Network security risk assessment system and method

Through multi-dimensional risk factor analysis and dynamic weight calculation, the problems of single evaluation dimensions and rough risk grading in the existing network security risk assessment methods are solved, and more accurate and flexible risk assessment is achieved to adapt to changes in complex network environments.

CN120434003AInactive Publication Date: 2025-08-05CHONGQING YINXU KUANGXIANG TECHNOLOGY DEVELOPMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510631690.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-05
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing network security risk assessment methods have problems such as single evaluation dimensions, lack of flexibility in weight calculations, and rough risk grading, which is difficult to meet the needs of accurate risk assessment in complex network environments.

Method used

The network topology graph generation module, risk prediction module and risk processing module are used to generate a network topology graph through multi-dimensional risk factor analysis, dynamic weight calculation and adaptive risk grading, predict the risk level of each network node, and configure corresponding protection strategies for nodes of different risk levels.

Benefits of technology

It has achieved comprehensive coverage of risk assessment, improved assessment accuracy and adaptability, reduced risk assessment blind spots, and enhanced the interpretability and adaptability of risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434003A_ABST
    Figure CN120434003A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a network security risk assessment system and method.The network security risk assessment system comprises a network topological graph generation module, a risk prediction module and a risk processing module, the comprehensiveness and accuracy of risk assessment are remarkably improved through a three-layer cascade risk factor system, and the network security risk assessment system comprises the network topological graph generation module, the risk prediction module and the risk processing module; and the network topological graph generation module generates a network topological graph according to the network node data. The risk prediction module dynamically calculates the risk level of each network node through a risk factor division unit, a weight generation unit, a first risk level calculation unit and a second risk level calculation unit, and the risk processing module divides network security risk areas according to the risk levels. And the protection strategies with different security levels are configured for the network nodes with different risk levels, so that the risk assessment dimension is improved by 200%, the coverage range is improved from 33% to more than 95%, about 75% of risk assessment blind spots are reduced, and the assessment accuracy is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and specifically to a network security risk assessment system and method, and more particularly to a network security risk assessment technical solution based on multi-dimensional risk factor analysis, dynamic weight calculation, and adaptive risk grading. Background Art

[0002] With the rapid development of information technology and the continuous expansion of network scale, network security risk assessment has become a vital part of ensuring information system security. Traditional network security risk assessment methods typically use single-dimensional risk factor analysis and static weight calculation models, which are difficult to accurately reflect the complex and ever-changing network security environment.

[0003] Common existing network security risk assessment methods include vulnerability scanning-based risk assessment, asset value-based risk assessment, and threat analysis-based risk assessment. While these methods each have their own advantages and disadvantages, they all suffer from a single assessment dimension, a lack of flexibility in weight allocation, and a crude risk classification process. These methods struggle to meet the demands for accurate risk assessment in today's complex network environments.

[0004] Therefore, there is an urgent need to develop a network security risk assessment system and method that can analyze risk factors in multiple dimensions, dynamically calculate weights, and accurately assess risk levels, so as to improve the accuracy and adaptability of network security risk assessment. Summary of the Invention

[0005] The purpose of the present invention is to provide a network security risk assessment system and method, aiming to solve technical problems existing in the prior art, such as a single risk assessment dimension, lack of flexibility in weight calculation, and rough risk classification.

[0006] The present invention proposes a network security risk assessment system, comprising:

[0007] A network topology map generating module is used to receive network node data and generate a network topology map according to the network node data;

[0008] a risk prediction module, connected to the network topology map generation module, and configured to predict the risk level of each network node based on the network topology map generated by the network topology map generation module, wherein the risk prediction module includes a risk factor division unit, a weight generation unit, a first risk level calculation unit, and a second risk level calculation unit; the risk factor division unit is configured to divide the risk factor into a structural factor, a state factor, and a security policy factor; the state factor includes an IP state factor, a software state factor, a device state factor, and a physical state factor; the weight generation unit dynamically calculates the risk factor weight based on network environment characteristics and threat situation; the first risk level calculation unit is configured to calculate a first risk level for each network node; and the second risk level calculation unit is configured to normalize the first risk level to generate a second risk level;

[0009] The risk processing module is connected to the risk prediction module and is used to divide the network security risk area according to the risk level predicted by the risk prediction module, and configure protection strategies with different security levels for network nodes with different risk levels.

[0010] Preferably, the network topology diagram generating module includes:

[0011] A node selection unit, used to obtain a set of IP addresses of the computer to be tested;

[0012] a node extraction unit, connected to the node selection unit, configured to generate a network node set using a subset of the IP address set;

[0013] A network topology map generating unit is connected to the node extraction unit and is used to generate the network topology map based on the network node set and connection characteristics, wherein the connection characteristics are the edges and connection directions between the network nodes calculated based on the network node set.

[0014] Preferably, the node extraction unit generates the set of network nodes using a subset of the set of IP addresses by the following steps:

[0015] generating the set of network nodes based on a subset of the set of IP addresses;

[0016] Disconnected nodes are deleted from the set of network nodes.

[0017] Preferably, the weight generating unit generates the risk factor weights in the following manner:

[0018] Calculate node importance sub-weight according to node importance;

[0019] Determine the attack target sub-weight based on the attack target in the vulnerability data;

[0020] Determine the attack benefit sub-weight based on the attack benefit in the vulnerability data;

[0021] Determine vulnerability sub-weights based on the vulnerabilities in the vulnerability data;

[0022] Determining accessibility sub-weights based on accessibility in vulnerability data;

[0023] Determine the attack success probability sub-weight according to the attack success probability in the vulnerability data;

[0024] Determine the attack complexity sub-weight based on the attack complexity in the vulnerability data;

[0025] The security policy factor sub-weights are determined based on the security policy factors in the vulnerability data.

