Information system business data security fraud-related risk assessment management method
By entering the correct account number and password in the information system, and using Unicode and MD5 algorithms to convert it into binary characters, combining capital letters and numbers to convert it into recognizable characters, generating evaluation scores and displaying warning pictures, the shortcomings of information system business data security fraud risk assessment management are solved, and the system's security and user warning capabilities are improved.
Patent Information
- Application Number
- CN202510568985.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
AI Technical Summary
The existing technology lacks effective methods for assessing and managing fraud risks in information system business data security, and it is impossible to effectively prevent and control the fraud risks of telecommunications and Internet companies throughout the business life cycle.
Enter the data security fraud risk assessment business management system by entering the correct account and password, use Unicode and MD5 algorithms to convert the account and password into binary form, and further convert it through the MD5 algorithm, combining capital letters, numbers and special characters into identifiable characters to judge the correctness of the account and password; at the same time, a vulnerability scanning tool is used to generate evaluation scores and a warning picture is generated based on the score.
The data security guarantee of system user information is realized, and the warning pictures are generated by evaluating scores, which improves the user's warning ability for potential risks and enhances the security prevention and control capabilities of the information system.
Smart Images

Figure CN120433994A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security processing technology, and in particular to a method for assessing and managing fraud risks associated with business data security in an information system. Background Art
[0002] In today's era of rapid digital development, many criminals exploit leaked personal data (such as names, ID numbers, contact information, and financial account information) and corporate trade secrets (such as R&D data, customer lists, and financial statements) online to carry out fraudulent activities. To address this, the state has enacted the "Law of the People's Republic of China on Combating Telecom Network Fraud," along with relevant industry standards. These laws aim to strengthen fraud risk prevention and control in telecom services by telecom and internet companies, focusing on key aspects such as resources, implementation processes, support platforms, and operational assurance, across all stages of the service lifecycle. Summary of the Invention
[0003] The present invention aims to at least solve the technical problems existing in the prior art, and in particular innovatively proposes a method for assessing and managing fraud risks associated with business data security in an information system.
[0004] In order to achieve the above-mentioned object of the present invention, the present invention provides an information system business data security fraud risk assessment and management method, comprising the following steps:
[0005] S1, enter the correct account and password to enter the data security fraud risk assessment business management system;
[0006] S2. Enter the correct account and password to enter the data security fraud risk assessment business management system and check the warning information.
[0007] In a preferred embodiment of the present invention, the method of entering the data security fraud risk assessment business management system by entering the correct account number and password in step S1 includes the following steps:
[0008] S11, obtaining the input account number and password, and processing the obtained account number and password to obtain a fourth binary account number and password;
[0009] S12, sending the binary fourth account number and password to the data security fraud risk assessment business management system;
[0010] S13, determining whether the received binary fourth account number and password exist in the data security fraud risk assessment business management system:
[0011] If the received binary fourth account number and password exist in the data security fraud risk assessment business management system, it means that the correct account number and password have been entered and the data security fraud risk assessment business management system has been entered;
[0012] If the received binary fourth account number and password do not exist in the data security fraud risk assessment business management system, it means that the wrong account number and password are entered and the data security fraud risk assessment business management system cannot be entered.
[0013] In a preferred embodiment of the present invention, the method for processing the acquired account number and password in step S11 to obtain the binary fourth account number and password is:
[0014] S111, after obtaining the input account and password, convert the account and password into a binary account and password; the binary account and password include a binary account and a binary password;
[0015] S112, after converting the account and password into a binary account and password, convert the binary account and password into a first binary account and password respectively; the first binary account and password include a first binary account and a first binary password;
[0016] S113, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; the second account and password include a second account and a second password;
[0017] S114, after converting the binary first account and password into a second account and password, converting the second account and password into a binary third account and password; the binary third account and password includes a binary third account and a binary third password;
[0018] S115, after converting the second account and password into a binary third account and password, convert the binary third account and password into a binary fourth account and password; the binary fourth account and password include a binary fourth account and a binary fourth password.
