Security attribute development system for network security

Through the security attribute development system of network security, user input and automated processing are used to generate damage scenario descriptions, which solves the problems of development link errors and inconsistent descriptions caused by manual filling of office documents in the prior art, and improves the accuracy and efficiency of network security development.

CN120181052APending Publication Date: 2025-06-20SHENZHEN GECKO NEW ENERGY VEHICLE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510289767.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing network security development process relies on manual filling of office documents, which can easily lead to development link errors and inconsistent descriptions, increasing the difficulty of auditing and the risk of confusing development needs.

Method used

It provides a security attribute development system for network security, including functional scenario input module, asset name input module, asset classification selection module, network security attribute setting module, STRIDE model application module and damage scenario description generation module. It generates damage scenario description through user input and automated processing to reduce manual errors.

Benefits of technology

It improves the accuracy and efficiency of the network security development process, reduces the workload of information security engineers to manually write documents, and allows them to focus more on the analysis of network security attributes and the formulation of response measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120181052A_ABST
    Figure CN120181052A_ABST
Patent Text Reader

Abstract

The invention provides a security attribute development system for network security, which relates to the technical field of automobiles and comprises a BBB. The invention provides a security attribute development system for network security, which is characterized in that after a user fills in a function scene and an asset name and selects an asset classification and a network attribute, a STRIDE model is adopted to automatically generate a description of a security damage scene; the problems of development link errors and inconsistent front and back descriptions easily occurring in a traditional document filling mode are avoided, and the accuracy and efficiency of the development process are improved; the workload of manually compiling documents by information security engineers is reduced, so that the engineers can concentrate on analysis of network security attributes and formulation of countermeasures, and the overall working efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of automobiles, and more particularly, to a security attribute development system for network security. Background Art

[0002] With the rapid development of the automotive industry, the network security issues of vehicles and components have become increasingly prominent. According to the requirements of EU regulation R155, automobiles and components must consider the network security of products throughout their entire life cycle to prevent attackers from launching cyberattacks on vehicles and products, thereby avoiding vehicle function failures or the leakage of relevant information. To meet this regulatory requirement, the network security development of vehicles and components must strictly follow the ISO21434 standard during the vehicle development process; However, the existing network security development process mainly relies on office documents for manual filling, and there are many deficiencies in the implementation of this method. For example, manual filling often easily leads to errors in the development link, and the descriptions before and after cannot be kept consistent, which not only increases the difficulty of review but also may lead to confusion in development requirements. Therefore, we have made improvements in this regard and proposed a security attribute development system for network security. Summary of the Invention

[0003] The purpose of the present invention is to address the problem that the existing network security development process mainly relies on office documents for manual filling, and manual filling often easily leads to errors in the development link.

[0004] To achieve the above-mentioned invention purpose, the present invention provides a security attribute development system for network security to improve the above problems.

[0005] Specifically, this application is as follows: A security attribute development system for network security, comprising: A function scenario input module for receiving the function scenario description input by the user; An asset name input module for receiving the asset name input by the user; An asset classification selection module providing a drop-down menu for the user to select the asset category; A network security attribute setting module for providing network security attributes that can be set by the user according to the asset classification selected by the user; A STRIDE model application module for automatically generating corresponding threat descriptions using the STRIDE model according to the network security attributes set by the user; A damage scenario description generation module for combining the asset name, network security attributes, and threat descriptions, and completing the damage scenario description of this asset according to the user's description, and automatically filling it into a table document; It further includes a control module.

[0006] As a preferred technical solution of the present application, the functional scenario description is made by the user according to the functions of the vehicle or components.

[0007] As a preferred technical solution of the present application, the asset name is described by the user according to the asset content involved in the way of function implementation.

[0008] As a preferred technical solution of the present application, the user selects the asset category by means of a drop-down menu.

[0009] As a preferred technical solution of the present application, the asset categories include data flow, data storage, functional modules, and external entities.

[0010] As a preferred technical solution of the present application, the user can set all the network security attributes involved in the asset according to the classification of the asset.

[0011] As a preferred technical solution of the present application, the network security attributes include authenticity, integrity, non-repudiation, confidentiality, availability, and authorization.

[0012] As a preferred technical solution of the present application, the threat description includes spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. As a preferred technical solution of the present application, it further includes an audit module for auditing the generated damage scenario description to ensure that it is consistent with the information input by the user and meets the requirements of the ISO21434 standard.

