Network asset management system and risk assessment method
Through the network asset management system, the network asset management system integrates multi-channel asset information, and uses security situation indicators and vulnerability knowledge base for risk assessment, solving the adaptive problems of asset surveying and risk discovery, and achieving efficient and accurate risk assessment and resource optimization.
Patent Information
- Application Number
- CN202510567113.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, the asset mapping and risk discovery process lacks adaptive learning capabilities, resulting in insufficient data sharing, duplicate work and waste of resources, making it difficult to effectively deal with complex cyber threats.
It provides a network asset management system that integrates asset surveying and mapping modules, security detection modules, control modules and risk assessment modules, collects asset information through multiple channels, uses security situation indicators to calculate risk assessment values, combines vulnerability knowledge base for model training and fine-tuning, conducts penetration detection and risk assessment, and generates risk assessment reports.
It realizes fast and accurate risk assessment and response, improves the adaptability of network security, optimizes resource allocation, and reduces the possibility and impact of security incidents.
Smart Images

Figure CN120455065A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of asset management, and in particular to a network asset management system and a risk assessment method. Background Art
[0002] As enterprises accelerate digital transformation, IT infrastructure becomes increasingly complex, and cyberattack methods evolve, cybersecurity challenges are becoming increasingly severe. Asset mapping and risk discovery, as fundamental aspects of cybersecurity, are crucial for ensuring the security of an organization's information assets.
[0003] Asset mapping is the process of comprehensively identifying, classifying, and assessing all IT assets within an organization, while risk discovery involves uncovering security weaknesses within these assets that could be exploited by attackers. These two processes have traditionally been considered independent security activities, performed by different tools and personnel with different roles. Inadequate data sharing leads to duplication of effort and wasted resources, and vulnerability detection processes lack adaptive learning capabilities, making them less adaptable to emerging threats. Summary of the Invention
[0004] In view of this, this application provides a network asset management system and risk assessment method that integrates data from the entire system to provide security managers with intelligent decision-making recommendations and scenario simulations to help them make quick and accurate response judgments when facing complex threats.
[0005] According to one aspect of the present application, a network asset management system is provided, comprising:
[0006] The asset mapping module is used to determine the security situation indicators of asset information collected by the target platform through multiple channels, and calculate the risk assessment values of multiple channels based on the security situation indicators;
[0007] The security detection module is used to perform penetration detection on asset information based on the detection sequence, security situation indicators, and test codes associated with the asset information's channel to determine risk vulnerability information of the asset information. The detection sequence is determined by the risk assessment value.
[0008] The control module is used to train the evaluation model based on historical security events and their risk probabilities in the vulnerability knowledge base, and to fine-tune the evaluation model based on updated information from the vulnerability knowledge base;
[0009] The risk assessment module is used to input asset information and risk vulnerability information into the assessment model, and compare the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, through the assessment model, and output the risk probability of the channel to which the asset information belongs.
[0010] Optionally, the asset mapping module includes:
[0011] A data collection module is used to collect asset information from multiple channels, wherein the asset information includes vulnerability information of known vulnerabilities and asset attribute information;
[0012] The multi-source integration module is used to pre-process asset information and associate vulnerability information of known vulnerabilities and asset attribute information from the same channel. Pre-processing includes data cleaning and data standardization.
[0013] An intelligent classification module is used to cluster asset information based on business scenarios and asset access rights in asset attribute information, forming multiple business asset groups under the same channel;
[0014] The risk scoring module is used to input asset information of different business asset groups under different channels into the security situation model, obtain security situation indicators, and calculate risk assessment values based on the security situation indicators. The security situation indicators include: asset importance value, vulnerability exploitability value and / or impact range value. The security situation model is trained based on preset scoring rules.
[0015] Optionally, the risk scoring module calculates a risk assessment value based on the asset importance value, vulnerability exploitability value, and impact scope value, including:
[0016] The sum of the asset importance value, vulnerability exploitability value, and impact range value is calculated as the risk assessment value.
[0017] Optionally, the security detection module includes:
[0018] A vulnerability detection module is used to match the security situation indicator with the preset indicator and use the preset code of the preset indicator that matches the security situation indicator as the test code;
[0019] A first penetration testing module is configured to execute a test code, identify a first vulnerability existing in a target platform, and attack the first vulnerability to obtain vulnerability information of the first vulnerability;
[0020] A vulnerability verification module, configured to cross-verify the first vulnerability and known vulnerabilities of the target platform based on the test code, and determine a second vulnerability that passes the cross-verification;
[0021] The second penetration testing module is used to determine the combined vulnerability and its vulnerability information based on the correlation between the second vulnerability and the asset attribute information if the second vulnerability is applied to the preset business scenario, wherein the combined vulnerability is obtained based on the second vulnerability, the first vulnerability and / or the known vulnerability, and the risk vulnerability information includes the vulnerability information of the first vulnerability and the combined vulnerability.
[0022] Optionally, the second penetration testing module determines the combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information, including:
[0023] Determining a dependency relationship between the current second vulnerability and other vulnerabilities based on the association relationship, where the other vulnerabilities include known vulnerabilities, the first vulnerability, and second vulnerabilities other than the current second vulnerability;
[0024] Generate vulnerability chains based on dependencies;
[0025] Simulate the attack path of the vulnerability chain to determine the first trigger probability of the vulnerability chain;
[0026] If the first trigger probability is greater than the first preset probability, generating a combination test code for the vulnerability chain based on the dependency relationship of the vulnerability chain and the security situation indicator;
[0027] Execute the combined test code to determine the second trigger probability of the vulnerability chain;
[0028] If the second trigger probability is greater than the second preset probability, a combined vulnerability is determined based on the vulnerability chain, and vulnerability information of the combined vulnerability is obtained.
[0029] Optionally, the network asset management system further includes:
[0030] The optimization feedback module is used to match optimization plans based on risk vulnerability information and risk probability, and generate risk assessment reports based on risk probability, asset information, risk vulnerability information, and optimization plans.
[0031] Optionally, the network asset management system further includes:
[0032] A configuration checking module is configured to perform compliance detection on asset attribute information in the asset information and add a first abnormality tag to the asset information that violates the regulations;
[0033] A behavior warning module is configured to add a second abnormality tag to the asset information and output an alarm message if abnormal operations are detected on the asset information, wherein abnormal operations include asset information changes and illegal operations;
[0034] The result aggregation module is used to match the risk level of the channel to which the asset information belongs based on the first abnormal label, the second abnormal label and the risk probability, and add the risk level to the risk assessment report.
