Service system security assessment method

By building internal employees and external social network maps and conducting comprehensive risk analysis, the problem of difficulty in comprehensively and timely assessment of business system security in the existing technology is solved, and accurate identification and timely response to internal dynamic risks and external threats are achieved, and the accuracy and timeliness of security assessment are improved.

CN120301693APending Publication Date: 2025-07-11CCS TRANSFAR TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510669085.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing technology is difficult to comprehensively and timely evaluate the security of the business system, and it is impossible to effectively identify dynamic changes in internal employee social relationships and external social network threats, resulting in inaccurate and lagging in security risks.

Method used

By building a map of internal employees and external social networks, conducting comprehensive risk analysis, using small group closeness formulas and external risk scoring formulas to evaluate risks, and developing security strategies for different risk levels.

Benefits of technology

It realizes accurate identification and timely response to business system security risks, improves the accuracy and timeliness of security assessments, and provides effective security policy support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301693A_ABST
    Figure CN120301693A_ABST
Patent Text Reader

Abstract

The invention discloses a service system security assessment method, and relates to the technical field of service system security assessment, and the assessment method comprises the following specific steps: S100, data collection and integration: collecting social network data of employees in a service system through an internal monitoring tool of the service system, collecting external social network information through a web crawler, and carrying out data collection and integration; according to the method, social network data of internal employees and external social network data are integrated, potential security risk points can be accurately identified by deeply analyzing social network relationships of the internal employees of a service system, and specifically, the method utilizes a social network analysis tool to meticulously sort contact networks among the employees, so that the security risk points are accurately identified. According to the method, employee nodes which are in abnormal frequent contact with external suspicious personnel and risk areas in which compact small groups are possibly formed are effectively found, and the refined analysis not only enhances the accuracy of risk identification, but also provides powerful data support for the formulation of a safety management strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of business system security assessment, and particularly to a business system security assessment method. Background Art

[0002] With the rapid development of information technology, business systems have increasingly become the core of enterprise operations. However, the security threats faced by business systems have also become increasingly complex and diverse, including improper behaviors of internal employees, attacks by external hackers, and intrusion of malicious software. These security threats may not only lead to serious consequences such as data leakage and system paralysis, but also cause huge losses to the reputation and economic benefits of enterprises. Therefore, business system security assessment has become a crucial link, which aims to comprehensively evaluate the security of business systems through scientific methods and means, and timely discover and eliminate potential security risks.

[0003] In the field of social network analysis, traditional technologies mainly rely on simple statistics and analysis of social network data. These technologies are usually used to identify key nodes, propagation paths, and user behavior patterns in social networks. In security assessment, traditional technologies also attempt to apply social network analysis to the assessment of internal employee social relationships and the monitoring of external social network threats.

[0004] For the assessment of internal employee social relationships, traditional technologies mainly focus on the social connections and interactions between employees. By statistically analyzing the communication records and email exchanges between employees, the social relationship network between employees is analyzed, and risk - prone relationship chains are identified. However, these technologies often can only provide static and one - sided analysis results, and it is difficult to comprehensively reflect the dynamic changes and potential risks of employee social relationships.

[0005] For the monitoring of external social network threats, traditional technologies mainly rely on the collection and analysis of public information on social networks. By monitoring keywords and topics related to business systems, potential security threats can be discovered in a timely manner. However, these technologies often can only provide limited and lagged information, and it is difficult to timely discover and respond to potential external threats.

[0006] Therefore, it is necessary to develop a business system security assessment method that can effectively improve the accuracy and timeliness of business system security assessment and provide strong support for enterprise information security protection. Summary of the Invention

[0007] The objective of the present invention is to make up for the deficiencies of the prior art and provide a method for security assessment of a business system. This method collects and integrates data to construct graphs of internal employees and external social networks, realizes visual analysis of social network relationships, and on this basis, conducts comprehensive risk analysis, including internal employee social network risk analysis and external social network risk analysis, and formulates corresponding security policies and countermeasures for different risk levels.

