Network security evaluation method and system used in equivalent security evaluation
By collecting a variety of data to calculate network security risk indicators, the problem of reducing assessment accuracy caused by single data types in the prior art is solved, and a more comprehensive security assessment and rapid response are achieved.
Patent Information
- Application Number
- CN202510651139.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-12-31
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-12
AI Technical Summary
The existing network security assessment methods have single data types, ignoring the influence of indirect factors, resulting in a decrease in the accuracy of assessment.
Collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data and risk data, calculate multiple indicators and judge security risk levels.
It has improved the data richness of network security assessment, comprehensively considered the security status of hardware and software assets, helped enterprises formulate comprehensive security strategies, timely detect network traffic abnormalities and security incidents, and improved security response speed.
Smart Images

Figure CN120474785A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data analysis technology, and in particular to a network security assessment method and system for use in security assessment. Background Art
[0002] Information security assessments are a crucial tool for ensuring information system security. Innovation and development in cybersecurity assessment methods and systems provide strong technical support for these assessments. By continuously optimizing these methods and systems, we can more efficiently and accurately assess the security status of information systems, helping enterprises identify and resolve issues promptly and ultimately improving information security for society as a whole.
[0003] The working principle of traditional network security assessment methods and systems is: first, collect relevant information of the system under test, such as system configuration, network traffic, etc.; then, pre-process the collected data and analyze the security status of the system, identify potential security risks, and calculate the security risk value faced by the network system; finally, generate a network security assessment report to determine whether it meets the requirements of the security level protection.
[0004] The existing technology still has the following shortcomings: when collecting data, the collected data type is single, and it is easy to ignore the impact of indirect factors on the network system, which leads to a decrease in the accuracy of network security assessment. Summary of the Invention
[0005] (1) Technical problems solved In view of the shortcomings of the existing technology, the present invention provides a network security assessment method and system for security assessment. , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators , according to the security risk indicators The security risk level of the network system is judged by the security risk threshold set, which solves the problem that the collected data type is single during data collection and the impact of indirect factors on the network system is easily ignored, thereby reducing the accuracy of network security assessment.
[0006] (2) Technical solution To achieve the above objectives, the present invention is implemented through the following technical solutions: a network security assessment method for security assessment, comprising the following steps: Collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data; Calculate hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data ; According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; Based on security risk indicators The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.
[0007] In the preferred embodiment of the network security assessment method used in the security assessment, the asset data indicators are calculated. The method is: Hardware asset data includes the hardware asset relative cost index , Hardware Asset Recovery Difficulty Index and hardware asset importance index ; Calculate hardware asset importance index based on hardware asset data , based on the formula:
[0008] in, For the The relative cost index of hardware assets under each cost category, It is the serial number corresponding to different cost categories, and its value is ; is the total quantity of cost categories, which must be a positive integer; It is the difficulty index of hardware asset recovery under different recovery methods. It is the sequence number corresponding to different recovery methods, and its value is ; is the total number of recovery methods, which is a positive integer; is the importance index of hardware assets in different links, It is the serial number corresponding to different links, and its value is ; is the total number of different links, which is a positive integer; Software asset data includes the number of software asset vulnerabilities and the number of software asset vulnerability types ; Vulnerability data includes the total number of vulnerabilities and the total number of vulnerability types ; Calculate software asset vulnerability based on software asset data and vulnerability data , based on the formula:
[0009] According to the hardware asset importance index and software asset vulnerability Calculating asset data indicators , based on the formula:
[0010] in, Hardware asset importance indicator The weight coefficient is 0.3 to 0.7; Software asset vulnerability The weight coefficient is 0.3 to 0.7; and 1.
[0011] In the preferred embodiment of the network security assessment method used in the security assessment, the threat data indicators are calculated. The method is: User behavior data includes the number of abnormal user behaviors in the current period , the length of the current cycle , the number of abnormal user behaviors in the previous cycle and the length of the previous cycle ; Calculate user abnormal behavior indicators based on user behavior data , based on the formula:
[0012] External threat data including severity scores for attack incidents , attack frequency and attack impact score ; Calculate the external threat severity index based on external threat data , based on the formula:
[0013] in, For the The severity score of the attack event, It is the sequence number corresponding to different attack events, and its value is ; is the total number of attack events, which is a positive integer; For the Frequency of attacks per attack event; For the The attack impact score of the attack event; The maximum value among all severity scores; is the maximum value among all attack frequencies; The maximum value among all attack impact range scores; Based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators , based on the formula: .
[0014] In the preferred solution of the network security assessment method used in the security assessment, the business assurance index is calculated. The method is: Backup data including backup data integrity score , the amount of backup data that can be used normally in case of failure , Total amount of backup data , Disaster test success rate and data recovery integrity ; Calculate backup data indicators based on backup data , based on the formula:
[0015] in, For the The integrity score of the backup data, It is the serial number corresponding to different backup data, and its value is ; The total amount of backup data; Business function data including business interruption time , business operation time , Number of business functions restored and the total number of business functions ; Calculate business function indicators based on business function data , based on the formula:
[0016] in, For the The duration of the business interruption, It is the sequence number corresponding to different service interruptions, and its value is ; is the total number of business interruptions; According to the backup data indicators and business function indicators Calculating business assurance indicators , based on the formula:
[0017] in, Backing up data indicators The weight coefficient is 0.4 to 0.6; Business function indicators The weight coefficient is 0.4 to 0.6; and =1.
