Network security protection capability assessment method and system
By setting multi-dimensional evaluation indicators and simulating attack scenarios, combined with correlation information and actual protection coefficient correction, the incompleteness and subjectivity of traditional evaluation methods are solved, a comprehensive and accurate evaluation of protective equipment is achieved, and the evaluation quality of network security protection capabilities is improved.
Patent Information
- Application Number
- CN202510758505.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-16
AI Technical Summary
Traditional network security protection capability assessment methods lack comprehensiveness and integrativeness, and are easily affected by subjective factors of evaluators, resulting in uncertainty and errors in the assessment results, and unable to accurately reflect the actual protection capabilities of the equipment.
Set multi-dimensional evaluation indicators, determine the initial protection capability assessment value through correlation information analysis, obtain result performance data under different simulated attack scenarios, determine the actual protection coefficient based on key factors, and revise the initial assessment value to form a more accurate protection capability assessment.
It achieves a comprehensive and objective evaluation of protective equipment, can identify the impact of key factors, provide detailed operating status and performance, improve the accuracy and comprehensiveness of the evaluation, and ensure the reliability of the evaluation results.
Smart Images

Figure CN120658443A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security protection capability assessment method and system. Background Art
[0002] Cybersecurity protection capability assessment involves a comprehensive evaluation of cybersecurity measures and equipment to determine their effectiveness and reliability against various cyber threats and attacks. As cyberattacks become increasingly frequent and sophisticated, protecting networks from malicious intrusions and data leaks has become crucial. The development of cybersecurity protection capability assessment methods aims to help organizations and individuals understand their cybersecurity status, identify potential security risks, and take appropriate measures to strengthen security.
[0003] However, traditional methods often only evaluate network security protection capabilities from a single dimension, lacking comprehensiveness and integration. Modern network attacks are diverse and complex, and evaluation from multiple angles is needed to better understand the overall protection capabilities. Traditional methods may be affected by subjective factors of evaluators, and the evaluation results may have subjective biases. The lack of objective evaluation standards and quantitative indicators will lead to uncertainty and errors in the evaluation results. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a network security protection capability assessment method and system, including: Pre-set multi-dimensional evaluation indicators that directly affect the evaluation of the network security protection capability of the protection equipment, and determine the correlation information of the multi-dimensional evaluation indicators from the protection equipment; Analyze the correlation information of the multi-dimensional evaluation indicators, determine the information data characteristics, and determine the initial protection capability evaluation value of the protective equipment based on the information data characteristics of the correlation information; Obtain performance data of protective equipment in different simulated attack scenarios, analyze the performance data, and identify key factors affecting network security protection capabilities; The actual protection coefficient of the protective equipment is determined based on the key factors, and the initial protection capability assessment value is corrected based on the actual protection coefficient to obtain the protection capability assessment value of the protective equipment.
[0005] Furthermore, the presetting of multi-dimensional evaluation indicators that directly affect the evaluation of the network security protection capability of the protection device, and determining the associated information of the multi-dimensional evaluation indicators from the protection device, includes: Pre-set multi-dimensional evaluation indicators that directly affect the cybersecurity protection capability assessment of protective equipment, and collect multi-dimensional information from protective equipment; The correlation degrees between the multidimensional information and the multidimensional evaluation indicators are determined respectively, and the multidimensional information with the highest correlation degree is determined as the correlation information corresponding to the multidimensional evaluation indicator.
[0006] Furthermore, the analysis of the correlation information of the multi-dimensional evaluation indicators to determine the characteristics of the information data includes: Determine the parameter value included in the associated information of the multidimensional evaluation index, and calculate the difference between the parameter value and the standard parameter value to obtain the parameter value difference; The parameter value whose parameter value difference exceeds the corresponding preset value is determined as the information data feature of the associated information.
