Information security risk quantitative evaluation method and system

By generating risk timing curves and analyzing steady state and sudden threat coefficients, the problem of insufficient correlation analysis of risk factors in traditional evaluation methods is solved, and the accuracy and comprehensiveness of information security risk assessment is achieved.

CN120378231AActive Publication Date: 2025-07-25HUANENG INFORMATION TECH CO LTD
View PDF 16 Cites 0 Cited by

Patent Information

Application Number
CN202510874116.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-07-25
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

Traditional information security risk assessment methods fail to deeply analyze the association and impact of risk factors, resulting in the assessment results that cannot truly reflect the overall security risk status of the system.

Method used

By obtaining the security event sequence of the target information system, a risk timing curve is generated, fluctuation characteristic analysis is carried out, steady state and sudden threat coefficients are determined, and weighted sum is performed to calculate the information security risk quantitative evaluation coefficient.

Benefits of technology

It realizes the accuracy and comprehensiveness of quantitative assessment of information security risks, and truly reflects the overall security risk status of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378231A_ABST
    Figure CN120378231A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of risk assessment, and discloses an information security risk quantitative assessment method and system, and the method comprises the steps: obtaining a plurality of security event sequences of a target information system, and generating a risk time sequence curve based on timestamps corresponding to the security event sequences, the risk time sequence curve is a curve that the risk value of the security event sequence changes along with time; performing fluctuation characteristic analysis on each risk value of the risk time sequence curve, and determining a fluctuation factor of each risk value; according to the fluctuation factor, obtaining a steady-state threat coefficient and a sudden threat coefficient, and carrying out weighted summation to obtain a security event threat coefficient of the target information system; according to the method, the security event threat coefficient corresponding to each security event sequence is extracted, the security event threat coefficient is analyzed, the information security risk quantitative evaluation coefficient of the target information system is calculated based on the analysis result, the accuracy and comprehensiveness of information security risk quantitative evaluation are ensured, and the overall security risk condition of the system is truly reflected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of risk assessment, and in particular, to a method and system for quantitatively assessing information security risks. Background Art

[0002] In today's digital age, information security is of vital importance. With the rapid development of information technology, the scale and complexity of information systems are constantly increasing, and the security threats faced are becoming increasingly diverse and complex. Traditional information security risk assessment methods are gradually showing many limitations in dealing with these challenges.

[0003] Traditional risk assessment methods lack in comprehensively considering the interrelationships among various risk factors. The security risks of information systems are caused by the interaction of multiple factors, such as technical vulnerabilities, human operations, management processes, etc. However, many assessment methods simply display and score these factors without deeply analyzing their associations and impacts, resulting in the assessment results not being able to truly reflect the overall security risk status of the system and affecting the accuracy of risk assessment. Summary of the Invention

[0004] Embodiments of the present invention provide a method and system for quantitatively assessing information security risks. The present invention can analyze various risk factors to ensure the accuracy and comprehensiveness of the quantitative assessment of information security risks and truly reflect the overall security risk status of the system.

[0005] To achieve the above object, the present invention provides a method for quantitatively assessing information security risks, including: Determine the target information system to be risk-assessed, obtain multiple security event sequences of the target information system, and generate a risk time series curve based on the timestamps corresponding to the security event sequences, where the risk time series curve is a curve of the risk values of the security event sequences changing with time; Analyze the fluctuation characteristics of each risk value of the risk time series curve to determine the fluctuation factor of each risk value; According to the fluctuation factor corresponding to each risk value, obtain the steady-state threat coefficient and the sudden threat coefficient of the target information system, and perform weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system; Extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate the quantitative assessment coefficient of the information security risk of the target information system based on the analysis results.

[0006] Further, before generating the risk time series curve based on the timestamps corresponding to the security event sequences, it further includes: Traverse and preprocess the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generate a risk time series curve based on the preprocessed risk values and the corresponding timestamps.

