Network security operation management method and system
By acquiring and analyzing multiple security operation data sets, identifying abnormal indicator values and executing management measures, the problem of insufficient network security operation efficiency caused by analyzing a single operation indicator dimension is solved, and comprehensive security operation monitoring and rapid response are achieved.
Patent Information
- Application Number
- CN202510569005.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-29
AI Technical Summary
The existing technology analyzes the network security operation process only through a single operation indicator dimension, resulting in the inability to improve the overall efficiency of network security operations.
Obtain multiple security operation data sets of the target network within the preset time period, and determine the indicator types and indicator values corresponding to various security operation data types through multi-dimensional analysis. Identify abnormal indicator values based on the size relationship between the indicator values and the preset indicator threshold value, and implement corresponding management measures.
It realizes comprehensive dynamic monitoring of the security operation status, accurately identify and quickly respond to security threats, and significantly improves the overall efficiency of network security operations.
Smart Images

Figure CN120389891A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular, to a network security operation management method and system. Background Art
[0002] Currently, the mainstream security operation visualization technology is mainly used for data display on the situation awareness platform. Among them, the platform processes data through methods such as security data collection, data preprocessing, situation analysis, and situation prediction, and then conducts situation display. That is to say, this technology generally has the ability to visually display and trend display single operation index data. Therefore, the analysis caliber is single and the audience is narrow, and it is impossible to comprehensively analyze operation indexes from different dimensions based on the experience accumulation of operation personnel to intelligently provide targeted operation optimization analysis suggestions.
[0003] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0004] The embodiments of this application provide a network security operation management method and system to at least solve the technical problem that the related technology only analyzes the network security operation process through a single operation index dimension, resulting in the inability to improve the overall efficiency of network security operation.
[0005] According to one aspect of the embodiments of this application, a network security operation management method is provided, including: obtaining a plurality of security operation data sets of a target network within a preset time period, where each security operation data set includes multiple types of security operation data under one management dimension; for each security operation data set, determining the index types corresponding to various types of security operation data in the security operation data set from a preset database, and determining the index values corresponding to each index type; determining the abnormal index values affecting the security operation of the target network based on the magnitude relationship between each index value and the corresponding preset index threshold, and executing corresponding management measures on the abnormal sources corresponding to the abnormal index values.
[0006] Optionally, obtaining a plurality of security operation data sets of a target network within a preset time period includes: obtaining the original logs of multiple data sources within the preset time period, where the data sources include at least one of the following: situation awareness platform, security tool management system, work order system, honeypot system; respectively parsing each original log to obtain a plurality of initial data sets, and respectively preprocessing each initial data set to obtain a plurality of security operation data sets, where the preprocessing includes at least one of the following: data cleaning, data standardization processing, data aggregation processing.
[0007] Optionally, the management dimension includes at least one of the following: intelligence management dimension, tool management dimension, work order management dimension, engineering management dimension, vulnerability management dimension, and security training management dimension, wherein the security operation data of the intelligence management dimension includes at least the following sub-type data: the amount of intelligence corresponding to different intelligence types, wherein the intelligence types include: internal intelligence generated by the network management system and external intelligence provided by a third party; the security operation data of the tool management dimension includes at least the following sub-type data: monitoring coverage data, tool operation status data, the number of tool detection rule alarms, tool alarm data, the number of security baseline compliances, and the number of covered security scenario types. The monitoring coverage data includes at least one of the following: the actual number of monitoring areas of the security operation tool, the number of client agents, the number of online client agents, the number of client agent updates, and the number of servers actually managed; the tool operation status data includes at least one of the following: memory usage, CPU utilization, and storage capacity utilization; the tool alarm data includes at least one of the following: the number of false alarm tickets, the number of noise tickets, and the number of risk tickets; the number of tool detection rule alarms is used to reflect the number of alarms for validating the security operation tool according to the pre-planned attack rules; the number of security baseline compliance includes at least one of the following: security operation tool The number of configuration baselines that meet the preset configuration baselines, the number of server access traffic that meets the preset host access baselines; the security operation data of the work order management dimension includes at least the following sub-types of data: the number of work order assessment errors in a unit time period, the assessment and processing time of work orders of various important levels, the number of work orders processed by various types of staff in a unit time period, the emergency response time corresponding to work orders of various important levels, the completion time and total occurrence time of emergency response of security incidents, among which the types of staff include: front-line staff and second-line staff; the security operation data of the engineering management dimension includes at least the following sub-types of data: standardized data, automated data, and standardized The data includes at least one of the following: the number of knowledge databases, the number of work orders whose work order operations include standardized manuals, and the number of emergency plan scenarios covered. The automation data includes at least: the number of bans executed by the automated ban mechanism within a unit time period, and the total ban duration of the automated ban mechanism within a unit time period; the security operation data in the vulnerability management dimension includes at least the following sub-types of data: the number of vulnerabilities fixed, the number of vulnerabilities rectified on time, and the number of vulnerability fixes postponed; the security operation data in the security training management dimension includes at least the following sub-types of data: the number of people who fell victim to phishing email drills, the number of people who passed the security training exam, the number of successful defenses in attack and defense drills, and the value output of the security team.
[0008] Optionally, the indicator types corresponding to various types of security operation data in the security operation data set are determined from a preset database, and the indicator values corresponding to each indicator type are determined, including: for the security operation data set corresponding to the intelligence management dimension, the first indicator type corresponding to various types of security operation data in the security operation data set is determined from the preset database, wherein the first indicator type is intelligence coverage; the intelligence coverage of each type of intelligence is determined based on the amount of intelligence of each type of intelligence and the total amount of intelligence of each type; for the security operation data set corresponding to the tool management dimension, the second indicator type corresponding to various types of security operation data in the security operation data set is determined from the preset database, wherein the second indicator type is The model includes at least one of the following: tool coverage rate, tool installation rate, tool online rate, security policy update rate, bastion management rate, tool availability rate, tool effectiveness test pass rate, alarm false alarm rate, alarm noise rate, risk alarm rate, security baseline compliance rate, and security scenario coverage rate; the tool coverage rate is determined based on the actual number of monitoring areas of the security operation tool and the total number of planned monitoring areas; the tool installation rate is determined based on the number of client agents and the number of servers in production on the configuration management database; the tool online rate is determined based on the number of online client agents and the total number of server-supervised client agents; the tool online rate is determined based on the number of client agent updates and the total number of server-supervised client agents. Determine the security policy update rate based on the number of servers actually managed and the number of servers planned to be managed; determine the bastion management rate based on the actual number of servers managed and the number of servers planned to be managed; determine the tool availability rate of each security operation tool based on the relationship between the tool operation status data of each security operation tool and the preset operation status threshold; determine the tool effectiveness detection pass rate of the security operation tool based on the number of tool detection rule alarms and the total number of attack expected detections; determine the alarm false alarm rate based on the number of false alarm tickets and the total number of tickets; determine the alarm noise rate based on the number of noise tickets and the total number of tickets; determine the risk alarm rate based on the number of risk tickets and the total number of tickets; determine the security baseline compliance rate based on the number of preset baseline compliance plans. Baseline compliance rate; determining the security scenario coverage rate based on the number of security scenario types covered and the total number of security scenario types that should be equipped for typical attacks; for the security operation data set corresponding to the work order management dimension, determining the third indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the third indicator type includes at least one of the following: judgment accuracy rate, on-time completion rate of judgment and processing corresponding to various levels of importance, work order processing rate of various staff members, on-time completion rate of emergency disposal corresponding to various levels of importance, and average response time of security incidents; determining the judgment accuracy rate based on the number of work order judgment errors in a unit time period and the total number of work orders in a unit time period;Determine the first average duration and first duration variance corresponding to each importance level based on the analysis and processing time of all work orders corresponding to each importance level, and determine the upper and lower limits of the corresponding analysis and processing time based on the first average duration and first duration variance corresponding to the importance level; determine the on-time completion rate of the analysis and processing corresponding to each importance level based on the analysis and processing time of each work order within each importance level and the upper and lower limits of the analysis and processing time corresponding to the importance level; determine the work order processing rate of each type of staff based on the number of work orders processed by each type of staff in a unit time period and the total number of work orders in a unit time period; determine the second average duration and second duration variance corresponding to each importance level based on the emergency response time of all work orders corresponding to each importance level, and ... emergency response time of each work order The corresponding second average duration and the variance of the second duration determine the corresponding upper and lower limits of the emergency response duration, and determine the on-time completion rate of the emergency response corresponding to each importance level based on the emergency response duration of each work order in each importance level and the upper and lower limits of the emergency response duration corresponding to the importance level; determine the average response time of the security incident based on the emergency response completion time and the total duration of the occurrence; for the security operation data set corresponding to the engineering management dimension, determine the fourth indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the fourth indicator type includes at least one of the following: standardized manual coverage rate, work order standardized execution rate, emergency plan scenario coverage rate, and automated ban duration; based on the number of knowledge databases and work orders The total number of pushed rules determines the coverage rate of the standardized manual; the work order standardization execution rate is determined based on the number of work orders that include the standardized manual and the total number of work orders; the emergency plan scenario coverage rate is determined based on the number of emergency plan scenarios covered and the number of emergency plan scenario coverage plans; the automated ban duration is determined based on the total ban duration and the number of bans; for the security operation data set corresponding to the vulnerability management dimension, the fifth indicator type corresponding to each type of security operation data in the security operation data set is determined from the preset database, wherein the fifth indicator type includes at least one of the following: vulnerability repair rate, vulnerability rectification rate on time, vulnerability repair extension rate; the vulnerability repair rate is determined based on the number of vulnerabilities repaired and the total number of vulnerabilities; the vulnerability repair rate is determined based on the number of vulnerabilities rectified on time and the total number of vulnerabilities Determine the vulnerability rectification rate on time; determine the vulnerability repair deferral rate based on the number of vulnerability repair deferrals and the total number of vulnerabilities; for the security operation data set corresponding to the security training management dimension, determine the sixth indicator type corresponding to each type of security operation data in the security operation data set from a preset database, wherein the sixth indicator type includes at least one of the following: phishing email drill hit rate, security training exam pass rate, attack and defense confrontation success rate, and security team effectiveness; determine the phishing email drill hit rate based on the number of people who were hit in the phishing email drill and the total number of people who participated in the drill; determine the security training exam pass rate based on the number of people who passed the security training exam and the total number of people who participated in the exam; determine the attack and defense confrontation success rate based on the number of successful defenses in the attack and defense drill and the number of successful attacks in the attack and defense drill;Determine the effectiveness of the security team based on the value output and investment costs of the security team.
