An intensive platform construction method for information security management
By quantifying the defense effectiveness level and leakage risk index, the problem of insufficient responsiveness to real-time network environment changes in traditional information security management has been solved, realizing the intelligence and automation of information security management and improving the accuracy of defense capabilities and risk assessment.
Patent Information
- Application Number
- CN202510763330.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-06-09
AI Technical Summary
Traditional information security management methods struggle to achieve unified monitoring and coordinated handling of multi-dimensional security elements, lack the ability to respond to real-time changes in the network environment, and are unable to effectively identify new attack patterns, resulting in protection gaps and a disconnect between scoring results and actual risks.
By obtaining the ratio of peak platform traffic to defense limit, the defense effectiveness level is quantified, a status identifier is generated, and a cleaning strategy is invoked based on the defense effectiveness level. Parameters are adjusted to achieve automated closed-loop management. Combined with encryption coverage and access control strength analysis, a data leakage risk value is generated to produce a data leakage risk index.
It enables visualized assessment and rapid response to network security status, improves the timeliness and accuracy of defense capabilities, comprehensively captures potential data breach risks, and provides quantitative risk assessment and dynamic defense strategies.
Smart Images

Figure CN120455133B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to a method for constructing an intensive platform for information security management. BACKGROUND
[0002] In the current wave of digitization sweeping the globe, information security has become a core issue of common concern for countries, enterprises and individuals. With the widespread application of technologies such as cloud computing, the Internet of Things and artificial intelligence, the network environment is becoming increasingly complex, and security incidents such as data breaches and cyber attacks are occurring frequently, posing unprecedented challenges to information security management.
[0003] Traditional information security management methods often rely on scattered security devices and independent management modules, making it difficult to achieve unified monitoring and coordinated disposal of multi-dimensional security elements, resulting in low security protection efficiency and delayed response, which cannot meet the dynamic changing security needs. Therefore, constructing an intensive and intelligent information security management platform to integrate security resources and improve management efficiency has become a key technology direction for ensuring information security.
[0004] Currently, the existing technology in the field of information security management still has some deficiencies. For example, the existing Chinese patent with application number 202110958360.2 discloses a method for constructing an information security scoring system based on artificial intelligence. This scheme crawls industry standard online information security related standard texts, determines suspected updated standard texts, determines industry standard texts that need to be updated, performs structured extraction on the industry standard texts that need to be updated through preset text matching rules to obtain structured standard data, and according to the industry standard texts that need to be updated, obtains the automatic test system and the reviewer manual evaluation result by evaluating the differences between the new and old standard texts and the differences between the new and old scoring standard texts. According to the comparison result, the updated standard text is processed to more accurately solve the problem of updating the standard text.
[0005] However, the above-mentioned patent has the following problems: 1. This scheme mainly relies on static analysis of standard texts (such as directory matching and similarity calculation), and lacks the ability to respond to real-time changes in the network environment. When new attacks occur, the standard text needs to be updated manually to adjust the evaluation indicators, which results in a slow response speed and may lead to gaps in protection when zero-day vulnerabilities or new DDoS attacks occur, as the system relies on preset standard texts and cannot automatically identify attack patterns not defined in the standard.
[0006] 2. This scheme mainly processes structured data of standard texts, and lacks sufficient mining of real-time behavior data (such as abnormal traffic and illegal access) in the network environment, which may cause the scoring result to deviate from the actual risk, even if there are potential attack signs, the score may still remain normal. SUMMARY
[0007] In order to overcome the shortcomings in the background art, the embodiment of the present application provides an intensive platform construction method for information security management, which can effectively solve the problems involved in the above background art.
[0008] The object of the present application can be achieved by the following technical solutions: an intensive platform construction method for information security management, comprising the following steps: S1. obtaining platform traffic peak and defense upper limit, calculating the ratio of traffic peak to defense upper limit, comparing and quantifying the defense effect level by comparing with the preset critical parameter, and generating a state identifier.
[0009] S2. According to the defense effect level, the corresponding cleaning strategy is called, and the change rate of the cleaned traffic peak is calculated based on the traffic peak before cleaning, so as to adjust the parameters in the cleaning strategy.
