Fusion method of multiple network security frameworks and network security system
Through the converged method of multi-network security frameworks, relevant tasks are identified and assigned and role allocation is determined to solve the problem of limited resources in network security in small and medium-sized enterprises, and the improvement of network security incident response capabilities and defense enhancement in resource-limited environments are achieved.
Patent Information
- Application Number
- CN202510264334.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-13
AI Technical Summary
Small and medium-sized enterprises face limited resources in terms of network security. The existing mature network security framework is not applicable to these enterprises, resulting in them being able to adopt passive defense strategies to affect the development of the enterprise.
A convergence method of multi-network security frameworks is proposed, which can achieve the advantages of multi-framework collaboration by obtaining and converging management information and task lists in different network security frameworks, identifying related tasks, performing role allocation, and determining roles responsible for multiple fields.
In an environment with limited resources, by integrating multiple network security frameworks, the response capabilities of network security incidents can be improved, network security defense can be enhanced, and different development stages and resource conditions of the enterprise.
Smart Images

Figure CN120151006A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technologies, and particularly to a method for integrating multiple network security frameworks and a network security system. Background Art
[0002] With the increasing importance of network security and the growing complexity of network attacks and security threats, many challenges have been brought to the development of enterprises. In this context, it is particularly urgent to form a network security team.
[0003] Currently, large enterprises usually take a series of measures in the cultivation of network security talents, such as clarifying training objectives, optimizing the training methods of talents, and cooperating with universities to jointly promote network security education. At the same time, some enterprises are also actively establishing cooperative relationships with other organizations or teams, such as CSIRT (Computer Security Incident Response Team), security organizations, government agencies, etc., sharing security threat intelligence, and improving threat perception capabilities.
[0004] However, small and medium-sized enterprises face huge challenges in network security. Specifically, although existing mature network security frameworks (such as SIM3 (Security Incident Management Maturity Model) and SOC-CMM (Security Operations Center Maturity Model)) can help improve the response capabilities and operational maturity of CSIRT for network security incidents, they are often not applicable to small and medium-sized enterprises with limited resources, resulting in small and medium-sized enterprises often having to adopt passive defense strategies, which seriously affects the development of enterprises. Summary of the Invention
[0005] The present disclosure is proposed in view of the above situation, and its purpose is to provide a method for integrating multiple network security frameworks and a network security system that can support the application of network security frameworks in an environment with limited resources.
[0006] To this end, a first aspect of the present disclosure provides a method for integrating multiple network security frameworks, including: obtaining a first framework, where the first framework is a network security framework and includes multiple domains, and each of the multiple domains has management information for describing the network security practices of each domain; obtaining a second framework, where the second framework is a network security framework and includes a task list and a role list, each task in the task list has a task description and required first skill information, and each role in the role list has second skill information; identifying tasks related to at least one of the multiple domains from the task list based on the management information and the task description to obtain a target list; performing role assignment on the target list based on a first matching degree between the tasks in the target list and the roles in the role list to obtain an assignment list, where the first matching degree is a second matching degree between the first skill information of the tasks in the target list and the second skill information of the roles in the role list; and determining the roles responsible for the multiple domains based on the assignment list. In this case, the advantages of multiple network security frameworks can be synergistically realized, and the inherent defects of a single framework can be overcome in an environment with limited resources, thereby facilitating the application of network security frameworks in an environment with limited resources. Thus, the response ability to network security events can be improved and network security defenses can be enhanced. Additionally, by integrating multiple network security frameworks, it is convenient to make personalized adjustments to the network security frameworks, enabling enterprises to select domains suitable for their current development stage and resource status.
[0007] In addition, in the integration method related to the first aspect of the present disclosure, optionally, the first framework is CIF-DC and the second framework is SCyWF. In this case, CIF-DC incorporates some features of other network security frameworks (such as SIM3 and SOC-CMM) and pays more attention to infrastructure, internal system protection, and personnel allocation, which is more applicable to small and medium-sized enterprises with scarce resources. Combining with the task assignment and role structure of SCyWF can save the human resource cost of enterprises.
[0008] In addition, in the integration method related to the first aspect of the present disclosure, optionally, after respectively performing NLP-based text processing and TF-IDF processing on the first skill information and the second skill information in sequence, cosine similarity calculation is performed to obtain the second matching degree, and the text processing includes word segmentation, stop word removal, and stemming. Since the two types of skill information come from different frameworks respectively, even for the same or similar skills, there are differences in description. In this case, using NLP can reduce noise to focus on the core content, thereby improving the effect of subsequent cosine similarity calculation.
[0009] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, before performing the role assignment for the target list, tasks in the target list with a task similarity greater than a preset similarity are merged based on the task similarity between tasks in the target list to update the target list. In this case, the number of tasks can be reduced to improve the applicability to resource-constrained environments, and it helps to assign similar tasks to the same role.
[0010] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, tasks with an urgency level greater than a first preset value are queried from the target list as a first list, the tasks in the first list are traversed in descending order of urgency level, roles are assigned to the tasks in the first list, and the load of the role list is updated; after completing the role assignment for the first list, tasks with a complexity level greater than a second preset value other than the first list are queried from the target list as a second list, the tasks in the second list are traversed in descending order of complexity level, roles are assigned to the tasks in the second list, and the load of the role list is updated; after completing the role assignment for the second list, tasks in the target list other than the first list and the second list are used as a third list, roles are assigned to the tasks in the third list, and the load of the role list is updated; after completing the role assignment for the third list, the role assignment for the target list is exited. In this case, the probability that an urgent task is implemented by a suitable role can be increased, and in addition, the risk that an urgent task and a complex task are not implemented due to not being assigned a role can be reduced.
