Asset risk assessment method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202280102551.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-07-22
AI Technical Summary
Existing technology makes it difficult to assess asset risk using objective, quantitative methods, resulting in poor assessment results and a lack of available methods to incorporate factors such as vulnerabilities, exposed surfaces, and attack potential into risk scores.
By determining two indicators: the vulnerability of assets and the severity of security incidents that have occurred, combined with the Common Vulnerability Scoring System (CVSS) score and security configuration compliance check, using the S-shaped growth curve function and the threshold value segmentation method, the calculation Risk indicators of assets, and then conduct qualitative analysis.
It improves the accuracy and objectivity of asset risk assessment, provides a more reliable risk scoring method, and promotes the effectiveness of zero-trust solutions and security situational awareness platforms.
Smart Images

Figure CN120359530A_ABST
Abstract
Description
Method, device, electronic device and storage medium for assessing asset risk Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a method, device, electronic device and storage medium for assessing asset risk. Background Art
[0002] Assessing asset risk is crucial for zero-trust solutions and security situational awareness platforms. Qualitative methods are often used, which are subjective and lead to poor assessment results.
[0003] Many factors can influence asset risk, such as vulnerabilities, exposed surfaces, and attack potential. Currently, there are no practical methods for incorporating these factors into risk scores. Consequently, it is difficult to assess asset risk using objective, quantitative methods.
[0004] Summary of the Invention
[0005] The embodiments of the present invention provide a method, device, electronic device and storage medium for assessing asset risk.
[0006] A method for assessing asset risk, comprising:
[0007] Determine the first indicator of the asset's vulnerability;
[0008] determining a second indicator representing a severity of a security event that has occurred with respect to the asset;
[0009] Based on the first indicator and the second indicator, a third indicator characterizing the risk of the asset is determined.
[0010] Therefore, in the embodiments of the present invention, asset risks are quantitatively assessed based on vulnerabilities and security events, thereby improving assessment accuracy.
[0011] In an exemplary embodiment, determining a first indicator representing the vulnerability of an asset includes:
[0012] Determining a Common Vulnerability Scoring System (CVSS) score for the asset;
[0013] Performing a compliance check on the security configuration of the asset to determine a compliance ratio of the asset;
[0014] The first indicator is determined based on the compliance ratio and the CVSS score.
[0015] Therefore, the first indicator is determined by comprehensively combining the CVSS score and the compliance ratio, thereby improving the accuracy of the first indicator.
[0016] In an exemplary embodiment, determining the first indicator based on the compliance ratio and the CVSS score includes:
[0017] Determining a CVSS risk indicator for the asset based on the CVSS score;
[0018] When the compliance ratio is greater than or equal to a first threshold, determining a minimum value between the CVSS risk index and a first preset value as the first index;
[0019] When the compliance ratio is greater than or equal to a second threshold value and less than the first threshold value, determining a minimum value between the CVSS risk indicator and a second preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the second preset value and the first preset value as the first indicator;
[0020] When the compliance ratio is greater than or equal to a third threshold value and less than the second threshold value, determining a minimum value between the CVSS risk indicator and a third preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value as the first indicator;
[0021] When the compliance ratio is less than a third threshold, determining a minimum value between the CVSS risk indicator and a fourth preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value as the first indicator;
[0022] The first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value.
[0023] Therefore, by constraining the first indicator in sections by compliance ratio, the accuracy of the first indicator is improved.
[0024] In an exemplary embodiment, determining the CVSS risk index of an asset based on the CVSS score includes: determining the CVSS risk index CVSS_Risk_score_1 of the asset; wherein CVSS_Risk_score_1=2*Initial_Vulnerability_Score*(Sigmoid(h1*∑(CVSS_Score))-0.5); wherein CVSS_Score is the CVSS score of each vulnerability; ∑ is a summation symbol; Sigmoid is an S-shaped growth curve function; Initial_Vulnerability_Score is an adjustable first preset parameter; and h1 is an adjustable second preset parameter.
[0025] It can be seen that the CVSS risk index not only combines the CVSS scores of all vulnerabilities, but also reflects the adjustment effect of h1 and Initial_Vulnerability_Score, and has better indicator value.
[0026] In an exemplary embodiment, determining a second indicator representing the severity of the security event that has occurred on the asset includes:
[0027] Determine the security incidents that have occurred for the asset, and the incident level, frequency, and duration of the security incidents that have occurred;
[0028] Determining a completeness score for the security incident based on the incident level, frequency, and duration;
[0029] Determining a confidentiality score for the security incident based on the incident level, frequency, and duration;
[0030] Determining an availability score for the security incident based on the incident level, occurrence frequency, and duration;
[0031] The second indicator is determined based on the integrity score, the confidentiality score, and the availability score.
[0032] Therefore, considering the event level, frequency and duration, the integrity score, confidentiality score and availability score are calculated respectively, which improves the accuracy of the second indicator.
