Asset security situation awareness and risk assessment system based on multi-source data fusion
By building an asset security situation awareness and risk assessment system with multi-source data fusion, it solves the problem that it is difficult to deeply analyze the causes of asset threats in the existing technology, and accurately evaluate and manage asset security risks, improving the efficiency and accuracy of security management.
Patent Information
- Application Number
- CN202510334372.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-25
AI Technical Summary
The existing asset security situation awareness system only stays at the level of perceived security situation, and fails to deeply analyze and accurately lock in the specific reasons why assets may be threatened, making it difficult for security managers to quickly locate the root cause of the problem and take effective measures.
The asset security situation awareness and risk assessment system based on multi-source data fusion is adopted, including asset simulation model construction, asset security situation awareness, asset threat instruction simulation and asset security risk assessment modules. By building asset simulation models and real-time perception of asset performance characteristics, threat instructions are generated and simulated to quantitatively evaluate the security risk level of assets.
It realizes an accurate assessment of asset security risks, improves the efficiency and accuracy of security management, can quickly identify and locate asset security risks, and provides more reliable security guarantees.
Smart Images

Figure CN120373839A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of asset security management, and more specifically, to an asset security situation perception and risk assessment system based on multi-source data fusion. Background Art
[0002] With the rapid development of information technology, the assets that various organizations and enterprises rely on are becoming increasingly diverse, including but not limited to hardware equipment, software systems, data resources, and network services. These assets are not only the core foundation of enterprise operations, but also the key to their business continuity and data security. However, at the same time, the security threats faced by assets are becoming increasingly complex and varied, including hacker attacks, malware, internal leaks, system vulnerabilities and other types. Therefore, how to effectively manage and ensure asset security has become an important issue that needs to be solved in the current information security field.
[0003] In order to overcome the limitations of traditional asset security management methods, asset security situation awareness systems have gradually become a research hotspot in recent years. Such systems can perceive the security situation of assets in real time through in-depth analysis of asset data, but most of them currently only stay at the level of perceiving the security situation of assets, and fail to further analyze and accurately identify the specific reasons why assets may be threatened. This means that although the system can detect the existence of security risks, security managers often find it difficult to quickly locate the root cause of the problem, and thus cannot take effective countermeasures.
[0004] In view of the above background, the present invention proposes an asset security situation awareness and risk assessment system based on multi-source data fusion, which aims to simulate the performance of assets under different threat scenarios based on simulation technology, so as to achieve the graded assessment of asset security risks. This innovative solution will significantly improve the efficiency and accuracy of asset security management and provide organizations with more reliable security protection. Summary of the invention
[0005] In view of the shortcomings of the prior art, the purpose of the present invention is to provide an asset security situation awareness and risk assessment system based on multi-source data fusion.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] An asset security situation awareness and risk assessment system based on multi-source data fusion, including an asset simulation model building module, an asset security situation awareness module, an asset threat instruction simulation module, and an asset security risk assessment module;
[0008] The asset simulation model building module builds an asset simulation model based on the asset configuration and asset network layout of the target asset;
[0009] The asset security situation awareness module regularly determines the asset performance feature set of the target asset, and determines whether there are potential security situation hazards in the target asset based on the asset performance feature set;
[0010] When the asset threat instruction simulation module determines that there are potential security situation hazards in the target asset, it uses a scripting language to generate multiple asset threat instructions and determines the performance feature consistency index of each asset threat instruction;
[0011] The asset security risk assessment module conducts a risk assessment on the target asset based on the performance feature consistency index of each asset threat instruction and determines the security risk level of the target asset.
[0012] Furthermore, it is determined whether there are potential security situation hazards in the target asset based on the asset performance feature set: the security situation awareness index of the target asset is determined based on the asset performance feature set, a security situation awareness standard index is set, and when the security situation awareness index of the target asset is less than the security situation awareness standard index, it is determined that there are potential security situation hazards in the target asset.
[0013] Furthermore, the asset performance feature set of the target asset is regularly determined and determined based on the following method: collect various aspects of asset data collected in the current cycle, extract features from various aspects of asset data, extract multiple asset performance features, and combine multiple asset performance features into an asset performance feature set in the form of a data set.
