Dynamic risk visualization management method for asset and risk management
Through automated scanning and asset management systems, network asset information is obtained, and risk is analyzed and visualized using graph database and neural network technology, the problem of difficulty in integrating and visualizing risk management in the existing technology is solved, and efficient and accurate risk monitoring and defense strategy optimization is achieved.
Patent Information
- Application Number
- CN202510188213.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-06-06
AI Technical Summary
The existing technology is difficult to effectively integrate and visualize asset and risk information in risk management, and it is impossible to identify and predict potential attack paths in a timely manner, resulting in security defense measures lag behind actual threats.
Automatic scanning and asset management systems are used to obtain network asset information, use graph database technology to build a network topology diagram, combine vulnerability database and attack diagram technology to analyze vulnerabilities and attack paths, use graph neural networks to perform dynamic analysis, and evaluate defense effectiveness through simulated attack technology, and finally use augmented reality and virtual reality technology to perform dynamic visual display.
Real-time dynamic monitoring and evaluation of risks is achieved, and the efficiency and accuracy of risk management is improved, which helps security managers quickly identify and respond to potential threats, optimize defense strategies, and improve network security protection capabilities.
Smart Images

Figure CN120106569A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of risk management, and in particular to a dynamic risk visualization management method oriented to asset and risk management. Background Art
[0002] At present, assets and risks in risk management are often stored in a decentralized manner, relying on static asset lists and manual analysis, lacking effective integration and visualization methods, making it difficult to cope with dynamically changing network environments and complex attack paths, and unable to effectively identify and predict potential attack paths, causing security defense measures to lag behind actual threats. This makes it difficult for managers to make timely and accurate decisions when facing potential risks. Therefore, there is an urgent need for a dynamic risk visualization management method for asset and risk management to dynamically monitor and evaluate risks. Summary of the invention
[0003] The purpose of the present invention is to provide a dynamic risk visualization management method for asset and risk management, aiming to solve the above problems.
[0004] The present invention provides a dynamic risk visualization management method for asset and risk management, comprising:
[0005] Utilize automated scanning and asset management systems to obtain asset information in the network, and classify assets based on the asset information, including servers, terminal devices, and security devices;
[0006] Based on the asset information, the connection relationship between the assets is determined using graph database technology to construct a network topology diagram;
[0007] Based on the vulnerability database and combined with attack graph technology, we analyze the vulnerabilities of each asset, generate attack graphs, and determine the preset attack paths;
[0008] Combining network traffic data and attack methods, using a graph neural network to analyze the preset attack path to determine the attack path, and determine the vulnerability of each node on the attack path;
[0009] Using simulated attack technology to evaluate the security defense system in the attack path to determine the defense effectiveness of the security defense system in the attack path;
[0010] Based on augmented reality and virtual reality technologies, the vulnerabilities, attack paths and defense effectiveness of each asset are dynamically displayed on the network topology diagram.
[0011] Preferably, the asset information in the network is acquired by using an automated scanning and asset management system, and the asset classification is performed based on the asset information, including:
[0012] Use automated scanning tools to scan the network and obtain scanned asset information;
[0013] Cleaning the scanned asset information and importing it into the asset management system, wherein the asset management system is updated based on the imported scanned asset information to obtain asset information in the network;
[0014] Key features are extracted from the asset information, and asset classification is performed based on a preset deep learning model.
[0015] Preferably, based on the asset information, a graph database technology is used to determine the connection relationship between the assets and construct a network topology diagram, including:
[0016] The asset information includes asset type, IP address, MAC address, host name, open ports, running services and operating system;
[0017] Nodes and edge types are defined according to the asset information, the asset information is imported into a graph database, and connection relationships between assets are determined according to the defined node and edge types, and a network topology diagram is constructed based on the connection relationships.