[0009] Optionally, before determining the abnormal indicator values that affect the target network security operation based on the size relationship between each indicator value and the corresponding preset indicator threshold, the method also includes: obtaining preset indicator thresholds for indicator types corresponding to various types of security operation data determined by experts based on historical experience; or, determining the indicator values of each type of security operation data under preset control scenarios, and determining the preset indicator thresholds for the indicator types corresponding to each type of security operation data based on the average value and variance of the indicator values, wherein the control scenarios include at least: attack and defense drill scenarios, and normalized operation scenarios.
[0010] Optionally, after determining the indicator value corresponding to each indicator type, the method also includes: determining the first weight value of each management dimension and the second weight value of the indicator data corresponding to each type of security operation indicator data; determining the security operation score of the target network within a preset time period based on the first weight value, the second weight value and the indicator value corresponding to each indicator type.
[0011] Optionally, the method also includes: displaying multiple security operation data sets, the indicator values corresponding to each type of security operation data in each operation data set and the corresponding preset indicator thresholds through a visual interface, and displaying the processing results of the abnormal source after the management measures are executed through a visual interface.
[0012] According to another aspect of an embodiment of the present application, a network security operation management system is also provided, including: an acquisition module for acquiring multiple security operation data sets of a target network within a preset time period, wherein each security operation data set includes multiple categories of security operation data under a management dimension; a determination module for determining, for each security operation data set, from a preset database the indicator type corresponding to each category of security operation data in the security operation data set, and determining the indicator value corresponding to each indicator type; a management module for determining abnormal indicator values that affect the target network security operation based on the size relationship between each indicator value and the corresponding preset indicator threshold, and executing corresponding management measures on the abnormal source corresponding to the abnormal indicator value.
[0013] According to another aspect of an embodiment of the present application, a non-volatile storage medium is further provided, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-mentioned network security operation management method by running the computer program.
[0014] According to another aspect of an embodiment of the present application, a computer program product is further provided, which includes a stored computer program, wherein when the computer program is executed by a processor, the above-mentioned network security operation management method is implemented.
[0015] In an embodiment of the present application, by obtaining a plurality of security operation data sets of a target network within a preset time period, wherein each security operation data set includes multiple types of security operation data under one management dimension; for each security operation data set, determining, from a preset database, the index types corresponding to the types of security operation data in the security operation data set, and determining the index values corresponding to each index type; determining, based on the magnitude relationship between each index value and the corresponding preset index threshold, the abnormal index values affecting the security operation of the target network, and executing corresponding management measures on the abnormal sources corresponding to the abnormal index values. Thus, a comprehensive and dynamic monitoring of the security operation state is achieved, the purpose of accurately identifying and quickly responding to security threats is achieved, the overall efficiency of security operation is significantly improved, and further, the technical problem that only analyzing the network security operation process through a single operation index dimension in the related art leads to the inability to improve the overall efficiency of network security operation is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0017] Figure 1 is a schematic flowchart of an optional network security operation management method according to an embodiment of the present application;
[0018] Figure 2 is a schematic visualization interface diagram of an optional core operation index according to an embodiment of the present application;
[0019] Figure 3 is a schematic visualization interface diagram of an optional operation work order according to an embodiment of the present application;
[0020] Figure 4 is a schematic visualization interface diagram of an optional security risk according to an embodiment of the present application;
[0021] Figure 5 is a schematic structural diagram of an optional network security operation management system according to an embodiment of the present application;
[0022] Figure 6 is a schematic structural diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solution in the embodiments of this application in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the scope of protection of this application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0025] In addition, the relevant information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and after receiving the consent information feedback from the aforementioned users or institutions, the relevant information is obtained.
[0026] Embodiment 1
[0027] According to an embodiment of this application, a network security operation and management method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0028] Figure 1 is a flowchart showing a network security operation and management method provided according to an embodiment of this application. As Figure 1 shown, the method includes the following steps:
[0029] Step S102, obtain multiple security operation data sets of the target network within a preset time period.
[0030] In the technical solution provided in the above step S102, in order to comprehensively monitor and manage the security operation of the target network, the embodiment of the present application proposes to collect and integrate multiple security operation data sets of the target network during the entire life cycle of attack and defense (i.e., a preset time period). Among them, including but not limited to: traffic monitoring data, alarm logs, performance monitoring data, work order logs, vulnerability information, equipment status data, etc. These data sets cover multiple management dimensions such as intelligence management dimension, tool management dimension, work order management dimension, engineering management dimension, vulnerability management dimension, and security training management dimension. The security operation data set under each management dimension contains multiple categories of security operation data related to the management dimension, thereby ensuring that the security effectiveness of each link can be quantitatively evaluated, so as to provide basic data support for subsequent multi-dimensional visual analysis and strategy optimization.
[0031] As an optional implementation, in the technical solution provided in the above step S102, the method may include:
[0032] Step S1021 : obtaining original logs of each of the plurality of data sources within a preset time period.
[0033] In the technical solution provided in the above step S1021, the above data sources include but are not limited to: situational awareness platform (used to collect network-level monitoring and analysis data), security tool management system (used to provide the operating status and alarm information of various security tools), work order system (used to record event processing and response records during security operations), honeypot system (collects attack data against fake resources for identifying and analyzing attack patterns), etc. Different data sources have different ways of accessing the management system, including but not limited to: standardized Syslog protocol, efficient message queue Kafka, direct database connection extraction and API interface integration, etc., to ensure the comprehensiveness and timeliness of the logs. In addition, the above original logs include but are not limited to: asset data, security alarm data, tool performance monitoring data, work order logs, etc.
[0034] In step S1022 , each original log is parsed to obtain multiple initial data sets, and each initial data set is preprocessed to obtain multiple security operation data sets.
[0035] Among them, the above-mentioned preprocessing includes but is not limited to: data cleaning (removing noise and outliers in the data, such as invalid logs, duplicate records or entries with incorrect formats, to ensure the accuracy of subsequent analysis), data standardization processing (converting data from different sources into a unified format and unit, so that data from different systems can be compared and integrated with each other, facilitating subsequent analysis), data aggregation processing (merging massive alarm information data of similar forms from the same data source within a certain time window into multiple alarm information sets with relatively consistent internal features according to alarm similarity, rule merging, text segmentation, waveform similarity, etc.).
[0036] In the technical solution provided in step S1022 above, the management system can parse the raw log obtained in step S1021 above, extracting key security information from the log content, such as the alarm type, event time, source IP address, destination IP address, and event description, and converting this information into key-value pairs to facilitate subsequent data processing and analysis. For example, the alarm type can be parsed as "Alarm Type: DDoS Attack" and the event time can be parsed as "Event Time: 2023-04-01 12:30:00."
