Power grid key information asset security threat level measurement evaluation method

Through distributed data collection and big data asset portrait technology, combined with the security threat index measurement model of the power grid key information assets, the problem that the existing technology cannot objectively evaluate the security threat of the power grid key information assets is solved, and the accurate assessment and threat level division of the asset security of the power communication network are achieved.

CN120223348APending Publication Date: 2025-06-27ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411515601.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-29
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing security threat assessment methods for key grid information assets cannot objectively evaluate the risk of threats, and cannot distinguish the degree of threats that the same threat acts in different network locations.

Method used

The distributed deployment S6000 platform is used for data acquisition, and the entire network data is collected through concurrent means, and different acquisition frequencies are used according to the data characteristics. Based on big data asset portrait technology and the measurement model of the security threat indicator of the power grid key information asset, a portrait of the asset being threatened is constructed, and the asset threat level is divided through cluster analysis.

Benefits of technology

An objective assessment of the asset security of power communication networks is achieved, which can accurately distinguish the degree of threats to different assets and helps security operation and maintenance personnel to accurately prioritize the assets with the highest vulnerability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223348A_ABST
    Figure CN120223348A_ABST
Patent Text Reader

Abstract

The invention provides a power grid key information asset security threat level measurement evaluation method. The method comprises the following steps: step 1, deploying an S6000 platform in a distributed manner for data acquisition; during data acquisition, data of the whole network are acquired in a concurrent mode, and different acquisition frequencies are used according to different characteristics of the acquired data; step 2, asset portraying based on big data; and step 3, establishing a power grid key information asset security threat index measurement model to carry out power grid key information asset security threat level measurement evaluation. By applying the technical scheme, the asset security research on the power communication network can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power network information systems, and particularly to a method for hierarchical measurement and evaluation of security threats to key information assets of a power grid. Background Art

[0002] At present, power network information systems encounter various network threat attacks during actual operation. Existing risk threat assessment methods mostly use the risk analysis principle in the national standard "GBT20984-2007 Information Security Technology Information Security Risk Assessment Specification" as the basic framework, and only evaluate the probability of occurrence by the frequency of threat appearance. For example Figure 1 , in traditional asset risk calculation, threats and assets are not directly related. According to the existing information system deployment and internal and external network isolation strategies of the company, the threat levels of the same threat acting on different network positions are obviously inconsistent. Therefore, traditional threat risk methods cannot objectively evaluate the risks of threats. Summary of the Invention

[0003] In view of this, the purpose of the present invention is to provide a method for hierarchical measurement and evaluation of security threats to key information assets of a power grid to realize the research on the asset security of a power communication network.

[0004] To achieve the above purpose, the present invention adopts the following technical solutions: A method for hierarchical measurement and evaluation of security threats to key information assets of a power grid includes the following steps:

[0005] Step 1: Distributively deploy the S6000 platform for data collection; when collecting data, collect the whole network data in a concurrent manner, and use different collection frequencies according to the different characteristics of the collected data;

[0006] Step 2: Asset portrait based on big data;

[0007] Step 3: A security threat index measurement model for key information assets of a power grid to perform hierarchical measurement and evaluation of security threats to key information assets of a power grid.

[0008] In a preferred embodiment, step 1 specifically includes extracting asset importance indicators, asset vulnerability indicators, and threat destructiveness indicators.

[0009] In a preferred embodiment, the asset importance assignment in step 1 is completed according to the S6000 ledger information. There are 55 asset information attributes such as equipment name, equipment classification, affiliated system, affiliated network, equipment type, manufacturer, brand, model, production date, commissioning date, installation location, and IP address in the S6000 ledger.

[0010] In a preferred embodiment, in step 1, the vulnerability indicators assign values to the vulnerabilities of the network-wide asset information based on the S6000 health index; the S6000 health index includes vulnerability statistics, configuration compliance statistics, antivirus update timeliness, and violation behaviors, where the violation behavior indicators are irrelevant to the vulnerability indicators.