[0018] Preferably, the vulnerabilities of each asset are analyzed and an attack graph is generated, including:
[0019] Analyze vulnerabilities based on CVSS technology and determine the exploitable indicators of vulnerabilities;
[0020] Determining an exploitability score of the vulnerability based on the exploitability indicator, and generating an attack graph according to the exploitability score;
[0021] The exploitable indicators include attack vectors, attack complexity, permission requirements, and user interactions;
[0022] The types of attack vectors include network, adjacency, local, and physical;
[0023] The attack complexity includes low difficulty and high difficulty;
[0024] The levels of permission requirements include no level, low level and high level;
[0025] The user interaction includes no interaction required and interaction required.
[0026] Preferably, determining a preset attack path includes:
[0027] Determine the initial node and target node of the attack graph;
[0028] Starting from the initial node, based on the exploitable score, the attack graph is traversed to determine all paths to the target node, and the paths are set as preset attack paths.
[0029] Preferably, combining network traffic data and attack methods, using a graph neural network to analyze the preset attack path to determine the attack path includes:
[0030] Obtain network traffic data and attack methods;
[0031] Analyzing the network traffic data to determine normal traffic patterns and abnormal traffic patterns;
[0032] Based on the attack method, identify potential attack behaviors according to the abnormal traffic pattern and determine the key attack points;
[0033] Screening the preset attack paths based on the key attack points to determine optional attack paths;
[0034] Evaluate the optional attack paths to determine the risk value and attack efficiency of each optional attack path;
[0035] The optional attack paths are screened based on the risk value and the attack efficiency to obtain an attack path.
[0036] Preferably, determining the vulnerability of each node on the attack path includes:
[0037] Establish vulnerability assessment indicators;
[0038] Based on the asset information and the vulnerabilities of each asset, the vulnerability of each node is evaluated according to the vulnerability assessment index;
[0039] The vulnerability assessment indicators include vulnerability severity indicators, exploitability indicators, vulnerability impact scope indicators and vulnerability repair status indicators.
[0040] Preferably, using simulated attack technology to evaluate the security defense system in the attack path to determine the defense effectiveness of the security defense system in the attack path includes:
[0041] Attacking the security defense system in the attack path based on the simulated attack technology to obtain attack data, the attack data including the number of detected attacks, the total number of attacks, the number of false alarms, the total number of alarms, the detection time, the attack occurrence time and the number of blocked attacks;
[0042] Evaluate the security defense system based on the attack data to determine a defense effectiveness evaluation index of the security defense system in the attack path;
[0043] The defense effectiveness evaluation indicators include detection rate, false alarm rate, response time and blocking rate.
[0044] Preferably, the detection rate is determined according to the following formula:
[0045] Detection rate = (number of detected attacks / total number of attacks) × 100%;
[0046] The false alarm rate is determined according to the following formula:
[0047] False alarm rate = (number of false alarms / total number of alarms) × 100%;
[0048] The response time is determined according to the following formula:
[0049] Response time = detection time - attack occurrence time;
[0050] The blocking rate is determined according to the following formula:
[0051] Blocking rate = (number of blocked attacks / total number of attacks) × 100%.
[0052] Preferably, the method further comprises: collecting historical attack data, and performing time series analysis based on a time series prediction model to determine and predict future attack behaviors.
[0053] Compared with the prior art, the beneficial effect of the present invention is that, through automated scanning and asset management system, the present invention can acquire and classify asset information in the network in real time, significantly improving the efficiency and accuracy of asset management and reducing errors and omissions in manual operations.
[0054] Using graph database technology to build a network topology diagram can intuitively display the connection relationship between various assets, helping security managers quickly understand the network structure and identify key nodes and potential attack paths.
[0055] Combining vulnerability database and attack graph technology, it is possible to analyze the vulnerabilities of each asset and generate an attack graph to determine the preset attack path. Dynamic analysis of the attack path through graph neural network can more accurately predict the attacker's behavior path and identify key vulnerable nodes.
[0056] By evaluating the security defense system through simulated attack technology, it is possible to quantify the effectiveness of the defense system, help security managers optimize defense strategies, and improve overall network security protection capabilities.
[0057] Using augmented reality and virtual reality technologies, the vulnerabilities, attack paths and defense effectiveness of each asset are dynamically displayed on the network topology diagram, providing a more intuitive and immersive way to display risks, helping security managers quickly identify and respond to potential threats.
