Grade protection evaluation method and system based on AI, terminal and storage medium
Through the AI-based grade protection evaluation method, the image detection data and operating status of network equipment are analyzed and the equipment grade score value is calculated, which solves the problem of low accuracy of grade protection evaluation in the existing technology, and achieves more efficient and accurate evaluation results.
Patent Information
- Application Number
- CN202510395088.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, the accuracy of grade protection evaluation is low and it is prone to artificial evaluation errors, resulting in incomplete results.
Using an AI-based grade protection evaluation method, the system evaluation level is determined by obtaining the image detection data and operating status of network equipment, analyzing the equipment detailed information and the grade evaluation model, calculating the equipment grade score value and the overall system score value.
It improves the accuracy of level protection assessment, reduces the probability of human misjudgment, and enhances the efficiency and automation of assessment.
Smart Images

Figure CN120223572A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network information security, and particularly to a level protection evaluation method, system, terminal and storage medium based on AI. Background Technique
[0002] Level protection refers to implementing security protection for important national information, proprietary information of legal persons, other organizations and citizens, as well as public information and information systems (network devices) that store, transmit and process this information in different levels, managing information security products used in information systems according to levels, and responding to and disposing of information security incidents occurring in information systems according to levels.
[0003] In the related art, the level protection evaluation work of network devices in the power industry is usually based on manual operations. First, manually judge whether the network device to be evaluated is running normally. If it is running normally, manually identify the type of the network device, and then conduct corresponding evaluations on the network device according to each evaluation index under the response level required by the level protection technical standard. Then, manually calculate the data obtained from the evaluation and compile a level protection evaluation report.
[0004] In view of the above related art, due to the diversity of the types and brands of network devices purchased by enterprises in different industries and the uneven quality and professional levels of evaluation technicians, it is easy to cause incomplete evaluation results and human evaluation errors, resulting in low accuracy of level protection evaluation, and there is still room for improvement. Summary of the Invention
[0005] In order to improve the accuracy of level protection evaluation, the present application provides a level protection evaluation method, system, terminal and storage medium based on AI.
[0006] In a first aspect, the present application provides a level protection evaluation method based on AI, adopting the following technical solutions: The level protection evaluation method based on AI includes: Obtain the image detection data of a preset network device; Analyze the image detection data to determine the detailed device information of the network device; Determine the actual level evaluation model according to the detailed device information and the preset relationship of the device level evaluation model; Obtain the device operation status of the network device; Analyze the device operation status, the detailed device information and the actual level evaluation model to determine the device level score value; Determine the weight of the device score value according to the detailed device information and the preset relationship of the device level weight; Analyze the device level score value and the weight of the device score value to determine the overall system score value; Determine the system evaluation level according to the relationship between the overall system score value and the preset level score value, and output it.
[0007] By adopting the above technical solution, analyze the image detection data of the network device to obtain the detailed device information, and then determine the actual level evaluation model for the network device's classified protection evaluation according to the relationship between the detailed device information and the device level evaluation model. After analyzing the device operating state, the detailed device information, and the actual level evaluation model, obtain the device level score value. Then, determine the overall system score value according to the device score value weight and the device level score value, and determine the level where the overall system score value is located, so that there is no need for personnel to distinguish the device types one by one, reducing the probability of misjudgment, and thus improving the accuracy of the classified protection evaluation.
[0008] Optionally, the steps for obtaining the operating state of the network device include: Obtain the startup feedback signal of the network device; Determine whether the startup feedback signal meets the requirements of the preset startup feedback signal; If not, define the preset shutdown operating state as the device operating state; If it meets the requirements, determine the parameters of the device to be started according to the detailed device information and the preset device state acquisition relationship; Control the preset state detection device to detect the network device according to the parameters of the device to be started to determine the device operating state.
[0009] By adopting the above technical solution, when it is determined that the startup feedback signal does not meet the requirements of the startup feedback signal, it indicates that the network device is shut down, so there is no need to perform further detection, and the shutdown operating state is defined as the device operating state. When it meets the requirements, it indicates that the network device is running, so control the state detection device to detect the state of the network device, thereby improving the efficiency and accuracy of the network device state detection.
[0010] Optionally, the steps for controlling the preset state detection device to detect the network device according to the parameters of the device to be started to determine the device operating state include: Control the state detection device to detect the network device according to the parameters of the device to be started to generate device state indicators; Determine the normal operating state indicators according to the detailed device information and the preset device state indicator relationship; Determine whether the device state indicators meet the requirements of the normal operating state indicators; If not, define the preset device abnormal operating state as the device operating state; If it meets the requirements, define the preset device normal operating state as the device operating state.
[0011] By adopting the above technical solution, after the device status detection device detects the device status indicators of the network device, the device status indicators are compared with the normal operation status indicators of the network device. Thus, when the two are inconsistent, the abnormal operation status of the device is determined as the device operation status; when they are consistent, the normal operation status of the device is determined as the device operation status, thereby improving the efficiency of determining the device operation status.
[0012] Optionally, the steps of analyzing the device operation status, device detailed information, and actual level assessment model to determine the device level score value include: Judge whether the device operation status meets the requirements of the preset direct assessment status; If not, adjust the status of the network device according to the preset status adjustment method and output the preset assessment trigger signal; If it meets the requirements, output the preset assessment trigger signal; Score the network device according to the assessment trigger signal and the actual level assessment model to determine the dimension score value; Determine the dimension score weight according to the device detailed information and the preset dimension weight relationship; Analyze the dimension score value and the dimension score weight to determine the device level score value.
