Security state evaluation method and device of network environment, equipment and storage medium

By obtaining security monitoring data from multiple data sources in the network environment, extracting features and using security situation models for evaluation, the problem of low evaluation accuracy in traditional methods is solved, and the adaptive security situation evaluation and compliance management of the network environment is improved.

CN120342697APending Publication Date: 2025-07-18CSG EHV POWER TRANSMISSION
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510501497.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The traditional network security state assessment method relies on manual intervention and static rules, and cannot adapt to changes in the network environment in real time, resulting in low evaluation accuracy.

Method used

By obtaining security monitoring data from multiple data sources in the network environment, statistical features, timing features and semantic features are extracted, security situation models are used for multi-dimensional evaluation, and matching them with network security compliance rules to generate compliance analysis results.

Benefits of technology

It realizes adaptive security situation evaluation of the network environment, improves the real-time and accuracy of the evaluation, and improves the efficiency and accuracy of compliance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342697A_ABST
    Figure CN120342697A_ABST
Patent Text Reader

Abstract

The invention relates to a security state evaluation method and device of a network environment, equipment and a storage medium. The method comprises the following steps: acquiring security monitoring data generated by a plurality of data sources in a network environment; the security monitoring data comprises log data, flow data and vulnerability data; extracting security features from the security monitoring data; the security features comprise statistical features, time sequence features and semantic features; inputting the security feature into a security situation model, determining security assessment index values of multiple dimensions according to the security feature through the security situation model, and determining a security situation assessment result of the network environment according to each security assessment index value; and matching the security situation assessment result with the network security compliance rule to generate a network security compliance analysis result of the network environment. By adopting the method, the security state evaluation accuracy of the network environment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a method, apparatus, computer device, computer-readable storage medium, and computer program product for evaluating the security status of a network environment. Background Art

[0002] In the field of network security technology, regularly performing security scans, vulnerability checks, traffic monitoring, etc. on various assets, services, and related devices in the network to identify potential security threats or compliance deviations is an essential link in ensuring network security. It can help enterprises ensure that their network environment complies with national, industry, or enterprise-internal security compliance standards, avoid data leakage, system vulnerabilities, and other security incidents, thereby safeguarding the network security and data protection of enterprises.

[0003] However, traditional security status evaluation methods usually rely on manual intervention and static security evaluation rules. This makes it impossible to perform real-time security status evaluation based on the latest network environment when the network environment changes or faces new security threats, resulting in a relatively low accuracy of the security status evaluation of the network environment. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium, and computer program product for evaluating the security status of a network environment that can improve the accuracy of the security status evaluation of the network environment.

[0005] In a first aspect, the present application provides a method for evaluating the security status of a network environment, including:

[0006] Obtaining security monitoring data generated by multiple data sources in the network environment; the security monitoring data includes log data, traffic data, and vulnerability data;

[0007] Extracting security features from the security monitoring data; the security features include statistical features, temporal features, and semantic features;

[0008] Inputting the security features into a security situation model, and determining security evaluation index values in multiple dimensions according to the security features through the security situation model, and determining the security situation evaluation result of the network environment according to each security evaluation index value;

[0009] Matching the security situation evaluation result with network security compliance rules to generate a network security compliance analysis result of the network environment.

[0010] In one embodiment, the determining security evaluation index values in multiple dimensions according to the security features through the security situation model includes:

[0011] Determine the asset exposure level, vulnerability threat level, attack complexity, compliance deviation degree, and network protection effectiveness according to the security features by means of the security situation model, as the security assessment index values of the multiple dimensions;

[0012] Among them, the asset exposure level is used to characterize the risk degree of asset exposure in the network environment; the vulnerability threat level is used to characterize the severity of vulnerabilities existing in the network environment; the attack complexity is used to characterize the complexity of attacking the network environment; the compliance deviation degree is used to measure the gap between the current security measures in the network environment and industry standards; the network protection effectiveness is used to measure the effectiveness of the current network protection measures in the network environment.

[0013] In one embodiment, determining the security situation assessment result of the network environment according to each of the security assessment index values includes:

[0014] Determine the current security situation assessment result of the network environment according to each of the security assessment index values;

[0015] Predict the security situation assessment result of the network environment in a future time period through the long short-term memory network in the security situation model according to the current security situation assessment result and the historical security situation assessment result.

[0016] In one embodiment, after predicting the security situation assessment result of the network environment in a future time period, the method further includes:

[0017] Obtain the weights corresponding to each of the security assessment index values when determining the current security situation assessment result and the network parameters of the long short-term memory network;

[0018] Construct a value function according to the current security situation assessment result and the benefit value after adjusting the weights and the network parameters; the value function is used to characterize the value of adjusting the weights and the network parameters for the current security situation assessment result.

[0019] Taking maximizing the value function as the optimization objective, optimize the weights and the network parameters to construct the optimized security situation model.

[0020] In one embodiment, extracting security features from the security monitoring data includes:

[0021] Conduct statistical analysis on the log data, traffic data, and vulnerability data included in the security monitoring data to obtain the statistical features;

[0022] Extract the security event features within each time window from the time series of network security events obtained from the analysis of the security monitoring data to obtain the time series features;

[0023] Convert the log data into vectorized semantic features;

[0024] Input the statistical features, the time series features, and the semantic features into an anomaly detection model, and identify, through the anomaly detection model, the abnormal features in the statistical features, the time series features, and the semantic features whose deviation from the normal behavior features is greater than a threshold as the security features.

[0025] In one embodiment, the matching of the security situation assessment result with the network security compliance rules to generate the network security compliance analysis result of the network environment includes:

[0026] When the security situation assessment result meets the data category applicable to any of the network security compliance rules, determine that the security situation assessment result matches any of the network security compliance rules; the network security compliance rules are knowledge graphs constructed according to compliance standards, compliance terms, and security requirements;

[0027] Generate a compliance gap report according to the difference between the security situation assessment result and any of the network security compliance rules, and determine the network security compliance analysis result of the network environment according to the compliance gap report.

[0028] In a second aspect, the present application also provides a security status assessment device for a network environment, including:

[0029] An acquisition module, configured to acquire security monitoring data generated by multiple data sources in a network environment; the security monitoring data includes log data, traffic data, and vulnerability data;

[0030] An extraction module, configured to extract security features from the security monitoring data; the security features include statistical features, time series features, and semantic features;

[0031] A determination module, configured to input the security features into a security situation model, and determine, through the security situation model, security assessment index values in multiple dimensions according to the security features, and determine the security situation assessment result of the network environment according to the security assessment index values;

[0032] A generation module, configured to match the security situation assessment result with network security compliance rules to generate the network security compliance analysis result of the network environment.

[0033] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.

