Security event grading response and disposal method based on multiple dimensions
Through a multi-dimensional hierarchical response method, a response matrix is constructed based on vulnerability level, impact scope and importance classification, which solves the problem of improper defense of the situational awareness system in the financial system, improves the response speed and disposal efficiency, and ensures financial security.
Patent Information
- Application Number
- CN202510582120.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-09-05
AI Technical Summary
Existing big data-based situational awareness systems lack specificity in financial systems, resulting in inappropriate defense timing, which may cause system shutdowns or virus spread, and fail to effectively utilize golden response time.
A multi-dimensional grading method is adopted to assign different weights according to the vulnerability level, impact scope, importance and user level, build a response matrix, calculate the response value and handle it in a graded manner, and preset temporary disposal plans.
It has improved the security response speed and disposal efficiency of the financial system, ensured reasonable emergency measures, and avoided losses and proliferation risks caused by improper disposal.
Smart Images

Figure CN120602117A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of financial network security technology, and in particular to a multi-dimensional security incident hierarchical response and disposal method. Background Art
[0002] In a complete cyberattack, the earlier the defender intervenes, the greater the probability of successful defense. Consequently, big data-based situational awareness systems have emerged, enabling timely detection of various security attacks. However, existing big data-based situational awareness systems are mostly designed by various security vendors. To broaden their applicability, they are generally general-purpose and only address detected attacks based on vulnerability severity. However, given the diversity and criticality of financial systems, overly stringent response methods could shut down systems over a minor issue, resulting in business losses and user experience issues. Overly lenient response methods could lead to further escalation of issues, further spread of Trojans, and loss of valuable time for response and action. Summary of the Invention
[0003] According to an embodiment of the present invention, a multi-dimensional security incident hierarchical response and handling method is provided, comprising the following steps: Potential attack events are classified according to their vulnerability level, the impact range of potential targets, the importance of potential targets, and the number of users involved, and each category is assigned a different weight. Construct a response matrix of the vulnerability level of the potential attack event, the impact range of the potential attack target, the importance of the potential attack target, and the number of users involved in the potential attack target, and obtain the response value of the response matrix; Events are graded according to the response value and assigned different warning levels. Each warning level corresponds to a different response coefficient, response time, and recovery time.
[0004] Furthermore, the basis for classifying and assigning weights to the influence ranges of potential attacked targets is the size of the influence ranges to which the potential attacked targets are connected and implicated.
[0005] Furthermore, the response value is related to the vulnerability level of the potential attack event, the impact range of the potential attacked target, the importance of the potential attacked target, and the weights of different classifications of the user level involved in the potential attacked target.
[0006] Furthermore, the response value is calculated as the product of the vulnerability level weight of the potential attack event, the weight of the impact range of the potential target, the weight of the importance of the potential target, and the user level involved in the potential target.
[0007] Furthermore, when the same potential target encounters multiple potential attack events, the response value is the response value obtained by the highest vulnerability level weight.
[0008] Furthermore, temporary disposal plans are preset according to the warning levels.
[0009] The multi-dimensional security incident hierarchical response and disposal method according to the embodiment of the present invention, combined with the characteristics of the financial system, scientifically determines the disposal level, quickly determines emergency measures, and implements hierarchical disposal, which greatly improves the response speed and disposal efficiency, enhances financial security, and has important strategic significance.
[0010] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the technology as claimed. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 This is a flowchart of a multi-dimensional security incident classification response and handling method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0012] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings to further illustrate the present invention.
[0013] First, combine Figure 1 The present invention describes a multi-dimensional security incident hierarchical response and handling method for handling financial network security incidents, which has a wide range of application scenarios.
[0014] like Figure 1 As shown, the multi-dimensional security incident hierarchical response and handling method according to the embodiment of the present invention has the following steps: In S1, as Figure 1 As shown, potential attack events are categorized based on their vulnerability level, the impact range of potential targets, the importance of potential targets, and the number of users involved, and each category is assigned a different weight. In this embodiment, the impact range of potential targets is categorized and weighted based on the size of the impact range connected to and implicated by the potential targets.
[0015] Specifically, regarding the vulnerability level of potential attack events, the vulnerability levels involved in the attack events that may be successfully exploited are classified.