[0010] S3. Based on the number of encrypted sensitive data and the total number of sensitive data, the encryption coverage rate is calculated, the access control strength is obtained by analyzing the RBAC strategy complexity, and the total weighted exposure risk value is calculated combined with the sensitive data weight.
[0011] S4. Based on the total weighted exposure risk value, the encryption coverage rate and the access control strength, the leakage risk value is obtained, the risk level to which the leakage risk value belongs is determined, and the data leakage risk index is obtained.
[0012] Preferably, the specific analysis method for obtaining platform traffic peak and defense upper limit is: deploying network traffic monitoring equipment at network key nodes, collecting network traffic data in real time according to the preset sampling frequency, and storing the collected network traffic data in the order of data collection time stamp.
[0013] Set the traffic peak statistical time period, in which period, the maximum value of traffic is selected from the collected network traffic data as the traffic peak, and the defense capability parameters pre-configured in the platform are read, the defense capability parameters including bandwidth threshold, data packet processing rate threshold, which are taken as the current defense upper limit of the platform.
[0014] Preferably, the specific analysis method for quantifying the defense effect level is: by dividing the traffic peak by the current defense upper limit of the platform, the ratio of traffic peak to defense upper limit is calculated.
[0015] Three critical parameters of defense effect evaluation interval are preset, and the ratio of calculated traffic peak to defense upper limit is compared with the preset critical parameter for judgment.
[0016] When the ratio is less than the first critical parameter value, the current defense effect level is marked as a "safe level", and a safe state identifier is generated.
[0017] When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as a "warning level", and a warning state identifier is generated.
[0018] When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as an "overload level", and an overload state identifier is generated.
[0019] Preferably, the specific analysis method of step S2 is: S21. According to the defense effect level corresponding to the ratio of the flow peak value to the defense upper limit, the corresponding cleaning strategy is called from the cleaning strategy set stored in the platform management database.
[0020] S22. During the execution of the cleaning strategy, the cleaned network flow data is still collected according to the preset sampling frequency, and the flow peak value in the set time period after cleaning is extracted therefrom, and the change rate of the flow peak value after cleaning is calculated based on the flow peak value after cleaning and the flow peak value before cleaning.
[0021] S23. The change rate of the flow peak value after cleaning is compared with the preset cleaning effect target value, and if the change rate of the flow peak value after cleaning does not reach the preset cleaning effect target value, the parameters in the currently executed cleaning strategy are adjusted, and the above steps are repeated after adjustment until the change rate of the flow peak value after cleaning reaches the preset cleaning effect target value.
[0022] Preferably, the specific analysis method of adjusting the parameters in the currently executed cleaning strategy is: if the change rate of the flow peak value after cleaning is less than or equal to the preset cleaning effect target value, the parameter value having a positive influence on the change rate of the flow peak value is increased, or the parameter value having a negative influence is decreased, and if the change rate of the flow peak value after cleaning is greater than the preset cleaning effect target value, the opposite adjustment operation is performed.
[0023] The deviation value of the change rate of the flow peak value after cleaning and the preset cleaning effect target value is calculated, a parameter-effect response model is constructed based on historical cleaning strategy execution data, and the influence sensitivity coefficient of each parameter on the change rate of the flow peak value is determined.
[0024] Based on the deviation value and the influence sensitivity coefficient of each parameter on the change rate of the flow peak value, the adjustment amount of each parameter is calculated, the calculated adjustment amount is applied to the current parameter value, and a new cleaning strategy parameter configuration is generated.
[0025] Preferably, the specific analysis method of the encryption coverage and the access control strength is: deploying a data monitoring probe in a data transmission link of the platform, counting the exposure times of sensitive data in the platform within a set time period through the data monitoring probe, and simultaneously, scanning all the sensitive data stored in the platform to obtain the number of encrypted sensitive data and the total number of sensitive data respectively.
[0026] Based on the number of encrypted sensitive data and the total number of sensitive data, the encryption coverage of sensitive data is calculated by taking the ratio of the two.
[0027] The complexity score of the RBAC policy is decomposed into three core indicators: the number of roles, the role hierarchical relationship, and the permission assignment rule. For each core indicator, a data value weight and a scoring analysis method are set respectively.