[0011] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, in response to there still being tasks in the first list that have not been assigned a role after completing the role assignment for the first list, the role assignment for the target list is exited; in response to there still being tasks in the third list that have not been assigned a role after completing the role assignment for the third list, the role assignment for the target list is exited; in response to exiting the role assignment for the target list and there being no tasks in the target list that have not been assigned a role, the roles responsible for the multiple domains are determined based on the assignment list. In this case, exiting the role assignment for the target list facilitates adjusting the relevant factors affecting the role assignment for the target list to improve the success rate of the role assignment for the first list, thereby reducing the risk that an urgent task is not implemented due to not being assigned a role. In addition, since the number of tasks in the third list is generally large, if tasks are assigned roles as much as possible in the current role assignment, the load of the roles may be too large. Exiting the role assignment for the target list helps to adjust the relevant factors of the role assignment to optimize the role assignment process.
[0012] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, in response to querying for the role with the smallest load and the highest first matching degree with the task in the first list from the roles with unsaturated load in the role list, the queried role is assigned to the task in the first list and the load of the role list is updated; in response to not querying for the role with the smallest load and the highest first matching degree with the task in the first list from the roles with unsaturated load in the role list, the role with the highest first matching degree with the task in the first list among the roles with unsaturated load in the role list is assigned to the task in the first list and the load of the role list is updated; and / or in response to querying for the role with the highest first matching degree with the task in the second list from the roles with unsaturated load in the role list, the queried role is assigned to the task in the second list and the load of the role list is updated; in response to not querying for the role with the highest first matching degree with the task in the second list from the roles with unsaturated load in the role list, the role with the smallest load among the roles with a first matching degree greater than a third preset value with the task in the second list in the role list is assigned to the task in the second list and the load of the role list is updated; and / or in response to querying for the role with the smallest load and the highest first matching degree with the task in the third list from the roles with unsaturated load in the role list, the queried role is assigned to the task in the third list and the load of the role list is updated; in response to not querying for the role with the smallest load and the highest first matching degree with the task in the third list from the roles with unsaturated load in the role list, the role with the highest first matching degree with the task in the third list among the roles with a load less than a fourth preset value and with unsaturated load in the role list is assigned to the task in the third list and the load of the role list is updated.
[0013] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, in response to exiting the role assignment of the target list and there being tasks in the first list that have not been assigned roles, adjust the maximum load of the roles in the role list according to the first matching degree between the roles and the tasks in the first list that have not been assigned roles; in response to exiting the role assignment of the target list and there being tasks in the third list that have not been assigned roles, merge the tasks that have not been assigned roles according to the task similarity between the tasks in the third list that have not been assigned roles to update the target list and / or adjust the maximum load of the roles in the role list according to the first matching degree between the roles and the tasks in the third list that have not been assigned roles; after updating the target list and / or adjusting the maximum load of the roles in the role list, re-perform role assignment on the target list based on the target list and the role list. Thereby, the probability that the unassigned tasks in the first list and the third list are assigned roles in the next role assignment can be increased.
[0014] In addition, in the fusion method according to the first aspect of the present disclosure, optionally, obtain the implementation status of the target list implemented based on the assignment list, and in response to the implementation status not meeting the preset requirements, adjust the relevant factors affecting the role assignment of the target list according to the implementation status, and re-perform role assignment on the target list, where the relevant factors include at least one of the first matching degree and the maximum load of the roles in the role list. Thereby, the role assignment can be dynamically adjusted according to the implementation status, thereby improving the effectiveness of the implementation of network security measures.
[0015] The second aspect of the present disclosure provides a network security system, including a processor and a memory, where the memory stores a computer program, and when the computer program is executed, it implements the fusion method according to the first aspect of the present disclosure.
[0016] According to the present disclosure, there is provided a fusion method and a network security system for multiple network security frameworks that can support the application of network security frameworks in resource-constrained environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The present disclosure will now be further explained in detail only by way of examples with reference to the accompanying drawings.
[0018] Figure 1 It is a schematic diagram showing CIF-DC involved in the examples of the present disclosure.
[0019] Figure 2 It is an exemplary flowchart showing the fusion method involved in the examples of the present disclosure.
[0020] Figure 3 It is an exemplary flowchart showing the acquisition of the target list involved in the examples of the present disclosure.
[0021] Figure 4 is an exemplary flowchart showing the role assignment of the target list involved in the examples of the present disclosure.
[0022] Figure 5A is an exemplary flowchart showing the role assignment of the first list involved in the examples of the present disclosure. Figure 5B is an exemplary flowchart showing the role assignment of the second list involved in the examples of the present disclosure. Figure 5C is an exemplary flowchart showing the role assignment of the third list involved in the examples of the present disclosure.
[0023] Figure 6 is an exemplary flowchart showing the optimized role assignment involved in the examples of the present disclosure. Detailed implementation manners
[0024] Hereinafter, with reference to the accompanying drawings, the preferred implementation manners of the present disclosure will be described in detail. In the following description, the same reference numerals are given to the same components, and redundant descriptions are omitted. In addition, the drawings are only schematic diagrams, and the proportional relationship of the sizes between components or the shapes of components, etc. may be different from the actual ones. It should be noted that the terms "include" and "have" in the present disclosure and any variations thereof, for example, a process, method, system, product or device including or having a series of steps or units do not necessarily have to be limited to those steps or units clearly listed, but may include or have other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0025] First, relevant terms related to the present disclosure will be introduced.
[0026] A "network security framework" may be a systematic guidance system applied to the field of network security. It generally includes a series of policies, processes, technical guidelines, and best practices to ensure information security, protect infrastructure, respond to network threats, and promote sustainable network security development.
[0027] The examples of the present disclosure relate to a method for integrating multiple network security frameworks (hereinafter simply referred to as the integration method), and this integration method can support the application of network security frameworks in resource-constrained environments. In addition, the integration method related to the examples of the present disclosure may also be referred to as a combination method, an integration method, etc. In some examples, the integration method related to the examples of the present disclosure may be applicable to the scenario of network security management in resource-constrained environments.