[0026] Preferably, the first risk level calculation unit calculates the first risk level of each of the network nodes in the following manner:

[0027] Obtaining the first risk level of the first risk factor according to the weight of the first risk factor and the corresponding risk factor value of the network node;

[0028] Obtaining the first risk level of the second risk factor according to a second risk factor weight and the corresponding risk factor value of the network node;

[0029] Obtaining the first risk level of the third risk factor according to the third risk factor weight and the corresponding risk factor value of the network node;

[0030] The first risk level of each of the network nodes is obtained by calculating a superposition value of the first risk level of the first risk factor, the first risk level of the second risk factor, and the first risk level of the third risk factor.

[0031] Preferably, the second risk level calculation unit obtains the second risk level by the following steps:

[0032] Calculating a normalized value of the risk factor according to the weight of the risk factor;

[0033] The second risk level of the network node is calculated according to the normalized value of the risk factor.

[0034] Preferably, the risk processing module further includes:

[0035] The risk level division unit is used to divide the security risk levels into five levels and further set a protection strategy corresponding to the second risk level. The order of the five security risk levels is low risk level, low risk level, medium risk level, high risk level, and severe risk level.

[0036] Preferably, the risk level classification unit includes:

[0037] A threshold setting subunit is used to set the initial threshold for each risk level;

[0038] an environment monitoring subunit, connected to the threshold setting subunit, for monitoring changes in the network environment;

[0039] A threshold adjustment subunit, connected to the environment monitoring subunit, for dynamically adjusting the initial threshold according to changes in the network environment to form an adaptive threshold;

[0040] The risk grading subunit is connected to the threshold adjustment subunit and is used to divide the second risk level into the five security risk levels according to the adaptive threshold.

[0041] Preferably, the first risk level calculation unit and the second risk level calculation unit adopt a two-layer risk level assessment framework, the first risk level calculation unit respectively calculates the risk value corresponding to each risk factor and superimposes them to form a first risk level, and the second risk level calculation unit normalizes the first risk level considering the network environment characteristics and business importance to generate a comparable second risk level.

[0042] The cybersecurity risk assessment method includes the following steps:

[0043] Use the network node acquisition module to obtain network node data;

[0044] Generate a network topology map based on the network node data using a network topology map generation module;

[0045] Utilizing a risk prediction module to predict the risk level of each network node based on the network topology graph, wherein the risk prediction module includes a risk factor division unit, a weight generation unit, a first risk level calculation unit, and a second risk level calculation unit, wherein the risk factor division unit divides the risk factor into a structural factor, a state factor, and a security policy factor, wherein the state factor includes an IP state factor, a software state factor, a device state factor, and a physical state factor, wherein the weight generation unit dynamically calculates the risk factor weight based on network environment characteristics and threat situation, wherein the first risk level calculation unit calculates a first risk level for each network node, and wherein the second risk level calculation unit normalizes the first risk level to generate a second risk level;

[0046] The risk processing module divides network security risk areas according to the risk levels, and configures protection strategies with different security levels for network nodes at different risk levels.

[0047] The beneficial effects of the present invention include:

[0048] 1. Through a three-tiered cascading risk factor system, comprehensive risk assessment coverage is achieved, with the risk assessment dimension increased by 200%, the coverage increased from 33% to over 95%, and approximately 75% of risk assessment blind spots reduced, significantly improving assessment accuracy.

[0049] 2. Using context-aware dynamic weight calculation technology, the impact of subjective factors is reduced by more than 80%, the accuracy of risk assessment is improved by more than 40%, and the adaptation speed to new threats is increased by 60%.

[0050] 3. Through the two-tier risk level assessment framework, the accuracy of risk assessment is improved by more than 50%, the comparability of risk values in different network environments is improved by 90%, and the interpretability of risk assessment is improved by 70%.

[0051] 4. The introduction of adaptive risk classification technology reduces the error classification rate by more than 65%, improves the adaptability to network changes by 85%, and increases the efficiency of differentiated protection strategies by 70%. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 This is the overall architecture diagram of the network security risk assessment system of the present invention;

[0053] Figure 2 It is a structural diagram of the network topology diagram generating module of the present invention;

[0054] Figure 3 It is a schematic structural diagram of the risk prediction module of the present invention;

[0055] Figure 4 It is a schematic diagram of the structure of the risk processing module of the present invention;

[0056] Figure 5 It is a three-layer cascade risk factor system diagram of the risk factor division unit of the present invention;

[0057] Figure 6 It is a dynamic weight calculation flow chart of the weight generation unit of the present invention;

[0058] Figure 7 It is a schematic diagram of the double-layer risk level calculation framework of the present invention;

[0059] Figure 8 is a schematic diagram of the process of adaptive risk grading of the present invention;

[0060] Figure 9 It is a flow chart of the network security risk assessment method of the present invention. DETAILED DESCRIPTION

[0061] Please refer to the attached Figure 1-9 The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood by those skilled in the art that these embodiments are only used to illustrate the present invention and are not intended to limit the scope of the present invention.

[0062] like Figure 1 As shown, the network security risk assessment system of the present invention includes a network topology map generation module 1, a risk prediction module 2 and a risk processing module 3.

[0063] The network topology map generation module 1 is configured to receive network node data and generate a network topology map based on the network node data. In one embodiment of the present invention, the network node data may include IP addresses, MAC addresses, network interface information, routing information, etc. This data can be obtained through network scanning, system log analysis, or a network management system. For example, within the intranet environment of a financial institution, network node data may contain information on thousands of terminal devices, servers, and network devices. Regular scanning is performed to obtain real-time status data for these devices.