[0013] By adopting the above technical solution, when the device operation status meets the requirements of the direct assessment status, the device detailed information is mapped to the corresponding dimension of the actual level assessment model, so that the dimension score value is obtained after item-by-item scoring, and then the device level score value is calculated according to the dimension score value and the dimension score weight, thereby improving the accuracy and efficiency of determining the device level score value.
[0014] Optionally, the steps of adjusting the status of the network device according to the preset status adjustment method include: Judge whether the device operation status meets the requirements of the preset device failure status; If it meets the requirements, associate and output the device detailed information and the preset warning information for reminder; If not, adjust the status of the network device according to the device operation status.
[0015] By adopting the above technical solution, when it is determined that the device operation status meets the requirements of the device failure status, it indicates that the network device has a fault. Therefore, the device detailed information and the warning information are associated for reminder; when it does not meet the requirements, it indicates that the network device is in an abnormal operation state. Therefore, the status of the network device is adjusted, so that the network device can perform level protection assessment, thereby improving the convenience of adjusting the network device.
[0016] Optionally, the steps of adjusting the status of the network device according to the device operation status include: Determine whether the operating state of the device meets the requirements of the preset device shutdown state; If not, obtain the device anomaly indicators; Adjust the state of the network device according to the device anomaly indicators; If so, control the network device to restart according to the device detailed information, and obtain the device restart state; Determine whether the device restart state meets the requirements of the device shutdown state; If not, re-evaluate the network device to determine the device level score value; If so, associate and output the device detailed information and the preset warning information for reminder.
[0017] By adopting the above technical solution, when the operating state of the device does not meet the requirements of the device shutdown state, determine the device anomaly indicators, and adjust the state of the network device according to the device anomaly indicators; when it meets, restart the network device, and detect and verify the state of the network device again. If it still shuts down, give a reminder, thereby improving the convenience of adjusting the state of the network device.
[0018] Optionally, the step of adjusting the state of the network device according to the device anomaly indicators includes: Determine whether the device anomaly indicators meet the requirements of the preset independent anomaly indicators; If so, analyze the device anomaly indicators to determine the device adjustment parameters; Control the network device to adjust its state according to the device adjustment parameters; If not, analyze the device anomaly indicators to determine the device load adjustment parameters; Control the network device to adjust its state according to the device load adjustment parameters, and obtain the device detection indicators again; When the device detection indicators do not meet the requirements of the preset normal indicator parameters, analyze the device detection indicators to determine the readjustment parameters; Control the network device to adjust its state according to the readjustment parameters.
[0019] By adopting the above technical solution, when the device anomaly indicators meet the requirements of the independent anomaly indicators, analyze the device anomaly indicators to determine the device adjustment parameters, and control the network device to adjust its state according to the device adjustment parameters; when they do not meet, adjust the state of the network device according to the device load adjustment parameters, and detect the device detection indicators again. When it is determined that the device detection indicators still do not meet the requirements of the normal indicator parameters, adjust the state of the network device according to the readjustment parameters, thereby improving the convenience of adjusting the state of the network device.
[0020] In a second aspect, the present application provides an AI-based classified protection assessment system, which adopts the following technical solution: An AI-based classified protection assessment system, comprising: An acquisition module, configured to acquire image detection data and device operation status; A memory, configured to store the program of the AI-based classified protection assessment method as described in any one of the above; A processor, the program in the memory can be loaded and executed by the processor and implement the AI-based classified protection assessment method as described in any one of the above.
[0021] By adopting the above technical solution, the processor loads and executes the program of the AI-based classified protection assessment method stored in the memory, and the acquisition module acquires a series of data related to the AI-based classified protection assessment, so as to analyze the image detection data of the network device to obtain detailed device information. Then, according to the relationship between the detailed device information and the device classification assessment model, the actual classification assessment model for the classified protection assessment of the network device is determined. After analyzing the device operation status, the detailed device information and the actual classification assessment model, a device classification score value is obtained. Then, according to the device score value weight and the device classification score value, the overall system score value is determined, and the level where the overall system score value is located is determined. Thus, there is no need for personnel to discriminate the device types one by one, reducing the probability of misjudgment, and further improving the accuracy of the classified protection assessment.
[0022] In a third aspect, the present application provides an intelligent terminal, which adopts the following technical solution: An intelligent terminal, comprising a memory and a processor, and a computer program capable of being loaded and executed by the processor and implementing the AI-based classified protection assessment method as described in any one of the above is stored on the memory.
[0023] By adopting the above technical solution, by operating the intelligent terminal, the processor loads and executes the computer program of the AI-based classified protection assessment method stored in the memory, so as to analyze the image detection data of the network device to obtain detailed device information. Then, according to the relationship between the detailed device information and the device classification assessment model, the actual classification assessment model for the classified protection assessment of the network device is determined. After analyzing the device operation status, the detailed device information and the actual classification assessment model, a device classification score value is obtained. Then, according to the device score value weight and the device classification score value, the overall system score value is determined, and the level where the overall system score value is located is determined. Thus, there is no need for personnel to discriminate the device types one by one, reducing the probability of misjudgment, and further improving the accuracy of the classified protection assessment.
