A Security Protection Efficiency Evaluation Method, System, and Electronic Device Based on Intelligent Computing Data Security Analysis
Through intelligent computing data security analysis methods, the basic functions of network security equipment and the detection ability of complex attacks are verified. Combined with advanced continuous threat scenario simulation, comprehensive security protection efficiency evaluation results are generated, which solves the problem of insufficient dynamic capabilities of the network security defense system in the existing technology, and improves the overall effectiveness of the network security system and its ability to deal with complex attacks.
Patent Information
- Application Number
- CN202510537824.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing technology has shortcomings in evaluating the dynamic capabilities of cybersecurity defense systems, especially in the face of advanced persistent threats (APTs) and complex attacks. Traditional vulnerability scanning and compliance inspections cannot meet the dynamic defense needs.
Through the method based on intelligent computing data security analysis, the basic functions of network security equipment are verified, mixed tests of new and old attack actions are carried out, and security assessments are conducted for SIEM/SOC systems are combined with advanced persistent threat scenario simulations, incident response and recovery time indicators are measured, security protection effectiveness evaluation results are generated, and comprehensive evaluation is carried out using EFFECT weighting method.
It has achieved a comprehensive assessment of network security equipment and defense systems, improved its ability to respond to complex attacks, optimized security strategies, and improved the overall efficiency and emergency response efficiency of the network security system.
Smart Images

Figure CN120090871B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of network security, and in particular, to a security protection effectiveness evaluation method, system, and electronic device based on intelligent computing data security analysis. Background Art
[0002] With the acceleration of digital transformation, network security threats have become increasingly complex, and traditional static evaluation methods are difficult to comprehensively reflect the dynamic protection capabilities of the defense system. Currently, network security protection faces severe challenges from new types of attacks such as advanced persistent threats (APTs) and ransomware. The above attack methods are not only highly concealed but also can lurk for a long time and gradually penetrate the target system, and traditional vulnerability scanning and compliance checking methods can no longer meet the needs of dynamic defense.
[0003] Existing technologies have attempted to solve this problem through dynamic risk assessment models. For example, existing technologies have proposed a method for monitoring and repairing internal risks in a computer based on dynamic risk assessment, which can automatically identify and repair internal risks through real-time monitoring, dynamic assessment, and combination of historical and real-time data. However, most of the above technical content focuses on the risk assessment of individual devices or systems and lacks systematic verification of the dynamic capabilities of the overall defense system.
[0004] In addition, the MITRE ATT&CK framework provides an important reference for the standardization of attack behaviors. By describing the tactics, techniques, and execution processes of attackers, the MITRE ATT&CK framework provides security personnel with a common language for analyzing and dealing with attacks. The ATT&CK framework has been widely applied in multiple scenarios such as red team testing, security operation maturity assessment, and threat intelligence collection. Nevertheless, there are still deficiencies in the application of the MITRE ATT&CK framework in the evaluation system, especially in the quantitative analysis of attack behaviors and defense capabilities, which still need to be further improved.
[0005] In summary, although existing technologies have made certain progress in dynamic risk assessment and attack behavior standardization, there are still deficiencies in comprehensively evaluating the dynamic capabilities of the defense system, and they can no longer meet people's requirements and urgently need to be improved. Summary of the Invention
[0006] The purpose of the embodiments of the present application is to provide a security protection effectiveness evaluation method, system, and electronic device based on intelligent computing data security analysis, which can comprehensively and systematically evaluate the network security defense system by combining dynamic risk assessment and attack behavior standardization, cope with increasingly complex network security threats, and solve the deficiencies existing in the prior art.
[0007] The embodiments of the present application provide the following solutions:
[0008] According to one aspect of the embodiments of the present application, a security protection effectiveness evaluation method based on intelligent computing data security analysis is provided, including: verifying whether the basic functions of network security devices are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of network security devices are enabled normally. The network security devices at least include firewalls, unified threat management devices, and intrusion detection and prevention systems; when the basic functions of network security devices are enabled normally, perform a mixed test of old and new attack actions on the network security devices to obtain the detection ability of the network security devices against network attacks; verify the detection ability of network attacks, and based on the advanced persistent threat scenario, simulate a security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and build threat portraits when processing log data from multiple sources; based on the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and build threat portraits, measure the event response and recovery time metrics, and generate a security protection effectiveness evaluation result according to the event response and recovery time metrics.
[0009] According to at least one specific implementation manner of the embodiments of the present application, verifying whether the basic functions of network security devices are enabled normally further includes: The basic functions of the network security devices are designed based on the network security defense system, including the rule enabling status of the intrusion prevention system of the firewall and the Web application firewall; verifying whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response device can trigger an alarm when an abnormal event is detected; evaluating whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response device cover the key nodes and security areas in the network.
[0010] According to at least one specific implementation manner of the embodiments of the present application, the firewall intrusion prevention system is used to detect and block malicious traffic, attack behaviors, and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network; identify malicious traffic and network attack behaviors through the signature database and the anomaly detection database. If malicious traffic and network attack behaviors are identified, automatic measures are taken to block the attacks; the Web application firewall is used to prevent network attacks against the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, and perform alarm processing on malicious requests and attack events; detect whether the log synchronization function of the honeypot and the endpoint detection and response device is running normally, verify whether the corresponding log information can be synchronized to the network security centralized management platform, detect whether the synchronization trigger alarm of the log synchronization and alarm mechanism is successful, and evaluate whether the honeypot and the endpoint detection and response device cover the key nodes and security areas in the network.
[0011] According to at least one specific implementation manner of the embodiments of the present application, when the basic functions of the network security device are normally enabled, performing a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks further includes: constructing a test library including a mixture of new and old attack actions, configuring the new and old attack actions in the test library, and randomly or according to a preset strategy selecting corresponding attack actions; performing a mixed attack test of new and old actions on the network security device, where the mixed attack test of new and old actions is set in an isolated test environment; setting up a simulated attacker to perform a mixed attack of new and old actions, where the mixed attack of new and old actions includes: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, cross-site scripting attack; obtaining the log data and alarm information generated during the test process of the mixed attack of new and old actions, analyzing the detection data metrics of the network security device against different mixed attacks of new and old actions, and evaluating the detection ability of the corresponding network security device against network attacks.