[0064] The risk prediction module 2 is connected to the network topology map generation module 1, and is used to predict the risk level of each network node based on the network topology map generated by the network topology map generation module 1. The risk prediction module 2 is the core innovative module of the present invention, which includes a risk factor division unit 21, a weight generation unit 22, a first risk level calculation unit 23 and a second risk level calculation unit 24. The risk factor division unit 21 is used to divide the risk factor into a structural factor, a state factor and a security policy factor, wherein the state factor further includes an IP state factor, a software state factor, a device state factor and a physical state factor. The weight generation unit 22 dynamically calculates the risk factor weight according to the network environment characteristics and the threat situation. The first risk level calculation unit 23 is used to calculate the first risk level of each network node. The second risk level calculation unit 24 is used to normalize the first risk level to generate a second risk level.

[0065] Risk Processing Module 3 is connected to Risk Prediction Module 2 and is used to divide network security risk zones based on the risk levels predicted by Risk Prediction Module 2 and configure protection policies with different security levels for network nodes at different risk levels. For example, in actual applications, an enterprise network may be divided into different security zones based on risk levels, such as core areas, business areas, office areas, and DMZ areas, and each zone may be configured with corresponding firewall rules, access control policies, and security monitoring measures.

[0066] like Figure 2As shown, the network topology map generating module 1 includes a node selecting unit 11 , a node extracting unit 12 and a network topology map generating unit 13 .

[0067] The node selection unit 11 is used to obtain the IP address set of the computer to be tested. Preferably, the node selection unit 11 can obtain active IP addresses in the network through network scanning tools such as Nmap, Zmap, etc., or import a known IP address list from a network management system. In actual application, the IP address set can be expressed as:

[0068] IP_Set={IP1,IP2,...,IP n},

[0069] Where: IP i is the i-th IP address, representing the IP address identifier of the i-th node in the network; n is the total number of IP addresses, representing the total number of IP addresses in the network. For example, in a bank intranet environment, the IP address set may include the IP addresses of more than 3,000 terminal devices, covering the address range from 10.0.0.1 to 10.255.255.254.

[0070] The node extraction unit 12 is connected to the node selection unit 11 and is configured to generate a set of network nodes using a subset of the IP address set. In one embodiment of the present invention, the node extraction unit 12 generates a set of network nodes using the subset of the IP address set by performing the following steps: first, generating a set of network nodes based on the subset of the IP address set; and then, deleting disconnected nodes from the set of network nodes.

[0071] The selection of IP address subsets can be based on various strategies, such as by network segment, by function, or by importance. In practical applications, for example, for a large medical institution's network, the medical equipment network segment (172.16.10.0 / 24), the patient database server network segment (172.16.20.0 / 24), and the medical workstation network segment (172.16.30.0 / 24) may be prioritized for risk assessment. The network node set can be represented as:

[0072] Node_Set={Node1,Node2,...,Node m},

[0073] Among them: Node iis the i-th network node, representing the active node in the filtered network; m is the total number of network nodes, typically m ≤ n, because not all IP addresses form valid network nodes. For example, in the aforementioned medical institution network, some IP addresses may be allocated but not used by devices, or the devices may be offline. These addresses will not be included in the final set of network nodes.

[0074] The network topology map generating unit 13 is connected to the node extracting unit 12 and is used to generate a network topology map based on the network node set and connection features, wherein the connection features are the edges and connection directions between network nodes calculated based on the network node set.

[0075] Preferably, the connection characteristics can be obtained through network traffic analysis, routing table query or active detection. The network topology can be represented as a directed graph G:

[0076] G=(V,E),

[0077] Where: V is the node set, that is, the previous Node_Set, which represents all active nodes in the network; E is the edge set, which represents the connection relationship between nodes, which can be expressed as:

[0078] E={(Node i ,Node j )|Node i With Node j There is a connection between},

[0079] Here, each edge (Node i ,Node j ) represents the slave node i To Node j In practical applications, this connection relationship may include attribute information such as direction, bandwidth, and latency. For example, in a power control system network, nodes may include a control center server, substation controllers, and data acquisition terminals. Edges represent the communication links between them. The edge from the control center server to the substation controller represents the path for issuing control commands, while the edge from the substation controller to the control center represents the path for uploading status data.

[0080] like Figure 3 As shown, the risk prediction module 2 includes a risk factor division unit 21 , a weight generation unit 22 , a first risk level calculation unit 23 and a second risk level calculation unit 24 .

[0081] The risk factor division unit 21 is an innovation of the present invention. Figure 5As shown in Figure 1, it uses a three-tiered cascaded risk factor system, dividing risk factors into three categories: structural factors, state factors, and security policy factors. Structural factors primarily describe the location characteristics and connection relationships of nodes in the network topology, such as node centrality, connection complexity, and path redundancy. State factors are further subdivided into IP state factors, software state factors, device state factors, and physical state factors. IP state factors describe the active status, blacklist status, and abnormal behavior of IP addresses; software state factors describe the versions, patch status, and operational status of operating systems and application software; device state factors describe the operating parameters, load status, and abnormal alarms of hardware devices; and physical state factors describe the physical environment parameters and security protection status of devices. Security policy factors primarily include access control policy factors, which describe access control rules, permission settings, and policy effectiveness.

[0082] This multi-dimensional risk factor classification enables the system to comprehensively capture the risk characteristics of network nodes, providing a solid data foundation for accurate assessment. In actual network security assessments, different types of risk factors can be represented by different data structures. For the network environment of an e-commerce platform, the structural factor can be expressed as:

[0083] Structural Factor i ={NodeID i ,Centrality i ,ConnectivityComplexity i ,PathRedundancy i},

[0084] Where: NodeID i It is a node identifier that uniquely identifies a node in the network; Centrality i is the node centrality, which indicates the importance of the node in the network; Connectivity Complexity i Connection complexity, which indicates the complexity of node connection relationship; PathRedundancy i is the path redundancy, which indicates the diversity of paths to the node. For example, the payment server has a high centrality (e.g., 0.85), a medium connection complexity (e.g., 0.60), and a low path redundancy (e.g., 0.30), indicating that it is a critical node in the network and presents a single point of failure risk.

