A network security level protection risk analysis system
By conducting pre-assessment and simulation assessments through the network security level protection risk analysis system, the problem of low assessment efficiency caused by repeated rectifications has been solved, achieving an efficient assessment process and convenient operation, and reducing costs and data turnover frequency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JIANGSU XIANGXIN INFORMATION SECURITY TECH CO LTD
- Filing Date
- 2025-02-28
- Publication Date
- 2026-05-26
AI Technical Summary
In the current network security level protection risk analysis, the system needs to be repeatedly submitted during the repeated rectification process, resulting in low evaluation efficiency, slow result acquisition speed, and long information transmission time.
The network security level protection risk analysis system is adopted, which includes a system connection unit, a pre-assessment unit, a formal assessment unit, and a result verification unit. By conducting pre-assessment and simulation assessment on the same computer, rectification points are obtained, rectification opinions are provided, until the required level protection is achieved, and the system is directly submitted for formal assessment, saving or shortening the repeated submission and rectification process.
It has optimized the efficiency of formal evaluation, reduced the cost of repeated submissions, increased the evaluation speed, made the operation convenient, and reduced the frequency of data turnover.
Smart Images

Figure CN120320970B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity risk analysis technology, and in particular to a cybersecurity risk analysis system. Background Technology
[0002] The role of cybersecurity level protection risk analysis is mainly reflected in several aspects, including: ensuring system security and compliance requirements, enhancing management level, identifying and mitigating data-related security risks, and understanding one's own cybersecurity status.
[0003] The typical information security compliance assessment process includes the following key steps: classification and filing, gap analysis, rectification and construction, assessment implementation, expert review, and supervision and inspection. During the gap analysis and expert review processes, any anomalies discovered will require rectification, which may be iterative. Throughout this iterative rectification process, the system needs to be repeatedly submitted. The information transmission and response to submissions both consume time, directly leading to low assessment efficiency and slow result retrieval. Summary of the Invention
[0004] This invention discloses a network security level protection risk analysis system, which aims to solve the technical problem that the system needs to be repeatedly submitted during the entire process of repeated rectification. The information transmission and response to the submitted content both take a certain amount of time, which directly leads to low evaluation efficiency and slow result acquisition speed.
[0005] To achieve the above objectives, the present invention adopts the following technical solution:
[0006] A network security level protection risk analysis system includes a system connection unit, a pre-assessment unit, a formal assessment unit, and a result verification unit. The system connection unit is used to establish a connection with the system under test. The pre-assessment unit is used to perform a pre-assessment of the system under test before the formal assessment and to obtain rectification points. The formal assessment unit is used to submit the system under test and formally conduct the level protection assessment. The result verification unit is used to compare and analyze the results of the pre-assessment unit and the formal assessment unit.
[0007] The pre-assessment unit includes an information filing module, a self-assessment module, a physical security assessment module, an information security assessment module, a security level assessment module, and a rectification analysis module. The information filing module is used by users to file information about the system under test in the system. The self-assessment module is used by users to select their self-estimated security level that they want to achieve. The physical security assessment module is used to perform physical security assessments on the system under test. The information security assessment module is used to perform information security assessments on the system under test. The security level assessment module assesses the security level based on the results of the physical security assessment and the information security assessment. The rectification analysis module analyzes the results of the physical security assessment and the information security assessment and provides rectification suggestions.
[0008] After downloading and installing this system on a computer, a connection path between the system under test and the computer can be established directly on the same computer through the system connection unit. Simulated testing can be performed through the pre-testing unit. After the simulated testing, the evaluation level and rectification analysis opinions can be obtained based on the test results. At this time, the user can carry out specific rectification based on the rectification analysis opinions. After rectification, the pre-test can be submitted again until the test reaches the required compliance level. Then, the formal test can be submitted directly through this system. Thus, with the support of this system, the repeated submission of formal test, repeated rectification, and time spent on information transmission are directly eliminated or shortened, thereby optimizing the efficiency of formal test and reducing the possible cost of repeated submission. Moreover, the system is easy to operate and can be implemented on the same computer, which also reduces the frequency of data turnover of the system under test, further optimizing the test efficiency.
[0009] In a preferred embodiment, the system connection unit includes a system connection module, an information reading module, a system clone module, and an information clearing module. The system connection module is used to directly establish a connection channel with the system under test. The information reading module obtains all information of the system under test based on the established connection channel. The system clone module is used to create a clone of the system under test in the system. The information clearing module is used to clear all data of the system under test after the graded protection risk analysis is completed.
