Information security risk quantitative evaluation method and system
By generating risk time series curves and calculating volatility factors, the problem of insufficient correlation analysis of risk factors in traditional assessment methods is solved, thus achieving accuracy and comprehensiveness in information security risk assessment.
Patent Information
- Application Number
- CN202510874116.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-06-27
AI Technical Summary
Traditional information security risk assessment methods fail to deeply analyze the relationships and impacts between risk factors, resulting in inaccurate assessment results that cannot truly reflect the overall security risk status of the system.
By generating risk time series curves, analyzing the fluctuation factors of risk values, calculating steady-state threat coefficients and sudden threat coefficients, performing weighted summation, extracting security event threat coefficients, and finally calculating information security risk quantitative assessment coefficients.
It achieves accurate and comprehensive quantitative assessment of information security risks, truly reflecting the overall security risk status of the system.
Smart Images

Figure CN120378231B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of risk assessment, in particular to an information security risk quantitative evaluation method and system. BACKGROUND
[0002] In today's digital age, information security is of great importance. With the rapid development of information technology, the scale and complexity of information systems are increasing, and the security threats they face are becoming increasingly diverse and complex. Traditional information security risk assessment methods gradually reveal many limitations in dealing with these challenges.
[0003] Traditional risk assessment methods lack comprehensive consideration of the interrelationships between various risk factors. The security risk of an information system is generated by the interaction of multiple factors, such as technical vulnerabilities, personnel operations, management processes, etc. However, many assessment methods simply display and score these factors without in-depth analysis of their relationships and influences, resulting in assessment results that cannot truly reflect the overall security risk situation of the system, affecting the accuracy of risk assessment. SUMMARY
[0004] The embodiments of the present application provide an information security risk quantitative evaluation method and system, which can analyze various risk factors to ensure the accuracy and comprehensiveness of information security risk quantitative evaluation and truly reflect the overall security risk situation of the system.
[0005] To achieve the above purpose, the present application provides an information security risk quantitative evaluation method, comprising:
[0006] determining a target information system to be risk evaluated, obtaining a plurality of security event sequences of the target information system, and generating a risk time sequence curve based on the time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of the risk values of the security event sequences changing with time;
[0007] performing fluctuation characteristic analysis on each risk value of the risk time sequence curve to determine a fluctuation factor of each risk value;
[0008] obtaining a steady-state threat coefficient and a burst threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and performing weighted summation on the steady-state threat coefficient and the burst threat coefficient to obtain a security event threat coefficient of the target information system;
[0009] extracting the security event threat coefficient corresponding to each security event sequence, analyzing all security event threat coefficients, and calculating an information security risk quantitative evaluation coefficient of the target information system based on the analysis result.
[0010] Further, before generating a risk timing curve based on the time stamp corresponding to the security event sequence, further comprising:
[0011] Traverse the risk value in each security event sequence and pre-process, wherein the pre-processing includes deleting duplicate data and deleting error data;
[0012] Generate a risk timing curve based on the pre-processed risk value and the corresponding time stamp.
[0013] Further, when analyzing the fluctuation characteristics of each risk value of the risk timing curve and determining the fluctuation factor of each risk value, comprising:
[0014] Randomly determine a risk value on the risk timing curve as a reference risk value;
[0015] Determine the reference time stamp corresponding to the reference risk value, and determine the forward time stamp and the backward time stamp corresponding to the reference time stamp;
[0016] Calculate the forward risk value mean of the risk value corresponding to all forward time stamps, and calculate the backward risk value mean of the risk value corresponding to all backward time stamps;
[0017] Determine the forward difference absolute value of the reference risk value and the forward risk value mean, and determine the backward difference absolute value of the reference risk value and the backward risk value mean;
[0018] Weighted sum of the forward difference absolute value and the backward difference absolute value to obtain the fluctuation factor of the reference risk value;
[0019] Extract and calculate the remaining risk values on the risk timing curve to obtain the fluctuation factor corresponding to each risk value.