[0037] After log parsing, the system can merge the parsed data from multiple data sources to form a unified data set to cover all relevant security operations information (i.e., multiple initial data sets). During the merging process, the system will perform deduplication operations to remove duplicate records to ensure the accuracy and consistency of the data set and avoid data conflicts or statistical errors in subsequent analysis. In addition, in order to provide a higher-level data analysis perspective, the management system can also aggregate the merged data. This includes but is not limited to: counting the number of events within a specific time period, such as the total number of alarms received in the last hour; or aggregating similar events from different sources, such as aggregating all DDoS attack alarms to obtain the overall trend of DDoS attacks. Therefore, aggregation processing helps to understand and evaluate the security operations status from a macro level, identify potential security threats or trends, and thus provide decision makers with more comprehensive and in-depth analysis results.
[0038] Therefore, after a series of processing steps in step S1022, the management system can obtain multiple security operation data sets with high data quality. The security operation data included in the security operation data sets corresponding to different management dimensions are as follows:
[0039] (1) Security operation data in the intelligence management dimension includes at least the following sub-types: the number of intelligence corresponding to different intelligence types. Among them, intelligence types include: internal intelligence generated by the network management system (also known as "self-generated intelligence") and external intelligence provided by a third party.
[0040] Among them, internal intelligence refers to security incident information collected through various security tools and systems (such as firewalls, intrusion detection systems, security information and event management systems (SIEM), host intrusion detection systems (HIDS), etc.); while external intelligence can be divided into commercial intelligence, human resources intelligence, group intelligence, etc. Commercial intelligence refers to information obtained by purchasing or subscribing to third-party security intelligence services (such as threat intelligence and vulnerability intelligence services), and human resources intelligence refers to information obtained through industry exchanges, network security communities, and sharing by security experts.
[0041] (2) The security operation data of the tool management dimension is designed from the aspects of equipment monitoring scope, availability, effectiveness, alarm management, access baseline, security scenarios, etc. Therefore, the security operation data of the tool management dimension includes at least the following sub-types of data: monitoring coverage data, tool operation status data, number of tool detection rule alarms, tool alarm data, number of security baseline compliance, and number of covered security scenario types. Among them:
[0042] The aforementioned monitoring coverage data is obtained by examining the monitoring scope of various devices to determine if there are any monitoring blind spots. Therefore, it includes at least one of the following: the actual number of monitoring areas of the security operation tool, the number of client agents, the number of online client agents, the number of updated client agents, and the number of servers actually managed (referring to the number of servers that have been successfully included in the monitoring and management scope of the bastion host. Access and operation behaviors of these servers, such as logins, file transfers, and command execution, will be recorded and audited by the bastion host to ensure compliance with pre-set security policies and compliance requirements). The client agent refers to security software or monitoring tools running on terminal devices (such as servers, personal computers, mobile devices, etc.) to collect various security-related data on the terminal (such as system logs, network traffic, running process information, etc.).
[0043] The aforementioned tool operation status data examines the normal operation of the security platform and security operations tools through multiple monitoring dimensions. Therefore, it includes at least one of the following: memory usage, CPU utilization, and storage capacity utilization.
[0044] The number of tool detection rule alarms mentioned above refers to the number of alarms identified and issued during actual operation by using planned attacks (such as white box attacks, scans, and drills) to verify the effectiveness of relevant security operation tools, in order to examine the detection rate of security operation tools.
[0045] The tool's alert data is used to assess the quality of security device alerts, reducing noise, false positives, and invalid alerts from non-compliant development, thereby improving the processing and analysis efficiency of relevant personnel. Therefore, it includes at least one of the following: the number of false positive tickets (i.e., the number of tickets that incorrectly identify non-actual threats as threats, generating unnecessary alerts); the number of noise tickets (i.e., the number of tickets that generate alerts due to normal network behavior or known, harmless events); and the number of risk tickets (i.e., the number of tickets that are confirmed to be true risk alerts).
[0046] The number of tool detection rule alarms reflects the number of alarms generated when validating security operation tools based on pre-planned attack rules.
[0047] The aforementioned security baseline compliance count includes at least one of the following: the number of security operations tools that conform to the preset configuration baseline, or the number of server access traffic that conforms to the preset host access baseline. The configuration baseline primarily examines whether security operations tools and software adhere to regulatory requirements, such as operating system settings, application security settings, and network device configuration. The host access baseline primarily focuses on server access traffic. For example, if the security baseline requires all servers to have firewalls enabled, the security baseline compliance count is the number of servers that actually have firewalls enabled.
[0048] The number of security scenarios covered above refers to the total number of security analysis scenarios that the security operations team has established and can effectively respond to. These scenarios are usually based on past experience, current threat intelligence, and predictions of the types of attacks that may be encountered in the future.
[0049] (3) The security operation data of the work order management dimension mainly revolves around the work order system's assessment and analysis phase and the emergency response phase. Therefore, the security operation data of the work order management dimension includes at least the following sub-types of data: the number of work order assessment errors within a unit time period, the assessment and processing time of work orders of various importance levels (including assessment acceptance time and assessment operation time), the number of work orders handled by various types of staff within a unit time period, the emergency response time corresponding to work orders of various importance levels (including emergency response acceptance time and emergency response operation time), the emergency response completion time and the total duration of security incidents. Among them, the importance level of the above work orders can be classified according to the actual application scenario, such as the following four categories: fatal level, important level, general level, and reminder level. The types of the above staff can be divided according to the staff's responsibilities and professional skills in the security operation or IT support process, such as the following: first-line staff, second-line staff, and third-line staff.
[0050] (4) Safety operation data from the engineering management dimension is mainly to identify operational problems in a timely manner through quantitative analysis of the pain points and difficulties of safety management, so as to improve operational efficiency. Therefore, safety operation data from the engineering management dimension includes at least the following sub-types of data: standardized data and automated data, among which:
[0051] The above-mentioned standardized data is mainly used to evaluate whether various security operations have standardized manuals (i.e., standard operating procedure documents that the security operations team should follow when handling various security incident work orders). This is the basic guarantee for the quality of security operations. Therefore, standardized data includes but is not limited to: the number of knowledge databases (referring to the number of standardized manuals or knowledge items that currently exist and can be referenced by the security team), the number of work orders whose work order operations include standardized manuals (referring to the number of work orders handled by the security operations team whose operating steps and methods are in line with those specified in the standardized manual), the number of emergency plan scenarios covered (i.e., the number of security threat scenarios actually covered by existing emergency plans), etc.
[0052] This automated data primarily reflects the automated or manual blocking of detected threats (such as malicious IP addresses and abnormal behavior) during network security operations. Therefore, automated data includes at least the number of automated blocking operations per unit time period and the total duration of automated blocking operations per unit time period.
[0053] (5) The security operation data of the vulnerability management dimension includes at least the following sub-types of data: the number of vulnerabilities repaired, the number of vulnerabilities rectified on time, and the number of vulnerabilities repaired after a delay. The number of vulnerabilities repaired refers to the number of vulnerabilities that have been successfully repaired through various means (such as updating software versions, applying security patches, changing configurations, repairing codes, etc.); the number of vulnerabilities rectified on time refers to the number of vulnerabilities that have been successfully repaired within the specified time based on the preset rectification plan or policy; the number of vulnerabilities repaired after a delay refers to the number of vulnerabilities that have been identified and planned to be repaired but have not been repaired on time.
[0054] (6) Security operation data in the security training management dimension includes at least the following sub-types of data: the number of people who were caught in phishing email drills, the number of people who passed the security training exam, the number of successful defenses in attack and defense drills, and the value output of the security team.
[0055] The number of successful defenses in the aforementioned attack and defense drills refers to the number of attacks successfully prevented, detected, and effectively responded to by the security defense system or team. This includes, but is not limited to, various network attacks intercepted by tools such as firewalls, intrusion detection systems (IDS), and security information and event management systems (SIEM), such as DDoS attacks, zero-day vulnerability exploits, and malware penetration.
[0056] In addition, the value output of the security team refers to the specific value provided by the security team through its work, such as the number of security incidents successfully prevented, the amount of potential losses reduced, the improved security compliance level, the improved security operation process, etc. The value output can be quantified as the economic losses avoided, the improved security indicators, the reduced security incident response time, the enhanced security protection ability, etc.
[0057] Step S104: For each security operation dataset, determine the metric types corresponding to various security operation data types in the preset database, and determine the metric values corresponding to each metric type.