[0033] In an exemplary embodiment, the method further includes:
[0034] Creating a first virtual scenario of the asset, wherein in the first virtual scenario, the asset includes a first vulnerability with a first CVSS score and a first security event with an emergency level;
[0035] creating a second virtual scenario of the asset, wherein in the second virtual scenario, the asset includes a second vulnerability with a second CVSS score and a second security event with an event level of alert, wherein the first CVSS score is greater than the second CVSS score;
[0036] determining a fourth indicator representing a risk of the asset in the first virtual scenario;
[0037] determining a fifth indicator representing a risk of the asset in a second virtual scenario;
[0038] Based on the fourth indicator and the fifth indicator, a qualitative analysis is performed on the third indicator.
[0039] Therefore, by creating a virtual scenario, conditions are provided for qualitative analysis, which promotes the convenience of implementation.
[0040] In an exemplary embodiment, the performing a qualitative analysis on the third indicator based on the fourth indicator and the fifth indicator includes:
[0041] When the third indicator is greater than or equal to the fourth indicator, the risk is determined to be at a high level;
[0042] When the third indicator is less than or equal to the fifth indicator, the risk is determined to be at a low level;
[0043] When the third indicator is greater than the fifth indicator and less than the fourth indicator, the risk is determined to be at an intermediate level.
[0044] It can be seen that qualitative analysis can be conveniently performed.
[0045] A device for assessing asset risk, comprising:
[0046] A first determining module is configured to determine a first indicator representing a vulnerability level of an asset;
[0047] a second determining module configured to determine a second indicator representing the severity of the security event that has occurred on the asset;
[0048] The third determination module is configured to determine a third indicator representing the risk of the asset based on the first indicator and the second indicator.
[0049] Therefore, in the embodiments of the present invention, asset risks are quantitatively assessed based on vulnerabilities and security events, thereby improving assessment accuracy.
[0050] In an exemplary embodiment, the first determination module is configured to determine a CVSS score of the asset; perform a compliance check on the asset regarding a security configuration to determine a compliance ratio of the asset; and determine the first indicator based on the compliance ratio and the CVSS score.
[0051] Therefore, the first indicator is determined by comprehensively combining the CVSS score and the compliance ratio, thereby improving the accuracy of the first indicator.
[0052] In an exemplary embodiment, the first determination module is configured to determine the CVSS risk index of the asset based on the CVSS score; when the compliance ratio is greater than or equal to a first threshold value, determine the minimum value between the CVSS risk index and a first preset value as the first index; when the compliance ratio is greater than or equal to a second threshold value and less than the first threshold value, determine the minimum value between the CVSS risk index and the second preset value, and determine the maximum value between the minimum value between the CVSS risk index and the second preset value and the first preset value as the first index; when the compliance ratio is greater than or equal to a third threshold value and less than the second threshold value, determine the minimum value between the CVSS risk index and the second preset value and the maximum value between the first preset value and the minimum value between the CVSS risk index and the second preset value as the first index; value, determine the minimum value between the CVSS risk indicator and the third preset value, and determine the maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value as the first indicator; when the compliance ratio is less than the third threshold value, determine the minimum value between the CVSS risk indicator and the fourth preset value, and determine the maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value as the first indicator; wherein the first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value.
[0053] Therefore, by constraining the first indicator in sections by compliance ratio, the accuracy of the first indicator is improved.
[0054] In an exemplary embodiment, the second determination module is configured to determine the security events that have occurred for the asset, the event level, frequency of occurrence and duration of the security events that have occurred; determine the integrity score of the security events that have occurred based on the event level, frequency of occurrence and duration; determine the confidentiality score of the security events that have occurred based on the event level, frequency of occurrence and duration; determine the availability score of the security events that have occurred based on the event level, frequency of occurrence and duration; and determine the second indicator based on the integrity score, confidentiality score and availability score.
[0055] Therefore, considering the event level, frequency and duration, the integrity score, confidentiality score and availability score are calculated respectively, which improves the accuracy of the second indicator.
[0056] In an exemplary embodiment, the method further includes:
[0057] A qualitative analysis module is configured to create a first virtual scenario of the asset, wherein in the first virtual scenario, the asset includes a first vulnerability with a first CVSS score and a first security event with an emergency event level; create a second virtual scenario of the asset, wherein in the second virtual scenario, the asset includes a second vulnerability with a second CVSS score and a second security event with an alarm event level, wherein the first CVSS score is greater than the second CVSS score; determine a fourth indicator characterizing the risk of the asset when it is in the first virtual scenario; determine a fifth indicator characterizing the risk of the asset when it is in the second virtual scenario; and perform a qualitative analysis on the third indicator based on the fourth indicator and the fifth indicator.
[0058] Therefore, by creating a virtual scenario, conditions are provided for qualitative analysis, which promotes the convenience of implementation.