[0028] The scores of the number of roles, the role hierarchical relationship, and the permission assignment rule are multiplied by the corresponding weights respectively, and the final score of the RBAC policy is obtained by adding the weighted scores, which is taken as the access control strength of the platform.
[0029] Preferably, the specific analysis method of the scores of the number of roles, the role hierarchical relationship, and the permission assignment rule is: traversing and counting the total number of roles actually created in the RBAC policy of the current platform, and comparing the counted number of roles with a preset role number score interval table to obtain the score corresponding to the number of roles.
[0030] The hierarchical membership relationship between the roles in the RBAC policy is analyzed, a role hierarchical relationship diagram is drawn, the longest path length from the highest level role to the lowest level role in the role hierarchical relationship diagram is calculated, and a preset role hierarchical depth interval table is compared to obtain the score corresponding to the role hierarchical relationship.
[0031] The minimum permission principle score, the responsibility separation principle score, the data abstraction principle score, the rationality and consistency score, and the scalability and flexibility score are obtained respectively according to the preset rules, and the corresponding score of the permission assignment rule is obtained by weighted summation.
[0032] Preferably, the specific analysis method of the leakage risk value is: extracting the exposure times of each type of sensitive data, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained from the RBAC policy score respectively to form a complete data set.
[0033] The exposure times of each type of sensitive data are multiplied by the corresponding data value weight to obtain a weighted risk value, and then the weighted risk value is summed to obtain a total weighted exposure risk value.
[0034] Based on the total weighted exposure risk value, the encryption coverage, and the access control strength of the platform, the leakage risk value is calculated.
[0035] Preferably, the specific analysis method of the data leakage risk index is: obtaining a preset risk level division rule table, the risk level division rule table comprising a plurality of risk numerical intervals and a risk level corresponding to each risk numerical interval.
[0036] Comparing the calculated leakage risk value with each risk numerical interval in the risk level division rule table to determine the risk level to which the leakage risk value belongs.
[0037] Obtaining a preset corresponding relationship between the risk level and the risk index, obtaining the corresponding risk index according to the determined risk level, and taking the risk index as the data leakage risk index.
[0038] Preferably, the step S4 further comprises: when the leakage risk value is at the boundary of two adjacent risk numerical intervals, determining the risk level to which it belongs according to a preset boundary processing rule, and the boundary processing rule comprises: belonging to a higher risk level interval, belonging to a lower risk level interval, or separately setting a boundary risk level.
[0039] Compared with the prior art, the embodiments of the present application have at least the following advantages or beneficial effects: 1. The present application quantifies the defense effect level by the ratio of the flow peak value to the upper limit of defense, converts the security defense capability into a calculable and comparable numerical index, and generates a state identifier, avoiding the ambiguity of traditional qualitative evaluation.
[0040] 2. The present application calls the corresponding cleaning strategy according to the defense effect level, calculates the change rate of the flow peak value after cleaning, adjusts the parameters in the cleaning strategy, and can form an automatic closed loop of "detection-cleaning-evaluation-tuning", continuously improving the defense capability of the platform.
[0041] 3. The present application obtains the leakage risk value based on the total weighted exposure risk value, the encryption coverage rate and the access control strength analysis, divides the risk level to which the leakage risk value belongs, and obtains the data leakage risk index, which can capture the potential risk of data leakage in all directions and intuitively understand the current data security situation. BRIEF DESCRIPTION OF DRAWINGS
[0042] The present application is further illustrated by the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present application. For ordinary skilled in the art, other drawings can be obtained without creative labor on the premise of the following drawings.
[0043] Figure 1 The present application is further illustrated by the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present application. For ordinary skilled in the art, other drawings can be obtained without creative labor on the premise of the following drawings.
[0044] Figure 2 The present application is further illustrated by the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present application. For ordinary skilled in the art, other drawings can be obtained without creative labor on the premise of the following drawings. Figure 1 The flowchart of step S2 in the present application.