[0007] Further, when analyzing the fluctuation characteristics of each risk value in the risk time series curve to determine the fluctuation factor of each risk value, it includes: Randomly determine a risk value on the risk time series curve as the benchmark risk value; Determine the benchmark timestamp corresponding to the benchmark risk value, and determine the forward timestamp and backward timestamp corresponding to the benchmark timestamp; Calculate the forward risk value average of the risk values corresponding to all forward timestamps, and calculate the backward risk value average of the risk values corresponding to all backward timestamps; Determine the absolute value of the forward difference between the benchmark risk value and the forward risk value average, and determine the absolute value of the backward difference between the benchmark risk value and the backward risk value average; Perform weighted summation on the absolute value of the forward difference and the absolute value of the backward difference to obtain the fluctuation factor of the benchmark risk value; Extract and calculate the remaining risk values on the risk time series curve to obtain the fluctuation factor corresponding to each risk value.

[0008] Further, when obtaining the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, it includes: Obtain a preset fluctuation factor, classify all the fluctuation factors according to the preset fluctuation factor to obtain steady-state fluctuation factors and sudden fluctuation factors; When the fluctuation factor is less than the preset fluctuation factor, classify the corresponding fluctuation factor as a steady-state fluctuation factor; When the fluctuation factor is greater than or equal to the preset fluctuation factor, classify the corresponding fluctuation factor as a sudden fluctuation factor; Calculate the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors; Calculate the sudden threat coefficient of the target information system according to all the sudden fluctuation factors.

[0009] Further, when calculating the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors, it includes: Preset the combination number q, and combine every q steady-state fluctuation factors based on the combination number q to obtain multiple groups of steady-state fluctuation factors; Calculate the steady-state fluctuation factor and value corresponding to each steady-state fluctuation factor group, and select the maximum steady-state fluctuation factor and value from all the steady-state fluctuation factors and values; Select the maximum steady-state fluctuation factor from all steady-state fluctuation factors; A ratio of the maximum steady-state fluctuation factor sum to the maximum steady-state fluctuation factor is determined as a steady-state threat coefficient of the target information system.

[0010] Furthermore, when calculating the sudden threat coefficient of the target information system according to all sudden fluctuation factors, it includes: Extracting the same burst fluctuation factor from all burst fluctuation factors and obtaining a plurality of burst fluctuation factor sequences; Count the number of the first burst fluctuation factor sequence of the burst fluctuation factor sequence; Extracting a burst fluctuation factor from all burst fluctuation factor sequences respectively, and calculating the first burst fluctuation factor and value; Obtaining a preset sudden fluctuation factor, eliminating all sudden fluctuation factor sequences that are smaller than the preset sudden fluctuation factor, and counting the number of second sudden fluctuation factor sequences of the remaining sudden fluctuation factor sequences; Extracting a burst fluctuation factor from the remaining burst fluctuation factor sequences respectively, and calculating a second burst fluctuation factor and value; The sudden threat coefficient of the target information system is calculated according to the number of the first sudden fluctuation factor sequences, the number of the second sudden fluctuation factor sequences, the first sudden fluctuation factor sum value and the second sudden fluctuation factor sum value.

[0011] Furthermore, when analyzing all security incident threat coefficients and calculating the information security risk quantitative assessment coefficient of the target information system based on the analysis results, it includes: Presetting a first preset adjustment coefficient and a second preset adjustment coefficient; Determine a characteristic security event threat coefficient of all security event threat coefficients, wherein the characteristic security event threat coefficient is the average of all security event threat coefficients; Calculate a first adjusted security event threat coefficient of the first preset adjustment coefficient and the characteristic security event threat coefficient, and calculate a second adjusted security event threat coefficient of the second preset adjustment coefficient and the characteristic security event threat coefficient; Sort all security incident threat coefficients in ascending order to determine the minimum security incident threat coefficient and the maximum security incident threat coefficient; generating a first coefficient identifier for a security event threat coefficient between the minimum security event threat coefficient and the first adjusted security event threat coefficient; Generate a second coefficient identifier for the security event threat coefficient between the first adjusted security event threat coefficient and the second adjusted security event threat coefficient; Generate a third coefficient identifier for the security event threat coefficient between the second adjusted security event threat coefficient and the maximum security event threat coefficient; Calculate the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier.