[0014] Furthermore, the security situation awareness index of the target asset is determined based on the asset performance feature set: obtain a security situation awareness model, use the asset performance feature set of the target asset as the input data of the security situation awareness model, and the security situation awareness model outputs the security situation awareness index.
[0015] Furthermore, the performance feature consistency index of the asset threat instruction is determined based on the following method: select an asset threat instruction, input the asset threat instruction into the asset simulation model, the asset simulation model conducts a one-cycle simulation, after the simulation ends, determine the asset performance feature set of the asset simulation model, match the asset performance feature set of the target asset with the asset performance feature set of the asset simulation model into a feature set comparison group, obtain a performance feature consistency analysis model, use the feature set comparison group as the input data of the performance feature consistency analysis model, and the performance feature consistency analysis model outputs the performance feature consistency index of the asset threat instruction.
[0016] Further, based on the performance characteristic consistency index of each asset threat instruction, a risk assessment is carried out on the target asset to determine the security risk level of the target asset: based on the performance characteristic consistency index of each asset threat instruction, the security risk complexity index index(pbd) of the target asset is determined, and it is set that each range of the security risk complexity index index(pbd) corresponds to a security risk level. The range of the security risk level is [0, index(pb1)], (index(pb1), index(pb2)], …, (index(pbD-1), index(pbD)]. The security risk levels include security risk level 1, security risk level 2, …, security risk level D-1, security risk level D. The asset risk of security risk level 1 is greater than the asset risk of security risk level 2, and so on.
[0017] Further, the security risk complexity index of the target asset is determined based on the following method: a performance characteristic consistency standard index is set. When the performance characteristic consistency index of the asset threat instruction is greater than or equal to the performance characteristic consistency standard index, the corresponding asset threat instruction is marked as a threat performance consistent instruction, and the total number of threat performance consistent instructions is marked as number(Bma). All the threat performance consistent instructions are compared pairwise, and the absolute difference value of the performance characteristic consistency index of the two compared threat performance consistent instructions is calculated to obtain the threat performance gap index. The sum of all threat performance gap indexes is calculated and averaged to obtain the average threat performance gap index index(avjbc). Through the security risk complexity index index(pbd) of the target asset is calculated, where a1 is the first coefficient and a2 is the second coefficient.
[0018] Compared with the prior art, the present invention has the following beneficial effects:
[0019] Through the asset simulation model construction module, the asset security situation awareness module, the asset threat instruction simulation module, and the asset security risk assessment module, in-depth analysis is regularly carried out on various aspects of asset data of the target asset to determine whether there are potential hidden dangers in the security situation of the target asset. After determining the potential hidden dangers in the security situation, the performance of the target asset when encountering different asset threat situations is simulated by combining simulation technology, and the performance in various asset threat situations is compared with the current actual performance, so as to comprehensively analyze the current security threat complexity of the target asset, and then conduct a grading assessment of the security risk of the target asset, which is convenient for accurately understanding the current security risk situation of the target asset. Brief Description of the Drawings
[0020] Figure 1 It is a module block diagram of an asset security situation awareness and risk assessment system based on multi-source data fusion;
[0021] Figure 2 Flow chart for determining the consistency index of the performance characteristics of asset threat instructions;
[0022] Figure 3 Flow chart for the operation of the asset security situation awareness and risk assessment system based on multi-source data fusion. Specific implementation manners
[0023] Referring to Figures 1-3 , the asset security situation awareness and risk assessment system based on multi-source data fusion includes an asset simulation model construction module, an asset security situation awareness module, an asset threat instruction simulation module, and an asset security risk assessment module.
[0024] The asset simulation model construction module determines target assets, determines the asset allocation and asset network layout of the target assets, and constructs an asset simulation model based on the asset allocation and asset network layout of the target assets.