[0020] Further, when obtaining the steady-state threat coefficient and the burst threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, comprising:
[0021] Obtain a preset fluctuation factor, classify all fluctuation factors according to the preset fluctuation factor, and obtain steady-state fluctuation factors and burst fluctuation factors;
[0022] When the fluctuation factor is less than the preset fluctuation factor, the corresponding fluctuation factor is classified as a steady-state fluctuation factor;
[0023] When the fluctuation factor is greater than or equal to the preset fluctuation factor, the corresponding fluctuation factor is classified as a burst fluctuation factor;
[0024] Calculate the steady-state threat coefficient of the target information system according to all steady-state fluctuation factors;
[0025] According to all the burst fluctuation factors, a burst threat coefficient of the target information system is calculated.
[0026] Further, in calculating a steady-state threat coefficient of the target information system according to all the steady-state fluctuation factors, comprising:
[0027] A combination number q is preset, and every q steady-state fluctuation factors are combined based on the combination number q to obtain a plurality of steady-state fluctuation factor groups;
[0028] A steady-state fluctuation factor sum value corresponding to each steady-state fluctuation factor group is calculated, and a maximum steady-state fluctuation factor sum value is selected from all the steady-state fluctuation factor sum values;
[0029] A maximum steady-state fluctuation factor is selected from all the steady-state fluctuation factors;
[0030] A ratio of the maximum steady-state fluctuation factor sum value to the maximum steady-state fluctuation factor is determined as the steady-state threat coefficient of the target information system.
[0031] Further, in calculating a burst threat coefficient of the target information system according to all the burst fluctuation factors, comprising:
[0032] Same burst fluctuation factors are extracted from all the burst fluctuation factors, and a plurality of burst fluctuation factor sequences are obtained;
[0033] A first burst fluctuation factor sequence number of the burst fluctuation factor sequences is counted;
[0034] One burst fluctuation factor is extracted from each of all the burst fluctuation factor sequences, and a first burst fluctuation factor sum value is calculated;
[0035] A preset burst fluctuation factor is obtained, all the burst fluctuation factor sequences smaller than the preset burst fluctuation factor are removed, a second burst fluctuation factor sequence number of the remaining burst fluctuation factor sequences is counted;
[0036] One burst fluctuation factor is extracted from each of the remaining burst fluctuation factor sequences, and a second burst fluctuation factor sum value is calculated;
[0037] According to the first burst fluctuation factor sequence number, the second burst fluctuation factor sequence number, the first burst fluctuation factor sum value and the second burst fluctuation factor sum value, a burst threat coefficient of the target information system is calculated.
[0038] Further, in analyzing all the security event threat coefficients and calculating an information security risk quantitative evaluation coefficient of the target information system based on the analysis result, comprising:
[0039] The first preset adjustment coefficient and the second preset adjustment coefficient are preset;
[0040] A characteristic security event threat coefficient of all security event threat coefficients is determined, wherein the characteristic security event threat coefficient is a mean value of all security event threat coefficients;
[0041] A first adjusted security event threat coefficient of the first preset adjustment coefficient and the characteristic security event threat coefficient is calculated, and a second adjusted security event threat coefficient of the second preset adjustment coefficient and the characteristic security event threat coefficient is calculated;
[0042] All security event threat coefficients are sorted in ascending order, and a minimum security event threat coefficient and a maximum security event threat coefficient are determined;
[0043] A first coefficient identifier is generated for a security event threat coefficient between the minimum security event threat coefficient and the first adjusted security event threat coefficient;
[0044] A second coefficient identifier is generated for a security event threat coefficient between the first adjusted security event threat coefficient and the second adjusted security event threat coefficient;
[0045] A third coefficient identifier is generated for a security event threat coefficient between the second adjusted security event threat coefficient and the maximum security event threat coefficient;
[0046] The information security risk quantitative evaluation coefficient of the target information system is calculated based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier.
[0047] Further, when the information security risk quantitative evaluation coefficient of the target information system is calculated based on the first coefficient identifier, the second coefficient identifier, and the third coefficient identifier, the following is included:
[0048] The information security risk quantitative evaluation coefficient of the target information system is calculated according to the following formula:
[0049] ;
[0050] Wherein s is the information security risk quantitative evaluation coefficient of the target information system, n is the number of security event threat coefficients, k i is the i-th security event threat coefficient, t1 is the first adjusted security event threat coefficient, t2 is the second adjusted security event threat coefficient, y1 is the number of security event threat coefficients corresponding to the first coefficient identifier, y2 is the number of security event threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security event threat coefficients corresponding to the third coefficient identifier.