[0012] According to at least one specific implementation manner of the embodiments of the present application, verifying the detection ability against network attacks, based on an advanced persistent threat scenario, simulating a security assessment of the SIEM / SOC system, where the security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct a threat profile when processing log data from multiple sources, and further includes: constructing an advanced persistent threat scenario for simulating the life cycle of the real advanced persistent threat scenario, where the advanced persistent threat scenario includes data reconnaissance, initial access, and privilege escalation; obtaining log data from multiple sources in the advanced persistent threat scenario, performing normalization processing on the obtained multi-source log data, and using preset data association rules and algorithms to perform correlation analysis on the normalized multi-source log data to identify potential security events and attack behaviors in the multi-source log data; constructing a threat profile of the attacker according to the results of the correlation analysis, where the threat profile includes the attack path, attack pattern, attack tool, and attack target, and evaluating and generating the threat level of the attack under the advanced persistent threat scenario.
[0013] According to at least one specific implementation manner of the embodiments of the present application, the ability to perform correlation analysis on multi-source logs and construct threat portraits based on the SIEM / SOC system, measure the event response and recovery time metrics, and generate a security protection effectiveness evaluation result based on the event response and recovery time metrics further includes: measuring the event response time and event recovery time of the network security device when detecting a security event according to the threat level of the attack in the advanced persistent threat scenario, where the event response time is specifically the time from the occurrence of the security event to the start of the response, and the event recovery time is specifically the time from the occurrence of the security event to the network returning to normal operation; generating a security protection effectiveness evaluation report for the network security device according to the correlation analysis result of the multi-source log data, the threat portrait, and the event response time and event recovery time, and the security protection effectiveness evaluation report is used for the detection ability evaluation, false alarm rate analysis, response time evaluation, and improvement suggestion summary of security events.
[0014] According to at least one specific implementation manner of the embodiments of the present application, in the process of generating the security protection effectiveness evaluation report for the network security device, the EFFECT weighting method is used to calculate the network security effectiveness evaluation value and generate the security protection effectiveness evaluation report, and the EFFECT weighting method satisfies the following formula:
[0015]
[0016] where: β1, β2, β3, β4 are the weights of the measurement factors, satisfying β1 + β2 + β3 + β4 = 1, NET is the network performance impact evaluation value, PASSET is the asset defense evaluation value, DP is the system protection ability, and Service is the business impact evaluation value.
[0017] According to another aspect of the embodiments of the present application, a security protection effectiveness evaluation system based on intelligent computing data security analysis is provided, which is used to implement the security protection effectiveness evaluation method based on intelligent computing data security analysis, and includes: a basic function verification module for network security devices, which verifies whether the basic functions of network security devices are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of network security devices are enabled normally. The network security devices at least include firewalls, unified threat management devices, and intrusion detection and prevention systems; a network security device attack detection ability module, which performs a mixed test of old and new attack actions on network security devices when the basic functions of network security devices are enabled normally, and obtains the detection ability of network security devices against network attacks; a multi-source log correlation analysis and threat portrait construction module, which verifies the detection ability of network security attacks, and based on the advanced persistent threat scenario, simulates a security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources; a security protection traffic assessment result generation module, which measures the event response and recovery time metrics based on the correlation analysis of multi-source logs and the ability of the SIEM / SOC system to construct threat portraits, and generates a security protection effectiveness evaluation result according to the event response and recovery time metrics.
[0018] According to still another aspect of the embodiments of the present application, an electronic device is provided, including: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; a computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the method.
[0019] According to other aspects of the embodiments of the present application, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the method is implemented.
[0020] The embodiments of the present application have the following advantages compared with the prior art:
[0021] The security protection effectiveness evaluation solution based on intelligent computing data security analysis proposed in the embodiments of the present application can comprehensively evaluate the SIEM / SOC system through verifying the basic functions of network security devices, testing their detection ability against network attacks, and combining the simulation of the advanced persistent threat (APT) scenario. The embodiments of the present application not only focus on the static functions of devices, but also evaluate the overall effectiveness of the network security system in the face of complex attacks through dynamic testing and multi-source log analysis. By measuring the event response and recovery time metrics, a comprehensive security protection effectiveness evaluation result is generated, providing a scientific basis for optimizing network security policies, thereby improving the overall effectiveness of the network security system and its ability to respond to complex attacks. Description of the Drawings
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the specific implementation manners or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1 It is a flowchart of the method from step S1 to step S3 in the embodiment of the present application.
[0024] Figure 2 It is a flowchart of the method from step S11 to step S13 in the embodiment of the present application.
[0025] Figure 3 It is a flowchart of the method from step S21 to step S23 in the embodiment of the present application.
[0026] Figure 4 It is a flowchart of the method from step S31 to step S33 in the embodiment of the present application.
[0027] Figure 5 It is a flowchart of the method from step S41 to step S42 in the embodiment of the present application.
[0028] Figure 6 It is the system architecture diagram of the embodiment of the present application.
[0029] Figure 7 It is the structural schematic diagram of the electronic device. Detailed Description of the Embodiments
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings. Obviously, the described embodiments are some specific implementation manners of the embodiments of the present application, rather than all of the specific implementation manners. Based on the specific implementation manners in the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the embodiments of the present application.
[0031] Description of the reference numerals: 800 - device, 801 - processor, 802 - memory, 803 - communication interface, 8021 - program code, 804 - bus.
[0032] As Figure 1 shown, the embodiment of the present application provides a security protection effectiveness evaluation method based on intelligent computing data security analysis, including:
[0033] Step S1: Verify whether the basic functions of the network security device are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of the network security device are enabled normally. The network security device includes at least a firewall, a unified threat management device UTM, and an intrusion detection and prevention system IDS / IPS. Among them, the firewall includes: a traditional firewall FW, a next-generation firewall NGFW, and a web application firewall WAF.