[0007] Furthermore, the determining of the initial protection capability evaluation value of the protection device based on the information data characteristics of the associated information includes: Determine the information data characteristics of the associated information, and evaluate and value the information data characteristics to obtain an evaluation value of the information data characteristics; Adding the evaluation values of the information data features of all related information corresponding to the multidimensional evaluation index to obtain the sub-evaluation value corresponding to the multidimensional evaluation index; Determine the correlation between the multidimensional evaluation index and the corresponding multidimensional information, convert the correlation into a vector, and normalize the vectorized correlation to obtain the weight corresponding to the multidimensional evaluation index; The initial protection capability evaluation value of the protective equipment is calculated based on the weights and sub-evaluation values corresponding to the multi-dimensional evaluation indicators.
[0008] Furthermore, the calculation formula for the initial protection capability evaluation value of the protective equipment is: , Among them, P is the initial protection capability evaluation value of the protective equipment, ai is the weight corresponding to the i-th multidimensional evaluation indicator, Di is the sub-evaluation value corresponding to the i-th multidimensional evaluation indicator, and n is the number of multidimensional evaluation indicators.
[0009] Furthermore, the acquisition of performance data of the protection device under different simulated attack scenarios and analysis of the performance data to determine the key factors affecting network security protection capabilities include: Pre-set different simulated attack scenarios and obtain performance data of protective equipment in different simulated attack scenarios; Predetermine candidate factors that affect network security protection capabilities, and screen and analyze the data in the result performance data to determine the data corresponding to the candidate factors; Determining a result status value of the candidate factor based on the data corresponding to the candidate factor, and determining an average result status value of the candidate factor in the historical result performance data; The difference between the result status value and the average result status value is calculated to obtain the result status difference, and the candidate factors whose result status difference exceeds the corresponding preset threshold are determined as key factors affecting network security protection capabilities.
[0010] Furthermore, the actual protection factor of the protective equipment is determined based on key factors, including: Determine the result status difference corresponding to the key factors, and divide the key factors into positive influencing factors and negative influencing factors based on the positive or negative status of the result status difference; Determining the result state difference corresponding to the positive influencing factor and the corresponding preset weight, and calculating the weighted sum of the result state difference corresponding to the positive influencing factor and the preset weight to obtain a first comprehensive value; Determine the result state difference corresponding to the negative influencing factor and the corresponding preset weight, and calculate the weighted sum of the result state difference corresponding to the negative influencing factor and the preset weight to obtain a second comprehensive value; Calculate the proportion of positive influencing factors to key factors to obtain a first proportion value, and calculate the proportion of negative influencing factors to key factors to obtain a second proportion value; Determine the proportion of the key factors to the candidate factors to obtain a third proportion value, and calculate the actual protection factor of the protective equipment based on the first comprehensive value, the second comprehensive value, the first proportion value, the second proportion value and the third proportion value.
[0011] Furthermore, the calculation formula for the actual protection factor of the protective equipment is: k=g3*m(g1*L1+g2*L2), Among them, k is the actual protection factor of the protective equipment, g3 is the third proportional value, m is the preset conversion coefficient, g1 is the first proportional value, L1 is the first comprehensive value, g2 is the second proportional value, and L2 is the second comprehensive value.
[0012] Furthermore, the initial protection capability evaluation value is corrected based on the actual protection coefficient to obtain the protection capability evaluation value of the protective equipment, including: A correspondence relationship between the correction coefficient and the actual protection coefficient interval is pre-set, wherein the correspondence relationship between the correction coefficient and the actual protection coefficient interval is associated with a corresponding correction coefficient for each actual protection coefficient interval; Obtaining an actual protection factor of the protective device, and based on a mapping relationship between an actual protection factor interval to which the actual protection factor belongs and a correction factor-actual protection factor interval correspondence relationship, selecting a correction factor corresponding to the actual protection factor interval as the correction factor of the protective device; Multiply the correction coefficient by the initial protection capability assessment value to obtain the protection capability assessment value of the protective equipment, and complete the correction of the initial protection capability assessment value.
[0013] The present invention also provides a network security protection capability evaluation system, comprising: A first determination module is used to pre-set multi-dimensional evaluation indicators that directly affect the network security protection capability evaluation of the protection device, and determine the correlation information of the multi-dimensional evaluation indicators from the protection device; An evaluation module is used to analyze the correlation information of the multi-dimensional evaluation indicators, determine the information data characteristics, and determine the initial protection capability evaluation value of the protective equipment based on the information data characteristics of the correlation information; The second determination module is used to obtain the performance data of the protection equipment under different simulated attack scenarios, and analyze the performance data to determine the key factors affecting the network security protection capability; The correction module is used to determine the actual protection coefficient of the protective equipment based on the key factors, and to correct the initial protection capability evaluation value based on the actual protection coefficient to obtain the protection capability evaluation value of the protective equipment.