[0051] In order to achieve the above object, the application further provides an information security risk quantitative evaluation system, comprising:
[0052] a curve generation module, configured to determine a target information system to be evaluated, acquire a plurality of security event sequences of the target information system, and generate a risk time sequence curve based on time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of risk values of the security event sequences changing with time;
[0053] a data analysis module, configured to analyze fluctuation characteristics of each risk value of the risk time sequence curve, and determine a fluctuation factor of each risk value;
[0054] a weighted summation module, configured to obtain a steady threat coefficient and a burst threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform weighted summation on the steady threat coefficient and the burst threat coefficient to obtain a security event threat coefficient of the target information system;
[0055] a risk evaluation module, configured to extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate an information security risk quantitative evaluation coefficient of the target information system based on an analysis result.
[0056] Further, the application further comprises:
[0057] a data processing module, configured to traverse and preprocess risk values in each security event sequence, wherein the preprocessing comprises deleting duplicate data and deleting error data;
[0058] generate the risk time sequence curve based on the preprocessed risk values and corresponding time stamps.
[0059] Compared with the prior art, the application has the following beneficial effects:
[0060] The application acquires a plurality of security event sequences of a target information system, generates a risk time sequence curve based on time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of risk values of the security event sequences changing with time; analyzes fluctuation characteristics of each risk value of the risk time sequence curve, and determines a fluctuation factor of each risk value; obtains a steady threat coefficient and a burst threat coefficient according to the fluctuation factor, performs weighted summation, and obtains a security event threat coefficient of the target information system; extracts the security event threat coefficient corresponding to each security event sequence, analyzes the security event threat coefficients, and calculates an information security risk quantitative evaluation coefficient of the target information system based on an analysis result, thereby guaranteeing the accuracy and comprehensiveness of information security risk quantitative evaluation and truly reflecting the overall security risk status of the system. BRIEF DESCRIPTION OF DRAWINGS
[0061] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments with reference made to the accompanying drawings. The drawings are for purposes of illustration only and are not intended to be limiting, of the application. Like reference numerals have been used wherever possible throughout the drawings and the following detailed description, to refer to like parts. In the drawings:
[0062] Figure 1 A flowchart of a method for quantitatively evaluating information security risk in an embodiment of the application is shown;
[0063] Figure 2 A structure diagram of a system for quantitatively evaluating information security risk in an embodiment of the application is shown. DETAILED DESCRIPTION
[0064] The specific embodiments of the present application will be further described with reference to the drawings and examples. The following examples are intended to illustrate the present application, but not to limit the scope of the present application.
[0065] In the description of the present application, it needs to be understood that the terms "center", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the purpose of facilitating the description of the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.
[0066] The terms "first", "second", "third", etc. are only used for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second", etc. can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0067] In the description of the present application, it needs to be explained that, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connection" should be understood broadly, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be direct connection, or indirect connection through intermediate medium, or internal communication of two elements. For those of ordinary skill in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0068] The following is a description of the preferred embodiments of the present application in conjunction with the accompanying drawings.
[0069] As Figure 1As shown, the embodiment of the present application discloses an information security risk quantitative evaluation method, comprising:
[0070] S110: determining a target information system to be risk evaluated, acquiring a plurality of security event sequences of the target information system, and generating a risk time sequence curve based on time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of risk values of the security event sequences changing with time;
[0071] In the embodiment, the security event sequence is a set of security events sorted by time.
[0072] In the embodiment, the security event includes illegal login, privilege abuse, intrusion by exploiting system vulnerabilities, virus, and operation of ransomware, and each security event corresponds to a time stamp and a risk value, and a security event sequence is constructed according to each type of security event.
[0073] In the embodiment, the risk value is a numerical value quantifying the degree of event harm, and the risk value specifically refers to event severity, for example, the risk value of illegal login is preferably 2, and the risk value of privilege abuse is preferably 3, and the like. The risk value can be set according to actual conditions. The range of the risk value is [1, 20].