[0008] To solve the above technical problems, the present invention provides the following technical solution: A method for security assessment of a business system, and the specific steps of this assessment method are as follows:

[0009] S100, Data collection and integration: Collect internal employee social network data of the business system through the internal monitoring tool of the business system, collect external social network information using a web crawler, integrate the internal employee social network data and the external social network data, and establish a unified data storage and management system;

[0010] S200, Construction of social network graphs: Based on the integrated internal employee social network data, construct an internal employee social network graph, and combine with external social network information to construct an exposure and reputation graph of the business system on the external social network;

[0011] S300, Comprehensive risk analysis: Comprehensive risk analysis includes internal employee social network risk analysis and external social network risk analysis;

[0012] In the S300, internal employee social network risk analysis in the comprehensive risk analysis: By finding employee nodes connected to external suspicious persons and screening and evaluating the suspicious persons, use the small group closeness formula to find overly close small groups in the internal employee social network graph, and evaluate the information leakage and internal attack risks brought by these situations through the internal risk scoring formula. The formula is: R int = ∑ m C m W m , where R int represents the internal employee social network risk score, C m represents the value of the mth risk factor, and W m represents its corresponding weight;

[0013] In the S300, external social network risk analysis in the comprehensive risk analysis: Real-time monitor the external social network information to identify whether there is leakage of sensitive information of the business system, pay attention to social network topics and trends related to the business system, analyze its potential impact on the security of the business system, and quantify the external social network risk through the external risk scoring formula according to factors such as the degree of leakage of sensitive information, the popularity of the topic, and the degree of potential threat. The formula is: R ext= ∑ n S n V n , where R ext represents the external social network risk score, S n represents the value of the nth risk factor, and V n represents its corresponding weight. Considering the propagation characteristics and influence scope of the external social network, the risk is further evaluated;

[0014] For the S300, in the comprehensive risk assessment of the comprehensive risk analysis, internal and external factors are comprehensively considered, and the comprehensive risk score is calculated through the comprehensive risk formula. The formula is: R total = R int ×α1 + R ext ×β1, where R total represents the comprehensive risk score of the business system, R int and R ext are the internal and external risk scores respectively, and α1, β1 are weight coefficients. Furthermore, the risk level of the business system is determined, and different risk levels correspond to different security policies and countermeasures;

[0015] S400, Security Policy Formulation and Implementation: According to the results of the comprehensive risk analysis, corresponding security policies are formulated. For internal risks, measures such as strengthening employee training, adjusting the internal organizational structure, and strengthening the monitoring of specific employees are taken; for external risks, measures such as strengthening information security management, activating emergency plans, and cooperating with external social network platforms for information control are taken. The formulated security policies are implemented, and their effects are continuously monitored and evaluated, and adjusted and optimized according to the actual situation.

[0016] Furthermore, for the S200, in the construction of the internal employee social network graph in the social network graph construction, employees are used as nodes, and each employee corresponds to a unique node identifier in the graph. There is a social connection between two employees, and an edge is established between their corresponding nodes. The weight of the edge is set according to factors such as the frequency and importance of the connection. The relationship strength between employees is calculated using the employee relationship strength formula, and the internal employee social network graph is displayed using Gephi.

[0017] Even further, for the S200, in the social network graph construction, the relationship strength between employees is calculated through the employee relationship strength formula. The formula is: R ij = α2F ij + β2I ij + γ2T ij , where R ij represents the relationship strength between employee i and employee j, F ij represents the connection frequency, I ij represents the importance of the communication content, Tij Represents the time span of contact, and α2, β2, γ2 represent different weight coefficients.

[0018] Furthermore, for S200, in the construction of the social network graph, the external social network exposure and reputation graph construction uses the business system itself, relevant social network topics, and key figures as nodes. Each node corresponds to a unique identifier in the graph. If there is an association between the business system and a certain social network topic, an edge is established between the corresponding nodes. The weight of the edge is set according to the popularity of the topic and the influence factors of the key figures. By analyzing external social network information, the exposure and reputation of the business system are calculated, and Gephi is used to display the external social network exposure and reputation graph.