[0018] In the preferred embodiment of the network security assessment method used in the security assessment, the security measures data is calculated. The method is: Security audit data including audit log completeness scores , Time Traceability Score and audit analysis effectiveness scoring ; Employee data including training effectiveness ratings , Training Application Rating and safety measures compliance scores ; Calculate safety measures data based on safety audit data and employee data , based on the formula: .
[0019] In the preferred solution of the network security assessment method used in the security assessment, the traffic impact index is calculated. The method is: Traffic data includes abnormal traffic size , total network traffic size , the extent of traffic pattern changes and the number of abnormal traffic types ; According to the number of abnormal traffic types Calculate the information entropy value of abnormal traffic , based on the formula:
[0020] in, For the The number of abnormal traffic types, It is the sequence number corresponding to different abnormal traffic types, and its value is ; is the total number of abnormal traffic types, which is a positive integer; According to the abnormal traffic size , total network traffic size , the extent of traffic pattern changes and abnormal traffic information entropy Calculating traffic impact indicators , based on the formula: .
[0021] In the preferred embodiment of the network security assessment method used in the security assessment, the emergency response index is calculated. The method is: Emergency response data including emergency response time , emergency event type score and risk assessment value of emergency response results ; Calculate emergency response indicators based on emergency response data , based on the formula:
[0022] in, For the Emergency response time for each emergency response incident; It is the serial number corresponding to different emergency response events, and its value is ; is the total number of emergency response events, which is a positive integer; For the The score value corresponding to the event type of each emergency response event; For the The risk assessment value of the emergency response results of each emergency response event.
[0023] In the preferred embodiment of the network security assessment method used in the security assessment, the risk index is calculated. The method is: Risk data including network device performance risk scores and physical security risk scores ; According to emergency response indicators Calculate risk indicators using risk data , based on the formula: .
[0024] In the preferred embodiment of the network security assessment method used in the security assessment, the method for determining the security risk level of the network system is: According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators , based on the formula:
[0025] The security risk threshold set includes the high risk threshold and low risk threshold ; According to the security risk index The security risk level of the network system is determined by the security risk threshold set based on the following criteria: .
[0026] The present invention also discloses a network security assessment system for use in security assessment, including: Data collection module, used to collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data; Index calculation module, which can calculate hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data ; Security risk judgment module, used to judge the risk based on asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; Based on security risk indicators The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.
[0027] (3) Beneficial effects The present invention provides a network security assessment method and system for use in security assessment, which has the following beneficial effects: (1) By collecting hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data and risk data, it can provide effective data for subsequent calculations and improve the data richness of network security assessment; (2) Based on the hardware asset importance index and software asset vulnerability Calculating asset data indicators , can comprehensively consider the security status of hardware and software assets and provide enterprises with a comprehensive asset risk assessment. and external threat severity index Calculating threat data indicators , which helps enterprises formulate overall security strategies, balance internal and external security protection investments, and improve system security. and business function indicators Calculating business assurance indicators , comprehensively considers backup data and business functions, provides enterprises with a comprehensive business security assessment, and helps enterprises formulate overall business security strategies. Calculate security measures data based on security audit data and employee data , which helps enterprises to find weak links in security measures and make timely improvements and perfections. Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index , can timely detect abnormalities in network traffic and assess the impact of abnormal traffic on the system. Calculate risk indicators using risk data , which helps enterprises to timely discover and handle security incidents and reduce risks; (3) Based on asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators This solves the problem that the data type collected is single and the impact of indirect factors on the network system is easily ignored during data collection, which leads to a decrease in the accuracy of network security assessment. The security risk level of the network system is judged by the security risk threshold set, and an alarm is issued when the security risk level requirement is not met, which is conducive to improving the security response speed and enhancing the effectiveness of security management. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 A schematic diagram of the working steps of a network security assessment method used in information security assessment according to the present invention; Figure 2 The present invention is a method for calculating security risk indicators in a network security assessment method for security assessment Schematic diagram of the steps; Figure 3 The present invention is a structural diagram of a network security assessment system used in information security assessment. DETAILED DESCRIPTION
[0029] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0030] See also Figure 1-2 The present invention provides a network security assessment method for security assessment, comprising the following steps: Step 1: Collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data.
[0031] Combined with the content of step 1: By collecting hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data and risk data, it can provide effective data for subsequent calculations and improve the data richness of network security assessments.
[0032] Step 2: Calculate the hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data .
[0033] Step 201: Calculate asset data indicators The method is: Hardware asset data includes the hardware asset relative cost index , Hardware Asset Recovery Difficulty Index and hardware asset importance index .
[0034] It should be noted that the hardware asset relative cost index It is used to measure the relative importance of a specific hardware asset in the overall hardware asset cost of the network system. It reflects the relationship between the cost input of the hardware equipment acquisition, maintenance, upgrade and other aspects and the overall hardware cost input. The hardware asset relative cost index is calculated by calculating the ratio of the sum of the acquisition cost, maintenance cost and upgrade cost of a specific hardware asset to the total hardware asset cost of the entire network system. .