[0028] Hereinafter, the examples of the present disclosure will be described in detail with reference to the accompanying drawings. Figure 1It is a schematic diagram showing CIF-DC (CSIRT implementation framework for developing countries, a network security framework proposed in [1]) related to the examples of the present disclosure. Among them, CIF-DC is a network security framework proposed in [1].
[0029] In the network security environment of an enterprise, with the help of a network security framework (which can also be called a network security model), the enterprise can more comprehensively understand its network security environment, so as to more effectively predict and counter potential threats and risks.
[0030] In some examples, a network security framework can include multiple domains, and multiple domains can have network security practices in different aspects. Specifically, each network security practice can contain activities or guidelines related to network security. That is to say, each network security practice can include the network security-related content responsible for the corresponding domain. In some examples, each domain can have management information, and the management information can be used to describe the network security practices (which can also be called network security measures) of each domain.
[0031] Taking the CIF-DC network security framework involved in the examples of the present disclosure as an example, refer to Figure 1 , CIF-DC can include multiple domains, such as a regulations domain, a physical infrastructure domain, an internal system protection domain, a CSIRT service domain, a personnel domain, and a CSIRT technology domain. Each domain can include network security practices. Taking the physical infrastructure domain as an example, the network security practices can include infrastructure convergence, physical access control, and requirements for backup centers.
[0032] In some examples, a network security framework can include content related to human resource management. Specifically, the network security framework can include a task list and a role list. The task list can include at least one task. The role list can include at least one role. Thus, through the network security framework, the tasks and roles in the network security environment can be defined, which is convenient for optimizing task allocation and personnel structure.
[0033] The inventors found through research that for a network security framework with more refined domains, its requirements for human resources are also higher, while a network security framework that is good at human resource management may not be comprehensive enough in domains or its focus is not on domains. In this case, it is difficult to apply a network security framework in an environment with limited resources. Therefore, the inventors proposed the fusion method involved in the examples of the present disclosure, which can fuse the domains of different network security frameworks and human resource management. For the convenience of description below, the network security framework from which the domain comes is called the first framework, and the network security framework from which the task list and the role list come is called the second framework.
[0034] Figure 2 It is an exemplary flowchart showing the fusion method involved in the examples of the present disclosure.
[0035] In some examples, referring to Figure 2 , the fusion method may include obtaining a first framework, where the first framework includes multiple domains (step S101), obtaining a second framework, where the second framework includes a task list and a role list (step S102), identifying tasks related to at least one of the multiple domains from the task list to obtain a target list (step S103), performing role assignment on the target list based on the target list and the role list to obtain an assignment list (step S104), and determining the roles responsible for the multiple domains based on the assignment list (step S105). In this case, it is possible to achieve the synergistic advantages of multiple cybersecurity frameworks (for example, being able to utilize the role list of the second framework to achieve the division of labor in the domains of the first framework), being able to overcome the inherent defects of a single framework in an environment with limited resources, thereby facilitating the application of cybersecurity frameworks in an environment with limited resources. Thus, it is possible to enhance the response ability to cybersecurity incidents and strengthen cybersecurity defenses. Additionally, by integrating multiple cybersecurity frameworks, it is convenient to make personalized adjustments to the cybersecurity frameworks, enabling enterprises to select domains suitable for their current development stage and resource status.
[0036] In some examples, referring to Figure 2 , in step S101, the domains covered by the first framework can be more comprehensive than the second framework described later. Thus, it is possible to provide more refined network practice activities for the cybersecurity environment.
[0037] Additionally, the first framework can be any cybersecurity framework including multiple domains. In some examples, the first framework can be CMMs (Capability Maturity Models, cybersecurity maturity models). In some examples, the first framework can be CIF-DC. In this case, CIF-DC covers more comprehensive domains, and can reduce the risk of missing important links in cybersecurity management.
[0038] Additionally, for CIF-DC, as described above, the multiple domains can include a regulatory domain, a physical infrastructure domain, an internal system protection domain, a CSIRT service domain, a personnel domain, and a CSIRT technology domain. Therefore, CIF-DC has at least the following advantages: a clear and complete regulatory framework, consideration of physical infrastructure, consideration of protecting internal resources of the cybersecurity team, and a complete manpower requirement and training plan. Thus, it is possible to make up for the deficiencies existing in most enterprises when dealing with cybersecurity issues.
[0039] In some examples, referring to Figure 2, in step S102, the second framework may require fewer human resources than the above-mentioned first framework. Thus, the applicability of the network security framework to resource-constrained environments can be improved.
[0040] In addition, the second framework can be any network security framework including a task list and a role list. In some examples, the second framework can be a framework applied to a network security environment and used to define different roles and tasks.
[0041] In some examples, the second framework can be SCyWF (Saudi Cybersecurity Workforce Framework). In this case, SCyWF can define and classify tasks and roles through a structured approach to enable enterprises to clarify the responsibilities and required skills of each role, which helps optimize task allocation in resource-constrained environments, thereby facilitating the alignment of human resources with network security requirements, thus improving the effectiveness of network security measures. On the other hand, it can also help reduce human resource costs, enabling resource-constrained enterprises to obtain the maximum security guarantee effect with the minimum investment.
[0042] In some examples, the first framework can be CIF-DC and the second framework can be SCyW. In this case, CIF-DC incorporates some features of other network security frameworks (such as SIM3 and SOC-CMM) and pays more attention to infrastructure, internal system protection, and personnel allocation, which is more applicable to small and medium-sized enterprises with scarce resources. Combining with the task allocation and role structure of SCyWF can save the human resource costs of enterprises.
[0043] In some examples, for SCyWF, the task list can pre-have multiple tasks (such as 635 tasks). In some examples, for SCyWF, the role list can include the following roles:
[0044] Network security architect. The network security architect can design and plan the network security architecture of the entire network security team (hereinafter referred to as the team) from a macro level.