[0014] Compared with the prior art, the network security protection capability assessment method and system according to the embodiment of the present invention have the following advantages: By setting multi-dimensional evaluation indicators, the present invention can comprehensively evaluate the network security protection capabilities of protection equipment and assess its performance from different angles; By analyzing the associated information on the protective equipment, the present invention can understand the operation status of the equipment, the occurrence of events, etc., and provide a data basis for subsequent evaluation; By determining data characteristics, the present invention can better understand and describe the operating status and performance of protective equipment, providing detailed information for evaluation; By analyzing simulated attack scenarios, the present invention can understand the performance of protective equipment in different situations and identify the impact of key factors on protective capabilities; By determining the actual protection factor, the present invention can more accurately assess the actual protection capability of the protective equipment, taking into account the impact of various factors on its performance; The present invention corrects the initial evaluation value and takes into account the influence of the actual protection factor, so as to obtain a more accurate and comprehensive protection capability evaluation value of the protection equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 Schematic diagram of the process structure of the network security protection capability evaluation method in an embodiment of the present invention; Figure 2 Schematic diagram of the network security protection capability evaluation system in an embodiment of the present invention. DETAILED DESCRIPTION
[0016] The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0017] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the platform or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on this application.
[0018] The terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of paths or nodes of the indicated technical feature. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "plurality" means two or more.
[0019] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Persons of ordinary skill in the art will understand the specific meanings of the above terms in this application based on specific circumstances.
[0020] like Figure 1 As shown, in an embodiment of the present application, a network security protection capability evaluation method is provided, including: S100: pre-setting a multidimensional evaluation indicator that directly affects the network security protection capability evaluation of a protective device, and determining the associated information of the multidimensional evaluation indicator from the protective device; S200: analyzing the associated information of the multidimensional evaluation indicator, determining the information data characteristics, and determining the initial protection capability evaluation value of the protective device based on the information data characteristics of the associated information; S300: obtaining the result performance data of the protective device under different simulated attack scenarios, and analyzing the result performance data to determine the key factors affecting the network security protection capability; S400: determining the actual protection coefficient of the protective device based on the key factors, and correcting the initial protection capability evaluation value based on the actual protection coefficient to obtain the protection capability evaluation value of the protective device.
[0021] Furthermore, the present invention can comprehensively evaluate the network security protection capabilities of protective equipment and evaluate its performance from different angles by setting multi-dimensional evaluation indicators; the present invention can understand the operating conditions of the equipment, the occurrence of events, etc. by analyzing the related information on the protective equipment, and provide a data basis for subsequent evaluation; the present invention can better understand and describe the operating status and performance of the protective equipment by determining data characteristics, and provide detailed information for evaluation; the present invention can understand the performance of the protective equipment in different situations and identify the impact of key factors on protection capabilities through analysis of simulated attack scenarios; the present invention can more accurately evaluate the actual protection capabilities of the protective equipment by determining the actual protection coefficient, taking into account the impact of various factors on its performance; the present invention can derive a more accurate and comprehensive protection capability evaluation value of the protective equipment by correcting the initial evaluation value and taking into account the impact of the actual protection coefficient.
[0022] In an embodiment of the present application, a network security protection capability evaluation method is provided, wherein a multidimensional evaluation indicator that directly affects the network security protection capability evaluation of a protective device is pre-set, and correlation information of the multidimensional evaluation indicator is determined from the protective device, including: pre-setting a multidimensional evaluation indicator that directly affects the network security protection capability evaluation of a protective device, and collecting multidimensional information from the protective device; respectively determining the correlation between the multidimensional information and the multidimensional evaluation indicator, and determining the multidimensional information with the highest correlation as the correlation information corresponding to the multidimensional evaluation indicator.