[0010] The information security assessment module includes an information scanning module, an assessment zoning module, a zoning penetration module, and a result collection module. The information scanning module scans all information of the system under test. The assessment zoning module divides the scanned information into three major zones based on network security, application security, and data security, and further subdivides each zone into smaller zones for individual assessment. The zoning penetration module simulates hacker attack methods within the zoning structure of major zones and smaller zones to verify the system's security protection capabilities and emergency response capabilities. The result collection module collects the penetration results.
[0011] By setting up a system connection unit, in addition to establishing a direct connection with the system under test for convenient evaluation, the system connection unit also creates a clone for the system under test through a system clone module. All evaluation processes in the pre-evaluation unit are carried out in this clone, thereby ensuring that the main system under test will not be affected and its normal use will not be disrupted after being attacked by the partition penetration module.
[0012] In a preferred embodiment, the physical security assessment module includes an information reading module, a manual filling module, an information omission checking module, an omission filling and uploading module, and an information analysis module. The information reading module reads all information related to physical security from the information filed in the information filing module. The manual filling module is used to match information that cannot be determined, including photos and videos, with the project categories in the physical security assessment.
[0013] The information omission detection module is used to detect omissions in project categories that lack information and remind users. The omission upload module is used by users to upload missing information. The information analysis module performs physical security assessment based on the information obtained and uploaded.
[0014] By setting up a physical security assessment module, since formal physical security assessments generally require on-site personnel to conduct assessments based on the actual environment, the physical security assessment module enables priority assessment of remote physical security, ensuring that this priority assessment is not limited to information security items, and also provides effective assistance for formal physical security assessments.
[0015] In a preferred embodiment, the formal evaluation unit includes a rating and filing module, an evaluation implementation module, an expert review module, a supervision and verification module, and a result query module. The rating and filing module is used for users to conduct rating and filing before the formal evaluation, and the rating and filing module is connected to the information filing module, and can directly obtain useful information from the information filing module for filling.
[0016] The assessment implementation module, expert review module, and supervision and verification module are used to provide formal assessment, expert review, and supervision and verification functions respectively during the formal assessment. The result query module is used to obtain the results of the formal assessment. The expert review module is connected to the grade assessment module and the result verification unit.
[0017] The result verification unit includes a system evaluation result acquisition module, an expert review result acquisition module, an information verification module, a verification result analysis module, a reverse supply module, and an evaluation standard modification module. The system evaluation result acquisition module is used to acquire all evaluation results of the pre-evaluation unit, the expert review result acquisition module is used to acquire the review results of the expert review module, and the information verification module is used to compare the evaluation results of the pre-evaluation unit with the review results of the expert review module.
[0018] The collation result analysis module is used to analyze and compare the differences in the results. The reverse supply module is used to filter out the differences with the expert review module, and the differences are reasonable according to the expert review results. The differences are then fed back to the evaluation logic of the pre-evaluation unit. The evaluation standard modification module modifies the evaluation standard synchronously based on the modified evaluation logic in the pre-evaluation unit.
[0019] By setting up a result verification unit, a connection is established between the pre-evaluation unit and the expert review module, enabling continuous updates and improvements to the system's pre-evaluation logic, and further ensuring the accuracy of the pre-evaluation results.
[0020] As described above, a network security level protection risk analysis system includes a system connection unit, a pre-assessment unit, a formal assessment unit, and a result verification unit. The system connection unit establishes a connection with the system under test. The pre-assessment unit performs a pre-assessment of the system under test before the formal assessment and identifies rectification points. The formal assessment unit submits the system under test and formally conducts the level protection assessment. The result verification unit compares and analyzes the results of the pre-assessment unit and the formal assessment unit. The pre-assessment unit includes an information filing module, a self-assessment module, a physical security assessment module, and an information security module. The system comprises a full evaluation module, a level assessment module, and a rectification analysis module. The information filing module allows users to file information about the system under test. The self-assessment module allows users to select their desired cybersecurity level. The physical security evaluation module performs physical security assessments on the system under test, and the information security evaluation module performs information security assessments. The level assessment module determines the cybersecurity level based on the results of the physical and information security assessments. The rectification analysis module analyzes the results of the physical and information security assessments and provides rectification suggestions. This invention provides a cybersecurity level protection risk analysis system that optimizes the efficiency of formal evaluations, reduces the costs associated with repeated submissions, and is easy to operate, requiring only a single computer and reducing the frequency of data turnover for the system under test. Attached Figure Description
[0021] Figure 1 This is a schematic diagram of the overall structure of a network security level protection risk analysis system proposed in this invention.