[0058] Through dynamic visualization, security managers can understand network risk status more quickly, make more accurate decisions, shorten response time, and reduce losses caused by network attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0060] Figure 1 It is a flow chart of a dynamic risk visualization management method for asset and risk management according to the present invention. DETAILED DESCRIPTION
[0061] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0062] like Figure 1 As shown, the present invention provides a dynamic risk visualization management method for asset and risk management, comprising:
[0063] Utilize automated scanning and asset management systems to obtain asset information in the network, and classify assets based on the asset information, including servers, terminal devices, and security devices;
[0064] Based on the asset information, the connection relationship between the assets is determined using graph database technology to construct a network topology diagram;
[0065] Based on the vulnerability database and combined with attack graph technology, we analyze the vulnerabilities of each asset, generate attack graphs, and determine the preset attack paths;
[0066] Combining network traffic data and attack methods, using a graph neural network to analyze the preset attack path to determine the attack path, and determine the vulnerability of each node on the attack path;
[0067] Using simulated attack technology to evaluate the security defense system in the attack path to determine the defense effectiveness of the security defense system in the attack path;
[0068] Based on augmented reality and virtual reality technologies, the vulnerabilities, attack paths and defense effectiveness of each asset are dynamically displayed on the network topology diagram.
[0069] The present invention can dynamically display the asset risk situation in the network in real time, and improve the efficiency and accuracy of risk management. Through the combination of automated scanning and asset management systems, asset information in the network can be quickly obtained, and accurate asset classification can be performed to provide basic data support for subsequent risk analysis. At the same time, the network topology structure diagram is constructed using graph database technology, which can clearly display the connection relationship between each asset, which helps to discover potential security risks. In addition, combined with the vulnerability database and attack graph technology, it is possible to deeply analyze the vulnerabilities of each asset and generate an attack graph to determine the preset attack path, providing an important reference for formulating effective defense strategies. Through the analysis of the preset attack path by the graph neural network, the vulnerability of each node on the attack path can be further determined, providing a strong basis for strengthening security protection. Finally, the security defense system is evaluated using simulated attack technology, which can truly reflect the defense effectiveness of the system and provide a scientific basis for optimizing defense measures.
[0070] In some embodiments of the present application, automated scanning and asset management systems are used to obtain asset information in a network, and asset classification is performed based on the asset information, including: using an automated scanning tool to scan the network to obtain scanned asset information; performing data cleansing on the scanned asset information and importing it into the asset management system, wherein the asset management system is updated based on the imported scanned asset information to obtain asset information in the network; and key features are extracted from the asset information, and asset classification is performed based on a preset deep learning model.
[0071] In this embodiment, automated scanning tools are deployed in the network, which can actively detect devices, software and services in the network. These scanning tools identify active devices in the network through various protocols and ports, and collect information about operating systems, open ports, running services and known vulnerabilities. The automated scanning process can be performed regularly to ensure the real-time and accuracy of asset information. After the scan is completed, the asset information obtained often contains a large amount of raw data, which needs to be cleaned to remove redundant and inconsistent information. Data cleaning may include removing duplicate records, correcting errors, standardizing data formats, etc. The cleaned data will be imported into the asset management system. The asset management system is a centralized database that stores and manages relevant information of all network assets. After importing the cleaned scanned asset information, the system will update its database based on this information to reflect the current asset status in the network. The asset management system extracts key features from these asset information, which may include IP addresses, MAC addresses, operating system types, service versions, hardware configurations, etc. In order to achieve efficient asset classification, a preset deep learning model is used. The deep learning model can recognize complex patterns and associations in the data through training, which is particularly effective for processing large and diverse asset information. During the training process, the model learns how to classify assets into different categories based on their key features, such as servers, network devices, security devices, etc. Asset classification through deep learning models can achieve automated and intelligent asset management. The classification results not only help with daily monitoring and maintenance of assets, but also provide support for security policy formulation, risk assessment, and compliance reporting.