[0074] S120: performing fluctuation characteristic analysis on each risk value of the risk time sequence curve to determine a fluctuation factor of each risk value;
[0075] In some embodiments of the present application, before the risk time sequence curve is generated based on the time stamps corresponding to the security event sequences, the method further comprises:
[0076] traversing and preprocessing the risk values in each security event sequence, wherein the preprocessing includes deleting duplicate data and deleting error data;
[0077] generating the risk time sequence curve based on the preprocessed risk values and the corresponding time stamps.
[0078] In the embodiment, deleting error data refers to deleting obviously incorrect risk values, for example, a risk value of 50.
[0079] The above technical solution has the beneficial effects that the risk values in each security event sequence are traversed and preprocessed, duplicate data and error data are deleted, the data accuracy is ensured, and a basis is provided for information security risk quantitative evaluation.
[0080] In some embodiments of the present application, when the fluctuation characteristic analysis is performed on each risk value of the risk time sequence curve to determine the fluctuation factor of each risk value, the method comprises:
[0081] Randomly determine a risk value on the risk time sequence curve as a benchmark risk value;
[0082] Determine a benchmark timestamp corresponding to the benchmark risk value, and determine a forward timestamp and a backward timestamp corresponding to the benchmark timestamp;
[0083] Calculate a forward risk value mean of risk values corresponding to all forward timestamps, and calculate a backward risk value mean of risk values corresponding to all backward timestamps;
[0084] Determine a forward difference absolute value of the benchmark risk value and the forward risk value mean, and determine a backward difference absolute value of the benchmark risk value and the backward risk value mean;
[0085] Weighted sum the forward difference absolute value and the backward difference absolute value to obtain a volatility factor of the benchmark risk value;
[0086] Extract and calculate the remaining risk values on the risk time sequence curve to obtain a volatility factor corresponding to each risk value.
[0087] In this embodiment, if the benchmark timestamp is 14:30:45, and two other timestamps are given, such as 14:20:45 and 14:35:45, then 14:20:45 is a forward timestamp, and 14:35:45 is a backward timestamp, which is illustrated by way of example for ease of understanding. That is, earlier than the benchmark timestamp is determined as a forward timestamp, and later than the benchmark timestamp is determined as a backward timestamp.
[0088] In this embodiment, the first weight is configured for the forward difference absolute value, preferably 0.4, and the second weight is configured for the backward difference absolute value, preferably 0.6. The weighted sum of the forward difference absolute value and the backward difference absolute value based on the first weight and the second weight obtains the volatility factor of the benchmark risk value.
[0089] In this embodiment, the above steps are repeated to extract and calculate the remaining risk values on the risk time sequence curve to obtain a volatility factor corresponding to each risk value.
[0090] The beneficial effects of the above technical solution are that the remaining risk values on the risk time sequence curve are extracted and calculated to obtain a volatility factor corresponding to each risk value. The volatility factor can represent the dispersion of each risk value relative to all risk values, and ensure the accuracy of subsequent evaluation.
[0091] S130: According to the volatility factor corresponding to each risk value, obtain the steady-state threat coefficient and the burst threat coefficient of the target information system, and weighted sum the steady-state threat coefficient and the burst threat coefficient to obtain the security event threat coefficient of the target information system;
[0092] In some embodiments of the present application, when obtaining the steady threat coefficient and the burst threat coefficient of the target information system according to the volatility factor corresponding to each risk value, the following steps are included:
[0093] A preset volatility factor is obtained, all volatility factors are classified according to the preset volatility factor, and a steady volatility factor and a burst volatility factor are obtained;
[0094] When the volatility factor is less than the preset volatility factor, the corresponding volatility factor is classified as a steady volatility factor;
[0095] When the volatility factor is greater than or equal to the preset volatility factor, the corresponding volatility factor is classified as a burst volatility factor;
[0096] The steady threat coefficient of the target information system is calculated according to all steady volatility factors;
[0097] The burst threat coefficient of the target information system is calculated according to all burst volatility factors.
[0098] In the embodiment, the preset volatility factor is preferably 6, and can also be adjusted according to actual conditions.