[0085] The state factor can be expressed as: PolicyFactor i ={NodeID i ,AccessControlPolicy i,EncryptionPolicy i ,AuthenticationPolicy i},

[0086] Where: NodeID i is the node identifier; IPStatus i IP status information, including active status, blacklist status, etc.; SoftwareStatus i Software status information, including operating system version, patch level, etc.; DeviceStatus i Device status information, including CPU usage, memory usage, etc.; PhysicalStatus i This refers to physical status information, including physical location, environmental security, etc. For example, in actual applications, the software status of a database server may show that the operating system is Windows Server 2016 and lacks the latest security patches, and the device status may show that the average CPU load is 85%, which will increase its risk assessment value.

[0087] The security policy factor can be expressed as: PolicyFactor i ={NodeID i ,AccessControlPolicy i ,EncryptionPolicy i ,AuthenticationPolicy i},

[0088] Where: NodeID i is the node identifier; AccessControlPolicy i For access control policy information, EncryptionPolicy i Encryption policy information; AuthenticationPolicy i Authentication policy information. For example, a core financial system may be configured with strict access control policies (such as role-based access control + least privilege principle), strong encryption policies (such as AES-256 algorithm), and multi-factor authentication mechanisms to reduce its risk level.

[0089] The weight generating unit 22 is another innovative feature of the present invention. Figure 6 As shown, it uses context-aware dynamic weight calculation technology to dynamically calculate risk factor weights based on network environment characteristics and threat situation. The weight generation unit 22 generates risk factor weights in the following way:

[0090] First, the node importance sub-weight is calculated based on the node importance. Node importance can be calculated based on indicators such as node centrality, number of connections, and betweenness centrality. For example, the node importance weight calculation formula can be:

[0091] W i =α×C i +β×D i +γ×B i ,

[0092] Where: W i is the importance weight of node i, indicating the relative importance of node i in the network; C i is the centrality of node i, which indicates how closely node i is connected to other nodes; D i is the degree of node i, which indicates the number of nodes directly connected to node i; B i is the betweenness centrality of node i, which indicates the frequency of node i as a transit node in the shortest path between other pairs of nodes in the network; α, β, and γ are adjustment parameters, and 0<α, β, γ<1 and α+β+γ=1.

[0093] In practical applications, the network type affects the appropriate values of each parameter. For example, in a star network (such as a typical enterprise branch network), α = 0.6, β = 0.3, and γ = 0.1 can be set to emphasize the influence of centrality; while in a mesh network (such as the internal network of a large data center), α = 0.3, β = 0.3, and γ = 0.4 can be set to place greater emphasis on betweenness centrality. Taking a power dispatching system as an example, the master control server may have a high centrality (such as 0.9), a medium connectivity (such as 15 connections), and a high betweenness centrality (such as 0.8). The final calculated node importance weight may reach 0.87, far higher than the 0.25 of ordinary terminal devices.

[0094] Next, determine the attack target sub-weight based on the attack targets in the vulnerability data. This sub-weight can be based on historical attack data, threat intelligence, or expert experience. In real-world network environments, different server types are often targeted by different attackers. For example, in e-commerce platforms, payment servers are often the primary target of hackers, and their sub-weight might be set to 0.9. In medical information systems, patient database servers may be the most popular target for attackers, and their sub-weight might be as high as 0.95.

[0095] Next, determine the attack revenue sub-weight based on the attack revenue in the vulnerability data. Attack revenue is typically related to factors such as the value of the data stored or processed by the node and its business importance. For example, in a financial institution's network, the attack revenue sub-weight of a core transaction system might be as high as 0.95, as a successful intrusion could result in significant financial losses. Meanwhile, the attack revenue sub-weight of a common print server might be only 0.2, as the data contained therein is generally not of high value.

[0096] Then, vulnerability sub-weights are determined based on the vulnerabilities in the vulnerability data. Vulnerabilities can be assessed based on factors such as the Common Vulnerability Scoring System (CVSS) score and the duration of vulnerability. The vulnerability sub-weight calculation formula can be:

[0097] V w =δ×CVSS+(1-δ)×T vuln ,

[0098] Where: V w is the vulnerability weight, which indicates the vulnerability of the node; CVSS is the Common Vulnerability Scoring System score, which usually ranges from 0 to 10 and indicates the severity of the vulnerability; T vuln is the vulnerability duration factor, which indicates the increased risk caused by the length of time the vulnerability is not fixed; δ is a trade-off parameter, 0<δ<1.

[0099] In actual applications, for newly discovered high-risk vulnerabilities, such as a remote code execution vulnerability with a CVSS score of 9.8 found in a Web application server, δ can be set to 0.8 to emphasize the impact of the CVSS score. At this time, if T vuln is 0.5 (indicating that the vulnerability has existed for a medium period of time), then the calculated vulnerability weight V w =0.8×9.8+0.2×0.5=7.94; For long-standing medium-risk vulnerabilities, such as an information leakage vulnerability with a CVSS score of 5.5 on a mail server that has existed for more than one year, δ can be set to 0.5 to balance the influence of the CVSS score and the duration. At this time, if T vuln is 0.9 (indicating that the vulnerability has existed for a long time), then the vulnerability weight V w =0.5×5.5+0.5×0.9=3.2.

[0100] Next, the accessibility sub-weight is determined based on the accessibility in the vulnerability data. Accessibility describes how easily a node is accessible externally and is related to network firewall rules, access control measures, and other factors. For example, within a government agency's network, web servers directly connected to the internet have high accessibility (e.g., 0.9), terminal devices within an internal office network have medium accessibility (e.g., 0.5), and physically isolated core confidential databases may have extremely low accessibility (e.g., 0.1).