[0034] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0035] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0036] For the above network environment security state evaluation method, device, computer device, computer-readable storage medium, and computer program product, security monitoring data generated by multiple data sources in the network environment is obtained, where the security monitoring data includes log data, traffic data, and vulnerability data; security features are extracted from the security monitoring data, where the security features include statistical features, temporal features, and semantic features; the security features are input into a security situation model, and the security situation model determines security evaluation index values in multiple dimensions according to the security features, and determines the security situation evaluation result of the network environment according to each security evaluation index value; the security situation evaluation result is matched with network security compliance rules to generate a network security compliance analysis result of the network environment. By collecting security monitoring data of multiple data sources in real time and performing in-depth analysis and feature extraction on the security monitoring data, intelligent analysis and dynamic modeling can be performed according to multiple types of security features through the security situation model, so that the security state evaluation of the network environment can adapt to the changes of the network environment, significantly improving the real-time performance and accuracy of security situation analysis, and being able to comprehensively and accurately determine the security situation evaluation result of the network environment according to multiple security evaluation index values, and matching the security situation evaluation result with network security compliance rules to achieve automated verification of existing compliance standards, comprehensively improving the efficiency and accuracy of network security compliance management, thereby improving the comprehensiveness and accuracy of the security state evaluation of the network environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments of the present application or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0038] Figure 1 It is an application environment diagram of a security state evaluation method for a network environment in an embodiment;

[0039] Figure 2 is a schematic flowchart of a method for evaluating the security status of a network environment in an embodiment;

[0040] Figure 3 is a schematic flowchart of a method for evaluating the security status of a network environment in another embodiment;

[0041] Figure 4 is a structural block diagram of a device for evaluating the security status of a network environment in an embodiment;

[0042] Figure 5 is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0043] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0044] The method for evaluating the security status of a network environment provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed in the cloud or on other network servers. The terminal 102 obtains security monitoring data generated by multiple data sources in the network environment; the security monitoring data includes log data, traffic data and vulnerability data; the terminal 102 extracts security features from the security monitoring data; the security features include statistical features, temporal features and semantic features; the terminal 102 inputs the security features into a security situation model, and the security situation model determines security evaluation index values in multiple dimensions according to the security features, and determines the security situation evaluation result of the network environment according to each security evaluation index value; the terminal 102 matches the security situation evaluation result with network security compliance rules to generate a network security compliance analysis result of the network environment. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0045] In an exemplary embodiment, as Figure 2 shown, a method for evaluating the security state of a network environment is provided. Taking the method applied to Figure 1 the terminal 102 in

[0046] Step S202: Obtain security monitoring data generated by multiple data sources in the network environment.

[0047] Among them, the security monitoring data includes log data, traffic data, and vulnerability data.

[0048] Among them, the security monitoring data generated by multiple data sources may include data from different security devices, or may include different types of data (such as log data, traffic data, vulnerability data, etc.) generated in the same security device. Among them, security devices may include firewalls, Web Application Firewalls (WAFs), and Intrusion Detection Systems (IDSs), etc.

[0049] In a specific implementation, the security monitoring data generated by multiple data sources in the network environment is usually multi-source heterogeneous data. Efficiently obtaining and standardizing real-time multi-source heterogeneous data is the primary step to ensure data consistency and the accuracy of subsequent analysis.

[0050] Optionally, the terminal can use Flume and Kafka as the intermediate layer for data transfer and transmission, and at the same time combine the adapter to connect to multiple security devices to complete the access and unified processing of security monitoring data. In other words, the terminal can obtain security monitoring data generated by multiple data sources in the network environment through the data collection framework of Flume and Kafka. Flume is an efficient and reliable distributed system for large-scale data collection. By configuring multiple Flume agent nodes, the terminal can collect real-time security monitoring data from different security devices, network traffic collection points, log systems, etc. The security monitoring data can include firewall logs, traffic data, vulnerability scan reports, etc. Each Flume agent node can transmit the security monitoring data collected from multiple data sources to Kafka. Kafka is a high-throughput and low-latency message queue system responsible for transmitting the data collected by Flume to subsequent processing modules. Kafka divides the data from different sources into multiple topics to ensure the efficiency and scalability of the data stream. The message persistence during data transmission ensures the fault tolerance of the system. It can be seen that in the process of data transfer, through the combination of Flume and Kafka, the unified transmission and management of multi-source heterogeneous data (such as log data, traffic data, vulnerability data, etc.) are realized. The security devices that the terminal needs to connect to mainly include firewalls (FW), web application firewalls (WAF), intrusion detection systems (IDS), etc.

[0051] In specific implementation, these security devices may have different data formats and communication protocols in different manufacturers and models. The terminal can include a dedicated adapter. The adapter is used to convert the security monitoring data provided by the security device into a unified standard format and send it into Kafka through Flume to obtain security monitoring data generated by multiple data sources in the network environment. Each adapter adopts a corresponding parsing method according to the different protocols of the device. Firewall logs may be transmitted in Syslog format, while IDS may use a custom JSON format. The terminal can define a set of standard protocol parsing rules for the adapter. The adapter can extract relevant information (such as event time, attack type, source IP, etc.) from the original security monitoring data. Then, through the adapter, the original security monitoring data is converted into a unified JSON or Avro format to obtain the security monitoring data in unified format. The standardized format helps subsequent data storage, processing, and analysis to ensure consistency during data transmission. Then, the security monitoring data in unified format can be subjected to data normalization processing to obtain standardized security monitoring data to eliminate the format differences of different data sources and ensure that the data can be uniformly interpreted in subsequent analysis.

[0052] Exemplarily, for the log data generated by different security devices, a regular expression library can be established to automatically match important fields in the log data (such as event ID, IP address, attack type, etc.). Therefore, for the log data in the unified format of security monitoring data, the log data can be regularized and mapped to unified standard fields, such as timestamp, sourceIP, eventType, etc., to form standardized structured data.

[0053] Exemplarily, for specific information in the unified format of security monitoring data (such as source IP of attack, target port, etc.), a set of custom tag systems can be defined. These tags identify data from different sources, facilitating subsequent analysis and risk assessment. For example, for the "allow" and "deny" fields in firewall logs, tags FW_ALLOW and FW_BLOCK can be defined to mark the type of the event.

[0054] In specific implementation, during the data normalization process, the terminal will clean and filter the security monitoring data in the unified format, removing irrelevant information, duplicate data, and noisy data. For example, discard irrelevant non-security events and merge duplicate security alert data according to preset rules to avoid data redundancy.

[0055] Through the unified collection and normalization of security monitoring data generated by multiple data sources, finally standardized security monitoring data is obtained. The standardized security monitoring data can be expressed as:

[0056] ;

[0057] Among them, represents all the security monitoring data finally obtained by the terminal, is each standardized data record, that is, each standardized security monitoring data. Each data record has a structure form of:

[0058] .

[0059] Subsequently, the terminal can extract security features from the standardized security monitoring data.

[0060] Due to the heterogeneity of multi-source data and the different log formats of different security devices, the core challenge of data collection is how to ensure that data from different data sources can be uniformly processed without losing key information. The terminal can ensure data accuracy through the combination of Flume and Kafka and ensure real-time data transmission to enable low-latency data collection in the face of the diversity and suddenness of security events. At the same time, relying on the high throughput characteristics of Kafka, it can efficiently process and store massive data while ensuring the stability and low latency of data collection under high concurrency. Through the collaborative work of Flume and Kafka, combined with adapters and standardized processing mechanisms, the real-time collection and standardization of multi-source data have been successfully achieved. This process provides high-quality input data for subsequent automated data mining and security situation modeling, laying a solid foundation for the overall performance and accuracy of the system.