[0035] Hardware Asset Recovery Difficulty Index It is used to evaluate the difficulty of restoring the normal operation of hardware equipment when it fails or is damaged. The determination method is: check the operation and maintenance records of the hardware equipment to obtain the fault recovery time score, recovery measure score and problem severity score. When the fault recovery time is less than 2 hours, the fault recovery time score is 2 points. When the fault recovery time is greater than 2 hours and less than 6 hours, the fault recovery time score is 5 points. When the fault recovery time is greater than 6 hours, the fault recovery time score is 8 points. When the recovery measures taken can completely solve the problem, the recovery measure score is 2 points. When the recovery measures taken can solve part of the problem, the recovery measure score is 5 points. When the recovery measures taken fail to solve the problem, the recovery measure score is 8 points. When the problem encountered does not affect the recovery process, the problem severity score is 2 points. When the problem encountered affects the recovery process but can be solved, the problem severity score is 5 points. When the problem encountered causes recovery failure, the problem severity score is 10 points. Calculate the sum of the fault recovery time score, recovery measure score and problem severity score as the hardware asset recovery difficulty index. .
[0036] Hardware asset link importance index It is used to measure the criticality of hardware equipment in the business process of the network system. It reflects the impact of the hardware equipment on the normal operation of the business, data processing, network connection and other key links. The method of obtaining it is: according to the opinions of professionals, the difficulty of replacing each hardware equipment and the impact on different business links are scored. The sum of the scores is the hardware asset link importance index. .
[0037] Calculate hardware asset importance index based on hardware asset data , based on the formula:
[0038] in, For the The relative cost index of hardware assets under each cost category, It is the serial number corresponding to different cost categories, and its value is ; is the total quantity of cost categories, which must be a positive integer; It is the difficulty index of hardware asset recovery under different recovery methods. It is the sequence number corresponding to different recovery methods, and its value is ; is the total number of recovery methods, which is a positive integer; is the importance index of hardware assets in different links, It is the serial number corresponding to different links, and its value is ; is the total number of different links, which is a positive integer.
[0039] It should be noted that the operating principle of this formula is: This reflects the importance of hardware assets at the economic level. Measures the ease with which a hardware asset can be restored to normal operation in the event of a failure. This reflects the criticality of hardware assets in the business process. The hardware asset importance index is obtained by calculating the sum of the three aspects and dividing it by the total number. .
[0040] Software asset data includes the number of software asset vulnerabilities and the number of software asset vulnerability types .
[0041] It should be noted that the number of software asset vulnerabilities Vulnerabilities refer to the total number of vulnerabilities in software assets, including security vulnerabilities, functional vulnerabilities, performance vulnerabilities, and other defects that may affect the normal operation and security of the software. A greater number of vulnerabilities indicates a greater risk to the security and stability of the software asset. This is determined by performing a comprehensive scan of the software asset using professional vulnerability scanning tools.
[0042] Number of software asset vulnerability types It refers to the total number of different types of vulnerabilities in software assets. Enterprises can check vulnerability scan reports and count the number of different types of vulnerabilities to determine the number of software asset vulnerability types.
[0043] Vulnerability data includes the total number of vulnerabilities and the total number of vulnerability types .
[0044] It should be noted that the total number of vulnerabilities The total number of all vulnerabilities in existing systems, software, networks, and other environments. Total number of vulnerability types It is the total number of different types of vulnerabilities in existing systems, software, networks and other environments. and the total number of vulnerability types Obtained by querying the National Information Security Vulnerability Database and Common Vulnerabilities and Exposures.
[0045] Calculate software asset vulnerability based on software asset data and vulnerability data , based on the formula:
[0046] It should be noted that the operating principle of this formula is: Used to measure the proportion of software asset vulnerabilities in the total number of vulnerabilities. It is used to measure the ratio of the number of software asset vulnerability types to the total number of vulnerability types. This formula quantifies the vulnerability of software assets by comparing the vulnerability of the software assets themselves with the overall vulnerability situation. The smaller the ratio of the number of software asset vulnerabilities to the number of software asset vulnerability types, the more vulnerable the software assets are. The lower the value, the more secure the software asset is relative to the overall vulnerability environment.
[0047] According to the hardware asset importance index and software asset vulnerability Calculating asset data indicators , based on the formula:
[0048] in, Hardware asset importance indicator The weight coefficient is 0.3 to 0.7, based on the hardware asset importance index. Asset data indicators importance determined. Software asset vulnerability The weight coefficient is 0.3 to 0.7, based on the vulnerability of software assets. Asset data indicators The importance of 1.
[0049] It should be noted that this formula takes into account the importance of hardware assets through a weighted method. and software asset vulnerability Asset data indicators Hardware asset importance index The higher the vulnerability of software assets The lower the asset data index The higher it is, the lower the overall risk profile of the asset.
[0050] Step 202: Calculate threat data indicators The method is: User behavior data includes the number of abnormal user behaviors in the current period , the length of the current cycle , the number of abnormal user behaviors in the previous cycle and the length of the previous cycle .