[0019] In a preferred embodiment of the present invention, the method for converting the account and password into a binary account and password in step S111 is:
[0020] Use Unicode to convert the account and password into a binary account and password; the number of digits of the binary account is 8A, where A is the number of digits of the account obtained in step S11; the number of digits of the binary password is 8B, where B is the number of digits of the password obtained in step S11.
[0021] In a preferred embodiment of the present invention, the method for converting the binary account and password into a binary first account and password respectively in step S112 is:
[0022] The binary account and password are converted into a binary first account and password respectively using the MD5 algorithm, where the number of bits of the binary first account and the binary first password are 128 bits respectively.
[0023] In a preferred embodiment of the present invention, the method for converting the binary first account and password into the second account and password in step S113 is:
[0024] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account and password. The second account and password are 22 digits each. The specific method is as follows:
[0025] S1131, determine the number of digits of the first binary account number:
[0026] If the number of digits in the first binary account number is equal to dC, proceed to the next step;
[0027] If the number of digits in the first binary account number is less than dC, add 0 after the first binary account number so that the number of digits in the first binary account number after adding 0 equals dC; then proceed to the next step;
[0028] S1132, group the binary first accounts into groups of d, from left to right, for a total of C groups;
[0029] S1133, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up the table.
[0030] Table 1 Numeric-character query table
[0031]
[0032]
[0033] In a preferred embodiment of the present invention, the calculation method of C in step S1131 is:
[0034]
[0035] Where C is the number of groups;
[0036] D0 is the number of digits of the first binary account number; here it is 128;
[0037] d is the number of bits per character group; here it is 6.
[0038] In a preferred embodiment of the present invention, the method for converting the second account and password into a binary third account and password in step S114 is:
[0039] Unicode is used to convert the second account and password into a binary third account and password. The number of bits of the binary third account and the binary third password are 176 bits respectively.
[0040] In a preferred embodiment of the present invention, the method for converting the binary third account and password into the binary fourth account and password in step S115 is:
[0041] The binary third account number and password are converted into a binary fourth account number and password using the MD5 algorithm; the number of bits of the binary fourth account number and the binary fourth password are 128 bits respectively.
[0042] In a preferred embodiment of the present invention, step S2 includes the following steps:
[0043] S21, obtaining the evaluation score of the monitoring system;
[0044] S21, after obtaining the evaluation score of the monitoring system, a warning picture is obtained according to the evaluation score of the monitoring system.
[0045] In a preferred embodiment of the present invention, the calculation method of the system evaluation score in step S21 is:
[0046]
[0047] Among them, W1 and W2 represent weights respectively;
[0048] c1 is the evaluation base number; c2 and c3 are the evaluation correlation numbers;
[0049] A3 represents the vulnerability assessment coefficient;
[0050] A4 represents vulnerability risk assessment.
[0051] In a preferred embodiment of the present invention, the value of A3 in step S21 is calculated using the following method:
[0052] When m1 is less than or equal to 0 and m2 is less than or equal to 0, A3 takes the value of 10;
[0053] When m1 is greater than 0 and m2 is less than or equal to 0, the value of A3 is 10-height / m1;
[0054] When m1 is less than or equal to 0 and m2 is greater than 0, A3 takes the value of 10-simple / m2;
[0055] When m1 is greater than 0 and m2 is greater than 0, the value of A3 is 10-(simple / m2+height / m1);
[0056] m1 represents the number of high-risk vulnerabilities, and m2 represents the number of medium-risk vulnerabilities;
[0057] Height / m1 represents the weighted average of high-risk vulnerabilities, and simple / m2 represents the weighted average of medium-risk vulnerabilities.