[0099] In some embodiments of the present application, when calculating the steady threat coefficient of the target information system according to all steady volatility factors, the following steps are included:
[0100] A combination number q is preset, and every q steady volatility factors are combined based on the combination number q to obtain a plurality of steady volatility factor groups;
[0101] The steady volatility factor sum value corresponding to each steady volatility factor group is calculated, and the maximum steady volatility factor sum value is selected from all steady volatility factor sum values;
[0102] The maximum steady volatility factor is selected from all steady volatility factors;
[0103] The ratio of the maximum steady volatility factor sum value to the maximum steady volatility factor is determined as the steady threat coefficient of the target information system.
[0104] In the embodiment, q is preferably 2, that is, every 2 steady volatility factors are combined to obtain a plurality of steady volatility factor groups.
[0105] The beneficial effects of the above technical solution are: the present application determines the ratio of the maximum steady volatility factor sum value to the maximum steady volatility factor as the steady threat coefficient of the target information system, which ensures the calculation accuracy of the steady threat coefficient, and provides a directional calculation support for information security risk quantification evaluation through the steady threat coefficient.
[0106] In some embodiments of the present application, when calculating the burst threat coefficient of the target information system according to all burst fluctuation factors, the following steps are included:
[0107] Extract the same burst fluctuation factor from all burst fluctuation factors, and obtain a plurality of burst fluctuation factor sequences;
[0108] Count the first burst fluctuation factor sequence number of the burst fluctuation factor sequences;
[0109] Extract one burst fluctuation factor from all burst fluctuation factor sequences respectively, and calculate the first burst fluctuation factor sum value;
[0110] Obtain a preset burst fluctuation factor, eliminate all burst fluctuation factor sequences smaller than the preset burst fluctuation factor, and count the second burst fluctuation factor sequence number of the remaining burst fluctuation factor sequences;
[0111] Extract one burst fluctuation factor from the remaining burst fluctuation factor sequences respectively, and calculate the second burst fluctuation factor sum value;
[0112] Calculate the burst threat coefficient of the target information system according to the first burst fluctuation factor sequence number, the second burst fluctuation factor sequence number, the first burst fluctuation factor sum value and the second burst fluctuation factor sum value.
[0113] In this embodiment, the preset burst fluctuation factor refers to the variance corresponding to all burst fluctuation factors, which can represent the dispersion degree of all burst fluctuation factors.
[0114] In this embodiment, the burst threat coefficient of the target information system is calculated according to the following formula:
[0115]
[0116] Wherein, r is the burst threat coefficient of the target information system, c1 is the first burst fluctuation factor sequence number, c2 is the second burst fluctuation factor sequence number, v1 is the first burst fluctuation factor sum value, and v2 is the second burst fluctuation factor sum value.
[0117] The beneficial effects of the above technical solution are: the burst threat coefficient of the target information system is calculated according to the first burst fluctuation factor sequence number, the second burst fluctuation factor sequence number, the first burst fluctuation factor sum value and the second burst fluctuation factor sum value, which ensures the calculation accuracy of the burst threat coefficient. The burst threat coefficient can provide another direction of calculation support for information security risk quantification evaluation.
[0118] In some embodiments of the present application, a third weight, preferably 0.3, is configured for the steady-state threat coefficient, and a fourth weight, preferably 0.7, is configured for the burst threat coefficient, and the steady-state threat coefficient and the burst threat coefficient are weighted and summed according to the third weight and the fourth weight to obtain the security event threat coefficient of the target information system.
[0119] The beneficial effects of the above technical solution are: the steady-state threat coefficient and the burst threat coefficient are weighted and summed according to the third weight and the fourth weight to obtain the security event threat coefficient of the target information system, and the security event threat coefficient can represent the security event threat situation of the target information system corresponding to a type of security event, thereby further ensuring the accuracy of security risk quantitative evaluation.
[0120] S140: Extracting the security event threat coefficient corresponding to each security event sequence, analyzing all security event threat coefficients, and calculating the information security risk quantitative evaluation coefficient of the target information system based on the analysis result.
[0121] In the present embodiment, the security event threat coefficient corresponding to each security event sequence can be obtained according to the above steps.