[0019] Furthermore, for S200, in the construction of the social network graph, the exposure E of the business system is calculated through the exposure calculation formula, and the formula is: E = ∑ k H k W k , where H k represents the popularity of the k-th relevant post and comment, and W k represents its degree of association with the business system.

[0020] Furthermore, for S200, in the construction of the social network graph, the reputation of the business system is calculated through the reputation calculation formula, and the formula is: where P pos represents the number of positive comments, P total represents the total number of comments, I l represents the influence of key figure l, and α3, β3 are weight coefficients.

[0021] Furthermore, for S300, in the comprehensive risk analysis, overly tight small groups are found in the internal employee social network graph through the small group tightness formula, and the formula is: where D group represents the tightness of the small group, N internal represents the number of connections between members within the small group, N total represents the maximum possible number of connections of the small group, R ij represents the relationship strength between member i and member j within the small group, and α4 and β4 are weight coefficients. Let the threshold of the small group tightness be T group , D group ≥T group When this occurs, an alarm is triggered, and the alarm is sent to the security management personnel via email, text message, and system pop-up window.

[0022] Furthermore, in S300, in the comprehensive risk analysis, the formula for calculating the degree of sensitive information leakage is used to quantify the degree of leakage of sensitive information of the business system on external social networks. The formula is: L sensitivity = ∑ post P sensitivity ×H post , where L sensitivity represents the degree of sensitive information leakage, P sensitivity represents the proportion of sensitive information in a single post, and H post represents the popularity of the post. A sensitive information leakage threshold T leak is set. When the calculated degree of sensitive information leakage L sensitivity exceeds this threshold, it is determined that the sensitive information of the business system has been leaked externally.

[0023] Furthermore, in S300, in the comprehensive risk analysis, the risk level is divided into three levels: high, medium, and low through the risk level assessment formula. The formula is: where L represents the risk level value, R total is the comprehensive risk score mentioned above, R min is the pre-set minimum risk threshold, and R max is the pre-set maximum risk threshold. The risk level is divided according to the value of L: when L ≥ 80, it is determined as a high risk level; when 40 ≤ L < 80, it is determined as a medium risk level; when L < 40, it is determined as a low risk level.

[0024] Furthermore, in S300, the security policies and countermeasures for different risk levels in the comprehensive risk analysis:

[0025] High risk level: Immediately carry out intensive employee information security training internally and adjust the internal organizational structure, establish an emergency team to strengthen monitoring, and externally comprehensively strengthen access control to the business system, activate the emergency plan, and cooperate with external parties;

[0026] Medium risk level: Organize regular employee information security training internally, optimize the internal structure to clarify the information sharing mechanism, strengthen the management of permissions for key positions, and externally strengthen access control and formulate an emergency plan to communicate with social platforms;

[0027] Low risk level: Regularly carry out employee information security training internally and maintain smooth internal collaboration, monitor social network behaviors daily and give security reminders, and externally maintain regular access control and improve the emergency plan to cooperate with social platforms.

[0028] Compared with the prior art, the security assessment method for a business system has the following beneficial effects:

[0029] I. By deeply analyzing the social network relationships of employees within the business system, the present invention can accurately identify potential security risk points. Specifically, this method uses social network analysis tools to meticulously sort out the connection network among employees, effectively discovering employee nodes that have unusually frequent connections with external suspicious persons, as well as risk areas within the organization that may form tight cliques. This refined analysis not only enhances the accuracy of risk identification but also provides strong data support for formulating security management strategies. For example, when it is found that certain employees have close connections with external suspicious persons, the security management team can quickly intervene for further investigation and risk assessment, thereby timely blocking potential information leakage and internal attack paths.