[0022] Figure 2 This is a schematic diagram of the system connection unit structure of a network security level protection risk analysis system proposed in this invention.
[0023] Figure 3This is a schematic diagram of the physical security assessment module structure of a network security level protection risk analysis system proposed in this invention.
[0024] Figure 4 This is a schematic diagram of the information security assessment module structure of a network security level protection risk analysis system proposed in this invention.
[0025] Figure 5 This is a schematic diagram of the result verification unit structure of a network security level protection risk analysis system proposed in this invention. Detailed Implementation
[0026] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0027] The network security level protection risk analysis system disclosed in this invention is mainly applied to the scenario of level protection risk analysis.
[0028] Reference Figure 1 A network security level protection risk analysis system includes a system connection unit, a pre-evaluation unit, a formal evaluation unit, and a result verification unit. The system connection unit is used to establish a connection with the system under test. The pre-evaluation unit is used to perform a pre-evaluation of the system under test before the formal evaluation and to obtain rectification points. The formal evaluation unit is used to submit the system under test and formally conduct the level protection evaluation. The result verification unit is used to compare and analyze the results of the pre-evaluation unit and the formal evaluation unit.
[0029] The pre-assessment unit includes an information filing module, a self-assessment module, a physical security assessment module, an information security assessment module, a security level assessment module, and a rectification analysis module. The information filing module allows users to file information about the system under test within the system. The self-assessment module allows users to select their desired security level. The physical security assessment module performs physical security assessments on the system under test. The information security assessment module performs information security assessments on the system under test. The security level assessment module assesses the security level based on the results of the physical and information security assessments. The rectification analysis module analyzes the results of the physical and information security assessments and provides rectification suggestions. After downloading and installing the system on a computer, a connection path is established directly between the system under test and the pre-assessment unit on the same computer through the configured system connection unit. After authorization, all information of the system under test is obtained and transmitted to the pre-assessment unit. Simulated assessments can then be performed through the pre-assessment unit. In the preliminary assessment unit, simulated assessments of physical security and information security are conducted based on the filing data from the information filing module and the information of the system under test. The self-assessment module allows users to select their desired security level, providing comparative information for subsequent level assessment and rectification analysis. After the simulated assessments in both aspects, the assessment results are analyzed to obtain the assessment level and rectification analysis opinions. At this point, users can carry out specific rectifications based on the rectification analysis opinions. After rectification, the preliminary assessment can be submitted again until the required security level is achieved. Then, the formal assessment can be submitted directly through this system. Thus, with the support of this system, the repeated submission of formal assessments, repeated rectifications, and information transmission time are directly eliminated or shortened, thereby optimizing the efficiency of formal assessments and reducing the potential costs of repeated submissions. Moreover, the system is easy to operate and can be implemented on the same computer, which also reduces the frequency of data turnover of the system under test, further optimizing the assessment efficiency.
[0030] Reference Figure 2 In a preferred embodiment, the system connection unit includes a system connection module, an information reading module, a system clone module, and an information clearing module. The system connection module is used to directly establish a connection channel with the system under test. The information reading module obtains all information of the system under test based on the established connection channel. The system clone module is used to create a clone of the system under test in the system. The information clearing module is used to clear all data of the system under test after the graded protection risk analysis is completed.
[0031] Reference Figure 4In a preferred embodiment, the information security assessment module includes an information scanning module, an assessment zoning module, a zoning penetration module, and a result collection module. The information scanning module scans all information of the system under test. The assessment zoning module divides the scanned information into three major zones based on network security, application security, and data security, and further subdivides each zone into smaller zones for individual assessment. The zoning penetration module simulates hacker attack methods within the zoning structure of the major zones and smaller zones to verify the system's security protection and emergency response capabilities. The result collection module collects penetration results. In the system connection unit, in addition to establishing a direct connection with the system under test for convenient assessment, a system clone module is also used to create a clone for the system under test. All assessment processes in the pre-assessment unit are performed in this clone, thereby ensuring that the main system under test will not be affected or its normal operation will be disrupted after being attacked by the zoning penetration module. In addition, the information clearing module can be used to clean up the system clone to avoid data redundancy in the system.