[0013] As a preferred technical solution of the present application, it further includes an optimization suggestion module that provides targeted network security optimization suggestions for the user according to the generated damage scenario description.

[0014] Compared with the prior art, the beneficial effects of the present invention are: In the solution of the present application: To solve the problem that the existing network security development process mainly relies on office documents for manual filling, which often easily leads to errors in the development link, this application provides a security attribute development system for network security. After the user fills in the functional scenario and asset name, and selects the asset classification and network attributes, the system automatically generates a description of the security damage scenario using the STRIDE model, avoiding the problems of development link errors and inconsistent descriptions before and after that are prone to occur in the traditional document filling method, improving the accuracy and efficiency of the development process; reducing the workload of information security engineers manually writing documents, enabling them to focus more on the analysis of network security attributes and the formulation of countermeasures, thereby improving the overall work efficiency. Brief Description of the Drawings

[0015] Figure 1 It is a schematic diagram of the security attribute development system for network security provided by this application; Figure 2 It is a simplified flowchart of the security attribute development system for network security provided by this application; Figure 3 It is a flowchart of the security attribute development system for network security provided by this application.

[0016] Labels in the figure: 100, Functional scenario input module; 200, Asset name input module; 300, Asset classification selection module; 400, Network security attribute setting module; 500, STRIDE model application module; 600, Damage scenario description generation module; 700, Control module. Detailed Description of the Embodiment

[0017] In order to enable the personnel in the technical field to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0018] As recorded in the background art, the existing network security development process mainly relies on office documents for manual filling, and there are many deficiencies in the implementation process. For example, manual filling often easily leads to errors in the development link and the descriptions before and after cannot be kept consistent, which not only increases the difficulty of review but also may lead to confusion in development requirements.

[0019] It should be noted that, without conflict, the embodiments and the features and technical solutions in the embodiments in the present invention can be combined with each other.

[0020] It should be noted that like reference numerals and letters refer to like items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0021] For Example 1, please refer to Figures 1-3 , a security attribute development system for network security, comprising: A functional scenario input module 100, configured to receive a functional scenario description input by a user, capable of accurately obtaining the user's understanding basis of network security requirements in a specific scenario, enabling subsequent security attribute development to closely revolve around the actual application scenario, which helps improve the network security adaptability of the system to different functional scenarios, because the network security risks and challenges faced by different functional scenarios are significantly different; An asset name input module 200, configured to receive the asset name input by the user, clarify the specific asset object targeted by the security development, help construct and implement security policies in a targeted manner, improve the accuracy of asset protection, and avoid generalization of security measures due to the determination of the specific asset, and concentrate resources and policies to effectively protect the specific asset; An asset classification selection module 300, which provides a drop-down menu for the user to select asset categories, standardizes the asset classification method, greatly improves the accuracy and efficiency of asset classification, reduces the risk of mistakes in formulating security policies caused by classification confusion, and the drop-down menu form can reduce user input errors. At the same time, the unified classification standard is conducive to the standardized development of subsequent operations such as setting security attributes based on categories; A network security attribute setting module 400, which provides network security attributes that can be set by the user according to the asset classification selected by the user, realizes the intelligent association and matching of network security attributes and asset classification, improves the scientificity and rationality of security attribute setting, makes the security attributes more in line with the asset characteristics, provides corresponding attribute settings based on asset classification, avoids blind attribute setting by the user, and ensures that the attribute setting is closely combined with the actual needs of the asset; A STRIDE model application module 500, which automatically generates corresponding threat descriptions according to the network security attributes set by the user by using the STRIDE model. By using the STRIDE model to automatically generate threat descriptions, it greatly improves the speed and accuracy of threat recognition, reduces the omissions and errors that may occur during manual threat analysis. This model is based on mature security theories and practical experiences, and can comprehensively and systematically sort out and generate descriptions of threats corresponding to various security attributes; The damage scenario description generation module 600 combines the asset name, network security attributes, and threat description, and according to the user's description, completes the damage scenario description of this asset and automatically fills it into the table document, automatically integrating key information to generate the damage scenario description and filling it into the document, improving the document generation efficiency and accuracy, avoiding errors and omissions caused by improper information integration when manually writing the document, and the automated process reduces the manual operation link, ensuring the consistency and integrity of information are reflected in the document; It also includes a control module 700. The functional scenario input module 100, asset name input module 200, asset classification selection module 300, network security attribute setting module 400, STRIDE model application module 500, and damage scenario description generation module 600 are all connected to the control module 700. Through the control module 700, the effective collaboration and management of each functional module are realized, ensuring the stability and orderliness of the operation of the entire system, improving the overall performance of the system. The control module is like the command center of the system, coordinating data interaction and function execution between modules, and avoiding conflicts and incorrect operations between modules.