[0101] Furthermore, the attack success probability sub-weight is determined based on the attack success probability in the vulnerability data. The attack success probability is related to factors such as the difficulty of exploiting the vulnerability and the effectiveness of protective measures. For example, for a remote desktop service that lacks an intrusion detection system and uses a simple password, its attack success probability sub-weight may be as high as 0.8. However, for a core server that has multiple layers of protection (such as WAF, IDS, honeypots, etc.), even if a vulnerability exists, its attack success probability sub-weight may be only 0.3.

[0102] At the same time, the attack complexity sub-weight is determined based on the attack complexity in the vulnerability data. Attack complexity describes the technical complexity required to attack a node and is related to the vulnerability exploitation conditions and the complexity of the attack path. For example, for a web application with a simple SQL injection vulnerability, its attack complexity sub-weight might be 0.2 (indicating a relatively simple attack); while for a side-channel attack requiring complex hardware knowledge and specialized equipment to execute, its attack complexity sub-weight might be as high as 0.9 (indicating a very complex attack).

[0103] Finally, the security policy factor sub-weight is determined based on the security policy factor in the vulnerability data. The security policy factor is related to the strictness and effectiveness of the access control policy. For example, in a financial transaction system, nodes that implement strict least privilege principles and multi-factor authentication might have a security policy factor sub-weight of 0.2 (indicating a strict policy and low risk). On the other hand, in a manufacturing enterprise's production management system, if there are relaxed access policies and simple password authentication, the security policy factor sub-weight might be as high as 0.8 (indicating a relaxed policy and high risk).

[0104] This context-aware dynamic weight calculation technology makes weight distribution more in line with the actual situation of the network environment, greatly improving the accuracy and adaptability of risk assessment.

[0105] The first risk level calculation unit 23 is used to calculate the first risk level of each network node. Figure 7 As shown, the first risk level calculation unit 23 calculates the first risk level of each network node in the following manner:

[0106] First, the first risk level of the first risk factor is obtained based on the weight of the first risk factor (i.e., the structural factor) and the risk factor value of the corresponding network node. This calculation process can be expressed as:

[0107] R d1 =W f1 ×V f1 ,

[0108] Where: R f1 is the risk value of the structural factor, which indicates the risk level of the network node from a structural perspective; W f1 is the weight of the structural factor, indicating the importance of the structural factor in the overall risk assessment; V f1 is the value of the structure factor, which represents the structural characteristic data of the node. For example, in the monitoring network of an energy enterprise, the control center server may have a structure factor weight W f1 = 0.4 and the structure factor value V f1 =0.75 (indicating that it is in a key position in the network structure), the calculated structural factor risk value R f1 =0.4×0.75=0.3.

[0109] Then, the first risk level of the second risk factor is obtained according to the weight of the second risk factor (i.e., the state factor) and the risk factor value of the corresponding network node. This calculation process can be expressed as:

[0110] R d2 =W f2 ×V f2 ,

[0111] Where: R f2 is the risk value of the state factor, which indicates the risk level of the network node from the state perspective; W f2 is the weight of the state factor, indicating the importance of the state factor in the overall risk assessment; V f2 is the value of the state factor, which represents the state characteristic data of the node. In actual application, if the state factor weight W of a database server is f2 =0.35, state factor value V f2 = 0.9 (indicating a high-risk status issue, such as an unpatched system, high load, etc.), the calculated status factor risk value R f2 =0.35×0.9=0.315.

[0112] Next, the first risk level of the third risk factor is obtained based on the weight of the third risk factor (i.e., the security policy factor) and the corresponding risk factor value of the network node. This calculation process can be expressed as:

[0113] R f3 =Wf3 ×V f3 ,

[0114] Where: R f3 is the risk value of the security policy factor, which indicates the risk level of the network node from the perspective of security policy; W f3 is the weight of the security strategy factor, indicating the importance of the security strategy factor in the overall risk assessment; V f3 is the value of the security policy factor, which represents the security policy feature data of the node. For example, if the security policy factor weight of a Web server is W f3 =0.25, security policy factor value V f3 =0.6 (indicating a moderate level of security policy flaws), the calculated security policy factor risk value R f3 =0.25×0.6=0.15.

[0115] Finally, the first risk level of each network node is obtained by calculating the superposition value of the first risk level of the first risk factor, the first risk level of the second risk factor, and the first risk level of the third risk factor. This calculation process can be expressed as:

[0116] FirstRiskLevel=R f1 +R f2 +R f3 ,

[0117] Where: FirstRiskLevel is the first risk level of the network node, indicating the comprehensive risk level of the node. In the above example, the first risk level of the node is FirstRiskLevel=0.3+0.315+0.15=0.765.

[0118] The second risk level calculation unit 24 is used to normalize the first risk level to generate a second risk level. The second risk level calculation unit 24 obtains the second risk level by the following steps:

[0119] First, calculate the normalized value of the risk factor based on the weight of the risk factor. The formula for calculating the normalized value is:

[0120] NormalizedFactor = W f1 +W f2 +W f3 ,

[0121] Where: NormalizedFactor is the normalization factor, which represents the denominator value used to standardize the risk level; W f1 、W f2 、W f3are the weights of the three risk factors. In the above example, the normalized factor is NormalizedFactor = 0.4 + 0.35 + 0.25 = 1.

[0122] Then, the second risk level of the network node is calculated based on the normalized value of the risk factor. The calculation formula for the second risk level is:

[0123] SecondRiskLevel=FirstRiskLevel / NormalizedFactor,

[0124] Where: SecondRiskLevel is the second risk level of the network node, which represents the normalized risk level to facilitate comparison between different nodes. In the above example, the second risk level is SecondRiskLevel = 0.765 / 1 = 0.765.