[0045] Security system designer. The security system designer can be responsible for the design, implementation, and maintenance of the network security system, the selection and configuration of security tools, and the conduct of security testing and verification.
[0046] Compliance officer. The compliance officer can ensure that the team's operational activities comply with laws and regulations and formulate and implement compliance plans.
[0047] Risk assessment expert. The risk assessment expert can ensure that the team's operational activities comply with laws, regulations, and internal policies.
[0048] Security Analyst. A security analyst can conduct a comprehensive analysis of security incidents, collect and apply threat intelligence, formulate and optimize security policies, and investigate and report security incidents.
[0049] Intrusion Detection System Administrator. An intrusion detection system administrator can manage and maintain intrusion detection and prevention systems.
[0050] ICS / OT Expert (Industrial Control Systems / Operational Technology Expert). An ICS / OT expert can focus on the design and optimization of network security architectures and the implementation of security measures.
[0051] Industrial Control System Administrator. An industrial control system administrator can be responsible for the daily operation, maintenance, configuration, and management of ICS systems (Industrial Control Systems).
[0052] In some examples, each task in the task list can have a task description and the required first skill information. In some examples, each role in the role list can have second skill information.
[0053] In some examples, the number of roles in the role list can be fixed (i.e., the roles in the role list are fixed when the second framework is determined and no roles are added or deleted during subsequent processing), and the number of tasks in the task list can be variable (i.e., the task list has an initial value when the second framework is determined and tasks in the task list can be added or deleted during subsequent processing). In this case, while maintaining the role consistency between the network security environment and the roles of the second framework, the tasks can cover multiple areas of the first framework, thus promoting the synergistic advantages of the first framework and the second framework.
[0054] In addition, the task description can be a specific description of a task. In some examples, the skill information (such as the first skill information and the second skill information) can include at least one of professional skills, knowledge, and experience.
[0055] In some examples, the skills of the personnel in the network security team can be evaluated to determine whether they match the second skill information of the role. Thereby, the matching degree between the second framework and the network security team can be improved. For example, data such as the educational background, work experience, professional skills, training records, and historical task performance of the personnel can be collected to evaluate the skills of the personnel. Another example is that the skills of the personnel can be verified through internal or external certifications, such as professional qualification certificates or skill assessment tests.
[0056] Figure 3It is an exemplary flowchart showing the acquisition of a target list related to the examples of the present disclosure.
[0057] In some examples, with reference to Figure 2 , in step S103, the target list may include at least one task, and the task may be related to a domain. That is to say, the tasks in the target list may be tasks related to at least one of multiple domains in the task list. In other words, the tasks in the target list may be sourced from the task list and have a relevant relationship with at least one of multiple domains. For example, the domain of CIF-DC can be mapped to the tasks of SCyWF to determine the tasks of SCyWF corresponding to the domain of CIF-DC.
[0058] In addition, at least one of the multiple domains may be a domain that requires role assignment. In some examples, the domains that require role assignment can be determined according to the enterprise situation. In some examples, the domains that require role assignment can be determined in response to the received user operation. For example, the user can manually select to determine the domains that require role assignment. In some examples, the domains that require role assignment can be adjusted according to the assignment list of the subsequent target list. For example, if it is identified through the assignment list that the role list is not sufficient to cover the target list (that is, the human resources are insufficient), the domains that require role assignment can be reduced. If it is identified through the assignment list that there are a certain number of roles with unsaturated loads in the role list, the domains that require role assignment can be increased.
[0059] In some examples, for each domain, the tasks related to the domain can be identified based on the information with a connection between the domain and the task. In some examples, the information with a connection can be the management information of each domain and the task description of each task. That is to say, the tasks related to at least one of multiple domains can be identified from the task list based on the management information and the task description.
[0060] In some examples, obtaining the target list based on the management information and the task description may include the following steps:
[0061] Step S201: Obtain the domains that require role assignment as the domain list.
[0062] Step S202: Identify the keywords of the management information of each domain in the domain list, and identify the tasks related to each domain in the domain list based on the keywords. That is to say, the tasks are associated with the domains through the keywords.
[0063] In addition, the present disclosure does not limit the manner of identifying keywords and identifying related tasks based on keywords. Those skilled in the art can select appropriate manners according to needs. For example, the manner of identifying keywords may include statistical methods such as TF-IDF and TextRank, and may also include machine learning-based methods. Another example is that the manner of identifying related tasks based on keywords may include rule-based methods such as keyword matching and regular expressions, and may also include machine learning-based methods.
[0064] Step S203: Obtain a target list based on tasks related to all fields in the field list. Specifically, after identifying the related tasks of each field in the field list, the related tasks of multiple fields can be used as the tasks in the target list.
[0065] In some examples, when identifying the related tasks of each field, in response to not identifying a task related to the field or the task related to the field not meeting the requirements of the field, the task list can be updated and the target list can be obtained again. For example, updating the task list can be adding a new task to the task list or updating the task description of the original task.
[0066] In some examples, before performing role assignment for the target list, tasks in the target list with a task similarity greater than a preset similarity (hereinafter simply referred to as task similarity) can be merged to update the target list. In this case, the number of tasks can be reduced to improve the applicability to resource-limited environments, and it helps to assign similar tasks to the same role. It should be noted that unless there is a contradiction, if the target list is updated, subsequent processing (such as role assignment for the target list) is based on the updated target list. In addition, the preset similarity can be set according to needs, and the present disclosure does not specifically limit its specific value.
[0067] In some examples, multiple tasks with a task similarity greater than the preset similarity can be merged into one new task. In some examples, the merged tasks can be used as subtasks of the new task. Thereby, it is convenient to trace the assignment situation of the merged tasks.