[0072] It can be understood that the present invention can automatically complete the acquisition and classification of asset information, greatly improving the efficiency and accuracy of risk management. Through the steps of data cleaning and importing into the asset management system, the accuracy and completeness of asset information are ensured, providing reliable basic data for subsequent risk analysis. At the same time, the use of deep learning models for asset classification can more accurately identify different types of assets and provide more refined data support for subsequent risk assessment.
[0073] In some embodiments of the present application, based on the asset information, graph database technology is used to determine the connection relationship between each asset and construct a network topology diagram, including: the asset information includes asset type, IP address, MAC address, host name, open port, running service and operating system; node and edge types are defined according to the asset information, the asset information is imported into a graph database, and the connection relationship between each asset is determined according to the defined node and edge types, and a network topology diagram is constructed based on the connection relationship.
[0074] In this embodiment, a network topology diagram is constructed, specifically: asset information includes but is not limited to asset type (such as servers, terminal devices and security devices, etc.), IP address, MAC address, host name, open ports, running services and operating system type.
[0075] Define node and edge types: In a graph database, asset information is abstracted as nodes, and the connection relationship between assets is represented by edges. Node types are defined based on asset types, such as server nodes, workstation nodes, etc. Edge types are defined based on the connection between assets, such as network connection edges, dependency edges, etc.
[0076] Data import into graph database: Import the collected asset information into the graph database. This step involves data format conversion and data cleaning to ensure data accuracy and completeness.
[0077] Determine the connection relationship: Using the query language of the graph database, based on the defined node and edge types, we can query and determine the connection relationship between assets. For example, by querying IP addresses and open port information, we can find out which assets have direct network connections.
[0078] Build a network topology diagram: Based on the determined connection relationships, a network topology diagram can be built. This diagram will intuitively display the layout of each asset in the network and the connection paths between them, helping network administrators quickly understand the network structure, discover potential security risks, and conduct effective asset management.
[0079] Dynamic update and monitoring: The network topology diagram is not static. As the network environment changes, asset information and connection relationships will also change. Therefore, it is necessary to regularly update the information in the diagram database and monitor the network status in real time to ensure the accuracy and real-time nature of the topology diagram.
[0080] It is understandable that the present invention, by adopting graph database technology, can intuitively display the distribution and connection relationship of assets in the network, so that risk managers can clearly understand the overall structure of the network and the relationship between assets. This network topology diagram not only helps to identify potential risk points and weak links, but also provides strong support for the formulation of targeted risk management strategies. At the same time, the use of graph database technology also greatly improves the efficiency of data processing and query, allowing risk managers to obtain the required information more quickly, thereby making more timely and accurate decisions.
[0081] In some embodiments of the present application, the vulnerabilities existing in each asset are analyzed and an attack graph is generated, including: analyzing the vulnerabilities based on CVSS technology to determine the exploitable indicators of the vulnerabilities; determining the exploitable scores of the vulnerabilities based on the exploitable indicators, and generating an attack graph based on the exploitable scores; the exploitable indicators include attack vectors, attack complexity, permission requirements and user interaction; the types of attack vectors include network, adjacent, local and physical; the attack complexity includes low difficulty and high difficulty; the level of permission requirements includes no level, low level and high level; the user interaction includes no interaction required and interaction required.
[0082] In this embodiment, in order to generate an attack graph, it is first necessary to perform vulnerability analysis on each asset. The following are the vulnerability analysis steps based on CVSS (Common Vulnerability Scoring System) technology:
[0083] Identify vulnerabilities: Scan all assets to identify existing vulnerabilities.
[0084] Vulnerability Assessment: A detailed assessment of each identified vulnerability is performed, including the following CVSS indicators:
[0085] Attack Vector (AV): describes how an attacker can exploit a vulnerability and reflects the conditions required for an attacker to exploit the vulnerability. Types include:
[0086] Network: An attacker can exploit the vulnerability from a remote network.
[0087] Adjacent: The attacker must be on the same subnet, such as via Bluetooth or Wi-Fi.
[0088] Local: The attacker needs physical access or a local login.
[0089] Physical: The attacker needs to directly perform physical manipulation on the asset.
[0090] Attack Complexity (AC): describes the difficulty for an attacker to exploit a vulnerability. It includes:
[0091] Low difficulty: The attacker needs no special conditions or only very few conditions.