[0059] In an exemplary embodiment, the qualitative analysis module is configured to determine that the risk is at a high level when the third indicator is greater than or equal to the fourth indicator; to determine that the risk is at a low level when the third indicator is less than or equal to the fifth indicator; and to determine that the risk is at an intermediate level when the third indicator is greater than the fifth indicator and less than the fourth indicator.
[0060] It can be seen that qualitative analysis can be conveniently performed.
[0061] An electronic device, comprising:
[0062] processor;
[0063] a memory for storing executable instructions of the processor;
[0064] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the method for assessing asset risk as described in any one of the above items.
[0065] A computer-readable storage medium stores computer instructions thereon, wherein when the computer instructions are executed by a processor, the method for assessing asset risk as described in any one of the above items is implemented.
[0066] A computer program product comprises a computer program, wherein when the computer program is executed by a processor, the method for assessing asset risk as described in any one of the above items is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, so that those skilled in the art will understand the above and other features and advantages of the present invention more clearly. In the accompanying drawings:
[0068] FIG1 is an exemplary schematic diagram of a method for assessing asset risk according to an embodiment of the present invention.
[0069] FIG2 is an exemplary schematic diagram of factors influencing asset risk according to an embodiment of the present invention.
[0070] FIG3 is a schematic diagram of a CVSS risk indicator function according to an embodiment of the present invention.
[0071] FIG4 is an exemplary schematic diagram of determining a first indicator according to an embodiment of the present invention.
[0072] FIG5 is an exemplary structural diagram of an apparatus for assessing asset risk according to an embodiment of the present invention.
[0073] FIG6 is a structural diagram of an electronic device according to an embodiment of the present invention.
[0074] The accompanying drawings are numerals as follows:
[0075] Meaning of reference numerals 101-103 Step 10 Asset risk 11 Vulnerability 21 Security incident 31 Compliance ratio 32 CVSS score 33 Incident level 34 Occurrence frequency 35 Duration 36 Integrity score 37 Confidentiality score 38 Availability score 41 First curve of the first indicator 42 Second curve of the first indicator 43 Third curve of the first indicator 44 Fourth curve of the first indicator 500 Apparatus for assessing asset risk 501 First determination module 502 Second determination module 503 Third determination module 504 Qualitative analysis module 600 Electronic device 601 Processor
[0076] 602 Memory DETAILED DESCRIPTION
[0077] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is further described in detail with reference to the following examples.
[0078] For the sake of brevity and intuitiveness in description, the solution of the present invention is explained below by describing several representative implementations. A large number of details in the implementations are only used to help understand the solution of the present invention. However, it is obvious that the technical solution of the present invention may not be limited to these details when implemented. In order to avoid unnecessarily obscuring the solution of the present invention, some implementations are not described in detail, but only a framework is given. Hereinafter, "including" means "including but not limited to", and "according to..." means "at least according to..., but not limited to only according to...". Due to the language habits of Chinese, when the number of a component is not specifically specified below, it means that the component can be one or more, or can be understood as at least one.
[0079] In embodiments of the present invention, an asset risk score is calculated based on a number of objective factors (e.g., those derived from vulnerabilities and security incidents). For example, objective factors may include asset compliance ratios, CVSS scores, integrity scores, confidentiality scores, and availability scores, thus encompassing a wide range of asset risk profiles. Therefore, embodiments of the present invention can accurately quantify asset risk scores based on a variety of objective factors.
[0080] First, embodiments of the present invention use two main objective factors to calculate asset risk scores:
[0081] (1) Vulnerability: This characterizes the vulnerability of an asset. Vulnerability is a characteristic of the asset itself. The more vulnerabilities it has, the greater its vulnerability and the greater the possibility of attack.
[0082] (2) Security incidents: Threats or attacks that occur on assets. If an asset has more vulnerabilities, it does not usually mean that more attacks are occurring against that asset. This is because if the asset is not widely exposed or well protected, there will not be many security incidents. Security incidents can usually be obtained from standard IDS or security situation awareness platforms, so they are more objective.
[0083] FIG1 is an exemplary schematic diagram of a method for assessing asset risk according to an embodiment of the present invention. As shown in FIG1 , the method includes:
[0084] Step 101: Determine a first indicator representing the vulnerability of an asset.
[0085] Assets here can include machines, machinery, transportation vehicles, and other equipment, appliances, and tools related to production and operations. For example, assets can be IT equipment in the information technology (IT) field (such as laptops, desktop computers, routers, switches, etc.). Assets can also be OT equipment in the operation technology (OT) field (such as field SCADA, generators, pipes, fans, programmable logic controllers (PLCs), remote processing units (RPUs), industrial robots, and industrial computers, etc.), or converged devices in the IoT field.