[0058] In the technical solution provided in the above step S104, various metric types in the security operation field are stored in the preset database, and these metric types are closely related to multiple types of security operation data included in the security operation dataset. When the management system receives a security operation dataset, it analyzes the attributes and data types of various security operation data in the dataset. Subsequently, the system queries the preset database to find the metric types that match these data types. Further, the system determines the metric values corresponding to each metric type.
[0059] As an alternative implementation, in the technical solution provided in the above step S104, the method may include:
[0060] (1) For the intelligence management dimension.
[0061] First, the system can determine the first metric type corresponding to various security operation data types in the security operation dataset from the preset database, where the first metric type is the intelligence coverage rate;
[0062] Next, the system can determine the intelligence coverage rate of each type of intelligence based on the number of each type of intelligence and the total number of all types of intelligence. Specifically, the expression for the intelligence coverage rate of each type of intelligence can be written as:
[0063]
[0064] (2) For the tool management dimension.
[0065] First, the system can determine the second metric type corresponding to various security operation data types in the security operation dataset from the preset database, where the second metric type includes at least one of the following: tool coverage rate, tool installation rate, tool online rate, security policy update rate, bastion management rate, tool availability rate, tool effectiveness detection passing rate, alarm false positive rate, alarm noise rate, risk alarm rate, security baseline compliance rate, defined security scenario coverage rate.
[0066] Next, the system can determine the metric values corresponding to each second metric type in the following manner:
[0067] Determine the tool coverage rate based on the actual number of monitored areas of the security operation tool and the total planned number of monitored areas. Among them, a low coverage rate may mean that there are unmonitored parts in the network. These areas may become security vulnerabilities or targets for attackers, increasing the risks faced by the network. Therefore, the coverage rate indicator is a key indicator for evaluating whether the monitoring measures in network security operations are sufficient and whether the strategies are effectively implemented. Specifically, the expression of the tool coverage rate can be written as:
[0068]
[0069] Determine the tool installation rate based on the number of client Agents and the number of put-into-production servers in the Configuration Management Database. Among them, this indicator can be understood as the ratio of the number of servers with installed and active client Agents to the total number of put-into-production servers recorded in the Configuration Management Database (CMDB). It can reflect what proportion of servers are being protected and monitored by the client Agent. Specifically, the expression of the tool installation rate can be written as:
[0070]
[0071] Determine the tool online rate based on the number of online client Agents and the total number of server-monitored client agents. Among them, this indicator rate can be understood as the ratio of the number of client Agents that can successfully establish communication with the server and report data at a specific time point to the total number of client Agents that the server theoretically manages or takes in. This indicator reflects the availability and health status of the client Agent. A high online rate means that most client Agents are running normally and can collect and report security data in a timely manner, which is crucial for network security situation awareness and response. Specifically, the expression of the tool online rate can be written as:
[0072]
[0073] Determine the security policy update rate based on the number of updated client Agents and the total number of server-monitored client agents. Among them, this indicator can be understood as the ratio of the actual number of security policy updates received and completed by the client Agent within the specified time period to the total number of policy updates sent by the server (such as the management platform of the security operation center) to all managed client Agents within the same time period. A high policy update rate indicates that the security policy update operation is well executed on the client side, which helps to improve the overall efficiency of security operations. Specifically, the expression of the above security policy update rate can be written as:
[0074]
[0075] Determine the bastion management rate based on the actual number of servers under management and the planned number of servers to be managed (referring to the total number of servers that should be included in the bastion host management according to the security policies and management requirements of the element sum). Among them, a high management rate means that more servers are effectively managed and monitored, and security risks are better controlled; while a low management rate may indicate the existence of high-risk servers that have not been included in management, and measures need to be taken to increase their management rate to ensure the overall security operation level. Specifically, the expression of the above security policy update rate can be written as:
[0076]
[0077] Determine the tool availability rate of each security operation tool based on the relationship between the tool operation status data of each security operation tool and the preset operation status threshold. Among them, the tool operation status data includes but is not limited to: memory usage rate, CPU utilization rate, storage capacity utilization rate, number of alarm logs, etc.; and the operation status thresholds corresponding to different tool operation status data can be: CPU usage rate does not exceed 80%, memory usage rate does not exceed 90%, storage capacity usage rate does not exceed 80%, and the number of alarm logs is not 0 within a preset time period (such as within 24 hours). Specifically, the expression of the above tool availability rate can be written as:
[0078]
[0079] For example, if there are 3 items of tool operation status data for security operation tool A, and only 1 item does not meet the operation status threshold, then the tool availability rate of this security operation tool A is 2 / 3 = 66.7%.
[0080] Determine the passing rate of the effectiveness detection of the security operation tool based on the number of alarm messages according to the tool detection rules and the total number of expected attacks to be detected (referring to the total number of attacks or abnormal behaviors that the security device should theoretically be able to detect in the set test or drill scenario). Among them, this indicator can reflect the degree of coincidence between the actual detection ability of the security operation tool and the theoretical expectation. A high detection rate means that the device can effectively identify most of the expected attacks, while a lower detection rate may indicate that the detection rules of the device are not accurate or comprehensive enough and need to be further optimized. Specifically, the expression of the above passing rate of the effectiveness detection of the tool can be written as:
[0081]
[0082] The false alarm rate is determined based on the number of false alarm tickets and the total number of tickets. This metric measures the proportion of tickets generated that are confirmed as false alarms by security operations personnel. Therefore, a high false alarm rate means that the system makes too many errors when identifying threats, which may cause security operations personnel to waste time dealing with false alarms and reduce overall response efficiency. The expression for the false alarm rate can be written as:
[0083]
[0084] The alarm noise rate is determined based on the number of noisy tickets and the total number of tickets. This metric reflects the system's oversensitivity when processing normal network activity. A high noise rate means the system needs more filtering and adjustments to reduce disruption to personnel and increase the visibility of real threat alerts. Specifically, the expression for the alarm noise rate can be written as:
[0085]
[0086] The risk alert rate is determined based on the number of risk tickets and the total number of tickets. This metric measures the proportion of all tickets that are confirmed to be true risk alerts. True risk alerts are security incidents that pose a genuine threat to the network or system and require urgent attention and resolution. This metric helps assess the security system's effectiveness in identifying and reporting true security threats. A low risk alert rate may indicate a system blind spot. Specifically, the above expression for the risk alert rate can be written as:
[0087]
[0088] The security baseline compliance rate is determined based on the number of security baseline compliances and the number of baseline compliance plans. This metric reflects the percentage of configurations or behaviors that actually meet the standard within the pre-set plan or standard. By calculating the baseline compliance rate, security operations personnel can intuitively understand the compliance rate of security configurations or system behaviors, allowing them to promptly adjust security policies, reduce security risks, and improve the robustness and effectiveness of the entire security operations system. Specifically, the security baseline compliance rate can be expressed as:
[0089]
[0090] Security scenario coverage is determined based on the number of security scenarios covered and the total number of security scenarios that should be designed and covered for typical attacks (i.e., the total number of security analysis scenarios that should be designed and covered for a complete security protection system, based on industry standards, security expert recommendations, and analysis of the current threat landscape). This metric aims to assess the comprehensiveness of the security operations system's response and protection capabilities against known and potential security threats. Specifically, it measures the degree of coverage of various security analysis scenarios designed and implemented in security operations (e.g., detection of specific types of attacks, identification of abnormal traffic, monitoring of internal penetration behavior, etc.) across the entire range of typical attack patterns and scenarios that should be targeted.
[0091] The expression for the above security scenario coverage can be written as:
[0092]
[0093] (3) Regarding the work order management dimension.
[0094] First, the system can determine the third indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the third indicator type includes at least one of the following: the accuracy rate of analysis and judgment, the on-time completion rate of analysis and judgment processing corresponding to various levels of importance, the work order processing rate of various types of staff, the on-time completion rate of emergency disposal corresponding to various levels of importance, and the average response time of security incidents.