[0023] Specifically, in the field of network security, it is very important to pre-set multi-dimensional evaluation indicators that directly affect the evaluation of the network security protection capability of protective equipment. These evaluation indicators can help evaluators fully understand the performance of protective equipment and evaluate its protection capabilities from different angles. The pre-set multi-dimensional evaluation indicators include the following aspects: performance indicators: such as throughput, latency, resource utilization, etc., used to evaluate the efficiency and performance of the device when processing data traffic and requests; security indicators: such as security protection measures, malware detection, security policy execution, etc., used to evaluate the device's ability to respond to security threats; compatibility indicators: such as protocol support, device interoperability, etc., used to evaluate the compatibility and integration of the device with other systems and devices; the multi-dimensional information collected on the protective device can cover various data, such as device logs, performance statistics, security event records, etc. By analyzing this data, evaluators can determine the correlation between the multi-dimensional information and the multi-dimensional evaluation indicators, and find out the information that has the most significant impact on the evaluation indicators; by determining the multi-dimensional information with the highest correlation as the associated information corresponding to the multi-dimensional evaluation indicators, evaluators can more accurately evaluate the network security protection capability of the protective equipment. In this step, by determining multi-dimensional evaluation indicators and related information, evaluators can comprehensively evaluate the performance, safety, and compatibility of protective equipment, thereby better understanding its overall protective capabilities. By collecting and analyzing multi-dimensional information and determining related information, evaluators can make decisions based on the data and more objectively and accurately evaluate the actual performance and potential risks of protective equipment. Determining related information can help optimize the evaluation process, improve the efficiency and accuracy of the evaluation, and provide guidance for subsequent improvements and optimizations.
[0024] In an embodiment of the present application, a network security protection capability assessment method is provided, in which the associated information of the multidimensional assessment indicators is analyzed to determine the information data characteristics, including: determining the parameter values contained in the associated information of the multidimensional assessment indicators, and calculating the difference between the parameter values and the standard parameter values to obtain the parameter value difference; and determining the parameter value whose parameter value difference exceeds the corresponding preset value as the information data characteristic of the associated information.
[0025] Specifically, the parameter values that need to be evaluated are determined. These parameters are specific indicators of performance, safety, reliability, etc., and standard parameter values are set as a reference benchmark. By collecting equipment data, the difference between the actual parameter value and the standard parameter value, that is, the parameter value difference, is calculated to determine the deviation of the equipment performance from the standard in actual operation. A preset threshold is set to represent the maximum deviation range allowed for the parameter value difference. Parameter values exceeding this range will be identified as key information. By comparing the parameter value difference with the preset value, parameter values exceeding the preset value are identified. These parameter values are identified as key information data features, indicating that these parameters have large deviations in actual operation. This step can achieve real-time monitoring of equipment performance and performance by continuously calculating and comparing parameter values, accurately evaluate the direct protection capabilities of protective equipment, and help improve the real-time and fault response capabilities of network security protection capabilities. The analysis results based on the parameter value difference can provide objective data support for managers to help them make more effective decisions.
[0026] In an embodiment of the present application, a network security protection capability assessment method is provided, which determines the initial protection capability assessment value of a protection device based on the information data characteristics of associated information, including: determining the information data characteristics of the associated information, and evaluating and taking values of the information data characteristics to obtain an assessment value of the information data characteristics; adding up the assessment values of the information data characteristics of all associated information corresponding to the multidimensional assessment index to obtain a sub-assessment value corresponding to the multidimensional assessment index; determining the correlation between the multidimensional assessment index and the corresponding multidimensional information, converting the correlation into a vector, and normalizing the vectorized correlation to obtain a weight corresponding to the multidimensional assessment index; and calculating the initial protection capability assessment value of the protection device based on the weight and sub-assessment value corresponding to the multidimensional assessment index.