[0011] 5. A method for measuring and evaluating the security threat level of key information assets in a power grid according to claim 2, characterized in that, in step 1, the threat indicators are extracted according to the information in the S6000 threat index; the S6000 collects various security device and antivirus system alarms, and according to the IP address mapping table and the S6000 asset inventory, the IP addresses in the security device alarms are corresponded to the asset information to distinguish the threat situations suffered by different assets.

[0012] In a preferred embodiment, step 2 specifically includes:

[0013] Step 21: Propose a method for constructing a portrait from different types of data from different perspectives; including: collecting the continuous search terms used when using a network search engine, and performing time-series modeling on the word frequency and freshness of the words to generate a timely portrait; extracting key semantic information from the pictures, texts, and video content browsed, followed, and shared on the social network to construct a portrait; using the travel trajectory information, generating a location-based portrait representation from aspects such as frequent activities, behavior patterns, and moving speeds according to family information, location information, and behavior frequencies at different locations; generating a user portrait for feature preferences according to the types of products purchased in the online mall, comments on the purchased products, and scores.

[0014] Step 22: The asset portrait technology based on the knowledge graph uses a large amount of real user data collected by the system, including asset vulnerabilities, open high-risk ports, and the expiration time of the virus library version, to construct a knowledge graph for the portrait; then, using the semantic similarity and logical relevance between entities provided by the knowledge graph, calculate the correlation between the words of all the corpus of the knowledge graph and the entities in the knowledge graph to obtain knowledge entities related to semantics; similarly calculate the label table with similar semantics to the known user behavior labels for the related entities, and obtain the behavior evaluation of the correlation with the user corresponding to the label through combined calculation, so as to generate a user behavior label association combination that can represent the user characteristics; this user behavior label association combination of user characteristics is the portrait description of the user.

[0015] Step 23: Through the asset importance assessment module, asset vulnerability assessment module, and threat destructiveness assessment module, collect all label information to construct a portrait of the asset under threat; calculate the independent threat behavior indicators of the relevant modules through the evaluation models of each module; according to the label source module, merge all label categories to construct a single asset portrait.

[0016] In a preferred embodiment, step 3 specifically includes:

[0017] Step 31: According to the threat destructiveness measurement module, extract the most attacked type of each asset; through the located attack type, extract the corresponding attack feature fields in the original log, including whether there is a CVE number exploited by the attack and whether the attack can be carried out by brute force cracking means;

[0018] Step 32: Screen in the vulnerability module according to the attack behavior characteristics extracted in step 31; check whether there are relevant vulnerabilities extracted by the attack, whether there are exploitable configuration non-compliance items such as weak passwords, and whether there is an expired virus library, and perform correlation analysis and calculation; combine the host vulnerability with the threat destructiveness depth management to comprehensively and deeply analyze the host vulnerability degree and expose the truly threatened vulnerabilities;

[0019] Step 33: Extract the importance index label, threat destructiveness index, and threat destructiveness indicator of the asset, and construct a three-dimensional coordinate system; locate all assets on the coordinate axes;

[0020] Step 34: Set the entire asset as a set and divide it into 5 partitions for constructing data, where each partition represents a family, that is, a threat level; the division method first creates an initial division, and then uses an iterative relocation technique to relocate each sample until the condition is met; according to the clustering result, divide it into 5 levels, and assign scores from 1 to 5 to each group in turn;

[0021] Clustering method: The K-means algorithm is a process of repeatedly moving the center points of classes. Move the center points of classes, also called centroids, to the average position of their included members, and then re-divide its internal members; k is a hyperparameter calculated by the algorithm, representing the number of classes. Here, K is the default threat measurement level number;

[0022] Randomly select 5 asset portraits as centroids, and take the corresponding importance numerical labels, vulnerability numerical labels, and threat destructiveness numerical labels as the values to be clustered. Then, for each subsequent initial centroid, select the point that is farthest from the initial centroids that have already been selected; for different asset IPs, normalize each type of asset label data; normalize the threat destructiveness of all assets, find the maximum and minimum values of the threat destructiveness, denoted as max(T) and min(T), and substitute the threat destructiveness values in the asset portraits into (t - min(T)) / (max(T) - min(T)) one by one to normalize the entire network's assets; for each asset point x in the dataset, calculate its distance D(x) from the nearest clustering center, i.e., the already selected clustering center. Select a new data point as the new clustering center, and the selection principle is that the point with a larger D(x) has a greater probability of being selected as the clustering center. Iterate multiple times until k clustering centers are selected, i.e., complete the classification of the threat levels of assets.