[0035] Optionally, the network asset management system further includes:
[0036] The data desensitization module is used to desensitize the first data if there is first data carrying a sensitive identifier in the asset information, and to desensitize the second data in the risk assessment report in response to the display operation of the risk assessment report, wherein the second data is risk probability, asset information, risk vulnerability information, and data in the optimization plan that is located in a preset sensitive position or matches the preset sensitive characters.
[0037] Optionally, the network asset management system further includes:
[0038] A display module, configured to display the risk assessment report in response to a display operation of the risk assessment report;
[0039] and / or,
[0040] The control module is further configured to periodically obtain vulnerability repair progress in response to a repair operation on a vulnerability of the target platform;
[0041] The display module is used to display the vulnerability repair progress through the timeline module.
[0042] and / or,
[0043] The display module is used to display the changed risk vulnerability information and its corresponding asset information in response to changes in the risk vulnerability information of any channel.
[0044] According to another aspect of the present application, a risk assessment method is provided, comprising:
[0045] Determine the security situation indicators of the asset information collected by the target platform through multiple channels, and calculate the risk assessment values of multiple channels based on the security situation indicators;
[0046] Based on the test code associated with the detection sequence, security situation indicators, and the channel to which the asset information belongs, the asset information is subjected to penetration testing to determine the risk vulnerability information of the asset information. The detection sequence is obtained by arranging the risk assessment values;
[0047] The evaluation model is trained based on historical security events and their risk probabilities in the vulnerability knowledge base, and is fine-tuned based on updated information from the vulnerability knowledge base.
[0048] The asset information and risk vulnerability information are input into the assessment model. The assessment model compares the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, and outputs the risk probability of the channel to which the asset information belongs.
[0049] Optionally, the risk assessment method further includes:
[0050] Collect asset information from multiple channels, including vulnerability information of known vulnerabilities and asset attribute information;
[0051] Preprocess asset information and associate vulnerability information of known vulnerabilities and asset attribute information from the same channel. Preprocessing includes data cleaning and data standardization.
[0052] Cluster asset information based on business scenarios and asset access rights in asset attribute information to form multiple business asset groups under the same channel;
[0053] Determine the security posture indicators of the target platform's asset information collected through multiple channels, and calculate the risk assessment values of multiple channels based on the security posture indicators, including:
[0054] The asset information of different business asset groups under different channels is input into the security situation model respectively to obtain security situation indicators, and the risk assessment value is calculated based on the security situation indicators, wherein the security situation indicators include: asset importance value, vulnerability exploitability value and / or impact range value. The security situation model is trained based on preset scoring rules.
[0055] Optionally, a risk assessment value is calculated based on the asset importance value, vulnerability exploitability value, and impact scope value, including:
[0056] The sum of the asset importance value, vulnerability exploitability value, and impact range value is calculated as the risk assessment value.
[0057] Optionally, the risk assessment method further includes:
[0058] Matching the security situation indicator with the preset indicator, and using the preset code of the preset indicator that matches the security situation indicator as the test code;
[0059] Based on the detection sequence, the security situation indicators, and the test code associated with the channel to which the asset information belongs, the asset information is subjected to penetration detection processing to determine risk vulnerability information of the asset information, including:
[0060] Executing the test code to identify a first vulnerability existing in the target platform, and attacking the first vulnerability to obtain vulnerability information of the first vulnerability;
[0061] Cross-verify the first vulnerability and known vulnerabilities of the target platform based on the test code to determine a second vulnerability that passes the cross-verification;
[0062] If the second vulnerability is applied to a preset business scenario, the combined vulnerability and its vulnerability information are determined based on the association between the second vulnerability and the asset attribute information, wherein the combined vulnerability is obtained based on the second vulnerability, the first vulnerability and / or the known vulnerability, and the risk vulnerability information includes the vulnerability information of the first vulnerability and the combined vulnerability.
[0063] Optionally, the second penetration testing module determines the combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information, including:
[0064] Determining a dependency relationship between the current second vulnerability and other vulnerabilities based on the association relationship, where the other vulnerabilities include known vulnerabilities, the first vulnerability, and second vulnerabilities other than the current second vulnerability;
[0065] Generate vulnerability chains based on dependencies;
[0066] Simulate the attack path of the vulnerability chain to determine the first trigger probability of the vulnerability chain;
[0067] If the first trigger probability is greater than the first preset probability, generating a combination test code for the vulnerability chain based on the dependency relationship of the vulnerability chain and the security situation indicator;
[0068] Execute the combined test code to determine the second trigger probability of the vulnerability chain;
[0069] If the second trigger probability is greater than the second preset probability, a combined vulnerability is determined based on the vulnerability chain, and vulnerability information of the combined vulnerability is obtained.
[0070] Optionally, the risk assessment method further includes:
[0071] Match optimization plans based on risk vulnerability information and risk probability, and generate risk assessment reports based on risk probability, asset information, risk vulnerability information, and optimization plans.
[0072] Optionally, the risk assessment method further includes:
[0073] Perform compliance detection on the asset attribute information in the asset information, and add a first abnormality tag to the illegal asset information;
[0074] If an abnormal operation of the asset information is detected, a second abnormal tag is added to the asset information and an alarm message is output, wherein the abnormal operation includes the change operation of the asset information and the illegal operation;
[0075] Based on the first abnormal label, the second abnormal label and the risk probability, the risk level of the channel to which the asset information belongs is matched, and the risk level is added to the risk assessment report.
[0076] Optionally, the risk assessment method further includes:
[0077] If there is first data carrying a sensitive identifier in the asset information, the first data is desensitized, and in response to the display operation of the risk assessment report, the second data in the risk assessment report is desensitized, wherein the second data is risk probability, asset information, risk vulnerability information, and data in the optimization plan that is located in a preset sensitive position or matches the preset sensitive characters.
[0078] Optionally, the risk assessment method further includes:
[0079] In response to the risk assessment report display operation, the risk assessment report is displayed.
[0080] Optionally, the risk assessment method further includes:
[0081] In response to the repair operation of the vulnerability of the target platform, the vulnerability repair progress is periodically obtained and displayed through the timeline module.
[0082] Optionally, the risk assessment method further includes:
[0083] In response to changes in risk vulnerability information of any channel, the changed risk vulnerability information and its corresponding asset information are displayed.
[0084] According to another aspect of the present application, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the above-mentioned risk assessment method are implemented.
[0085] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the steps of the above-mentioned risk assessment method when executing the program.