[0016] In this embodiment, the following vulnerability classification criteria are considered: 1. Critical, high, medium, and low-risk security vulnerabilities disclosed by the China National Vulnerability Database; 2. Common vulnerabilities are automatically upgraded by one vulnerability level, such as the top 10 common security vulnerabilities disclosed by the OWASP (Open Web Application Security Project); 3. Logical attacks involving account movement and financial transactions; 4. Attacks involving the leakage of sensitive information, user personal information, and other potential reputational risks that may cause user losses, legal action, and other legal risks. Examples are shown in Table 1:
[0017] Specifically, the impact scope of potential attack targets is classified based on the following criteria: If a potential attack target is successfully attacked, the scope of the impact that may be caused to its physically and logically connected systems and business transaction systems is simultaneously implicated, covering operating systems, databases, middleware, application software, network equipment, big data platforms, identity authentication systems, access management / authorization systems, etc. An example is shown in Table 2:
[0018] Specifically, the classification of the importance of potential targets is based on the importance of the potential targets themselves, such as critical infrastructure, important financial transaction systems, industry information sharing platforms, user personal information management systems, etc. Examples are shown in Table 3:
[0019] Specifically, the classification basis for the user level involved in the potential attack target is: the user level involved in the attacked system. An example is shown in Table 4: In S2, as Figure 1As shown, a response matrix of the vulnerability level of the potential attack event, the impact range of the potential attacked target, the importance of the potential attacked target, and the user level involved in the potential attacked target is constructed, and the response value of the response matrix is obtained. In this embodiment, the response value is related to the weights of the different categories of the vulnerability level of the potential attack event, the impact range of the potential attacked target, the importance of the potential attacked target, and the user level involved in the potential attacked target. Further, the calculation formula of the response value is the product of the vulnerability level weight of the potential attack event, the weight of the impact range of the potential attacked target, the weight of the importance of the potential attacked target, and the user level involved in the potential attacked target, that is, response value = impact range assignment * importance assignment * user level assignment * vulnerability level assignment. When the same potential attacked target encounters multiple potential attack events, the response value is the response value obtained by the highest vulnerability level weight. Examples are shown in Table 5: Each warning level corresponds to a different response coefficient, response time, and recovery time. In this embodiment, based on the response value calculated in the previous step, a hierarchical disposal is implemented. According to national and industry regulatory requirements for national critical information infrastructure, each agency can adjust the response time and recovery time. That is, temporary disposal plans are preset according to the warning level. Examples are shown in Table 6:
[0020] Above, refer to Figure 1 This disclosure describes a multi-dimensional, hierarchical security incident response and handling method based on an embodiment of the present invention. By combining the characteristics of the financial system, the method scientifically determines the handling level, rapidly determines emergency measures, and implements hierarchical handling, significantly improving response speed and handling efficiency, enhancing financial security, and possessing significant strategic significance. It should be noted that, in this specification, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. Without further limitation, elements defined by the phrase "include..." do not preclude the presence of other identical elements in the process, method, article, or device comprising the elements. Although the present invention has been described in detail through the above preferred embodiments, it should be understood that the above description should not be construed as limiting the invention. Numerous modifications and alternatives to the present invention will become apparent to those skilled in the art after reading the above disclosure. Therefore, the scope of protection of the present invention shall be defined by the appended claims.
Claims
1. A multi-dimensional security incident hierarchical response and handling method, characterized in that: The following steps are included: Potential attack events are classified according to their vulnerability level, the impact range of potential targets, the importance of potential targets, and the number of users involved, and each category is assigned a different weight. Constructing a response matrix of potential attack events, the impact range of the potential attacked target, the importance of the potential attacked target, and the user level involved in the potential attacked target, and obtaining a response value of the response matrix; Events are graded according to the response value and assigned different warning levels. Each warning level corresponds to a different response coefficient, response time, and recovery time.
2. The multi-dimensional security incident hierarchical response and handling method according to claim 1 is characterized in that: The basis for classifying and assigning weights to the influence ranges of the potential attacked targets is the size of the influence ranges to which the potential attacked targets are connected and implicated.
3. The multi-dimensional security incident hierarchical response and handling method according to claim 2, characterized in that: The response value is related to the vulnerability level of the potential attack event, the impact range of the potential attacked target, the importance of the potential attacked target, and the weights of different categories of user levels involved in the potential attacked target.
4. The multi-dimensional security incident hierarchical response and handling method according to claim 3 is characterized in that: The calculation formula of the response value is the product of the vulnerability level weight of the potential attack event, the weight of the impact range of the potential attacked target, the weight of the importance of the potential attacked target and the user level involved in the potential attacked target.
5. The multi-dimensional security incident hierarchical response and handling method according to claim 4 is characterized in that: When the same potential target encounters vulnerability levels of multiple potential attack events, the response value is the response value obtained by the highest vulnerability level weight.
6. The multi-dimensional security incident hierarchical response and handling method according to claim 1, characterized in that: According to the warning level, temporary disposal plans are preset respectively.