Risk assessment method and device for software supply chain, equipment, medium and program product
By obtaining risk assessment data from each link of the software supply chain and calculating the triangle fuzzy number, entropy value and target weight, the problem of low accuracy of traditional risk assessment methods is solved, and more efficient and accurate risk assessment is achieved.
Patent Information
- Application Number
- CN202510240202.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-24
AI Technical Summary
The risk assessment methods of traditional software supply chains are relatively low in accuracy and cannot effectively evaluate the security risks in all links of the software supply chain.
By obtaining the risk assessment data of the application to be evaluated under different indicators to be evaluated, determining the triangle fuzzy number, entropy value and target weight, and comprehensively evaluating the risk assessment value of the application.
It improves the accuracy of the software supply chain risk assessment, can more objectively reflect the importance of the indicators to be evaluated and the uncertainty of the risk assessment data, reduces the amount of data processing, and improves the evaluation efficiency.
Smart Images

Figure CN120197165A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of risk assessment, and particularly to a risk assessment method, device, equipment, medium, and program product for a software supply chain. Background Art
[0002] With the rapid development of information technology, software applications are becoming increasingly widespread, and at the same time, the resulting security risk issues are becoming increasingly prominent. Especially for the software supply chain of the power system, since each link of the supply chain is not isolated but interconnected and mutually influential, when a security risk occurs in the software supply chain, it will affect all links of the entire supply chain, causing losses to enterprises.
[0003] In the traditional method, the overall risk of the supply chain software is usually subjectively evaluated, resulting in a low accuracy of risk assessment. Summary of the Invention
[0004] Based on this, it is necessary to provide a risk assessment method, device, equipment, medium, and program product for a software supply chain that can improve the accuracy of risk assessment in view of the above technical problems.
[0005] In a first aspect, this application provides a risk assessment method for a software supply chain, including:
[0006] Obtain risk assessment data of the application to be evaluated under different evaluation indicators to be evaluated; the different evaluation indicators to be evaluated are evaluation indicators of the dimension of the software supply chain to which the application to be evaluated belongs;
[0007] For each evaluation indicator to be evaluated, determine the triangular fuzzy number corresponding to the evaluation indicator according to the risk assessment data under the evaluation indicator to be evaluated;
[0008] Determine the entropy value of the evaluation indicator according to the triangular fuzzy number of the evaluation indicator;
[0009] Determine the target weight of each evaluation indicator according to each entropy value;
[0010] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different evaluation value indicators to be evaluated.
[0011] In one embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data; correspondingly, determining the entropy value of the evaluation indicator according to the triangular fuzzy number of the evaluation indicator includes: determining the entropy value of the evaluation indicator according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the evaluation indicator.
[0012] In one embodiment, determining the entropy value corresponding to the index to be evaluated according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the index to be evaluated includes: determining a first difference between the minimum risk assessment data and the expected risk assessment data; determining a second difference between the maximum risk assessment data and the expected risk assessment data; and determining the entropy value of the index to be evaluated according to the first difference and the second difference.
[0013] In one embodiment, determining the entropy value corresponding to the index to be evaluated according to the first difference and the second difference includes: determining a first entropy value parameter according to the first difference; determining a second entropy value parameter according to the second difference; and performing a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value of the index to be evaluated.
[0014] In one embodiment, determining the target weight of each index to be evaluated according to the entropy values includes: determining the total entropy value according to the entropy values corresponding to each index to be evaluated; and for each index to be evaluated, determining the target weight of the corresponding index to be evaluated according to the proportion of the entropy value corresponding to the index to be evaluated in the total entropy value.
[0015] In one embodiment, determining the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different indexes to be evaluated includes: for each index to be evaluated, determining the index risk assessment value of the index to be evaluated according to the risk assessment data and the target weight under the index to be evaluated; and determining the comprehensive risk assessment value of the application to be evaluated according to the index risk assessment values of different indexes to be evaluated.
[0016] In a second aspect, the present application further provides a risk assessment device for a software supply chain, including:
[0017] An acquisition module, configured to acquire risk assessment data of the application to be evaluated under different indexes to be evaluated; the different indexes to be evaluated are evaluation indexes of the software supply chain dimension to which the application to be evaluated belongs;
[0018] A first determination module, configured to, for each index to be evaluated, determine a triangular fuzzy number corresponding to the index to be evaluated according to the risk assessment data under the index to be evaluated;
[0019] A second determination module, configured to determine the entropy value of the index to be evaluated according to the triangular fuzzy number of the index to be evaluated;
[0020] A third determination module, configured to determine the target weight of each index to be evaluated according to the entropy values;
[0021] A fourth determination module, configured to determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different indexes to be evaluated.