[0034] In step S1, the basic functions of the network device refer to the core functions and basic capabilities that the network security device must possess to ensure the security of the network environment. In the embodiments of the present application, the basic functions of the network device involve the monitoring and response capabilities of the network security device, as well as its integration and management in the security defense system, which is of great significance for implementing the embodiments of the present application. The firewall Firewall includes a traditional firewall FW, a next-generation firewall NGFW, and a web application firewall WAF. Among them, the traditional firewall is a rule-based device used to control the in and out of network traffic, usually performing access control based on IP addresses, port numbers, and protocol types. The next-generation firewall adds functions such as application identification, user identity identification, intrusion prevention IPS, and content filtering on the basis of the traditional firewall, and can control network traffic more precisely. The web application firewall WAF provides the function of protecting web applications and prevents application-layer attacks such as SQL injection, cross-site scripting XSS, and webshell upload. The unified threat management device UTM integrates multiple security functions, such as: firewall, intrusion detection and prevention IDS / IPS, anti-virus, anti-spam, content filtering, etc., and can provide a one-stop security solution.
[0035] Step S2: When the basic functions of the network security device are enabled normally, conduct a mixed test of old and new attack actions on the network security device to obtain the detection ability of the network security device against network attacks. The purpose of conducting the mixed test of old and new attack actions in step S2 is to detect network access control and security protection devices and examine their blocking rates against known and unknown threats.
[0036] Step S3: Verify the detection ability of network attacks, and conduct a security assessment of the SIEM / SOC system based on the simulation of advanced persistent threat scenarios APT. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources.
[0037] In step S3, SIEM / SOC refers to Security Information and Event Management SIEM / Security Operations Center SOC. Security Information and Event Management SIEM / Security Operations Center SOC is a core component of modern network security systems. SIEM / SOC provides comprehensive security monitoring, threat detection, and incident response capabilities by integrating people, processes, and technologies. The SIEM system's role is to collect log data from multiple sources such as network devices, applications, and user activities, and perform centralized management and analysis. The SIEM system can identify abnormal behaviors and potential threats through real-time monitoring and analysis of log data, issue alerts in a timely manner, and conduct correlation analysis on multi-source logs to identify complex attack patterns. The SOC, through the SIEM system and other tools, monitors network and system activities in real time, detects potential threats, classifies, investigates, and responds to detected security incidents, reduces the impact of incidents on the business, identifies and responds to new threats, optimizes security policies and processes based on incident handling results, and enhances the overall defense capabilities. SIEM / SOC provides a comprehensive security operation framework, which can significantly enhance network security protection capabilities through real-time monitoring, threat detection, incident response, and compliance management.
[0038] Step S4: Based on the SIEM / SOC system's ability to perform correlation analysis on multi-source logs and build threat profiles, measure the incident response and recovery time metrics, and generate a security protection effectiveness evaluation result according to the incident response and recovery time metrics.
[0039] In step S4, the incident response and recovery time metrics can be the Mean Time to Detect (MTTD) and the Mean Time to Remediate (MTTR). The compliance rates of MTTD and MTTR are used as evaluation metrics for operational response effectiveness. Step S4 measures the incident response and recovery time metrics (such as MTTD and MTTR) through the SIEM / SOC system's correlation analysis of multi-source logs and threat profiling capabilities, and generates a security protection effectiveness evaluation result based on these metrics. Step S4 also verifies the efficiency of work order flow and personnel response capabilities, uses the compliance rates of MTTD and MTTR as evaluation metrics for operational response effectiveness. Step S4 can comprehensively evaluate the detection, response, and recovery capabilities of the network security system in the face of threats, ensure the efficiency and effectiveness of security operations, optimize the security operation process, enhance the security protection effectiveness, and also enhance the utilization of threat intelligence, improve the transparency and manageability of security operations.
[0040] The technical solutions provided in steps S1 to S4 can comprehensively verify the functions of network security devices and the overall effectiveness of network security. Through systematic verification and dynamic testing, the functions of network security devices and the overall effectiveness of the network security system are comprehensively evaluated. The technical solutions provided in steps S1 to S4 not only focus on the static functions of devices but also evaluate the dynamic protection capabilities of the network security system in the face of complex attacks through APT scenario simulation and multi-source log analysis. By quantifying event response and recovery time metrics, detailed security protection effectiveness evaluation results are generated, providing a scientific basis for optimizing network security policies and significantly enhancing the network security protection capabilities of network security devices.
[0041] As Figure 2 shown, in step S1, it is verified whether the basic functions of the network security device are enabled normally, which further includes:
[0042] Step S11, the basic functions of the network security device are designed based on the network security defense system, including checking the rule enabling status of the detection firewall, intrusion prevention system (IPS), and web application firewall (WAF);
[0043] Step S12, verify whether the log synchronization and alarm mechanism of the honeypot and endpoint detection and response (EDR) devices can trigger an alarm when an abnormal event is detected;
[0044] Step S13, evaluate whether the log synchronization and alarm mechanism of the honeypot and EDR devices cover key nodes and security areas in the network.
[0045] In step S13, key nodes refer to devices, systems, or locations in the network that have important functions or store critical data. Key nodes are usually the core parts of network operation and are crucial for business continuity and data security. If a key node is attacked or fails, it may lead to serious business interruptions or data leaks. A security area refers to different areas in the network divided according to security requirements and functions. Each security area has clear security policies and access control rules to isolate different security-level network parts and prevent attacks from spreading from one area to another. By evaluating whether the log synchronization and alarm mechanism of the honeypot and EDR devices cover key nodes and security areas in the network, step S13 can timely detect potential threats, reduce the impact of network attacks on the business, optimize security policies and access control rules according to the monitoring results of network optimization security policies, conduct unified analysis of logs through a centralized management platform, reduce manual intervention, improve security operation efficiency, ensure that key nodes and security areas are effectively monitored, and reduce the risk of the network being attacked.