[0122] In some embodiments of the present application, when all security event threat coefficients are analyzed and the information security risk quantitative evaluation coefficient of the target information system is calculated based on the analysis result, the following steps are included:
[0123] A first preset adjustment coefficient and a second preset adjustment coefficient are preset;
[0124] A characteristic security event threat coefficient of all security event threat coefficients is determined, wherein the characteristic security event threat coefficient is the mean value of all security event threat coefficients;
[0125] A first adjusted security event threat coefficient of the first preset adjustment coefficient and the characteristic security event threat coefficient is calculated, and a second adjusted security event threat coefficient of the second preset adjustment coefficient and the characteristic security event threat coefficient is calculated;
[0126] All security event threat coefficients are sorted in ascending order to determine a minimum security event threat coefficient and a maximum security event threat coefficient;
[0127] A first coefficient identifier is generated for the security event threat coefficient between the minimum security event threat coefficient and the first adjusted security event threat coefficient;
[0128] A second coefficient identifier is generated for the security event threat coefficient between the first adjusted security event threat coefficient and the second adjusted security event threat coefficient;
[0129] a third coefficient identifier is generated between the second adjusted security event threat coefficient and the maximum security event threat coefficient;
[0130] The information security risk quantitative evaluation coefficient of the target information system is calculated based on the first coefficient identifier, the second coefficient identifier and the third coefficient identifier.
[0131] In the embodiment, the first preset adjustment coefficient is preferably 0.95, and the second preset adjustment coefficient is preferably 1.05.
[0132] In the embodiment, the first coefficient identifier does not include the first adjusted security event threat coefficient, but includes a security event threat coefficient equal to the first adjusted security event threat coefficient. The second coefficient identifier does not include the first adjusted security event threat coefficient and the second adjusted security event threat coefficient, and does not include a security event threat coefficient equal to the first adjusted security event threat coefficient and the second adjusted security event threat coefficient. The third coefficient identifier does not include the second adjusted security event threat coefficient, but includes a security event threat coefficient equal to the second adjusted security event threat coefficient.
[0133] The above technical solution has the beneficial effects that: the information security risk quantitative evaluation coefficient of the target information system is calculated based on the first coefficient identifier, the second coefficient identifier and the third coefficient identifier, the accuracy and comprehensiveness of the information security risk quantitative evaluation are ensured, and the overall security risk status of the system is truly reflected.
[0134] In some embodiments of the present application, when calculating the information security risk quantitative evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier and the third coefficient identifier, the following is included:
[0135] The information security risk quantitative evaluation coefficient of the target information system is calculated according to the following formula:
[0136] ;
[0137] Wherein s is the information security risk quantitative evaluation coefficient of the target information system, n is the number of security event threat coefficients, k i is the i-th security event threat coefficient, t1 is the first adjusted security event threat coefficient, t2 is the second adjusted security event threat coefficient, y1 is the number of security event threat coefficients corresponding to the first coefficient identifier, y2 is the number of security event threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security event threat coefficients corresponding to the third coefficient identifier.
[0138] In order to further illustrate the technical idea of the present application, the technical solution of the present application will be described in conjunction with specific application scenarios.
[0139] Correspondingly, asFigure 2 As shown, the present application also provides an information security risk quantitative evaluation system, comprising:
[0140] a curve generation module, configured to determine a target information system to be evaluated, acquire a plurality of security event sequences of the target information system, and generate a risk time sequence curve based on time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of risk values of the security event sequences changing with time;
[0141] a data analysis module, configured to analyze fluctuation characteristics of each risk value of the risk time sequence curve, and determine a fluctuation factor of each risk value;
[0142] a weighted summation module, configured to obtain a steady threat coefficient and a burst threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform weighted summation on the steady threat coefficient and the burst threat coefficient to obtain a security event threat coefficient of the target information system;
[0143] a risk evaluation module, configured to extract a security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate an information security risk quantitative evaluation coefficient of the target information system based on an analysis result.
[0144] In some embodiments of the present application, the system further comprises:
[0145] a data processing module, configured to traverse and preprocess risk values in each security event sequence, wherein the preprocessing comprises deleting duplicate data and deleting erroneous data;
[0146] generate a risk time sequence curve based on the preprocessed risk values and corresponding time stamps.