[0032] Reference Figure 3 In a preferred embodiment, the physical security assessment module includes an information reading module, a manual filling module, an information omission checking module, an omission filling and uploading module, and an information analysis module. The information reading module reads all information related to physical security from the information filed in the information filing module. The manual filling module is used to match information that cannot be determined, including photos and videos, with the project categories in the physical security assessment.
[0033] Reference Figure 3 In a preferred embodiment, the information omission detection module is used to identify missing information categories and remind users. The omission upload module is used by users to upload missing information. The information analysis module performs physical security assessment based on the information acquired and uploaded. Since physical security assessment in formal assessments generally requires on-site personnel to conduct assessments based on the actual environment, the physical security assessment module allows users to remotely upload the actual environment to the system in the form of text, photos, and videos. The manual filling module and the information omission detection module complete the full matching of information and category items, and then the information is assessed and analyzed. This enables priority assessment of remote physical security, making the priority assessment not limited to information security items, and providing effective assistance for formal physical security assessments.
[0034] Reference Figure 1 In a preferred embodiment, the formal evaluation unit includes a rating and filing module, an evaluation implementation module, an expert review module, a supervision and verification module, and a result query module. The rating and filing module is used for users to conduct rating and filing before the formal evaluation, and the rating and filing module is connected to the information filing module, which can directly obtain useful information from the information filing module for filling.
[0035] Reference Figure 1 In a preferred embodiment, the evaluation implementation module, the expert review module, and the supervision and verification module are used to provide formal evaluation, expert review, and supervision and verification functions respectively during the formal evaluation. The result query module is used to obtain the results of the formal evaluation. The expert review module is connected to the grade assessment module and the result verification unit.
[0036] Reference Figure 5 In a preferred embodiment, the result verification unit includes a system evaluation result acquisition module, an expert review result acquisition module, an information verification module, a verification result analysis module, a reverse supply module, and an evaluation standard modification module. The system evaluation result acquisition module is used to acquire all evaluation results of the pre-evaluation unit, the expert review result acquisition module is used to acquire the review results of the expert review module, and the information verification module is used to compare the evaluation results of the pre-evaluation unit with the review results of the expert review module.
[0037] Reference Figure 5 In a preferred embodiment, the collation result analysis module is used to analyze and compare the differences in the results. The reverse supply module is used to filter out the differences with the expert review module, and the differences are considered reasonable in the expert review results. The differences are then fed back to the evaluation logic of the pre-evaluation unit. The evaluation standard modification module modifies the evaluation standards of the pre-evaluation unit based on the modified evaluation logic. The collation unit is set up to establish a connection between the pre-evaluation unit and the expert review module. After the pre-evaluation unit has conducted the evaluation and no rectification opinions are received, the system to be tested is submitted to the formal evaluation unit. If the expert review provides some rectification opinions or there are certain differences in the scores of several areas, the collation result analysis module analyzes the differences. If the analysis shows that the differences actually exist and are reasonable in terms of review, the evaluation logic of the pre-evaluation unit is modified in the grade evaluation module according to the expert review results. Under this structure, the continuous updating and improvement of the system's pre-evaluation logic can be achieved, further ensuring the accuracy of the pre-evaluation results.
[0038] Working Principle: After downloading and installing this system on a computer, a connection path is established directly between the system under test and the computer on the same computer through the configured system connection unit. After authorization, all information of the system under test is obtained and transmitted to the pre-evaluation unit. The pre-evaluation unit can then conduct simulated evaluations. In the pre-evaluation unit, simulated evaluations are performed on both physical security and information security aspects based on the filing data from the information filing module and the obtained information of the system under test. The self-assessment module allows users to select their self-estimated, desired compliance level, thus providing comparative information for subsequent compliance assessments and rectification analysis. After two rounds of simulated testing, the evaluation results can be analyzed to obtain the assessment level and rectification analysis opinions. At this time, users can carry out specific rectification based on the rectification analysis opinions. After rectification, they can resubmit the preliminary evaluation until the evaluation reaches the required security level. Then, they can directly submit the formal evaluation through this system. Thus, with the support of this system, the repeated submission of formal evaluations, repeated rectifications, and the time spent on information transmission are directly eliminated or shortened, thereby optimizing the efficiency of formal evaluation and reducing the possible cost of repeated submissions. Moreover, the system is easy to operate and can be implemented on the same computer, which also reduces the frequency of data turnover of the system under test, further optimizing the evaluation efficiency.