[0046] The optimized technical solutions provided by steps S11 to S13 ensure the normal operation of the basic functions of network security devices by verifying the rule enabling status of IPS and WAF, execute their basic design functions, and ensure the reliability of the basic functions of the network security defense system. By verifying the log synchronization and alarm mechanisms of honeypot and EDR devices, it ensures that alarms can be triggered in a timely manner when abnormal events are detected, enhances the detection and response capabilities for abnormal events, quickly discovers potential threats, reduces the impact of attacks on the network environment, and improves the overall response speed. By evaluating whether the log synchronization and alarm mechanisms of honeypot and EDR devices cover key nodes and security areas, it ensures that there are no blind spots in network security monitoring, optimizes the coverage of security monitoring, ensures the overall security of the network environment, ensures the matching of the basic functions of network security devices with the overall defense system design, and realizes the collaborative work between devices on the basis of verifying and guaranteeing the independent functions of network security devices, improving the reliability of the entire network security defense system and providing basic data for subsequent security assessments.
[0047] Exemplarily, a firewall intrusion prevention system (IPS) is used to detect and block malicious traffic, attack behaviors, and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network. Attack patterns include known attack patterns and unknown attack patterns. Known attack patterns refer to attack behaviors and patterns that have been identified and recorded by security researchers. Known attack patterns usually have clear characteristics and can be detected through a signature database. The IPS can use a preset signature rule library to identify known attack patterns. The signature rule library is a collection of known attack characteristics. By matching the packet characteristics in network traffic, the IPS can quickly identify and block network attacks, such as DDoS attacks, SQL injection attacks, cross-site scripting attacks (XSS), and so on. Unknown attack patterns refer to attack behaviors and patterns that have not been identified or recorded. Unknown attack patterns usually have a high degree of concealment and innovation and are difficult to detect through traditional signature matching methods. For example, zero-day attacks, which use vulnerabilities that have not been made public for attacks; advanced persistent threats (APT), which gradually penetrate the target system through a multi-stage attack path; fileless attacks, which use malicious code in memory to execute attacks and do not rely on the file system.
[0048] The optimized technical solutions provided by steps S11 to S13 can identify malicious traffic and network attack behaviors through a signature database and an anomaly detection database. The anomaly detection database is a system for storing and managing data related to anomaly detection. The core function of the anomaly detection database is to help identify and analyze data patterns that do not conform to expected behaviors, so as to detect anomaly events through artificial intelligence technologies such as machine learning and statistical analysis. If malicious traffic and network attack behaviors are identified, automatic measures will be taken to block the attack. The automatic measures to block the attack can include: discarding malicious data packets, blocking connections, or reconfiguring firewall rules, recording the detected threats and attack behaviors, and providing data support for subsequent data analysis. IPS is mainly applied to network boundary protection to prevent external attacks from entering the internal network.
[0049] The Web Application Firewall (WAF) is used to prevent network attacks against the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, perform alarm processing on malicious requests and attack events, and detect whether the log synchronization function of the honeypot and the Endpoint Detection and Response (EDR) device is running normally, and verify whether the corresponding log information can be synchronized to the network security centralized management platform to ensure the integrity of the network security protection system.
[0050] The protection function of the Web Application Firewall (WAF) and the log synchronization function of the honeypot and EDR device build a complete network security protection system. The Web Application Firewall (WAF) can effectively prevent attacks against Web applications, while the log synchronization function ensures the integrity and coordination ability of the security protection system, not only enhancing the security of Web applications, but also improving the overall efficiency of the security protection system, optimizing the security operation efficiency, and providing network security guarantee for the security and stability of the network environment.
[0051] As Figure 3 shown, in step S2, when the basic functions of the network security device are enabled normally, a mixed test of new and old attack actions is performed on the network security device to obtain the detection ability of the network security device against network attacks, which further includes:
[0052] Step S21, construct a test library including a mixture of new and old attack actions, configure the new and old attack actions in the test library, and randomly or according to a preset strategy select the corresponding attack actions.
[0053] Step S22, perform a mixed attack test of new and old actions in the network security device. The mixed attack test of new and old actions is set in an isolated test environment.
[0054] Step S23: Set up a simulated attacker to perform a mixed attack of old and new actions. The mixed attack of old and new actions includes: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, and cross-site scripting attack.
[0055] Step S24: Obtain the log data and warning information generated during the test of the mixed attack of old and new actions, analyze the detection data metrics of different mixed attacks of old and new actions by the network security device, and evaluate the detection ability of the corresponding network security device against network attacks. Among them, the detection data metrics include: detection rate, false alarm rate, and response time.
[0056] The optimization technical solution provided by steps S21 to S24 comprehensively evaluates the detection ability of the network security device against network attacks when the basic functions are enabled normally by constructing a test library, performing a mixed attack test in an isolated environment, and analyzing the detection data metrics. It can provide detailed evaluation results to assist in optimizing security policies and device configurations, can adjust device rules targeted, improve the overall protection ability, and performing attack tests in an isolated test environment (such as a sandbox) can ensure the security of the test process and avoid affecting the production environment. It can not only identify the potential weaknesses of the device when facing complex attacks, but also provide a scientific basis for optimizing security policies and improving security operation efficiency, significantly enhancing the overall effectiveness of the network security protection system. The evaluation results can assist in decision-making and make reasonable decisions during device selection and network security policy adjustment to ensure the overall effectiveness of the network security protection system.
[0057] As Figure 4 shown, in step S3, verify the detection ability against network attacks, and conduct a security assessment of the SIEM / SOC system based on the simulation of the advanced persistent threat scenario APT. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources, and further includes:
[0058] Step S31: Construct an advanced persistent threat scenario to simulate the life cycle of the real advanced persistent threat scenario, which includes data reconnaissance, initial access, and privilege escalation in the advanced persistent threat scenario;
[0059] Step S32: Obtain log data from multiple sources in the advanced persistent threat scenario, perform normalization processing on the obtained multi-source log data, and use preset data correlation rules and algorithms to perform correlation analysis on the normalized multi-source log data to identify potential security events and attack behaviors in the multi-source log data;
[0060] Step S33: Construct a threat profile of the attacker based on the results of the correlation analysis. The threat profile includes the attack path, attack pattern, attack tool, and attack target, and evaluate and generate the threat level of the attack under the advanced persistent threat scenario.