[0025] An asset simulation model is constructed in the following manner: Select simulation software, add corresponding network nodes (such as routers, switches, servers, terminal devices, etc.) in the simulation software according to the asset network layout of the target asset, and connect them with links in accordance with the actual connection method to construct a network topology. Set the attribute parameters of the nodes, such as the IP address allocation of server nodes, the port rate of network devices, MAC addresses, etc., to make them consistent with the parameters in the asset configuration. Create corresponding modules according to the hardware and software conditions in the asset configuration. For example, for server hardware, a module representing the server can be created, and sub-modules such as CPU, memory, and disk can be set in it, and the resource interaction relationships between them can be defined; for the operating system and application programs, corresponding software modules can be created, which are connected to the hardware modules through input and output interfaces to simulate the call of hardware resources by the software and the interaction between software. Define the behavior logic and parameters of each module. For example, for the CPU module in the server module, set parameters such as its processing power (measured by indicators such as instructions per second) and the calculation method of utilization rate. The application program module defines its startup time, running process, resource requirements, etc., so that the constructed module can truly reflect the actual running state of the target asset. Accurately set the parameters of hardware assets in the simulation model, such as the number of CPU cores, memory capacity, disk I / O speed of the server, and the port bandwidth and forwarding ability of network devices, to ensure that these parameters are consistent with the data in the actual asset configuration file. For example, set the memory capacity of the server in the simulation software to 256GB in actuality, and configure the disk I / O read and write speed according to the actual hard disk performance indicators, so that the simulation model can perform operation simulation based on real hardware conditions. For software assets, set the parameters of the operating system (such as system scheduling strategy, memory allocation strategy, etc.), the running parameters of the application program (such as the maximum number of concurrent users, response time requirements, etc.), and the configuration parameters of the database system (such as query optimization strategy, data cache size, etc.), so that the running characteristics of the software in the simulation model are consistent with the actual situation. Define the communication behavior logic between network devices, such as the routing forwarding rules of routers, the port forwarding mechanism of switches, the access control strategy of firewalls, etc., and the network interaction logic between servers and terminal devices, such as the server responding to the service requests of terminals, and terminals uploading and downloading data to the server, to ensure that the network behavior in the simulation model conforms to the actual target asset network configuration and business process. Consider the operation behavior logic of users on the target asset, such as the verification process for users to log in to the system, the operation permissions and operation processes of users with different permissions for various application programs and data, etc. By setting corresponding logical judgment and operation trigger mechanisms in the simulation model, simulate the behavior of real users on the target asset, so that the model can reflect the impact on the target asset that may be brought about by changes in user behavior. Finally, the asset simulation model is constructed.
[0026] The asset security situation awareness module collects various aspects of asset data of the target asset in real time (asset data includes but is not limited to the following aspects: network traffic data, user behavior data, resource performance data), regularly determines the asset performance feature set of the target asset, determines the security situation awareness index of the target asset based on the asset performance feature set, sets a security situation awareness standard index (the security situation awareness standard index is a preset index used to compare with the security situation awareness index). When the security situation awareness index of the target asset is less than the security situation awareness standard index, it is determined that there is a security situation hidden danger for the target asset (when the security situation awareness index of the target asset is greater than or equal to the security situation awareness standard index, no corresponding processing is performed).
[0027] Regularly determine the asset performance feature set of the target asset, which is determined based on the following method: collect various aspects of asset data collected during the current period, perform feature extraction on various aspects of asset data (such as extracting features such as traffic size and protocol type from network traffic data, extracting features such as login time, operation type, and operation object from user behavior data, and extracting features such as CPU usage rate and memory usage rate from resource performance data), obtain multiple asset performance features, and combine multiple asset performance features into an asset performance feature set in the form of a data set.
[0028] Determine the security situation awareness index of the target asset based on the asset performance feature set: obtain the security situation awareness model, use the asset performance feature set of the target asset as the input data of the security situation awareness model, and the security situation awareness model outputs the security situation awareness index.
[0029] Security situation awareness model: construct a deep learning model, collect multiple asset performance feature sets, train the deep learning model through the asset performance feature sets, assign a security situation awareness index to each asset performance feature set, and the index range of the security situation awareness index is (10.0 - 100.0). The smaller the security situation awareness index, the greater the security situation hidden danger of the target asset. Divide the training data into a training set, a validation set, and a test set, with a ratio of 70%:15%:15%. Use the training set to train the model, continuously adjust the parameters of the model to minimize the value of the loss function. During the training process, use the validation set to monitor the performance of the model to avoid overfitting, and use the test set to evaluate the trained model. Finally, construct the security situation awareness model.