[0030] II. By real-time monitoring the exposure and reputation of the business system on external social networks, the present invention can quickly detect any leakage of sensitive information related to the business system. This real-time monitoring mechanism helps the security management team to timely discover and respond to potential security threats. At the same time, this method also pays attention to social network topics and trends related to the business system. By deeply analyzing these topics and trends, it can predict and identify possible malicious attack planning and discussions on system vulnerabilities, thereby taking preventive measures in advance. This forward-looking threat monitoring ability greatly improves the security defense level of the business system.

[0031] Other advantages, objectives, and features of the present invention will be described to some extent in the following specification, and to some extent, will be obvious to those skilled in the art based on the study of the following text, or can be taught from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0033] Figure 1 It is a flowchart of a security assessment method for a business system;

[0034] Figure 2 It is a flowchart of the comprehensive risk analysis steps. DETAILED DESCRIPTION OF THE INVENTION

[0035] The technical solutions in the embodiments of the present invention will be described clearly and completely below. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0036] Embodiment 1:

[0037] Security assessment of the financial business system:

[0038] In the financial industry, with the increasing frequency of digital transactions, the financial business system faces many security challenges. For example, internal employees may communicate with external suspicious persons due to negligence and malice, thus leaking sensitive customer information and transaction data; discussions about financial product vulnerabilities and system security issues may also appear on external social networks, affecting the reputation of financial institutions and customer trust.

[0039] Data collection and integration:

[0040] Collection of internal employee social network data: Through the internal monitoring tools of the financial business system, collect the communication records, email exchanges, and instant messaging information of employees in internal office software (such as enterprise email for handling emails related to financial transactions and instant messaging tools for internal business communication).

[0041] Among them, when collecting internal employee social network data, it is necessary to ensure the legality of data collection first; when collecting internal employee social network data, it is necessary to ensure the legality of data collection first: the following measures can be specifically adopted:

[0042] The information collection is clearly consented to by the employees;

[0043] Based on the necessary situation of human resource management, pay attention to clear boundaries.

[0044] Collection of external social network information: Use web crawlers to collect posts, comments, and topics related to the financial business system on mainstream social media platforms (such as Weibo, Zhihu) and financial industry-related forums.

[0045] Data integration: Integrate the internal employee social network data with the external social network data to establish a unified data storage and management system.

[0046] Construction of the social network graph:

[0047] Construction of the internal employee social network graph: Take employees as nodes, and set the connection frequency between employee i and employee j as F ij , the importance of the communication content as I ij , the time span of the connection as T ij , according to the formula Rij = α2F ij + β2I ij + γ2T ij , calculate the relationship strength. For example, for two employees who often jointly handle large transactions, their F ij is high, I ij is high, and the calculated relationship strength value R ij is high. Then, use Gephi to display the internal employee social network graph. Different colors of nodes and line thicknesses represent different relationship strengths.

[0048] Construction of external social network exposure and reputation graph: Use the financial business system itself, related financial product topics, industry experts, and opinion leaders as nodes. Let H k represent the popularity of the k-th related post and comment, and W k represent its degree of association with the business system. According to the formula: E = ∑ k H k W k , calculate the exposure. Let P pos represent the number of positive comments, P total represent the total number of comments, I l represent the influence of the key person l, and α3 and β3 are weight coefficients. According to the formula: Calculate the reputation degree, and use Gephi to display the external social network exposure and reputation graph. Use a bar chart to represent the popularity of different topics, and use colors to represent the quality of the reputation.

[0049] Comprehensive risk analysis:

[0050] Internal employee social network risk analysis: Identify employee nodes that are connected to external suspicious persons. For example, if it is found that an employee frequently contacts persons with unknown identities from high-risk financial regions outside, let the contact frequency with external suspicious persons be F ext , when F ext ≥ T ext (T ext is the preset external contact frequency threshold), trigger an alarm, and use the small group closeness formula: Find overly close small groups in the internal employee social network graph. For example, if it is found that members of a small group often discuss sensitive customer information internally, let the number of connections between members within the small group be N internal , the maximum possible number of connections in the small group be N total , and its closeness D group is relatively high. Let the value of the m-th risk factor be C m , and its corresponding weight be W m , through the internal risk scoring formula: Rint = ∑ m C m W m Perform risk quantification.