[0051] It should be noted that the number of abnormal user behaviors in the current cycle Refers to the specific number of abnormal user behaviors that are identified by the system or related mechanisms as deviating from normal patterns or expected behavioral standards during the current cycle. Number of abnormal user behaviors in the previous cycle Refers to the specific number of abnormal user behaviors that were identified by the system or related mechanisms as deviating from normal patterns or expected behavioral standards during the previous cycle. Number of abnormal user behaviors in the current cycle and the number of abnormal user behaviors in the previous cycle By utilizing various anomaly detection algorithms and machine learning models, the collected user behavior data is analyzed and processed to determine the duration of the cycle. The length of the cycle is determined by business needs and can be one day, one week, one month, etc.
[0052] Calculate user abnormal behavior indicators based on user behavior data , based on the formula:
[0053] It should be noted that this formula calculates the ratio between the number of abnormal user behaviors in different periods and the period length to obtain the user abnormal behavior index. User abnormal behavior indicators The higher it is, the more serious the proportion of abnormal user behavior in the current cycle is, and the higher the security risk is.
[0054] External threat data including severity scores for attack incidents , attack frequency and attack impact score .
[0055] It should be noted that the severity score of the attack incident Used to measure the damage and impact caused by an attack. Professional security personnel will score the system losses and social impact caused by the attack according to relevant security standards or guidelines. The total score is the severity score of the attack. Attack frequency Refers to the number of attack events that occur within a unit of time. The number of attack events is counted by monitoring system logs, network traffic, etc., and the attack frequency is calculated based on the set time unit. Indicates the scope of the attack's impact. This may include factors such as the number of affected systems, networks, users, and business processes. This information is obtained by determining the number of affected systems, components, and users; identifying which business processes were disrupted or interrupted; and determining whether the attack affected specific data areas, such as sensitive or critical data. These factors are combined and assigned a corresponding score to indicate the scope of the attack's impact.
[0056] Calculate the external threat severity index based on external threat data , based on the formula:
[0057] in, For the The severity score of the attack event, It is the sequence number corresponding to different attack events, and its value is ; is the total number of attack events, which is a positive integer; For the Frequency of attacks per attack; For the The attack impact score of the attack event; The maximum value among all severity scores; is the maximum value among all attack frequencies; The maximum value among all attack impact range scores.
[0058] It should be noted that this formula comprehensively considers the severity score of the attack incident. , attack frequency and attack impact score These three key factors are used to quantify the severity of external threats. , attack frequency and attack impact score The higher the external threat severity index The higher it is, the higher the security risk.
[0059] Based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators , based on the formula:
[0060] It should be noted that the operating principle of this formula is: is the base of the natural logarithm in the exponential function. and external threat severity index When any one or both of the two increase, it means that the threat faced by the network system is increasing. Through the role of the exponential function, the growth trend of the threat faced by the system can be more sensitively reflected. Threat data indicators The higher it is, the more threats the system faces and the higher the security risk.
[0061] Step 203: Calculate service assurance indicators The method is: Backup data including backup data integrity score , the amount of backup data that can be used normally in case of failure , Total amount of backup data , Disaster test success rate and data recovery integrity .
[0062] It should be noted that the backup data integrity score It is a quantitative assessment of the integrity of the backup data compared to the original data. It is obtained by comparing the backup data with the original data file by file and record by record. You can use professional data comparison tools to check whether there are missing files, incomplete records or inconsistent data structures in the backup data. Calculate the ratio of the number of missing files, incomplete records and inconsistent data structures in the backup data to the total number of original data. When the ratio is less than 20 Backup data integrity score 8 points. When the ratio is greater than 20 and less than 40 Backup data integrity score 6 points. When the ratio is greater than 40 and less than 60 Backup data integrity score 4 points. When the ratio is greater than 50 Backup data integrity score 2 points. The amount of backup data that can be used normally in case of failure Indicates the number of backup data that can be successfully restored and used normally in the event of a system failure or data loss. It reflects the availability and reliability of backup data and is obtained by regularly performing fault simulation tests to simulate system failures or data loss, then attempting to restore the backup data and checking whether the restored data can be used normally. Record the number of backup data that are successfully restored and used normally. Total number of backup data Refers to the total amount of all stored backup data at a specific point in time. It includes various types of backups, such as full backups, incremental backups, differential backups, etc., as well as backup copies at different points in time. It can be obtained through querying the backup storage management system. Disaster test success rate This refers to the ratio of the number of times a system is successfully restored and operating normally to the total number of tests during disaster recovery testing. It reflects the effectiveness and reliability of the backup system and disaster recovery plan. This is achieved by regularly conducting comprehensive disaster recovery tests, simulating various disaster scenarios such as server failures, data center disasters, and network outages. During the test, the number of successful system restorations is recorded and the disaster test success rate is calculated. Refers to the completeness of the restored data compared to the original data when restoring data from a backup. The method of obtaining it is to compare the restored data with the original data file by file and record by record. You can use professional data comparison tools to check whether there are missing files, incomplete records or inconsistent data structures in the restored data. Calculate the ratio of the number of missing files, incomplete records and inconsistent data structures in the restored data to the total number of data before the failure. When the ratio is less than 20 When the data is restored completely 8 points. When the ratio is greater than 20 and less than 40 When the data is restored completely 6 points. When the ratio is greater than 40 and less than 60 When the data is restored completely 4 points. When the ratio is greater than 50 When the data is restored completely 2 points.