[0068] In some examples, before performing role assignment for the target list, tasks that require cross-role collaboration can be identified and disassembled. In this case, the possibility of a task requiring multiple roles to collaborate can be reduced. On the one hand, the complexity of role assignment can be reduced, and on the other hand, the clarity of task assignment can also be improved.
[0069] In some examples, text processing can be performed on the task descriptions of each task in the target list based on NLP (Natural Language Processing), and the text-processed task descriptions can be vectorized to obtain a first vector, and the similarity between the first vectors of the tasks in the target list can be calculated to obtain task similarity. In this case, the automation of obtaining task similarity can be improved, which helps to adapt to the integration of diverse cybersecurity frameworks. In some examples, the text processing based on NLP can include word segmentation, stop word removal, and stemming.
[0070] In some examples, before identifying relevant tasks in a domain, the task list can be adjusted according to the requirements of the domain. Thereby, the probability of identifying relevant tasks can be increased. For example, for the physical infrastructure domain, according to the requirements of the physical infrastructure domain such as the security requirements of data centers, the protection requirements of network devices, and the requirements of physical access control, etc., the tasks of SCyWF can be adjusted. For example, the frequency of data center monitoring can be increased, and the strictness of physical access control can be enhanced.
[0071] Figure 4 is an exemplary flowchart showing the role assignment of the target list involved in the examples of the present disclosure. Figure 5A is an exemplary flowchart showing the role assignment of the first list involved in the examples of the present disclosure. Figure 5B is an exemplary flowchart showing the role assignment of the second list involved in the examples of the present disclosure. Figure 5C is an exemplary flowchart showing the role assignment of the third list involved in the examples of the present disclosure.
[0072] In some examples, referring to Figure 2 , in step S104, the assignment list can represent the correspondence between the tasks of the target list and the roles of the role list. That is, the assignment list can be used to determine the tasks of the target list that are responsible for the roles of the role list. In other words, the assignment list can be used to determine the roles in the role list assigned to the tasks of the target list. Thereby, the role of implementing the task can be determined.
[0073] In some examples, role assignment can be performed on the target list based on the matching degree (hereinafter simply referred to as the first matching degree) between the tasks of the target list and the roles of the role list to obtain an assignment list. In addition, the higher the first matching degree, the more suitable the task is for the role.
[0074] In some examples, the first matching degree can be stored in a storage medium. Thereby, it is convenient to adjust the first matching degree subsequently. In some examples, after initially determining the first matching degree, the first matching degree can be stored in the storage medium; when updating the first matching degree, the first matching degree in the storage medium can be directly updated; when re - performing role assignment subsequently, the first matching degree can be directly read from the storage medium. That is, when re - performing role assignment, the first matching degree can not be reset. Thereby, it is convenient to dynamically adjust the first matching degree to improve the accuracy of the matching degree between tasks and roles.
[0075] In some examples, in the role assignment of each task in the target list, the role with the highest first matching degree among the roles with unsaturated load in the role list can be assigned to the task to obtain an assignment list. That is, among the roles with unsaturated load, the most matching role is selected each time and assigned to the task.
[0076] In some examples, role assignment can be performed on the target list based on the first matching degree, as well as the urgency and complexity of the tasks in the target list to obtain an assignment list. For example, the urgency can be a level from 1 to 5, where 1 means not urgent and 5 means very urgent. The complexity is similar to the urgency.
[0077] In some examples, in role assignment, tasks with an urgency greater than a first preset value can be preferentially assigned. In this case, the probability that an urgent task is implemented by a suitable role can be increased, and in addition, the risk that an urgent task is not implemented due to not being assigned a role can be reduced. In some examples, in role assignment, tasks with an urgency greater than a first preset value can be assigned roles first, followed by tasks with a complexity greater than a second preset value, and finally other tasks in the target list except the aforementioned tasks are assigned.
[0078] In some examples, before starting the role assignment of the target list, the urgency and complexity of each task in the target list can be determined, and the maximum load of each role in the role list can be initialized.
[0079] Specifically, referring to Figure 4 , the role assignment considering the urgency and complexity of tasks can include:
[0080] Step S301: Query tasks with an urgency greater than a first preset value from the target list as a first list, traverse the tasks in the first list in descending order of urgency, assign roles to the tasks in the first list, and update the load of the role list.
[0081] In some examples, in the role assignment of the first list, the role with the smallest load and the highest first matching degree can be preferentially considered. Thereby, the timeliness and quality of the implementation of urgent tasks can be improved.
[0082] In some examples, with reference to Figure 5A , the role assignment of the first list may include:
[0083] Step S401: In response to querying for the role with the smallest load and the highest first matching degree with the task of the first list from the roles with unsaturated load in the role list, the queried role can be assigned to the task of the first list and the load of the role list can be updated.
[0084] Step S402: In response to not querying for the role with the smallest load and the highest first matching degree with the task of the first list from the roles with unsaturated load in the role list, the role with the highest first matching degree with the task of the first list among the roles with unsaturated load in the role list can be assigned to the task of the first list and the load of the role list can be updated.
[0085] Specifically, traverse the tasks of the first list. For each task, in the case where there are roles with unsaturated load (that is, the prerequisite is that there are roles with unsaturated load): If a role with the smallest load and the highest first matching degree can be found, the task is preferentially assigned to it; otherwise, directly find the role with the highest first matching degree (that is, not considering the smallest load) and assign the task to it.
[0086] In some examples, in response to there still being tasks in the first list that have not been assigned roles after completing the role assignment of the first list, the role assignment of the target list can be exited. That is, the subsequent steps are not continued. In this case, it is convenient to adjust the relevant factors (hereinafter simply referred to as assignment factors) that affect the role assignment of the target list to improve the success rate of the role assignment of the first list, thereby being able to reduce the risk that urgent tasks are not implemented due to not being assigned roles. For example, when the loads of all the roles in the role list are saturated, the role assignment can be paused until the tasks in the first list are assigned.