[0027] Specifically, the method determines the associated information by calculating the numerical differences of parameters. Each information data feature is assigned an evaluation value, representing the degree of impact of the feature on the device's performance. These evaluation values are derived based on expert experience. The evaluation values of the multidimensional evaluation indicator corresponding to all associated information data features are summed to obtain the sub-evaluation values of the multidimensional evaluation indicator. The correlation between the multidimensional evaluation indicator and the corresponding multidimensional information is determined and converted into vectors. These vectors are normalized to obtain the weights of the multidimensional evaluation indicator, which reflect the importance of different indicators in the evaluation. Based on the weights and sub-evaluation values of the multidimensional evaluation indicators, the initial protective capability evaluation value of the protective equipment is calculated through a weighted summation method to help evaluators fully understand the overall protective capability level of the equipment. This step, by comprehensively considering the weights and sub-evaluation values of the multidimensional evaluation indicators, allows for a more comprehensive assessment of the device's direct performance and avoids misjudgments caused by one-sided evaluations. By quantifying the evaluation values and calculating the weights, evaluators can make data-based decisions, reduce the interference of subjective factors, and improve the objectivity and accuracy of their decisions. The method for determining weights and calculating evaluation values can help optimize the evaluation process, improve evaluation efficiency, and provide guidance for subsequent improvements and optimization.
[0028] In an embodiment of the present application, a network security protection capability evaluation method is provided, and the calculation formula for the initial protection capability evaluation value of the protection device is: , Among them, P is the initial protection capability evaluation value of the protective equipment, ai is the weight corresponding to the i-th multidimensional evaluation indicator, Di is the sub-evaluation value corresponding to the i-th multidimensional evaluation indicator, and n is the number of multidimensional evaluation indicators.
[0029] In an embodiment of the present application, a method for evaluating network security protection capabilities is provided, which obtains result performance data of a protection device in different simulated attack scenarios, analyzes the result performance data, and determines key factors affecting network security protection capabilities, including: pre-setting different simulated attack scenarios, and obtaining result performance data of the protection device in different simulated attack scenarios; pre-setting candidate factors affecting network security protection capabilities, and screening and analyzing data in the result performance data to determine data corresponding to the candidate factors; determining a result status value of the candidate factor based on the data corresponding to the candidate factor, and determining an average result status value of the candidate factor in the historical result performance data; calculating the difference between the result status value and the average result status value to obtain a result status difference, and determining the candidate factor whose result status difference exceeds the corresponding preset threshold as a key factor affecting network security protection capabilities.
[0030] Specifically, a series of different types of simulated attack scenarios are determined, which may include various types of network attacks, such as DDoS attacks, malware propagation, intrusion attempts, etc. The performance of the protection equipment in each attack scenario is simulated and tested or actually run, and the performance data of the equipment in each scenario is collected and recorded, such as the number of attacks blocked, response speed, false alarm rate, etc.; candidate factors that affect network security protection capabilities are pre-set, and data related to the candidate factors are filtered out from the collected result performance data, and analyzed to determine the performance of these factors in different attack scenarios; based on the data corresponding to the candidate factors, the result status value of each factor in different scenarios is determined to indicate the performance level of the factor in each scenario; the difference between the result status value of each candidate factor and its average result status value in historical data is calculated to obtain the result status difference; the result status difference is compared with the preset threshold, and the candidate factors that exceed the threshold will be determined as key factors affecting network security protection capabilities because their performance in certain scenarios is significantly different from the historical average. This step, through analysis of candidate factors and differential calculations, can more precisely evaluate the performance of network security protection equipment in different scenarios and identify specific factors affecting performance. Based on the analysis of key factors, it can provide objective data support for network security managers, helping them make more informed decisions and optimize network security protection strategies.
[0031] In an embodiment of the present application, a network security protection capability assessment method is provided, which determines the actual protection coefficient of a protective device based on key factors, including: determining the result state difference corresponding to the key factor, and dividing the key factor into positive influencing factors and negative influencing factors according to the positive or negative situation of the result state difference; determining the result state difference corresponding to the positive influencing factor and the corresponding preset weight, and calculating the weighted sum of the result state difference corresponding to the positive influencing factor and the preset weight to obtain a first comprehensive value; determining the result state difference corresponding to the negative influencing factor and the corresponding preset weight, and calculating the weighted sum of the result state difference corresponding to the negative influencing factor and the preset weight to obtain a second comprehensive value; calculating the proportion of positive influencing factors to key factors to obtain a first proportion value, and calculating the proportion of negative influencing factors to key factors to obtain a second proportion value; determining the proportion of key factors to candidate factors to obtain a third proportion value, and calculating the actual protection coefficient of the protective device based on the first comprehensive value, the second comprehensive value, the first proportion value, the second proportion value and the third proportion value.