[0147] In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0148] Although the present application has been described with reference to the embodiments above in the foregoing description, it is to be understood that various modifications will be apparent to those skilled in the art without departing from the scope of the present application, and that the components thereof can be substituted with equivalents. In particular, each feature disclosed in the described embodiments of the present application can be used in any combination with each other feature disclosed in the described embodiments, unless structural conflicts arise between the features. It is not necessary to describe all combinations of features in the present specification, which is merely for the purpose of omitting the description and saving resources.
[0149] Those skilled in the art can understand that the above are only preferred embodiments of the present application, and are not used to limit the present application, although the present application is described in detail with reference to the foregoing embodiments, and those skilled in the art can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some technical features. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for quantitatively evaluating information security risks, characterized by, The method comprises the following steps: determining a target information system to be risk evaluated, obtaining a plurality of security event sequences of the target information system, and generating a risk time sequence curve based on the time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of the risk values of the security event sequences changing with time; performing fluctuation characteristic analysis on each risk value of the risk time sequence curve to determine a fluctuation factor of each risk value; obtaining a steady threat coefficient and a sudden threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, performing weighted summation on the steady threat coefficient and the sudden threat coefficient to obtain a security event threat coefficient of the target information system; extracting the security event threat coefficient corresponding to each security event sequence, analyzing all the security event threat coefficients, and calculating an information security risk quantitative evaluation coefficient of the target information system based on the analysis result; when analyzing all the security event threat coefficients and calculating the information security risk quantitative evaluation coefficient of the target information system based on the analysis result, the method comprises the following steps: pre-setting a first preset adjustment coefficient and a second preset adjustment coefficient; determining a characteristic security event threat coefficient of all the security event threat coefficients, wherein the characteristic security event threat coefficient is the mean value of all the security event threat coefficients; calculating a first adjusted security event threat coefficient of the first preset adjustment coefficient and the characteristic security event threat coefficient, and calculating a second adjusted security event threat coefficient of the second preset adjustment coefficient and the characteristic security event threat coefficient; sorting all the security event threat coefficients in ascending order to determine a minimum security event threat coefficient and a maximum security event threat coefficient; generating a first coefficient identifier for the security event threat coefficients between the minimum security event threat coefficient and the first adjusted security event threat coefficient; generating a second coefficient identifier for the security event threat coefficients between the first adjusted security event threat coefficient and the second adjusted security event threat coefficient; generating a third coefficient identifier for the security event threat coefficients between the second adjusted security event threat coefficient and the maximum security event threat coefficient; calculating the information security risk quantitative evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier and the third coefficient identifier. 2.The information security risk quantitative evaluation method according to claim 1, characterized in that, Before generating the risk time sequence curve based on the time stamps corresponding to the security event sequences, the method further comprises the following steps: traversing and preprocessing the risk values in each security event sequence, wherein the preprocessing comprises deleting duplicate data and deleting error data; generating the risk time sequence curve based on the preprocessed risk values and the corresponding time stamps. 3.The information security risk quantitative evaluation method according to claim 1, characterized in that, When performing fluctuation characteristic analysis on each risk value of the risk time sequence curve to determine a fluctuation factor of each risk value, the method comprises the following steps: randomly determining a risk value on the risk time sequence curve as a reference risk value; determining a reference time stamp corresponding to the reference risk value, and determining a forward time stamp and a backward time stamp corresponding to the reference time stamp; Calculate the forward risk value mean of all forward time stamp corresponding risk values, and calculate the backward risk value mean of all backward time stamp corresponding risk values; Determine the forward difference absolute value of the reference risk value and the forward risk value mean, and determine the backward difference absolute value of the reference risk value and the backward risk value mean; Weighted sum of the forward difference absolute value and the backward difference absolute value to obtain the volatility factor of the reference risk value; Extract and calculate the remaining risk values on the risk time series curve to obtain the volatility factor corresponding to each risk value. 4.The information security risk quantitative evaluation method according to claim 1, characterized in that, When obtaining the steady state threat coefficient and the burst threat coefficient of the target information system according to the volatility factor corresponding to each risk value, it includes: Obtain a preset volatility factor, classify all volatility factors according to the preset volatility factor, and obtain steady state volatility factors and burst volatility factors; When the volatility factor is less than the preset volatility factor, the corresponding volatility factor is classified as a steady state volatility factor; When the volatility factor is greater than or equal to the preset volatility factor, the corresponding volatility factor is classified as a burst volatility factor; Calculate the steady state threat coefficient of the target information system according to all steady state volatility factors; Calculate the burst threat coefficient of the target information system according to all burst volatility factors.