[0030] The asset threat instruction simulation module, when it is determined that there is a security situation hidden danger for the target asset, uses a scripting language to generate multiple asset threat instructions (each asset threat instruction corresponds to a different asset threat reason to simulate different asset threat situations), and determines the performance feature consistency index of each asset threat instruction.
[0031] The consistency index of the performance characteristics of the asset threat instruction is determined based on the following method: Select an asset threat instruction, input the asset threat instruction into the asset simulation model. The asset simulation model conducts a cycle of simulation. After the simulation ends, determine the asset performance characteristic set of the asset simulation model. Match the asset performance characteristic set of the target asset with the asset performance characteristic set of the asset simulation model to form a characteristic set comparison group. Obtain the performance characteristic consistency analysis model, use the characteristic set comparison group as the input data of the performance characteristic consistency analysis model, and the performance characteristic consistency analysis model outputs the performance characteristic consistency index of the asset threat instruction.
[0032] Performance characteristic consistency analysis model: Construct a deep learning model, collect multiple characteristic set comparison groups. Each characteristic set comparison group consists of the asset performance characteristic set of a target asset and the asset performance characteristic set of the asset simulation model. Use the characteristic set comparison groups to train the deep learning model, and assign a performance characteristic consistency index to each characteristic set comparison group. The value range of the performance characteristic consistency index is (1.0 - 25.0). The larger the performance characteristic consistency index, the higher the similarity of the characteristic performance of the asset performance characteristic set of the target asset and the asset performance characteristic set of the asset simulation model in each dimension. Divide the training data into a training set, a validation set, and a test set, with a ratio of 60%:20%:20%. Train the training set, validation set, and test set. After training is completed, construct the performance characteristic consistency analysis model.
[0033] The asset security risk assessment module conducts a risk assessment on the target asset based on the performance characteristic consistency index of each asset threat instruction, and determines the security risk level of the target asset.
[0034] Conduct a risk assessment on the target asset based on the performance characteristic consistency index of each asset threat instruction, and determine the security risk level of the target asset: Based on the performance characteristic consistency index of each asset threat instruction, determine the security risk complexity index index(pbd) of the target asset. Set that each range of the security risk complexity index index(pbd) corresponds to a security risk level. The range of the security risk level is [0, index(pb1)], (index(pb1), index(pb2)], …, (index(pbD - 1), index(pbD)]. The security risk levels include security risk level 1, security risk level 2, …, security risk level D - 1, security risk level D. The asset risk of security risk level 1 is greater than the asset risk of security risk level 2, and so on.
[0035] The security risk complexity index of the target asset is determined based on the following method: Set a consistent performance characteristic standard index (the consistent performance characteristic standard index is a preset index used to compare with the consistent performance characteristic index). When the consistent performance characteristic index of the asset threat instruction is greater than or equal to the consistent performance characteristic standard index, mark the corresponding asset threat instruction as a threat performance consistent instruction (when the consistent performance characteristic index of the asset threat instruction is less than the consistent performance characteristic standard index, no corresponding processing is done). Mark the total number of threat performance consistent instructions as number(Bma). Compare all threat performance consistent instructions pairwise, calculate the absolute difference of the consistent performance characteristic indices of the two compared threat performance consistent instructions to obtain the threat performance gap index. Calculate the sum mean of all threat performance gap indices to obtain the average threat performance gap index index(avjbc). Through Calculate to obtain the security risk complexity index index(pbd) of the target asset, where a1 is the first coefficient, a2 is the second coefficient, the value of a1 is 0.92, and the value of a2 is 0.58 (the smaller the threat performance gap index of the two compared threat performance consistent instructions, the more likely it is that these two threat performance consistent instructions may cause similar asset performance characteristics of the target asset, and subsequent in-depth analysis is required to analyze the actual problems existing in the target asset).
[0036] Through the asset simulation model construction module, asset security situation awareness module, asset threat instruction simulation module, and asset security risk assessment module, regularly conduct in-depth analysis on various aspects of asset data of the target asset to determine whether there are potential security situation hazards in the target asset. After determining the potential security situation hazards, combine simulation technology to simulate the performance of the target asset when encountering different asset threat situations, compare the performance in various asset threat situations with the current actual performance, and then comprehensively analyze the current security threat complexity of the target asset, and then conduct a grading assessment of the security risk of the target asset to facilitate accurately understanding the current security risk situation of the target asset.