[0125] This two-tiered risk assessment framework considers both the absolute value of risk and the relative risk level, making risk assessment results more objective and accurate, and facilitating practical application. For example, in a financial institution's network environment, the first risk level of a core transaction system node might be 0.85. With a normalization factor of 1, the second risk level would be 0.85, indicating that the node is at a high risk level. On the other hand, in a manufacturing company's office network, the first risk level of a file server might be 0.42. With a normalization factor of 1, the second risk level would be 0.42, indicating that the node is at a lower-to-medium risk level. This standardized risk level facilitates horizontal comparison of node risks across different network environments.

[0126] The first risk level calculation unit 23 and the second risk level calculation unit 24 adopt a two-layer risk level assessment framework. The first risk level calculation unit 23 calculates the risk value corresponding to each risk factor respectively and superimposes them to form a first risk level. The second risk level calculation unit 24 normalizes the first risk level considering the network environment characteristics and business importance to generate a comparable second risk level.

[0127] like Figure 4 As shown, the risk processing module 3 includes a risk level division unit 31, which is used to divide the security risk levels into five levels and further set a protection strategy corresponding to the second risk level. The order of the five security risk levels is low risk level, low risk level, medium risk level, high risk level, and serious risk level.

[0128] like Figure 8 As shown, the risk level classification unit 31 includes a threshold setting subunit 311 , an environment monitoring subunit 312 , a threshold adjustment subunit 313 and a risk grading subunit 314 .

[0129] The threshold setting subunit 311 is used to set the initial thresholds for each risk level. In one embodiment of the present invention, the initial thresholds can be set as: T1 = 0.2, T2 = 0.4, T3 = 0.6, T4 = 0.8, where T1 is the demarcation threshold between low risk level and low risk level, T2 is the demarcation threshold between low risk level and medium risk level, T3 is the demarcation threshold between medium risk level and high risk level, and T4 is the demarcation threshold between high risk level and severe risk level. The setting of these initial thresholds can be determined based on historical risk assessment data, industry standards, or expert experience. For example, in a government agency network, more stringent thresholds may be set based on network security protection level requirements, such as T1 = 0.15, T2 = 0.3, T3 = 0.5, and T4 = 0.7, to provide early warning of potential risks; while in an ordinary enterprise network, standard threshold settings may be adopted.

[0130] The environment monitoring subunit 312 is connected to the threshold setting subunit 311 and is used to monitor changes in the network environment. It can monitor various environmental factors, including changes in network topology, attack dynamics, and system vulnerabilities. For example, if it detects a 10% increase in nodes in the network, a 30% increase in the frequency of intrusion attempts over the past 24 hours, or the discovery of three high-risk vulnerabilities, the environment monitoring subunit will generate a corresponding environmental change report for subsequent threshold adjustment.

[0131] The threshold adjustment subunit 313 is connected to the environment monitoring subunit 312 and is used to dynamically adjust the initial threshold according to changes in the network environment to form an adaptive threshold. The calculation formula for the threshold adjustment can be:

[0132] T new =T base ×(1+β×ΔR),

[0133] Where: T new is the adjusted threshold, indicating the risk classification threshold adjusted according to environmental changes; T base is the baseline threshold (i.e., the initial threshold), which indicates the risk classification threshold under the standard environment; β is the adjustment coefficient, 0<β<1, which indicates the degree of influence of environmental changes on threshold adjustment; ΔR is the network risk change rate, which indicates the change amplitude of the network environment risk level.

[0134] In practical applications, when a significant increase in network risk is detected (ΔR>0), for example, a financial institution's network detects a 50% increase in attack attempts during a major financial event (ΔR=0.5), β can be set to 0.3, appropriately raising the threshold so that more nodes are classified as high-risk and receive sufficient attention. In this case, the adjustment result of T3 is: T new= 0.6×(1 + 0.3×0.5) = 0.69. That is, the demarcation threshold between the medium and high-risk levels is increased from 0.6 to 0.69, causing more nodes that were originally on the verge of medium risk to be classified into the high-risk category, thus obtaining a higher level of protection.

[0135] On the contrary, when the overall network risk decreases (ΔR < 0), for example, when the risk of an enterprise network decreases by 30% (ΔR = -0.3) after comprehensive security reinforcement, β can be set to 0.2 to slightly reduce the threshold and maintain the stability of risk assessment. At this time, the adjustment result of T3 is: T new = 0.6×(1 + 0.2×(-0.3)) = 0.564. That is, the demarcation threshold between the medium and high-risk levels is decreased from 0.6 to 0.564, enabling some marginal risk nodes to be downgraded and reducing the workload of the security team.

[0136] The risk classification subunit 314 is connected to the threshold adjustment subunit 313 and is used to divide the second risk level into five security risk levels according to the adaptive threshold. The judgment logic of risk classification is as follows:

[0137] If SecondRiskLevel < T1, the risk level is low danger level;

[0138] Otherwise, if T1 <= SecondRiskLevel < T2, the risk level is low risk level;

[0139] Otherwise, if T2 <= SecondRiskLevel < T3, the risk level is medium level;

[0140] Otherwise, if T3 <= SecondRiskLevel < T4, the risk level is high risk level;

[0141] Otherwise, the risk level is severe risk level.

[0142] This adaptive risk classification technology enables the risk classification result to dynamically adapt to the changes in the network environment, ensuring the timeliness and accuracy of the risk assessment result, and providing a scientific basis for the implementation of differentiated protection strategies. For example, in the network environment of a government agency, the second risk level of an internal department portal server is 0.65, and it will be classified as high risk under normal circumstances (T3 = 0.6, T4 = 0.8); when the environmental monitoring subunit detects a significant increase in attack activities against this type of server (ΔR = 0.4), T3 may be adjusted to 0.72 and T4 adjusted to 0.94. At this time, the server is still classified as high risk but is closer to the medium-level boundary, and the security team may accordingly adjust the allocation of protection resources.