[0058] In a preferred embodiment of the present invention, the value of A4 in step S21 is calculated using the following method:
[0059] A4=10-topRisk-simRisk,
[0060] topRisk indicates the risk factor of high-risk vulnerabilities;
[0061] simRisk indicates the risk factor of medium-risk vulnerabilities.
[0062] In a preferred embodiment of the present invention, the method for obtaining a warning image according to the evaluation score of the monitoring system in step S22 includes the following steps:
[0063] S221, grading based on assessment scores:
[0064] R≤J1, first level warning;
[0065] J1<R≤J2, which is a second-level warning;
[0066] J2<R≤J3, which is the third-level warning;
[0067] J3<R≤J4, which is the fourth level warning;
[0068] R>J4, level 5 warning;
[0069] J1<J2<J3<J4, respectively, are the first to fourth preset thresholds;
[0070] S221, obtain the warning template. After obtaining the warning template, classify the warning template according to the level:
[0071]
[0072] r is the red channel pixel value;
[0073] g is the green channel pixel value;
[0074] b is the blue channel pixel value;
[0075] ε is the level number, ε = 1 to 5, corresponding to ε = 1 for level 1 warning, ε = 2 for level 2 warning, ε = 3 for level 3 warning, ε = 4 for level 4 warning, and ε = 5 for level 5 warning; β is the level number, here it is 5; K is the red depth number;
[0076] S223: Display the differentiated warning template on the warning viewing page.
[0077] The present invention also discloses a computer system, comprising:
[0078] processor;
[0079] a memory for storing processor-executable instructions;
[0080] Wherein, the processor is configured to implement the information system business data security fraud risk assessment management method when executing the executable instructions.
[0081] The present invention also discloses a computer-readable storage medium, comprising:
[0082] a memory having a computer program stored thereon;
[0083] A processor is used to execute the program in the memory to implement the information system business data security fraud risk assessment management method.
[0084] To sum up, due to the adoption of the above-mentioned technical solution, the present invention can securely enter the data security fraud risk assessment business management system through the correct account and password, ensure the data security of system user information, and use the scanning report results to calculate the evaluation score. According to the evaluation score of the monitoring system, a warning picture can be obtained to provide a warning to the user.
[0085] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0086] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments with reference to the accompanying drawings, in which:
[0087] Figure 1 It is a schematic block diagram of the process of the present invention. DETAILED DESCRIPTION
[0088] The following describes embodiments of the present invention in detail. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended only to explain the present invention and are not to be construed as limiting the present invention.
[0089] The present invention discloses a method for assessing and managing fraud risk of business data security in an information system. Figure 1 As shown, the following steps are included:
[0090] S1, enter the correct account and password to enter the data security fraud risk assessment business management system;
[0091] S2. Enter the correct account and password to enter the data security fraud risk assessment business management system and check the warning information.
[0092] In a preferred embodiment of the present invention, the method of entering the data security fraud risk assessment business management system by entering the correct account number and password in step S1 includes the following steps:
[0093] S11, obtaining the input account number and password, and processing the obtained account number and password to obtain a fourth binary account number and password;
[0094] S12, sending the binary fourth account number and password to the data security fraud risk assessment business management system;
[0095] S13, determining whether the received binary fourth account number and password exist in the data security fraud risk assessment business management system:
[0096] If the received binary fourth account number and password exist in the data security fraud risk assessment business management system, it means that the correct account number and password have been entered and the data security fraud risk assessment business management system has been entered;
[0097] If the received binary fourth account number and password do not exist in the data security fraud risk assessment business management system, it means that the wrong account number and password are entered and the data security fraud risk assessment business management system cannot be entered.