[0061] The optimization technical solutions provided by steps S31 to S33 can construct the APT scenario, perform multi-source log correlation analysis, and construct the threat profile, which can more accurately evaluate the detection ability of the SIEM / SOC system in the face of complex attacks. The correlation analysis of multi-source logs helps to identify attack behaviors across devices and systems, reduce false alarms and improve detection accuracy, providing a comprehensive perspective for the security assessment of the SIEM / SOC system, ensuring that the system can cope with complex APT attacks, improving the accuracy of APT detection, and also enhancing the utilization efficiency of processing network threat intelligence by constructing a threat profile, optimizing the security operation process, and providing a comprehensive basis for network security assessment and optimization.
[0062] As Figure 5 shown, in step S4, based on the correlation analysis of multi-source logs by the SIEM / SOC system and the ability to construct a threat profile, measure the event response and recovery time metrics, and generate a security protection effectiveness assessment result according to the event response and recovery time metrics, which further includes:
[0063] Step S41: According to the threat level of the attack under the advanced persistent threat scenario, measure the mean time to respond (MTTR) and mean time to detect (MTTD) of the network security device when detecting a security event. The event response time is specifically the time from the occurrence of the security event to the start of the response, and the event recovery time is specifically the time from the occurrence of the security event to the network returning to normal operation;
[0064] Step S42: Generate a security protection effectiveness assessment report for the network security device based on the correlation analysis results of multi-source log data, the threat profile, and the event response time and event recovery time. The security protection effectiveness assessment report is used for the detection ability assessment, false alarm rate analysis, response time assessment, and summary of improvement suggestions of security events.
[0065] Exemplarily, in the process of generating the security protection effectiveness assessment report for the network security device, the EFFECT weighting method is used to calculate the network security effectiveness evaluation value and generate the security protection effectiveness assessment report. The EFFECT weighting method satisfies the following formula:
[0066]
[0067] Wherein: β1, β2, β3, and β4 are the weights of the measurement factors, satisfying β1 + β2 + β3 + β4 = 1, NET is the evaluation value of the network performance impact (average value), PASSET is the evaluation value of the asset defense (average value), DP is the system protection ability, and Service is the evaluation value of the business impact.
[0068] The optimization technical solution provided by steps S41 to S42 comprehensively evaluates the security protection effectiveness of network security devices through the correlation analysis of multi-source logs and the construction of threat portraits, combined with the event response and recovery time indicators, conducts a quantitative analysis of the network security protection effectiveness, optimizes the network security strategy and resource allocation strategy, increases the utilization efficiency of network security threat intelligence, improves the security operation effect, and provides a comprehensive perspective for the security assessment of network security devices by combining APT scenario simulation and multi-source log analysis, ensuring that the system can cope with complex APT attacks. The optimization technical solution provided by steps S41 to S42 not only quantifies the detection and response capabilities of the device but also provides a basis for optimizing the security strategy and resource allocation, significantly improving the overall effectiveness of the network security protection system. In the EFFECT formula, key issues can be quickly identified through quantitative evaluation, reducing the time for manual troubleshooting and analysis, improving the security operation efficiency. Through clear weight allocation and quantitative indicators, the evaluation process of network security effectiveness becomes more transparent and manageable. By comprehensively evaluating multiple key indicators, the overall effectiveness of evaluating network security devices or systems is quantified, significantly improving the transparency, manageability, and overall response ability of the network security system.
[0069] For the method steps disclosed in the above embodiments, for the purpose of simple description, the method steps are expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present application are not limited by the described action sequence, because according to the embodiments of the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present application.
[0070] Any process or method description, whether in the form of a flowchart or otherwise, can be understood as representing a module, segment, or part of the code of an executable instruction including one or more steps for implementing a specific logical function or process. The scope of the preferred implementation of the embodiments of the present application includes additional implementations, where the steps may not be executed in the order shown or discussed, including performing and implementing the functions in a substantially simultaneous manner or in the reverse order according to the functions involved, or executing computer instructions in a program structure such as a loop or a branch to implement the corresponding functions, which is naturally understandable to those skilled in the art when implementing the embodiments of the present application.
[0071] Such asFigure 6 As shown in the figure, the embodiment of the present application also provides a security protection effectiveness evaluation system based on intelligent computing data security analysis, which is used to implement the security protection effectiveness evaluation method based on intelligent computing data security analysis described in any specific implementation manner in the description of the present application, including:
[0072] The basic function verification module of the network security device verifies whether the basic functions of the network security device are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of the network security device are enabled normally. The network security device at least includes a firewall, a unified threat management device, and an intrusion detection and prevention system;
[0073] The attack detection ability module of the network security device, when the basic functions of the network security device are enabled normally, conducts a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks;
[0074] The multi-source log correlation analysis and threat portrait construction module verifies the detection ability of network attacks. Based on the advanced persistent threat scenario, it simulates the security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to conduct correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources;
[0075] The security protection traffic assessment result generation module, based on the ability of the SIEM / SOC system to conduct correlation analysis of multi-source logs and construct threat portraits, measures the event response and recovery time indicators, and generates a security protection effectiveness evaluation result according to the event response and recovery time indicators.
[0076] The implementation manner of the system described above is only illustrative. For example: each functional module, unit, or subsystem in the system can be physically separated or not, or can be a physical unit or not, that is, it can be located in the same place or distributed to multiple different systems and their subsystems or modules. Those skilled in the art can select some or all of the functional modules, units, or subsystems according to actual needs to achieve the purpose of the embodiment of the present application. For the above situations, those of ordinary skill in the art can understand and implement them without creative labor.