[0045] Figure 3 For Figure 1 The flow chart of adjusting the parameters in the cleaning strategy in step S2. DETAILED DESCRIPTION
[0046] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0047] Please refer to Figure 1 As shown in the figure, the present application provides an intensive platform construction method for information security management, which comprises the following steps: S1. Obtain the platform traffic peak value and the defense upper limit, calculate the ratio of the traffic peak value to the defense upper limit, and compare the ratio with the preset critical parameter to quantify the defense effect level and generate a state identifier.
[0048] The specific analysis method for obtaining the platform traffic peak value and the defense upper limit is: deploying network traffic monitoring equipment at network key nodes, collecting network traffic data in real time according to a preset sampling frequency, and storing the collected network traffic data in the order of data collection time stamp; by deploying monitoring equipment at key nodes and collecting traffic data in real time, the dynamic changes of network traffic can be comprehensively mastered, and abnormal traffic fluctuations can be discovered in time.
[0049] Set a traffic peak value statistical time period, in which, from the collected network traffic data, the maximum traffic value is selected as the traffic peak value, and the defense capability parameters pre-configured in the platform are read, the defense capability parameters including a bandwidth threshold and a data packet processing rate threshold, and the defense capability parameters are taken as the current defense upper limit of the platform; setting the traffic peak value and the defense upper limit provides a quantitative basis for subsequent defense effect evaluation, so that the network carrying capacity and potential risks can be intuitively understood by the manager, and service interruption or attack penetration caused by traffic overload can be avoided.
[0050] The specific analysis method for quantifying the defense effect level is: by dividing the traffic peak value by the current defense upper limit of the platform, the ratio of the traffic peak value to the defense upper limit is calculated.
[0051] The calculated ratio of the traffic peak value to the defense upper limit is compared with the preset critical parameter of the three defense effect evaluation intervals to determine.
[0052] When the ratio is less than the first critical parameter value, the current defense effect level is marked as "safe level", and a safe state identifier is generated.
[0053] When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as a "warning level", and a warning state identifier is generated.
[0054] When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as an "overload level", and an overload state identifier is generated; the defense effect is divided into clear levels, realizing the visualization and standardized evaluation of network security state, facilitating quick response decisions according to different levels, avoiding security disposal delay due to ambiguous judgment, and improving the timeliness and accuracy of overall defense.
[0055] S2. According to the defense effect level, the corresponding cleaning strategy is called, and the change rate of the peak flow value after cleaning is calculated based on the peak flow value before cleaning, so as to adjust the parameters in the cleaning strategy.
[0056] Please refer to Figure 2 The specific analysis method of step S2 is: S21. According to the defense effect level corresponding to the ratio of the peak flow value to the defense upper limit, the corresponding cleaning strategy is called from the cleaning strategy set stored in the platform management database; the cleaning strategy is automatically called according to the defense level, realizing the intelligentization and self-adaptation of traffic cleaning.
[0057] It should be noted that the specific content of the corresponding cleaning strategy is: when the defense effect level is "safe interval", the current cleaning strategy is maintained.
[0058] When the defense effect level is "warning interval", a lightweight cleaning strategy containing intelligent speed limit and connection number limit is enabled.
[0059] When the defense effect level is "overload interval", the traffic is pulled to a third-party cleaning service, and the standby cleaning resource is started.
[0060] S22. During the execution of the cleaning strategy, the network traffic data after cleaning is still collected according to the preset sampling frequency, and the peak flow value in the set time period after cleaning is extracted, and the change rate of the peak flow value after cleaning is calculated based on the peak flow value after cleaning and the peak flow value before cleaning.
[0061] It should be noted that the calculation formula of the change rate of the peak flow value after cleaning is:
[0062] , wherein represents the change rate of the peak flow value after cleaning, , respectively represent the peak flow value after cleaning and the peak flow value before cleaning.
[0063] S23. Compare the change rate of the flow peak value after cleaning with the preset cleaning effect target value. If the change rate of the flow peak value after cleaning does not reach the preset cleaning effect target value, adjust the parameters in the currently executed cleaning strategy, and repeat the above steps after adjustment until the change rate of the flow peak value after cleaning reaches the preset cleaning effect target value. By monitoring the change rate of the flow after cleaning in real time and dynamically adjusting the strategy parameters, the cleaning effect is ensured to be optimal, the DDoS and other flow type attacks are effectively resisted, the stability and availability of network services are ensured, and the business interruption loss caused by attacks is reduced.