[0086] Through the collaborative work of the above submodules, the above technical solution leverages multi-source asset information to determine security posture indicators such as asset importance, vulnerability exploitability, and impact. The security posture indicators are then used to calculate a risk assessment for each information channel, which represents the security status and potential risk of the network assets in each channel. The risk assessments are then ranked according to their risk assessments, and customized test code is developed based on the characteristics of each channel and the specific circumstances of the asset. Penetration testing of the asset information is then conducted using this test code and the security posture indicators to identify risk vulnerabilities. This combines asset mapping with vulnerability detection, enabling efficient context-based correlation analysis. This enhances effective information flow and collaborative mechanisms, ensures that risk testing covers the potential attack surface, and rapidly identifies vulnerabilities in high-risk channels. Furthermore, a large-scale model for evaluating channel risk probability is trained using historical security events and their risk probabilities, aggregated from various security device logs. Updates to the vulnerability knowledge base are monitored in real time, and the model is continuously fine-tuned with updated information to address the rapid evolution of new attack vectors and improve the accuracy of risk assessments. After obtaining the large-scale assessment model, it compares the asset attribute information in the asset information with the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs. This allows the possible attack modes and attack trends of the asset information channel to be analyzed from the perspective of data association and time series patterns, and the risk probability is quantified to clarify the potential risk level caused by the vulnerability in each channel. This not only achieves the goal of objective batch processing of resource information from multiple channels, but also helps users prioritize vulnerabilities according to their level of risk and focus resources on addressing high-risk vulnerabilities, minimizing the likelihood and impact of security incidents and avoiding resource waste.
[0087] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0088] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0089] Figure 1 One of the structural diagrams of the network asset management system provided by an embodiment of the present application is shown;
[0090] Figure 2The second structural diagram of the network asset management system provided by the embodiment of the present application is shown;
[0091] Figure 3 A schematic diagram of a risk assessment method according to an embodiment of the present invention is shown;
[0092] Figure 4 A schematic diagram of the electronic structure of a computer device provided in an embodiment of the present application is shown;
[0093] Reference numerals:
[0094] 100 network asset management system, 110 asset mapping module, 111 data collection module, 112 multi-source integration module, 113 intelligent classification module, 114 risk scoring module, 120 security detection module, 121 vulnerability detection module, 122 first penetration testing module, 123 vulnerability verification module, 124 second penetration testing module, 130 control module, 140 risk assessment module, 150 optimization feedback module, 161 configuration check module, 162 behavior warning module, 170 result aggregation module, 180 data desensitization module, 190 display module. DETAILED DESCRIPTION
[0095] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.
[0096] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and are not to be construed as limiting the present application.
[0097] It will be understood by those skilled in the art that, unless expressly stated otherwise, the singular forms "a", "an", "said" and "the" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of this application refers to the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "connected" to another element, it may be directly connected or connected to the other element, or there may be intermediate elements. In addition, "connected" or "connected" as used herein may include wireless connection or wireless fusion. The term "and / or" used herein includes all or any unit and all combinations of one or more associated listed items.
[0098] Now, exemplary embodiments according to the present application will be described in more detail with reference to the accompanying drawings. However, these exemplary embodiments may be implemented in a variety of different forms and should not be construed as being limited to the embodiments set forth herein. It should be understood that these embodiments are provided to make the disclosure of this application thorough and complete and to fully convey the concepts of these exemplary embodiments to those of ordinary skill in the art.
[0099] In this embodiment, a network asset management system 100 is provided. Figure 1 and Figure 2 As shown, the system includes: an asset mapping module 110, a safety detection module 120, a control module 130, and a risk assessment module 140. The asset mapping module is in communication with the safety detection module 120, the control module 130 is in communication with the safety detection module 120 and the risk assessment module 140, and the safety detection module 120 is in communication with the risk assessment module 140.
[0100] Specifically, the asset mapping module 110 is used to determine the security situation indicators of the asset information collected by the target platform through multiple channels, and calculate the risk assessment values of the multiple channels based on the security situation indicators.
[0101] Asset information includes vulnerability information and asset attribute information. Asset attribute information includes hardware device information, software information, sensitive files, databases, cloud resources, domain names, IP addresses, versions, configurations, etc. Multiple channels can include internet forums, websites, blogs, etc. AI crawler technology can be used to collect asset information from multiple channels.
[0102] It should be noted that the security posture indicator includes at least one of the following: Degree of Importance (DOI), Degree of Vulnerability Exploitability (DOVE), and Scope of Impact (SOI).
[0103] The security detection module 120 is used to perform penetration detection on the asset information based on the detection sequence, security situation indicators and test codes associated with the channel to which the asset information belongs, and determine the risk vulnerability information of the asset information.
[0104] The detection order is obtained by arranging the risk assessment values.
[0105] The control module 130 is used to train the evaluation model based on historical security events and their risk probabilities in the vulnerability knowledge base, and to fine-tune the evaluation model based on updated information of the vulnerability knowledge base.
[0106] For example, historical operational data and feedback information (such as alarms, logs, and vulnerability detection data generated within the system) from modules such as asset mapping, security testing, and risk assessment are collected as training data sets. A version management mechanism is used to track updates to the knowledge base, ensuring that historical data is traceable. Outdated information is regularly cleaned and marked, retaining highly reliable, up-to-date, and most relevant data. The latest collected security events, vulnerability information, and attack samples (such as continuously tracking new threats and attack methods in the security field) are organized into the training data set. The knowledge base includes access to major threat intelligence platforms, open source intelligence, and commercial intelligence sources through APIs and subscription services. Incremental learning or online learning algorithms are used to refine and adjust the model. Verification tests are conducted in a sandbox environment to ensure that the new large evaluation model is stable and effective in various scenarios. The verified model automatically replaces the old model in the production environment, and the model performance is continuously monitored for the next round of optimization, forming a closed-loop improvement system. This allows the system to automatically fine-tune or retrain large assessment models by leveraging continuously updated internal and external knowledge bases, ensuring that the system can quickly acquire the latest vulnerability repair solutions, threat intelligence, industry standards, and security best practices, thereby improving detection accuracy and response speed.
[0107] It's worth noting that control module 130 can coordinate risk assessments across different channels and prioritize them based on the risk assessments to determine the order of asset detection. This allows for prioritizing detection of high-risk channels when security resources are limited, promptly identifying those potentially causing significant losses. This also allows for better response to sudden threats and shortens the window of exposure for high-risk vulnerabilities.
[0108] The risk assessment module 140 is used to input asset information and risk vulnerability information into the assessment model, and compare the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, through the assessment model, and output the risk probability of the channel to which the asset information belongs.
[0109] It can be understood that risk attribute information is used to locate cross-asset and cross-vulnerability associated risk clusters, and vulnerability time series information is used to represent risk windows to facilitate the discovery of periodic, trending or sudden risk patterns.