[0077] The following starts from the perspectives of verifying the operation mechanism and algorithm model design, and evaluates the specific implementation manners disclosed in the embodiment of the present application from the perspectives of evaluation dimensions and weights, score calculation and model comparison, algorithm optimization and innovation points, and model limitations:
[0078] When verifying the operation mechanism of each specific implementation manner of the embodiment of the present application, a periodic task and a dynamic trigger mechanism are established for verification, including:
[0079] Periodic tasks: daily basic verification (phase 1), weekly ability re-evaluation (phase 2), monthly association rule optimization (phase 3), quarterly response process testing (phase 4).
[0080] Dynamic trigger mechanism: immediate verification is performed for vulnerability scan results or policy changes to ensure the timeliness of evaluation.
[0081] Evaluation dimensions and weights:
[0082] The model includes five core dimensions (Table 1), and multi-dimensional quantitative evaluation is achieved through a dynamic weight mechanism
[0083]
[0084] Score calculation and model comparison:
[0085] Score calculation method, basic score calculation:
[0086] 1. Each boundary verification score = (number of passed verification items / total number of verification items) Boundary weight Basic assigned score.
[0087] Total functional verification score = Σ(boundary verification scores) / Σ(boundary weights) Basic score assignment.
[0088] Coverage score = (number of covered boundaries / total number of boundaries to be covered) Coverage score assignment.
[0089] 2. Protection ability calculation:
[0090] Single protection ability score = basic score Σ(boundary verification pass rate boundary weight) / Σ(boundary weights).
[0091] 3. Business protection calculation:
[0092] Business protection score = Σ(verification item scores business importance weight) / total number of businesses.
[0093] 4. Scenario verification calculation:
[0094] Effectiveness score = (association analysis accuracy score assignment + multi-source data analysis score score assignment + scenario recognition score score assignment).
[0095] 5. Operation response calculation:
[0096] MTTD effectiveness = Σ(compliance rate of each level score distribution).
[0097] MTTR effectiveness = Σ(compliance rate of each level score distribution).
[0098] 6. Free verification calculation:
[0099] Verification action score = basic score threat level weight boundary weight verification result weight.
[0100] 7. Aggregation of multiple identical verification results:
[0101] If the overall evaluation occurs over a period of time, there will definitely be multiple executions of the same verification. Therefore, it is necessary to aggregate the multiple results: take the latest N verification results (N = 5).
[0102] Apply time decay weight;
[0103] Time decay weight formula: Time decay weight = e^(-λ(current_time - test_time))
[0104] Suggested value of λ: 0.1
[0105] Remove the highest and lowest scores;
[0106] Weighted score = Σ(single score time weight) / Σ(time weight).
[0107] 8. Total score synthesis:
[0108] Final score = (basic score + protection ability score + business protection verification score + scenario verification bonus + operation response score + free verification) (1 + boundary coverage rate weighting) verification pass rate.
[0109] Comparison and analysis with existing models:
[0110] To verify the multidimensionality and accuracy of this model, three types of typical models are selected for comparative experiments (Table 2):
[0111]
[0112] Comparison of experimental data (Table 3):
[0113]
[0114] Conclusion: As can be seen from Tables 1 to 3, the technical solution provided by the embodiments of the present application has multidimensionality and accuracy. This model covers device functions, protection capabilities, business protection, scenario verification, and response processes through five major dimensions, which is more comprehensive than the static model (2 types) and the attack graph model (3 types). Both the ATT&CK coverage rate (88%) and the MTTR (4.2 hours) are better than the comparison models, and the false alarm rate (5.1%) is lower than that of the attack graph model (12.3%).
[0115] Algorithm optimization and innovation points:
[0116] 1. Dynamic weight matrix: Define the priority of the attack path between security regions (e.g., Internet → core area weight 1.5), which conforms to the high risk of external threats in actual attack and defense.
[0117] 2. Hierarchical scoring mechanism: Adopt a structure of "basic score + scenario bonus + operation score" to avoid deviation in a single dimension. For example, although a certain enterprise fails to meet the MTTR standard (operation score 180 / 250), it can still reflect its technical advantages through a high protection ability score (270 / 300).
[0118] 3. Adversarial verification design: In the second stage, mix new and old attack actions (ratio 7:3) to improve the adaptability to 0day attacks (detection rate 78%, higher than 52% of the machine learning model).
[0119] In some embodiments, the algorithm model provided by the embodiments of the present application can be further extended and improved. For example, aiming at the limitations of the algorithm model such as strong data basis, high demand for manual intervention, and high computational complexity, adopt automated and intelligent means to continuously integrate the latest network security threat intelligence into the attack library, avoid subjective errors that may be introduced due to the dependence of the response process verification on manual participation, and use platform tools to support the efficient calculation of the weight matrix and attenuation factor.
[0120] Experiments and results:
[0121] Single-case in-depth verification, taking a certain financial enterprise as the test object:
[0122] Phase 1: The detection of EDR privileged operations is not enabled, deducting 30 points from the basic score;
[0123] Phase 2: The blocking rate of the WAF for new injection attacks is 65%, and the protection ability score is 52 / 80;
[0124] Phase 4: MTTR (high-risk events) is 6 hours, and the response score is 45 / 65;
[0125] Total score: 872 (Grade B), indicating that the response process and terminal protection need to be optimized.
[0126] Multi-industry comparative experiments are extended to finance, healthcare, and manufacturing to verify the model's generalization ability:
[0127]
[0128] As can be seen from the above specific implementation manners, the security protection effectiveness evaluation method and the corresponding evaluation model proposed in the embodiments of the present application effectively improve the comprehensiveness and accuracy of security verification through dynamic weights and multi-dimensional quantitative analysis. Future work will explore AI-driven automated attack simulations and optimize the time decay factor parameters. At the same time, the applicability of the model in the cloud-native environment can be further verified to enhance the implementation effects of the embodiments of the present application in different application scenarios.