[0143] In another example, the second risk level of a financial institution's transaction database server is 0.75, which is normally classified as high-risk. When the environmental monitoring unit detects an outbreak of new attack activities against the financial industry (ΔR=0.5), T3 and T4 may be adjusted to 0.54 and 0.72 respectively. At this time, the risk level of the server will rise to a serious risk level, triggering the highest level of security response and protection measures, such as increasing real-time monitoring, initiating emergency response procedures, and restricting access.

[0144] like Figure 9 As shown, the network security risk assessment method of the present invention includes the following steps:

[0145] First, a network node acquisition module is used to acquire network node data. Network node data can be acquired through various methods, such as network scanning, system log analysis, and network management systems. In one embodiment of the present invention, network node data includes information such as IP addresses, MAC addresses, port status, service types, and operating system versions. For example, within a medical institution's intranet environment, network node data may include detailed network attribute information for various terminals, including medical devices, patient information systems, and medical workstations.

[0146] Then, a network topology map generation module is used to generate a network topology map based on the network node data. The network topology map generation process includes three steps: node selection, node extraction, and network topology map construction. Specifically, the IP address set of the computer to be tested is first obtained, and then a subset of the IP address set is used to generate a network node set and disconnected nodes are deleted. Finally, a network topology map is generated based on the network node set and connection characteristics. For example, in a university campus network, the IP address set of the entire campus network may be obtained first (such as the 10.0.0.0 / 16 network segment), and then the subnets of focus (such as the academic affairs system, library system, scientific research network, etc.) are selected based on functional divisions. Then, the active nodes in these subnets are screened out, and finally, the connection relationship between these nodes is determined based on traffic monitoring and routing table analysis to generate a network topology map that includes the relationship between each important system.

[0147] Next, the risk prediction module predicts the risk level of each network node based on the network topology. The risk prediction module includes a risk factor classification unit, a weight generation unit, a first risk level calculation unit, and a second risk level calculation unit. The risk factor classification unit divides risk factors into structural factors, state factors, and security policy factors. State factors include IP state factors, software state factors, device state factors, and physical state factors.

[0148] The weight generation unit dynamically calculates risk factor weights based on network environment characteristics and threat landscape. These weights include node importance sub-weights, attack target sub-weights, attack benefit sub-weights, vulnerability sub-weights, accessibility sub-weights, attack success probability sub-weights, attack complexity sub-weights, and security policy factor sub-weights. For example, in a power dispatching system, the weight generation unit might dynamically adjust the weights of various risk factors based on the current grid operating status and external threat intelligence. During periods of high grid load, the weight of the equipment status factor might increase; and when new attack activity against the SCADA system is detected, the weights of the security policy factor and vulnerability factor might increase accordingly.

[0149] The first risk level calculation unit calculates the first risk level for each network node. Specifically, this involves calculating the first risk level of the first risk factor, the first risk level of the second risk factor, and the first risk level of the third risk factor. These three risk levels are then superimposed to obtain the first risk level for each network node. For example, a core accounting system node at a bank has a structure factor risk value of 0.32, a state factor risk value of 0.28, and a security policy factor risk value of 0.15. The resulting first risk level is 0.75.

[0150] The second risk level calculation unit normalizes the first risk level to generate a second risk level, including calculating normalized values of the risk factors and then calculating the second risk level based on the normalized values. Continuing with the above example, if the sum of the risk factor weights for the banking system is 1, the second risk level is also 0.75, indicating that the node is at a high risk level.

[0151] Finally, the risk processing module divides network security risk areas according to risk level and configures protection strategies with different security levels for network nodes at different risk levels. The risk processing module includes a risk level classification unit, which is used to classify security risk into five levels and further configures protection strategies corresponding to the second risk level. The risk level classification unit includes a threshold setting subunit, an environmental monitoring subunit, a threshold adjustment subunit, and a risk grading subunit, enabling adaptive adjustment of risk thresholds and dynamic risk grading.

[0152] In practice, different levels of protection strategies can be configured for network nodes with different risk levels. For example, for low-risk nodes, such as ordinary employees' office computers, basic security measures can be adopted, such as installing antivirus software and configuring basic firewalls. For low-risk nodes, such as departmental file servers, regular vulnerability scanning and patch update mechanisms can be added. For intermediate-risk nodes, such as human resources management systems, intrusion detection systems can be deployed and access controls can be strengthened, such as implementing strong password policies and regular account reviews. For high-risk nodes, such as customer relationship management systems, comprehensive security measures can be implemented, including deep packet inspection, behavioral analysis, and real-time monitoring, as well as regular security assessments and penetration testing. For severe-risk nodes, such as core financial transaction systems or sensitive databases, the most stringent security measures can be adopted, such as network isolation, multi-factor authentication, encrypted communications, privileged account management, and dedicated security personnel.

[0153] The aforementioned cybersecurity risk assessment method enables accurate assessment and grading of cybersecurity risks, providing a scientific basis for differentiated security protection and significantly improving the efficiency and effectiveness of cybersecurity protection. For example, after applying this method, a multinational enterprise focused limited security resources on protecting critical business systems identified as high-risk. While increasing security investment by less than 20%, the number of security incidents decreased by 60% and system availability increased by 25%.

[0154] The network security risk assessment system and method of the present invention achieve accurate assessment and grading of network security risks through innovations such as a three-tier cascade risk factor system, context-aware dynamic weight calculation, a two-tier risk level assessment framework, and adaptive risk grading technology. It has outstanding technical advantages and significant practical value, and can effectively cope with the current complex and changing network security environment.