[0095] Next, the system can determine the indicator value corresponding to each third indicator type in the following manner:
[0096] The accuracy of the judgment is determined based on the number of work order judgment errors and the total number of work orders in the unit time period. Among them, the total number of work orders in the unit time period refers to the total number of all security work orders received by the security operation team in a specific time period (such as one day, one week or one month); and the number of work order judgment errors in the unit time period refers to the number of work orders that were misjudged or misanalyzed by security operation personnel among these work orders, that is, the number of security incident work orders that security operation personnel failed to correctly identify or handle. Therefore, this indicator refers to the accuracy of the security operation team's judgment and analysis of security work orders within a certain period. Among them, the judgment accuracy rate should be as low as possible, which means that the number of work orders that are misjudged is small, and the security operation team has a strong ability to analyze and handle security incidents. If the judgment accuracy rate is too high, it means that the security operation team has more misjudgments or errors in the judgment and analysis, and needs to further analyze the causes of the errors, improve the judgment methods and processes, and enhance the team's overall judgment capabilities and operational level. Specifically, the expression of the above judgment accuracy rate can be written as:
[0097]
[0098] Based on the analysis and processing time of all work orders corresponding to each importance level (such as fatal, important, general, and reminder), determine the first average time (reflecting the time required for general work order processing) and the first time variance (measuring the degree of fluctuation in the work order processing time) corresponding to each importance level, and determine the corresponding upper and lower limits of the analysis and processing time based on the first average time and the first time variance corresponding to the importance level (for example, set the variance of the average plus or minus a certain multiple as the upper and lower limits); based on the analysis and processing time of each work order within each importance level and the upper and lower limits of the analysis and processing time corresponding to the importance level, determine the on-time completion rate of the analysis and processing corresponding to each importance level. Among them, this indicator can help the security operation team monitor and optimize the work order processing process, ensure a rapid response to security incidents of different severities, and improve overall operational efficiency. Specifically, the expression for the on-time completion rate of the analysis and processing corresponding to each importance level can be written as:
[0099]
[0100] The work order processing rate for each type of staff member is determined based on the number of work orders handled by each type of staff member within a specific time period and the total number of work orders within that time period. This metric refers to the ratio of the number of security work orders successfully handled by each type of staff member to the total number of work orders received within a specific time period. By analyzing the work order analysis capabilities of different types of staff members, we can improve the knowledge base or strengthen skills training to enhance personnel capabilities. Specifically, the expression for the work order processing rate for each type of staff member can be written as:
[0101]
[0102] Based on the emergency response time of all work orders corresponding to each importance level (such as fatal, important, general, and reminder), the second average duration and the variance of the second duration corresponding to each importance level are determined. Furthermore, based on the second average duration and the variance of the second duration corresponding to the importance level, the corresponding upper and lower limits of the emergency response time are determined (for example, the variance of the average plus or minus a certain multiple is set as the upper and lower limits). Based on the emergency response time of each work order within each importance level and the upper and lower limits of the emergency response time corresponding to the importance level, the on-time completion rate of emergency response corresponding to each importance level is determined. This indicator quantitatively analyzes the emergency response efficiency of security incidents at different importance levels, identifies work orders with slow processing speeds or large fluctuations, and thus optimizes the emergency response process and improves overall operational efficiency.
[0103] Specifically, the expression for the on-time completion rate of emergency response corresponding to each importance level can be written as:
[0104]
[0105] The average response time for security incidents is determined based on the emergency response completion time (the time from first noticing a security incident to completing the initial response or taking initial action) and the total duration of the incident (the total time from the time the security incident is detected or occurs to the time the incident is handled). This average response time is also known as the Mean Time to Repair (MTTR). It refers to the time it takes for staff to complete the initial response from the time the security team receives the incident. This metric reflects the staff's response efficiency. Specifically, the average response time for security incidents can be expressed as:
[0106] Average response time for security incidents = time to complete emergency response – total time of incident
[0107] (3) Engineering management dimension.
[0108] First, the system can determine the fourth indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the fourth indicator type includes at least one of the following: standardized manual coverage, work order standardized execution rate, emergency plan scenario coverage, and automated ban duration.
[0109] Next, the system may determine the indicator value corresponding to each fourth indicator type in the following manner:
[0110] The standardized manual coverage rate is determined based on the number of knowledge databases and the total number of work order push rules. Among them, this indicator is used to measure the degree of perfection and application scope of standardized operation manuals or knowledge bases in security operations. Specifically, it reflects the proportion of the number of existing standardized operation instructions or solutions for various situations and work order processing processes that may arise in security operations to the total number of all work order push rules. Therefore, the higher the standardized manual coverage rate, the more detailed and standardized operation instructions there are for various work orders and events in security operations. The more standardized operations the security team can refer to when facing security incidents, the more streamlined the processing process will be, which will help improve the overall efficiency and effectiveness of security operations and reduce delays, errors or loopholes that may be caused by non-standard processing or lack of guidance. Specifically, the expression for the above standardized manual coverage rate can be written as:
[0111]
[0112] The work order standardization execution rate is determined based on the number of work orders whose operations include the standardized manual and the total number of work orders. This metric is an important indicator for measuring the efficiency and standardization of the security operations team's process execution. The higher this ratio, the more the security operations team is able to follow the standardized manual and perform standardized operations during the work order processing process, thereby ensuring that the response and handling of security incidents can meet unified quality standards and reduce risks and errors caused by individual differences or inconsistent processes. Specifically, the expression for the work order standardization execution rate can be written as:
[0113]
[0114] The emergency plan scenario coverage rate is determined based on the number of emergency plan scenarios covered and the number of emergency plan scenario coverage plans (i.e., the number of emergency plans that the security operations team should theoretically prepare based on a specific risk environment, based on security threat intelligence, historical security incidents, and industry best practices). A high emergency plan scenario coverage rate means that the team is fully prepared for various possible security threats and emergencies, enabling more effective response to emergencies and reducing losses. A lower coverage rate may indicate that some security scenarios have not been fully considered, and the emergency plan system needs to be further improved to ensure the comprehensiveness and effectiveness of security operations. Specifically, the expression for the emergency plan scenario coverage rate can be written as:
[0115]
[0116] The automated ban duration is determined based on the total ban duration (i.e., the total duration from the start of all ban operations to the effectiveness of the ban within the preset statistical period) and the number of bans (the total number of ban operations performed by the security operations team within the same statistical period). This indicator reflects the response speed and efficiency of the security team or automated system when performing ban operations. The shorter the average ban time, the more agile the security response is, and the more quickly it can block threats and protect network data assets. Therefore, this indicator is in units of time (such as seconds, minutes, or hours). Specifically, the expression for the above automated ban duration can be written as:
[0117]
[0118] (5) Vulnerability management dimension.
[0119] First, the system can determine the fifth indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the fifth indicator type includes at least one of the following: vulnerability repair rate, vulnerability rectification rate on time, and vulnerability repair extension rate.
[0120] Next, the system may determine the indicator value corresponding to each fifth indicator type in the following manner:
[0121] The vulnerability repair rate is determined based on the number of vulnerabilities fixed and the total number of vulnerabilities. This indicator reflects the responsiveness and repair speed when faced with security vulnerabilities. A high vulnerability repair rate means that security vulnerabilities can be effectively identified and handled, reducing the risk of attacks due to unrepaired vulnerabilities. A low vulnerability repair rate may indicate deficiencies in vulnerability management, such as limited detection capabilities, poor repair processes, insufficient resource allocation, and lack of team skills, all of which may increase the likelihood of security threats. Therefore, by continuously monitoring and optimizing the vulnerability repair rate, the security of its systems and networks can be ensured, potential security risks can be reduced, and the work efficiency and response speed of the security team can be improved. Specifically, the expression for the vulnerability repair rate can be written as:
[0122]
[0123] The vulnerability rectification rate is determined based on the number of vulnerabilities rectified on time and the total number of vulnerabilities. This indicator reflects the security team's response speed and efficiency in vulnerability repair, as well as whether it can promptly handle discovered vulnerabilities in accordance with established security policies and standards. A high vulnerability rectification rate indicates that vulnerability management is done well, and security vulnerabilities can be quickly identified and repaired, reducing potential security risks. If this ratio is low, it may mean that there are delays or bottlenecks in the vulnerability repair process, and it is necessary to further optimize the process, allocate more resources, or enhance the capabilities of the security team to improve the timeliness and efficiency of vulnerability rectification. Therefore, regular monitoring and analysis of the vulnerability rectification rate is crucial to continuously improve the security protection system and ensure that critical information assets are protected in a timely manner. Specifically, the expression for the vulnerability rectification rate can be written as:
[0124]
[0125] The vulnerability repair deferral rate is determined based on the number of vulnerability repair deferrals and the total number of vulnerabilities. Among them, this indicator reflects the ability and efficiency in vulnerability management. A high ratio means that there are more repair delays when facing vulnerabilities, which may increase the risk of security attacks. Therefore, this indicator is a key performance indicator (KPI) in security operations and risk management. It helps security teams and management identify bottlenecks and deficiencies in the vulnerability management process, guide resource allocation and process improvements, so as to reduce repair delays and improve the overall security protection level. Therefore, by continuously monitoring the vulnerability repair deferral rate, it is possible to promptly discover and solve the problem of delayed repairs, such as adjusting repair priorities, increasing repair resources, optimizing repair processes, improving security team skills, etc., to ensure that all identified vulnerabilities can be repaired in a timely and effective manner, reducing the impact of security threats. Specifically, the expression for the vulnerability repair deferral rate above can be written as:
[0126]
[0127] (6) Security training management dimension.