[0086] Here, determining the first indicator representing the vulnerability level of the asset specifically includes: determining the CVSS score of the asset; performing a compliance check on the asset regarding the security configuration to determine the compliance ratio of the asset; and determining the first indicator based on the compliance ratio and the CVSS score.
[0087] CVSS provides a method for capturing the key characteristics of an asset's vulnerability and generating a numerical score reflecting its severity. CVSS attempts to assign a severity score to vulnerabilities, allowing responders to prioritize responses and resources based on the threat. CVSS scores typically range from 0 to 10, with 10 being the most severe. CVSS is typically maintained by FIRST, and CVSS scores can be generated by vulnerability scanners.
[0088] Additionally, security-related configurations can be subject to compliance checks based on certain entity (e.g., company) or industry standards to determine the asset's compliance ratio. In this embodiment of the present invention, the compliance ratio is the result of a compliance check. The compliance ratio can be derived from a respective compliance check tool. For example, assuming there are 100 compliance checks and an asset complies with 98 of them, the asset's compliance ratio is 98%.
[0089] For example, compliance checks may include:
[0090] (1) Check whether the password strength is compliant.
[0091] (2) Check whether the patch is complete.
[0092] (3) Check whether the operating system version meets the specification requirements.
[0093] The above exemplary descriptions of typical examples of CVSS scores and compliance checks are provided. Those skilled in the art will appreciate that such descriptions are merely exemplary and are not intended to limit the scope of protection of the embodiments of the present invention.
[0094] In one embodiment, determining the first indicator based on the compliance ratio and the CVSS score includes:
[0095] (1) Based on the CVSS score, determine the CVSS risk index of the asset.
[0096] The CVSS risk index of an asset can be implemented as a metric related to the sum of the CVSS scores of the vulnerabilities.
[0097] In one embodiment, determining the CVSS risk indicator of the asset based on the CVSS score includes determining a CVSS risk indicator CVSS_Risk_score_1 of the asset.
[0098] CVSS_Risk_score_1=2*Initial_Vulnerability_Score*(Sigmoid(h1*∑(CVSS_Score))-0.5).
[0099] Where CVSS_Score is the CVSS score for each vulnerability; ∑ is the summation symbol; Sigmoid is the S-shaped growth curve function; Initial_Vulnerability_Score is the raw vulnerability score, implemented as a first adjustable preset parameter; and h1 is a second adjustable preset parameter. For example, assuming an asset has five vulnerabilities, first calculate the CVSS scores for each of these five vulnerabilities (i.e., there are five CVSS_Scores). Then, sum these five CVSS scores to obtain ∑(CVSS_Score). Based on this formula, we can calculate CVSS_Risk_score_1.
[0100] Figure 3 is a schematic diagram of a CVSS risk indicator function according to an embodiment of the present invention. The CVSS scores for various vulnerabilities corresponding to an asset are accumulated, and the accumulated result is multiplied by the hyperparameter h1 as the input to the sigmoid function. Because the accumulated CVSS scores can be very large, the sigmoid function is applied here to compress the large scores into relatively small scores that can be compared with other scores. More importantly, the CVSS scores of all assets can be distributed along a gradient from 0 to 40. As shown in Figure 3, the entire equation forms an increasing curve on the XY coordinate system. The hyperparameter h1 is applied to the equation, which shifts the curve upward along the y-axis from 0 to 40. An appropriate h1 value can ensure smooth movement of the curve and avoid imbalances.
[0101] (2) When the compliance ratio is greater than or equal to the first threshold value, the minimum value between the CVSS risk indicator and the first preset value is determined as the first indicator; when the compliance ratio is greater than or equal to the second threshold value and less than the first threshold value, the minimum value between the CVSS risk indicator and the second preset value is determined, and the maximum value between the minimum value between the CVSS risk indicator and the second preset value and the first preset value is determined as the first indicator; when the compliance ratio is greater than or equal to the third threshold value and less than the second threshold value, the minimum value between the CVSS risk indicator and the third preset value is determined, and the maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value is determined as the first indicator; when the compliance ratio is less than the third threshold value, the minimum value between the CVSS risk indicator and the fourth preset value is determined, and the maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value is determined as the first indicator; wherein the first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value. Therefore, by constraining the first indicator in sections by compliance ratio, the accuracy of the first indicator is improved.
[0102] For example, the first preset value may be 20, the second preset value may be 24, the third preset value may be 32, the fourth preset value may be 40, the first threshold value may be 90%, the second threshold value may be 75%, and the third threshold value may be 50%.
[0103] Figure 4 is an exemplary schematic diagram of determining a first indicator according to an embodiment of the present invention. In Figure 4 , the horizontal coordinate X represents CVSS_Risk_score_1, and the vertical coordinate Y represents the first indicator. A first curve 41 of the first indicator is: Y = min(20, X). A second curve 42 of the first indicator is: Y = max(20, min(24, X)). A third curve 43 of the first indicator is: Y = max(24, min(32, X)). A fourth curve 44 of the first indicator is: Y = max(32, min(40, X)). X represents CVSS_Risk_score_1. Here, max() represents the maximum value function, and min() represents the minimum value function.