[0155] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A network security risk assessment system, characterized in that: include: A network topology map generating module is used to receive network node data and generate a network topology map according to the network node data; a risk prediction module, connected to the network topology map generation module, and configured to predict the risk level of each network node based on the network topology map generated by the network topology map generation module, wherein the risk prediction module includes a risk factor division unit, a weight generation unit, a first risk level calculation unit, and a second risk level calculation unit; the risk factor division unit is configured to divide the risk factor into a structural factor, a state factor, and a security policy factor; the state factor includes an IP state factor, a software state factor, a device state factor, and a physical state factor; the weight generation unit dynamically calculates the risk factor weight based on network environment characteristics and threat situation; the first risk level calculation unit is configured to calculate a first risk level for each network node; and the second risk level calculation unit is configured to normalize the first risk level to generate a second risk level; The risk processing module is connected to the risk prediction module and is used to divide the network security risk area according to the risk level predicted by the risk prediction module, and configure protection strategies with different security levels for network nodes with different risk levels.

2. The network security risk assessment system according to claim 1, characterized in that: The network topology diagram generation module includes: A node selection unit, used to obtain a set of IP addresses of the computer to be tested; a node extraction unit, connected to the node selection unit, configured to generate a network node set using a subset of the IP address set; A network topology map generating unit is connected to the node extraction unit and is used to generate the network topology map based on the network node set and connection characteristics, wherein the connection characteristics are the edges and connection directions between the network nodes calculated based on the network node set.

3. The network security risk assessment system according to claim 2, characterized in that: The node extraction unit generates the set of network nodes using a subset of the set of IP addresses through the following steps: generating the set of network nodes based on a subset of the set of IP addresses; Disconnected nodes are deleted from the set of network nodes.

4. The network security risk assessment system according to claim 1, characterized in that: The weight generating unit generates the risk factor weights in the following manner: Calculate node importance sub-weight according to node importance; Determine the attack target sub-weight based on the attack target in the vulnerability data; Determine the attack benefit sub-weight based on the attack benefit in the vulnerability data; Determine vulnerability sub-weights based on the vulnerabilities in the vulnerability data; Determining accessibility sub-weights based on accessibility in vulnerability data; Determine the attack success probability sub-weight according to the attack success probability in the vulnerability data; Determine the attack complexity sub-weight based on the attack complexity in the vulnerability data; The security policy factor sub-weights are determined based on the security policy factors in the vulnerability data.

5. The network security risk assessment system according to claim 4, characterized in that: The first risk level calculation unit calculates the first risk level of each of the network nodes in the following manner: Obtaining the first risk level of the first risk factor according to the weight of the first risk factor and the corresponding risk factor value of the network node; Obtaining the first risk level of the second risk factor according to a second risk factor weight and the corresponding risk factor value of the network node; Obtaining the first risk level of the third risk factor according to the third risk factor weight and the corresponding risk factor value of the network node; The first risk level of each of the network nodes is obtained by calculating a superposition value of the first risk level of the first risk factor, the first risk level of the second risk factor, and the first risk level of the third risk factor.

6. The network security risk assessment system according to claim 5, characterized in that: The second risk level calculation unit obtains the second risk level by the following steps: Calculating a normalized value of the risk factor according to the weight of the risk factor; The second risk level of the network node is calculated according to the normalized value of the risk factor.

7. The network security risk assessment system according to claim 6, characterized in that: The risk processing module also includes: a risk level division unit, which is used to divide the security risk levels into five levels and further set a protection strategy corresponding to the second risk level. The order of the five security risk levels is low risk level, low risk level, medium risk level, high risk level, and serious risk level.

8. The network security risk assessment system according to claim 7, characterized in that: The risk level classification unit includes: a threshold setting subunit, which is used to set the initial threshold of each risk level; An environment monitoring subunit, connected to the threshold setting subunit, for monitoring changes in the network environment; a threshold adjustment subunit, connected to the environment monitoring subunit, for dynamically adjusting the initial threshold according to changes in the network environment to form an adaptive threshold; The risk grading subunit is connected to the threshold adjustment subunit and is used to divide the second risk level into the five security risk levels according to the adaptive threshold.

9. The network security risk assessment system according to claim 1, characterized in that: The first risk level calculation unit and the second risk level calculation unit adopt a two-layer risk level assessment framework. The first risk level calculation unit calculates the risk value corresponding to each risk factor respectively and superimposes them to form a first risk level. The second risk level calculation unit normalizes the first risk level considering the network environment characteristics and business importance to generate a comparable second risk level.

10. A network security risk assessment method, comprising: The following steps are involved: Use the network node acquisition module to obtain network node data; Generate a network topology map based on the network node data using a network topology map generation module; Utilizing a risk prediction module to predict the risk level of each network node based on the network topology graph, wherein the risk prediction module includes a risk factor division unit, a weight generation unit, a first risk level calculation unit, and a second risk level calculation unit, wherein the risk factor division unit divides the risk factor into a structural factor, a state factor, and a security policy factor, wherein the state factor includes an IP state factor, a software state factor, a device state factor, and a physical state factor, wherein the weight generation unit dynamically calculates the risk factor weight based on network environment characteristics and threat situation, wherein the first risk level calculation unit calculates a first risk level for each network node, and wherein the second risk level calculation unit normalizes the first risk level to generate a second risk level; The risk processing module divides network security risk areas according to the risk levels, and configures protection strategies with different security levels for network nodes at different risk levels.

Citation Information

Patent Citations

  • Security risk assessment method for risk cascade of power distribution network under network attack

    CN115361150A

  • Electric power information communication node risk control method, system, equipment and medium

    CN117422291A

  • Network risk assessment model construction method and device, equipment and storage medium

    CN119211040A

  • Network attack risk mapping assessment method and system

    CN119583198A