[0128] First, the system can determine the sixth indicator types corresponding to various types of security operation data in the security operation data set from a preset database. Among them, the sixth indicator types include at least one of the following: the hit rate in phishing email drills, the passing rate of security training exams, the participation rate in security training exams, the success rate of attack and defense confrontations, and the effectiveness of the security team.
[0129] Next, the system can determine the indicator values corresponding to each of the sixth indicator types in the following manner:
[0130] Determine the hit rate of phishing email drills based on the number of employees who were hit and the total number of participants in the drill. Among them, this indicator reflects the ability of employees within the security team to identify and resist phishing emails. Specifically, it reflects the proportion of employees who received simulated phishing emails during the security awareness drill or test of phishing emails and failed to recognize these emails as phishing attacks, thus "being hit", that is, clicking on malicious links or attachments in the emails or leaking sensitive information. A lower proportion of employees being hit in phishing email drills indicates that employees have stronger security awareness, can effectively identify and avoid the traps of phishing emails, and reduce potential security risks. Conversely, if the proportion is higher, it means that it is necessary to strengthen the network security training of employees, improve their ability to identify phishing emails, and their coping strategies when encountering suspicious emails. Specifically, the expression of the above-mentioned hit rate of phishing email drills can be written as:
[0131]
[0132] Determine the passing rate of security training exams based on the number of employees who passed the exam and the total number of exam participants. This indicator is one of the important indicators to measure the results of security training activities. It not only reflects the theoretical mastery of security knowledge by employees after receiving training, but also indirectly reflects the design quality of the security training plan, the appropriateness of the training content, and the effectiveness of the training methods. Therefore, the higher this ratio, the more effective the security training, the more solid the employees' mastery of security knowledge, and the higher the average level of security awareness and skills. Specifically, the expression of the above-mentioned passing rate of security training exams can be written as:
[0133]
[0134] Determine the success rate of offense and defense confrontation based on the number of successful defenses in the offense and defense drill and the number of successful attacks in the offense and defense drill (i.e., the number of attack events in which the attacker successfully breaks through the defense and causes a certain impact in the offense and defense drill). Among them, this indicator quantitatively measures the ability of the security defense system or security team to successfully resist attacks in actual combat drills or actual network attack scenarios. Therefore, a high success rate of offense and defense confrontation means that the security defense system or team can effectively prevent most attacks and protect the network from being invaded. On the contrary, if the success rate of offense and defense confrontation is low, it indicates that there are loopholes in the defense measures or the response mechanism is not efficient enough, and it is necessary to further analyze the reasons for the successful attacks, optimize the defense strategy and improve the response ability. Specifically, the expression of the above-mentioned success rate of offense and defense confrontation can be written as:
[0135]
[0136] Determine the effectiveness of the security team based on the value output of the security team and the input cost of the security team (i.e., the total cost invested in the information technology field of the security team, including IT infrastructure construction, IT application development, IT operation and maintenance services, etc.). Therefore, this indicator aims to evaluate whether the work results of the security team match its input and whether sufficient security value is brought. A high effectiveness value means that the security team provides a high level of security benefits relative to its cost investment, which indicates that the security investment is effectively utilized and the work efficiency and effect of the security team are good. Specifically, the expression of the above-mentioned effectiveness of the security team can be written as:
[0137]
[0138] In addition, the above-mentioned indicator values can also include an attack traceability indicator, which is used to evaluate the staff's ability to trace back the portrait, specifically including but not limited to: attack path, attack exploitation method, IP attribution, attacker identity, etc.
[0139] After determining the indicator values corresponding to various types of security operation data types in each security operation data set through the above, the management system can also convert the above complex and redundant indicator values into an intuitive numerical value through the following method, so as to facilitate non-professional personnel to understand the overall situation of security operation.
[0140] Specifically, determine the first weight value of each management dimension and the second weight value of the indicator data corresponding to each type of security operation indicator data; determine the (comprehensive) security operation score of the target network within a preset time period according to the first weight value, the second weight value, and the indicator values corresponding to each indicator type.
[0141] Among them, the above scoring values can be applied to security risk early warning to help the security team quickly identify changes in the security situation, timely discover weak links in security protection, take preventive measures, and avoid potential security threats from evolving into actual attack events; they can also be applied to decision-making and planning to help high-level decision-makers provide key decision-making basis. For example, by analyzing historical scoring trends, decision-makers can understand the long-term performance of security operations, identify the priorities of security investments, and formulate future security strategies, such as strengthening security training, introducing new technologies or services, etc.
[0142] Step S106: Determine the abnormal indicator values affecting the target network security operation according to the magnitude relationship between each indicator value and the corresponding preset indicator threshold, and execute corresponding management measures on the abnormal sources corresponding to the abnormal indicator values.
[0143] In the technical solution provided in the above step S106, the management system compares the indicator values corresponding to various security operation indicator data with the preset indicator thresholds of the corresponding types, and quickly identifies the abnormal indicator values that do not conform to the preset thresholds, that is, the indicator performances deviating from the normal range, which may be signals of security threats, operation errors or system failures. Once an abnormal indicator value is detected, the system will automatically or semi-automatically analyze the source of the abnormal problem, such as equipment failure, policy configuration error or malicious attack, etc. According to the preset rules or expert suggestions, corresponding management measures are automatically generated or recommended. These measures may include adjusting security policies, optimizing resource allocation, starting the emergency response process or fixing system vulnerabilities, etc.
[0144] It should be noted that the embodiment of the present application can also monitor the implementation situation and effects of the management measures in real time, verify the effectiveness of the management measures, and optimize the preset indicator thresholds, management measures, etc. according to the results, forming a continuously improving closed loop of security operation.
[0145] As an optional implementation manner, in the technical solution provided in the above step S106, the preset indicator thresholds corresponding to various indicator types can be determined in the following two ways, including:
[0146] Method 1: Obtain the preset indicator thresholds of the indicator types corresponding to various security operation data determined by expert personnel based on historical experience.
[0147] Method 2: Determine the indicator values of each type of security operation data under the preset comparison scenarios respectively, and determine the preset indicator thresholds of the indicator types corresponding to each type of security operation data according to the average value and variance of the indicator values, where the comparison scenarios include at least: attack and defense drill scenarios, normal operation scenarios.
[0148] Among them, the above-mentioned Method 1 relies on the judgment of experts and industry consensus, and is applicable to those indicators with clear definitions and strong predictability, which can ensure the rationality and effectiveness of the threshold; while Method 2 identifies the normal fluctuation range and abnormal conditions of the indicators by comparing the two control scenarios of the attack and defense drill scenario and the normal operation scenario. Therefore, Method 2 is applicable to indicators that need to dynamically adjust the threshold according to the actual operation situation, such as the response time of security incidents, the number of security baseline conformances, etc. It should be noted that in actual application scenarios, the above two methods can also be combined to improve the accuracy and robustness of threshold setting. For example, the initial threshold can be set based on expert experience first, and then fine-tuned and verified through statistical analysis of the control scenario data to form a more scientific and reasonable indicator threshold setting system.
[0149] To help security operation personnel quickly identify the current network security situation, multiple security operation data sets, the indicator values corresponding to various security operation data in each operation data set, and the corresponding preset indicator thresholds can be respectively displayed through a visual interface. Compared with pure text or data tables, the graphical interface can convey information faster, reduce the understanding time, and thus quickly judge whether the indicator deviates from the normal range and whether there are potential security threats.
[0150] Among them, the above-mentioned preset indicator threshold can be understood as an indicator baseline, which represents the expected performance of the indicator type corresponding to the security operation data under normal operation conditions. When the real-time indicator value significantly deviates from the indicator baseline, the visual interface can immediately display the abnormal fluctuation and trigger the early warning mechanism. This immediate visual feedback helps the security team respond in a timely manner, quickly locate the source of the problem, and take corresponding defensive measures.
[0151] For example, Figure 2 is a schematic diagram of a visual interface for an optional core operation indicator, such as Figure 2 shown. This visual interface displays the core operation indicators in the form of charts, such as tool availability rate, monitoring coverage rate, etc., to show the detailed data of the core operation indicators in detail, and at the same time integrates the automated analysis results to clearly present the rectification suggestions and optimization progress. Figure 3 is a schematic diagram of a visual interface for an optional operation work order, such as Figure 3 shown. This visual interface displays the work order indicators in the form of charts, such as the judgment accuracy rate, the on-time completion rate of judgment work orders, the on-time completion rate of emergency disposal work orders, the alarm governance rate, etc. Thus, the existing problems are identified through data analysis, and according to the obtained optimization suggestions, the response speed and efficiency of the on-duty personnel are continuously improved. Figure 4 is a schematic diagram of a visual interface for an optional security risk, such as Figure 4As shown in the figure. The visualization interface displays risk indicators in the form of charts, such as vulnerability repair rate, timely feedback rate of vulnerabilities, and timely rectification rate of vulnerabilities, etc., to comprehensively display the rectification status of vulnerabilities and the rectification trend, which is convenient for tracking dynamic changes.