[0064] Please refer to Figure 3 The specific analysis method of adjusting the parameters in the currently executed cleaning strategy is as follows: if the change rate of the flow peak value after cleaning is less than or equal to the preset cleaning effect target value, the parameter value that has a positive influence on the flow peak value change rate is increased, or the parameter value that has a negative influence is decreased; if the change rate of the flow peak value after cleaning is greater than the preset cleaning effect target value, the opposite adjustment operation is performed.
[0065] The deviation value of the change rate of the flow peak value after cleaning and the preset cleaning effect target value is calculated, a parameter-effect response model is constructed based on historical cleaning strategy execution data, and the influence sensitivity coefficient of each parameter on the flow peak value change rate is determined; based on the data-driven parameter adjustment method, the parameter-effect response model is constructed combined with historical experience, so that the optimization of the cleaning strategy is more scientific and precise.
[0066] It should be noted that the specific analysis method of constructing the parameter-effect response model is as follows: read the key data generated in the past cleaning strategy execution process, including the parameter configuration of each cleaning strategy (such as filtering rule strength, flow speed threshold, black and white list setting, etc.), flow peak value before / after cleaning, cleaning time consumption, execution timestamp, divide the historical data into training set and validation set, use the training set to train and construct linear regression model, fit the parameter weight by least square method, and directly extract the regression coefficient absolute value determined by the model training to determine the parameter sensitivity coefficient, wherein the larger the value is, the more significant the influence of the parameter on the flow peak value change rate is.
[0067] Based on the deviation value and the influence sensitivity coefficient of each parameter on the flow peak value change rate, the adjustment amount of each parameter is calculated, the calculated adjustment amount is applied to the current parameter value, and a new cleaning strategy parameter configuration is generated; by quantifying the parameter sensitivity coefficient, blind adjustment of the strategy is avoided, the cleaning efficiency is improved, the resource consumption is reduced, the adaptability of the system to different attack scenarios is enhanced, and dynamic and fine flow cleaning is realized.
[0068] It should be noted that the calculation formula of the adjustment amount of each parameter is as follows: , wherein, a deviation value of the flow peak change rate after cleaning from a preset cleaning effect target value, is a preset adjustment step coefficient, is an importance weight of the first parameter, is a number of the first parameter, , and satisfies .
[0069] S3. Calculate the encryption coverage based on the number of encrypted sensitive data and the total number of sensitive data, analyze the access control strength by disassembling the RBAC policy complexity, and calculate the total weighted exposure risk value in combination with the sensitive data weight.
[0070] The specific analysis method of the encryption coverage and the access control strength is: deploying a data monitoring probe in the data transmission link of the platform, counting the exposure times of sensitive data in the platform within a set time period through the data monitoring probe, and simultaneously, scanning all sensitive data stored in the platform to respectively obtain the number of encrypted sensitive data and the total number of sensitive data; by deploying the data monitoring probe to count the exposure and encryption of sensitive data, the data security status can be accurately mastered, the data leakage risk points can be identified, and the basis for encryption policy optimization can be provided.
[0071] Based on the number of encrypted sensitive data and the total number of sensitive data, the ratio of the two is calculated to obtain the encryption coverage of sensitive data.
[0072] The complexity score of the RBAC policy is disassembled into three core indicators of the number of roles, role hierarchical relationship, and permission assignment rule. For each core indicator, a data value weight and a scoring analysis method are respectively set.
[0073] The scores of the number of roles, role hierarchical relationship, and permission assignment rule are respectively multiplied by the corresponding weights, the final score of the RBAC policy is obtained by adding the weighted scores, and the score is taken as the access control strength of the platform; the RBAC policy is scored in multiple dimensions, the access control strength is quantified, the permission assignment vulnerability is found, the permission management system is optimized, and the data security defense line is built from the two dimensions of data encryption and access control.
[0074] The specific analysis method of the scores of the number of roles, role hierarchical relationship, and permission assignment rule is: traversing and counting the total number of roles actually created in the RBAC policy of the current platform, comparing the counted number of roles with a preset role number score interval table to obtain the score corresponding to the number of roles.