[0087] Step S302: After completing the role assignment of the first list, query tasks with a complexity greater than a second preset value other than the first list from the target list as the second list, traverse the tasks of the second list in descending order of complexity, assign roles to the tasks of the second list, and update the load of the role list. Thereby, the risk that complex tasks are not implemented due to not being assigned roles can be reduced.
[0088] In some examples, in response to failing to query tasks assignable to the second list from roles with unsaturated load in the role list, tasks assignable to the second list can be queried from roles with saturated load in the role list. That is, if no suitable role is queried from roles with unsaturated load, whether the load is saturated can be disregarded. In other words, complex tasks will still be continuously assigned to roles even when the loads are all saturated. Thereby, the success rate of role assignment for the second list can be increased. That is, complex tasks can be assigned to roles as much as possible in the current role assignment. Since the number of complex tasks is small, the impact on role overload is small. In this case, the number of iterations of role assignment can be reduced with a small impact on role overload.
[0089] In some examples, in the role assignment for the second list, the role with the highest first matching degree can be preferentially considered. Thereby, the completion quality of complex tasks can be improved.
[0090] In some examples, referring to Figure 5B , the role assignment for the second list can include:
[0091] Step S501: In response to querying the role with the highest first matching degree for the tasks in the second list from roles with unsaturated load in the role list, assign the queried role to the tasks in the second list and update the load of the role list.
[0092] Step S502: In response to failing to query the role with the highest first matching degree for the tasks in the second list from roles with unsaturated load in the role list, assign the role with the smallest load among the roles with a first matching degree greater than a third preset value for the tasks in the second list in the role list to the tasks in the second list and update the load of the role list.
[0093] Specifically, traverse the tasks in the second list. For each task, when there are roles with unsaturated load, preferentially consider the role with the highest first matching degree. If not found, regardless of whether the load is saturated, assign the task to the role with the smallest load under the condition that the first matching degree is satisfied.
[0094] Step S303: After completing the role assignment for the second list, use the tasks in the target list other than the first list and the second list as the third list, assign roles to the tasks in the third list, and update the load of the role list.
[0095] In some examples, the tasks in the third list can be traversed, roles can be assigned to the tasks in the third list, and the load of the role list can be updated.
[0096] In some examples, in the role assignment for the third list, the load of the role can be preferentially considered. Thereby, the completion degree of ordinary task implementation can be improved.
[0097] In some examples, with reference to Figure 5C , the role assignment for the third list may include:
[0098] Step S601: In response to querying for the role with the smallest load and the highest first matching degree with the task of the third list from the roles with unsaturated load in the role list, assign the queried role to the task of the third list and update the load of the role list.
[0099] Step S602: In response to not querying for the role with the smallest load and the highest first matching degree with the task of the third list from the roles with unsaturated load in the role list, assign the role with the highest first matching degree among the roles with unsaturated load and a load less than the fourth preset value in the role list to the task of the third list and update the load of the role list.
[0100] Specifically, traverse the tasks in the third list. For each task, in the case where there are roles with unsaturated load (i.e., the prerequisite is that there are roles with unsaturated load): If a role with the smallest load and the highest first matching degree can be found, preferentially assign the task to it; otherwise, select the role with the highest first matching degree among the roles with a load less than a certain value.
[0101] In some examples, in response to there still being tasks in the third list that have not been assigned roles after completing the role assignment for the third list, the role assignment for the target list can be exited. Since the number of tasks in the third list is generally large, if tasks are assigned to roles as much as possible in the current role assignment, the load of the roles may become too large. In this case, exiting the role assignment for the target list helps to adjust the assignment factors of the role assignment to optimize the role assignment process.
[0102] Step S304: After completing the role assignment for the third list, exit the role assignment for the target list.
[0103] In some examples, in response to exiting the role assignment for the target list and there being tasks in the target list that have not been assigned roles (hereinafter simply referred to as unassigned tasks), the assignment factors of the role assignment can be adjusted and the role assignment for the target list can be performed again.
[0104] In some examples, the assignment factors may include at least one of the maximum load of the role, the first matching degree, and the number of tasks in the target list. Specifically, the corresponding assignment factors can be selected for adjustment according to the actual situation.
[0105] In some examples, in response to exiting the role assignment for the target list and there being unassigned tasks in the first list, the maximum load capacity of the roles in the role list can be adjusted according to the first matching degree between the roles and the unassigned tasks in the first list. Thereby, the probability that the unassigned tasks in the first list are assigned to roles in the next role assignment can be increased. For example, the maximum load capacity of the roles with a higher matching degree to the unassigned tasks can be increased.
[0106] In some examples, in response to exiting the role assignment for the target list and there being unassigned tasks in the third list, the unassigned tasks can be merged according to the task similarity between the unassigned tasks in the third list to update the target list and / or the maximum load capacity of the roles in the role list can be adjusted according to the first matching degree between the roles and the unassigned tasks in the third list. Thereby, the probability that the unassigned tasks in the third list are assigned to roles in the next role assignment can be increased. For example, some related or similar tasks can be merged to reduce the number of tasks, and the maximum load capacity of the roles with a higher matching degree to the unassigned tasks can be increased according to the actual processing capacity of the roles.
[0107] In some examples, after updating the assignment factors (such as the maximum load capacity of the roles in the target list and / or the role list), the role assignment for the target list can be performed again.
[0108] In addition, the present disclosure does not specifically limit the specific values of the first preset value, the second preset value, the third preset value, and the fourth preset value, and those skilled in the art can adjust them according to the actual situation.
[0109] In addition, the role assignment for completing the corresponding list (such as the target list, the first list, the second list, or the third list) involved in various examples of the present disclosure can mean that role assignment has been attempted for each task in the list, but it is not limited to whether the role is successfully assigned.