[0098] In a preferred embodiment of the present invention, the method for processing the acquired account number and password in step S11 to obtain the binary fourth account number and password is:
[0099] S111, after obtaining the input account and password, convert the account and password into a binary account and password; the binary account and password include a binary account and a binary password;
[0100] S112, after converting the account and password into a binary account and password, convert the binary account and password into a first binary account and password respectively; the first binary account and password include a first binary account and a first binary password;
[0101] S113, after converting the binary account and password into a first binary account and password respectively, converting the first binary account and password into a second account and password; the second account and password include a second account and a second password;
[0102] S114, after converting the binary first account and password into a second account and password, converting the second account and password into a binary third account and password; the binary third account and password includes a binary third account and a binary third password;
[0103] S115, after converting the second account and password into a binary third account and password, convert the binary third account and password into a binary fourth account and password; the binary fourth account and password include a binary fourth account and a binary fourth password.
[0104] In a preferred embodiment of the present invention, the method for converting the account and password into a binary account and password in step S111 is:
[0105] Use Unicode to convert the account and password into a binary account and password; the number of digits of the binary account is 8A, where A is the number of digits of the account obtained in step S11; the number of digits of the binary password is 8B, where B is the number of digits of the password obtained in step S11.
[0106] In a preferred embodiment of the present invention, the method for converting the binary account and password into a binary first account and password respectively in step S112 is:
[0107] The binary account and password are converted into a binary first account and password respectively using the MD5 algorithm, where the number of bits of the binary first account and the binary first password are 128 bits respectively.
[0108] In a preferred embodiment of the present invention, the method for converting the binary first account and password into the second account and password in step S113 is:
[0109] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account and password; the second account and the second password are 22 digits each. The specific method of using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account and password into the second account is as follows:
[0110] S1131, determine the number of digits of the first binary account number:
[0111] If the number of digits in the first binary account number is equal to dC, proceed to the next step;
[0112] If the number of digits in the first binary account number is less than dC, add 0 after the first binary account number so that the number of digits in the first binary account number after adding 0 equals dC; then proceed to the next step;
[0113] S1132, group the binary first accounts into groups of d, from left to right, for a total of C groups;
[0114] S1133, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0115] Table 1 Numeric-character query table
[0116] Numerical character Numerical character Numerical character Numerical character Numerical character 0 A 13 N 26 a 39 n 52 0 1 B 14 O 27 b 40 o 53 1 2 C 15 P 28 c 41 p 54 2 3 D 16 Q 29 d 42 q 55 3 4 E 17 R 30 e 43 r 56 4 5 F 18 S 31 f 44 s 57 5 6 G 19 T 32 g 45 t 58 6 7 H 20 U 33 h 46 u 59 7 8 I 21 V 34 i 47 v 60 8 9 J 22 W 35 j 48 w 61 9 10 K 23 X 36 k 49 x 62 + 11 L 24 Y 37 l 50 y 63 / 12 M 25 Z 38 m 51 z
[0117] The method for converting a binary first password into a second password using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / is the same as the method for converting a binary first account into a second account using uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / . Specifically:
[0118] S113-1, determine the number of bits of the first binary password:
[0119] If the number of bits of the first binary password is equal to d′C′, proceed to the next step;
[0120] If the number of digits of the first binary password is less than d′C′, add 0 after the first binary password so that the number of digits of the first binary password after adding 0 is equal to d′C′; then proceed to the next step;
[0121] S113-2, divide the binary first codes into groups of d′ from left to right, for a total of C′ groups;
[0122] S113-3, convert the binary characters in each group into decimal, and obtain the corresponding characters of each group by looking up Table 1.
[0123] In a preferred embodiment of the present invention, the calculation method of C in step S1131 is:
[0124]
[0125] Where C is the number of groups;
[0126] D0 is the number of digits of the first binary account number; here it is 128;
[0127] d is the number of bits per character group; here it is 6;
[0128] is a ceiling function; for example
[0129] is the floor function; for example
[0130] In a preferred embodiment of the present invention, the calculation method of C′ in step S113-1 is:
[0131]
[0132] Where C′ is the number of cipher suites;
[0133] D0′ is the number of bits of the first binary code; here it is 128;
[0134] d′ is the number of bits per character group; here it is 6.