[0012] Further, when calculating the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier, it includes: Calculate the information security risk quantification evaluation coefficient of the target information system according to the following formula: ; where s is the information security risk quantification evaluation coefficient of the target information system, n is the number of security event threat coefficients, k i is the i-th security event threat coefficient, t1 is the first adjusted security event threat coefficient, t2 is the second adjusted security event threat coefficient, y1 is the number of security event threat coefficients corresponding to the first coefficient identifier, y2 is the number of security event threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security event threat coefficients corresponding to the third coefficient identifier.

[0013] To achieve the above object, the present invention also provides an information security risk quantification evaluation system, including: A curve generation module, configured to determine a target information system to be risk-assessed, obtain multiple security event sequences of the target information system, and generate a risk time series curve based on the timestamps corresponding to the security event sequences, where the risk time series curve is a curve of the risk value of the security event sequence changing with time; A data analysis module, configured to perform a fluctuation feature analysis on each risk value of the risk time series curve to determine the fluctuation factor of each risk value; A weighted summation module, configured to obtain the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform a weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system; A risk assessment module, configured to extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate the information security risk quantification evaluation coefficient of the target information system based on the analysis result.

[0014] Further, it also includes: A data processing module is used to traverse and preprocess the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generate a risk time series curve based on the preprocessed risk values and the corresponding timestamps.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention obtains multiple security event sequences of a target information system, generates a risk time series curve based on the timestamps corresponding to the security event sequences, where the risk time series curve is a curve of the risk values of the security event sequences changing with time; analyzes the fluctuation characteristics of each risk value of the risk time series curve to determine the fluctuation factor of each risk value; obtains a steady-state threat coefficient and a sudden threat coefficient according to the fluctuation factor, performs weighted summation to obtain the security event threat coefficient of the target information system; extracts the security event threat coefficient corresponding to each security event sequence, analyzes the security event threat coefficient, and calculates the information security risk quantification evaluation coefficient of the target information system based on the analysis result, ensuring the accuracy and comprehensiveness of the information security risk quantification evaluation and truly reflecting the overall security risk status of the system. Description of the Drawings

[0016] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings: Figure 1 Shows a schematic flow chart of an information security risk quantification evaluation method in an embodiment of the present invention; Figure 2 Shows a schematic structural diagram of an information security risk quantification evaluation system in an embodiment of the present invention. Detailed Embodiments

[0017] The following combines the drawings and embodiments to further describe the specific embodiments of the present invention in detail. The following embodiments are used to illustrate the present invention but are not used to limit the scope of the present invention.

[0018] In the description of the present application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present application.

[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise specified, the meaning of "a plurality" is two or more.

[0020] In the description of this application, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", and "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.

[0021] The following is a description of the preferred embodiments of the present invention in conjunction with the accompanying drawings.

[0022] As Figure 1 shown, the embodiments of the present invention disclose an information security risk quantification and assessment method, including: S110: Determine the target information system to be risk-assessed, obtain multiple security event sequences of the target information system, and generate a risk time series curve based on the timestamps corresponding to the security event sequences, where the risk time series curve is a curve of the risk values of the security event sequences changing with time; In this embodiment, the security event sequence is a set of security events sorted by time.

[0023] In this embodiment, the security events include: illegal login, privilege abuse, intrusion using system vulnerabilities, viruses, ransomware running, etc. Each security event corresponds to a timestamp and a risk value, and a security event sequence is constructed according to each type of security event.

[0024] In this embodiment, the risk value is a numerical value quantifying the harm degree of an event. Specifically, the risk value refers to the severity of the event. For example, the risk value of an illegal login is preferably 2, and the risk value of privilege abuse is preferably 3, etc. It can be set according to the actual situation. The range of the risk value is [1, 20].