[0051] External social network risk analysis: Real-time monitoring of external social network information to identify whether sensitive information of the financial business system has been leaked. Let the proportion of sensitive information in a single post be P sensitivity , and the popularity of this post be H post , according to the formula: L sensitivity = ∑ post P sensitivity ×H post , quantify the degree of sensitive information leakage. For example, it is found that there is a discussion about the security vulnerability of the financial business system on a certain forum, and the popularity of this post is relatively high. P sensitivity and H post can be determined through specific analysis. Pay attention to social network topics and trends related to the financial business system, and analyze their potential impact on the security of the business system. Let the value of the nth risk factor be S n , and its corresponding weight be V n , through the external risk scoring formula: R ext = ∑ n S n V n , quantify the external social network risk.

[0052] Comprehensive risk assessment: Consider internal and external factors comprehensively. Let the internal risk score be R int , and the external risk score be R ext , and the weight coefficients be α and β. Through the comprehensive risk formula:: R total = R int ×α1 + R ext ×β1, calculate the comprehensive risk score. For example, assume: R int = 60, R ext = 40, α1 = 0.6, β1 = 0.4, then the comprehensive risk score: R total = 60×0.6 + 40×0.4 = 52. According to the risk level assessment formula:: Assume R min = 20, then the risk level value: Is determined to be a medium risk level.

[0053] Security policy formulation and implementation:

[0054] Internal risk security strategy: Organize regular employee information security training, at least once a month, with a focus on emphasizing the security of financial transaction information and internal data protection. Regulate employees' social network behaviors, clearly prohibit communication involving financial operations with external suspicious persons, optimize and adjust the internal organizational structure, clarify the information sharing and collaboration mechanisms among departments, avoid security risks caused by poor information circulation, and strengthen the authority management of employees in key positions to ensure that their operations are within a reasonable range.

[0055] External risk security strategy: Strengthen the access control of business systems, regularly update the password policy, improve the complexity and security of passwords, closely monitor information related to financial business systems on external social networks, promptly detect potential risks, formulate a detailed emergency plan, clarify the emergency response process and responsibility division in the medium-risk situation, and be able to quickly take measures to handle security incidents once they occur to reduce losses.

[0056] This embodiment conducts a security assessment of the financial business system. First, in the data collection and integration stage, it collects internal employees' social network data and external social network information and establishes a unified storage and management system. Then, it constructs a social network graph. The internal graph shows the strength of employee relationships, and the external graph presents the system exposure and reputation. In the comprehensive risk analysis, it identifies internal and external suspicious connections and small groups, quantifies internal and external risks, and finally determines the medium-risk level through comprehensive evaluation. For this risk level, internally, it adopts strategies such as regular training, structural optimization, and authority management, while externally, it strengthens access control, monitors information, and formulates an emergency plan.

[0057] Embodiment 2:

[0058] Security assessment of e-commerce business systems:

[0059] In the e-commerce field, the security of business systems is of crucial importance. E-commerce enterprises process a large amount of order information and customer data every day. The leakage of this information may cause losses to customers and damage to the enterprise's reputation. At the same time, evaluations and discussions on product quality, logistics services, and the e-commerce system itself on external social networks will also affect the operation of the enterprise.

[0060] Data collection and integration:

[0061] Collection of internal employees' social network data: Through the internal monitoring tools of the e-commerce business system, collect communication records, email exchanges, and instant messaging information of employees in internal office software (such as enterprise email for processing order information and instant messaging tools for customer service and logistics coordination).

[0062] External social network information collection: Use web crawlers to collect posts, comments, and topics related to the e-commerce business system on mainstream social media platforms (such as Weibo and Taobao Community) and relevant forums in the e-commerce industry.

[0063] Data integration: Integrate internal employee social network data with external social network data to establish a unified data storage and management system.