[0075] It should be noted that in a specific embodiment, when the number of roles is ≤10, the system role division is relatively simple, the management complexity is low, and the score is 1-2.
[0076] When the number of roles is 11-30, it indicates that the system has certain scale of authority management requirements, and there is a moderate degree of complexity, with a score of 3-5. When the number of roles is > 30, it means that the role system is large and the management difficulty increases significantly, with a score of 6-10.
[0077] The hierarchical membership relationship between the roles in the RBAC policy is analyzed, a role hierarchical relationship diagram is drawn, the longest path length from the highest level role to the lowest level role in the role hierarchical relationship diagram is calculated, and the longest path length is compared with the preset role hierarchical depth interval table to obtain the score corresponding to the role hierarchical relationship.
[0078] According to the preset rules, the minimum privilege principle score, the responsibility separation principle score, the data abstraction principle score, the rationality and consistency score, and the scalability and flexibility score are obtained respectively, and the corresponding score of the permission allocation rule is obtained by weighted summation; the score standard is refined from three dimensions of role quantity, hierarchical relationship and permission allocation rule, realizing comprehensive and deep evaluation of the access control policy, reducing the risk of data leakage and illegal access caused by out-of-control permission, and improving the standardization and security of the overall permission management.
[0079] It should be noted that the specific analysis method of the minimum privilege principle score is: comparing the permission set of each role with the business responsibility demand of the role, counting the number of unnecessary permissions in the role permissions that exceed the required permissions to complete the task, setting a deduction rule according to the proportion of unnecessary permissions, and calculating the minimum privilege principle score.
[0080] The specific analysis method of the responsibility separation principle score is: identifying the roles involved in sensitive business processes in permission allocation, checking whether the key operation permissions such as execution, approval and supervision in the same sensitive process are allocated to different roles, and if a role can independently complete a complete sensitive process, the corresponding score is deducted according to the risk level, and the responsibility separation principle score is obtained.
[0081] The specific analysis method of the data abstraction principle score is: analyzing whether abstracted permissions are used in the permission allocation rule, if abstracted permissions based on business logic (such as "order approval" and "data archiving") are used instead of underlying system operation permissions (such as "database write"), the corresponding score is given according to the abstraction level and coverage, and the data abstraction principle score is calculated.
[0082] The specific analysis method of the rationality and consistency score is: matching the permission allocation rule with the organization business process document and the security policy, checking whether there is a conflict between the permissions of different roles, and according to the severity, the set score is deducted for the cases where the permission allocation does not match the business requirements and the role permissions are contradictory, and the rationality and consistency score is obtained.
[0083] The specific analysis method of the extensibility and flexibility score is: simulating the operation of adding a role, adding a business scenario or modifying the permission of an existing role, evaluating the operation complexity required for adjusting the current permission allocation rule, setting a score standard according to the system configuration modification amount and permission rule change amount required for adjustment, and calculating the extensibility and flexibility score.
[0084] S4. Based on the total weighted exposure risk value, encryption coverage and access control strength, a leakage risk value is analyzed, a risk level to which the leakage risk value belongs is determined, and a data leakage risk index is obtained.
[0085] The specific analysis method of the leakage risk value is: respectively extracting the exposure times of each type of sensitive data, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained by RBAC policy scoring, to form a complete data set.
[0086] The exposure times of each type of sensitive data are multiplied by the corresponding data value weight to obtain a weighted risk value, and then the weighted risk value is summed to obtain a total weighted exposure risk value.
[0087] Based on the total weighted exposure risk value, encryption coverage and access control strength of the platform, a leakage risk value is calculated; the leakage risk value is calculated comprehensively in multiple dimensions to avoid one-sidedness of single index evaluation, the risk priority of high-value data is highlighted by introducing data value weight, and a risk assessment model more suitable for actual scenarios is constructed by combining encryption coverage and access control strength, which can accurately identify the potential risk of data leakage and provide quantitative decision basis for security resource allocation and risk disposal.
[0088] The specific analysis method of the data leakage risk index is: obtaining a preset risk level division rule table, the risk level division rule table including a plurality of risk value intervals and a risk level corresponding to each risk value interval.