[0110] In addition, the update of the load capacity of the role list involved in various examples of the present disclosure can mean that when a role in the role list is assigned a task, the load capacity of the corresponding role is updated. For example, the number of tasks assigned (such as the number of tasks can be 1) can be added to the load capacity of the role. In addition, the load capacity not being saturated can mean that the load capacity is not greater than the maximum load capacity. In addition, the load capacity can refer to the number of tasks currently assigned to the role, and the maximum load capacity can refer to the maximum number of tasks that can be assigned to the role.
[0111] In some examples, the first matching degree can be the matching degree between the first skill information required for the above-mentioned task and the second skill information possessed by the character (hereinafter simply referred to as the second matching degree). That is, the first skill information and the second skill information can be used to determine the first matching degree between a character and a task. In other words, in the character assignment of the target list, the first matching degree can be determined based on the second matching degree between the first skill information of the tasks in the target list and the second skill information of the characters in the character list, and the character assigned to the tasks in the target list can be determined based on the first matching degree, thereby obtaining the assignment list. Thus, it is convenient to automatically obtain the first matching degree.
[0112] In some examples, the first skill information and the second skill information can be vectorized into text and then the similarity is calculated to obtain the second matching degree. In some examples, the similarity calculation can be cosine similarity calculation. In some examples, after the first skill information and the second skill information are respectively and sequentially processed by NLP-based text processing and TF-IDF (Term Frequency-Inverse Document Frequency) processing, the cosine similarity is calculated to obtain the second matching degree. Since the two skill information comes from different frameworks respectively, even for the same or similar skills, there are differences in description. In this case, using NLP can reduce noise to focus on the core content, thereby improving the effect of subsequent cosine similarity calculation. In some examples, the text processing can include word segmentation, stop word removal, and stemming.
[0113] In some examples, the first matching degree can be adjustable. In this case, the flexibility of character assignment can be improved to optimize the character assignment process, which helps to improve the efficiency and quality of task implementation. In some examples, the first matching degree can be adjusted according to the implementation situation of the task. Specifically, the implementation situation of the implemented target list can be obtained, and the first matching degree can be adjusted based on the implementation situation. Thus, it helps to improve the effectiveness of character assignment.
[0114] In some examples, the character assignment of the target list can be performed through at least one iteration until all the tasks in the target list are assigned characters.
[0115] In some examples, the assignment list can be verified to confirm whether each task has been assigned and whether the character assignment is reasonable. If there are unassigned tasks or the load of the characters is too large, the assignment factors of the character assignment can be adjusted.
[0116] In some examples, refer to Figure 2, in step S105, the allocation list can be used to determine the correspondence between the tasks of the determined target list and the roles of the role list. In some examples, based on the correspondence between tasks and roles, and the above-mentioned correlation between tasks and domains, roles responsible for multiple domains can be determined. Thus, it is possible to enable the domains to have the support of corresponding tasks and roles. That is, it is possible to determine the division of labor for multiple domains of the first framework.
[0117] In some examples, in response to exiting the role allocation of the target list and there being no tasks in the target list that have not been assigned roles, roles responsible for multiple domains can be determined based on the allocation list. That is, after determining that all tasks in the target list have been assigned roles, subsequent processing can be continued. Since there is a correlation between at least some of the tasks in the target list (for example, some tasks need to be implemented in parallel or sequentially). In this case, determining that all tasks in the target list have been assigned roles can improve the stability and fluency of network security management.
[0118] Figure 6 It is an exemplary flowchart showing the optimized role allocation involved in the examples of the present disclosure.
[0119] In some examples, the fusion method may further include an optimization step. Refer to Figure 6 , in the optimization step, the implementation situation of the target list implemented based on the allocation list can be obtained (step S701). In response to the implementation situation not meeting the preset requirements, the allocation factors of the role allocation are adjusted according to the implementation situation (step S702), and step S104 is re-executed (that is, the role allocation for the target list is re-performed). Specifically, after implementing the tasks in the target list according to the allocation list, its implementation situation can be monitored and optimized according to the implementation situation. Thus, it is possible to dynamically adjust the role allocation according to the implementation situation, thereby improving the effectiveness of network security measure implementation. In addition, the preset requirements can be any desired requirements for the task implementation process. For example, requirements corresponding to the timeliness, completion quality, completion rate, and completion degree of tasks. Another example is whether the workload of personnel is saturated.
[0120] In some examples, refer to Figure 6 , in response to the implementation situation meeting the preset requirements, step S701 can be continued. That is, the implementation situation of the target list can be continuously monitored.
[0121] In some examples, for the implementation situation, the adjustable allocation factors may include at least one of the first matching degree and the maximum load of the roles in the role list. How to specifically adjust the allocation factors can be identified and determined based on the implementation situation, and the present disclosure does not specifically limit it.
[0122] In addition, the implementation status can be any information related to task implementation. In some examples, the implementation status can include the task status. The task status can include at least one of the completion degree, timeliness, completion quality, and task effect of the task (for example, whether the training and capabilities of personnel have been improved after the completion of the training task). In some examples, the implementation status can also include the role status. The role status can include at least one of the working hours and workload.
[0123] As described above, for the implementation status, the allocation factors can be adjusted. For example, if the working hours of a role are too long and the workload is not much, it may be that the role is unable to handle some tasks, and the first matching degree can be considered for adjustment. Another example is that the working hours of the role match the workload, but there are still unfinished tasks, which may mean that the load of the role is too large, and the maximum load of the role can be considered for adjustment. Another example is that if an urgent task is completed overtime or a complex task fails to be completed, the first matching degree can be considered for reduction.
[0124] Examples of the present disclosure also relate to a network security system, including a processor and a memory. The memory can store a computer program, and when the computer program is executed, one or more steps in the above-mentioned fusion method are implemented.
[0125] Examples of the present disclosure also relate to a computer-readable storage medium, which can store at least one instruction, and when the at least one instruction is executed by a processor, one or more steps in the above-mentioned fusion method are implemented. Among them, the computer-readable storage medium can include, but is not limited to, any type of disk, including floppy disks, optical discs, DVDs, CD-ROMs, microdrives, and magneto-optical discs, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), or any type of medium or device suitable for storing instructions and / or data.