[0061] Step S204, extract security features from the security monitoring data.

[0062] Among them, the security features include statistical features, temporal features, and semantic features.

[0063] In specific implementation, the terminal extracts security features from the security monitoring data, which means automatically discovering potential security threats through data mining techniques, mining valuable feature information, and providing effective support for subsequent security situation modeling. To ensure the comprehensiveness and multidimensionality of the features, the terminal can adopt hybrid feature engineering, combining three types of information: statistical features, temporal features, and semantic features, to construct a comprehensive feature set.

[0064] In one embodiment, extracting security features from the security monitoring data may include: performing statistical analysis on the log data, traffic data, and vulnerability data included in the security monitoring data to obtain statistical features; extracting the security event features within each time window from the time series of network security events analyzed based on the security monitoring data to obtain temporal features; and converting the log data into vectorized semantic features.

[0065] Among them, the statistical features can be the statistical analysis of data such as traffic data, log data, and vulnerability data, and indicators such as frequency and distribution are extracted. These statistical features can reveal abnormal fluctuations in network traffic or attack patterns.

[0066] Optionally, the statistical feature can be the access frequency in the firewall log, that is, the request frequency of the IP address. The request frequency of the IP address can be equal to the ratio between the total number of access requests of the IP address within a specified time period and the time window of this frequency. This statistical feature can be used to discover potential DOS attacks (Denial of Service).

[0067] The statistical features may include:

[0068] ;

[0069] wherein, represents the request frequency of the source , is the total number of access requests within a specified time period, is the time window for calculating this frequency.

[0070] Among them, the time series feature can be the security event feature within each time window extracted from the time series of security data. Since network security events have temporality and attack behaviors often follow a certain time series pattern, the extraction of time series features is crucial for anomaly detection. The terminal can adopt a sliding window method to extract the security event features within each time window from the time series as the time series features, such as the anomaly degree of traffic change, the time interval of log events, etc.

[0071] Optionally, the time series features may include:

[0072] ;

[0073] wherein, represents the anomaly degree at the time point , is the feature value of the current time window, and are respectively the mean and standard deviation of the feature values of the previous time window. Through this formula, anomaly points inconsistent with normal traffic or network behaviors can be detected. Optionally, the feature value may include: summary features of traffic data within the current time window (such as the total traffic within the window, traffic frequency, or number of connections), the time interval of log events within the current time window (such as the average time interval of log events or the frequency of log event occurrences). By comparing the feature value of the current window with the mean and standard deviation of the previous window (or multiple windows), abnormal behaviors or attack events that significantly deviate from the normal pattern in the time series can be effectively identified.

[0074] Among them, the semantic feature can be the vectorized semantic feature successfully converted by natural language processing technologies (such as TF-IDF, Word2Vec, etc.). The log data in security monitoring data often contains rich business semantic information. For example, attackers may leave specific keywords or abnormal behavior patterns in the logs. By converting the log data into vectorized semantic features, potential malicious behaviors can be helped to be discovered. For example, SQL injection attacks or XSS (Cross-Site Scripting) attacks can be detected based on abnormal keywords in the logs.

[0075] Optionally, the semantic features may include:

[0076] ;

[0077] wherein, is the frequency of occurrence of the term in the document ; is the number of documents containing the term t, is the total number of documents. The calculation of this semantic feature can help discover malicious vocabulary frequently appearing in the log data, so as to identify potential attacks.

[0078] In a specific implementation, the terminal can parallelly extract statistical features, temporal features and semantic features based on a distributed feature calculation framework. Considering the large and continuously increasing amount of network security data, the terminal can build a distributed feature calculation framework based on PySpark. PySpark supports parallel processing of large-scale data and can quickly extract various features from massive log and traffic data. This distributed feature calculation framework performs parallel processing on the data through RDD (Resilient Distributed Dataset) operations, significantly improving the efficiency of feature calculation. Specifically, the terminal can convert the collected standardized security monitoring data into the RDD format, which can perform efficient feature calculation in a distributed environment to extract and summarize the features in the security monitoring data of different data sources. The distributed computing of PySpark can process a large amount of security data and complete the extraction and calculation of features in a short time. This parallel processing can effectively support the real-time analysis of massive log data and ensure the timeliness of the data mining results.

[0079] Step S206: Input the security features into a security situation model, and determine security assessment index values in multiple dimensions according to the security features through the security situation model, and determine the security situation assessment result of the network environment according to each security assessment index value.

[0080] Among them, the security assessment index values in multiple dimensions can reflect the security state of the network system from different perspectives, and each dimension has corresponding feature support.

[0081] In one embodiment, determining security assessment index values in multiple dimensions according to the security features through the security situation model includes: determining the asset exposure level, vulnerability threat degree, attack complexity, compliance deviation degree and network protection effectiveness according to the security features through the security situation model as the security assessment index values in multiple dimensions.

[0082] Among them, the asset exposure level is used to characterize the risk degree of asset exposure in the network environment. In other words, the asset exposure level reflects the risk degree of devices and services exposed to the outside in the network. Through the security posture model, asset-related features such as the number of open ports of network devices, types of accessible services, and network topology can be extracted from security features, and the asset exposure level can be determined based on the asset-related features.

[0083] Optionally, the asset exposure level can be expressed as:

[0084] ;

[0085] Among them, indicates whether the th asset is exposed, is the indicator function of asset exposure, is the total number of assets. Therefore, the asset exposure level can be measured by calculating the proportion of exposed assets.

[0086] Among them, the vulnerability threat degree is used to characterize the severity of vulnerabilities existing in the network environment. Through the security posture model, vulnerability-related features such as the CVSS (Common Vulnerability Scoring System) score of vulnerabilities, repair status, and whether there are public attack methods can be extracted from security features, and the vulnerability threat degree can be determined based on the vulnerability-related features.

[0087] Optionally, the vulnerability threat degree can be expressed as:

[0088] ;

[0089] Among them, represents the CVSS score of the th vulnerability, is the weight of the vulnerability repair status, is the total number of vulnerabilities, and the vulnerability threat degree can be determined by performing weighted calculation on the CVSS score.

[0090] Among them, the attack complexity is used to characterize the complexity of attacking the network environment. In other words, the attack complexity is used to describe the resources and technical difficulty that the attacker needs to invest. Through the security posture model, attack-related features such as the complexity of the attack method, required attack tools, and complexity of the attack path can be extracted from security features, and the attack complexity can be determined based on the attack-related features.

[0091] Optionally, the attack complexity can be expressed as:

[0092] ;

[0093] Among them, indicates the The complexity of an attack method is the total number of attack methods. By averaging the complexity of different attack methods.

[0094] Among them, the compliance deviation is used to measure the gap between the current security measures in the network environment and industry standards, which can be GDPR, ISO 27001, etc. Through the security posture model, compliance-related features such as compliance inspection results and the implementation of compliance requirements can be extracted from security features, and these compliance-related features can be obtained from the compliance inspection tools of data sources.