[0025] S120: Analyze the fluctuation characteristics of each risk value of the risk time series curve to determine the fluctuation factor of each risk value; In some embodiments of this application, before generating the risk time series curve based on the timestamps corresponding to the security event sequences, it further includes: Traverse and preprocess the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generate a risk time series curve based on the preprocessed risk values and the corresponding timestamps.

[0026] In this embodiment, deleting error data means deleting obviously incorrect risk values, such as a risk value of 50.

[0027] The beneficial effects of the above technical solution are: The present invention traverses and preprocesses the risk values in each security event sequence, deletes duplicate data and error data, ensuring data accuracy and providing a basis for quantitative assessment of information security risks.

[0028] In some embodiments of the present application, when analyzing the fluctuation characteristics of each risk value of the risk time series curve to determine the fluctuation factor of each risk value, it includes: Randomly determine a risk value on the risk time series curve as the reference risk value; Determine the reference timestamp corresponding to the reference risk value, and determine the forward timestamp and backward timestamp corresponding to the reference timestamp; Calculate the average forward risk value of the risk values corresponding to all forward timestamps, and calculate the average backward risk value of the risk values corresponding to all backward timestamps; Determine the absolute value of the forward difference between the reference risk value and the average forward risk value, and determine the absolute value of the backward difference between the reference risk value and the average backward risk value; Perform weighted summation on the absolute value of the forward difference and the absolute value of the backward difference to obtain the fluctuation factor of the reference risk value; Extract and calculate the remaining risk values on the risk time series curve to obtain the fluctuation factor corresponding to each risk value.

[0029] In this embodiment, if the reference timestamp is 14:30:45 and two other timestamps are given, such as 14:20:45 and 14:35:45, then 14:20:45 is the forward timestamp and 14:35:45 is the backward timestamp. Here, for easy understanding, an example is shown. That is, earlier than the reference timestamp is determined as the forward timestamp, and later than the reference timestamp is determined as the backward timestamp.

[0030] In this embodiment, configure a first weight, preferably 0.4, for the absolute value of the forward difference, and configure a second weight, preferably 0.6, for the absolute value of the backward difference. Perform weighted summation on the absolute value of the forward difference and the absolute value of the backward difference based on the first weight and the second weight to obtain the fluctuation factor of the reference risk value.

[0031] In this embodiment, the above steps are repeated to extract and calculate the remaining risk values on the risk time series curve, and the fluctuation factor corresponding to each risk value is obtained.

[0032] The beneficial effects of the above technical solution are as follows: The present invention extracts and calculates the remaining risk values on the risk time series curve, and obtains the fluctuation factor corresponding to each risk value. The fluctuation factor can characterize the discrete situation of each risk value relative to all risk values, ensuring the accuracy of subsequent evaluations.

[0033] S130: According to the fluctuation factor corresponding to each risk value, obtain the steady-state threat coefficient and the sudden threat coefficient of the target information system, and perform weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security incident threat coefficient of the target information system. In some embodiments of the present application, when obtaining the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, it includes: Obtain a preset fluctuation factor, classify all the fluctuation factors according to the preset fluctuation factor, and obtain a steady-state fluctuation factor and a sudden fluctuation factor. When the fluctuation factor is less than the preset fluctuation factor, the corresponding fluctuation factor is classified as a steady-state fluctuation factor. When the fluctuation factor is greater than or equal to the preset fluctuation factor, the corresponding fluctuation factor is classified as a sudden fluctuation factor. Calculate the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors. Calculate the sudden threat coefficient of the target information system according to all the sudden fluctuation factors.

[0034] In this embodiment, the preset fluctuation factor is preferably 6, and it can be specifically adjusted according to the actual situation.