[0092] High Difficulty: Attackers need complex conditions to exploit the vulnerability.
[0093] Privilege Requirement (PR): describes the privilege level an attacker needs to exploit the vulnerability. This includes:
[0094] None: No permissions are required.
[0095] Low: The attacker requires limited privileges.
[0096] High: The attacker requires high-level permissions.
[0097] User Interaction (UI): Describes whether the vulnerability exploit requires user interaction. Includes:
[0098] No interaction required (None): No user action is required to exploit the vulnerability.
[0099] Required: Exploitation requires some user action.
[0100] Calculate the exploitability score: Calculate the exploitability score of each vulnerability based on the CVSS scoring formula and the above indicators. The score range is usually from 0 to 10, and the higher the score, the easier it is to exploit.
[0101] Generate attack graph: Use the exploitability scores of the vulnerabilities to build an attack graph. An attack graph is a graphical representation of the relationships between different vulnerabilities and how they can be linked to form attack paths.
[0102] Through the above steps, the vulnerabilities in the assets can be effectively analyzed and an attack graph can be generated to help the security team understand the potential attack scenarios and better protect the network and system security.
[0103] It is understandable that the present invention can intuitively display potential network attack paths and methods by comprehensively analyzing the vulnerabilities of various assets and generating attack graphs. Based on the CVSS technology, a detailed analysis of the vulnerabilities can comprehensively assess the severity and difficulty of exploitation of the vulnerabilities, thereby providing risk managers with more accurate risk assessment information. The generation of attack graphs not only helps to identify the most vulnerable parts of the network, but also provides an important reference for formulating effective security protection measures.
[0104] In some embodiments of the present application, determining a preset attack path includes: determining an initial node and a target node of an attack graph; starting from the initial node, based on the available score, traversing the attack graph, determining all paths to the target node, and setting the path as the preset attack path.
[0105] It is understandable that by determining the preset attack path, it is possible to foresee the possible paths of potential network attacks, which is crucial for developing targeted defense strategies. The clear setting of the initial node and the target node makes the analysis process more targeted and reduces unnecessary analysis burden. Using the traversal method based on exploitable scoring, it is possible to efficiently screen out the paths that are most likely to be exploited by attackers from many possible attack paths. These paths are the preset attack paths.
[0106] In some embodiments of the present application, in combination with network traffic data and attack techniques, a graph neural network is used to analyze the preset attack path to determine the attack path, including: obtaining network traffic data and attack techniques; analyzing the network traffic data to determine normal traffic patterns and abnormal traffic patterns; based on the attack techniques, identifying potential attack behaviors according to the abnormal traffic patterns and determining key attack points; screening the preset attack paths based on the key attack points to determine optional attack paths; evaluating the optional attack paths to determine the risk value and attack efficiency of each optional attack path; screening the optional attack paths based on the risk value and attack efficiency to obtain attack paths.
[0107] In order to effectively analyze and determine the network attack path, a method based on graph neural network (GNN) is proposed. The following are the detailed steps:
[0108] Obtain network traffic data and attack methods:
[0109] Collect network traffic data, including source IP, destination IP, protocol, port, packet size, timestamp, etc. Collect known attack methods, including vulnerability exploits, malware behaviors, social engineering techniques, etc.
[0110] Analyze network traffic data to determine traffic patterns:
[0111] Use data mining techniques to pre-process network traffic data, including data cleaning, normalization, etc. Apply machine learning algorithms, such as cluster analysis, to distinguish between normal and abnormal traffic patterns.
[0112] Identify potential attacks:
[0113] Based on known attack methods, we establish association rules between abnormal traffic patterns and potential attack behaviors. We use graph neural networks to model network traffic and represent network entities (such as hosts, services, and users) and the relationships between them as graph structures. We use GNN to learn graph structure data, identify potential attack behaviors related to abnormal traffic patterns, and determine key attack points.
[0114] Filter preset attack paths:
[0115] According to the identified key attack points, the preset attack paths are screened to exclude those paths that do not contain the key attack points, and the optional attack paths that contain one or more key attack points are retained.