[0135] In a preferred embodiment of the present invention, the method for converting the second account and password into a binary third account and password in step S114 is:
[0136] Unicode is used to convert the second account and password into a binary third account and password. The number of bits of the binary third account and the binary third password are 176 bits respectively.
[0137] In a preferred embodiment of the present invention, the method for converting the binary third account and password into the binary fourth account and password in step S115 is:
[0138] The binary third account number and password are converted into a binary fourth account number and password using the MD5 algorithm; the number of bits of the binary fourth account number and the binary fourth password are 128 bits respectively.
[0139] For example, the account and password entered are Beite520 and woaiBT1314 respectively;
[0140] The first step is to obtain the input account number Beite520 and password woaiBT1314, and then use Unicode to convert the account number Beite520 into a binary account number 01000010011001010101101001010111010001100101001101010011001000110000;
[0141] Convert the password woaiBT1314 using Unicode to the binary password 01110111011011110110000101101001010000100101010000110001001100110011000100110100.
[0142] The second step is to use the MD5 algorithm to convert the binary account 01000010011001010101010010111010001100101001010011001000110000 to the binary first account 1001010101010000100001010000111101000000010111110100011001000010100000001110011101000101010101010101010111011111000000101111010001;
[0143] Use the MD5 algorithm to convert the binary password 011101110110111101100001011010101001010000100101010000110001001100110011000100110100 to the binary first password 1110111111111001111001001110111010100011100011101001001000110100100001011111010100110000101100101111.
[0144] The third step is to use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first account number 100101010101000010000101000011110100000010111110100011001000010100000001110011101000101010111010101010111011111011111000000101111010001 to the second account number lUIUPQL6MhQHOiuq3vwL0Q; specifically:
[0145] 1) Since the number of digits of the first binary account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001 is 128 Therefore, the number of digits in the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101101111011111000000101111010001 is less than 132. , so add 0 after the first binary account 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101111011111000000101111010001, and we get The first account number equal to 132 bits of binary is 10010101010000100001010000111101000000101111101000110010000101000000011100111010001010111010101011011110111110000001011110100010000.
[0146] 2) Arrange the binary first account number 1001010101000010000101000011110100000010111110100011001000010100000001110011101000101011101010101011011110111110000001011110100010000 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 2.
[0147] Table 2 Binary-decimal-character correspondence table
[0148] Binary Decimal character 100101 37 l 010100 20 U 001000 8 I 010100 20 U 001111 15 P 010000 16 Q 001011 11 L 111010 58 6 001100 12 M 100001 33 h 010000 16 Q 000111 7 H 001110 14 O 100010 34 i 101110 46 u 101010 42 q 110111 55 3 101111 47 v 110000 48 w 001011 11 L 110100 52 0 010000 16 Q
[0149] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 2; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 2.
[0150] Use uppercase letters A to Z, lowercase letters a to z, numbers 0 to 9, and special characters + and / to convert the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010100110000111111011010100001000101100101111 to the second password 7 / nk7qOOkaQv6nMP3tCLLw. Specifically:
[0151] 1) Since the number of bits of the first binary code 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111101111010100001000101100101111 is 128 Therefore, the number of bits of the binary first password 11101111111110011110010011101110101000111000111010010001101001000010111111101010011100110000111111011010100001000101100101111 has less than 132 bits. , so add 0 after the first binary password 1110111111111001111001001110111010100011100011101001000110100100001011111110101001110000111110111010100001000101100101111, and we get The first binary password equal to 132 bits is 111011111111100111100100111011101010001110001110100100011010010000101111111010100111001100001111110110101000010001011001011110000101100101111000010110010111100001011001011110000.
[0152] 2) Arrange the binary first password 1110111111111100111100100111011101010001110001110100100011010010000101111111010101001110011000011111011110110100001000101100101111 in groups of 6 from left to right, and divide it into 22 groups in total, as shown in the first column of Table 3.