[0035] In some embodiments of the present application, when calculating the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors, it includes: Preset the combination number q, and combine every q steady-state fluctuation factors based on the combination number q to obtain multiple groups of steady-state fluctuation factors. Calculate the sum value of the steady-state fluctuation factors corresponding to each group of steady-state fluctuation factors, and select the maximum sum value of the steady-state fluctuation factors from all the sum values of the steady-state fluctuation factors. Select the maximum steady-state fluctuation factor from all the steady-state fluctuation factors. Determine the ratio of the maximum sum value of the steady-state fluctuation factors to the maximum steady-state fluctuation factor as the steady-state threat coefficient of the target information system.

[0036] In this embodiment, q is preferably 2, that is, every two steady-state fluctuation factors are combined to obtain multiple steady-state fluctuation factor groups.

[0037] The beneficial effect of the above technical solution is that the present invention determines the ratio of the sum of the maximum steady-state fluctuation factors to the maximum steady-state fluctuation factor as the steady-state threat coefficient of the target information system, ensuring the calculation accuracy of the steady-state threat coefficient. The steady-state threat coefficient can provide a computational support for the quantitative assessment of information security risks in one direction.

[0038] In some embodiments of the present application, when calculating the sudden threat coefficient of the target information system according to all the sudden fluctuation factors, it includes: Extract the same sudden fluctuation factors from all the sudden fluctuation factors to obtain multiple sudden fluctuation factor sequences; Count the number of the first sudden fluctuation factor sequences of the sudden fluctuation factor sequences; Extract one sudden fluctuation factor from each of all the sudden fluctuation factor sequences and calculate the sum of the first sudden fluctuation factors; Obtain a preset sudden fluctuation factor, eliminate all the sudden fluctuation factor sequences smaller than the preset sudden fluctuation factor, and count the number of the second sudden fluctuation factor sequences of the remaining sudden fluctuation factor sequences; Extract one sudden fluctuation factor from each of the remaining sudden fluctuation factor sequences and calculate the sum of the second sudden fluctuation factors; Calculate the sudden threat coefficient of the target information system according to the number of the first sudden fluctuation factor sequences, the number of the second sudden fluctuation factor sequences, the sum of the first sudden fluctuation factors, and the sum of the second sudden fluctuation factors.

[0039] In this embodiment, the preset sudden fluctuation factor refers to the variance corresponding to all the sudden fluctuation factors, which can characterize the dispersion degree of all the sudden fluctuation factors.

[0040] In this embodiment, the sudden threat coefficient of the target information system is calculated according to the following formula: ; where r is the sudden threat coefficient of the target information system, c1 is the number of the first sudden fluctuation factor sequences, c2 is the number of the second sudden fluctuation factor sequences, v1 is the sum of the first sudden fluctuation factors, and v2 is the sum of the second sudden fluctuation factors.

[0041] The beneficial effect of the above technical solution is that the present invention calculates the sudden threat coefficient of the target information system according to the number of the first sudden fluctuation factor sequences, the number of the second sudden fluctuation factor sequences, the sum of the first sudden fluctuation factors, and the sum of the second sudden fluctuation factors, ensuring the calculation accuracy of the sudden threat coefficient. The sudden threat coefficient can provide a computational support for the quantitative assessment of information security risks in another direction.

[0042] In some embodiments of the present application, a third weight is configured for the steady-state threat coefficient, preferably 0.3, and a fourth weight is configured for the sudden threat coefficient, preferably 0.7. The steady-state threat coefficient and the sudden threat coefficient are weighted and summed according to the third weight and the fourth weight to obtain the security event threat coefficient of the target information system.

[0043] The beneficial effects of the above technical solution are as follows: According to the third weight and the fourth weight, the present invention performs weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system. The security event threat coefficient can represent the security event threat situation corresponding to a type of security event of the target information system, further ensuring the accuracy of the quantitative assessment of security risks.

[0044] S140: Extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate the information security risk quantitative assessment coefficient of the target information system based on the analysis results.

[0045] In this embodiment, according to the above steps, the security event threat coefficient corresponding to each security event sequence can be obtained.