[0024] Fourthly, the present application provides a computer storage medium capable of storing corresponding programs, which is characterized by facilitating the improvement of the accuracy of hierarchical protection assessment. The technical solution is as follows: A computer-readable storage medium stores a computer program that can be loaded and executed by a processor to perform the hierarchical protection assessment method based on AI described in any one of the above.
[0025] By adopting the above technical solution, a computer program for the hierarchical protection assessment method based on AI is stored in the computer-readable storage medium, enabling the processor to load and execute the computer program in the storage medium, thereby analyzing the image detection data of the network device to obtain detailed device information. Then, based on the relationship between the detailed device information and the device level assessment model, the actual level assessment model for the hierarchical protection assessment of the network device is determined. After analyzing the device operating state, detailed device information, and the actual level assessment model, the device level score value is obtained. Then, based on the device score value weight and the device level score value, the overall system score value is determined, and the level where the overall system score value is located is determined. Thus, it is no longer necessary for personnel to discriminate the device types one by one, reducing the probability of misjudgment and further improving the accuracy of the hierarchical protection assessment.
[0026] In summary, the present application includes at least one of the following beneficial technical effects: By analyzing the image detection data of the network device to obtain detailed device information, based on the relationship between the detailed device information and the device level assessment model, the actual level assessment model for the hierarchical protection assessment of the network device is determined. After analyzing the device operating state, detailed device information, and the actual level assessment model, the device level score value is obtained. Then, based on the device score value weight and the device level score value, the overall system score value is determined, and the level where the overall system score value is located is determined. Thus, it is no longer necessary for personnel to discriminate the device types one by one, reducing the probability of misjudgment and further improving the accuracy of the hierarchical protection assessment; When it is determined that the start feedback signal does not meet the requirements of the already started feedback signal, it indicates that the network device is shut down. Therefore, it is no longer necessary to perform further detection. The shutdown operating state is defined as the device operating state. When it meets the requirements, it indicates that the network device is running. Therefore, the status detection device is controlled to detect the status of the network device, thereby improving the efficiency and accuracy of the network device status detection; When the device operating state does not meet the requirements of the device shutdown state, the device abnormal indicators are determined, and the status of the network device is adjusted according to the device abnormal indicators. When it meets the requirements, the network device is restarted, and after detecting and verifying the status of the network device again, if it is still shut down, a reminder is given, thereby improving the convenience of adjusting the status of the network device. Description of the Drawings
[0027] Figure 1It is a flowchart of the AI-based hierarchical protection evaluation method in the embodiments of the present application.
[0028] Figure 2 It is a flowchart of the steps for obtaining the device operation status of a network device in the embodiments of the present application.
[0029] Figure 3 It is a flowchart of the steps for controlling a preset status detection device to detect a network device according to the device parameters to be started to determine the device operation status in the embodiments of the present application.
[0030] Figure 4 It is a flowchart of the steps for analyzing the device operation status, device detailed information, and actual hierarchical evaluation model to determine the device hierarchical score value in the embodiments of the present application.
[0031] Figure 5 It is a flowchart of the steps for adjusting the status of a network device according to a preset status adjustment method in the embodiments of the present application.
[0032] Figure 6 It is a flowchart of the steps for adjusting the status of a network device according to the device operation status in the embodiments of the present application.
[0033] Figure 7 It is a flowchart of the steps for adjusting the status of a network device according to the device abnormal index in the embodiments of the present application. Detailed implementation manners
[0034] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the following further describes the present application in detail with reference to the appended Figures 1-7 drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0035] The embodiments of this application disclose an AI-based hierarchical protection evaluation method, specifically disclose a processing terminal, a device information collection device, and a status collection device. The processing terminal is respectively connected to the device information collection device and the status collection device through wireless communication or data wires to achieve data interaction and control. After the processing terminal controls the device information collection device to collect the image detection data of the network device, the processing terminal performs image recognition on the image detection data to obtain the detailed device information of the network device, and determines the actual hierarchical evaluation model according to the relationship between the device information and the device hierarchical evaluation model. The processing terminal then controls the status detection device to detect the device operation status of the network device, and then analyzes the device operation status, the detailed device information, and the actual hierarchical evaluation model to determine the device hierarchical score value, and determines the overall system score value according to the device hierarchical score value and the device score value weight. According to the overall system score value, the corresponding system evaluation level is found in the hierarchical score value relationship and output, without the need for personnel to discriminate the device type one by one and select the evaluation criteria for manual calculation and evaluation, thereby reducing the probability of misjudgment and improving the accuracy of hierarchical protection evaluation.
[0036] Referring to Figure 1 , the embodiments of this application disclose an AI-based hierarchical protection evaluation method, including the following steps: Step S100: Obtain the image detection data of the preset network device.
[0037] Among them, the network device refers to the device waiting for hierarchical protection evaluation, usually including various key hardware such as routers, switches, servers, and firewalls. The image detection data refers to the clear image data of the network device. In one embodiment, the image detection data is stored in the secondary terminal of the network device. When hierarchical protection evaluation is required, the processing terminal sends an image detection data call request to the network device, and the network device sends the image detection data to the processing terminal; in another embodiment, it is obtained by shooting the network device with a camera installed near the network device and sending it to the processing terminal.
[0038] Step S101: Analyze the image detection data to determine the detailed device information of the network device.