[0032] Specifically, according to the previously calculated result state difference, the key factors are divided into positive influencing factors (the result state difference is positive) and negative influencing factors (the result state difference is negative); a preset weight is assigned to each positive influencing factor and negative influencing factor to reflect their importance to the performance of the protective equipment; the weighted sum of the product of the result state difference of the positive influencing factors and the negative influencing factors and the corresponding preset weights is calculated respectively to obtain a first comprehensive value and a second comprehensive value; the proportion of the positive influencing factors and the negative influencing factors in the key factors is calculated respectively to obtain a first proportion value and a second proportion value; the proportion of the key factors in all candidate factors is calculated to obtain a third proportion value; based on the first comprehensive value, the second comprehensive value, the first proportion value, the second proportion value and the third proportion value, the actual protection coefficient of the protective equipment is obtained by calculation, reflecting the comprehensive evaluation of the performance of the equipment under various key factors. This step can more comprehensively evaluate the actual protective capabilities of protective equipment and accurately reflect the impact of various factors on equipment performance by comprehensively considering the weights of positive and negative influencing factors, the difference in result status, and the proportion value. By assigning different weights to positive and negative influencing factors and considering their proportions, the importance of each factor can be better weighed to avoid biased conclusions caused by one-sided evaluations.
[0033] In an embodiment of the present application, a method for evaluating network security protection capability is provided, wherein the actual protection coefficient of the protection device is calculated as follows: k=g3*m(g1*L1+g2*L2), Among them, k is the actual protection factor of the protective equipment, g3 is the third proportional value, m is the preset conversion coefficient, g1 is the first proportional value, L1 is the first comprehensive value, g2 is the second proportional value, and L2 is the second comprehensive value.
[0034] In an embodiment of the present application, a network security protection capability assessment method is provided, wherein an initial protection capability assessment value is corrected based on an actual protection coefficient to obtain a protection capability assessment value of a protection device, including: presetting a correction coefficient-actual protection coefficient interval correspondence relationship, wherein the correction coefficient-actual protection coefficient interval correspondence relationship is associated with a corresponding correction coefficient for each actual protection coefficient interval; obtaining the actual protection coefficient of the protection device, and based on a mapping relationship between the actual protection coefficient interval to which the actual protection coefficient belongs within the correction coefficient-actual protection coefficient interval correspondence relationship, selecting a correction coefficient corresponding to the actual protection coefficient interval as the correction coefficient of the protection device; multiplying the correction coefficient by the initial protection capability assessment value to obtain the protection capability assessment value of the protection device, thereby completing the correction of the initial protection capability assessment value.
[0035] Specifically, for each actual protection coefficient interval, a corresponding correction coefficient is set, and the actual protection coefficient interval to which the protective equipment belongs is determined based on the actual protection coefficient of the protective equipment calculated previously; based on the interval to which the actual protection coefficient belongs, the correction coefficient corresponding to the interval is selected from the correction coefficient-actual protection coefficient interval correspondence relationship as the correction coefficient of the protective equipment; the correction coefficient is multiplied by the initial protection capability assessment value to obtain a corrected protection capability assessment value, which will more accurately reflect the actual protection capability of the protective equipment and take into account the adjustment of the initial assessment value by the correction coefficient. By introducing the correction coefficient, this step can more accurately assess the actual protection capability of the protective equipment, taking into account the adjustment factors under different actual conditions, and avoiding deviations in the assessment value; by selecting the correction coefficient based on the mapping relationship of the interval to which the actual protection coefficient belongs, the assessment value in different situations can be adjusted in a personalized manner to be more in line with the actual situation; the introduction of the correction coefficient can comprehensively consider the impact of various factors on the performance of the protective equipment, making the assessment more comprehensive and accurate.