[0063] Calculate backup data indicators based on backup data , based on the formula:
[0064] in, For the The integrity score of the backup data, It is the serial number corresponding to different backup data, and its value is ; The total amount of backup data.
[0065] It should be noted that the operating principle of this formula is: is the average value of the backup data integrity score. The lower the average value of the backup data integrity score, the greater the security risk. Indicates the success rate of disaster testing and data recovery integrity The lower it is, the greater the security risk. It indicates the proportion of backup data that can be used normally in the total backup data when a failure occurs. The smaller the proportion, the greater the security risk.
[0066] Business function data including business interruption time , business operation time , Number of business functions restored and the total number of business functions .
[0067] It should be noted that the business interruption time Refers to the duration of time that business cannot proceed normally due to various reasons. This may include business stagnation caused by hardware failure, software problems, network interruption, etc. The method of obtaining it is: Use system monitoring tools to monitor the operating status of the business system in real time. When the system fails or anomalies, the monitoring tool will record the time when the failure occurs and the time when it returns to normal, so as to calculate the business interruption time. Business uptime It refers to the total time that the business system operates normally within a certain period of time, reflecting the stability and reliability of the business system. The method of obtaining it is: the business system log file will record the system startup time, shutdown time and the operation time of each business module, etc. By analyzing these logs, the business operation time can be accurately determined. Refers to the number of business functions that have successfully resumed normal operation after a business interruption. It reflects the company's recovery ability and efficiency in responding to business interruption events. The method of obtaining this number is: After the business interruption, each function of the business system is tested to determine which functions have resumed normal operation. You can use automated testing tools or manual testing methods to test each function of the business system one by one and record the number of functions that have resumed normal operation. Total number of business functions This refers to the total number of functions a business system possesses. This includes core and supporting functions, as well as the specific functions of each business module. This information can be obtained by reviewing documents such as the business system's design, requirements, and functional specifications, which describe each function in detail. By consulting these documents, you can determine the total number of business functions.
[0068] Calculate business function indicators based on business function data , based on the formula:
[0069] in, For the The duration of the business interruption, It is the sequence number corresponding to different service interruptions, and its value is ; The total number of service interruptions.
[0070] It should be noted that this formula combines the business interruption time , business operation time , Number of business functions restored and the total number of business functions Factors such as the following are used to evaluate the stability and reliability of business functions, thereby obtaining business function indicators. If the service interruption time is short and the service function is restored well, the service function index It will be relatively small, indicating that the stability and reliability of the business function are higher and the security risks faced are smaller.
[0071] According to the backup data indicators and business function indicators Calculating business assurance indicators , based on the formula:
[0072] in, Backing up data indicators The weight coefficient is 0.4 to 0.6, based on the backup data index Business assurance indicators importance determined. Business function indicators The weight coefficient is 0.4 to 0.6, based on the business function indicators Business assurance indicators The importance of =1.
[0073] It should be noted that this formula comprehensively considers the backup data indicators and business function indicators The impact of two aspects leads to business assurance indicators . Backup data indicators The higher the value, the stronger the availability of backup data and the business assurance index. The higher the value, the smaller the security risk. The higher the value, the more stable and reliable the business functions are, and the business assurance index is The higher it is, the smaller the security risk.
[0074] Step 204: Calculate safety measures data The method is: Security audit data including audit log completeness scores , Time Traceability Score and audit analysis effectiveness scoring .
[0075] It should be noted that the audit log completeness score This is used to measure the completeness of security audit log records. It reflects whether the audit log covers all key security events, operations, and activities. The method of obtaining this information is to arrange for a dedicated person to regularly review the audit log, compare it with the preset completeness standards, evaluate the event types, level of detail, and coverage recorded in the log, and assign a corresponding score based on the inspection results. Time traceability score Used to evaluate the accuracy and scope of the security audit system's ability to trace back the time of an incident. This is obtained by querying historical audit logs to determine the longest time the system can trace back, and assigning a corresponding score based on the scope of the traceability. Audit Analysis Effectiveness Score This measure measures the effectiveness of security audit analysis, specifically whether audit log analysis can promptly identify security issues, abnormal behavior, and potential risks. This is achieved by regularly evaluating audit analysis results, comparing them to the actual security situation, and assigning a score based on the results.
[0076] Employee data including training effectiveness ratings , Training Application Rating and safety measures compliance scores .
[0077] It should be noted that the training effect score Used to measure the actual effect of employee security training. The method of obtaining it is: after the training, a test paper containing questions on security policy, password management, network security, etc. is designed to test the employees' security knowledge and score them, and the training effect score is obtained. Training application score It is used to measure the extent to which employees apply the knowledge and skills learned in safety training at work. The method of obtaining it is: select some actual safety cases, analyze the behavior of employees in these cases, evaluate whether they apply the knowledge and skills learned in training, and score them. Safety Measures Compliance Score It is used to measure employees' compliance with corporate safety measures. The method of obtaining it is: record employees' safety violations and deduct points according to the severity of the violations. The deduction points are subtracted from the base score to get the safety measures compliance score. .