[0153] Table 3 Binary-decimal-character correspondence table
[0154]
[0155]
[0156] 3) Convert the binary characters in each group to decimal, as shown in the second column of Table 3; obtain the corresponding characters of each group by looking up Table 1, as shown in the third column of Table 3.
[0157] The fourth step is to use Unicode to convert the second account number lUIUPQL6MhQHOiuq3vwL0Q into the binary third account number 0110110001010101010010010101010101010000010100010100110000110110010011010101000010100100001001001000010011110110101010101010100010010000100100100100001001111011010101010110001001100110110100110000101000010100001;
[0158] The second password 7 / nk7qOOkaQv6nMP3tCLLw is converted into a binary third password using Unicode: 0011011100101111011011001101011001101110111000101001111010011101010110100001010100010111011000110110011010101010011010100000011001101101010100100110101000000110011011010001001101101000100000110011011010001000110110111.
[0159] The fifth step is to use the MD5 algorithm to convert the binary third account 01101100010101010101001001010101010101000001010001010011000011011001001101010000101001000010010010011101101010101011100010011001101100111 0111010011000011000001010001 converted to binary fourth account number 10111100001001111001010100000111100101010101101111001001100110101011101111001000011011110101010000100001111010101000010000111101000110100101010101010100;
[0160] Use MD5 algorithm to convert the binary third password 001101110010111101101101100110101100110111011100010100111101001110110101100001010100010111011000110110110010101010011010100000011001101101010100010000 11010011000100110001110111 converted to binary the fourth code is 11101110110101010110001110000010100111010101011111111101000010111110001001110110111100110101010011101101010111000110000011100101.
[0161] Since the fourth binary account number is 101111000010011110010100000111100101010101011011110010011001101010111011110010000110111101010100000100001111010001101001010101010100 and the fourth binary password is 111011101101010101011000111000001010 011101010110101111111110100001011111000100111011011110011010100111011010111000110000011100101 The number of characters is too long, which can be converted to hexadecimal, which are BC27941E556F266D7790DEA087A34AD4 and EED6B1C14EAD7FD0BE276F353B5C60E5 respectively.
[0162] In a preferred embodiment of the present invention, the analysis result value of the system's evaluation score is:
[0163]
[0164] W1 and W2 represent weights, which are 0.55 and 0.45 respectively. c1 is the evaluation base; c2 and c3 are the evaluation correlation numbers, which have the same value of 5.
[0165] A3 and A4 are obtained as follows:
[0166] A3 uses the following logic to determine its value:
[0167] When m1 is less than or equal to 0 and m2 is less than or equal to 0, A3 takes the value of 10;
[0168] When m1 is greater than 0 and m2 is less than or equal to 0, the value of A3 is 10-height / m1;
[0169] When m1 is less than or equal to 0 and m2 is greater than 0, A3 takes the value of 10-simple / m2;
[0170] When m1 is greater than 0 and m2 is greater than 0, the value of A3 is 10-(simple / m2+height / m1);
[0171] m1 represents the number of high-risk vulnerabilities, and m2 represents the number of medium-risk vulnerabilities;
[0172] height / m1 represents the weighted average of high-risk vulnerabilities, and simple / m2 represents the weighted average of medium-risk vulnerabilities;
[0173] The weighted average is calculated using the following formula:
[0174] in:
[0175] f i +g j =1, as well as It is called weight; it is calculated by multiplying the number and the weight, i∈{1,2,3,…,m1}, j∈{1,2,3,…,m2}, as well as x p is the pth element in the high-risk vulnerability risk value array topSid, p∈{1,2,3,…,m1};
[0176] y q It is the qth element in the medium-risk vulnerability risk value array simSid, q∈{1,2,3,…,m2}.