[0064] Social network graph construction:

[0065] Internal employee social network graph construction: Take employees as nodes. Let the connection frequency between employee i and employee j be F ij , the importance of the communication content be I ij , the time span of the connection be T ij , according to the formula: R ij = α2F ij + β2I ij + γ2T ij , calculate the relationship strength. For example, for two employees who often jointly handle large orders, their F ij is high, I ij is high, and the calculated relationship strength value R ij is high. Then, use the visualization tool Gephi to display the internal employee social network graph, where nodes and line thicknesses of different colors represent different relationship strengths.

[0066] External social network exposure and reputation graph construction: Take the e-commerce business system itself, related product topics, industry experts, and opinion leaders as nodes. Let the popularity of the kth relevant post and comment be H k , W k represent its degree of association with the business system. According to the formula: E = ∑ k H k W k , calculate the exposure. Let P pos represent the number of positive comments, P total represent the total number of comments, I l represent the influence of key person l, and α, β be weight coefficients E. According to the formula: Calculate the reputation degree, and use Gephi to display the external social network exposure and reputation graph, representing the popularity of different topics with bar charts and the quality of reputation with colors.

[0067] Comprehensive risk analysis:

[0068] Internal employee social network risk analysis: Identify employee nodes that are connected to external suspicious persons. For example, if it is found that an employee frequently contacts external persons with unknown identities from high-risk e-commerce regions, let the connection frequency with external suspicious persons be Fext When F ext ≥T ext (T ext is the preset external connection frequency threshold), an alarm is triggered, and the small group tightness formula is used to find overly tight small groups in the internal employee social network graph. For example, if it is found that members of a small group often discuss sensitive customer order information internally, and the maximum number of connections in the small group is N total , and its tightness D group is relatively high. Let the value of the mth risk factor be C m , and its corresponding weight be W m . Through the internal risk scoring formula: R int =∑ m C m W m to quantify the risk.

[0069] External social network risk analysis: Real-time monitoring of external social network information to identify whether there is a leakage of sensitive information in the e-commerce business system. Let the proportion of sensitive information in a single post be P sensitivity , and the popularity of this post be H post . According to the formula: L sensitivity =∑ post P sensitivity ×H post to quantify the degree of sensitive information leakage. For example, if it is found that there is a discussion about the security vulnerability of the e-commerce business system on a certain forum and the popularity of this post is relatively high, P sensitivity and H post can be determined through specific analysis. Pay attention to social network topics and trends related to the e-commerce business system and analyze their potential impact on the security of the business system. Let the value of the nth risk factor be S n , and its corresponding weight be V n . Through the external risk scoring formula: R ext =∑ n S n V n to quantify the external social network risk.

[0070] Comprehensive risk assessment: Considering internal and external factors comprehensively. Let the internal risk score be R int , and the external risk score be R ext . The weight coefficients are α and β. Through the comprehensive risk formula: R total =R int ×α1 + R ext ×β1, calculate the comprehensive risk score. For example, assume R int =40, R ext =30, α1 = 0.6, β1 = 0.4, then the comprehensive risk score: Rtotal = 40 × 0.6 + 30 × 0.4 = 36. According to the risk level assessment formula: Assume R min = 20, then the risk level value is determined to be a low - risk level.

[0071] Security policy formulation and implementation:

[0072] Internal risk security policy: Regularly conduct employee information security training, once every quarter, to maintain employees' information security awareness. Encourage employees to actively participate in information security activities, such as security knowledge competitions, to improve employees' participation and enthusiasm. Maintain the existing internal organizational structure to ensure smooth collaboration between departments. Conduct daily monitoring of employees' social network behaviors, correct problems in a timely manner, give general security reminders to employees, emphasize the importance of information security, and encourage employees to consciously abide by information security regulations.

[0073] External risk security policy: Maintain the regular access control measures of the business system, regularly check and update security settings. Conduct irregular monitoring of information related to the business system on external social networks to ensure there are no major security hazards. Improve the emergency response plan to ensure that security incidents that may occur can be quickly responded to even in low - risk situations. Maintain a good cooperative relationship with external social network platforms to jointly create a safe and stable network environment.