[0104] Step 102: Determine a second indicator representing the severity of a security event that has occurred on an asset.
[0105] For example, a security event may be any event that attempts to change the security status of an asset's information system (eg, changing access control measures, changing security levels, changing user passwords, etc.).
[0106] CIA (integrity, confidentiality, and availability) are crucial in information security. C: Confidentiality, or confidentiality, ensures that information is not disclosed to unauthorized users or entities during storage, use, and transmission. I: Integrity, ensures that information is not tampered with without authorization during storage, use, and transmission, preventing authorized users or entities from inappropriately modifying information and maintaining internal and external consistency. A: Availability, ensures that authorized users or entities are not abnormally denied access to information and resources, allowing them reliable and timely access to information and resources.
[0107] For security incident factors, three aspects need to be considered: incident severity, frequency, and duration. This embodiment of the present invention calculates the CIA attributes of security incidents: integrity score, confidentiality score, and availability score. These scores can be determined by referring to local and global risk assessment standards, such as ISO 27005 and GBT-20984.
[0108] In one embodiment, a security event that has occurred for an asset, the event level, frequency, and duration of the security event are determined; an integrity score for the security event is determined based on the event level, frequency, and duration; a confidentiality score for the security event is determined based on the event level, frequency, and duration; an availability score for the security event is determined based on the event level, frequency, and duration; and a second indicator is determined based on the integrity score, confidentiality score, and availability score. Incident levels, in descending order of severity, may include: normal event, warning, and emergency, among others.
[0109] for example:
[0110] The calculation formulas for the integrity score Integrity_Risk_Score, confidentiality score Confidentiality_Risk_Score, and availability score Availability_Risk_Score are as follows:
[0111] Integrity_Risk_Score=Initial_Integrity_Score-2*Initial_Integrity_Score*(Sigmoid(h2*∑(weight-bias-per-event))-0.5);
[0112] Confidentiality_Risk_Score=Initial_Confidentiality_Score-2*Initial_Confidentiality_Score*(Sigmoid(h2*∑(weight-bias-per-event))-0.5);
[0113] Availability_Risk_Score=Initial_Availability_Score-2*Initial_Availability_Score*(Sigmoid(h2*∑(weight-bias-per-event))-0.5);
[0114] weight-bias-per-event=Event type value*Frequency Weight*Duration Weight+History Bias.
[0115] The Security_Event_Risk_Score, the second metric, is obtained by summing the Integrity_Risk_Score, Confidentiality_Risk_Score, and Availability_Risk_Score. By default, the Initial_Integrity_Score can be 15, the Initial_Confidentiality_Score can be 15, and the Initial_Availability_Score can be 30 (for example, assuming availability is more important). Preferably, the Initial_Integrity_Score, Initial_Confidentiality_Score, and Initial_Availability_Score are all adjustable.
[0116] Event type value is a parameter that describes the event level: (1) When the event level is a notification event (event), it is assigned a value of 2; when the event level is an alarm (warning), it is assigned a value of 5; when the event level is an emergency (alert), it is assigned a value of 10. The more critical the event, the higher the score of Event type value. Frequency Weight is a parameter that describes the frequency of event occurrence: the higher the frequency of event occurrence, the higher the Frequency Weight score. Duration Weight is a parameter that describes the duration of the event: the longer the duration, the higher the Duration Weight score. History Bias indicates whether the event has ever occurred. When this type of event has not occurred, it is assigned a value of 0; when the event is downgraded after review (due to factors such as false alarms), the amplitude is 2; when the event is upgraded after review, the value is 4. h2 is an adjustable preset parameter.
[0117] For example, assume that security event A, security event B, and security event C occur on an asset within a predetermined timeframe. First, the weight-bias-per-event for security event A is calculated based on the level, frequency, and duration of security event A. Similarly, the weight-bias-per-event for security event B and the weight-bias-per-event for security event C are calculated. Then, the weight-bias-per-event for security event A, security event B, and security event C are summed to obtain ∑(weight-bias-per-event). Based on ∑(weight-bias-per-event), the integrity score Integrity_Risk_Score, confidentiality score Confidentiality_Risk_Score, and availability score Availability_Risk_Score of the asset for all security events are calculated respectively. The integrity score Integrity_Risk_Score, confidentiality score Confidentiality_Risk_Score, and availability score Availability_Risk_Score are then summed to obtain the Integrity_Risk_Score, which is the second indicator of the asset.
[0118] The above describes a typical example of determining the second indicator by using specific numerical values. Those skilled in the art will appreciate that this description is merely exemplary and is not intended to limit the scope of protection of the embodiments of the present invention.
[0119] Step 103: Based on the first indicator and the second indicator, determine a third indicator that characterizes the risk of the asset.