[0039] Among them, the detailed device information refers to the identification, appearance characteristics, and port layout of the network device, including device model, brand, serial number, hardware specifications, etc., which are obtained by the processing terminal using an image recognition algorithm to perform image recognition on the image detection data. In the embodiments of this application, a convolutional neural network based on deep learning is used, pre-trained on a massive network device image sample library, so as to accurately and quickly identify device information according to the image.
[0040] Step S102: Determine the actual hierarchical evaluation model according to the detailed device information and the preset relationship between the device hierarchical evaluation models.
[0041] Among them, the device level assessment model relationship refers to the corresponding relationship between device information and the assessment model. Since the dimensions and criteria for level assessment of different network devices are different, it is necessary for the operator to map the device information to the level assessment model one by one to form a mapping table. For example, the assessment dimensions corresponding to a router are physical security, network security configuration, identity authentication and access control, log auditing, etc.; while the assessment dimensions corresponding to a firewall are policy management, intrusion detection, performance and redundancy, logs and reports, etc. The operator constructs an assessment model based on relevant standards and assessment dimensions.
[0042] The actual level assessment model refers to the model for actually conducting level assessment on network devices, which is determined by the processing terminal by looking up in the device level assessment model relationship according to the device information.
[0043] Step S103: Obtain the device operation status of the network device.
[0044] Among them, the device operation status refers to the operation status of the network device, including three types: shutdown, normal operation, and abnormal operation. The specific acquisition method refers to the steps of Figure 2
[0045] Step S104: Analyze the device operation status, device detailed information, and actual level assessment model to determine the device level score value.
[0046] Among them, after determining the device operation status, map the device detailed information to the actual level assessment model according to the device operation status, so that the actual level assessment model conducts an assessment on the network device to obtain the device level score value. The specific method refers to the steps of Figure 4 , providing data support for subsequent determination of the system level.
[0047] Step S105: Determine the weight of the device score value according to the device detailed information and the preset device level weight relationship.
[0048] Among them, the device level weight relationship refers to the corresponding relationship between the device and the weight of the score value. Since the roles and importance of different devices in the network are different, their weights in the level assessment are also different. For example, the weight of a router is twenty percent, and that of a switch is fifteen percent, etc. The operator maps the device information to the weight of the score value one by one to form a mapping table.
[0049] The weight of the device score value refers to the weight of the network device score in the system, which is obtained by the processing terminal by looking up in the mapping table corresponding to the device level weight relationship according to the device detailed information.
[0050] Step S106: Analyze the device level score value and the weight of the device score value to determine the overall system score value.
[0051] Among them, the overall system score value refers to the grade determination score of the system, which is obtained by calculating the product of the processing terminal's computing device grade score value and the device score value weight, and then calculating the sum of the products of each network device.
[0052] Step S107: Determine the system evaluation grade according to the overall system score value and the preset relationship between the grade score values, and output it.
[0053] Among them, the relationship between the grade score values refers to the corresponding relationship between the grades and the scores. The grades include a total of five grades from one to five. Below 60 points is grade one, 60 - 69 points is grade two, 70 - 79 points is grade three, 80 - 89 points is grade four, and 90 points and above is grade five.
[0054] The system evaluation grade refers to the grade of the system, which is obtained by the processing terminal looking up in the mapping table corresponding to the relationship between the overall system score value and the grade score values.
[0055] Refer to Figure 2 , the steps to obtain the device operating state of the network device include: Step S200: Obtain the startup feedback signal of the network device.
[0056] Among them, the startup feedback signal refers to the signal feedback by the network device in response to the inquiry instruction of whether the processing terminal starts. If it starts, it gives feedback; if it shuts down, it does not give feedback.
[0057] Step S201: Determine whether the startup feedback signal meets the requirements of the preset startup feedback signal.
[0058] Among them, the startup feedback signal refers to the feedback signal when the network device starts. The requirements for the startup feedback signal refer to being consistent with the startup feedback signal, which is stored in the processing terminal by the operator.
[0059] The processing terminal determines whether the startup feedback signal is consistent with the startup feedback signal, thereby determining whether the network device is in the operating state.
[0060] Step S2011: If it does not meet the requirements, define the preset shutdown operating state as the device operating state.
[0061] Among them, if the processing terminal determines that the startup feedback signal is inconsistent with the startup feedback signal, it indicates that the network device is not in the operating state. Therefore, the shutdown operating state is defined as the device operating state.
[0062] The shutdown operating state refers to the state where the network device is shut down, which is stored in the processing terminal by the operator.
[0063] Step S2012: If it meets the requirements, determine the device parameters to be started according to the device details and the preset collection relationship of device status.
[0064] Among them, if the processing terminal determines that the start feedback signal is consistent with the started feedback signal, it indicates that the network device is in the running state. Therefore, determine the device parameters to be started according to the device details and the device status collection relationship, providing data support for subsequent determination of the device running state.
[0065] The device status collection relationship refers to the corresponding relationship between device information and status collection devices. For example, the status data of a router is collected by device A, and the status data of a firewall is collected by device B. After the operator corresponds the device information with the status collection devices one by one, a mapping table is formed.
[0066] The device parameters to be started refer to the device information of the status detection device to be started, which is obtained by the processing terminal searching in the device status collection relationship according to the device details.
[0067] Step S202: Control the preset status detection device to detect the network device according to the device parameters to be started to determine the device running state.