[0046] In some embodiments of the present application, when analyzing all the security event threat coefficients and calculating the information security risk quantitative assessment coefficient of the target information system based on the analysis results, it includes: Preset a first preset adjustment coefficient and a second preset adjustment coefficient; Determine the characteristic security event threat coefficient of all the security event threat coefficients, where the characteristic security event threat coefficient is the mean value of all the security event threat coefficients; Calculate the first adjusted security event threat coefficient of the first preset adjustment coefficient and the characteristic security event threat coefficient, and calculate the second adjusted security event threat coefficient of the second preset adjustment coefficient and the characteristic security event threat coefficient; Sort all the security event threat coefficients in ascending order to determine the minimum security event threat coefficient and the maximum security event threat coefficient; Generate a first coefficient identifier for the security event threat coefficients between the minimum security event threat coefficient and the first adjusted security event threat coefficient; Generate a second coefficient identifier for the security event threat coefficients between the first adjusted security event threat coefficient and the second adjusted security event threat coefficient; Generate a third coefficient identifier for the security event threat coefficients between the second adjusted security event threat coefficient and the maximum security event threat coefficient; Calculate the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier.

[0047] In this embodiment, the first preset adjustment coefficient is preferably 0.95, and the second preset adjustment coefficient is preferably 1.05.

[0048] In this embodiment, the first coefficient identifier does not include the first adjusted security event threat coefficient, but includes the security event threat coefficient equal to the first adjusted security event threat coefficient. The second coefficient identifier does not include the first adjusted security event threat coefficient and the second adjusted security event threat coefficient, nor the security event threat coefficient equal to the first adjusted security event threat coefficient and the second adjusted security event threat coefficient. The third coefficient identifier does not include the second adjusted security event threat coefficient, but includes the security event threat coefficient equal to the second adjusted security event threat coefficient.

[0049] The beneficial effects of the above technical solutions are as follows: The present invention calculates the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier, ensuring the accuracy and comprehensiveness of the information security risk quantification evaluation and truly reflecting the overall security risk status of the system.

[0050] In some embodiments of the present application, when calculating the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier, it includes: Calculate the information security risk quantification evaluation coefficient of the target information system according to the following formula: ; where s is the information security risk quantification evaluation coefficient of the target information system, n is the number of security event threat coefficients, k i is the i-th security event threat coefficient, t1 is the first adjusted security event threat coefficient, t2 is the second adjusted security event threat coefficient, y1 is the number of security event threat coefficients corresponding to the first coefficient identifier, y2 is the number of security event threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security event threat coefficients corresponding to the third coefficient identifier.

[0051] To further elaborate on the technical idea of the present invention, the technical solutions of the present invention will be described in combination with specific application scenarios.

[0052] Correspondingly, as Figure 2 shown, the present application also provides an information security risk quantification evaluation system, including: A curve generation module for determining a target information system to be risk-assessed, obtaining multiple security event sequences of the target information system, and generating a risk time-series curve based on the timestamps corresponding to the security event sequences, where the risk time-series curve is a curve of the risk values of the security event sequences changing with time; A data analysis module for performing fluctuation feature analysis on each risk value of the risk time-series curve to determine the fluctuation factor of each risk value; A weighted summation module for obtaining the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factors corresponding to each risk value, and performing weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system; A risk assessment module for extracting the security event threat coefficients corresponding to each security event sequence, analyzing all the security event threat coefficients, and calculating the information security risk quantification assessment coefficient of the target information system based on the analysis results.

[0053] In some embodiments of the present application, it further includes: A data processing module for traversing and preprocessing the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generating a risk time-series curve based on the preprocessed risk values and the corresponding timestamps.

[0054] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in a suitable manner in any one or more embodiments or examples.

[0055] Although the present invention has been described above with reference to embodiments, various improvements can be made to it and components therein can be replaced with equivalents without departing from the scope of the present invention. In particular, as long as there is no structural conflict, the various features in the embodiments disclosed in the present invention can be combined with each other in any way, and only for the sake of saving space and resources, the description of all these combinations is not given in this specification.