[0023] Compared with the prior art, the present invention has the following beneficial effects: Applying the present technical solution can achieve the research on the asset security of the power communication network. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 is the traditional asset threat assessment principle;

[0025] Figure 2 is the schematic diagram of the index data collection process of the preferred embodiment of the present invention;

[0026] Figure 3 is the schematic diagram of a single asset portrait of the preferred embodiment of the present invention;

[0027] Figure 4 is the schematic diagram of the whole network threat index system of the preferred embodiment of the present invention;

[0028] Figure 5 is the schematic diagram of the classification of the threat levels of assets of the preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0030] It should be noted that the following detailed description is illustrative and is intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present application belongs.

[0031] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application; as used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.

[0032] A method for hierarchical measurement and evaluation of security threats to key information assets in a power grid, referring to Figures 1-5 , includes the following steps:

[0033] Step 1: The S6000 platform is deployed in a distributed manner. Each provincial power company has deployed a set of S6000 systems. When collecting data, the whole network data is collected concurrently, and different collection frequencies are used according to the different characteristics of the collected data, such as Figure 2 .

[0034] During the data collection process, the data is mainly stored in three locations:

[0035] ElasticSearch is used to store the original alarms of security devices;

[0036] HDFS is used to store threat summary information;

[0037] MySQL is used to store the association relationship between IP addresses and information systems, asset information of IP addresses, and vulnerability information.

[0038] (1) Extraction of asset importance indicators

[0039] The asset importance assignment can be completed according to the S6000 ledger information. There are 55 asset information attributes such as device name, device classification, affiliated system, affiliated network, device type, manufacturer, brand, model, production date, commissioning date, installation location, IP address, etc. in the S6000 ledger. According to the classification of the importance of information systems (category I, category II, and category III systems) in the "Safety Accident Investigation Regulations of State Grid Corporation of China" (State Grid Safety Quality

[2016] No. 1033), the assets belonging to various information systems, including host, network, security and other software and hardware and terminal assets in the relevant information communication operation and maintenance network segments, are divided into three levels: extremely high, high, and medium; terminal assets are of low level, and the importance assignment of assets is completed. There are 55 fields in the asset information in the S6000 platform to mark the asset attributes, Table 1.

[0040] Table 1 Asset importance assignment

[0041]

[0042]

[0043] (2) Extraction of Asset Vulnerability Indicators

[0044] Vulnerability indicators can assign values to the vulnerability of the entire network's asset information based on the S6000 health index. Currently, the S6000 health index includes vulnerability statistics, configuration compliance statistics, anti-virus update timeliness, and violation behaviors. Among them, the violation behavior indicator is currently irrelevant to the vulnerability indicator.

[0045] 1) Vulnerability statistics: including vulnerability scan results and intelligence-related vulnerabilities.

[0046] The vulnerability scan results are the vulnerability information obtained by each unit after scanning the assets using vulnerability scanning software. Intelligence-related vulnerabilities are compared with the vulnerabilities in the CVE public vulnerability database based on the version information of the operating system, database, and middleware obtained from the asset information to discover vulnerabilities that cannot be recognized by the vulnerability scanning device, as shown in Table 2.

[0047] Table 2 Vulnerability Scan Results Serial number Asset information field Serial number Asset information field

[0048]

[0049]

[0050] 2) Configuration compliance: includes four indicators: host non-compliance, firewall non-compliance, host high-risk ports, and weak passwords.

[0051] Host non-compliance includes compliance check results such as account password policy, access control, audit policy, and resource control. Firewall non-compliance includes compliance check results such as account password policy, open redundant services, and audit policy. The host high-risk ports check the high-risk port information published by the operation. The open port situation is regularly obtained through the agent deployed in the host device, and the open high-risk ports are recorded and displayed, as shown in Table 3.