[0129] As Figure 7 shown, on the basis of providing a security protection effectiveness evaluation method and system based on intelligent computing data security analysis, the embodiments of the present application also provide corresponding electronic devices and computer program products:
[0130] An electronic device includes: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory communicate with each other through the communication bus; a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the steps of the security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0131] A computer program product includes a computer program, and when the computer program is executed by a processor, it implements the security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0132] Figure 7 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present application. As Figure 7 shown, the device 800 includes a processor 801, a memory 802, a communication interface 803, and a bus 804. Among them, the processor 801, the memory 802, and the communication interface 803 communicate through the bus 804, and can also achieve communication through other means such as wireless transmission. The memory 802 is used to store instructions, and the processor 801 is used to execute the instructions stored in the memory 802. The memory 802 stores program code 8021, and the processor 801 can call the program code 8021 stored in the memory 802 to execute the steps of the security protection effectiveness evaluation method based on intelligent computing data security analysis.
[0133] It should be understood that in the embodiments of the present application, the processor 801 may be a CPU, and the processor 801 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0134] The memory 802 may include a read-only memory (ROM) and a random access memory (RAM), and provide instructions and data to the processor 801. The memory 802 may also include a non-volatile random access memory. The memory 802 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0135] In addition to the data bus, the bus 804 may also include a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity, all kinds of buses are labeled as the bus 804 in the figure.
[0136] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid state drive (SSD).
[0137] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered that the scope described in the specification of the embodiments of the present application is covered.
[0138] In the description of the specification of the embodiments of the present application, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one specific implementation manner of the embodiments of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0139] In addition, the technical solutions between the various embodiments of the present application can be combined with each other, but it must be based on the fact that those skilled in the art can implement them. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the embodiments of the present application.
[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present application, rather than to limit them. Although the embodiments of the present application have been described in detail with reference to the foregoing specific embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements on some or all of the technical features, and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the specific embodiments of the present application.
Claims
1. A security protection effectiveness evaluation method based on intelligent computing data security analysis, characterized in that Including: Verify whether the basic functions of the network security devices are enabled properly. During the verification process, it includes whether the log synchronization and alert mechanism of the network security devices are enabled properly. The network security devices at least include firewalls, unified threat management devices, and intrusion detection and prevention systems; When the basic functions of the network security devices are enabled properly, conduct a mixed test of old and new attack actions on the network security devices to obtain the detection ability of the network security devices against network attacks; Verify the detection ability of network attacks. Based on the advanced persistent threat scenario, simulate a security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources; Based on the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits, measure the event response and recovery time metrics, and generate a security protection effectiveness assessment result according to the event response and recovery time metrics. The generation of the security protection effectiveness assessment result according to the event response and recovery time metrics is specifically: Establish a periodic task and a dynamic trigger mechanism for verification, including: Periodic tasks: daily basic verification, weekly capability re-evaluation, monthly association rule optimization, quarterly response process test; Dynamic trigger mechanism: conduct immediate verification for vulnerability scan results or policy changes to ensure the timeliness of the assessment; Evaluation dimensions and weights: The model includes five core dimensions and realizes multi-dimensional quantitative evaluation through a dynamic weight mechanism: Score for each boundary verification = (number of passed verification items / total number of verification items) * boundary weight * basic allocation score. Total function verification score = Σ(score for boundary verification) / Σ(boundary weight) * basic score allocation. Coverage score = (number of covered boundaries / total number of boundaries to be covered) * coverage score allocation; Calculation of protection ability: Single protection ability score = basic score * Σ(pass rate of boundary verification * boundary weight) / Σ(boundary weight); Calculation of business protection: Business protection score = Σ(score of verification item * business importance weight) / total number of businesses; Calculation of scenario verification; Scenario verification effectiveness score = (accuracy rate of correlation analysis * score allocation + score of multi-source data analysis * score allocation + score of scenario recognition * score allocation); Calculation of operation response: MTTD effectiveness = Σ(pass rate of each level * score allocation); MTTR effectiveness = Σ(pass rate of each level * score allocation); Calculation of free verification: Verification action score = basic score * threat level weight * boundary weight * verification result weight; Aggregation of multiple identical verification results: The overall assessment occurs over a period of time, and the multiple results are aggregated and calculated: Take the verification results of the most recent N times; Synthesis of total score: Final score = (basic score + protection ability score + business protection verification score + scenario verification effectiveness score + operation response score + free verification) * (1 + coverage score) * boundary verification pass rate.
2. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 1, wherein The verification of whether the basic functions of the network security devices are enabled properly further includes: The basic functions of the network security device are designed based on a network security defense system, including detecting the rule enabling status of the firewall intrusion prevention system and the Web application firewall; Verifying whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response device can trigger an alarm when an abnormal event is detected; Evaluating whether the log synchronization and alarm mechanism of the honeypot and the endpoint detection and response device covers key nodes and security areas in the network.
3. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 2, wherein The firewall intrusion prevention system is used to detect and block malicious traffic, attack behaviors, and potential threats, monitor network traffic in real time, and detect abnormal behaviors and attack patterns in the network; Identify malicious traffic and network attack behaviors through the signature database and the anomaly detection database. If malicious traffic and network attack behaviors are identified, automatic measures are taken to block the attack; The Web application firewall is used to prevent network attacks against the application layer, detect the traffic of the current Web application, filter malicious requests in the traffic of the current Web application, identify potential attack behaviors, record the access logs and attack events of the Web application, and perform alarm processing on malicious requests and attack events; Detect whether the log synchronization function of the honeypot and the endpoint detection and response device is running properly, verify whether the corresponding log information can be synchronized to the network security centralized management platform, detect whether the synchronization trigger alarm of the log synchronization and alarm mechanism is successful, and evaluate whether the honeypot and the endpoint detection and response device cover key nodes and security areas in the network.
4. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 1, wherein, When the basic functions of the network security device are enabled normally, conduct a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks. Further include: Construct a test library including a mixture of new and old attack actions, configure the new and old attack actions in the test library, and randomly or according to a preset strategy select the corresponding attack actions; Conduct a mixed new and old action attack test on the network security device. The mixed new and old action attack test is set in an isolated test environment; Set up a simulated attacker to conduct a mixed new and old action attack. The mixed new and old action attack includes: initial intrusion, privilege escalation, lateral movement, data leakage, SQL injection, cross-site scripting attack; Obtain the log data and alarm information generated during the test of the mixed new and old action attack, analyze the detection data metrics of the network security device against different mixed new and old action attacks, and evaluate the detection ability of the corresponding network security device against network attacks.
5. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 1, characterized in that Verify the detection ability against network attacks. Based on the advanced persistent threat scenario, simulate a security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis of multi-source logs and construct threat portraits when processing log data from multiple sources. Further include: Construct an advanced persistent threat scenario to simulate the life cycle of the real advanced persistent threat scenario, including data reconnaissance, initial access, and privilege escalation in the advanced persistent threat scenario; Obtain log data from multiple sources in the advanced persistent threat scenario, normalize the obtained multi-source log data, and use preset data association rules and algorithms to perform correlation analysis on the normalized multi-source log data to identify potential security events and attack behaviors in the multi-source log data; Construct a threat profile of the attacker based on the results of the correlation analysis. The threat profile includes the attack path, attack pattern, attack tool, and attack target, and evaluate and generate the threat level of the attack in the advanced persistent threat scenario.
6. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 1, characterized in that Based on the ability of the SIEM / SOC system to perform correlation analysis on multi-source logs and construct a threat profile, measure the event response and recovery time metrics, and generate a security protection effectiveness evaluation result according to the event response and recovery time metrics. Further include: According to the threat level of the attack in the advanced persistent threat scenario, measure the event response time and event recovery time of the network security device when a security event is detected. The event response time is specifically the time from the occurrence of the security event to the start of the response, and the event recovery time is specifically the time from the occurrence of the security event to the network returning to normal operation; Generate a security protection effectiveness evaluation report for the network security device according to the correlation analysis results, threat profile, event response time, and event recovery time of the multi-source log data. The security protection effectiveness evaluation report is used for the detection ability evaluation of security events, false alarm rate analysis, response time evaluation, and summary of improvement suggestions.
7. The security protection effectiveness evaluation method based on intelligent computing data security analysis according to claim 6, characterized in that, In the process of generating the security protection effectiveness evaluation report for the network security device, use the EFFECT weighting method to calculate the network security effectiveness evaluation value and generate the security protection effectiveness evaluation report. The EFFECT weighting method satisfies the following formula: Where: β1, β2, β3, β4 are the weights of the measurement factors, satisfying β1 + β2 + β3 + β4 = 1, NET is the network performance impact evaluation value, PASSET is the asset defense evaluation value, DP is the system protection ability, and Service is the business impact evaluation value.
8. A security protection effectiveness evaluation system based on intelligent computing data security analysis, which is used to implement the security protection effectiveness evaluation method based on intelligent computing data security analysis described in any one of claims 1 to 7, and is characterized in that, Include: Network security device basic function verification module, verify whether the basic functions of the network security device are enabled normally. During the verification process, it includes whether the log synchronization and alarm mechanism of the network security device are enabled normally. The network security device at least includes a firewall, unified threat management device, and intrusion detection and prevention system; Network security device attack detection ability module, when the basic functions of the network security device are enabled normally, perform a mixed test of new and old attack actions on the network security device to obtain the detection ability of the network security device against network attacks; Multi-source log correlation analysis and threat profile construction module, verify the detection ability of network attacks, and based on the advanced persistent threat scenario, simulate a security assessment of the SIEM / SOC system. The security assessment includes the ability of the SIEM / SOC system to perform correlation analysis on multi-source logs and construct a threat profile when processing log data from multiple sources; The security protection traffic assessment result generation module, based on the correlation analysis of multi-source logs by the SIEM / SOC system and the ability to build threat portraits, measures the event response and recovery time indicators, and generates the security protection effectiveness assessment result according to the event response and recovery time indicators. The generation of the security protection effectiveness assessment result according to the event response and recovery time indicators is specifically as follows: Establish a periodic task and a dynamic trigger mechanism for verification, including: Periodic tasks: daily basic verification, weekly capability re-assessment, monthly association rule optimization, quarterly response process testing; Dynamic trigger mechanism: perform immediate verification for vulnerability scan results or policy changes to ensure the timeliness of assessment; Assessment dimensions and weights: The model includes five core dimensions, and multi-dimensional quantitative assessment is achieved through a dynamic weight mechanism: Each boundary verification score = (number of passed verification items / total number of verification items) * boundary weight * basic allocation score, total function verification score = Σ(boundary verification scores) / Σ(boundary weights) * basic score allocation, coverage score = (number of covered boundaries / total number of boundaries to be covered) * coverage score allocation; Calculation of protection ability: Single protection ability score = basic score * Σ(boundary verification passing rate * boundary weight) / Σ(boundary weights); Calculation of business protection: Business protection score = Σ(verification item scores * business importance weights) / total number of businesses; Calculation of scenario verification; Scenario verification effectiveness score = (association analysis accuracy rate * score allocation + multi-source data analysis score * score allocation + scenario recognition score * score allocation); Calculation of operation response: MTTD effectiveness = Σ(attainment rates of each level * score allocation); MTTR effectiveness = Σ(attainment rates of each level * score allocation); Calculation of free verification: Verification action score = basic score * threat level weight * boundary weight * verification result weight; Aggregation of multiple identical verification results: The overall assessment occurs within a period of time, and the multiple results are aggregated and calculated: Take the most recent N verification results; Synthesis of total score: Final score = (basic score + protection ability score + business protection verification score + scenario verification effectiveness score + operation response score + free verification) * (1 + coverage score) * boundary verification passing rate.
9. An electronic device, characterized in that, Including: A processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; a computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Network attack data analysis and intelligent processing method
CN107277039A
Intelligent networked automobile network security assessment method
CN118074970A