[0095] Optionally, the compliance deviation can be expressed as:

[0096] ;

[0097] Among them, indicates whether the th compliance requirement is met, is the total number of items of the compliance standard. The degree of compliance deviation is measured by calculating the number of items that deviate from the compliance standard.

[0098] Among them, the network protection effectiveness is used to measure the effectiveness of the current network protection measures in the network environment. The network protection measures can include network protection measures such as firewalls, IDSs, and WAFs. Through the security posture model, protection-related features such as the configuration of protection tools, interception rate, and false alarm rate can be extracted from security features, and these protection-related features can be extracted from the log data in security monitoring data.

[0099] Optionally, the network protection effectiveness can be expressed as:

[0100] ;

[0101] Among them, is the number of attack events successfully intercepted, is the number of attack events with missed reports. The protection effect is evaluated by calculating the interception rate of the protection measures.

[0102] In one embodiment, the security posture assessment result may include the values of each security assessment index.

[0103] In one embodiment, the security situation assessment result may include the weighted sum result of each security assessment index value. In a specific implementation, determining the security situation assessment result of the network environment based on each security assessment index value may include: performing a weighted sum on each security assessment index value to obtain a comprehensive security situation score as the security situation assessment result. Optionally, the weights of each security assessment index value may be calculated by the Analytic Hierarchy Process (AHP). First, a comparison matrix of the security assessment index values of each dimension is constructed, and the weights of the security assessment index values of each dimension are calculated by the eigenvalue method. The finally obtained weight values can be expressed as:

[0104] ;

[0105] where, represents the weight value of the security assessment index value of the th dimension, is the sum of the weight values of the security assessment index values of all dimensions.

[0106] After determining the weight values of each dimension, a weighted sum can be performed on each security assessment index value to obtain a comprehensive security situation score, which represents the overall security status of the network. The comprehensive security situation score can be expressed as:

[0107] ;

[0108] where, represents the security assessment index value of the th dimension, is the weight value of the th dimension. Through weighted summation, a comprehensive security situation score is obtained as the final security situation assessment result.

[0109] By constructing a dynamic and multi-dimensional security situation model, it is possible to combine security features to real-time assess the security situation of the network environment and identify potential risks and security vulnerabilities. Multi-dimensional security situation modeling relies on security assessment index values of multiple dimensions, and these indicators are combined through mathematical formulas and models to form a comprehensive security scoring system, which evaluates the overall security state of the network and helps the security team to timely identify and respond to potential security threats.

[0110] Step S208, matching the security situation assessment result with the network security compliance rules to generate a network security compliance analysis result of the network environment.

[0111] Among them, the network security compliance rules are rules for judging whether the network environment meets the security compliance standards of the country, industry or enterprise internal, that is, a kind of compliance requirement.

[0112] In specific implementation, matching the security situation assessment result with the network security compliance rules can be to perform intelligent correlation analysis on the security situation assessment result and the compliance requirements to generate the network security compliance analysis result, providing specific guiding suggestions for subsequent repair and optimization. Compliance analysis is a key step to ensure that an enterprise complies with relevant regulations and standards, which can help the enterprise identify the gaps from the legal compliance requirements and prevent potential compliance risks. The core of compliance analysis lies in the understanding and application of multiple security compliance standards.

[0113] In one embodiment, before matching the security situation assessment result with the network security compliance rules, a knowledge graph of network security compliance rules can be constructed according to compliance standards, compliance terms, and security requirements, so as to obtain the network security compliance rules in the form of a knowledge graph, and then the security situation assessment result is matched with the network security compliance rules to generate the network security compliance analysis result of the network environment.

[0114] Among them, the knowledge graph can include three main entities: entities, relationships, and attributes. Among them, entities include compliance standards, regulatory clauses, network assets, vulnerabilities, network events, etc.; relationships include the dependency relationships or impact links between entities, such as the association between compliance standards and compliance clauses, the dependency between vulnerabilities and vulnerability repairs, etc.; attributes refer to the attributes of each entity, such as the specific requirements of compliance clauses, the harm level of vulnerabilities, etc.

[0115] For example, assume that a clause of a compliance standard requires the encryption protection of specific types of data. At this time, it can be represented as a triple of entity-relationship-entity:

[0116] , that is, the compliance standard GDPR requires data to be encrypted.

[0117] The relationship between each compliance clause and its applicable assets, risk points, and security control measures can be represented in the knowledge graph through this structure.

[0118] After constructing the knowledge graph of network security compliance rules, a rule reasoning algorithm can be used for intelligent correlation analysis to automatically match the network security compliance rules with the current security situation assessment results, so as to identify the deficiencies and deviations of the enterprise in terms of compliance and obtain the network security compliance analysis results. Optionally, the rule reasoning algorithm can be the Rete algorithm, which is an efficient rule matching algorithm that can quickly match and infer the association between compliance standards and the actual security status (such as security vulnerabilities, asset exposures, etc.) in the network environment based on the security situation assessment results and network security compliance rules. This algorithm describes the conditions between rules by establishing a network and efficiently performs reasoning in a streaming processing manner. In the compliance intelligent correlation analysis, the network security compliance rules can be used as rule conditions, and the network security status (such as vulnerabilities, attack events, etc.) described in the security situation assessment results can be regarded as fact data, and the inference engine analyzes which compliance requirements in the fact data are not met based on these rule conditions.

[0119] In one embodiment, matching the security situation assessment results with the network security compliance rules to generate the network security compliance analysis results of the network environment may include: when the security situation assessment results meet the data category applicable to any network security compliance rule, determining that the security situation assessment results match any network security compliance rule; the network security compliance rules are knowledge graphs constructed according to compliance standards, compliance clauses, and security requirements; generating a compliance gap report based on the differences between the security situation assessment results and any network security compliance rule, and determining the network security compliance analysis results of the network environment according to the compliance gap report.

[0120] In specific implementation, the terminal can, according to the current security situation assessment results, match each fact data (such as asset exposure level, vulnerability threat level, etc.) in the security situation assessment results with the network security compliance rules, and determine whether each fact data in the security situation assessment results meets the data category applicable to the network security compliance rules. For example, vulnerability data is applicable to vulnerability management rules. When the security situation assessment results meet the data category applicable to any network security compliance rule, the network security compliance rule can be activated, and through the inference engine, relevant compliance defects can be marked, a compliance gap report can be generated based on the differences between the security situation assessment results and any network security compliance rule, indicating which compliance clauses have not been complied with, and repair suggestions can be generated to obtain the network security compliance analysis results of the network environment.

[0121] Through this reasoning mechanism, the gap between the security status and compliance standards can be automatically identified, and actionable repair suggestions can be provided.

[0122] Among them, the compliance gap report is one of the output results of compliance intelligent correlation analysis. By comparing the current security status with compliance standards, it reveals compliance deviations and helps enterprises identify potential compliance risks.

[0123] Exemplarily, the compliance gap report may include gap identification results, risk assessment results, and remediation suggestions.

[0124] First, the terminal can list the terms under each compliance standard according to network security compliance rules and check their compliance in the current network security environment based on the security posture assessment results. For example, if a certain compliance clause requires encryption protection for a specific type of data and this protection measure is not implemented in the current network environment, the gap identification result can be recorded in the compliance gap report.