[0022] This application provides a security attribute development system for network security. After the user fills in the functional scenario and asset name, selects the asset classification and network attributes, the system automatically generates a description of the security damage scenario using the STRIDE model, avoiding the problems of development link errors and inconsistent descriptions before and after that are prone to occur in the traditional document filling method, improving the accuracy and efficiency of the development process; reducing the workload of information security engineers manually writing documents, enabling them to focus more on the analysis of network security attributes and the formulation of countermeasures, thereby improving the overall work efficiency. In Embodiment 2, the security attribute development system for network security provided in Embodiment 1 is further optimized. Specifically, the functional scenario description is made by the user according to the functions of the vehicle or components, making the functional scenario description more targeted and professional, conforming to the network security requirement characteristics in the field of vehicles and components, and improving the effectiveness of the system in the application of this specific field. Because vehicles and components have their unique functional architectures and operation modes, based on this, the functional scenario description can better identify the unique network security risk points and requirement points in this field.

[0023] Furthermore, the asset name is described by the user according to the way of function implementation for the involved asset content, further refining the determination basis of the asset name, making the asset definition clearer and more accurate, facilitating the precise implementation of security protection measures for this asset, and avoiding security vulnerabilities caused by fuzzy asset scope. Describing the asset content based on the function implementation method can accurately grasp its boundary and characteristics from the perspective of the role and function of the asset in the business process, providing an accurate basis for customizing security policies.

[0024] Furthermore, the user selects the asset category through a drop-down menu. The drop-down menu provides a visual and standardized selection method, reducing errors and ambiguities that may occur in free user input and ensuring the consistency and standardization of asset classification. In the network security management of automobile manufacturing enterprises, there are many different types of assets, ranging from production equipment, R & D data to sales management systems, etc.

[0025] Furthermore, as Figure 3 shown, the asset categories include data flow, data storage, functional modules, and external entities. Defining the specific scope of asset categories makes the asset classification system more complete and systematic, helps to comprehensively cover various asset forms that may be involved in the vehicle and parts field, and lays a foundation for all-round network security protection. These asset categories basically cover the key elements of information processing and interaction in this field. Formulating security policies for different categories can achieve comprehensive protection.

[0026] Furthermore, based on the asset classification, the user can set all network security attributes related to the asset, strengthening the correlation between network security attribute settings and asset classification, improving the pertinence and effectiveness of attribute settings, ensuring the most suitable security attributes are matched for different types of assets, and enhancing the overall network security protection level. Different asset categories face different security threats and requirements. Setting attributes according to classification can achieve reasonable allocation and efficient utilization of security resources.

[0027] Furthermore, as Figure 3 shown, the network security attributes include authenticity, integrity, non-repudiation, confidentiality, availability, and authorization. This determines the key set of network security attributes. These attributes comprehensively cover the core aspects of network security, providing a comprehensive and systematic attribute framework for the system to ensure network security of vehicles and parts, and ensuring the prevention of security risks from multiple dimensions. These attributes are key elements obtained through long-term practice and theoretical summary in the field of network security. Their comprehensive application can effectively resist various types of security attacks and threats. For example, the authenticity attribute can prevent the injection of false identities or information, such as preventing malicious attackers from disguising as legitimate vehicle parts to communicate with the vehicle system; the integrity attribute can ensure that data and system components are not illegally modified, such as preventing malicious tampering of vehicle control software leading to security accidents; non-repudiation can be used to trace the responsibility of security incidents, such as being able to determine the source of data leakage in the event of a vehicle data leakage incident; confidentiality can protect sensitive information from being leaked, such as the personal privacy information of vehicle users; availability ensures that the system and assets can be used normally when needed, such as the reliable operation of the vehicle braking system in an emergency; authorization controls the access rights to assets and system functions, preventing unauthorized access and operations, such as restricting unauthorized personnel from accessing the vehicle diagnostic system, thus comprehensively protecting vehicle network security.

[0028] Furthermore, asFigure 3 As shown, threat descriptions include spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege, which clarify the types of threat descriptions generated by the STRIDE model for specific cybersecurity attributes. This enables security personnel to quickly and clearly understand the possible types of threats, facilitating the formulation of targeted countermeasures, improving the timeliness and effectiveness of threat response. These threat descriptions cover common forms of cybersecurity threats, and generating them based on the STRIDE model ensures the comprehensiveness and accuracy of threat identification, providing a precise direction for subsequent defense work.