[0078] Calculate safety measures data based on safety audit data and employee data , based on the formula:
[0079] It should be noted that the operating principle of this formula is: It is the average score of the safety audit data, reflecting the comprehensive performance of the safety audit in different aspects. The total score of the employee data is obtained by first taking the natural logarithm , and then perform index calculation to get the final employee training effect score. The higher the average score of the safety audit data, the higher the safety measures data The higher the score, the better the safety situation of the enterprise. The higher the employee training effect score, the better the safety measures data. The higher it is, the better the security posture of the enterprise.
[0080] Step 205: Calculate traffic impact index The method is: Traffic data includes abnormal traffic size , total network traffic size , the extent of traffic pattern changes and the number of abnormal traffic types .
[0081] It should be noted that the abnormal traffic size It refers to the total amount of traffic detected on the network during a specific period of time that is different from the normal traffic pattern, reflecting the severity of potential security issues. Professional network traffic monitoring tools are used to identify abnormal traffic and measure its size. It refers to the total amount of all data traffic passing through the network during a specific period of time, including normal traffic and abnormal traffic. Using network traffic monitoring tools, you can monitor the total network traffic in real time. Used to measure the degree of change in network traffic. The acquisition method is: collect network traffic data in the current cycle and the previous cycle, calculate the difference between the average network traffic in the current cycle and the average network traffic in the previous cycle, and use it as the magnitude of the traffic pattern change. The cycle time is determined according to business needs. Number of abnormal traffic types This refers to the number of abnormal traffic flows within each abnormal traffic type detected on the network. This is determined by using network traffic analysis tools to identify abnormal traffic flows, categorizing them into different types, and then counting the number of abnormal traffic flows within each type.
[0082] According to the number of abnormal traffic types Calculate the information entropy value of abnormal traffic , based on the formula:
[0083] in, For the The number of abnormal traffic contained in each abnormal traffic type, It is the sequence number corresponding to different abnormal traffic types, and its value is ; The total number of abnormal traffic types, which is a positive integer.
[0084] It should be noted that the operating principle of this formula is: when the number of all abnormal traffic types is evenly distributed, the numerator is relatively small relative to the denominator, and the abnormal traffic information entropy value is It will be larger, indicating that the uncertainty of the distribution of abnormal traffic types is higher and the security risks faced are also higher.
[0085] According to the abnormal traffic size , total network traffic size , the extent of traffic pattern changes and abnormal traffic information entropy Calculating traffic impact indicators , based on the formula:
[0086] It should be noted that this formula comprehensively evaluates the impact of abnormal traffic on the network by taking into account the scale of abnormal traffic, changes in traffic patterns, and the distribution of abnormal traffic types. The larger the value, the greater the impact of abnormal traffic on the network and the higher the security risk.
[0087] Step 206: Calculate emergency response indicators The method is: Emergency response data including emergency response time , emergency event type score and risk assessment value of emergency response results .
[0088] It should be noted that the emergency response time It refers to the time from the discovery of an emergency to the implementation of initial response measures. Use a professional event monitoring system to record the time when the event occurs and the time when response measures are taken to determine the emergency response time. Emergency event type score It is a numerical value that quantitatively evaluates the type of emergency event, reflecting the relative severity of different types of emergency events. It is obtained by collecting relevant data on various emergency events that have occurred in the past, including the type of event, the actual impact, response measures and results, etc. By statistically analyzing this data, a relationship model between event type and impact degree is established, thereby determining scores for different types of emergency events. The higher the score, the more serious the type of emergency event. It is a quantitative value obtained after risk assessment of the emergency event handling results, reflecting the degree of risk that still exists after the event is handled. By analyzing relevant data before and after the event handling, such as the number of system vulnerabilities, attack frequency, business interruption time, etc., the risk level of the event handling results is evaluated and the risk assessment value of the emergency event handling results is obtained. .
[0089] Calculate emergency response indicators based on emergency response data , based on the formula:
[0090] in, For the Emergency response time for each emergency response incident; It is the serial number corresponding to different emergency response events, and its value is ; is the total number of emergency response events, which is a positive integer; For the The score value corresponding to the event type of each emergency response event; For the The risk assessment value of the emergency response results of each emergency response event.
[0091] It should be noted that the operating principle of this formula is: by comprehensively considering the three factors of event type, processing result risk and response time, the emergency response index is obtained. Emergency response time The longer the emergency event type score and risk assessment value of emergency response results The higher it is, the worse the emergency response will be and the higher the security risk will be.
[0092] Step 207: Calculate risk indicators The method is: Risk data including network device performance risk scores and physical security risk scores .
[0093] It should be noted that the network equipment performance risk score It is an indicator for quantitatively evaluating the risks that network equipment may face in terms of performance. It reflects the potential risk level of network equipment in processing data traffic, coping with high loads, and ensuring network stability. By analyzing the log files of network equipment, looking for performance-related events and error information, and scoring them separately according to the severity of the relevant events in the logs and the frequency of error information, the specific scoring method is: when the event causes the system to crash, the severity score is 10 points. When the event affects the operation of the system but the system can continue to work, the severity score is 6 points. When the event does not affect the operation of the system, the severity score is 1 point. When the error message occurs less than once a month, the frequency score is 2 points. When the error message occurs 1 to 5 times a month, the frequency score is 4 points. When the error message occurs 6 to 10 times a month, the frequency score is 6 points. When the error message occurs more than 10 times a month, the frequency score is 10 points. Calculate the sum of the two scores as the network equipment performance risk score. Physical Security Risk Score This metric quantitatively assesses the physical security risks faced by network equipment and related infrastructure. It considers physical factors that may impact the normal operation of network equipment and data security, such as the equipment's location, access control, fire and water protection measures, and power supply. An on-site inspection of the physical environment housing the network equipment is conducted. The inspection covers areas such as whether the equipment is safely located, whether appropriate fire and water protection measures are in place, and whether the power supply is stable and reliable. Each item is scored, and the sum of these scores is used to determine the physical security risk score.