[0177] A4=10-topRisk-simRisk,
[0178] topRisk indicates the risk factor of high-risk vulnerabilities;
[0179] simRisk indicates the risk factor of medium-risk vulnerability;
[0180] When the length of the topSidX array is less than or equal to 0, topRisk is 0;
[0181] When the length of the topSidX array is greater than 0, topRisk is the maximum value of topSidX;
[0182] When the length of the simSidX array is less than or equal to 0, simRisk is 0;
[0183] When the length of the simSidX array is greater than 0, simRisk is the maximum value of simSidX;
[0184] topSidX represents the ratio of each element in the high-risk vulnerability risk value array topSid to the median of the array;
[0185] simSidX represents the ratio of each element in the medium-risk vulnerability risk value array simSid to the median of the array.
[0186] The high-risk vulnerability risk value array and the medium-risk vulnerability risk value array are derived from a vulnerability scanning report generated by a vulnerability scanning tool. The vulnerability scanning tool may be a vulnerability scanning tool such as nessus.
[0187] A3 represents the vulnerability assessment coefficient. It represents a comprehensive assessment of the vulnerability of the application system, calculated using the scan report results fed back after the vulnerability scanning tool integrated in this technology platform performs a scan task.
[0188] A4 represents a vulnerability risk assessment, which is calculated by the present invention.
[0189] The system first uses vulnerability scanning tools to scan computer application systems for vulnerabilities and generates a vulnerability scan report. The system then automatically analyzes the scan report and obtains the risk value of each vulnerability in the report. Based on the risk value, the system then classifies the vulnerability into different levels: X represents the risk value. When 7 <= X <= 10, the vulnerability is considered high-risk; when 4 <= X <= 7, the vulnerability is considered medium-risk; and when 0 <= X <= 4, the vulnerability is considered low-risk. Based on the analysis results, the system then identifies high- and medium-risk vulnerabilities.
[0190] The first step is to start the analysis model;
[0191] The second step is to calculate A3 and A4 based on the scanning report:
[0192] Taking the first set of data as an example, as shown in Table 4, the risk value array of high-risk vulnerabilities is [9,8], the risk value array of medium-risk vulnerabilities is [6,5,5], the weight of high-risk vulnerabilities is 0.6, and the weight of medium-risk vulnerabilities is 0.4.
[0193] Table 4 Data example display
[0194]
[0195] Assume that the median of the medium-risk vulnerability risk value array is 6, the median of the high-risk vulnerability risk value array is 8, and other risk values are not listed.
[0196] The weighted average risk value of high-risk vulnerabilities is: (9+8)*0.6 / 2;
[0197] The weighted average risk value of medium-risk vulnerabilities is: (6+5+5)*0.4 / 3;
[0198] The average overall vulnerability risk is (9+8)*0.6 / 2+(6+5+5)*0.4 / 3=7.233;
[0199] From this we can get A3 = 10-7.233 = 2.767;
[0200] The median ratio array of high-risk vulnerabilities is: [9 / 8,8 / 8], that is, [1.125,1];
[0201] Then topRisk=1.125;
[0202] The median ratio array of medium-severity vulnerabilities is: [6 / 6, 5 / 6, 5 / 6], that is, [1, 0.833, 0.833];
[0203] Then simRisk=1;
[0204] From this we can get A4 = 10-1.125-1 = 7.875;
[0205] The third step is to calculate the analysis result value R based on A3 and A4;
[0206] Assume that the weights of A3 and A4 are 0.55 and 0.45 respectively;
[0207] R=log5(0.55*5 2.767 +0.45*5 7.875 )=7.3794.