[0116] Evaluate alternative attack paths:
[0117] Evaluate the risk value and attack efficiency of each optional attack path. The risk value can be calculated based on factors such as the concealment, potential impact, and success probability of the attack path. The attack efficiency can be calculated based on factors such as the complexity of the attack path, the required resources, and the completion time.
[0118] Determine the final attack path:
[0119] According to the evaluation results, a decision model (such as a multi-objective optimization algorithm) is used to conduct a final screening of the optional attack paths. The attack path with a lower risk value and higher attack efficiency is selected as the final attack path.
[0120] Through the above steps, graph neural networks are used to conduct in-depth analysis of network attack paths, and effectively identify and determine potential attack paths, thereby providing strong support for network security defense.
[0121] It is understandable that by combining network traffic data and attack techniques, and using graph neural networks to further analyze preset attack paths, enterprises can gain a deeper understanding of the specific characteristics and behavior patterns of potential attacks. Distinguishing between normal and abnormal traffic patterns helps to accurately identify abnormal activities in the network, which is a key step in discovering potential attack behaviors. Identifying potential attack behaviors based on attack techniques and determining key attack points makes the analysis process more focused and can quickly identify possible sources of attacks. Screening preset attack paths, determining optional attack paths, and evaluating the risk value and attack efficiency of each path ensures that the determined attack path is both practical and reflects the highest security threat.
[0122] In some embodiments of the present application, determining the vulnerability of each node on the attack path includes: establishing a vulnerability assessment index; based on the asset information and the vulnerabilities of each asset, assessing the vulnerability of each node according to the vulnerability assessment index; the vulnerability assessment index includes a vulnerability severity index, an exploitability index, a vulnerability impact range index, and a vulnerability repair status index.
[0123] It is understandable that by establishing vulnerability assessment indicators and conducting a detailed assessment of the vulnerability of each node based on asset information and vulnerability conditions, enterprises can fully grasp the security weaknesses of each node on the attack path. The vulnerability severity indicator reflects the degree of harm that the vulnerability itself may cause, providing a key basis for evaluation. The exploitability indicator takes into account the ease with which attackers can exploit the vulnerability, which helps enterprises understand which vulnerabilities are more likely to be exploited and thus prioritize protection. The vulnerability impact range indicator reveals the scope of the vulnerability once it is exploited, which is crucial for assessing the possible consequences of the attack. The vulnerability repair status indicator reflects the company's response to known vulnerabilities, which helps to find which vulnerabilities have not been properly handled, so that timely measures can be taken to repair them.
[0124] In some embodiments of the present application, the security defense system in the attack path is evaluated using simulated attack technology to determine the defense effectiveness of the security defense system in the attack path, including: attacking the security defense system in the attack path based on the simulated attack technology to obtain attack data, the attack data including the number of detected attacks, the total number of attacks, the number of false alarms, the total number of alarms, the detection time, the attack occurrence time, and the number of blocked attacks; evaluating the security defense system based on the attack data to determine defense effectiveness evaluation indicators of the security defense system in the attack path; the defense effectiveness evaluation indicators include detection rate, false alarm rate, response time, and blocking rate.
[0125] In some embodiments of the present application, the detection rate is determined according to the following formula: detection rate = (number of detected attacks / total number of attacks) × 100%; the false alarm rate is determined according to the following formula: false alarm rate = (number of false alarms / total number of alarms) × 100%; the response time is determined according to the following formula: response time = detection time-attack occurrence time; the blocking rate is determined according to the following formula: blocking rate = (number of blocked attacks / total number of attacks) × 100%.
[0126] In this embodiment, by simulating attacks, security experts can identify potential security vulnerabilities and conduct quantitative analysis of the defense effectiveness of the security defense system. This application proposes an evaluation method that evaluates the security defense system in the attack path through simulated attack technology to determine its defense effectiveness. Specifically:
[0127] First, simulated attack technology is used to attack security defense systems in the attack path. In this process, the attacker simulates real attack behaviors to test whether the security defense system can effectively detect and respond to these attacks. Attack data is obtained through simulated attacks, which include the number of detected attacks, the total number of attacks, the number of false alarms, the total number of alarms, the detection time, the time when the attack occurred, and the number of attacks that were successfully blocked.