[0110] The network asset management system provided by the present application embodiment, through the collaborative work of the above submodules, can utilize multi-source asset information to determine security status indicators such as asset importance, vulnerability exploitability, and impact range. The security status indicators are then used to calculate a risk assessment value for each information channel, which represents the security status and potential risk of the network assets in each information channel. The risk assessment values are then sorted according to their risk assessment values, and corresponding test code is customized based on the characteristics of different channels and the specific circumstances of the assets. Penetration testing of the asset information is then performed using this test code and security status indicators to determine the risk vulnerability information of the asset information. This combines asset mapping with vulnerability detection, enabling efficient correlation analysis based on a complete context, enhancing effective information flow and collaborative mechanisms, ensuring that risk testing covers potential attack surfaces, and rapidly identifying potential vulnerabilities in high-risk channels. Furthermore, various security device logs are aggregated and a large-scale assessment model for evaluating channel risk probability is trained using recorded historical security events and their risk probabilities. The vulnerability knowledge base is monitored in real time for updates, and the assessment model is continuously fine-tuned with updated information to address the rapid evolution of new attack methods and improve the accuracy of risk assessment. After obtaining the large-scale assessment model, it compares the asset attribute information in the asset information with the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs. This allows the relationship and mutual influence between different assets, as well as the behavior patterns of assets in different time periods, to be analyzed from the perspective of data association and time series patterns. The risk probability is then quantified to clarify the level of risk that may be caused by vulnerabilities in each channel. This not only achieves the goal of objective batch processing of resource information from multiple channels, but also helps users prioritize vulnerabilities according to their level of risk and focus resources on addressing high-risk vulnerabilities, minimizing the likelihood and impact of security incidents and avoiding waste of resources.
[0111] In one embodiment, if Figure 2 As shown, the asset mapping module 110 specifically includes: a data collection module 111 , a multi-source integration module 112 , an intelligent classification module 113 and a risk scoring module 114 .
[0112] Specifically, the data collection module 111 is used to collect asset information from multiple channels.
[0113] Asset information includes vulnerability information and asset attribute information for known vulnerabilities. Vulnerability information describes the details of the vulnerability, such as vulnerability number, disclosure time, vulnerability type, vulnerability address, attack path, and affected components.
[0114] The multi-source integration module 112 is used to pre-process the asset information and associate the vulnerability information of known vulnerabilities from the same channel with the asset attribute information.
[0115] Among them, preprocessing includes data cleaning and data standardization, thereby cleaning out redundant and abnormal data.
[0116] The intelligent classification module 113 is used to cluster asset information based on business scenarios and asset access permissions in the asset attribute information to form multiple business asset groups under the same channel.
[0117] The risk scoring module 114 is used to input the asset information of different business asset groups under different channels into the security situation model respectively, obtain the asset importance value, vulnerability exploitability value and impact range value, and calculate the risk assessment value based on the asset importance value, vulnerability exploitability value and impact range value.
[0118] The security posture model is trained based on preset scoring rules. For example, the asset importance value can be calculated based on information such as business functions, data sensitivity, and compliance requirements. The vulnerability exploitability value indicates the ease with which an attacker can exploit the vulnerability. This value can be calculated by combining technical barriers and external threat intelligence. The impact scope value indicates the assets or business scope that could be affected if the vulnerability is exploited. This value can be calculated based on factors such as asset connectivity, network impact, and asset location, such as data access scope and user impact.
[0119] In this embodiment, the intelligent classification module is able to classify, label, and consolidate the asset information acquired by the data collection module, labeling the asset information according to different categories and attributes. This allows for the accurate selection of specific analysis and testing rules for different asset categories, thereby determining the specific risks they face. This not only provides a more detailed dimension for risk analysis, facilitating more accurate vulnerability scanning, better distinguishing between high-value and low-value assets, and rationalizing resource allocation, but also enables a more comprehensive assessment of the system's risk profile by merging asset data from different channels.
[0120] Furthermore, Risk Assessment Value (RAV) = Degree of Importance (DOI) + Degree of Vulnerability Exploitation (DOVE) + Sphere of Influence (SOI).
[0121] In one embodiment, if Figure 2 As shown, the security detection module 120 specifically includes: a vulnerability detection module 121 , a first penetration testing module 122 , a vulnerability verification module 123 and a second penetration testing module 124 .
[0122] Specifically, the vulnerability detection module 121 is used to match the security situation indicator with a preset indicator, and use the preset code of the preset indicator that matches the security situation indicator as the test code.
[0123] The first penetration testing module 122 is used to execute the test code, identify the first vulnerability existing in the target platform, and attack the first vulnerability to obtain vulnerability information of the first vulnerability.
[0124] It is understandable that the first vulnerability is a possible vulnerability detected by scanning through a channel-specific test code. The first vulnerability may be a known vulnerability in the asset information or an unknown vulnerability.
[0125] The vulnerability verification module 123 is used to cross-verify the first vulnerability and the known vulnerabilities of the target platform based on the test code, and determine a second vulnerability that passes the cross-verification.
[0126] It should be noted that if the first vulnerabilities include all known vulnerabilities, cross-validation can be performed directly on different first vulnerabilities; if the first vulnerabilities only include some known vulnerabilities, cross-validation needs to be performed on the union of the first vulnerabilities and the known vulnerabilities.
[0127] The second penetration testing module 124 is configured to determine a combined vulnerability and vulnerability information thereof based on an association relationship between the second vulnerability and the asset attribute information if the second vulnerability is applied to a preset business scenario.
[0128] The combined vulnerability is derived based on the second vulnerability, the first vulnerability, and / or known vulnerabilities, and the risk vulnerability information includes vulnerability information for the first vulnerability and the combined vulnerability. Preset business scenarios represent application scenarios that are vulnerable to attack or have high security risks. They can be reasonably set based on system functions, such as payment scenarios involving monetary transactions and data query scenarios involving private information.
[0129] In this embodiment, based on the security situation index, the test code (POC) that meets the specific scenario of the channel to which it belongs is dynamically matched, and the vulnerability attack logic in the specific scenario is simulated using the test code, and the first vulnerability existing in the target platform is identified and attacked. In this way, known vulnerabilities, configuration defects, common risks, etc. are quickly screened to avoid unnecessary scanning, which helps to improve the efficiency and accuracy of vulnerability detection and reduce the possibility of false positives. Then, the vulnerability verification module generates multiple exploitable POCs for each vulnerability and cross-validates them to determine the true exploitability of the vulnerability, further reduce false positives and ensure the accuracy of subsequent risk assessment data. And for the second vulnerability with higher exploitability. On the basis of standard penetration testing, the second vulnerability acting in the high-risk scenario is further screened out through business scenarios, and the correlation between it and asset attribute information is simulated into a real attack scenario, and the possibility of hidden risks and vulnerability combination exploitation is found in a multi-angle and multi-stage manner, and then the POC of the combined attack is generated for deep penetration testing to improve the accuracy and reliability of vulnerability scanning.