[0094] According to emergency response indicators Calculate risk indicators using risk data , based on the formula:
[0095] It should be noted that this formula comprehensively considers the emergency response indicators and risk data to obtain risk indicators Emergency Response Indicators The lower the risk, the better the emergency response and the smaller the risk. The lower the risk score of network equipment performance and physical security risk scores The higher the risk, the smaller the risk. The lower.
[0096] Combined with the contents of step 201 to step 207: According to the hardware asset importance index and software asset vulnerability Calculating asset data indicators , can comprehensively consider the security status of hardware and software assets and provide enterprises with a comprehensive asset risk assessment. and external threat severity index Calculating threat data indicators , which helps enterprises formulate overall security strategies, balance internal and external security protection investments, and improve system security. and business function indicators Calculating business assurance indicators , comprehensively considers backup data and business functions, provides enterprises with a comprehensive business security assessment, and helps enterprises formulate overall business security strategies. Calculate security measures data based on security audit data and employee data , which helps enterprises to find weak links in security measures and make timely improvements and perfections. Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index , can timely detect abnormalities in network traffic and assess the impact of abnormal traffic on the system. Calculate risk indicators using risk data , which helps enterprises to detect and handle security incidents in a timely manner and reduce risks.
[0097] Step 3: Based on asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; Based on security risk indicators The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.
[0098] Step 301: The method for determining the security risk level of the network system is: According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators , based on the formula:
[0099] It should be noted that this formula obtains the security risk index by considering multiple factors. Security Risk Indicators The higher it is, the higher the security risk.
[0100] The security risk threshold set includes the high risk threshold and low risk threshold .
[0101] It should be noted that the high risk threshold The method for determining the risk index is to collect historical operation data of the network system, calculate the security risk index of the network system according to the above method, and observe the performance changes of the network system. When the performance of the network system is significantly reduced, the corresponding security risk index value at this time is used as the high risk threshold. reference value.
[0102] Low risk threshold The method for determining this is to consult industry standards, specifications, and best practice guidelines related to cybersecurity. These resources often provide recommendations for categorizing cybersecurity risk levels. Based on these standards and guidelines and the actual situation of the network system, determine the low-risk threshold.
[0103] According to the security risk index The security risk level of the network system is determined by the security risk threshold set based on the following criteria:
[0104] Combined with the content of step 301: According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators This solves the problem that the data type collected is single and the impact of indirect factors on the network system is easily ignored during data collection, which leads to a decrease in the accuracy of network security assessment. The security risk level of the network system is judged by the security risk threshold set, and an alarm is issued when the security risk level requirement is not met, which is conducive to improving the security response speed and enhancing the effectiveness of security management.
[0105] See also Figure 3 On the other hand, the present invention also discloses a network security assessment system for use in security assessment, which is used to implement the above network security assessment method, including: Data collection module, used to collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data; Index calculation module, which can calculate hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the abnormal traffic information entropy value based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data ; Security risk judgment module, used to judge the risk based on asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; Based on security risk indicators The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.
[0106] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art will appreciate that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution.
[0107] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0108] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.
Claims
1. A network security assessment method for use in information security assessment, characterized by: The following steps are involved: Collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data; Calculate hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the information entropy value of abnormal traffic based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data ; According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; According to the security risk index The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.
2. The network security assessment method for security protection assessment according to claim 1, characterized in that: Calculating asset data indicators The method is: Hardware asset data includes the hardware asset relative cost index , Hardware Asset Recovery Difficulty Index and hardware asset importance index ; Calculate hardware asset importance index based on hardware asset data , based on the formula: in, For the The relative cost index of hardware assets under each cost category, It is the serial number corresponding to different cost categories, and its value is ; is the total quantity of cost categories, which must be a positive integer; It is the difficulty index of hardware asset recovery under different recovery methods. It is the sequence number corresponding to different recovery methods, and its value is ; is the total number of recovery methods, which is a positive integer; is the importance index of hardware assets in different links, It is the serial number corresponding to different links, and its value is ; is the total number of different links, which is a positive integer; Software asset data includes the number of software asset vulnerabilities and the number of software asset vulnerability types ; Vulnerability data includes the total number of vulnerabilities and the total number of vulnerability types ; Calculate software asset vulnerability based on software asset data and vulnerability data , based on the formula: According to the hardware asset importance index and software asset vulnerability Calculating asset data indicators , based on the formula: in, Hardware asset importance indicator The weight coefficient is 0.3 to 0.7; Software asset vulnerability The weight coefficient is 0.3 to 0.7; and 1.