5. The information security risk quantification assessment method of claim 4, wherein, When calculating the steady state threat coefficient of the target information system according to all steady state volatility factors, it includes: Pre-set the number of combinations q, combine every q steady state volatility factors based on the number of combinations q to obtain multiple steady state volatility factor groups; Calculate the steady state volatility factor sum value corresponding to each steady state volatility factor group, and select the maximum steady state volatility factor sum value from all steady state volatility factor sum values; Select the maximum steady state volatility factor from all steady state volatility factors; Determine the ratio of the maximum steady state volatility factor sum value to the maximum steady state volatility factor as the steady state threat coefficient of the target information system.
6. The information security risk quantification assessment method of claim 4, wherein, When calculating the burst threat coefficient of the target information system according to all burst volatility factors, it includes: Extract the same burst volatility factor from all burst volatility factors, and obtain multiple burst volatility factor sequences; Statistical first burst volatility factor sequence number of burst volatility factor sequence; Extract one burst volatility factor from all burst volatility factor sequences respectively, and calculate the first burst volatility factor sum value; Obtain a preset burst volatility factor, eliminate all burst volatility factor sequences less than the preset burst volatility factor, and count the second burst volatility factor sequence number of the remaining burst volatility factor sequences; Extract one burst volatility factor from the remaining burst volatility factor sequences respectively, and calculate the second burst volatility factor sum value; Calculate the burst threat coefficient of the target information system according to the first burst volatility factor sequence number, the second burst volatility factor sequence number, the first burst volatility factor sum value and the second burst volatility factor sum value.
7. The information security risk quantification assessment method of claim 1, wherein, When calculating the information security risk quantitative evaluation coefficient of the target information system based on the first coefficient identifier, the second coefficient identifier and the third coefficient identifier, it includes: An information security risk quantitative evaluation coefficient of the target information system is calculated according to the following formula: ; Wherein, s is the information security risk quantitative evaluation coefficient of the target information system, n is the number of security event threat coefficients, k i is the i th security event threat coefficient, t1 is the first adjusted security event threat coefficient, t2 is the second adjusted security event threat coefficient, y1 is the number of security event threat coefficients corresponding to the first coefficient identifier, y2 is the number of security event threat coefficients corresponding to the second coefficient identifier, and y3 is the number of security event threat coefficients corresponding to the third coefficient identifier.
8. An information security risk quantification assessment system, applied to the information security risk quantification assessment method of any one of claims 1-7, characterized in that, Comprise: A curve generation module is configured to determine a target information system to be risk evaluated, acquire a plurality of security event sequences of the target information system, and generate a risk time sequence curve based on time stamps corresponding to the security event sequences, wherein the risk time sequence curve is a curve of risk values of the security event sequences changing with time; A data analysis module is configured to analyze fluctuation characteristics of each risk value of the risk time sequence curve, and determine a fluctuation factor of each risk value; A weighted summation module is configured to obtain a steady threat coefficient and a burst threat coefficient of the target information system according to the fluctuation factor corresponding to each risk value, and perform weighted summation on the steady threat coefficient and the burst threat coefficient to obtain a security event threat coefficient of the target information system; A risk evaluation module is configured to extract the security event threat coefficient corresponding to each security event sequence, analyze all the security event threat coefficients, and calculate an information security risk quantitative evaluation coefficient of the target information system based on an analysis result.
9. The information security risk quantification assessment system of claim 8, wherein, Further comprise: A data processing module is configured to traverse and preprocess risk values in each security event sequence, wherein the preprocessing comprises deleting duplicate data and deleting error data; The risk time sequence curve is generated based on the preprocessed risk values and corresponding time stamps.
Citation Information
Patent Citations
Multi-level information security risk assessment method and device for information system
CN116980200A
Cybersecurity risk analysis and mitigation
US11552974B1