[0125] Exemplarily, the gap identification result can be expressed as:

[0126] ;

[0127] Among them, is the number of instances that do not meet the compliance requirements, is the total number of all applicable instances. In this way, the compliance gap can be quantitatively demonstrated.

[0128] In addition, the terminal can assign a risk level to each compliance deviation according to the severity of the gap as the risk assessment result and record it in the compliance gap report. Clauses with a greater degree of compliance deficiency will be marked as high risk, affecting the overall compliance and legal liability of the enterprise; while low-risk deviations will be marked as low risk.

[0129] Finally, the terminal can generate remediation suggestions for each compliance defect based on the analysis of the compliance gap. For example, if some data is not encrypted, the terminal can recommend enabling data encryption technology, or updating firewall configuration and other remediation suggestions and record them in the compliance gap report. Optionally, the remediation suggestions may include information such as technical solutions, implementation steps, and cost estimates.

[0130] Exemplarily, the remediation suggestion can be expressed as the remediation priority:

[0131]

[0132] Among them, represents the risk level, represents the degree of impact of the compliance deficiency on the enterprise's business. After comprehensive calculation, a priority can be assigned to each remediation task to ensure that the enterprise can first solve high-risk and high-impact problems.

[0133] In the above security status evaluation method for the network environment, security monitoring data generated by multiple data sources in the network environment is obtained, where the security monitoring data includes log data, traffic data, and vulnerability data; security features are extracted from the security monitoring data, where the security features include statistical features, temporal features, and semantic features; the security features are input into a security situation model, and the security situation model determines security evaluation index values in multiple dimensions according to the security features, and determines the security situation evaluation result of the network environment according to each security evaluation index value; the security situation evaluation result is matched with network security compliance rules to generate a network security compliance analysis result for the network environment. By collecting the security monitoring data of multiple data sources in real time and deeply analyzing and extracting features from the security monitoring data, intelligent analysis and dynamic modeling can be performed according to multiple types of security features through the security situation model, so that the security status evaluation of the network environment can adapt to the changes in the network environment, significantly improving the real-time performance and accuracy of security situation analysis, and being able to comprehensively and accurately determine the security situation evaluation result of the network environment according to multiple security evaluation index values, and matching the security situation evaluation result with network security compliance rules to achieve automatic verification of existing compliance standards, comprehensively improving the efficiency and accuracy of network security compliance management, thereby improving the comprehensiveness and accuracy of the security status evaluation of the network environment.

[0134] In another embodiment, extracting security features from the security monitoring data includes: performing statistical analysis on the log data, traffic data, and vulnerability data included in the security monitoring data to obtain statistical features; extracting security event features within each time window from the time series of network security events obtained by analyzing the security monitoring data to obtain temporal features; converting the log data into vectorized semantic features; inputting the statistical features, temporal features, and semantic features into an anomaly detection model, and identifying, through the anomaly detection model, anomaly features whose deviation degree from normal behavior features in the statistical features, temporal features, and semantic features is greater than a threshold as security features.

[0135] Exemplarily, the anomaly monitoring model can be an anomaly detection model based on an autoencoder. The autoencoder can effectively discover anomaly points in the data while learning the normal behavior features of the data by compressing and reconstructing the input data. The autoencoder is a neural network model that includes an encoder and a decoder. During the training process, the model learns to compress the input data into a smaller representation space (encoding), and then reconstruct the data from this representation space. Data with a large reconstruction error is considered anomaly data, that is, potential security events.

[0136] ;

[0137] Among them, is the input data, is the output data after being reconstructed by the autoencoder. A larger reconstruction error indicates that this data point has a large difference from the normal mode and may have abnormal behavior.

[0138] Based on the trained autoencoder model, an anomaly score can be calculated for each statistical feature, temporal feature, and semantic feature to reflect its deviation from the normal behavior features. And the abnormal features with a deviation degree greater than the threshold are marked as potential security events, which are used as security features for subsequent input into the security situation model.

[0139] Through a combination of hybrid feature engineering and deep learning models, the terminal can obtain a feature set of security features and the corresponding anomaly scores (the degree of deviation from normal behavior features). The feature set of security features can be expressed as:

[0140] ;

[0141] Among them, represents all the extracted features, represents the th feature.

[0142] The calculation formula for the anomaly score is:

[0143] .

[0144] Through the above technical solution, by combining hybrid feature engineering and deep learning models, valuable features can be extracted from security monitoring data, and potential security threats can be effectively identified. This process provides important data support for subsequent security situation modeling and risk prediction, ensuring that the system can detect abnormal behaviors and potential attacks in a timely and accurate manner when facing a complex and dynamic network security environment.

[0145] In another embodiment, the security situation assessment result of the network environment is determined according to each security assessment index value, including: determining the current security situation assessment result of the network environment according to each security assessment index value; predicting the security situation assessment result of the network environment in a future time period through the long short-term memory network in the security situation model based on the current security situation assessment result and the historical security situation assessment result.

[0146] In specific implementation, in order to improve the prediction ability of the security situation model and realize the prediction of dynamic security situation changes, a time series analysis method based on LSTM (long short-term memory network) can be introduced. LSTM can capture the long-term dependence relationships in historical security situation data and predict the security risks in the future for a period of time.

[0147] In the LSTM, the input data is the current security situation assessment result and the historical security situation assessment result. The current security situation assessment result can be used as the latest historical security situation assessment result, and the output of the LSTM is the predicted value of the security situation assessment result in the future for a period of time. The LSTM recursively processes the input data through time steps and learns the patterns in the time series.

[0148] Exemplarily, the output of the LSTM network can be expressed as:

[0149] ;

[0150] where, is the input data at the current time step. Optionally, the input data can include not only the security situation assessment result but also data such as the attack frequency. is the output of the LSTM network, representing the predicted future security risks. The future security risks can include the security situation assessment result in the future time period and the predicted value of the attack frequency in the future time period.

[0151] In the above technical solution, the LSTM network in the security situation model is used to predict the future security situation assessment result, and the future security risks can be warned.

[0152] In another embodiment, after predicting the security situation assessment result in the future time period of the network environment, it further includes: obtaining the weights corresponding to each security assessment index value and the network parameters of the long short-term memory network when determining the current security situation assessment result; constructing a value function according to the current security situation assessment result and the benefit value after adjusting the weights and network parameters; the value function is used to characterize the value of adjusting the weights and network parameters for the current security situation assessment result; taking maximizing the value function as the optimization goal, optimizing the weights and the network parameters to construct an optimized security situation model.