[0022] In a third aspect, the present application also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0023] Obtain risk assessment data of the application to be evaluated under different evaluation metrics; the different evaluation metrics are evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0024] For each evaluation metric, determine the triangular fuzzy number corresponding to the evaluation metric according to the risk assessment data under the evaluation metric;
[0025] Determine the entropy value of the evaluation metric according to the triangular fuzzy number of the evaluation metric;
[0026] Determine the target weight of each evaluation metric according to each entropy value;
[0027] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different evaluation value metrics.
[0028] In a fourth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0029] Obtain risk assessment data of the application to be evaluated under different evaluation metrics; the different evaluation metrics are evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0030] For each evaluation metric, determine the triangular fuzzy number corresponding to the evaluation metric according to the risk assessment data under the evaluation metric;
[0031] Determine the entropy value of the evaluation metric according to the triangular fuzzy number of the evaluation metric;
[0032] Determine the target weight of each evaluation metric according to each entropy value;
[0033] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different evaluation value metrics.
[0034] In a fifth aspect, the present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:
[0035] Obtain risk assessment data of the application to be evaluated under different evaluation metrics; the different evaluation metrics are evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0036] For each evaluation metric, determine the triangular fuzzy number corresponding to the evaluation metric according to the risk assessment data under the evaluation metric;
[0037] Determine the entropy value of the index to be evaluated according to the triangular fuzzy number of the index to be evaluated;
[0038] Determine the target weight of each index to be evaluated according to each entropy value;
[0039] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different indexes to be evaluated.
[0040] The above-mentioned risk assessment method, device, equipment, medium and program product of the software supply chain obtain the risk assessment data of the application to be evaluated under different indexes to be evaluated, thus providing an original data basis for the comprehensive risk assessment value of the application to be evaluated. For each index to be evaluated, according to the risk assessment data under the index to be evaluated, determine the corresponding triangular fuzzy number of the index to be evaluated, so as to reflect the uncertainty of the risk assessment data under each index to be evaluated. At the same time, determining the comprehensive risk assessment value based on the triangular fuzzy number is also beneficial to reducing the data processing volume and improving the evaluation efficiency. By determining the entropy value of the index to be evaluated according to the triangular fuzzy number of the index to be evaluated, the degree of chaos of the risk assessment data under each index to be evaluated can be reflected. The greater the degree of chaos, the greater the information uncertainty or dispersion degree corresponding to the index to be evaluated. Accordingly, assign corresponding weights to different indexes to be evaluated, and realize the objective quantification of the importance of the indexes to be evaluated. Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different indexes to be evaluated, realize the risk assessment of the application to be evaluated, and improve the accuracy of the risk assessment result. Description of the Drawings
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained according to these drawings.
[0042] Figure 1 It is a schematic flowchart of the risk assessment method of the software supply chain in an embodiment;
[0043] Figure 2 It is a schematic flowchart of the entropy value determination step of the index to be evaluated in an embodiment;
[0044] Figure 3 It is a schematic flowchart of the risk assessment method of the software supply chain in another embodiment;
[0045] Figure 4 It is a structural block diagram of the risk assessment device of the software supply chain in an embodiment;
[0046] Figure 5 It is the internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0047] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0048] In one embodiment, as Figure 1 shown, a risk assessment method for a software supply chain is provided. In this embodiment, an example is given where this method is applied to a terminal. It can be understood that this method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0049] S110. Obtain risk assessment data of the application to be evaluated under different evaluation indicators to be evaluated, where the different evaluation indicators to be evaluated are evaluation indicators of the software supply chain dimension to which the application to be evaluated belongs.
[0050] The risk assessment data can be understood as data used to characterize the performance of the application to be evaluated under the evaluation indicators to be evaluated. Exemplarily, the risk assessment data can be a value between 0 and 1. The larger the value corresponding to the risk assessment data, the greater the security risk evaluated or determined for the application to be evaluated under the corresponding evaluation indicator to be evaluated.