[0037] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by technicians in the field according to the actual situation.
[0038] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0039] It should be understood that in various embodiments of the present application, the order numbers of the above processes do not indicate the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0040] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0041] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0042] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0043] If the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solution of the present application, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, and other media that can store program codes.
[0044] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An asset security situation awareness and risk assessment system based on multi-source data fusion, characterized in that It includes an asset simulation model construction module, an asset security situation awareness module, an asset threat instruction simulation module, and an asset security risk assessment module; The asset simulation model construction module constructs an asset simulation model based on the asset allocation of the target asset and the asset network layout; The asset security situation awareness module regularly determines the asset performance characteristic set of the target asset, and determines whether there are potential security situation hazards in the target asset based on the asset performance characteristic set; The asset threat instruction simulation module, when it is determined that there are potential security situation hazards in the target asset, uses a scripting language to generate multiple asset threat instructions and determines the performance characteristic consistency index of each asset threat instruction; The asset security risk assessment module conducts a risk assessment on the target asset based on the performance characteristic consistency index of each asset threat instruction and determines the security risk level of the target asset.
2. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 1, characterized in that, Determine whether there are potential security situation hazards in the target asset based on the asset performance characteristic set: determine the asset security situation awareness index of the target asset based on the asset performance characteristic set, set the standard index of security situation awareness, and when the asset security situation awareness index of the target asset is less than the standard index of security situation awareness, it is determined that there are potential security situation hazards in the target asset.
3. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 1, characterized in that Regularly determine the asset performance characteristic set of the target asset, and determine it based on the following method: collect various aspects of asset data collected during the current period, extract features from the various aspects of asset data, extract multiple asset performance characteristics, and combine the multiple asset performance characteristics into an asset performance characteristic set in the form of a data set.
4. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 2, wherein Determine the asset security situation awareness index of the target asset based on the asset performance characteristic set: obtain the security situation awareness model, use the asset performance characteristic set of the target asset as the input data of the security situation awareness model, and the security situation awareness model outputs the asset security situation awareness index.
5. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 1, characterized in that, The performance characteristic consistency index of the asset threat instruction is determined based on the following method: select an asset threat instruction, input the asset threat instruction into the asset simulation model, the asset simulation model conducts a one-cycle simulation, after the simulation ends, determine the asset performance characteristic set of the asset simulation model, match the asset performance characteristic set of the target asset with the asset performance characteristic set of the asset simulation model to form a characteristic set comparison group, obtain the performance characteristic consistency analysis model, use the characteristic set comparison group as the input data of the performance characteristic consistency analysis model, and the performance characteristic consistency analysis model outputs the performance characteristic consistency index of the asset threat instruction.
6. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 1, characterized in that Based on the performance characteristic consistency index of each asset threat instruction, conduct a risk assessment on the target asset to determine the security risk level of the target asset: Based on the performance characteristic consistency index of each asset threat instruction, determine the security risk complexity index index(pbd) of the target asset. Set a range corresponding to each security risk complexity index index(pbd) for a security risk level. The range of the security risk level is [0, index(pb1)], (index(pb1), index(pb2)], …, (index(pbD-1), index(pbD)]. The security risk levels include security risk level 1, security risk level 2, …, security risk level D-1, security risk level D. The asset risk of security risk level 1 is greater than that of security risk level 2, and so on.
7. The asset security situation awareness and risk assessment system based on multi-source data fusion according to claim 6, characterized in that The security risk complexity index of the target asset is determined in the following manner: Set a consistent performance characteristic standard index. When the consistent performance characteristic index of the asset threat instruction is greater than or equal to the consistent performance characteristic standard index, mark the corresponding asset threat instruction as a threat performance consistent instruction, mark the total number of threat performance consistent instructions as number(Bma), compare all threat performance consistent instructions pairwise, calculate the absolute difference of the consistent performance characteristic indexes of the two compared threat performance consistent instructions to obtain a threat performance gap index, calculate the sum mean of all threat performance gap indexes to obtain an average threat performance gap index index(avjbc), and obtain the security risk complexity index index(pbd) of the target asset through calculation, where a1 is the first coefficient and a2 is the second coefficient.