[0074] In this embodiment, for the security assessment of the e - commerce business system, it also goes through each stage. The data collection integrates relevant internal and external information. The construction of the social network graph reflects employees' relationships and the external situation of the system. When conducting comprehensive risk analysis, relevant risk factors are identified and quantitatively scored. The comprehensive assessment is a low - risk level. Correspondingly, internally, regular training and daily monitoring are implemented, and externally, regular access control is maintained and the emergency response plan is improved to ensure the security of the e - commerce business system.

[0075] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above - mentioned exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms. Therefore, in any aspect, the embodiments should be regarded as exemplary and non - restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be encompassed within the present invention. Any reference signs in the claims should not be regarded as limiting the claimed rights.

Claims

1. A security assessment method for a business system, characterized in that, The specific steps of this evaluation method are as follows: S100, Data collection and integration: Collect the internal employee social network data of the business system through the internal monitoring tools of the business system, collect external social network information using web crawlers, integrate the internal employee social network data and the external social network data, and establish a unified data storage and management system; S200, Social network graph construction: Based on the integrated internal employee social network data, construct the internal employee social network graph, and combine the external social network information to construct the exposure and reputation graph of the business system on the external social network; S300, Comprehensive risk analysis: Comprehensive risk analysis includes internal employee social network risk analysis and external social network risk analysis; The S300, in the comprehensive risk analysis, conducts risk analysis on the internal employee social network: by identifying employee nodes connected to external suspicious persons and screening and evaluating the suspicious persons, using the small group tightness formula to find overly tight small groups in the internal employee social network graph, and evaluating the information leakage and internal attack risks brought by these situations through the internal risk scoring formula. The formula is: R int = ∑ m C m W m , where R int represents the internal employee social network risk score, C m represents the value of the m-th risk factor, and W m represents its corresponding weight; In the S300, for the external social network risk analysis in the comprehensive risk analysis: real-time monitoring of external social network information to identify whether there is any leakage of sensitive information of the business system, paying attention to social network topics and trends related to the business system, analyzing their potential impact on the security of the business system, and quantifying the external social network risk through an external risk scoring formula according to factors such as the degree of leakage of sensitive information, the popularity of topics, and the degree of potential threat. The formula is: R ext = ∑ n S n V n , where R ext represents the external social network risk score, S n represents the value of the nth risk factor, V n represents its corresponding weight, and further assess the risk considering the propagation characteristics and influence scope of the external social network; The S300, in the comprehensive risk assessment of the comprehensive risk analysis, comprehensively considers internal and external factors, and calculates the comprehensive risk score through the comprehensive risk formula. The formula is: R total = R int ×α1 + R ext ×β1, where R total represents the comprehensive risk score of the business system, R int and R ext are the internal and external risk scores respectively, and α1 and β1 are weight coefficients. Furthermore, the risk level of the business system is determined, and different risk levels correspond to different security policies and countermeasures; S400, Security policy formulation and implementation: According to the results of the comprehensive risk analysis, formulate corresponding security policies. For internal risks, take measures such as strengthening employee training, adjusting the internal organizational structure, and strengthening the monitoring of specific employees; for external risks, take measures such as strengthening information security management, starting emergency response plans, and cooperating with external social network platforms for information control. Implement the formulated security policies, continuously monitor and evaluate their effects, and adjust and optimize according to the actual situation.

2. The security assessment method for a service system according to claim 1, characterized in that In the construction of the internal employee social network graph in S200, social network graph construction, employees are used as nodes, and each employee corresponds to a unique node identifier in the graph. If there is a social connection between two employees, an edge is established between their corresponding nodes. The weight of the edge is set according to factors such as the frequency and importance of the connection. Use the employee relationship strength formula to calculate the relationship strength between employees, and use Gephi to display the internal employee social network graph.