[0051] Exemplarily, the application to be evaluated may include power system software. The evaluation indicators of the software supply chain dimension to which the application to be evaluated belongs may include at least one of software development security indicators, operating environment indicators, development team ability indicators, operation and maintenance guarantee indicators, software open source degree indicators, data backup integrity indicators, and supplier reputation indicators, etc. It should be noted that the present application does not make any limitations on the specific type and quantity of the application to be evaluated, nor does it make any limitations on the type and quantity of the evaluation indicators to be evaluated.
[0052] Among them, the software development security indicators may include at least one of the following: software vulnerability situation, code complexity, and software update frequency, etc. It is not difficult to understand that software vulnerabilities may become the entry point for attackers; code complexity affects the maintenance difficulty and potential security risks; the software update frequency reflects the response speed to software security issues.
[0053] Among them, the operating environment indicators may include at least one of the compatibility of hardware devices, the stability of the operating environment, and the network topology of the power system. It is not difficult to understand that different network topologies may affect the spread range of attacks, the compatibility of hardware devices may cause abnormal software operation, and the instability of the operating environment may increase the vulnerability of the system to attacks.
[0054] Among them, the development team ability indicators may include at least one of the technical level of the development team and the standardization of the development process.
[0055] Exemplarily, based on the historical data of the application to be evaluated under the to-be-evaluated indicators, the risk assessment data of the corresponding to-be-evaluated indicators can be determined.
[0056] In an alternative embodiment, the risk assessment data can be determined based on different risk assessment data algorithms under the to-be-evaluated indicators. Exemplarily, the risk assessment data algorithm can divide the historical system data intervals of the to-be-evaluated indicators under different risk assessment data, and then determine the corresponding risk assessment data according to the historical system data interval where the historical data is located. The risk assessment data algorithm can be set by technicians according to actual needs, and the present application does not make any limitation on the risk assessment data algorithm.
[0057] In another alternative embodiment, based on the historical data under the to-be-evaluated indicators, the risk assessment data of the corresponding to-be-evaluated indicators can be determined by the probabilistic risk assessment method or the expert scoring method.
[0058] In yet another alternative embodiment, the above two methods can be combined to jointly determine the risk assessment data of the corresponding to-be-evaluated indicators.
[0059] Exemplarily, the historical data of the operation and maintenance guarantee indicators may include historical vulnerability data and repair data within a first preset time period. The repair data may include at least one of the repair data for starting repair within 3-5 working days and the repair data for completing repair within 1-2 weeks.
[0060] Exemplarily, the historical data of the data backup integrity may include historical data loss data and backup recovery data within a second preset time period. The backup recovery data may include at least one of the backup recovery time, the backup recovery success rate, and the backup recovery accuracy rate.
[0061] S120. For each to-be-evaluated indicator, according to the risk assessment data under the to-be-evaluated indicator, determine the triangular fuzzy number corresponding to the to-be-evaluated indicator.
[0062] Among them, the triangular fuzzy number can be understood as a special form of the fuzzy number, and its membership function presents a triangular distribution on the real number set R. Let a and c be the lower and upper limits of the fuzzy number respectively, and b be the value with the greatest possibility or the expected value. Then the triangular fuzzy number can be represented by (a, b, c).
[0063] In an optional embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data. Among them, the expected risk assessment data can be the median or mean value of the assessments in the risk assessment data. Exemplarily, before determining the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data from the risk assessment data, data cleaning and normalization processing can also be performed on the risk assessment data under the to-be-evaluated index.
[0064] For the sake of illustration, take the triangular fuzzy number (0.6, 0.7, 0.8) corresponding to the supplier credibility index as an example. Among them, 0.6 represents the minimum risk assessment data under the supplier credibility index; 0.8 represents the maximum risk assessment data under the supplier credibility index; 0.7 represents the expected risk assessment data under the supplier credibility index.
[0065] S130. Determine the entropy value of the to-be-evaluated index according to the triangular fuzzy number of the to-be-evaluated index.
[0066] Among them, the entropy value of the to-be-evaluated index is used to characterize the degree of chaos of the risk assessment data under the to-be-evaluated index, that is, the degree of uncertainty. The larger the entropy value of the to-be-evaluated index, the more chaotic the risk assessment data, and the greater the uncertainty of the evaluation result. Correspondingly, the risk corresponding to the to-be-evaluated index is greater, so more attention needs to be paid. On the contrary, the smaller the entropy value of the to-be-evaluated index, the more orderly the risk assessment data, and the smaller the uncertainty of the evaluation result.