[0068] Among them, after determining the device parameters to be started, the processing terminal controls the status detection device to start according to the device parameters to be started, and determines the device running state after detecting the network device. For the specific method, refer to Figure 3 the steps.
[0069] The status detection device refers to a device that detects the running state data of a network device, including a camera for shooting the running parameters of the network device, such as CPU usage rate, etc., and also includes a thermal sensor kit attached to key parts of the main structure of the network device, such as the processor heat sink, power module, network interface chip and other areas prone to heat generation, to detect and send the device temperature data and location in real time.
[0070] Refer to Figure 3 , the steps of controlling the preset status detection device to detect the network device according to the device parameters to be started to determine the device running state include: Step S300: Control the status detection device to detect the network device according to the device parameters to be started to generate device status indicators.
[0071] Among them, the device status indicator refers to a data indicator representing the device running state, including CPU usage rate, memory occupancy rate, network traffic load, alarm light status, etc., which is obtained by extracting key features in the image after image recognition of the screen shot image of the network device by the camera, and also includes temperature and location, which are detected by the thermal sensor kit and sent to the processing terminal.
[0072] Step S301: Determine the normal operation status indicators according to the device details and the preset relationship between device status indicators.
[0073] Among them, the relationship between device status indicators refers to the corresponding relationship between device information and device normal indicators. Since different devices have different corresponding normal indicators, for example, the CPU usage rate of a router does not exceed 70%, the memory usage rate remains below 70%, and the temperature does not exceed 40 degrees Celsius; the throughput of a firewall does not exceed 90% and the temperature is within the safe range. Therefore, the operator forms a mapping table by corresponding device information with device normal indicators one by one.
[0074] The normal operation status indicators refer to the indicators when the network device is operating normally, which are obtained by the processing terminal looking up in the mapping table corresponding to the relationship between device status indicators according to the device details.
[0075] Step S302: Determine whether the device status indicators meet the requirements of the normal operation status indicators.
[0076] Among them, the requirements of the normal operation status indicators refer to being within the indicator range corresponding to the normal operation status indicators, which are stored in the processing terminal by the operator.
[0077] The processing terminal determines whether the device status indicators are within the indicator range corresponding to the normal operation status indicators, so as to determine whether the network device is operating normally.
[0078] Step S3021: If not, define the preset abnormal operation status of the device as the device operation status.
[0079] Among them, if the processing terminal determines that the device status indicators are not within the indicator range corresponding to the normal operation status indicators, it indicates that the device is not operating normally. Therefore, define the abnormal operation status of the device as the device operation status.
[0080] The abnormal operation status of the device refers to the state where the network device is operating abnormally, which is stored in the processing terminal by the operator.
[0081] Step S3022: If it meets the requirements, define the preset normal operation status of the device as the device operation status.
[0082] Among them, if the processing terminal determines that the device status indicators are within the indicator range corresponding to the normal operation status indicators, it indicates that the device is operating normally. Therefore, define the normal operation status of the device as the device operation status.
[0083] The normal operation status of the device refers to the state where the network device is operating normally, which is stored in the processing terminal by the operator.
[0084] Refer to Figure 4, the steps of analyzing the device operation status, device detailed information, and actual level assessment model to determine the device level score value include: Step S400: Determine whether the device operation status meets the requirements of the preset direct assessment status.
[0085] Among them, the direct assessment status refers to the status in which the network device can be directly assessed for its level, that is, the normal operation status. The requirements of the direct assessment status refer to being consistent with the direct assessment status.
[0086] The processing terminal determines whether the device operation status is consistent with the direct assessment status, so as to determine whether the network device can be directly assessed for level protection.
[0087] Step S401: If not, adjust the status of the network device according to the preset status adjustment method and output the preset assessment trigger signal.
[0088] Among them, if the processing terminal determines that the device operation status is inconsistent with the direct assessment status, it indicates that the network device is shut down or operating abnormally. At this time, the network device cannot be assessed for level protection or cannot be accurately assessed for level protection. Therefore, the status of the network device is adjusted according to the status adjustment method. The specific method refers to Figure 5 the steps of. After the adjustment is completed, an assessment trigger signal is output to provide a timing signal for the subsequent level protection assessment of the network device.
[0089] The status adjustment method refers to the method of adjusting the status of the network device to the normal operation status, specifically referring to Figure 5 the steps of. The assessment trigger signal refers to the signal that can be used for level protection assessment. There are two conditions for outputting the assessment trigger signal in this step. One is to output the assessment trigger signal when the status of the network device is adjusted to the normal status, and the other is to output the assessment trigger signal when the operator or the processing terminal restarts the network device and determines that the status is normal.
[0090] Step S402: If it meets the requirements, output the preset assessment trigger signal.
[0091] Among them, if the processing terminal determines that the device operation status is consistent with the direct assessment status, it indicates that the network device can be directly assessed for level protection. Therefore, an assessment trigger signal is output to provide a timing signal for the subsequent level protection assessment of the network device.
[0092] The assessment trigger signal in this step is the same as the assessment trigger signal in step S401, and will not be elaborated here.
[0093] Step S403: Score the network device according to the assessment trigger signal and the actual level assessment model to determine the dimension score value.
[0094] Among them, when the processing terminal receives the evaluation trigger signal, in response to the evaluation trigger signal, the processing terminal maps the data of the network device into the dimensions corresponding to the actual level evaluation model, so as to score each dimension. For example, for a router, the data of the physical security, network security configuration, identity authentication and access control, and log audit level dimensions of the router are mapped into the actual level evaluation model, so as to determine the score values of the corresponding dimensions, providing data support for the subsequent determination of the device level score value.
