memory. The memory 802 may be a volatile memory, a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0089] In addition to the data bus, the bus 804 may also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity, all kinds of buses are labeled as the bus 804 in the figure.
[0090] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid state drive (SSD).
[0091] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered that the scope described in the specification of the embodiments of the present application is covered.
[0092] In the description of the specification of the embodiments of the present application, the descriptions with reference to the terms "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one specific implementation manner of the embodiments of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0093] In addition, the technical solutions between the various embodiments of the present application can be combined with each other, but it must be based on the fact that those skilled in the art can implement them. When the combination of the technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the embodiments of the present application.
[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present application, rather than limiting them. Although the embodiments of the present application have been described in detail with reference to the foregoing specific embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements on some or all of the technical features, and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the specific embodiments of the present application.
Claims
1. A security protection effectiveness evaluation method based on intelligent data security analysis, characterized in that: include: Verify whether the basic functions of the network security equipment are enabled normally, including whether the log synchronization and alarm mechanism of the network security equipment are enabled normally during the verification process. The network security equipment includes at least a firewall, a unified threat management device, and an intrusion detection and prevention system; When the basic functions of the network security device are enabled normally, a mixed test of new and old attack actions is conducted on the network security device to obtain the network security device's ability to detect network attacks; Verify the ability to detect network attacks and simulate security assessments of SIEM / SOC systems based on advanced persistent threat scenarios. The security assessments include the ability to correlate and analyze logs from multiple sources and build threat profiles when SIEM / SOC systems process log data from multiple sources. Based on the SIEM / SOC system's correlation analysis of multi-source logs and the ability to build threat portraits, the incident response and recovery time indicators are measured, and security protection effectiveness evaluation results are generated based on the incident response and recovery time indicators.
2. The security protection effectiveness evaluation method based on intelligent data security analysis according to claim 1 is characterized in that: The verifying whether the basic functions of the network security device are enabled normally further includes: The basic functions of the network security equipment are designed based on the network security defense system, including detecting the rule activation status of the firewall intrusion prevention system and the Web application firewall; Verify that the log synchronization and alerting mechanisms of the honeypot and endpoint detection and response device can trigger alerts when abnormal events are detected; Evaluate whether the log synchronization and alarm mechanisms of honeypots and endpoint detection and response devices cover key nodes and security areas in the network.
3. The security protection effectiveness evaluation method based on intelligent data security analysis according to claim 2 is characterized in that: The firewall intrusion prevention system is used to detect and block malicious traffic, attack behaviors and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network; Identify malicious traffic and network attack behaviors through signature databases and anomaly detection databases. If malicious traffic and network attack behaviors are identified, automatic measures are taken to prevent the attack. The Web application firewall is used to prevent network attacks targeting the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, and perform alarm processing on malicious requests and attack events; Check whether the log synchronization function of the honeypot and endpoint detection and response equipment is operating normally, verify whether the corresponding log information can be synchronized to the network security centralized management platform, check whether the synchronization of log synchronization and alarm mechanism triggers the alarm successfully, and evaluate whether the honeypot and endpoint detection and response equipment cover the key nodes and security areas in the network.
4. The security protection effectiveness evaluation method based on intelligent data security analysis according to claim 1 is characterized in that: When the basic functions of the network security device are normally enabled, performing a mixed test of new and old attack actions on the network security device to obtain the network attack detection capability of the network security device further includes: Constructing a test library including a mixture of new and old attack actions, configuring the new and old attack actions in the test library, and selecting corresponding attack actions randomly or according to a preset strategy; Performing a new and old action mixed attack test in a network security device, wherein the new and old action mixed attack test is set in an isolated test environment; Set up simulated attackers to conduct mixed attacks of new and old actions, including: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, and cross-site scripting attacks; The log data and alarm information generated during the test of the new and old action mixed attack are obtained, the detection data indicators of the network security equipment for different new and old action mixed attacks are analyzed, and the detection capability of the corresponding network security equipment for network attacks is evaluated.
5. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 1 is characterized in that: The network attack detection capability is verified by simulating a security assessment of the SIEM / SOC system based on an advanced persistent threat scenario. The security assessment includes the SIEM / SOC system's ability to correlate and analyze multi-source logs and build threat profiles when processing log data from multiple sources, and further includes: Constructing an advanced persistent threat scenario to simulate the life cycle of a real advanced persistent threat scenario, including data reconnaissance, initial access, and privilege escalation; In the advanced persistent threat scenario, log data is obtained from multiple sources, the obtained multi-source log data is normalized, and the normalized multi-source log data is subjected to association analysis using preset data association rules and algorithms to identify potential security events and attack behaviors in the multi-source log data; A threat profile of the attacker is constructed based on the results of the correlation analysis. The threat profile includes attack paths, attack modes, attack tools, and attack targets, and the threat level of the attack in an advanced persistent threat scenario is evaluated and generated.
6. The security protection effectiveness evaluation method based on intelligent data security analysis according to claim 1 is characterized in that: The SIEM / SOC system-based correlation analysis of multi-source logs and the ability to build threat profiles, measuring incident response and recovery time indicators, and generating security protection effectiveness evaluation results based on the incident response and recovery time indicators further include: According to the threat level of the attack in the advanced persistent threat scenario, measure the event response time and event recovery time of the network security device when a security incident is detected. The event response time is specifically the time from the occurrence of the security incident to the start of the response, and the event recovery time is specifically the time from the occurrence of the security incident to the restoration of normal network operation; A security protection effectiveness evaluation report of network security equipment is generated based on the correlation analysis results of multi-source log data, threat portraits, event response time and event recovery time. The security protection effectiveness evaluation report is used for detection capability evaluation, false alarm rate analysis, response time evaluation and improvement suggestion summary of security incidents.
7. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 6 is characterized in that: In the process of generating the security protection effectiveness evaluation report of the network security equipment, the EFFECT weighted method is used to calculate the network security effectiveness evaluation value and generate the security protection effectiveness evaluation report. The EFFECT weighted method satisfies the following formula: Among them: β1, β2, β3, β4 are the weights of the measurement factors, satisfying β1+β2+β3+β4=1, NET is the network performance impact evaluation value, PASSET is the asset defense evaluation value, DP is the system protection capability, and Service is the business impact evaluation value.
8. A security protection effectiveness evaluation system based on intelligent computing data security analysis, used to implement the security protection effectiveness evaluation method based on intelligent computing data security analysis according to any one of claims 1 to 7, characterized in that: include: A network security device basic function verification module verifies whether the basic functions of the network security device are normally enabled, including whether the log synchronization and alarm mechanism of the network security device are normally enabled. The network security device includes at least a firewall, a unified threat management device, and an intrusion detection and prevention system; The network security device attack detection capability module performs a mixed test of new and old attack actions on the network security device when the basic functions of the network security device are normally enabled, and obtains the network security device's detection capability against network attacks; Multi-source log correlation analysis and threat profile building module verifies the ability to detect network attacks and simulates security assessment of SIEM / SOC systems based on advanced persistent threat scenarios. The security assessment includes the ability to correlate and analyze multi-source logs and build threat profiles when the SIEM / SOC system processes log data from multiple sources. The security protection traffic assessment result generation module measures the incident response and recovery time indicators based on the SIEM / SOC system's correlation analysis of multi-source logs and the ability to build threat portraits, and generates security protection effectiveness assessment results based on the incident response and recovery time indicators.
9. An electronic device, characterized in that: include: A processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the steps of the method described in any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Network attack data analysis and intelligent processing method
CN107277039A
Intelligent networked automobile network security assessment method
CN118074970A
Security verification case generation method and device based on multiple scenes
CN118138309A
Cross-regional group company network security management method and system
CN118214605A
Network security situation awareness and active defense system
CN119854011A
Cited By
Information security model auxiliary decision-making method and system based on intelligent knowledge graph
CN120934889A
Data access security intelligent management method based on network intrusion detection
CN121012668A