[0039] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A network security level protection risk analysis system, comprising a system connection unit, a pre-assessment unit, a formal assessment unit, and a result verification unit, characterized in that, The system connection unit is used to establish a connection with the system under test. The pre-evaluation unit is used to pre-evaluate the system under test before the formal evaluation and obtain rectification points. The formal evaluation unit is used to submit the system under test and formally conduct the information security evaluation. The result verification unit is used to compare and analyze the results of the pre-evaluation unit and the formal evaluation unit. The pre-assessment unit includes an information filing module, a self-assessment module, a physical security assessment module, an information security assessment module, a security level assessment module, and a rectification analysis module. The information filing module is used by users to file information about the system under test in the system. The self-assessment module is used by users to select their self-estimated security level and the security level they want to achieve. The physical security assessment module is used to conduct physical security assessments of the system under test. The information security assessment module is used to conduct information security assessments of the system under test. The security level assessment module assesses the security level based on the results of the physical security assessment and the information security assessment. The rectification analysis module analyzes the results of the physical security assessment and the information security assessment and provides rectification suggestions. The result verification unit includes a system evaluation result acquisition module, an expert review result acquisition module, an information verification module, a verification result analysis module, a reverse supply module, and an evaluation standard modification module. The system evaluation result acquisition module is used to acquire all evaluation results of the pre-evaluation unit, the expert review result acquisition module is used to acquire the review results of the expert review module, and the information verification module is used to compare the evaluation results of the pre-evaluation unit with the review results of the expert review module. The collation result analysis module is used to analyze and compare the differences in the results. The reverse supply module is used to filter out the differences with the expert review module, and the differences are reasonable according to the expert review results. The differences are then fed back to the evaluation logic of the pre-evaluation unit. The evaluation standard modification module modifies the evaluation standard synchronously based on the modified evaluation logic in the pre-evaluation unit.
2. The network security level protection risk analysis system according to claim 1, characterized in that, The system connection unit includes a system connection module, an information reading module, a system clone module, and an information clearing module. The system connection module is used to directly establish a connection channel with the system under test. The information reading module obtains all information of the system under test based on the established connection channel. The system clone module is used to create a clone of the system under test in the system. The information clearing module is used to clear all data of the system under test after the graded protection risk analysis is completed.
3. The network security level protection risk analysis system according to claim 1, characterized in that, The information security assessment module includes an information scanning module, an assessment zoning module, a zoning penetration module, and a result collection module. The information scanning module scans all information of the system under test. The assessment zoning module divides the scanned information into three major zones based on network security, application security, and data security, and further subdivides each zone into smaller zones for individual assessment. The zoning penetration module simulates hacker attack methods within the zoning structure of major zones and smaller zones to verify the system's security protection capabilities and emergency response capabilities. The result collection module collects the penetration results.
4. The network security level protection risk analysis system according to claim 1, characterized in that, The physical security assessment module includes an information reading module, a manual filling module, an information omission checking module, an omission filling and uploading module, and an information analysis module. The information reading module reads all information related to physical security from the information filed in the information filing module. The manual filling module is used to match information that cannot be determined, including photos and videos, with the project categories in the physical security assessment.
5. A network security level protection risk analysis system according to claim 4, characterized in that, The information omission detection module is used to detect omissions in project categories that lack information and remind users. The omission upload module is used by users to upload missing information. The information analysis module performs physical security assessment based on the information obtained and uploaded.
6. The network security level protection risk analysis system according to claim 1, characterized in that, The formal evaluation unit includes a rating and filing module, an evaluation implementation module, an expert review module, a supervision and verification module, and a result query module. The rating and filing module is used for users to conduct rating and filing before the formal evaluation. The rating and filing module is connected to the information filing module and can directly obtain useful information from the information filing module for filling.
7. A network security level protection risk analysis system according to claim 6, characterized in that, The assessment implementation module, expert review module, and supervision and verification module are used to provide formal assessment, expert review, and supervision and verification functions respectively during the formal assessment. The result query module is used to obtain the results of the formal assessment. The expert review module is connected to the grade assessment module and the result verification unit.