[0095] The dimension score value refers to the score values of different dimensions of the network device, which are obtained by the processing terminal mapping the data of different dimensions of the network device into the dimensions corresponding to the actual level evaluation model for scoring.
[0096] Step S404: Determine the dimension score weight according to the device detailed information and the preset dimension weight relationship.
[0097] Among them, the dimension weight relationship refers to the corresponding relationship between the device information and the dimension weight. There are multiple evaluation dimensions in the network device, and the importance of different dimensions is different, so there are different weights. For example, for a router, the weight of physical security is between 5% and 10%, the weight of network security configuration is between 30% and 40%, the identity authentication and access control is between 20% and 30%, and the log audit is between 10% and 20%. Specifically, it is adjusted by the operator, and the device information and the dimension weight are corresponded one by one to form a mapping table.
[0098] The dimension score weight refers to the score weights of each dimension of the network device, which are obtained by the processing terminal looking up in the mapping table corresponding to the dimension weight relationship according to the device detailed information.
[0099] Step S405: Analyze the dimension score value and the dimension score weight to determine the device level score value.
[0100] Among them, the device level score value in this step is the same as the device level score value in step S104. The processing terminal calculates the product between the dimension score value and the dimension score weight, and then calculates the sum of the products corresponding to all dimensions to obtain the device level score value.
[0101] Refer to Figure 5 , the steps of adjusting the state of the network device according to the preset state adjustment method include: Step S500: Determine whether the device running state meets the requirements of the preset device failure state.
[0102] Among them, the device failure state refers to the network device being in a failure state, and the requirements of the device failure state refer to being consistent with the device failure state.
[0103] The processing terminal identifies whether the fault light of the network device is on, so as to determine whether the device operating state is consistent with the device fault state, and thus determine whether the state of the network device can be adjusted.
[0104] Step S501: If it meets the conditions, associate and output the device detailed information and the preset warning information for reminder.
[0105] Among them, if the processing terminal determines that the device operating state is consistent with the device fault state, it indicates that the network device has a fault and cannot pass the state adjustment to make the network device perform the classified protection assessment. Therefore, after associating the device detailed information and the warning information, output them for prompt.
[0106] The warning information refers to the information that the processing terminal prompts that the network device has a fault, and can adopt methods such as pop-up reminder, voice alarm, and SMS push.
[0107] Step S502: If it does not meet the conditions, perform state adjustment on the network device according to the device operating state.
[0108] Among them, if the processing terminal determines that the device operating state is inconsistent with the device fault state, it indicates that the network device has not failed. Therefore, state adjustment can be performed, and the state of the network device is adjusted according to the device operating state. The specific method refers to Figure 6 the steps.
[0109] Refer to Figure 6 , the steps of performing state adjustment on the network device according to the device operating state include: Step S600: Judge whether the device operating state meets the requirements of the preset device shutdown state.
[0110] Among them, the device shutdown state refers to the state where the network device is shut down, and the requirements of the device shutdown state refer to being consistent with the device shutdown state.
[0111] The processing terminal judges whether the device operating state is consistent with the device shutdown state, so as to determine how to adjust the state of the network device.
[0112] Step S601: If it does not meet the conditions, obtain the device abnormal indicators.
[0113] Among them, if the processing terminal determines that the device operating state is inconsistent with the device shutdown state, it indicates that the network device is only operating abnormally. Therefore, the device abnormal indicators are detected to provide data support for subsequent state adjustment of the network device.
[0114] The device abnormal indicators refer to the indicators when the network device is in an abnormal state, which are determined by the processing terminal comparing the operating indicators of the network device with the normal indicators.
[0115] Step S6011: Adjust the status of the network device according to the device exception indicators.
[0116] Among them, after the processing terminal determines the device exception indicators, it adjusts the status of the network device according to the device exception indicators, so that the network device is in a normal operating state and is suitable for performing the classified protection assessment.
[0117] Step S602: If it meets the requirements, control the network device to restart according to the device detailed information and obtain the device restart status.
[0118] Among them, if the processing terminal determines that the device operating state is consistent with the device shutdown state, it indicates that the network device is shut down. Therefore, it reminds the operator according to the device detailed information, so that the operator restarts the network device, or controls the processing terminal to restart the corresponding network device according to the device detailed information, and detects the device restart status, providing data support for determining whether the network device can perform the classified protection assessment later.
[0119] The device restart status refers to the status of the network device after restart. The acquisition method is the same as that of the device operating state and will not be elaborated here.
[0120] Step S603: Determine whether the device restart status meets the requirements of the device shutdown state.
[0121] Among them, the processing terminal determines whether the device restart status is consistent with the device shutdown state, so as to determine whether the network device has restarted successfully.
[0122] Step S6031: If it does not meet the requirements, re-evaluate the network device to determine the device level score value.
[0123] Among them, if the processing terminal determines that the device restart status is inconsistent with the device shutdown state, it indicates that the network device has restarted successfully. Therefore, re-evaluate the network device to determine the device level score value. The specific process is the same as that of Figure 4 the steps.
[0124] Step S6032: If it meets the requirements, associate and output the device detailed information and the preset warning information for reminder.