[0130] For example, asset information is collected and confirmed (which can be provided by the asset mapping module) to clarify the test scope and objectives. Test priorities and key areas are determined based on risk assessment values. The AI vulnerability detection engine unit is called to automatically generate a personalized POC list and perform vulnerability scans based on the pre-set rules. Automated routine scans are performed to discover common vulnerabilities and provide feedback on basic test results. Multiple independently generated POCs are used to cross-validate each suspected vulnerability, filter out false positives, and confirm the true exploitability of the vulnerability. Complex vulnerabilities and potential risk combinations are further verified through multi-angle verification and attack combination testing.
[0131] Furthermore, the second penetration testing module 124 determines the combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information, including: determining the dependency relationship between the current second vulnerability and other vulnerabilities based on the association relationship; generating a vulnerability chain based on the dependency relationship; simulating the attack path of the vulnerability chain to determine the first triggering probability of the vulnerability chain; if the first triggering probability is greater than the first preset probability, generating a combined test code for the vulnerability chain based on the dependency relationship and security situation indicators of the vulnerability chain; executing the combined test code to determine the second triggering probability of the vulnerability chain; if the second triggering probability is greater than the second preset probability, determining the combined vulnerability based on the vulnerability chain, and obtaining the vulnerability information of the combined vulnerability.
[0132] Among them, other vulnerabilities include known vulnerabilities, first vulnerabilities, and second vulnerabilities other than the current second vulnerability.
[0133] In this embodiment, network attacks often exploit the synergy of multiple vulnerabilities to achieve their objectives. By determining the dependency relationship between the current second vulnerability and other vulnerabilities and generating a vulnerability chain, the connections and interactions between multiple vulnerabilities can be clearly visualized, avoiding focusing solely on a single vulnerability while ignoring its potential connections with other vulnerabilities. Simulating the attack path of the vulnerability chain and determining the first trigger probability can analyze the vulnerability chain's exploitability from the attacker's perspective. If the first trigger probability is greater than the first preset probability, indicating that the vulnerability chain presents a high risk, a combination test code is generated, taking into account the relationships between the vulnerabilities and the current security status of the system. The combination test code is executed to determine the second trigger probability and compared with the second preset probability to further verify the vulnerability chain's exploitability in a real-world environment. If the second trigger probability is greater than the second preset probability, indicating that the vulnerability chain is highly likely to be exploited, it is output as a combined vulnerability and detailed vulnerability information for the combined vulnerability is obtained. This allows for the precise location of complex vulnerability combinations, enhances the ability to identify unknown vulnerabilities, and facilitates a comprehensive understanding of the security threats facing the system. Furthermore, it avoids overinvesting in low-risk vulnerabilities, optimizes resource allocation, and improves security work efficiency and effectiveness.
[0134] In one obtained, such as Figure 2 As shown, the network asset management system 100 further includes an optimization feedback module 150 . The risk assessment module 140 is in communication with the optimization feedback module 150 .
[0135] Specifically, the optimization feedback module 150 is used to match optimization solutions based on risk vulnerability information and risk probability, and generate a risk assessment report for the target platform based on risk probability, asset information, risk vulnerability information, and optimization solutions.
[0136] In this embodiment, a feasible remediation optimization solution is provided and a report is output based on vulnerability characteristics and context. This can provide security recommendations based on the organization's specific environment and business needs, forming a reliable security return on investment analysis.
[0137] In one embodiment, if Figure 2 As shown, the network asset management system 100 further includes a configuration check module 161, a behavior warning module 162, and a result aggregation module 170. The configuration check module 161, the behavior warning module 162, and the result aggregation module 170 are communicatively connected. The configuration check module 161, the behavior warning module 162, and the result aggregation module 170 are all communicatively connected to the control module 130, so that the control module 130 can summarize the data processing results of the configuration check module 161, the behavior warning module 162, and the result aggregation module 170.
[0138] Specifically, the configuration checking module 161 is used to perform compliance detection on the asset attribute information in the asset information, and add a first abnormality tag to the illegal asset information.
[0139] The behavior warning module 162 is used to add a second abnormality tag to the asset information and output an alarm message if abnormal operation of the asset information is detected, wherein the abnormal operation includes the change operation of the asset information and the illegal operation.
[0140] The result aggregation module 170 is used to match the risk level of the channel to which the asset information belongs based on the first abnormality label, the second abnormality label and the risk probability, and add the risk level to the risk assessment report.
[0141] In this embodiment, the configuration check module is used to check whether the asset attribute information such as the server's password policy and access control permissions in the asset information meets the security standards through multi-dimensional detection means such as legal terms matching, document format compliance, and logical contradictions, so as to timely discover the security risks in the asset configuration, ensure that the various configurations of the system meet its operating requirements, and avoid system failures due to incorrect or unreasonable configurations. At the same time, the behavior warning module can be used to detect abnormal operations of asset information. When abnormal operations occur, a second abnormal label is added to the asset information, and an alarm message is output, so that the user can quickly learn about the possible security issues in the system and take corresponding measures before the potential threats cause serious losses. The purpose of continuous monitoring of asset configuration and operation is achieved to meet the requirements of relevant laws and regulations and regulatory agencies for information security management. In addition, the result aggregation module can be used to integrate the first abnormal label, the second abnormal label and the risk probability, and to grade the risks existing in each channel.
[0142] Among them, abnormal operations include changes to asset information and illegal operations, such as phishing email semantic trap text, forged official seals and signatures, voiceprint fraud attacks, etc.
[0143] In one embodiment, if Figure 2 As shown, the network asset management system 100 also includes: a data desensitization module 180.
[0144] Specifically, the data desensitizing module 180 is used to desensitize the first data if there is first data carrying a sensitive identifier in the asset information, and to desensitize the second data in the risk assessment report in response to the display operation of the risk assessment report.
[0145] The second data includes risk probability, asset information, risk vulnerability information, and data in the optimization plan that is located in pre-set sensitive locations or matches pre-set sensitive characters. Pre-set sensitive locations or matching pre-set sensitive characters can be determined based on actual business scenarios and user permissions. After the user's identity is verified through multi-factor authentication, the user is granted corresponding permissions based on minimum access rights.