[0153] In the specific implementation, in the process of security situation assessment, a real-time update and feedback mechanism of the model needs to be introduced to continuously update the model according to real-time data to adapt to the changing network environment. Therefore, an online learning mechanism based on reinforcement learning can be introduced, which can adjust the parameters and weights of the security assessment model according to new data feedback, so that the model can self-optimize over time. The key of the online learning mechanism is to update the model according to new security monitoring data. Specifically, new events and features will be obtained from the real-time collected security monitoring data and fed back to the security situation model. Through this mechanism, it can adapt to the dynamically changing network environment without the need for a full re-training. The reinforcement learning module is the core component of the online learning mechanism, and the value function can be expressed as the update formula of reinforcement learning:

[0154] ;

[0155] in, Indicates the current status Next select action The value of is the reward value, is the discount factor, is the learning rate. By continuously updating the value function, it is possible to make the best decision when facing a new environment. Specifically, the state It can be the current security situation assessment result, action It can be used to adjust the weights and reward values corresponding to the security assessment index values of each dimension. It can be used to reflect the effect after adjusting the weight (such as the benefit measurement value of detection accuracy, false alarm rate reduction, or prediction effect improvement), discount factor Used to control whether the model focuses on short-term effects or long-term effects. To maximize the value function As an optimization goal, the best strategy can be found to make the long-term security situation assessment results the most accurate, with the lowest false positives and the highest security.

[0156] The above technical solution dynamically optimizes the model through a reinforcement learning mechanism. This security situation model can reflect the security status of the network in real time and accurately, providing strong data support for subsequent decision-making.

[0157] In another embodiment, the network security compliance analysis results may include a risk heat map. The risk heat map is used to intuitively display compliance deviations and security risks, as well as the status of different assets, services, and systems in terms of compliance and security risks, so that the security team can quickly locate problem areas.

[0158] The risk heat map combines the network topology with compliance deviations and risk scores to display the risk level of each area in the network environment. The terminal determines the risk level of the area based on security assessment indicators such as asset exposure level and vulnerability threat level, and colors different areas according to the risk level, so that high-risk areas can be clearly seen at a glance.

[0159] Based on the risk assessment results, the risk heat map visually displays each asset, service, and device in the network environment according to their risk levels. Red indicates high-risk areas, suggesting significant compliance deficiencies or security vulnerabilities in the network environment; yellow indicates medium-risk areas, suggesting certain compliance deviations but relatively minor impacts; green indicates low-risk areas, suggesting that the network environment meets compliance requirements and the security protection measures are in place. This visual display method enables network security administrators to intuitively see the security weak areas and high-risk parts in the current network and take corresponding compliance and security optimization measures.

[0160] Optionally, the generation of the risk heat map depends on the following formula:

[0161] ;

[0162] where represents the impact factor of the th asset, is the vulnerability score of this asset, and is the number of assets. Through this weighted calculation, the risk level can be effectively combined with the actual security threats, providing an intuitive visual basis for decision-making.

[0163] In another embodiment, the terminal can dynamically adjust the rule base through expert feedback. Expert feedback refers to the operation suggestions or rule modifications provided by security experts to the system based on security events and compliance requirements in actual operation. Through expert feedback, the deficiencies of the rule engine can be identified in a timely manner, and compliance standards and their implementation methods can be adjusted or added to ensure that the system always remains consistent with the latest compliance requirements and security threats. The implementation of the expert feedback mechanism usually relies on the regular review and manual correction of the rule engine. Security experts can supplement the rules according to the actual situation, or correct some rules with false positives and false negatives to improve the accuracy of the rule engine. The integration of expert feedback is usually based on rule adaptation algorithms, which can adjust the weights of compliance rules or update the standards in the rule base according to the feedback information given by experts. Model iteration and verification: To ensure the effectiveness of the online learning and expert feedback mechanisms, the system also needs to conduct iterative evaluations through model verification. After each model update, the system will use historical data and simulation environments to verify the new model and evaluate its performance in terms of repair efficiency, risk warning accuracy, and compliance checking. Common verification methods include Cross-Validation and A / B testing. By comparing the performance of different versions of the model on the same dataset, the effect of iteration can be evaluated, and the model can be further adjusted. The iterative optimization of the system is not limited to model updates. It also needs to automatically enter a feedback loop after each optimization. After each compliance gap analysis, risk assessment, and generation of repair plans, the implementation effect of the repair plan will be evaluated in real time through monitoring data and actual repair effects. If it is found that some repair measures fail to reduce security risks or compliance gaps as expected, the subsequent repair plan can be adjusted according to the feedback. For example, if a vulnerability is not effectively reduced after repair, the system will adjust the next repair strategy according to the actual effect of the repair measure and give more effective remedial suggestions. Through system iterative optimization, the system can continuously adapt to new security threats, compliance requirements, and changes in the enterprise environment during actual operation. The combination of the online learning mechanism and expert feedback can not only optimize the decision-making process of the system in real time but also improve the repair efficiency of the system and the accuracy of compliance checking through repeated training. The iterative optimization of the system ensures that network security management is always in an efficient and compliant state and can continuously maintain a high level of protection in a changing environment.

[0164] In summary, the above-mentioned method for evaluating the security state of the network environment is based on automated data mining and a multi-dimensional security situation model, which not only improves the automation degree of the security state evaluation of the network environment, but also makes the security situation perception more comprehensive and the decision-making support more intelligent, greatly improving the efficiency and accuracy of network security compliance management. Through automated data mining and deep learning technologies, effective information is extracted from various heterogeneous data, combined with a dynamic security situation model and a compliance check mechanism, to form a complete network security compliance management system.

[0165] First of all, the data collection and standardization link is the basis for the system to operate efficiently. In the present invention, by constructing a real-time data pipeline based on Flume and Kafka, it is possible to collect raw data in real time from multiple devices and applications (such as firewalls, IDSs, WAFs, etc.) in the enterprise network environment, including traffic data, log data, vulnerability information, etc. These data are usually heterogeneous, with inconsistent formats and diverse sources, and traditional security compliance products often have difficulty in effectively processing and analyzing them. In the present invention, different security devices and applications are docked through an automated adapter, and a regularization expression library and a custom tag system are used to standardize these data, converting the raw data into a data set in a unified format, providing a basis for subsequent feature extraction and analysis. Through this automated data collection and standardization process, the defects of strong manual dependence and low data processing efficiency in traditional products are solved. Next, the data mining and feature extraction link is crucial for the intelligent analysis ability of the system. The present invention combines deep learning technology with traditional data mining methods, designs a hybrid feature engineering, and can extract multi-dimensional security features from the standardized data. These features include statistical features (such as traffic frequency, protocol distribution), temporal features (such as sliding window anomaly degree), and semantic features (such as log keyword vectorization, etc.). These features not only cover network traffic and behavior patterns, but also can reveal potential security threats and their evolution trends. Different from the traditional detection method that relies on rule matching, the present invention uses a distributed computing framework based on PySpark, which can efficiently process large-scale data sets and achieve rapid extraction and calculation of features. This link greatly improves the accuracy and efficiency of threat detection through an automated and intelligent manner, avoiding threat undetected and false alarms caused by the lag in rule base updates in traditional products.