[0152] In addition, the management system also displays the processing results of the abnormal source after the implementation of management measures through the visualization interface, so as to ensure that the security team can see the impact of management measures on the abnormal source in real time, greatly increasing the transparency of the entire security operation process.
[0153] Based on the solutions defined in the above steps S102 to S106, compared with the prior art, the network security operation management method provided in the embodiments of the present application has the following technical advantages:
[0154] (1) By collecting and analyzing security operation data under different management dimensions, the embodiments of the present application can evaluate the security status of the network from a more comprehensive perspective, while the prior art often only focuses on a single or a few dimensions and is difficult to provide a comprehensive security perspective.
[0155] (2) Based on historical data and control scenarios (such as attack and defense drills and normal operation), the embodiments of the present application dynamically calculate the preset index thresholds, which is more scientific than fixed thresholds, can more accurately reflect the dynamic changes of security operations, and reduce false alarms and missed reports.
[0156] (3) The embodiments of the present application support real-time monitoring and response, can immediately take measures to handle abnormalities, and at the same time, through the closed-loop management mechanism, continuously optimize the index thresholds and processing processes to ensure the continuous improvement of security operations.
[0157] (4) The embodiments of the present application provide differentiated views for different audiences, meet the analysis needs of different security roles, improve the efficiency and accuracy of information transmission, while the views of the prior art are often relatively single and cannot meet diverse needs.
[0158] (5) The embodiments of the present application display the index values and processing results through an intuitive visualization interface, thereby improving the transparency and communication efficiency of security operations.
[0159] Embodiment 2
[0160] According to the embodiments of the present application, there is also provided a network security operation management system for implementing the network security operation management method in Embodiment 1, as Figure 5 shown. The network security operation management system at least includes: an acquisition module 52, a determination module 54, and a management module 56, where:
[0161] An acquisition module 52 is configured to acquire multiple security operation data sets of a target network within a preset time period, wherein each security operation data set includes multiple types of security operation data under a management dimension;
[0162] a determination module 54 for determining, for each security operation data set, from a preset database, the indicator types corresponding to the various types of security operation data in the security operation data set, and determining the indicator value corresponding to each indicator type;
[0163] The management module 56 is used to determine the abnormal indicator value that affects the target network security operation based on the size relationship between each indicator value and the corresponding preset indicator threshold, and to execute corresponding management measures on the abnormal source corresponding to the abnormal indicator value.
[0164] It should be noted that each module in the network security operation management system in the embodiment of the present application corresponds one-to-one to each implementation step of the network security operation management method in Example 1. Since a detailed description has been given in Example 1, some details not reflected in this embodiment can be referred to Example 1 and will not be elaborated here.
[0165] Example 3
[0166] According to an embodiment of the present application, a computer program product is also provided, which includes a computer program, wherein when the computer program is executed by a processor, the network security operation management method in Example 1 is implemented.
[0167] According to an embodiment of the present application, a non-volatile storage medium is also provided, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the network security operation management method in Example 1 by running the computer program.
[0168] According to an embodiment of the present application, a processor is also provided, which is used to run a computer program, wherein the network security operation management method in Example 1 is executed when the computer program is running.
[0169] According to an embodiment of the present application, an electronic device is also provided, which includes: a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the network security operation management method in Example 1 through the computer program.
[0170] Optionally, when the computer program runs, it executes the following steps: obtaining a plurality of security operation data sets of the target network within a preset time period, where each security operation data set includes multiple types of security operation data under one management dimension; for each security operation data set, determining, from a preset database, the metric types corresponding to the types of security operation data in the security operation data set, and determining the metric values corresponding to each metric type; determining the abnormal metric values that affect the security operation of the target network based on the magnitude relationship between each metric value and the corresponding preset metric threshold, and executing corresponding management measures on the abnormal sources corresponding to the abnormal metric values.
[0171] As an alternative implementation, the above electronic device may exist in the form of a mobile terminal, a computer terminal, or a similar computing device. Figure 6 The hardware structure block diagram of an electronic device for implementing the network security operation management method is shown. As Figure 6 shown, the electronic device 60 may include one or more (shown as 602a, 602b,..., 602n in the figure) processors 602 (the processor 602 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 604 for storing data, and a transmission device 606 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 6 the structure shown is only schematic and does not limit the structure of the above electronic device. For example, the electronic device 60 may further include more or fewer components than Figure 6 shown, or have a different configuration from Figure 6 shown.
[0172] It should be noted that the above one or more processors 602 and / or other data processing circuits are generally referred to as "data processing circuits" in this article. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the electronic device 60. As involved in the embodiments of the present application, the data processing circuit is a processor control (such as the selection of a variable resistor terminal path connected to an interface).
[0173] The memory 604 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the network security operation management method in the embodiment of the present application. The processor 602 executes various functional applications and data processing by running the software programs and modules stored in the memory 604, that is, implementing the vulnerability detection method of the above-mentioned application. The memory 604 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 604 may further include a memory remotely located relative to the processor 602, and these remote memories may be connected to the electronic device 60 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0174] The transmission device 606 is used to receive or send data via a network. Specific examples of the aforementioned network may include a wireless network provided by the communications provider of the electronic device 60. In one embodiment, the transmission device 606 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 606 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0175] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the electronic device 60 .
[0176] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0177] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0178] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0179] The unit described as a separating component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0180] In addition, each functional unit in various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0181] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: USB flash drive, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk, or optical disc and other various media that can store program codes.
[0182] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and retouches can be made, and these improvements and retouches should also be regarded as the protection scope of the present application.
Claims
1. A network security operation and management method, characterized in that, Including: Obtain multiple security operation data sets of a target network within a preset time period. Each of the security operation data sets includes multiple types of security operation data under one management dimension; For each of the security operation data sets, determine the index types corresponding to the types of security operation data in the security operation data set from a preset database, and determine the index values corresponding to each of the index types; Determine the abnormal index values affecting the security operation of the target network based on the magnitude relationship between each of the index values and the corresponding preset index thresholds, and execute corresponding management measures on the abnormal sources corresponding to the abnormal index values.
2. The method according to claim 1, wherein Obtain multiple security operation data sets of a target network within a preset time period, including: Obtain the original logs of multiple data sources within a preset time period, where the data sources include at least one of the following: a situation awareness platform, a security tool management system, a work order system, and a honeypot system; Parse each of the original logs to obtain multiple initial data sets, and preprocess each of the initial data sets to obtain the multiple security operation data sets, where the preprocessing includes at least one of the following: data cleaning, data standardization processing, and data aggregation processing.
3. The method according to claim 1, wherein The management dimension includes at least one of the following: intelligence management dimension, tool management dimension, work order management dimension, engineering management dimension, vulnerability management dimension, and security training management dimension, where The security operation data of the intelligence management dimension at least includes the following subtype data: the number of intelligence corresponding to different intelligence types, where the intelligence types include: internal intelligence generated by a network management system and external intelligence provided by a third party; The security operation data of the tool management dimension at least includes the following subtype data: monitoring coverage data, tool running status data, the number of tool detection rule alarms, tool alarm data, the number of security baseline conformances, and the number of covered security scenario types. The monitoring coverage data includes at least one of the following: the number of actual monitoring areas of security operation tools, the number of client Agents, the number of online client Agents, the number of updated client Agents, and the number of actually managed servers. The tool running status data includes at least one of the following: memory usage rate, CPU utilization rate, and storage capacity utilization rate. The tool alarm data includes at least one of the following: the number of false alarm work orders, the number of noise work orders, and the number of risk work orders. The number of tool detection rule alarms is used to reflect the number of alarms for validating the effectiveness of security operation tools according to pre-planned attack rules. The number of security baseline conformances includes at least one of the following: the number of security operation tools that conform to a preset configuration baseline and the number of access traffic of servers that conform to a preset host access baseline; The security operation data of the work order management dimension includes at least the following sub-types: the number of work order assessment errors within a unit time period, the assessment and processing time of work orders of various importance levels, the number of work orders processed by various types of staff within a unit time period, the emergency response time corresponding to work orders of various importance levels, the completion time of emergency response to security incidents, and the total duration of occurrence. The types of staff include: front-line staff and second-line staff; The security operations data of the engineering management dimension includes at least the following sub-types: standardized data and automated data. The standardized data includes at least one of the following: the number of knowledge databases, the number of work orders whose operations include standardized manuals, and the number of emergency plan scenarios covered. The automated data includes at least the number of bans executed by the automated ban mechanism within a unit time period and the total ban duration executed by the automated ban mechanism within a unit time period. The security operation data of the vulnerability management dimension includes at least the following sub-types of data: number of vulnerabilities fixed, number of vulnerabilities rectified on time, and number of vulnerabilities fixed after expiration; The security operation data in the security training management dimension includes at least the following sub-type data: the number of people who fell victim to phishing email drills, the number of people who passed the security training exam, the number of successful defenses in attack and defense drills, and the value output of the security team.