[0120] Figure 2 is an exemplary diagram of factors influencing asset risk according to an embodiment of the present invention. In Figure 2, asset risk 10 can be derived from vulnerabilities 11 and security events 21. Vulnerabilities 11 include a compliance ratio 31 and a CVSS score 32. Security events 21 include an integrity score 36, a confidentiality score 37, and an availability score 38. Furthermore, integrity score 36, confidentiality score 37, and availability score 38 are constrained by event level 33, occurrence frequency 34, and duration 36, respectively.
[0121] In one embodiment, the method further includes: creating a first virtual scenario for the asset, wherein in the first virtual scenario, the asset contains a first vulnerability with a first CVSS score and a first security event with an emergency level; creating a second virtual scenario for the asset, wherein in the second virtual scenario, the asset contains a second vulnerability with a second CVSS score and a second security event with an alarm level, wherein the first CVSS score is greater than the second CVSS score; determining a fourth indicator representing the risk of the asset in the first virtual scenario; determining a fifth indicator representing the risk of the asset in the second virtual scenario; and performing a qualitative analysis of the third indicator based on the fourth and fifth indicators. Therefore, by creating the virtual scenario, conditions are provided for qualitative analysis, thereby facilitating implementation.
[0122] Through the process shown in Figure 1, a quantified third indicator can be obtained. In actual use, it is usually necessary to categorize risk scores into three categories: low, medium, and high. Assuming that the score range of the third indicator is from 0 to 100, the risk score is dynamic due to the modification of parameters such as h1 and h2. Regardless of how the parameters are modified, in order to correctly classify the score, two virtual scenarios of the asset can be inserted, representing the bottom line of the medium risk rating zone and the other bottom line of the high risk rating zone. For example, for the bottom line of the high risk rating zone, a vulnerability with a severity of "high" and a high CVSS score (such as 7.0) is virtualized, and a security event of the "urgent" type is inserted; for the bottom line of the medium risk rating zone, a vulnerability with a severity of "medium" and a low CVSS score (such as 4.0) is virtualized, and a security event of the "warning" type is inserted.
[0123] In one embodiment, a qualitative analysis of the third indicator based on the fourth and fifth indicators includes: determining the risk as high when the third indicator is greater than or equal to the fourth indicator; determining the risk as low when the third indicator is less than or equal to the fifth indicator; and determining the risk as intermediate when the third indicator is greater than the fifth indicator and less than the fourth indicator. This demonstrates that embodiments of the present invention can also qualitatively assess asset risk based on quantitative assessment results, facilitating implementation.
[0124] FIG5 is an exemplary structural diagram of an apparatus for assessing asset risk according to an embodiment of the present invention. As shown in FIG5 , the apparatus 500 for assessing asset risk includes:
[0125] A first determining module 501 is configured to determine a first indicator representing the vulnerability of an asset;
[0126] A second determination module 502 is configured to determine a second indicator representing the severity of a security event that has occurred on an asset;
[0127] The third determination module 503 is configured to determine a third indicator representing the risk of the asset based on the first indicator and the second indicator.
[0128] In one embodiment, the first determination module 501 is configured to determine a CVSS score of an asset; perform a compliance check on the asset regarding security configuration to determine a compliance ratio of the asset; and determine a first indicator based on the compliance ratio and the CVSS score.
[0129] In one embodiment, the first determination module 501 is configured to determine the CVSS risk index of the asset based on the CVSS score; when the compliance ratio is greater than or equal to the first threshold value, determine the minimum value between the CVSS risk index and the first preset value as the first index; when the compliance ratio is greater than or equal to the second threshold value and less than the first threshold value, determine the minimum value between the CVSS risk index and the second preset value, and determine the maximum value between the minimum value between the CVSS risk index and the second preset value and the first preset value as the first index; when the compliance ratio is greater than or equal to the third threshold value and less than the second threshold value, determine the CVSS risk index. The minimum value between the VSS risk indicator and the third preset value, and the maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value are determined as the first indicator; when the compliance ratio is less than the third threshold value, the minimum value between the CVSS risk indicator and the fourth preset value is determined, and the maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value are determined as the first indicator; wherein the first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value.
[0130] In one embodiment, the second determination module 502 is configured to determine the security events that have occurred for the asset, the event level, frequency and duration of the security events that have occurred; determine the integrity score of the security events that have occurred based on the event level, frequency and duration; determine the confidentiality score of the security events that have occurred based on the event level, frequency and duration; determine the availability score of the security events that have occurred based on the event level, frequency and duration; and determine the second indicator based on the integrity score, confidentiality score and availability score.