[0056] Those of ordinary skill in the art can understand that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. An information security risk quantification and assessment method, characterized in that Including: Determine the target information system to be risk-assessed, obtain multiple security event sequences of the target information system, and generate a risk time series curve based on the timestamps corresponding to the security event sequences, where the risk time series curve is a curve of the risk values of the security event sequences changing with time; Conduct a fluctuation characteristic analysis on each risk value of the risk time series curve to determine the fluctuation factor of each risk value; Obtain the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform a weighted sum on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system; Extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate the information security risk quantitative assessment coefficient of the target information system based on the analysis results.

2. The information security risk quantification and assessment method according to claim 1, wherein Before generating the risk time series curve based on the timestamps corresponding to the security event sequences, it further includes: Traverse and preprocess the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generate a risk time series curve based on the preprocessed risk values and the corresponding timestamps.

3. The information security risk quantification and assessment method according to claim 1, wherein When conducting a fluctuation characteristic analysis on each risk value of the risk time series curve to determine the fluctuation factor of each risk value, it includes: Randomly determine a risk value on the risk time series curve as the reference risk value; Determine the reference timestamp corresponding to the reference risk value, and determine the forward timestamp and the backward timestamp corresponding to the reference timestamp; Calculate the forward risk value average of the risk values corresponding to all the forward timestamps, and calculate the backward risk value average of the risk values corresponding to all the backward timestamps; Determine the absolute value of the forward difference between the reference risk value and the forward risk value average, and determine the absolute value of the backward difference between the reference risk value and the backward risk value average; Perform a weighted sum on the absolute value of the forward difference and the absolute value of the backward difference to obtain the fluctuation factor of the reference risk value; Extract and calculate the remaining risk values on the risk time series curve to obtain the fluctuation factor corresponding to each risk value.

4. The information security risk quantification and assessment method according to claim 1, wherein When obtaining the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, it includes: Obtain a preset fluctuation factor, classify all the fluctuation factors according to the preset fluctuation factor to obtain the steady-state fluctuation factor and the sudden fluctuation factor; When the fluctuation factor is less than the preset fluctuation factor, classify the corresponding fluctuation factor as the steady-state fluctuation factor; When the fluctuation factor is greater than or equal to the preset fluctuation factor, classify the corresponding fluctuation factor as the sudden fluctuation factor; Calculate the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors; Calculate the sudden threat coefficient of the target information system according to all the sudden fluctuation factors.

5. The information security risk quantification and assessment method according to claim 4, wherein When calculating the steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors, it includes: Preset the number of combinations \(q\), and combine every \(q\) steady-state fluctuation factors based on the number of combinations \(q\) to obtain multiple groups of steady-state fluctuation factors; Calculate the sum value of the steady-state fluctuation factors corresponding to each group of steady-state fluctuation factors, and select the maximum sum value of the steady-state fluctuation factors from all the sum values of the steady-state fluctuation factors; Select the maximum steady-state fluctuation factor from all the steady-state fluctuation factors; Determine the ratio of the maximum sum value of the steady-state fluctuation factors to the maximum steady-state fluctuation factor as the steady-state threat coefficient of the target information system.

6. The information security risk quantification and assessment method according to claim 4, characterized in that When calculating the sudden threat coefficient of the target information system according to all the sudden fluctuation factors, it includes: Extract the same sudden fluctuation factors from all the sudden fluctuation factors and obtain multiple sequences of sudden fluctuation factors; Count the number of the first sequences of sudden fluctuation factors of the sequences of sudden fluctuation factors; Extract one sudden fluctuation factor from each of all the sequences of sudden fluctuation factors and calculate the sum value of the first sudden fluctuation factors; Obtain the preset sudden fluctuation factor, eliminate all the sequences of sudden fluctuation factors smaller than the preset sudden fluctuation factor, and count the number of the second sequences of sudden fluctuation factors of the remaining sequences of sudden fluctuation factors; Extract one sudden fluctuation factor from each of the remaining sequences of sudden fluctuation factors and calculate the sum value of the second sudden fluctuation factors; Calculate the sudden threat coefficient of the target information system according to the number of the first sequences of sudden fluctuation factors, the number of the second sequences of sudden fluctuation factors, the sum value of the first sudden fluctuation factors, and the sum value of the second sudden fluctuation factors.