4. The method according to claim 3, characterized in that, Determining indicator types corresponding to various types of security operation data in the security operation data set from a preset database, and determining indicator values corresponding to each indicator type, including: For the security operation data set corresponding to the intelligence management dimension, determining, from the preset database, a first indicator type corresponding to each type of security operation data in the security operation data set, wherein the first indicator type is intelligence coverage; determining the intelligence coverage rate of each type of intelligence based on the amount of intelligence of each type and the total amount of intelligence of each type; For the security operation data set corresponding to the tool management dimension, determine the second indicator types corresponding to various security operation data types in the security operation data set from the preset database, where the second indicator types include at least one of the following: tool coverage rate, tool installation rate, tool online rate, security policy update rate, bastion management rate, tool availability rate, tool effectiveness detection pass rate, alarm false positive rate, alarm noise rate, risk alarm rate, security baseline compliance rate, defined security scenario coverage rate; determine the tool coverage rate according to the actual number of monitored areas and the total number of planned monitored areas of the security operation tool; determine the tool installation rate according to the number of client Agents and the number of put-into-production servers in the configuration management database; determine the tool online rate according to the number of online client Agents and the total number of server supervision client agents; determine the security policy update rate according to the number of updated client Agents and the total number of server supervision client agents; determine the bastion management rate according to the actual number of managed servers and the planned number of managed servers; determine the tool availability rate of each security operation tool according to the relationship between the tool operation status data of each security operation tool and the preset operation status threshold; determine the tool effectiveness detection pass rate of the security operation tool according to the number of alarm tickets detected by the tool detection rule and the total number of expected attack detections; determine the alarm false positive rate according to the number of false positive work orders and the total number of work orders; determine the alarm noise rate according to the number of noise work orders and the total number of work orders; determine the risk alarm rate according to the number of risk work orders and the total number of work orders; determine the security baseline compliance rate according to the number of security baseline compliance and the preset baseline compliance plan number; determine the security scenario coverage rate according to the number of covered security scenario types and the total number of security scenario types that should be equipped for typical attacks; For the security operation data set corresponding to the work order management dimension, determine the third indicator types corresponding to various security operation data types in the security operation data set from the preset database, where the third indicator types include at least one of the following: research and judgment accuracy rate, on-time completion rate of research and judgment processing corresponding to each importance level, work order processing rate of various staff members, on-time completion rate of emergency response corresponding to each importance level, average response time of security incidents; determine the research and judgment accuracy rate based on the number of incorrect research and judgments of work orders within the unit time period and the total number of work orders within the unit time period; determine the first average time and the first time variance corresponding to each importance level based on the research and judgment processing time of all work orders corresponding to each importance level, and determine the upper and lower limits of the corresponding research and judgment processing time based on the first average time and the first time variance corresponding to the importance level. Determine the on-time completion rate of research and judgment processing corresponding to each importance level based on the research and judgment processing time of each work order within each importance level and the upper and lower limits of the research and judgment processing time corresponding to the importance level; determine the work order processing rate of various staff members based on the number of work orders processed by various staff members within the unit time period and the total number of work orders within the unit time period; determine the second average time and the second time variance corresponding to each importance level based on the emergency response time of all work orders corresponding to each importance level, and determine the upper and lower limits of the corresponding emergency response time based on the second average time and the second time variance corresponding to the importance level. Determine the on-time completion rate of emergency response corresponding to each importance level based on the emergency response time of each work order within each importance level and the upper and lower limits of the emergency response time corresponding to the importance level; determine the average response time of the security incident based on the emergency response completion time and the total occurrence time of the security incident; For the security operation data set corresponding to the engineering management dimension, determine the fourth indicator types corresponding to various security operation data types in the security operation data set from the preset database, where the fourth indicator types include at least one of the following: standardization manual coverage rate, work order standardization execution rate, emergency plan scenario coverage rate, automated blocking duration; determine the standardization manual coverage rate based on the number of knowledge databases and the total number of work order push rules; determine the work order standardization execution rate based on the number of work orders containing the standardization manual in the work order operations and the total number of work orders; determine the emergency plan scenario coverage rate based on the number of covered emergency plan scenarios and the planned number of covered emergency plan scenarios; determine the automated blocking duration based on the total blocking duration and the number of blocking times; For the security operation data set corresponding to the vulnerability management dimension, determining a fifth indicator type corresponding to each type of security operation data in the security operation data set from the preset database, wherein the fifth indicator type includes at least one of the following: a vulnerability repair rate, a vulnerability rectification rate on time, and a vulnerability repair delay rate; determining the vulnerability repair rate based on the number of vulnerabilities repaired and the total number of vulnerabilities; determining the vulnerability rectification rate on time based on the number of vulnerabilities rectified on time and the total number of vulnerabilities; and determining the vulnerability repair delay rate based on the number of vulnerabilities repaired on time and the total number of vulnerabilities. For the security operation data set corresponding to the security training management dimension, the sixth indicator type corresponding to each type of security operation data in the security operation data set is determined from the preset database, wherein the sixth indicator type includes at least one of the following: phishing email drill success rate, security training exam pass rate, attack and defense confrontation success rate, and security team effectiveness; the phishing email drill success rate is determined based on the number of people who are hit in the phishing email drill and the total number of people who participate in the drill; the security training exam pass rate is determined based on the number of people who pass the security training exam and the total number of people who participate in the exam; the attack and defense confrontation success rate is determined based on the number of successful defenses in the attack and defense drill and the number of successful attacks in the attack and defense drill; the security team effectiveness is determined based on the value output of the security team and the investment cost of the security team.
5. The method according to claim 1, wherein Before determining the abnormal indicator value affecting the target network security operation based on the magnitude relationship between each indicator value and the corresponding preset indicator threshold, the method further includes: Obtain preset indicator thresholds for indicator types corresponding to various types of safety operation data determined by experts based on historical experience; Alternatively, determine the indicator value of each type of security operation data under a preset control scenario, and determine the preset indicator threshold of the indicator type corresponding to each type of security operation data based on the average value and variance of the indicator value, wherein the control scenario includes at least: attack and defense drill scenario, normalized operation scenario.
6. The method according to claim 1, wherein After determining the indicator value corresponding to each indicator type, the method further includes: Determine a first weight value for each management dimension and a second weight value for the indicator data corresponding to each type of security operation indicator data; A security operation score of the target network within a preset time period is determined based on the first weight value, the second weight value, and the indicator values corresponding to each indicator type.
7. The method according to claim 1, wherein The method further comprises: A visual interface is used to display multiple security operation data sets, the indicator values corresponding to each type of security operation data in each operation data set, and the corresponding preset indicator thresholds, and the processing results of the abnormal source after the management measures are executed are displayed through the visual interface.
8. A network security operation and management system, characterized in that include: An acquisition module, configured to acquire multiple security operation data sets of a target network within a preset time period, wherein each of the security operation data sets includes multiple types of security operation data under one management dimension; A determination module, configured to determine, for each of the security operation data sets, an index type corresponding to each type of security operation data in the security operation data set from a preset database, and determine an index value corresponding to each index type; A management module, configured to determine an abnormal index value affecting the target network security operation according to a magnitude relationship between each index value and a corresponding preset index threshold, and execute a corresponding management measure on an abnormal source corresponding to the abnormal index value.
9. A non-volatile storage medium, characterized in that, A computer program is stored in the non-volatile storage medium, wherein a device where the non-volatile storage medium is located executes the network security operation management method according to any one of claims 1 to 7 by running the computer program.
10. A computer program product, characterized in that, Comprising: A computer program, wherein when the computer program is executed by a processor, the network security operation management method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Enterprise data security monitoring method and device based on big data, equipment and medium
CN120811748A
Enterprise data security monitoring method, device and equipment based on big data, and medium
CN120811748B
Multi-scene operation target monitoring and risk early warning processing method, device and terminal
CN121644855A