[0146] In this embodiment, after obtaining the asset information, it is checked whether there is first data with a sensitive identifier in the asset information, that is, data that itself has sensitive attributes (such as customer ID number, bank card number, login password). If the first data exists, it is desensitized using a preset desensitization method, so that the first data is in an unrecognizable or difficult-to-recognize format during system transmission, analysis, and storage, effectively protecting the original data and effectively reducing the risk of data leakage. At the same time, no additional performance burden is added when reading and querying the data. Furthermore, when displaying the risk assessment report, the second data is desensitized. This allows users to view different sensitive information under different scenario permissions, avoiding information leakage while ensuring that the report data is referenceable. Desensitization strategies are then selected according to different types of data to provide the system with more flexible access control.
[0147] It is understandable that the first data may be desensitized by using methods such as substitution algorithms and numerical transformation, and the second data may be desensitized by using methods such as deterministic shielding, disordering and shuffling.
[0148] Further, if Figure 2 As shown, the network asset management system 100 further includes: a display module 190 .
[0149] In one embodiment, the display module 190 is configured to display the risk assessment report in response to a display operation of the risk assessment report.
[0150] In another embodiment, the control module 130 is further configured to periodically obtain vulnerability repair progress in response to a repair operation on a vulnerability of the target platform; and the display module 190 is configured to display the obtained vulnerability repair progress through a timeline module.
[0151] In another embodiment, the display module 190 is configured to display the changed risk vulnerability information and its corresponding asset information in response to changes in the risk vulnerability information of any channel.
[0152] Each module in the aforementioned network asset management system may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor within a computer device in the form of hardware, or may be stored in a computer device memory in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0153] In this embodiment, a network asset management system is provided, such as Figure 3 As shown, the method includes:
[0154] Step 301: Determine security situation indicators of asset information collected by a target platform through multiple channels, and calculate risk assessment values of the multiple channels based on the security situation indicators.
[0155] Among them, the security situation indicators include at least one of the following: asset importance value, vulnerability exploitability value, and impact range value.
[0156] Step 302 : Based on the detection sequence, security situation indicators, and the test code associated with the channel to which the asset information belongs, a penetration detection process is performed on the asset information to determine risk vulnerability information of the asset information.
[0157] The detection order is obtained by arranging the risk assessment values.
[0158] Step 303: training the large evaluation model based on historical security events and their risk probabilities in the vulnerability knowledge base, and fine-tuning the large evaluation model based on updated information of the vulnerability knowledge base.
[0159] In step 304, the asset information and risk vulnerability information are input into the assessment model. The assessment model compares the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, and outputs the risk probability of the channel to which the asset information belongs.
[0160] In this embodiment, asset information from multiple sources can be used to determine security indicators such as asset importance, vulnerability exploitability, and impact. The security indicators are then used to calculate a risk assessment for each information channel, which represents the security status and potential risk of the network assets in each channel. Assets are ranked according to their risk assessment values, and customized test code is developed based on the characteristics of each channel and the specific circumstances of the asset. This test code and security indicators are then used to conduct penetration testing on the asset information to determine its risk vulnerability information. This combines asset mapping with vulnerability detection, enabling efficient context-based correlation analysis. This enhances effective information flow and collaboration, ensures that risk testing covers potential attack surfaces, and rapidly identifies vulnerabilities in high-risk channels. Furthermore, various security device logs are aggregated and a large-scale model for evaluating channel risk probability is trained using recorded historical security events and their risk probabilities. Updates to the vulnerability knowledge base are monitored in real time, and the large-scale model is continuously fine-tuned with updated information to address the rapid evolution of new attack vectors and improve the accuracy of risk assessments. After obtaining the large-scale assessment model, it compares the asset attribute information in the asset information with the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs. This allows the possible attack modes and attack trends of the asset information channel to be analyzed from the perspective of data association and time series patterns, and the risk probability is quantified to clarify the potential risk level caused by the vulnerability in each channel. This not only achieves the goal of objective batch processing of resource information from multiple channels, but also helps users prioritize vulnerabilities according to their level of risk and focus resources on addressing high-risk vulnerabilities, minimizing the likelihood and impact of security incidents and avoiding resource waste.
[0161] Furthermore, the risk assessment method also includes: collecting asset information from multiple channels, wherein the asset information includes vulnerability information of known vulnerabilities and asset attribute information; preprocessing the asset information, and associating the vulnerability information of known vulnerabilities and asset attribute information from the same channel, wherein the preprocessing includes data cleaning and data standardization; clustering the asset information based on the business scenarios and asset access rights in the asset attribute information to form multiple business asset groups under the same channel.
[0162] Furthermore, security situation indicators of asset information collected by the target platform through multiple channels are determined, and risk assessment values of multiple channels are calculated based on the security situation indicators, including: inputting asset information of different business asset groups under different channels into the security situation model respectively to obtain security situation indicators, and calculating risk assessment values based on the security situation indicators, wherein the security situation indicators include: asset importance value, vulnerability exploitability value and / or impact range value, and the security situation model is trained based on preset scoring rules.
[0163] Calculating a risk assessment value based on the asset importance value, the vulnerability exploitability value, and the impact range value includes: calculating the sum of the asset importance value, the vulnerability exploitability value, and the impact range value as the risk assessment value.
[0164] Furthermore, the risk assessment method further includes: matching the security situation indicator with a preset indicator, and using a preset code of the preset indicator that matches the security situation indicator as a test code.
[0165] Based on the detection order, the security situation indicators and the test code associated with the channel to which the asset information belongs, the asset information is subjected to penetration detection processing to determine the risk vulnerability information of the asset information, including: executing the test code to identify a first vulnerability existing in the target platform, and attacking the first vulnerability to obtain vulnerability information of the first vulnerability; cross-verifying the first vulnerability and the known vulnerabilities of the target platform based on the test code to determine a second vulnerability that passes the cross-verification; if the second vulnerability is applied to a preset business scenario, determining a combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information, wherein the combined vulnerability is obtained based on the second vulnerability, the first vulnerability and / or the known vulnerability, and the risk vulnerability information includes the vulnerability information of the first vulnerability and the combined vulnerability.
[0166] Furthermore, the second penetration testing module determines the combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information, including: determining the dependency relationship between the current second vulnerability and other vulnerabilities based on the association relationship, wherein the other vulnerabilities include known vulnerabilities, the first vulnerability and the second vulnerability other than the current second vulnerability; generating a vulnerability chain based on the dependency relationship; performing attack path simulation on the vulnerability chain to determine the first triggering probability of the vulnerability chain; if the first triggering probability is greater than the first preset probability, generating a combined test code for the vulnerability chain based on the dependency relationship and security situation indicators of the vulnerability chain; executing the combined test code to determine the second triggering probability of the vulnerability chain; if the second triggering probability is greater than the second preset probability, determining the combined vulnerability based on the vulnerability chain, and obtaining the vulnerability information of the combined vulnerability.