[0036] like Figure 2 As shown, in an embodiment of the present application, a network security protection capability evaluation system is provided, including: a first determination module, which is used to pre-set multidimensional evaluation indicators that directly affect the network security protection capability evaluation of the protection device, and determine the correlation information of the multidimensional evaluation indicators from the protection device; an evaluation module, which is used to analyze the correlation information of the multidimensional evaluation indicators, determine the information data characteristics, and determine the initial protection capability evaluation value of the protection device based on the information data characteristics of the correlation information; a second determination module, which is used to obtain the result performance data of the protection device under different simulated attack scenarios, and analyze the result performance data to determine the key factors affecting the network security protection capability; a correction module, which is used to determine the actual protection coefficient of the protection device based on the key factors, and correct the initial protection capability evaluation value based on the actual protection coefficient to obtain the protection capability evaluation value of the protection device.
[0037] In summary, an embodiment of the present invention provides a network security protection capability assessment method and system, which includes: pre-setting multi-dimensional assessment indicators that directly affect the network security protection capability assessment of protective equipment, and determining their associated information; analyzing the associated information of the multi-dimensional assessment indicators to determine the information data characteristics, and determining the initial protection capability assessment value of the protective equipment based thereon; obtaining the result performance data of the protective equipment under different simulated attack scenarios, and analyzing and determining the key factors affecting the network security protection capability; determining the actual protection coefficient of the protective equipment based on the key factors, and correcting the initial protection capability assessment value based thereon to obtain the protection capability assessment value of the protective equipment. The present invention can more comprehensively and objectively assess the network security protection capability of the protective equipment, timely discover and respond to potential security threats, and thereby guide the optimization of network security measures, improve network security protection capabilities, and ensure the safe and stable operation of the network system.
[0038] Finally, it should be noted that it is apparent that persons skilled in the art may make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, to the extent such modifications and variations fall within the scope of the present invention and its equivalents, the present invention is intended to include such modifications and variations.
[0039] The above description is only an example of an embodiment of the present invention, but it does not limit the scope of the present invention. Any structural changes made according to the present invention, as long as they do not lose the essence of the present invention, should be considered to fall within the scope of protection of the present invention and be subject to restrictions. Technical personnel in the relevant technical field can clearly understand that for the convenience and simplicity of description, the specific working process and related instructions of the platform described above can refer to the corresponding process in the aforementioned platform embodiment, and will not be repeated here.
[0040] The term "comprise," "comprising," or any other similar term is intended to cover a non-exclusive inclusion such that a process, platform, article, or apparatus / platform that comprises a list of elements includes not only those elements but also other elements not expressly listed or inherent to such process, platform, article, or apparatus / platform.
[0041] Thus far, the technical solutions of the present invention have been described in conjunction with the further embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to closely related technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
[0042] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A network security protection capability assessment method, characterized in that: include: Pre-set multi-dimensional evaluation indicators that directly affect the evaluation of the network security protection capability of the protection equipment, and determine the correlation information of the multi-dimensional evaluation indicators from the protection equipment; Analyze the correlation information of the multi-dimensional evaluation indicators, determine the information data characteristics, and determine the initial protection capability evaluation value of the protective equipment based on the information data characteristics of the correlation information; Obtain performance data of protective equipment in different simulated attack scenarios, analyze the performance data, and identify key factors affecting network security protection capabilities; The actual protection coefficient of the protective equipment is determined based on the key factors, and the initial protection capability assessment value is corrected based on the actual protection coefficient to obtain the protection capability assessment value of the protective equipment.
2. A method for evaluating network security protection capabilities according to claim 1, characterized in that: The presetting of multi-dimensional evaluation indicators that directly affect the evaluation of the network security protection capability of the protection device, and determining the associated information of the multi-dimensional evaluation indicators from the protection device, include: Pre-set multi-dimensional evaluation indicators that directly affect the cybersecurity protection capability assessment of protective equipment, and collect multi-dimensional information from protective equipment; The correlation degrees between the multidimensional information and the multidimensional evaluation indicators are determined respectively, and the multidimensional information with the highest correlation degree is determined as the correlation information corresponding to the multidimensional evaluation indicator.