[0067] In an optional embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data. Correspondingly, the entropy value of the to-be-evaluated index can be determined according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the to-be-evaluated index.
[0068] S140. Determine the target weight of each to-be-evaluated index according to each entropy value.
[0069] It can be understood that the entropy values of each evaluation index to be evaluated have been determined in the foregoing steps. In this step, according to each entropy value, the target weight of each evaluation index to be evaluated is determined, and a larger target weight is assigned to the evaluation index to be evaluated with a larger entropy value, so as to improve the accuracy of the risk assessment result. It is not difficult to understand that the target weight characterizes the relative importance of the evaluation index to be evaluated, so as to facilitate the subsequent determination of the comprehensive risk assessment value of the application to be evaluated.
[0070] In an optional embodiment, according to the entropy values corresponding to each evaluation index to be evaluated, the target weights of different evaluation indexes to be evaluated are determined, including: according to the entropy values corresponding to each evaluation index to be evaluated, the total entropy value is determined; for each evaluation index to be evaluated, according to the proportion of the entropy value corresponding to the evaluation index in the total entropy value, the target weight of the corresponding evaluation index to be evaluated is determined.
[0071] For ease of understanding, an example is given below. For example, the entropy value corresponding to the supplier credibility index is 0.3; the entropy value corresponding to the software open source degree index is 0.4; the entropy value corresponding to the software development security index is 0.25; the entropy value corresponding to the development team ability index is 0.35; the entropy value corresponding to the operation and maintenance guarantee index is 0.2; the entropy value corresponding to the data backup integrity index is 0.3.
[0072] From this, it can be determined that the total entropy value is 1.8. The target weight of the supplier credibility index is the proportion of the entropy value corresponding to this index in the total entropy value, that is: 0.3 / 1.8 = 0.167. Correspondingly, the target weight of the software open source degree index is 0.222; the target weight of the code security index is 0.139; the target weight of the software development security index is 0.194; the target weight of the operation and maintenance guarantee index is 0.111; the target weight of the data backup integrity index is 0.167.
[0073] S150. According to the risk assessment data and the corresponding target weights under different evaluation values to be evaluated, determine the comprehensive risk assessment value of the application to be evaluated.
[0074] In an optional embodiment, for each evaluation index to be evaluated, according to the risk assessment data and the target weight under the evaluation index to be evaluated, the index risk assessment value of the evaluation index to be evaluated can be determined; according to the index risk assessment values of different evaluation indexes to be evaluated, the comprehensive risk assessment value of the application to be evaluated is determined.
[0075] In some embodiments, the index risk assessment values of different evaluation indexes to be evaluated can be accumulated to obtain the comprehensive risk assessment value of the application to be evaluated.
[0076] In some embodiments, according to the minimum risk assessment data, the expected risk assessment data, the maximum risk assessment data and the target weight under the evaluation index to be evaluated, the index risk assessment value of the evaluation index to be evaluated can be determined.
[0077] Optionally, the product of the minimum risk assessment data and the target weight can be used as the first assessment value; the product of the expected risk assessment data and the target weight can be used as the second assessment value; the product of the maximum risk assessment data and the target weight can be used as the third assessment value; the first assessment value, the second assessment value, and the third assessment value are added together to obtain the index risk assessment value of the index to be evaluated.
[0078] In some other embodiments, the index risk assessment value of the index to be evaluated can be determined according to each risk assessment data and the target weight under the index to be evaluated. Optionally, the average risk assessment data of the index to be evaluated can be determined according to each risk assessment data under the index to be evaluated; the product of the average risk assessment data and the target weight is used as the index risk assessment value of the index to be evaluated.
[0079] In some embodiments, multiple risk levels can be preset in advance, and each risk level corresponds to a comprehensive risk assessment value interval. Exemplarily, three risk levels can be set, namely, a low risk level, a medium risk level, and a high risk level. If the comprehensive risk assessment value is less than the first risk assessment value, the application to be evaluated is at the low risk level; if the comprehensive risk assessment value is not less than the first risk assessment value and less than the second risk assessment value, the application to be evaluated is at the medium risk level; if the comprehensive risk assessment value is not less than the second risk assessment value, the application to be evaluated is at the high risk level. Among them, the first risk assessment value is less than the second risk assessment value. It should be noted that the first risk assessment value and the second risk assessment value can be set by those skilled in the art according to needs or experience, and the present application does not make any limitations in this regard. Exemplarily, the first risk assessment value can be 0.3, and the second risk assessment value can be 0.7.