[0052] Table 3 Host Non-compliance Serial number Asset information field Serial number Asset information field

[0053]

[0054] 3) Anti-virus update timeliness: This indicator judges the timeliness rate of virus library updates by obtaining the last update time of the anti-virus software virus library. If the anti-virus software is not updated in a timely manner, the probability of being infected by a virus will increase. Therefore, this indicator is also included in the vulnerability indicator, as shown in Table 4.

[0055] Table 4 Anti-virus Update Timeliness Serial number Asset information field Serial number Asset information field

[0056]

[0057]

[0058] (3) Threat destructive index extraction

[0059] Threat indicators can be extracted based on the information in the S6000 threat index. Currently, the S6000 collects alarms from a variety of security devices and antivirus systems. According to the IP address mapping table and the S6000 asset list, the IP addresses in the security device alarms can be corresponded with the asset information to distinguish the threat situations suffered by different assets.

[0060] 1) Known network attack threats: Detect known network attack threats through WAF device alarms, IDS / IPS device alarms, and attack traceability device alarms. There are a total of 61 fields in the known network attack detection alarms, which can be used to identify known network attack threats. Table 5.

[0061] Table 5 Known network attack threats

[0062]

[0063]

[0064]

[0065] 2) Known malware threats: Detect known malware threats through the antivirus system. There are a total of 36 fields in the alarms collected by the antivirus system, which are used to identify known malware threats. Table 6.

[0066] Table 6 Known malware threats

[0067]

[0068]

[0069] 3) Unknown threat assignment: Use the unknown threat results discovered in Project 1 to improve the accuracy of threat assignment. Assign values to the possible unknown threats to assets based on the detection results given in Project 1.

[0070] Step 2: Asset profiling technology based on big data

[0071] The portrait technology proposes methods for constructing portraits from different types of data from different perspectives. For example, continuously collected search terms used when using a web search engine are collected, and temporal modeling is performed on the word frequency and freshness of the words to generate a time-sensitive portrait; or key semantic information is extracted based on content such as pictures, texts, and videos browsed, followed, and shared on social networks to construct a portrait; or location-based portrait representations are generated from aspects such as frequent activities, behavior patterns, and movement speeds using travel trajectory information based on home information, location information, and behavior frequencies at different locations; or user portraits are generated for feature preferences based on the types of products purchased in an online mall, comments, and ratings on the purchased products.

[0072] The asset portrait technology based on the knowledge graph uses a large amount of real user data collected by the system, including asset vulnerabilities, open high-risk ports, expiration times of virus library versions, etc., to construct a knowledge graph for portraits. Then, using the semantic similarity and logical relevance between entities provided by the knowledge graph, the correlation between the words of all the corpus of the knowledge graph and the entities in the knowledge graph is calculated to obtain semantically related knowledge entities. Similarly, a label table with semantic similarity to known user behavior labels is calculated for relevant entities, and a behavioral evaluation of the correlation between the label and the corresponding user is obtained through combined calculation, thereby generating an associated combination of user behavior labels that can represent user characteristics. This associated combination of user behavior labels for user characteristics is the portrait description of the user.

[0073] Through the asset importance assessment module, asset vulnerability assessment module, and threat destructiveness assessment module, all label information is collected to construct a portrait of the asset under threat. Through the evaluation models of each module, the independent threat behavior indicators of the relevant modules are calculated. According to the label source module, all label categories are merged to construct a single asset portrait, such as Figure 3 .

[0074] Step 3: Grid Key Information Asset Security Threat Indicator Measurement Model

[0075] In the grid information system, there are a large number of assets and a large number of key nodes. Traditional asset threat assessment methods mostly use a certain formula as the risk measurement method. Although the assessment method is fixed and unified, it cannot objectively and truly reflect the actual threat situation of the current information system. The threat situations of various assets cannot be objectively and truly distinguished, making it impossible for security operation and maintenance personnel to accurately and preferentially focus on the assets with the highest vulnerability.

[0076] To better measure security threats, this model uses the method of big data clustering analysis, utilizes the label data in the asset portrait, performs relevant correlation analysis, and uses the method of partition clustering to measure asset threats.