3. The network security assessment method for security protection assessment according to claim 2, characterized in that: Calculating threat data indicators The method is: User behavior data includes the number of abnormal user behaviors in the current period , the length of the current cycle , the number of abnormal user behaviors in the previous cycle and the length of the previous cycle ; Calculate user abnormal behavior indicators based on user behavior data , based on the formula: External threat data including severity scores for attack incidents , attack frequency and attack impact score ; Calculate the external threat severity index based on external threat data , based on the formula: in, For the The severity score of the attack event, It is the sequence number corresponding to different attack events, and its value is ; is the total number of attack events, which is a positive integer; For the Frequency of attacks per attack; For the The attack impact score of the attack event; The maximum value among all severity scores; is the maximum value among all attack frequencies; The maximum value among all attack impact range scores; Based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators , based on the formula: 。 4. The network security assessment method for use in information security assessment according to claim 3, characterized in that: Calculating business assurance indicators The method is: Backup data including backup data integrity score , the amount of backup data that can be used normally in case of failure , Total amount of backup data , Disaster test success rate and data recovery integrity ; Calculate backup data indicators based on backup data , based on the formula: in, For the The integrity score of the backup data, It is the serial number corresponding to different backup data, and its value is ; The total amount of backup data; Business function data including business interruption time , business operation time , Number of business functions restored and the total number of business functions ; Calculate business function indicators based on business function data , based on the formula: in, For the The duration of the business interruption, It is the sequence number corresponding to different service interruptions, and its value is ; is the total number of business interruptions; According to the backup data indicators and business function indicators Calculating business assurance indicators , based on the formula: in, Backing up data indicators The weight coefficient is 0.4 to 0.6; Business function indicators The weight coefficient is 0.4 to 0.6; and =1.
5. The network security assessment method for security protection assessment according to claim 4, characterized in that: Calculating safety measures data The method is: Security audit data including audit log completeness scores , Time Traceability Score and audit analysis effectiveness scoring ; Employee data including training effectiveness ratings , Training Application Rating and safety measures compliance scores ; Calculate safety measures data based on safety audit data and employee data , based on the formula: 。 6. The network security assessment method for use in information security assessment according to claim 5, characterized in that: Calculating traffic impact indicators The method is: Traffic data includes abnormal traffic size , total network traffic size , the extent of traffic pattern changes and the number of abnormal traffic types ; According to the number of abnormal traffic types Calculate the information entropy value of abnormal traffic , based on the formula: in, For the The number of abnormal traffic types, It is the sequence number corresponding to different abnormal traffic types, and its value is ; is the total number of abnormal traffic types, which is a positive integer; According to the abnormal traffic size , total network traffic size , the extent of traffic pattern changes and abnormal traffic information entropy Calculating traffic impact indicators , based on the formula: 。 7. The network security assessment method for use in information security assessment according to claim 6, characterized in that: Calculating emergency response indicators The method is: Emergency response data including emergency response time , emergency event type score and risk assessment value of emergency response results ; Calculate emergency response indicators based on emergency response data , based on the formula: in, For the Emergency response time for each emergency response incident; It is the serial number corresponding to different emergency response events, and its value is ; is the total number of emergency response events, which is a positive integer; For the The score value corresponding to the event type of each emergency response event; For the The risk assessment value of the emergency response results of each emergency response event.
8. The network security assessment method for use in information security assessment according to claim 7, characterized in that: Calculating risk indicators The method is: Risk data including network device performance risk scores and physical security risk scores ; According to emergency response indicators Calculate risk indicators using risk data , based on the formula: 。 9. The network security assessment method for use in information security assessment according to claim 8, characterized in that: The method for determining the security risk level of a network system is: According to asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators , based on the formula: The security risk threshold set includes the high risk threshold and low risk threshold ; According to the security risk index The security risk level of the network system is determined by the security risk threshold set based on the following criteria: 。 10. A network security assessment system for use in security assessment, characterized by: include: Data collection module, used to collect hardware asset data, software asset data, vulnerability data, user behavior data, external threat data, backup data, business function data, security audit data, employee data, traffic data, emergency response data, and risk data; Index calculation module, which can calculate hardware asset importance index based on hardware asset data , calculate software asset vulnerability based on software asset data and vulnerability data , according to the hardware asset importance index and software asset vulnerability Calculating asset data indicators ; Calculate user abnormal behavior indicators based on user behavior data , calculate the external threat severity index based on external threat data , based on user abnormal behavior indicators and external threat severity index Calculating threat data indicators ; Calculate backup data indicators based on backup data , calculate business function indicators based on business function data , according to the backup data indicators and business function indicators Calculating business assurance indicators ; Calculate safety measures data based on safety audit data and employee data ; Calculate the information entropy value of abnormal traffic based on traffic data , and further calculate the traffic impact index ; Calculate emergency response indicators based on emergency response data , according to emergency response indicators Calculate risk indicators using risk data ; Security risk judgment module, used to judge the risk based on asset data indicators , threat data indicators , business assurance indicators , safety measures data , Traffic impact indicators and risk indicators Calculating security risk indicators ; Preset security risk threshold set; based on security risk indicators The security risk level of the network system is determined by the security risk threshold set; an alarm is issued when the security risk level requirement is not met.