[0089] The calculated leakage risk value is compared with each risk value interval in the risk level division rule table to determine the risk level to which the leakage risk value belongs.
[0090] The corresponding relationship between the risk level and the risk index is obtained in advance, the corresponding risk index is obtained according to the determined risk level, and the risk index is taken as the data leakage risk index; the leakage risk value is mapped to an intuitive risk index and level, realizing the hierarchical management of data leakage risk, and the clear risk level division facilitates quick positioning of risk severity and formulating differentiated response strategies.
[0091] The step S4 further comprises: when the leakage risk value is at the boundary of two adjacent risk value intervals, determining the risk grade to which it belongs according to a preset boundary processing rule, the boundary processing rule comprising: classifying it into a higher risk grade interval, classifying it into a lower risk grade interval, or separately setting a boundary risk grade; the setting of the boundary processing rule enhances the rigor of risk assessment, avoids risk misjudgment caused by critical value ambiguity, and improves the reliability and practicality of risk assessment.
[0092] Although the embodiments of the present application have been shown and described above, it should be understood by those skilled in the art that the above embodiments are exemplary and cannot be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application, which are still covered by the protection scope of the present application.
Claims
1. An intensive platform construction method for information security management, characterized in that, Comprise the following steps: S1. Obtain the platform traffic peak and defense upper limit, calculate the ratio of the traffic peak to the defense upper limit, compare the ratio with the preset critical parameter to quantify the defense effect level, and generate a state identifier; S2. According to the defense effect level, the corresponding cleaning strategy is called, and the change rate of the traffic peak after cleaning is calculated based on the traffic peak before cleaning, so as to adjust the parameters in the cleaning strategy; The specific analysis method for adjusting the parameters in the cleaning strategy is: if the change rate of the traffic peak after cleaning is less than or equal to the preset cleaning effect target value, increase the parameter value that has a positive influence on the change rate of the traffic peak, or decrease the parameter value that has a negative influence, if the change rate of the traffic peak after cleaning is greater than the preset cleaning effect target value, execute the opposite adjustment operation; Calculate the deviation value of the change rate of the traffic peak after cleaning and the preset cleaning effect target value, build a parameter-effect response model based on historical cleaning strategy execution data, and determine the influence sensitivity coefficient of each parameter on the change rate of the traffic peak; Based on the deviation value and the influence sensitivity coefficient of each parameter on the change rate of the traffic peak, the adjustment amount of each parameter is calculated, and the calculated adjustment amount is applied to the current parameter value to generate a new cleaning strategy parameter configuration; S3. Calculate the encryption coverage based on the number of encrypted sensitive data and the total number of sensitive data, analyze the access control strength by decomposing the RBAC strategy complexity, and calculate the total weighted exposure risk value combined with the sensitive data weight; S4. Based on the total weighted exposure risk value, the encryption coverage, and the access control strength, the leakage risk value is analyzed, the risk level to which the leakage risk value belongs is determined, and the data leakage risk index is obtained; The specific analysis method of the leakage risk value is: respectively extracting the exposure times of each type of sensitive data, the encryption coverage, the data value weight corresponding to each type of sensitive data, and the access control strength value obtained by RBAC strategy scoring, forming a complete data set; Multiply the exposure times of each type of sensitive data by the corresponding data value weight to obtain the weighted risk value, and then sum the weighted risk values to obtain the total weighted exposure risk value; Based on the total weighted exposure risk value, the encryption coverage, and the access control strength of the platform, the leakage risk value is calculated.
2. The method of claim 1, wherein the method further comprises: The specific analysis method for obtaining the platform traffic peak and the defense upper limit is: Deploy network traffic monitoring equipment at network key nodes, collect network traffic data in real time according to a preset sampling frequency, and store the collected network traffic data in chronological order according to the data collection timestamp; Set a traffic peak statistical time period, filter the maximum traffic value from the collected network traffic data as the traffic peak within the time period, and read the preconfigured defense capability parameters in the platform, including the bandwidth threshold and the data packet processing rate threshold, which are used as the current defense upper limit of the platform.