7. The information security risk quantification and assessment method according to claim 1, wherein When analyzing all the threat coefficients of the security incidents and calculating the information security risk quantification evaluation coefficient of the target information system based on the analysis results, it includes: Preset the first preset adjustment coefficient and the second preset adjustment coefficient; Determine the characteristic threat coefficient of the security incidents of all the threat coefficients of the security incidents, where the characteristic threat coefficient of the security incidents is the average value of all the threat coefficients of the security incidents; Calculate the first adjusted threat coefficient of the security incidents of the first preset adjustment coefficient and the characteristic threat coefficient of the security incidents, and calculate the second adjusted threat coefficient of the security incidents of the second preset adjustment coefficient and the characteristic threat coefficient of the security incidents; Sort all the threat coefficients of the security incidents in ascending order, and determine the minimum threat coefficient of the security incidents and the maximum threat coefficient of the security incidents; Generate a first coefficient identifier for the threat coefficients of the security incidents between the minimum threat coefficient of the security incidents and the first adjusted threat coefficient of the security incidents; Generate a second coefficient identifier for the threat coefficients of the security incidents between the first adjusted threat coefficient of the security incidents and the second adjusted threat coefficient of the security incidents; Generate a third coefficient identifier for the threat coefficients of the security incidents between the second adjusted threat coefficient of the security incidents and the maximum threat coefficient of the security incidents; Calculate the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier.

8. The information security risk quantification and assessment method according to claim 7, wherein When calculating the information security risk quantification evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier, it includes: Calculate the information security risk quantification evaluation coefficient of the target information system according to the following formula: ; Among them, s is the information security risk quantification assessment coefficient of the target information system, n is the number of security incident threat coefficients, and k i is the i-th security incident threat coefficient, t1 is the first adjusted security incident threat coefficient, t2 is the second adjusted security incident threat coefficient, y1 is the number of security incident threat coefficients corresponding to the first coefficient identifier, y2 is the number of security incident threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security incident threat coefficients corresponding to the third coefficient identifier.

9. An information security risk quantification and assessment system, which is applied to the information security risk quantification and assessment method according to any one of claims 1-8, and is characterized in that, Including: A curve generation module, which is used to determine a target information system to be risk-assessed, obtain multiple security event sequences of the target information system, and generate a risk time-series curve based on the timestamps corresponding to the security event sequences, where the risk time-series curve is a curve of the risk values of the security event sequences changing with time; A data analysis module, which is used to analyze the fluctuation characteristics of each risk value of the risk time-series curve and determine the fluctuation factor of each risk value; A weighted summation module, which is used to obtain the steady-state threat coefficient and the sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform weighted summation on the steady-state threat coefficient and the sudden threat coefficient to obtain the security event threat coefficient of the target information system; A risk assessment module, which is used to extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate the information security risk quantitative assessment coefficient of the target information system based on the analysis results.

10. The information security risk quantification and assessment system according to claim 9, wherein It further includes: A data processing module, which is used to traverse and preprocess the risk values in each security event sequence, where the preprocessing includes deleting duplicate data and deleting error data; Generate a risk time-series curve based on the preprocessed risk values and the corresponding timestamps.

Citation Information

Patent Citations

  • Information system risk assessment method and apparatus

    CN106713333A

  • Method and system for evaluating risk of information system

    CN106790198A

  • Information security risk assessment method and device, equipment and storage medium

    CN111444514A

  • Quantitative assessment method for data security risk

    CN115982711A

  • Multi-dimensional information security risk assessment method and system, and storage medium

    CN116305168A