[0080] Taking the index risk assessment value of the application to be evaluated as 0.633 as an example, the risk level is the medium risk level, indicating that there are certain security risks in the application to be evaluated in terms of security. To further reduce the security risk, each link of the supply chain corresponding to the application to be evaluated can be analyzed, so as to further identify security vulnerabilities and potential threats, and formulate corresponding improvement measures to monitor the change of the security level. Exemplarily, the index risk assessment values corresponding to each index to be evaluated can be used as the optimization basis, so as to formulate improvement measures targeted and improve work efficiency.
[0081] In an alternative embodiment, the comprehensive risk assessment value and the risk level corresponding to each application to be evaluated can be presented in a visual manner to facilitate intuitively determining the risk status of each application to be evaluated.
[0082] In the embodiments of the present application, by obtaining the risk assessment data of the application to be evaluated under different evaluation indicators, an original data basis is provided for the comprehensive risk assessment value of the application to be evaluated. For each evaluation indicator, according to the risk assessment data under the evaluation indicator, the triangular fuzzy number corresponding to the evaluation indicator is determined, which can reflect the uncertainty of the risk assessment data under each evaluation indicator. At the same time, determining the comprehensive risk assessment value based on the triangular fuzzy number is also beneficial to reducing the data processing volume and improving the evaluation efficiency. By determining the entropy value of the evaluation indicator according to the triangular fuzzy number of the evaluation indicator, the degree of chaos of the risk assessment data under each evaluation indicator can be reflected. The greater the degree of chaos, the greater the information uncertainty or dispersion degree corresponding to the evaluation indicator. Accordingly, corresponding weights are assigned to different evaluation indicators, realizing the objective quantification of the importance of the evaluation indicators. According to the risk assessment data and the corresponding target weights under different evaluation value indicators, the comprehensive risk assessment value of the application to be evaluated is determined, realizing the risk assessment of the application to be evaluated and improving the accuracy of the risk assessment result.
[0083] On the basis of the technical solutions of the above embodiments, the present application also provides an alternative embodiment. In this alternative embodiment, the step of determining the entropy value of the evaluation indicator is refined.
[0084] See Figure 2 The steps for determining the entropy value of the evaluation indicator shown include:
[0085] S210. Determine the first difference between the minimum risk assessment data and the expected risk assessment data.
[0086] S220. Determine the second difference between the maximum risk assessment data and the expected risk assessment data.
[0087] S230. Determine the entropy value of the evaluation indicator according to the first difference and the second difference.
[0088] In an alternative embodiment, the first entropy value parameter can be determined according to the first difference; the second entropy value parameter can be determined according to the second difference; and the weighted sum of the first entropy value parameter and the second entropy value parameter is obtained to get the entropy value of the evaluation indicator.
[0089] Optionally, the first entropy value parameter E1 can be determined according to the following formula:
[0090] E1 = |a - b| * ln|a - b|;
[0091] Wherein, E1 represents the first entropy value parameter, a represents the minimum risk assessment data, and b represents the expected risk assessment data.
[0092] Optionally, the second entropy value parameter E2 can be determined according to the following formula:
[0093] E2 = |c - b| * ln|c - b|;
[0094] Wherein, E2 represents the second entropy value parameter, b represents the expected risk assessment data, and c represents the maximum risk assessment data.
[0095] Optionally, the entropy value E corresponding to the index to be evaluated can be determined according to the following formula:
[0096] .
[0097] In another optional embodiment, the entropy value E of the index to be evaluated can also be determined according to the following formula:
[0098] ;
[0099] Wherein, E represents the entropy value of the index to be evaluated; a represents the minimum risk assessment data; b represents the expected risk assessment data; c represents the maximum risk assessment data.
[0100] Based on the technical solutions of the above embodiments, the present application also provides an optional embodiment, in which the risk assessment method for the software supply chain is described in detail.
[0101] See Figure 3 The risk assessment method for the software supply chain shown, including:
[0102] S301. Obtain the risk assessment data of the application to be evaluated under different indexes to be evaluated, and the different indexes to be evaluated are the evaluation indexes of the software supply chain dimension to which the application to be evaluated belongs.