3. The method of claim 1, wherein the method further comprises: The specific analysis method for quantifying the defense effect level is: Divide the traffic peak by the current defense upper limit of the platform to calculate the ratio of the traffic peak to the defense upper limit; The ratio of the calculated flow peak value to the defense upper limit is compared with the preset critical parameter to determine three defense effect evaluation intervals; When the ratio is less than the first critical parameter value, the current defense effect level is marked as "safe level", and a safe state identifier is generated; When the ratio is greater than or equal to the first critical parameter value and less than the second critical parameter value, the current defense effect level is marked as "warning level", and a warning state identifier is generated; When the ratio is greater than or equal to the second critical parameter value, the current defense effect level is marked as "overload level", and an overload state identifier is generated.
4. The method of claim 1, wherein the method further comprises: The specific analysis method of step S2 is: S21. According to the defense effect level corresponding to the ratio of the flow peak value to the defense upper limit, the corresponding cleaning strategy is called from the cleaning strategy set stored in the platform management database; S22. During the execution of the cleaning strategy, the cleaned network flow data is still collected according to the preset sampling frequency, and the flow peak value in the set time period after cleaning is extracted, and the change rate of the flow peak value after cleaning is calculated based on the flow peak value before and after cleaning; S23. The change rate of the flow peak value after cleaning is compared with the preset cleaning effect target value, if the change rate of the flow peak value after cleaning does not reach the preset cleaning effect target value, the parameters in the currently executed cleaning strategy are adjusted, and the above steps are repeated after adjustment until the change rate of the flow peak value after cleaning reaches the preset cleaning effect target value.
5. The method of claim 1, wherein the method further comprises: The specific analysis method of the encryption coverage and the access control strength is: Deploy data monitoring probes in the data transmission link of the platform, and count the exposure times of sensitive data in the platform in a set time period through the data monitoring probes, and at the same time, scan all sensitive data stored in the platform to obtain the number of encrypted sensitive data and the total number of sensitive data respectively; Based on the number of encrypted sensitive data and the total number of sensitive data, the ratio of the two is calculated to obtain the encryption coverage of sensitive data; The complexity score of RBAC policy is decomposed into three core indicators: role number, role hierarchical relationship and permission assignment rule. For each core indicator, the data value weight and scoring analysis method are set respectively; The role number, role hierarchical relationship and permission assignment rule scores are multiplied by the corresponding weights respectively, and the final score of the RBAC policy is obtained by adding the weighted scores, which is taken as the access control strength of the platform.
6. The method of claim 5, wherein the method further comprises: The specific analysis method of the role number, role hierarchical relationship and permission assignment rule scores is: Traverse and count the total number of roles actually created in the current platform RBAC policy, and compare the counted role number with the preset role number score interval to obtain the role number corresponding score; Analyze the hierarchical membership relationship between roles in the RBAC policy, draw a role hierarchical relationship diagram, calculate the longest path length from the highest level role to the lowest level role in the role hierarchical relationship diagram, and compare it with the preset role hierarchical depth interval table to obtain the role hierarchical relationship corresponding score; The minimum permission principle score, the responsibility separation principle score, the data abstraction principle score, the rationality and consistency score, and the scalability and flexibility score are obtained according to preset rules, and a corresponding score of the permission allocation rule is obtained by weighted summation.
7. The method of claim 1, wherein the method further comprises: The specific analysis method of the data leakage risk index is: A preset risk level division rule table is obtained, and the risk level division rule table includes a plurality of risk numerical intervals and a risk level corresponding to each risk numerical interval; The calculated leakage risk value is compared with each risk numerical interval in the risk level division rule table to determine the risk level to which the leakage risk value belongs; A corresponding relationship between the risk level and the risk index is obtained in advance, and the corresponding risk index is obtained according to the determined risk level, and the risk index is taken as the data leakage risk index.
8. The method of claim 1, wherein the method further comprises: The step S4 further includes: when the leakage risk value is at the boundary of two adjacent risk numerical intervals, a risk level to which the leakage risk value belongs is determined according to a preset boundary processing rule, and the boundary processing rule includes: the leakage risk value is classified into a higher risk level interval, a lower risk level interval, or a separately set boundary risk level.
Citation Information
Patent Citations
Flow cleaning method and device
CN110113435A
Artificial intelligence-based information safety scoring system construction method
CN113886830A