[0125] Among them, if the processing terminal determines that the device restart status is consistent with the device shutdown state, it indicates that the network device restart has failed and the network device has a fault. Therefore, associate the device detailed information and the warning information for prompt.
[0126] The warning information in this step is the same as the warning information in Step S501 and will not be elaborated here.
[0127] Refer to Figure 7 , the steps of adjusting the status of the network device according to the device exception indicators include: Step S700: Determine whether the device anomaly metrics meet the requirements of the preset independent anomaly metrics.
[0128] Among them, the independent anomaly metric means that there is only one type of anomaly metric in the device. For example, there is only a temperature anomaly metric or a running parameter anomaly metric. The requirement of the independent anomaly metric means that it is consistent with the independent anomaly metric.
[0129] The processing terminal determines whether the device anomaly metrics are consistent with the independent anomaly metrics, so as to determine whether the network device has only one type of anomaly.
[0130] Step S701: If it meets the requirements, analyze the device anomaly metrics to determine the device adjustment parameters.
[0131] Among them, if the processing terminal determines that the device anomaly metrics are consistent with the independent anomaly metrics, it means that the network device has only one type of anomaly. Therefore, after analyzing the device anomaly metrics, determine the device adjustment parameters to provide data support for the subsequent state adjustment of the network device.
[0132] The device adjustment parameters refer to the parameters for adjusting the state of the network device. The processing terminal analyzes the device anomaly metrics. If the device anomaly metric is that the temperature is too high, calculate the cooling power according to the excessive temperature and the temperature power coefficient, and then control the cooling fan to cool the network device with the cooling power; if the device anomaly metric is that the CPU usage rate is too high, the adjustment parameter is to stop some tasks to reduce the CPU usage rate.
[0133] Step S7011: Control the network device to perform state adjustment according to the device adjustment parameters.
[0134] Among them, after the processing terminal determines the device adjustment parameters, the processing terminal controls the network device itself or the auxiliary adjustment device, such as the cooling fan light, to adjust the state of the network device according to the device adjustment parameters, so that the network device is in a normal running state, which is convenient for the level protection assessment.
[0135] Step S702: If it does not meet the requirements, analyze the device anomaly metrics to determine the device load adjustment parameters.
[0136] Among them, if the processing terminal determines that the device anomaly metrics are inconsistent with the independent anomaly metrics, it means that the network device has two types of anomalies, namely, the temperature is too high and the running parameters are abnormal. Therefore, analyze the device anomaly metrics to determine the device load adjustment parameters to provide data support for the subsequent state adjustment of the network device.
[0137] The device load adjustment parameter refers to the parameter for adjusting the operating parameters of a network device. The processing terminal identifies the indicators among the device exception indicators that are operating parameters, calculates the difference from the normal indicators to determine the exceeded indicators, and determines the tasks to be stopped according to the indicators occupied by the corresponding tasks.
[0138] Step S703: Control the network device to perform status adjustment according to the device load adjustment parameter, and obtain the device detection indicators again.
[0139] Among them, after the processing terminal determines the device load adjustment parameter, the processing terminal controls the network device to stop some tasks according to the device load adjustment parameter, so that the operating parameters of the network device remain normal, and the device detection indicators are detected again, providing data support for determining whether the temperature is too high due to abnormal operating parameters in the follow-up.
[0140] Step S704: When the device detection indicators do not meet the requirements of the preset normal indicator parameters, analyze the device detection indicators to determine the readjustment parameter.
[0141] Among them, the normal indicator parameter refers to the normal range of the device operating indicators, and the requirement of the normal indicator parameter refers to being within the range corresponding to the normal indicator parameter.
[0142] When the processing terminal determines that the device detection indicators are not within the range corresponding to the normal indicator parameters, it indicates that the high temperature of the network device is not caused by abnormal operating parameters of the network device. Therefore, analyze the device detection indicators to determine the readjustment parameter, providing data support for the subsequent adjustment of the network device.
[0143] The readjustment parameter refers to the parameter for adjusting the temperature of the network device. The processing terminal obtains the power parameter according to the product of the value by which the temperature in the device detection indicators exceeds the normal indicator parameter temperature and the temperature power coefficient.
[0144] Step S705: Control the network device to perform status adjustment according to the readjustment parameter.
[0145] Among them, after the processing terminal determines the readjustment parameter, the processing terminal controls the cooling fan to cool the network device with the power corresponding to the readjustment parameter, so that the temperature of the network device remains normal, facilitating the level protection evaluation.
[0146] Based on the same inventive concept, an embodiment of the present application provides an AI-based level protection evaluation system, including: An acquisition module, configured to acquire image detection data, device operating status, startup feedback signal, device exception indicators, device restart status, and device detection indicators; A memory, configured to store a program such as the AI-based level protection evaluation method; A processor, and a program in the memory can be loaded and executed by the processor to implement an AI-based hierarchical protection evaluation method.
[0147] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the division of the above function modules is used as an example. In actual applications, the above functions can be allocated to different function modules as needed, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above. The specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0148] The embodiments of the present application provide a computer-readable storage medium storing a computer program that can be loaded and executed by a processor to implement an AI-based hierarchical protection evaluation method.
[0149] Computer storage media include, for example: USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs, and other media that can store program codes.
[0150] Based on the same inventive concept, the embodiments of the present application provide an intelligent terminal including a memory and a processor, and a computer program stored on the memory that can be loaded and executed by the processor to implement an AI-based hierarchical protection evaluation method.