[0167] Furthermore, the risk assessment method also includes: matching an optimization plan based on risk vulnerability information and risk probability, and generating a risk assessment report for the target platform based on risk probability, asset information, risk vulnerability information, and optimization plan.
[0168] Furthermore, the risk assessment method also includes: performing compliance detection on the asset attribute information in the asset information, and adding a first abnormal label to the illegal asset information; if an abnormal operation of the asset information is detected, adding a second abnormal label to the asset information, and outputting an alarm message, wherein the abnormal operation includes the change operation of the asset information and the illegal operation; based on the first abnormal label, the second abnormal label and the risk probability, matching the risk level of the channel to which the asset information belongs, and adding the risk level to the risk assessment report.
[0169] Furthermore, the risk assessment method also includes: if there is first data carrying a sensitive identifier in the asset information, the first data is desensitized, and in response to the display operation of the risk assessment report, the second data in the risk assessment report is desensitized, wherein the second data is risk probability, asset information, risk vulnerability information, data in the optimization plan located in a preset sensitive position or consistent with preset sensitive characters.
[0170] Furthermore, the risk assessment method further includes: in response to a display operation of the risk assessment report, displaying the risk assessment report.
[0171] Furthermore, the risk assessment method further includes: in response to a repair operation on a vulnerability of the target platform, periodically obtaining vulnerability repair progress, and displaying the vulnerability repair progress through a timeline module.
[0172] Furthermore, the risk assessment method further includes: in response to changes in risk vulnerability information of any channel, displaying the changed risk vulnerability information and its corresponding asset information.
[0173] It should be noted that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0174] For the specific limitations of risk assessment methods, please refer to the limitations of network asset management systems above and will not be repeated here.
[0175] Based on the above Figure 3 The method shown in FIG. 1 is a method for performing the above-mentioned operation. Accordingly, the embodiment of the present application further provides a readable storage medium having a computer program stored thereon. When the computer program is executed by the processor, the computer program is executed as shown in FIG. Figure 3 The risk assessment method shown.
[0176] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each implementation scenario of the present application.
[0177] Based on the above Figure 1 and Figure 2 The system structure shown, and Figure 3 The method embodiment shown is as follows Figure 4 As shown, the embodiment of the present application further provides a computer device, the computer device 400 includes a processor 401 and a memory 402, the memory 402 stores a program or instruction that can be run on the processor 401, and the program or instruction is executed by the processor 401 to achieve the above-mentioned Figure 3 The risk assessment method shown.
[0178] The memory 402 can be used to store software programs and various data. The memory 402 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 402 may include volatile memory or non-volatile memory, or the memory 402 may include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 402 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0179] Processor 401 may include one or more processing units. Optionally, processor 401 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 401.
[0180] The computer device may specifically be a personal computer, a server, a network device, etc.
[0181] Optionally, the computer device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a Wi-Fi module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a Bluetooth interface, a Wi-Fi interface), etc.
[0182] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the computer device, and may include more or fewer components, or a combination of certain components, or different component arrangements.
[0183] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform, or by means of hardware. The present application determines the security situation indicators of asset information collected by a target platform through multiple channels, and calculates risk assessment values for the multiple channels based on the security situation indicators, wherein the security situation indicators include at least one of the following: an asset importance value, a vulnerability exploitability value, and an impact range value; performs penetration detection on the asset information based on the detection order, the security situation indicators, and the test code associated with the channel to which the asset information belongs, and determines the risk vulnerability information of the asset information, wherein the detection order is obtained by arranging the risk assessment values; trains an evaluation model based on historical security events and their risk probabilities in a vulnerability knowledge base, and fine-tunes the evaluation model based on updated information from the vulnerability knowledge base; inputs the asset information and risk vulnerability information into the evaluation model, and compares the asset attribute information in the asset information with the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, through the evaluation model, and outputs the risk probability of the channel to which the asset information belongs; matches an optimization plan based on the risk vulnerability information and the risk probability, and generates a risk assessment report for the target platform based on the risk probability, the asset information, the risk vulnerability information, and the optimization plan. The embodiments of the present application utilize multi-source asset information to determine security indicators such as asset importance, vulnerability exploitability, and impact range. The security indicators are then used to calculate a risk assessment value for each information channel, which represents the security status and potential risk of the network assets in each information channel. The risk assessment values are then sorted by risk assessment value, and corresponding test code is customized based on the characteristics of each channel and the specific circumstances of the asset. This test code and security indicators are then used to conduct penetration testing on the asset information to determine the risk vulnerability information of the asset information. This combines asset mapping with vulnerability detection, enabling efficient correlation analysis based on a complete context, enhancing effective information flow and coordination mechanisms, ensuring that risk testing covers potential attack surfaces, and rapidly identifying potential vulnerabilities in high-risk channels. Furthermore, various security device logs are aggregated and a large-scale assessment model for evaluating channel risk probability is trained using recorded historical security events and their risk probabilities. Updates to the vulnerability knowledge base are monitored in real time, and the assessment model is continuously fine-tuned with updated information to address the rapid evolution of new attack methods and improve the accuracy of risk assessments. After obtaining the large assessment model, the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability time series information of the channel to which the asset information belongs, are compared through the large assessment model. In this way, the relationship and mutual influence between different assets, as well as the behavior patterns of assets in different time periods, are analyzed from the perspective of data association and time series patterns, and the risk probability is quantified to clarify the degree of risk that may be caused by vulnerabilities in each channel.This not only achieves the objective of batch processing information from multiple channels, but also helps users prioritize vulnerabilities based on risk and focus resources on addressing high-risk vulnerabilities, minimizing the likelihood and impact of security incidents and avoiding resource waste. Finally, based on vulnerability characteristics and context, it provides a feasible remediation and optimization solution and outputs a report. This provides future security recommendations tailored to an organization's specific environment and business needs, forming a reliable security return on investment analysis.
[0184] Those skilled in the art will understand that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily required to implement the present application. Those skilled in the art will understand that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the implementation scenario description, or can be changed accordingly and located in one or more devices different from the implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple sub-modules.
[0185] The serial numbers of the above application are for descriptive purposes only and do not represent the advantages or disadvantages of the implementation scenarios. The above disclosure only discloses several specific implementation scenarios of the present application, but the present application is not limited thereto. Any changes that can be conceived by those skilled in the art should fall within the scope of protection of the present application.