[0029] Example 3 further optimizes the cybersecurity attribute development system provided in Example 1 or 2. Specifically, it also includes an audit module for auditing the generated damage scenario description to ensure its consistency with the information input by the user and compliance with the requirements of the ISO21434 standard. The audit module guarantees the accuracy and standardization of the damage scenario description, making it meet international standard requirements, improving the credibility and referenceability of the system output results, and facilitating communication and collaboration in cybersecurity work within a wider industry scope.

[0030] Furthermore, it also includes an optimization suggestion module that provides targeted cybersecurity optimization suggestions for the user based on the generated damage scenario description, helping the user promptly discover and solve potential cybersecurity problems, enhancing the perfection and advancement of the cybersecurity protection system, and strengthening the system's ability to prevent and respond to cybersecurity risks. Generating optimization suggestions based on the damage scenario description can deeply analyze the deficiencies in the existing security situation and provide practical improvement directions, promoting the continuous improvement of the cybersecurity protection level.

[0031] The usage process of the cybersecurity attribute development system provided by the present invention is as follows: Functional scenario: Described by the user according to the functions of the vehicle or components; Asset name: Described by the user according to the way the function is implemented, including the asset content involved in this function; Asset classification: The user selects the asset category through a drop-down menu. This asset category includes data flow, data storage, functional modules, and external entities; Cybersecurity attributes: The user can set all the cybersecurity attributes involved in this asset according to the asset category, including authenticity, integrity, non-repudiation, confidentiality, availability, and authorization; The system will automatically generate corresponding threat descriptions according to the network security attributes using the STRIDE model, including spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege; After the above steps are completed, the automated tool combines the asset name, network security attributes, and threat descriptions, and completes the description of the damage scenario for this asset according to the user's description, and automatically fills it into the form document.

[0032] In the present invention, unless otherwise clearly specified and defined, terms such as "installation", "connection", "connection", "fixation", etc. should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can be a mechanical connection, an electrical connection, or communicable with each other; it can be directly connected, or indirectly connected through an intermediate medium, and can be the communication inside two components or the interaction relationship between two components, unless otherwise clearly defined. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0033] Obviously, the above-described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. The accompanying drawings show the preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present invention more thorough and comprehensive. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements for some of the technical features. Any equivalent structure using the content of the specification and drawings of the present invention, directly or indirectly applied in other related technical fields, is similarly within the scope of the patent protection of the present invention.

Claims

1. A network security security attribute development system, characterized in that: include: A function scenario input module (100), used to receive a function scenario description input by a user; An asset name input module (200), used to receive an asset name input by a user; An asset classification selection module (300) provides a drop-down menu for the user to select an asset category; A network security attribute setting module (400) provides network security attributes that can be set by the user according to the asset classification selected by the user; A STRIDE model application module (500) automatically generates a corresponding threat description using the STRIDE model according to the network security attributes set by the user; The damage scenario description generation module (600) combines the asset name, network security attributes, and threat description, completes the damage scenario description of the asset according to the user's description, and automatically fills it into the table document; Also included is a control module (700).

2. The network security attribute development system according to claim 1, characterized in that: Functional scenario descriptions are made by users based on the functions of vehicles or components.

3. The network security security attribute development system according to claim 1, characterized in that: The asset name is used by the user to describe the asset content involved according to the way the function is implemented.

4. The network security security attribute development system according to claim 1, characterized in that: Users select asset categories through the drop-down menu.

5. The network security attribute development system according to claim 1, characterized in that: The asset categories include data flows, data storage, functional modules, and external entities.

6. The network security security attribute development system according to claim 1, characterized in that: Users can set all network security attributes related to assets based on asset classification.

7. The network security security attribute development system according to claim 1, characterized in that: The network security attributes include authenticity, integrity, non-repudiation, confidentiality, availability, and authorization.

8. The network security attribute development system according to claim 1, characterized in that: The threats described include spoofing, tampering, repudiation, information disclosure, denial of service, and escalation of privileges.

9. The network security attribute development system according to claim 1, characterized in that: It also includes an audit module for reviewing the generated damage scenario description to ensure that it is consistent with the information entered by the user and complies with the requirements of the ISO21434 standard.

10. The network security attribute development system according to claim 1, characterized in that: It also includes an optimization suggestion module, which provides users with targeted network security optimization suggestions based on the generated damage scenario description.