[0128] Next, based on these attack data, the security defense system is evaluated to determine its defense effectiveness in the attack path. The evaluation indicators include detection rate, false alarm rate, response time and blocking rate. The detection rate measures the ability of the security defense system to detect attacks, the false alarm rate reflects the proportion of false alarms generated by the security defense system during the detection process, the response time refers to the time difference from the occurrence of the attack to the detection of the attack by the security defense system, and the blocking rate measures the proportion of attacks successfully blocked by the security defense system.
[0129] It is understandable that by actually testing the security defense system through simulated attack technology, enterprises can intuitively understand the actual effectiveness of the security defense system. The detection rate indicator reveals the ability of the security defense system to identify attacks. A high detection rate means that the system can detect potential threats in a timely manner. The false alarm rate indicator reflects the accuracy of the system. A low false alarm rate helps reduce unnecessary alarms and improve the efficiency of security operations. The response time indicator measures the speed at which the system detects an attack and responds. A shorter response time helps enterprises respond to attacks quickly and reduce losses. The blocking rate indicator directly reflects the system's ability to defend against attacks. A high blocking rate means that the system can effectively prevent attacks and protect the security of corporate assets.
[0130] In some embodiments of the present application, the method further includes: collecting historical attack data, and performing time series analysis based on a time series prediction model to determine and predict future attack behaviors.
[0131] It is understandable that by collecting and analyzing historical attack data, we can gain insight into the development trends and potential patterns of attack behaviors. The application of time series prediction models enables enterprises to predict future attack behaviors based on historical data, which not only helps enterprises prepare for defense in advance, but also optimizes resource allocation and improves the pertinence and efficiency of security defense.
[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that they can still modify or replace the technical solution of the present invention with equivalents, and these modifications or equivalent replacements cannot cause the modified technical solution to deviate from the spirit and scope of the technical solution of the present invention.
[0133] The system provided in the above embodiment is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the modules or steps in the embodiments of the present invention can be decomposed or combined. For example, the modules in the above embodiment can be combined into one module, or further divided into multiple sub-modules to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present invention are only for distinguishing the modules or steps, and are not regarded as improper limitations of the present invention.
[0134] Those skilled in the art should be able to appreciate that the modules and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software or a combination of the two, and the programs corresponding to the software modules and method steps can be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs or any other form of storage medium known in the technical field. In order to clearly illustrate the interchangeability of electronic hardware and software, the composition and steps of each example have been generally described in the above description according to the function. Whether these functions are performed in electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
Claims
1. A dynamic risk visualization management method for asset and risk management, characterized in that: include: Utilize automated scanning and asset management systems to obtain asset information in the network, and classify assets based on the asset information, including servers, terminal devices, and security devices; Based on the asset information, the connection relationship between the assets is determined using graph database technology to construct a network topology diagram; Based on the vulnerability database and combined with attack graph technology, we analyze the vulnerabilities of each asset, generate attack graphs, and determine the preset attack paths; Combining network traffic data and attack methods, using a graph neural network to analyze the preset attack path to determine the attack path, and determine the vulnerability of each node on the attack path; Using simulated attack technology to evaluate the security defense system in the attack path to determine the defense effectiveness of the security defense system in the attack path; Based on augmented reality and virtual reality technologies, the vulnerabilities, attack paths and defense effectiveness of each asset are dynamically displayed on the network topology diagram.
2. The dynamic risk visualization management method for asset and risk management according to claim 1 is characterized in that: Utilize automated scanning and asset management systems to obtain asset information on the network and classify assets based on the asset information, including: Use automated scanning tools to scan the network and obtain scanned asset information; Cleaning the scanned asset information and importing it into the asset management system, wherein the asset management system is updated based on the imported scanned asset information to obtain asset information in the network; Key features are extracted from the asset information, and asset classification is performed based on a preset deep learning model.