Claims
1. A network asset management system, characterized in that: The network asset management system includes: An asset mapping module, configured to determine security situation indicators of asset information collected by a target platform through multiple channels, and to calculate risk assessment values of the multiple channels based on the security situation indicators; a security detection module, configured to perform penetration detection on the asset information based on a detection sequence, the security situation indicator, and a test code associated with the channel to which the asset information belongs, to determine risk vulnerability information of the asset information, wherein the detection sequence is obtained by arranging the risk assessment values; A control module is used to train an evaluation model based on historical security events and their risk probabilities in a vulnerability knowledge base, and to fine-tune the evaluation model based on updated information of the vulnerability knowledge base; The risk assessment module is used to input the asset information and the risk vulnerability information into the assessment model, compare the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability timing information of the channel to which the asset information belongs, through the assessment model, and output the risk probability of the channel to which the asset information belongs.
2. The network asset management system according to claim 1, characterized in that: The asset mapping module includes: a data collection module, configured to collect the asset information from the multiple channels, wherein the asset information includes vulnerability information of known vulnerabilities and asset attribute information; A multi-source integration module, configured to pre-process the asset information and associate the vulnerability information of the known vulnerabilities with the asset attribute information from the same channel, wherein the pre-processing includes data cleaning and data standardization; An intelligent classification module, configured to cluster the asset information based on the business scenarios and asset access rights in the asset attribute information to form multiple business asset groups under the same channel; The risk scoring module is used to input the asset information of different business asset groups under different channels into the security situation model respectively, obtain the security situation indicators, and calculate the risk assessment value based on the security situation indicators, wherein the security situation indicators include: asset importance value, vulnerability exploitability value and / or impact range value, and the security situation model is trained based on preset scoring rules.
3. The network asset management system according to claim 2, characterized in that: The risk scoring module calculates the risk assessment value based on the asset importance value, the vulnerability exploitability value, and the impact scope value, including: The sum of the asset importance value, the vulnerability exploitability value, and the impact range value is calculated as the risk assessment value.
4. The network asset management system according to claim 2, characterized in that: The safety detection module includes: a vulnerability detection module, configured to match the security situation indicator with a preset indicator, and use a preset code of the preset indicator that matches the security situation indicator as the test code; a first penetration testing module, configured to execute the test code, identify a first vulnerability existing in the target platform, and attack the first vulnerability to obtain vulnerability information of the first vulnerability; a vulnerability verification module, configured to cross-verify the first vulnerability and known vulnerabilities of the target platform based on the test code, and determine a second vulnerability that passes the cross-verification; The second penetration testing module is used to determine a combined vulnerability and its vulnerability information based on the association between the second vulnerability and the asset attribute information if the second vulnerability is applied to a preset business scenario, wherein the combined vulnerability is obtained based on the second vulnerability, the first vulnerability and / or the known vulnerability, and the risk vulnerability information includes vulnerability information of the first vulnerability and the combined vulnerability.
5. The network asset management system according to claim 4, characterized in that: The second penetration testing module determines a combined vulnerability and vulnerability information thereof based on the association between the second vulnerability and the asset attribute information, including: Determine, based on the association relationship, a dependency relationship between the current second vulnerability and other vulnerabilities, wherein the other vulnerabilities include the known vulnerabilities, the first vulnerability, and the second vulnerabilities other than the current second vulnerability; generating a vulnerability chain based on the dependency relationship; Performing an attack path simulation on the vulnerability chain to determine a first trigger probability of the vulnerability chain; If the first trigger probability is greater than a first preset probability, generating a combination test code for the vulnerability chain based on the dependency relationship of the vulnerability chain and the security posture indicator; executing the combined test code to determine a second trigger probability of the vulnerability chain; If the second trigger probability is greater than a second preset probability, the combined vulnerability is determined based on the vulnerability chain, and vulnerability information of the combined vulnerability is obtained.
6. The network asset management system according to any one of claims 1 to 5, characterized in that: The network asset management system further includes: The optimization feedback module is used to match the optimization plan based on the risk vulnerability information and the risk probability, and generate a risk assessment report based on the risk probability, the asset information, the risk vulnerability information, and the optimization plan.
7. The network asset management system according to claim 6, characterized in that: The network asset management system further includes: A configuration checking module is configured to perform compliance detection on the asset attribute information in the asset information and add a first abnormality tag to the asset information that violates the regulations; a behavior warning module, configured to add a second abnormality tag to the asset information and output an alarm message if abnormal operation of the asset information is detected, wherein the abnormal operation includes a change operation of the asset information and an illegal operation; A result aggregation module is used to match the risk level of the channel to which the asset information belongs based on the first abnormality label, the second abnormality label and the risk probability, and add the risk level to the risk assessment report.
8. The network asset management system according to claim 6, characterized in that: The network asset management system further includes: A data desensitizing module is used to desensitize first data carrying a sensitive identifier if the asset information contains the first data, and to desensitize second data in the risk assessment report in response to a display operation of the risk assessment report, wherein the second data is the risk probability, the asset information, the risk vulnerability information, and the data in the optimization plan that is located in a preset sensitive position or matches a preset sensitive character.
9. The network asset management system according to claim 6, characterized in that: The network asset management system further includes: a display module, configured to display the risk assessment report in response to a display operation of the risk assessment report; and / or, The control module is further configured to periodically obtain vulnerability repair progress in response to a repair operation on a vulnerability of the target platform; The display module is used to display the vulnerability repair progress through the timeline module; and / or, The display module is used to display the changed risk vulnerability information and the corresponding asset information in response to changes in the risk vulnerability information of any channel.
10. A risk assessment method, characterized in that: The method comprises: Determining security situation indicators of asset information collected by the target platform through multiple channels, and calculating risk assessment values of the multiple channels based on the security situation indicators; Performing penetration testing on the asset information based on a detection order, the security situation indicator, and a test code associated with the channel to which the asset information belongs, to determine risk vulnerability information of the asset information, wherein the detection order is obtained by arranging the risk assessment values; Training an evaluation model based on historical security events and their risk probabilities in a vulnerability knowledge base, and fine-tuning the evaluation model based on updated information from the vulnerability knowledge base; The asset information and the risk vulnerability information are input into the assessment model, and the asset attribute information in the asset information and the risk attribute information of the channel to which the asset information belongs, as well as the risk vulnerability information and the vulnerability timing information of the channel to which the asset information belongs are compared by the assessment model, and the risk probability of the channel to which the asset information belongs is output.
Citation Information
Cited By
Network security threat assessment method and system
CN122027274A
A cyber-security threat assessment method and system
CN122027274B