[0103] S302. For each index to be evaluated, determine the triangular fuzzy number corresponding to the index to be evaluated according to the risk assessment data under the index to be evaluated; the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data.
[0104] S303. Determine the first difference between the minimum risk assessment data and the expected risk assessment data.
[0105] S304. Determine the second difference between the maximum risk assessment data and the expected risk assessment data.
[0106] S305. Determine the first entropy value parameter according to the first difference.
[0107] S306. Determine the second entropy value parameter according to the second difference.
[0108] S307. Perform a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value corresponding to the index to be evaluated.
[0109] S308. Determine the total entropy value according to the entropy values corresponding to each index to be evaluated.
[0110] S309. For each index to be evaluated, determine the target weight of the corresponding index to be evaluated according to the proportion of the entropy value corresponding to the index to be evaluated in the total entropy value.
[0111] S310. For each index to be evaluated, determine the index risk assessment value of the index to be evaluated according to the risk assessment data and the target weight under the index to be evaluated.
[0112] S311. Determine the comprehensive risk assessment value of the application to be evaluated according to the index risk assessment values of different indexes to be evaluated.
[0113] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indications of the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0114] Based on the same inventive concept, the embodiments of the present application also provide a risk assessment device for implementing the above-mentioned software supply chain risk assessment method, corresponding to the software supply chain risk assessment device. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more of the following risk assessment device embodiments can refer to the limitations on the software supply chain risk assessment method in the above text, and will not be repeated here.
[0115] In an exemplary embodiment, as Figure 4 shown, a risk assessment device for a software supply chain is provided, including: an acquisition module 410, a first determination module 420, a second determination module 430, a third determination module 440, and a fourth determination module 450, where:
[0116] The acquisition module 410 is configured to acquire risk assessment data of the application to be evaluated under different indexes to be evaluated; the different indexes to be evaluated are evaluation indexes of the software supply chain dimension to which the application to be evaluated belongs.
[0117] The first determination module 420 is configured to determine, for each index to be evaluated, a triangular fuzzy number corresponding to the index to be evaluated according to the risk assessment data under the index to be evaluated.
[0118] The second determination module 430 is configured to determine the entropy value of the index to be evaluated according to the triangular fuzzy number of the index to be evaluated.
[0119] The third determination module 440 determines the target weight of each index to be evaluated according to the entropy values.
[0120] The fourth determination module 450 determines the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different indexes to be evaluated.
[0121] In one embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data; correspondingly, the second determination module 430 includes a first determination unit configured to determine the entropy value of the index to be evaluated according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the index to be evaluated.
[0122] In one embodiment, the first determination unit includes: a first determination subunit configured to determine a first difference between the minimum risk assessment data and the expected risk assessment data; a second determination subunit configured to determine a second difference between the maximum risk assessment data and the expected risk assessment data; and a third determination subunit configured to determine the entropy value corresponding to the index to be evaluated according to the first difference and the second difference.
[0123] In one embodiment, the third determination subunit is specifically configured to: determine a first entropy value parameter according to the first difference; determine a second entropy value parameter according to the second difference; and perform a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value corresponding to the index to be evaluated.
[0124] In one embodiment, the third determination module 440 includes: a second determination unit configured to determine the total entropy value according to the entropy values corresponding to each index to be evaluated; and a third determination unit configured to determine the target weight of the corresponding index to be evaluated according to the proportion of the entropy value corresponding to the index to be evaluated in the total entropy value for each index to be evaluated.
[0125] In one embodiment, the fourth determination module 450 includes: a fourth determination unit configured to determine the index risk assessment value of the index to be evaluated according to the risk assessment data and the target weight of the index to be evaluated for each index to be evaluated; and a fifth determination unit configured to determine the comprehensive risk assessment value of the application to be evaluated according to the index risk assessment values of different indexes to be evaluated.