3. The dynamic risk visualization management method for asset and risk management according to claim 1 is characterized in that: Based on the asset information, the connection relationship between the assets is determined using graph database technology to construct a network topology diagram, including: The asset information includes asset type, IP address, MAC address, host name, open ports, running services and operating system; Nodes and edge types are defined according to the asset information, the asset information is imported into a graph database, and connection relationships between assets are determined according to the defined node and edge types, and a network topology diagram is constructed based on the connection relationships.
4. The dynamic risk visualization management method for asset and risk management according to claim 1, characterized in that: Analyze the vulnerabilities of each asset and generate an attack graph, including: Analyze vulnerabilities based on CVSS technology and determine the exploitable indicators of vulnerabilities; Determining an exploitability score of the vulnerability based on the exploitability indicator, and generating an attack graph according to the exploitability score; The exploitable indicators include attack vectors, attack complexity, permission requirements, and user interactions; The types of attack vectors include network, adjacency, local, and physical; The attack complexity includes low difficulty and high difficulty; The levels of permission requirements include no level, low level and high level; The user interaction includes no interaction required and interaction required.
5. The dynamic risk visualization management method for asset and risk management according to claim 4 is characterized in that: Identify the pre-defined attack paths, including: Determine the initial node and target node of the attack graph; Starting from the initial node, based on the exploitable score, the attack graph is traversed to determine all paths to the target node, and the paths are set as preset attack paths.
6. The dynamic risk visualization management method for asset and risk management according to claim 1, characterized in that: Combining network traffic data and attack methods, the graph neural network is used to analyze the preset attack path to determine the attack path, including: Obtain network traffic data and attack methods; Analyzing the network traffic data to determine normal traffic patterns and abnormal traffic patterns; Based on the attack method, identify potential attack behaviors according to the abnormal traffic pattern and determine the key attack points; Screening the preset attack paths based on the key attack points to determine optional attack paths; Evaluate the optional attack paths to determine the risk value and attack efficiency of each optional attack path; The optional attack paths are screened based on the risk value and the attack efficiency to obtain an attack path.
7. The dynamic risk visualization management method for asset and risk management according to claim 1, characterized in that: Determine the vulnerability of each node on the attack path, including: Establish vulnerability assessment indicators; Based on the asset information and the vulnerabilities of each asset, the vulnerability of each node is evaluated according to the vulnerability assessment index; The vulnerability assessment indicators include vulnerability severity indicators, exploitability indicators, vulnerability impact scope indicators and vulnerability repair status indicators.
8. The dynamic risk visualization management method for asset and risk management according to claim 1, characterized in that: The security defense system in the attack path is evaluated by using simulated attack technology to determine the defense effectiveness of the security defense system in the attack path, including: Attacking the security defense system in the attack path based on the simulated attack technology to obtain attack data, the attack data including the number of detected attacks, the total number of attacks, the number of false alarms, the total number of alarms, the detection time, the attack occurrence time and the number of blocked attacks; Evaluate the security defense system based on the attack data to determine a defense effectiveness evaluation index of the security defense system in the attack path; The defense effectiveness evaluation indicators include detection rate, false alarm rate, response time and blocking rate.
9. The dynamic risk visualization management method for asset and risk management according to claim 8, characterized in that: The detection rate is determined according to the following formula: Detection rate = (number of detected attacks / total number of attacks) × 100%; The false alarm rate is determined according to the following formula: False alarm rate = (number of false alarms / total number of alarms) × 100%; The response time is determined according to the following formula: Response time = detection time - attack occurrence time; The blocking rate is determined according to the following formula: Blocking rate = (number of blocked attacks / total number of attacks) × 100%.
10. The dynamic risk visualization management method for asset and risk management according to claim 1, characterized in that: The method further comprises: Collect historical attack data and perform time series analysis based on the time series prediction model to determine and predict future attack behaviors.
Citation Information
Cited By
Safety operation and maintenance auditing system
CN120450650A
Saving insurance evaluation method and system
CN120896719A
A method and system for evaluating the security posture
CN120896719B
Attack path prediction method and device based on asset analysis and graph convolutional neural network
CN121690656A
A closed-loop adaptive security protection method and device for a power monitoring system and a storage medium
CN122697697A