[0131] In one embodiment, a qualitative analysis module 504 is also included, which is configured to create a first virtual scenario of the asset, wherein in the first virtual scenario, the asset contains a first vulnerability with a first CVSS score and a first security event with an event level of emergency; create a second virtual scenario of the asset, wherein in the second virtual scenario, the asset contains a second vulnerability with a second CVSS score and a second security event with an event level of alarm, wherein the first CVSS score is greater than the second CVSS score; determine a fourth indicator that characterizes the risk of the asset when it is in the first virtual scenario; determine a fifth indicator that characterizes the risk of the asset when it is in the second virtual scenario; and perform a qualitative analysis on the third indicator based on the fourth indicator and the fifth indicator.
[0132] In one embodiment, the qualitative analysis module 504 is configured to determine that the risk is at a high level when the third indicator is greater than or equal to the fourth indicator; determine that the risk is at a low level when the third indicator is less than or equal to the fifth indicator; and determine that the risk is at an intermediate level when the third indicator is greater than the fifth indicator and less than the fourth indicator.
[0133] The embodiment of the present invention further provides an electronic device having a processor-memory architecture. FIG6 is a structural diagram of an electronic device according to an embodiment of the present invention.
[0134] As shown in FIG6 , electronic device 600 includes a processor 601, a memory 602, and a computer program stored in memory 602 and executable on processor 601. When executed by processor 601, the computer program implements any of the above methods for assessing asset risk. Specifically, memory 602 can be implemented as various storage media, such as electrically erasable programmable read-only memory (EEPROM), flash memory, or programmable read-only memory (PROM). Processor 601 can be implemented as one or more central processing units (CPUs) or one or more field programmable gate arrays (FPGAs), wherein the FPGAs integrate one or more CPU cores. Specifically, the CPU or CPU core can be implemented as a CPU, an MCU, a DSP, or the like.
[0135] It should be noted that not all steps and modules in the above processes and structure diagrams are required, and certain steps or modules can be omitted based on actual needs. The execution order of the steps is not fixed and can be adjusted as needed. The division of the modules is merely for the convenience of describing the functional division adopted. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can be implemented by the same module. These modules can be located in the same device or in different devices.
[0136] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include a specially designed permanent circuit or logic device (such as a dedicated processor, such as an FPGA or ASIC) for performing a specific operation. The hardware module may also include a programmable logic device or circuit (such as a general-purpose processor or other programmable processor) temporarily configured by software to perform a specific operation. As for whether to implement the hardware module mechanically, or using a dedicated permanent circuit, or using a temporarily configured circuit (such as configured by software), it can be decided based on cost and time considerations.
[0137] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the scope of protection of the present invention.
Claims
1. A method for assessing asset risk, characterized in that: include: Determining (101) a first indicator representing the vulnerability of the asset; determining (102) a second indicator characterizing the severity of a security event that has occurred for the asset; Based on the first indicator and the second indicator, a third indicator characterizing the risk of the asset is determined (103).
2. The method according to claim 1, characterized in that The determining (101) of a first indicator representing the vulnerability of an asset comprises: Determine the Common Vulnerability Scoring System (CVSS) score for the asset; Performing a compliance check on the security configuration of the asset to determine a compliance ratio of the asset; The first indicator is determined based on the compliance ratio and the CVSS score.
3. The method according to claim 1, characterized in that Determining the first indicator based on the compliance ratio and the CVSS score includes: Determining a CVSS risk indicator for the asset based on the CVSS score; When the compliance ratio is greater than or equal to a first threshold, determining a minimum value between the CVSS risk index and a first preset value as the first index; When the compliance ratio is greater than or equal to a second threshold value and less than the first threshold value, determining a minimum value between the CVSS risk indicator and a second preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the second preset value and the first preset value as the first indicator; When the compliance ratio is greater than or equal to a third threshold value and less than the second threshold value, determining a minimum value between the CVSS risk indicator and a third preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value as the first indicator; When the compliance ratio is less than a third threshold, determining a minimum value between the CVSS risk indicator and a fourth preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value as the first indicator; The first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value.
4. The method according to claim 3, characterized in that Determining the CVSS risk indicator of the asset based on the CVSS score includes: Determine the CVSS risk indicator CVSS_Risk_score_1 of the asset; Among them, CVSS_Risk_score_1=2*Initial_Vulnerability_Score*(Sigmoid(h1*∑(CVSS_Score))–0.5); Where CVSS_Score is the CVSS score of each vulnerability; ∑ is the summation symbol; Sigmoid is the S-shaped growth curve function; Initial_Vulnerability_Score is the adjustable first preset parameter; h1 is the adjustable second preset parameter.
5. The method according to claim 1, characterized in that The determining (102) of a second indicator representing the severity of the security incident that has occurred on the asset includes: Determine the security incidents that have occurred for the asset, and the incident level, frequency, and duration of the security incidents that have occurred; Determining a completeness score for the security incident based on the incident level, frequency, and duration; Determining a confidentiality score for the security incident based on the incident level, frequency, and duration; Determining an availability score for the security incident based on the incident level, occurrence frequency, and duration; The second indicator is determined based on the integrity score, the confidentiality score, and the availability score.