[0126] Each module in the above risk assessment device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent thereof, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0127] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structural diagram may be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communicating with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a risk assessment method for a software supply chain. The display unit of the computer device is used to form a visually visible picture, which may be a display screen, a projection device, or a virtual reality imaging device. The display screen may be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0128] Those skilled in the art can understand that Figure 5 the structure shown in
[0129] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0130] Obtain risk assessment data of the application to be evaluated under different evaluation metrics; the different evaluation metrics are evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0131] For each evaluation metric, determine the triangular fuzzy number corresponding to the evaluation metric according to the risk assessment data under the evaluation metric;
[0132] Determine the entropy value of the evaluation metric according to the triangular fuzzy number of the evaluation metric;
[0133] Determine the target weight of each evaluation metric according to each entropy value;
[0134] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different evaluation value metrics.
[0135] In one embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data; when the processor executes the computer program, the following steps are further implemented: determine the entropy value of the evaluation metric according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the evaluation metric.
[0136] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the first difference between the minimum risk assessment data and the expected risk assessment data; determine the second difference between the maximum risk assessment data and the expected risk assessment data; determine the entropy value corresponding to the evaluation metric according to the first difference and the second difference.
[0137] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the first entropy value parameter according to the first difference; determine the second entropy value parameter according to the second difference; perform a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value corresponding to the evaluation metric.
[0138] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine the total entropy value according to the entropy values corresponding to each evaluation metric; for each evaluation metric, determine the target weight of the corresponding evaluation metric according to the proportion of the entropy value corresponding to the evaluation metric in the total entropy value.
[0139] In one embodiment, when the processor executes the computer program, the following steps are further implemented: for each evaluation metric, determine the index risk assessment value of the evaluation metric according to the risk assessment data and the target weight under the evaluation metric; determine the comprehensive risk assessment value of the application to be evaluated according to the index risk assessment values of different evaluation metrics.
[0140] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0141] Obtain risk assessment data of the application to be evaluated under different evaluation metrics; the different evaluation metrics are evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0142] For each evaluation metric, determine the triangular fuzzy number corresponding to the evaluation metric according to the risk assessment data under the evaluation metric;
[0143] Determine the entropy value of the evaluation metric according to the triangular fuzzy number of the evaluation metric;
[0144] Determine the target weight of each evaluation metric according to the entropy values;
[0145] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different evaluation value metrics.
[0146] In one embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data; when the computer program is executed by a processor, the following steps are also implemented: determine the entropy value of the evaluation metric according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the evaluation metric.
[0147] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented: determine the first difference between the minimum risk assessment data and the expected risk assessment data; determine the second difference between the maximum risk assessment data and the expected risk assessment data; determine the entropy value corresponding to the evaluation metric according to the first difference and the second difference.
[0148] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented: determine the first entropy value parameter according to the first difference; determine the second entropy value parameter according to the second difference; perform a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value corresponding to the evaluation metric.
[0149] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented: determine the total entropy value according to the entropy values corresponding to each evaluation metric; for each evaluation metric, determine the target weight of the corresponding evaluation metric according to the proportion of the entropy value corresponding to the evaluation metric in the total entropy value.
[0150] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: for each metric to be evaluated, determine the metric risk assessment value of the metric to be evaluated according to the risk assessment data and the target weight under the metric to be evaluated; determine the comprehensive risk assessment value of the application to be evaluated according to the metric risk assessment values of different metrics to be evaluated.
[0151] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0152] Obtain the risk assessment data of the application to be evaluated under different metrics to be evaluated; the different metrics to be evaluated are the evaluation metrics of the software supply chain dimension to which the application to be evaluated belongs;
[0153] For each metric to be evaluated, determine the triangular fuzzy number corresponding to the metric to be evaluated according to the risk assessment data under the metric to be evaluated;
[0154] Determine the entropy value of the metric to be evaluated according to the triangular fuzzy number of the metric to be evaluated;
[0155] Determine the target weight of each metric to be evaluated according to each entropy value;
[0156] Determine the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data and the corresponding target weights under different metric values to be evaluated.
[0157] In one embodiment, the triangular fuzzy number includes the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data determined from the risk assessment data; when the computer program is executed by a processor, the following steps are further implemented: determine the entropy value of the metric to be evaluated according to the minimum risk assessment data, the expected risk assessment data, and the maximum risk assessment data of the metric to be evaluated.
[0158] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine the first difference between the minimum risk assessment data and the expected risk assessment data; determine the second difference between the maximum risk assessment data and the expected risk assessment data; determine the entropy value corresponding to the metric to be evaluated according to the first difference and the second difference.
[0159] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determine the first entropy value parameter according to the first difference; determine the second entropy value parameter according to the second difference; perform a weighted sum on the first entropy value parameter and the second entropy value parameter to obtain the entropy value corresponding to the metric to be evaluated.