[0208] Obtaining a viewable warning image based on the calculated evaluation score includes the following steps:
[0209] a) There are five levels of warnings based on the assessment scores:
[0210] R≤J1, first level warning;
[0211] J1<R≤J2, which is the second-level warning;
[0212] J2<R≤J3, which is the third-level warning;
[0213] J3<R≤J4, which is the fourth level warning;
[0214] R>J4, level 5 warning;
[0215] J1<J2<J3<J4, respectively, are the first to fourth preset thresholds;
[0216] b) Obtain the warning template, which is an exclamation mark template. After obtaining the warning template, the warning template is classified according to the following levels:
[0217]
[0218] r is the red channel pixel value;
[0219] g is the green channel pixel value;
[0220] b is the blue channel pixel value;
[0221] ε is the level number, ε = 1 to 5, corresponding to ε = 1 for level 1 warning, ε = 2 for level 2 warning, ε = 3 for level 3 warning, ε = 4 for level 4 warning, and ε = 5 for level 5 warning; β is the level number, here it is 5; K is the red depth number;
[0222] c) Display the differentiated warning template on the warning viewing page.
[0223] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
Claims
1. A method for assessing and managing fraud risk in information system business data security, characterized in that: The following steps are involved: S1, enter the correct account and password to enter the data security fraud risk assessment business management system; S2. Enter the correct account and password to enter the data security fraud risk assessment business management system and check the warning information.
2. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: The method for entering the data security fraud risk assessment business management system by entering the correct account number and password in step S1 includes the following steps: S11, obtaining the input account number and password, and processing the obtained account number and password to obtain a fourth binary account number and password; S12, sending the binary fourth account number and password to the data security fraud risk assessment business management system; S13, determining whether the received binary fourth account number and password exist in the data security fraud risk assessment business management system: If the received binary fourth account number and password exist in the data security fraud risk assessment business management system, it means that the correct account number and password have been entered and the data security fraud risk assessment business management system has been entered; If the received binary fourth account number and password do not exist in the data security fraud risk assessment business management system, it means that the wrong account number and password are entered and the data security fraud risk assessment business management system cannot be entered.
3. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: Step S2 includes the following steps: S21, obtaining the evaluation score of the monitoring system; S21, after obtaining the evaluation score of the monitoring system, a warning picture is obtained according to the evaluation score of the monitoring system.
4. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: The calculation method of the system evaluation score in step S21 is: Among them, W1 and W2 represent weights respectively; c1 is the evaluation base number; c2 and c3 are the evaluation correlation numbers; A3 represents the vulnerability assessment coefficient; A4 represents vulnerability risk assessment.
5. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: In step S21, the value of A3 is calculated using the following method: When m1 is less than or equal to 0 and m2 is less than or equal to 0, A3 takes the value of 10; When m1 is greater than 0 and m2 is less than or equal to 0, the value of A3 is 10-height / m1; When m1 is less than or equal to 0 and m2 is greater than 0, A3 takes the value of 10-simple / m2; When m1 is greater than 0 and m2 is greater than 0, the value of A3 is 10-(simple / m2+height / m1); m1 represents the number of high-risk vulnerabilities, and m2 represents the number of medium-risk vulnerabilities; Height / m1 represents the weighted average of high-risk vulnerabilities, and simple / m2 represents the weighted average of medium-risk vulnerabilities.
6. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: In step S21, the value of A4 is calculated using the following method: A4=10-topRisk-simRisk, topRisk indicates the risk factor of high-risk vulnerabilities; simRisk indicates the risk factor of medium-risk vulnerabilities.
7. The information system business data security fraud risk assessment and management method according to claim 1 is characterized in that: The method for obtaining a warning image according to the evaluation score of the monitoring system in step S22 includes the following steps: S221, grading based on assessment scores; S221, obtaining a warning template, and after obtaining the warning template, classifying the warning template according to the level; S223: Display the differentiated warning template on the warning viewing page.
8. A computer system, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the information system business data security fraud risk assessment and management method according to one of claims 1 to 7 when executing the executable instructions.
9. A computer-readable storage medium, characterized in that include: a memory having a computer program stored thereon; A processor is used to execute the program in the memory to implement the information system business data security fraud risk assessment management method according to any one of claims 1 to 7.