3. The security assessment method for a service system according to claim 2, wherein, The S200 calculates the relationship strength between employees through the employee relationship strength formula in the construction of the social network graph. The formula is: R ii = α2F ij + β2I ij + γ2T ij , where R ij represents the relationship strength between employee i and employee j, F ij represents the connection frequency, I ij represents the importance of the communication content, T ij represents the time span of the connection, and α2, β2, and γ2 represent different weight coefficients.

4. The security assessment method for a service system according to claim 1, characterized in that, In the construction of the external social network exposure and reputation graph in S200, social network graph construction, the business system itself, relevant social network topics, and key figures are used as nodes, and each node corresponds to a unique identifier in the graph. If the business system is associated with a certain social network topic, an edge is established between the corresponding nodes. The weight of the edge is set according to factors such as the popularity of the topic and the influence of key figures. By analyzing external social network information, calculate the exposure and reputation of the business system, and use Gephi to display the external social network exposure and reputation graph.

5. The security assessment method for a service system according to claim 4, characterized in that The S200 calculates the exposure E of the business system through the exposure calculation formula in social network graph construction. The formula is: E = ∑ k H k W k , where H k represents the popularity of the k-th relevant post and comment, and W k represents its degree of association with the business system.

6. A security assessment method for a service system according to claim 4, characterized in that, In the S200, the reputation of the business system is calculated through a reputation calculation formula in the construction of the social network graph. The formula is: Among them, P pos represents the number of positive comments, and P total represents the total number of comments. I l represents the influence of the key person l, and α3 and β3 are weight coefficients.

7. A security assessment method for a service system according to claim 1, characterized in that In the S300, in the comprehensive risk analysis, too tight small groups are identified in the internal employee social network graph through the small group tightness formula, and the formula is: where D group represents the tightness of the small group, N internal represents the number of connections between members within the small group, N total represents the maximum possible number of connections that the small group may have, R ij represents the relationship strength between employee i and employee j within the small group, and α4 and β4 are weight coefficients. Let the threshold of the small group tightness be T group , D group ≥T group triggers an alarm, and the alarm is sent to the security management personnel by means of email, text message and system pop-up window.

8. A security assessment method for a service system according to claim 1, characterized in that The S300 is used in comprehensive risk analysis to quantify the degree of leakage of sensitive information in a business system on an external social network through a sensitive information leakage degree calculation formula. The formula is: L sensitivity = ∑ post P sensitivity × H post , where L sensitivity represents the degree of sensitive information leakage, P sensitivity represents the proportion of sensitive information in a single post, and H post represents the popularity of the post. A sensitive information leakage threshold T leak is set. When the calculated degree of sensitive information leakage L sensitivity exceeds this threshold, it is determined that the sensitive information of the business system has been leaked externally.

9. A method for security assessment of a service system according to claim 1, characterized in that, In the S300, in the comprehensive risk analysis, the risk level is divided into three levels: high, medium, and low through the risk level assessment formula. The formula is as follows: Among them, L represents the risk level value, and R total is the comprehensive risk score mentioned above, and R min is the pre-set minimum risk threshold, and R max is the pre-set maximum risk threshold. The risk level is divided according to the value of L: when L≥80, it is determined as a high risk level; when 40≤L<80, it is determined as a medium risk level; when L<40, it is determined as a low risk level.

10. A security assessment method for a service system according to claim 9, characterized in that, In S300, the security policies and countermeasures for different risk levels in comprehensive risk analysis: High risk level: Immediately carry out high-intensity employee information security training and adjust the internal organizational structure within the company, establish an emergency response team to strengthen monitoring, and externally comprehensively strengthen access control to the business system, start the emergency response plan, and cooperate with external parties; Medium risk level: Organize regular employee information security training within the company, optimize the internal structure to clarify the information sharing mechanism, strengthen the authority management of key positions, and externally strengthen access control and formulate an emergency response plan to communicate with social platforms; Low risk level: Regularly carry out employee information security training within the company and maintain smooth internal collaboration, daily monitor social network behaviors and give security reminders, and externally maintain regular access control and improve the emergency response plan to cooperate with social platforms.