[0151] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the division of the above function modules is used as an example. In actual applications, the above functions can be allocated to different function modules as needed, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above. The specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0152] The above are all the preferred embodiments of the present application. Without limiting the protection scope of the present application accordingly, any feature disclosed in this specification (including the abstract and drawings), unless specifically described, can be replaced by other equivalent or similar-purpose alternative features. That is, unless specifically described, each feature is only an example of a series of equivalent or similar features.
Claims
1. The AI-based level protection evaluation method is characterized by: include: Obtain image detection data of preset network devices; Analyze image detection data to determine device details of network devices; Determine the actual rating model based on the equipment detailed information and the preset equipment rating model relationship; Get the device operation status of the network device; Analyze the equipment operating status, equipment detailed information and actual rating model to determine the equipment rating value; Determine the equipment rating weight based on the equipment detailed information and the preset equipment level weight relationship; Analyze the equipment grade rating and equipment rating weight to determine the overall system rating; The system rating level is determined and output based on the relationship between the system's overall rating value and the preset rating value.
2. The AI-based level protection evaluation method according to claim 1 is characterized in that: The steps for obtaining the device operating status of a network device include: Obtain the startup feedback signal of the network device; Determining whether the start feedback signal meets the preset requirements of the started feedback signal; If it does not meet the requirements, the preset shutdown operation state is defined as the equipment operation state; If it meets the requirements, the parameters of the device to be started are determined based on the detailed information of the device and the preset device status collection relationship; According to the parameters of the device to be started, the preset status detection device is controlled to detect the network device to determine the operating status of the device.
3. The AI-based level protection evaluation method according to claim 2 is characterized in that: The steps of controlling a preset state detection device to detect the network device according to the parameters of the device to be started to determine the operation state of the device include: Controlling the state detection device to detect the network device according to the parameters of the device to be started to generate a device state indicator; Determine the normal operation status indicator based on the equipment detailed information and the preset equipment status indicator relationship; Determine whether the equipment status indicators meet the requirements of normal operating status indicators; If it does not meet the requirements, the preset abnormal operation state of the equipment is defined as the equipment operation state; If it meets the requirements, the preset normal operation state of the equipment is defined as the equipment operation state.
4. The AI-based level protection evaluation method according to claim 1 is characterized in that: The steps of analyzing the equipment operating status, equipment detailed information and the actual rating model to determine the equipment rating value include: Determine whether the equipment operating status meets the requirements of the preset direct assessment status; If not, the network device is adjusted according to a preset state adjustment method and a preset evaluation trigger signal is output; If it meets the requirements, the preset evaluation trigger signal is output; Scoring the network device according to the rating trigger signal and the actual rating model to determine the dimension rating value; Determine the dimension scoring weight based on the device detailed information and the preset dimension weight relationship; The dimension score values and dimension score weights are analyzed to determine the equipment level score value.
5. The AI-based level protection evaluation method according to claim 4 is characterized in that: The steps of adjusting the state of the network device according to the preset state adjustment method include: Determine whether the equipment operation status meets the requirements of the preset equipment failure status; If it meets the requirements, the device detailed information and preset warning information will be associated and output for reminder; If not, adjust the status of the network device according to the device's operating status.
6. The AI-based level protection evaluation method according to claim 5 is characterized in that: The steps for adjusting the status of network devices according to the device operating status include: Determine whether the equipment operation status meets the requirements of the preset equipment shutdown status; If it does not meet the requirements, obtain the device abnormality indicator; Adjust the status of network devices according to abnormal device indicators; If it is in compliance, the network device is controlled to restart according to the detailed device information, and the device restart status is obtained; Determine whether the device restart status meets the requirements of the device shutdown status; If not, the network equipment will be re-scored to determine the equipment grade score; If it meets the requirements, the device detailed information and preset warning information will be associated and output as a reminder.
7. The AI-based level protection evaluation method according to claim 6 is characterized in that: The steps for adjusting the status of network devices based on device abnormality indicators include: Determine whether the equipment abnormality index meets the requirements of the preset independent abnormality index; If it meets the requirements, the abnormal indicators of the equipment are analyzed to determine the equipment adjustment parameters; Control network devices to adjust their status according to device adjustment parameters; If not, analyze the equipment abnormality indicators to determine the equipment load adjustment parameters; Control network devices to adjust their status according to device load adjustment parameters, and obtain device detection indicators again; When the equipment detection index does not meet the preset normal index parameter requirements, analyze the equipment detection index to determine the readjustment parameters; The network device is controlled to adjust its status according to the readjustment parameters.
8. An AI-based level protection evaluation system, characterized in that: include: An acquisition module is used to acquire image detection data and equipment operation status; A memory, used to store a program of the AI-based level protection assessment method according to any one of claims 1 to 7; The program in the processor memory can be loaded and executed by the processor to implement the AI-based level protection assessment method as described in any one of claims 1 to 7.
9. An intelligent terminal, characterized in that: It includes a memory and a processor, and the memory stores a computer program that can be loaded by the processor and executes the AI-based level protection assessment method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: A computer program is stored which can be loaded by a processor and execute the AI-based level protection assessment method as described in any one of claims 1 to 7.
Citation Information
Cited By
AI-based equal-preserving gap dynamic evaluation method and system
CN122120007A