[0126] Although the present disclosure has been specifically described above in conjunction with the drawings and examples, it can be understood that the above description does not limit the present disclosure in any form. Those skilled in the art can make deformations and changes to the present disclosure according to needs without departing from the essence and scope of the present disclosure, and these deformations and changes all fall within the scope of the present disclosure.
[0127] The literature information cited in the present disclosure is as follows:
[0128] [1]Lee G S, Kim S H, Lee I Y, et al. Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru[J]. The Electronic Journal of Information Systems in Developing Countries, 2025, 91(1): e12350.
Claims
1. A method for integrating multiple network security frameworks, characterized in that: include: Acquire a first framework, the first framework is a network security framework and includes multiple fields, each of the multiple fields has management information, and the management information is used to describe the network security practice of each field; acquire a second framework, the second framework is a network security framework and includes a task list and a role list, each task in the task list has a task description and required first skill information, and each role in the role list has second skill information; identify tasks related to at least one of the multiple fields from the task list based on the management information and the task description to obtain a target list; Based on the first matching degree between the tasks in the target list and the roles in the role list, the target list is assigned roles to obtain an assignment list, wherein the first matching degree is a second matching degree between the first skill information of the tasks in the target list and the second skill information of the roles in the role list; Roles responsible for the plurality of areas are determined based on the assignment list.
2. The fusion method according to claim 1, characterized in that: The first framework is CIF-DC, and the second framework is SCyWF.
3. The fusion method according to claim 1, characterized in that: The first skill information and the second skill information are respectively subjected to NLP-based text processing and TF-IDF processing, and then cosine similarity calculation is performed to obtain the second matching degree, wherein the text processing includes word segmentation, stop word removal and stem extraction.
4. The fusion method according to claim 1, characterized in that: Before the role allocation of the target list is performed, the tasks in the target list whose task similarity is greater than a preset similarity are merged based on the task similarity between the tasks in the target list to update the target list.
5. The fusion method according to claim 1, characterized in that: Tasks with urgency greater than a first preset value are queried from the target list as the first list, the tasks in the first list are traversed in order of urgency from large to small, roles are assigned to the tasks in the first list, and the load of the role list is updated; after completing the role assignment of the first list, tasks with complexity greater than a second preset value other than the first list are queried from the target list as the second list, the tasks in the second list are traversed in order of complexity from large to small, roles are assigned to the tasks in the second list, and the load of the role list is updated; after completing the role assignment of the second list, the tasks in the target list other than the first list and the second list are taken as the third list, roles are assigned to the tasks in the third list, and the load of the role list is updated; after completing the role assignment of the third list, the role assignment of the target list is exited.
6. The fusion method according to claim 5, characterized in that: In response to the fact that after completing the role allocation of the first list, there are still tasks in the first list that are not assigned to roles, exiting the role allocation of the target list; in response to the fact that after completing the role allocation of the third list, there are still tasks in the third list that are not assigned to roles, exiting the role allocation of the target list; in response to exiting the role allocation of the target list and there are no tasks in the target list that are not assigned to roles, determining the roles responsible for the multiple areas based on the allocation list.
7. The fusion method according to claim 5, characterized in that: In response to finding a role with the smallest load and the highest first matching degree with the tasks in the first list from the roles whose load is not saturated in the role list, assigning the queried role to the tasks in the first list and updating the load of the role list; in response to not finding a role with the smallest load and the highest first matching degree with the tasks in the first list from the roles whose load is not saturated in the role list, assigning the role with the highest first matching degree with the tasks in the first list from the roles whose load is not saturated in the role list to the tasks in the first list and updating the load of the role list; and / or In response to finding a role with the highest first matching degree with the task in the second list from the roles whose load is not saturated in the role list, assigning the queried role to the task in the second list and updating the load of the role list; in response to not finding a role with the highest first matching degree with the task in the second list from the roles whose load is not saturated in the role list, assigning the role with the smallest load among the roles in the role list whose first matching degree with the task in the second list is greater than a third preset value to the task in the second list and updating the load of the role list; and / or In response to finding a role with the smallest load and the highest first matching degree with the tasks in the third list from the roles in the role list whose load is not saturated, the queried role is assigned to the tasks in the third list and the load of the role list is updated. In response to not finding a role with the smallest load and the highest first matching degree with the tasks in the third list from the roles in the role list whose load is not saturated, the role with the highest first matching degree with the tasks in the third list among the roles in the role list whose load is not saturated and whose load is less than a fourth preset value is assigned to the tasks in the third list and the load of the role list is updated.
8. The fusion method according to claim 5 or 6, characterized in that: In response to exiting the role assignment of the target list and there being tasks in the first list that are not assigned to the role, adjusting the maximum load of the role in the role list according to a first matching degree between the role and the tasks in the first list that are not assigned to the role; In response to exiting the role assignment of the target list and there being tasks not assigned to roles in the third list, the tasks not assigned to roles in the third list are merged according to the task similarity between the tasks not assigned to roles in the third list to update the target list and / or the maximum load of the roles in the role list is adjusted according to the first matching degree between the roles and the tasks not assigned to roles in the third list; after updating the target list and / or adjusting the maximum load of the roles in the role list, the roles in the target list are reallocated based on the target list and the role list.
9. The fusion method according to claim 1, characterized in that: Obtaining an implementation status of the target list based on the allocation list, and in response to the implementation status not satisfying a preset requirement, adjusting relevant factors affecting the role allocation of the target list according to the implementation status, and reallocating roles for the target list, wherein the relevant factors include at least one of the first matching degree and a maximum load of the roles in the role list.
10. A network security system, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed, the fusion method according to any one of claims 1 to 9 is implemented.