[0077] 1) According to the threat destructiveness measurement module, extract the most attacked type for each asset. Through the located attack type, extract the corresponding attack feature fields in the original log, including whether there is a CVE number exploited by the attack and whether the attack can be carried out by brute force means.

[0078] 2) According to the attack behavior characteristics extracted in step 1, conduct screening in the vulnerability module. Check whether there are relevant vulnerabilities extracted by the attack, whether there are exploitable configuration non-compliance items such as weak passwords, and whether there is an expired virus library, and perform correlation analysis and calculation. Combine the host vulnerability with the threat destructiveness depth management to comprehensively and deeply analyze the host vulnerability level and expose the truly threatened vulnerabilities.

[0079] 3) Extract the importance index label, threat destructiveness index, and threat destructiveness indicator of the asset to construct a three-dimensional coordinate system. Locate all assets on the coordinate axes.

[0080] 4) Assume the entire asset as a set, divide and construct 5 partitions of the data, where each partition represents a family (cluster), that is, a threat level. The partitioning method first creates an initial partition, and then uses an iterative relocation technique to relocate each sample until the conditions are met. According to the clustering results, divide into 5 levels, and assign scores from 1 to 5 to each group in turn, such as Figure 4 。

[0081] 5) Clustering method: The K-means algorithm is a process of repeatedly moving the center points of the clusters. Move the center points of the clusters, also known as centroids, to the average position of their included members, and then re-partition their internal members. k is a hyperparameter calculated by the algorithm, representing the number of clusters. Here, K is the default threat measurement level number.

[0082] Randomly select 5 asset portraits as centroids, and take the corresponding importance numerical labels, vulnerability numerical labels, and threat destructiveness numerical labels as the values to be clustered. Then, for each subsequent initial centroid, select the point that is farthest from the initial centroids that have already been selected. In this way, it is ensured that the selected initial centroids are not only random but also dispersed. For different asset IPs, normalize each type of asset label data. For example, normalize the threat destructiveness of all assets, find the maximum and minimum values of the threat destructiveness, denoted as max(T) and min(T), and substitute the threat destructiveness values in the asset portraits into (t - min(T)) / (max(T) - min(T)) one by one, thereby achieving the normalization of all network assets. For each asset point x in the dataset, calculate its distance D(x) from the nearest cluster center (referring to the selected cluster center). Select a new data point as the new cluster center, and the selection principle is that the point with a larger D(x) has a greater probability of being selected as the cluster center. Iterate multiple times until k cluster centers are selected, that is, complete the classification of the threat level of assets, such as Figure 5 .

Claims

1. A method for measuring and evaluating the security threat level of key information assets in a power grid, characterized in that: The following steps are involved: Step 1: Distributed deployment of the S6000 platform for data collection; data is collected in a concurrent manner across the entire network, with different collection frequencies used according to the different characteristics of the collected data; Step 2: Asset profiling based on big data; Step 3: Develop a security threat indicator measurement model for key information assets of power grid to conduct security threat level measurement and evaluation of key information assets of power grid.

2. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 1, characterized in that: The step 1 specifically includes extracting asset importance indicators, asset vulnerability indicators and threat destructiveness indicators.

3. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 2, characterized in that: The asset importance assignment in step 1 is completed based on the S6000 ledger information. The S6000 ledger has 55 asset information attributes including equipment name, equipment classification, system, network, equipment type, manufacturer, brand, model, production date, commissioning date, installation location, IP address, etc.

4. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 2, characterized in that: In step 1, the vulnerability index assigns the vulnerability of the entire network asset information based on the S6000 health index; the S6000 health index includes vulnerability statistics, configuration compliance statistics, anti-virus update timeliness and violation behavior, among which the violation behavior indicator is irrelevant to the vulnerability index.

5. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 2, characterized in that: In step 1, the threat indicator is extracted based on the information in the S6000 threat index; the S6000 collects alarms from a variety of security devices and antivirus systems, and matches the IP addresses in the security device alarms with the asset information based on the IP address mapping table and the S6000 asset list to distinguish the threats to different assets.

6. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 1, characterized in that: The step 2 specifically includes: Step 21: Propose methods for constructing portraits from different angles and types of data; including: collecting continuous search terms used when using online search engines, and performing time series modeling on the frequency and freshness of terms to generate timely portraits; extracting key semantic information to construct portraits based on the pictures, texts, and videos browsed, followed, and shared on social networks; using travel trajectory information, based on family information, location information, and the frequency of behavior in different locations, generating location-based portrait representations from aspects such as frequent activities, behavioral patterns, and movement speeds; generating user portraits based on feature preferences based on the types of goods purchased in online shopping malls, comments on the purchased goods, and ratings; Step 22: The asset profiling technology based on the knowledge graph uses a large amount of real user data collected by the system, including asset vulnerabilities, open high-risk ports, and virus library version expiration time, to build a knowledge graph for profiling; then, using the semantic similarity and logical correlation between entities provided by the knowledge graph, the correlation between the words of all corpora of the knowledge graph and the entities in the knowledge graph is calculated to obtain semantically related knowledge entities; similarly, a label table of related entities with semantically similar semantics to known user behavior labels is calculated, and a behavioral evaluation of the correlation with the user corresponding to the label is obtained through combination calculation, thereby generating a user behavior label association combination that can represent user characteristics; this user behavior label association combination of user characteristics is a portrait description of the user; Step 23: Through the asset importance assessment module, asset vulnerability assessment module and threat destructiveness assessment module, all label information is collected to build an asset threat profile; through the evaluation model of each module, the independent threat behavior indicators of the relevant modules are calculated; according to the label source module, all label categories are merged to build a single asset profile.

7. A method for measuring and evaluating the security threat level of key information assets of a power grid according to claim 1, characterized in that: The step 3 specifically includes: Step 31: Extract the attack type with the most attacks for each asset according to the threat destructiveness measurement module; extract the corresponding attack feature field in the original log according to the located attack type, including whether there is a CVE number used in the attack and whether the attack can be carried out by brute force; Step 32: Screen in the vulnerability module according to the attack behavior features extracted in step 31; check whether there are related vulnerabilities extracted by the attack, whether there are any configuration non-compliance items that can be exploited, such as weak passwords, and whether there are expired virus libraries, and perform correlation analysis and calculation; combine host vulnerability with threat destructiveness in-depth management, comprehensively and deeply analyze the host vulnerability level, and expose the real threatened vulnerabilities; Step 33: Extract the asset importance index label, the asset threat destructiveness index, and the asset threat destructiveness index, and construct a three-dimensional coordinate system; place all assets on the coordinate axis; Step 34: Assume that the entire asset is a set, and divide it into 5 partitions to construct the data, where each partition represents a family, that is, a threat level; the partitioning method first creates an initial partition, and then uses an iterative relocation technique to relocate each sample until the conditions are met; according to the clustering results, it is divided into 5 levels, and each group is assigned a score of 1 to 5 in turn; Step 35: Clustering method: The K-means algorithm is a process of repeatedly moving the center point of a cluster, also known as the centroid, to the average position of its members, and then re-dividing its internal members; k is a hyperparameter calculated by the algorithm, indicating the number of clusters, where K is the default threat metric level; Randomly select 5 asset portraits as centroids, take the corresponding importance numerical labels, vulnerability numerical labels and threat destructiveness numerical labels as the values ​​to be clustered, then, for each subsequent initial centroid, select the point farthest from the initial centroid that has been selected; for different asset IPs, normalize the data of each type of asset label; normalize the threat destructiveness of all assets, find the maximum and minimum values ​​of the threat destructiveness, record them as max(T) and min(T), substitute the threat destructiveness values ​​in the asset portraits into (t-min(T)) / (max(T)-min(T)) one by one, and realize the normalization of the assets of the entire network; for each asset point x in the data set, calculate its distance D(x) from the nearest cluster center, that is, the selected cluster center, and select a new data point as the new cluster center. The principle of selection is that the point with a larger D(x) has a greater probability of being selected as the cluster center. Iterate multiple times until k cluster centers are selected, and the asset threat level classification is completed.