6. The method according to any one of claims 1 to 5, characterized in that Also includes: Creating a first virtual scenario of the asset, wherein in the first virtual scenario, the asset includes a first vulnerability with a first CVSS score and a first security event with an emergency level; creating a second virtual scenario of the asset, wherein in the second virtual scenario, the asset includes a second vulnerability with a second CVSS score and a second security event with an event level of alert, wherein the first CVSS score is greater than the second CVSS score; determining a fourth indicator representing a risk of the asset in the first virtual scenario; determining a fifth indicator representing a risk of the asset in a second virtual scenario; Based on the fourth indicator and the fifth indicator, a qualitative analysis is performed on the third indicator.
7. The method according to claim 6, characterized in that The performing a qualitative analysis on the third indicator based on the fourth indicator and the fifth indicator includes: When the third indicator is greater than or equal to the fourth indicator, the risk is determined to be at a high level; When the third indicator is less than or equal to the fifth indicator, the risk is determined to be at a low level; When the third indicator is greater than the fifth indicator and less than the fourth indicator, the risk is determined to be at an intermediate level.
8. A device for assessing asset risk, characterized in that: include: A first determination module (501) is configured to determine a first indicator representing a vulnerability level of an asset; A second determination module (502) is configured to determine a second indicator representing the severity of the security event that has occurred on the asset; The third determination module (503) is configured to determine a third indicator representing the risk of the asset based on the first indicator and the second indicator.
9. The device according to claim 8, characterized in that The first determination module (501) is configured to determine a CVSS score of the asset; Performing a compliance check on the security configuration of the asset to determine a compliance ratio of the asset; The first indicator is determined based on the compliance ratio and the CVSS score.
10. The device according to claim 8, characterized in that The first determination module (501) is configured to determine the CVSS risk index of the asset based on the CVSS score; when the compliance ratio is greater than or equal to a first threshold value, determine the minimum value between the CVSS risk index and a first preset value as the first index; when the compliance ratio is greater than or equal to a second threshold value and less than the first threshold value, determine the minimum value between the CVSS risk index and the second preset value, and determine the maximum value between the minimum value between the CVSS risk index and the second preset value and the first preset value as the first index; When the compliance ratio is greater than or equal to a third threshold value and less than the second threshold value, determining a minimum value between the CVSS risk indicator and a third preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the third preset value and the second preset value as the first indicator; When the compliance ratio is less than a third threshold, determining a minimum value between the CVSS risk indicator and a fourth preset value, and determining a maximum value between the minimum value between the CVSS risk indicator and the fourth preset value and the third preset value as the first indicator; The first threshold value is greater than the second threshold value, the second threshold value is greater than the third threshold value, the first preset value is less than the second preset value, the second preset value is less than the third preset value, and the third preset value is less than the fourth preset value.
11. The device according to claim 8, characterized in that The second determination module (502) is configured to determine a security event that has occurred on the asset, and an event level, occurrence frequency, and duration of the security event that has occurred; Determining a completeness score for the security incident based on the incident level, frequency, and duration; Determining a confidentiality score for the security incident based on the incident level, frequency, and duration; Determining an availability score for the security incident based on the incident level, occurrence frequency, and duration; The second indicator is determined based on the integrity score, the confidentiality score, and the availability score.
12. The device according to any one of claims 8 to 11, characterized in that Also includes: A qualitative analysis module (504) is configured to create a first virtual scenario of the asset, wherein in the first virtual scenario, the asset includes a first vulnerability with a first CVSS score and a first security event with an emergency level; and create a second virtual scenario of the asset, wherein in the second virtual scenario, the asset includes a second vulnerability with a second CVSS score and a second security event with an alarm level, wherein the first CVSS score is greater than the second CVSS score. Determining a fourth indicator representing the risk of the asset when it is in the first virtual scene; determining a fifth indicator representing the risk of the asset when it is in the second virtual scene; Based on the fourth indicator and the fifth indicator, a qualitative analysis is performed on the third indicator.
13. The device according to claim 12, characterized in that The qualitative analysis module (504) is configured to determine that the risk is a high level when the third indicator is greater than or equal to the fourth indicator; determine that the risk is a low level when the third indicator is less than or equal to the fifth indicator; and determine that the risk is an intermediate level when the third indicator is greater than the fifth indicator and less than the fourth indicator.
14. An electronic device, characterized in that: include: Processor (601); a memory (602) for storing executable instructions of the processor (601); The processor (601) is configured to read the executable instructions from the memory (602) and execute the executable instructions to implement the method for assessing asset risk according to any one of claims 1 to 7.
15. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed by a processor, the method for assessing asset risk according to any one of claims 1 to 7 is implemented.
16. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the method for assessing asset risk according to any one of claims 1 to 7.