[0160] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: determining a total entropy value according to the entropy values corresponding to each evaluation index to be evaluated; for each evaluation index to be evaluated, determining the target weight of the corresponding evaluation index according to the proportion of the entropy value corresponding to the evaluation index to be evaluated in the total entropy value.
[0161] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: for each evaluation index to be evaluated, determining the index risk evaluation value of the evaluation index to be evaluated according to the risk assessment data and the target weight under the evaluation index to be evaluated; determining the comprehensive risk evaluation value of the application to be evaluated according to the index risk evaluation values of different evaluation indexes to be evaluated.
[0162] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0163] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0164] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A software supply chain risk assessment method, characterized in that: The method comprises: Obtain risk assessment data of the application to be assessed on different indicators to be assessed; the different indicators to be assessed are assessment indicators of the software supply chain dimension to which the application to be assessed belongs; For each indicator to be evaluated, determining the triangular fuzzy number corresponding to the indicator to be evaluated according to the risk assessment data under the indicator to be evaluated; Determining the entropy value of the indicator to be evaluated according to the triangular fuzzy number of the indicator to be evaluated; Determine the target weight of each indicator to be evaluated according to each entropy value; The comprehensive risk assessment value of the application to be assessed is determined based on the risk assessment data under different value indicators to be assessed and the corresponding target weights.
2. The method according to claim 1, characterized in that: The triangular fuzzy number includes minimum risk assessment data, expected risk assessment data and maximum risk assessment data determined from the risk assessment data; Correspondingly, determining the entropy value of the indicator to be evaluated according to the triangular fuzzy number of the indicator to be evaluated includes: determining the entropy value of the indicator to be evaluated according to the minimum risk assessment data, expected risk assessment data and maximum risk assessment data of the indicator to be evaluated.
3. The method according to claim 2, characterized in that Determining the entropy value of the indicator to be evaluated according to the minimum risk assessment data, the expected risk assessment data and the maximum risk assessment data of the indicator to be evaluated includes: determining a first difference between the minimum risk assessment data and the expected risk assessment data; determining a second difference between the maximum risk assessment data and the expected risk assessment data; An entropy value of the indicator to be evaluated is determined according to the first difference and the second difference.
4. The method according to claim 3, characterized in that The step of determining the entropy value of the indicator to be evaluated according to the first difference and the second difference includes: Determining a first entropy value parameter according to the first difference; Determining a second entropy parameter according to the second difference; A weighted sum is performed on the first entropy value parameter and the second entropy value parameter to obtain the entropy value of the indicator to be evaluated.
5. The method according to any one of claims 1 to 4, characterized in that: Determining the target weight of each of the indicators to be evaluated according to each of the entropy values includes: According to the entropy value corresponding to each indicator to be evaluated, the total entropy value is determined; For each indicator to be evaluated, the target weight of the corresponding indicator to be evaluated is determined according to the proportion of the entropy value corresponding to the indicator to be evaluated in the total entropy value.
6. The method according to any one of claims 1 to 4, characterized in that: Determining the comprehensive risk assessment value of the application to be assessed based on the risk assessment data and corresponding target weights under different value indicators to be assessed includes: For each indicator to be evaluated, determine the indicator risk assessment value of the indicator to be evaluated based on the risk assessment data and target weight under the indicator to be evaluated; According to the indicator risk assessment values of different indicators to be assessed, a comprehensive risk assessment value of the application to be assessed is determined.
7. A software supply chain risk assessment device, characterized in that: The device comprises: An acquisition module is used to acquire risk assessment data of the application to be evaluated under different indicators to be evaluated; the different indicators to be evaluated are assessment indicators of the software supply chain dimension to which the application to be evaluated belongs; A first determination module is used to determine, for each indicator to be evaluated, a triangular fuzzy number corresponding to the indicator to be evaluated according to risk assessment data under the indicator to be evaluated; A second determination module is used to determine the entropy value of the indicator to be evaluated according to the triangular fuzzy number of the indicator to be evaluated; A third determination module determines the target weight of each of the indicators to be evaluated according to each of the entropy values; The fourth determination module determines the comprehensive risk assessment value of the application to be evaluated according to the risk assessment data under different value indicators to be evaluated and the corresponding target weights.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.