[0166] After feature extraction, the system comprehensively evaluates the security status of the current network environment through multi-dimensional security situation modeling. This process uses a dynamic evaluation matrix based on the analytic hierarchy process to comprehensively analyze multiple security risk dimensions (such as asset exposure surface, vulnerability threat level, attack complexity, etc.) and predict potential risks according to the time series model. Traditional security situation assessments usually rely on static models and are difficult to adapt to the rapidly changing network environment. However, the dynamic security situation modeling method adopted in the present invention can update the weights of each security dimension in real time and adjust the risk assessment results according to the real-time collected data. Especially in the face of constantly changing attack threats and network environments, the model of the present invention can learn the attack patterns through deep learning methods and generate real-time risk prediction results. Through this dynamic modeling, the system of the present invention can provide more accurate and timely security situation awareness, solving the limitations of traditional systems in dealing with complex attacks and dynamic threats.

[0167] At the same time, compliance inspection and intelligent correlation analysis are another innovation of the present invention. In traditional network security compliance management, compliance inspections are usually based on static rule libraries and lack intelligent correlation analysis functions. To address this issue, the present invention effectively models the relationships between network security events, asset information, vulnerability entries, and compliance requirements by constructing a compliance knowledge graph and realizes intelligent reasoning through a rule inference engine based on the Rete algorithm. This enables the system to automatically generate reports that comply with the latest regulations and compliance requirements based on real-time data and provide targeted repair suggestions. Through this intelligent correlation analysis, the present invention can overcome the problems of lagging compliance inspections and poor flexibility in traditional products. Especially in the face of emerging regulations or emergencies, the system can respond quickly and provide timely and effective decision-making support.

[0168] At the decision-making support level, the present invention introduces an intelligent decision-making engine based on machine learning, which can generate a prioritized repair plan according to the real-time security situation assessment results and provide a cost estimate of the repair plan. This decision-making engine can not only provide targeted security improvement suggestions for enterprises based on the network security situation but also automatically adjust the compliance baseline during the compliance inspection process to ensure that the system always meets the latest regulatory requirements. Compared with traditional report generation and decision-making support methods, the decision-making support system of the present invention is more flexible and intelligent, can provide personalized decision-making support according to the real-time security situation and compliance requirements, and avoids the drawbacks of regular report generation and manual intervention in traditional products.

[0169] Finally, the adaptive and continuous optimization capabilities of the system are also important features of the present invention. By introducing reinforcement learning technology, the system can continuously optimize compliance baselines and security policies based on expert feedback and analysis results of historical security incidents. Especially when facing new security threats or regulatory changes, the system of the present invention can automatically adjust corresponding policies, thus avoiding the drawback of slow response to new threats in traditional systems. Through continuous learning and optimization, the security protection capabilities and compliance management levels of the system can be gradually improved, ensuring that the network security environment is always in the best state.

[0170] In summary, through technologies such as automated data mining, deep learning, dynamic security situation modeling, and intelligent compliance correlation analysis, the present invention overcomes multiple defects of existing products in aspects such as data collection, threat detection, compliance inspection, and decision support. The system can not only efficiently process multi-source heterogeneous data and conduct comprehensive security situation assessments, but also dynamically adjust compliance standards and security protection policies according to real-time data. These innovative technical means give the present invention significant advantages in improving the efficiency, accuracy, and intelligence level of security compliance management, solve the deficiencies of traditional products when facing complex and dynamic network security environments and compliance requirements, and provide a more advanced and efficient network security compliance management solution.

[0171] In another embodiment, as Figure 3 shown, a method for evaluating the security state of a network environment is provided. Taking the case where this method is applied to the Figure 1 terminal 102 as an example, it includes the following steps:

[0172] Step S302, obtain security monitoring data generated by multiple data sources in the network environment.

[0173] The security monitoring data includes log data, traffic data, and vulnerability data.

[0174] Step S304, extract security features from the security monitoring data.

[0175] In one of the embodiments, the extracting security features from the security monitoring data includes:

[0176] Perform statistical analysis on the log data, traffic data, and vulnerability data included in the security monitoring data to obtain the statistical features; extract the security event features within each time window from the time series of network security events obtained based on the security monitoring data analysis to obtain the time series features; convert the log data into vectorized semantic features; input the statistical features, time series features, and semantic features into an anomaly detection model, and identify, through the anomaly detection model, the abnormal features in the statistical features, time series features, and semantic features whose deviation from the normal behavior features is greater than the threshold as the security features.

[0177] Among them, the security features include statistical features, time series features, and semantic features.

[0178] Step S306: Input the security features into a security situation model, and determine, through the security situation model, the asset exposure level, vulnerability threat degree, attack complexity, compliance deviation degree, and network protection effectiveness based on the security features as the security assessment index values in multiple dimensions.

[0179] Among them, the asset exposure level is used to represent the risk degree of asset exposure in the network environment; the vulnerability threat degree is used to represent the severity of the vulnerabilities existing in the network environment; the attack complexity is used to represent the complexity of attacking the network environment; the compliance deviation degree is used to measure the gap between the current security measures in the network environment and industry standards; the network protection effectiveness is used to measure the effectiveness of the current network protection measures in the network environment.

[0180] Step S308: Determine the current security situation assessment result of the network environment based on each security assessment index value.

[0181] Step S310: Predict the security situation assessment result of the network environment in a future time period through the long short-term memory network in the security situation model based on the current security situation assessment result and the historical security situation assessment result.

[0182] In one embodiment, after predicting the security situation assessment result of the network environment in a future time period, the method further includes: obtaining the weights corresponding to each security assessment index value when determining the current security situation assessment result and the network parameters of the long short-term memory network; constructing a value function according to the current security situation assessment result and the benefit value after adjusting the weights and the network parameters; the value function is used to represent the value of adjusting the weights and the network parameters for the current security situation assessment result; taking maximizing the value function as the optimization goal, optimizing the weights and the network parameters to construct the optimized security situation model.

[0183] Step S312: When the security posture assessment result meets the data category applicable to any network security compliance rule, it is determined that the security posture assessment result matches any network security compliance rule.

[0184] The network security compliance rule is a knowledge graph constructed based on compliance standards, compliance clauses, and security requirements.

[0185] Step S314: Generate a compliance gap report based on the difference between the security posture assessment result and any network security compliance rule, and determine the network security compliance analysis result of the network environment according to the compliance gap report.

[0186] It should be noted that the specific limitations of the above steps can refer to the specific limitations of a security status assessment method for a network environment described above.

[0187] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indication of the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0188] Based on the same inventive concept, an embodiment of the present application further provides a security status assessment device for a network environment for implementing the security status assessment method for the network environment involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the security status assessment device for a network environment provided below can refer to the limitations of the security status assessment method for a network environment in the above text, and will not be repeated here.

[0189] In an exemplary embodiment, as Figure 4 shown, a security status assessment device for a network environment is provided, including:

[0190] An acquisition module 410, configured to acquire security monitoring data generated by multiple data sources in the network environment; the security monitoring data includes log data, traffic data, and vulnerability data.

[0191] An extraction module 420 is configured to extract security features from the security monitoring data; the security features include statistical features, temporal features, and semantic features.

[0192] A determination module 430 is configured to input the security features into a security situation model, determine security assessment index values in multiple dimensions according to the security features through the security situation model, and determine a security situation assessment result of the network environment according to each of the security assessment index values.

[0193] A generation module 440 is configured to match the security situation assessment result with network security compliance rules to generate a network security compliance analysis result of the network environment.

[0194] In one embodiment, the determination module 430 is specifically configured to determine an asset exposure level, a vulnerability threat degree, an attack complexity, a compliance deviation degree, and network protection effectiveness according to the security features through the security situation model as the security assessment index values in the multiple dimensions; wherein, the asset exposure level is used to characterize the risk degree of asset exposure in the network environment; the vulnerability threat degree is used to characterize the severity of vulnerabilities existing in the network environment; the attack complexity is used to characterize the complexity of attacking the network environment; the compliance deviation degree is used to measure the gap between the current security measures in the network environment and industry standards; and the network protection effectiveness is used to measure the effectiveness of the current network protection measures in the network environment.

[0195] In one embodiment, the determination module 430 is specifically configured to determine the current security situation assessment result of the network environment according to each of the security assessment index values; and predict the security situation assessment result of the network environment in a future time period according to the current security situation assessment result and the historical security situation assessment result through a long short-term memory network in the security situation model.

[0196] In one embodiment, the determination module 430 is specifically configured to obtain weights corresponding to the security assessment index values when determining the current security situation assessment result and network parameters of the long short-term memory network; construct a value function according to the current security situation assessment result and a benefit value obtained by adjusting the weights and the network parameters; the value function is used to characterize the value of adjusting the weights and the network parameters for the current security situation assessment result; and optimize the weights and the network parameters with the maximization of the value function as an optimization objective to construct the optimized security situation model.

[0197] In one embodiment, the extraction module 420 is specifically configured to perform statistical analysis on the log data, the traffic data, and the vulnerability data included in the security monitoring data to obtain the statistical features; extract the security event features within each time window from the time series of network security events obtained by analyzing the security monitoring data to obtain the time series features; convert the log data into vectorized semantic features; and input the statistical features, the time series features, and the semantic features into an anomaly detection model, and identify, through the anomaly detection model, the anomaly features whose degree of deviation from the normal behavior features in the statistical features, the time series features, and the semantic features is greater than a threshold as the security features.

[0198] In one embodiment, the generation module 440 is specifically configured to determine that the security situation assessment result matches any one of the network security compliance rules when the security situation assessment result meets the data category applicable to any one of the network security compliance rules; the network security compliance rule is a knowledge graph constructed according to compliance standards, compliance terms, and security requirements; generate a compliance gap report based on the difference between the security situation assessment result and any one of the network security compliance rules, and determine the network security compliance analysis result of the network environment according to the compliance gap report.

[0199] Each module in the above security status assessment device of the network environment can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or independent of the processor, or stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0200] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as Figure 5As shown in the figure. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a method for evaluating the security state of a network environment. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0201] Those skilled in the art can understand that Figure 5 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component arrangement.

[0202] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0203] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0204] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0205] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0206] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0207] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0208] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. A method for evaluating the security state of a network environment, characterized in that The method includes: Obtaining security monitoring data generated by multiple data sources in a network environment; the security monitoring data includes log data, traffic data, and vulnerability data; Extracting security features from the security monitoring data; the security features include statistical features, temporal features, and semantic features; Inputting the security features into a security situation model, and determining security evaluation index values in multiple dimensions according to the security features through the security situation model, and determining a security situation evaluation result of the network environment according to each of the security evaluation index values; Matching the security situation evaluation result with network security compliance rules to generate a network security compliance analysis result of the network environment.

2. The method according to claim 1, wherein The determining, by the security situation model, security evaluation index values in multiple dimensions according to the security features includes: Determining an asset exposure level, a vulnerability threat degree, an attack complexity, a compliance deviation degree, and a network protection effectiveness as the security evaluation index values in the multiple dimensions through the security situation model according to the security features; Wherein, the asset exposure level is used to characterize the risk degree of asset exposure in the network environment; the vulnerability threat degree is used to characterize the severity of vulnerabilities existing in the network environment; the attack complexity is used to characterize the complexity of attacking the network environment; the compliance deviation degree is used to measure the gap between the current security measures in the network environment and industry standards; the network protection effectiveness is used to measure the effectiveness of the current network protection measures in the network environment.

3. The method according to claim 1, wherein The determining the security situation evaluation result of the network environment according to each of the security evaluation index values includes: Determining the current security situation evaluation result of the network environment according to each of the security evaluation index values; Predicting a security situation evaluation result of the network environment in a future time period through a long short-term memory network in the security situation model according to the current security situation evaluation result and a historical security situation evaluation result.

4. The method according to claim 3, characterized in that, After predicting the security situation evaluation result of the network environment in the future time period, the method further includes: Obtaining the weights corresponding to each of the security evaluation index values when determining the current security situation evaluation result and the network parameters of the long short-term memory network; Constructing a value function according to the current security situation evaluation result and the benefit value after adjusting the weights and the network parameters; the value function is used to characterize the value of adjusting the weights and the network parameters for the current security situation evaluation result; Optimizing the weights and the network parameters with the optimization goal of maximizing the value function to construct an optimized security situation model.

5. The method according to claim 1, wherein The extracting security features from the security monitoring data includes: Performing statistical analysis on the log data, the traffic data, and the vulnerability data included in the security monitoring data to obtain the statistical features; Extracting security event features within each time window from the time series of network security events analyzed based on the security monitoring data to obtain the temporal features; Converting the log data into vectorized semantic features; Input the statistical features, the temporal features, and the semantic features into an anomaly detection model, and identify, through the anomaly detection model, the anomaly features in the statistical features, the temporal features, and the semantic features whose degree of deviation from the normal behavior features is greater than a threshold as the security features.

6. The method according to claim 1, characterized in that The matching of the security situation assessment result with the network security compliance rules to generate the network security compliance analysis result of the network environment includes: When the security situation assessment result meets the data category applicable to any of the network security compliance rules, determine that the security situation assessment result matches any of the network security compliance rules; the network security compliance rules are knowledge graphs constructed based on compliance standards, compliance clauses, and security requirements; Generate a compliance gap report according to the difference between the security situation assessment result and any of the network security compliance rules, and determine the network security compliance analysis result of the network environment according to the compliance gap report.

7. A security status evaluation device for a network environment, characterized in that, The device includes: An acquisition module, configured to acquire security monitoring data generated by multiple data sources in a network environment; the security monitoring data includes log data, traffic data, and vulnerability data; An extraction module, configured to extract security features from the security monitoring data; the security features include statistical features, temporal features, and semantic features; A determination module, configured to input the security features into a security situation model, determine security assessment index values in multiple dimensions through the security situation model according to the security features, and determine the security situation assessment result of the network environment according to each of the security assessment index values; A generation module, configured to match the security situation assessment result with network security compliance rules to generate the network security compliance analysis result of the network environment.

8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • FTTR network security assessment method, system, device and medium

    CN120915594A

  • Database security situation assessment and prediction method based on multi-dimensional indexes

    CN121309231A

  • A database security situation assessment and prediction method based on multi-dimensional indexes

    CN121309231B

  • Gateway port on-off control method, equipment and medium

    CN121664549A

  • Network security protection efficiency evaluation method and system for physical isolation network

    CN121664696A