3. A method for evaluating network security protection capabilities according to claim 2, characterized in that: The analysis of the correlation information of the multi-dimensional evaluation indicators to determine the characteristics of the information data includes: Determine the parameter value included in the associated information of the multidimensional evaluation index, and calculate the difference between the parameter value and the standard parameter value to obtain the parameter value difference; The parameter value whose parameter value difference exceeds the corresponding preset value is determined as the information data feature of the associated information.
4. A method for evaluating network security protection capabilities according to claim 3, characterized in that: The determining of the initial protection capability evaluation value of the protection equipment based on the information data characteristics of the associated information includes: Determine the information data characteristics of the associated information, and evaluate and value the information data characteristics to obtain an evaluation value of the information data characteristics; Adding the evaluation values of the information data features of all related information corresponding to the multidimensional evaluation index to obtain the sub-evaluation value corresponding to the multidimensional evaluation index; Determine the correlation between the multidimensional evaluation index and the corresponding multidimensional information, convert the correlation into a vector, and normalize the vectorized correlation to obtain the weight corresponding to the multidimensional evaluation index; The initial protection capability evaluation value of the protective equipment is calculated based on the weights and sub-evaluation values corresponding to the multi-dimensional evaluation indicators.
5. A method for evaluating network security protection capabilities according to claim 4, characterized in that: The calculation formula for the initial protection capability evaluation value of the protective equipment is: , Among them, P is the initial protection capability evaluation value of the protective equipment, ai is the weight corresponding to the i-th multidimensional evaluation indicator, Di is the sub-evaluation value corresponding to the i-th multidimensional evaluation indicator, and n is the number of multidimensional evaluation indicators.
6. A method for evaluating network security protection capabilities according to claim 4, characterized in that: The acquisition of performance data of the protection device under different simulated attack scenarios and analysis of the performance data to determine the key factors affecting network security protection capabilities include: Pre-set different simulated attack scenarios and obtain performance data of protective equipment in different simulated attack scenarios; Predetermine candidate factors that affect network security protection capabilities, and screen and analyze the data in the result performance data to determine the data corresponding to the candidate factors; Determining a result status value of the candidate factor based on the data corresponding to the candidate factor, and determining an average result status value of the candidate factor in the historical result performance data; The difference between the result status value and the average result status value is calculated to obtain the result status difference, and the candidate factors whose result status difference exceeds the corresponding preset threshold are determined as key factors affecting network security protection capabilities.
7. A method for evaluating network security protection capabilities according to claim 6, characterized in that: The actual protection factor of the protective equipment is determined based on key factors, including: Determine the result status difference corresponding to the key factors, and divide the key factors into positive influencing factors and negative influencing factors based on the positive or negative status of the result status difference; Determining the result state difference corresponding to the positive influencing factor and the corresponding preset weight, and calculating the weighted sum of the result state difference corresponding to the positive influencing factor and the preset weight to obtain a first comprehensive value; Determine the result state difference corresponding to the negative influencing factor and the corresponding preset weight, and calculate the weighted sum of the result state difference corresponding to the negative influencing factor and the preset weight to obtain a second comprehensive value; Calculate the proportion of positive influencing factors to key factors to obtain a first proportion value, and calculate the proportion of negative influencing factors to key factors to obtain a second proportion value; Determine the proportion of the key factors to the candidate factors to obtain a third proportion value, and calculate the actual protection factor of the protective equipment based on the first comprehensive value, the second comprehensive value, the first proportion value, the second proportion value and the third proportion value.
8. A method for evaluating network security protection capabilities according to claim 7, characterized in that: The calculation formula for the actual protection factor of the protective equipment is: k=g3*m(g1*L1+g2*L2), Among them, k is the actual protection factor of the protective equipment, g3 is the third proportional value, m is the preset conversion coefficient, g1 is the first proportional value, L1 is the first comprehensive value, g2 is the second proportional value, and L2 is the second comprehensive value.
9. A method for evaluating network security protection capabilities according to claim 6, characterized in that: The step of correcting the initial protection capability evaluation value based on the actual protection coefficient to obtain the protection capability evaluation value of the protective equipment includes: A correspondence relationship between the correction coefficient and the actual protection coefficient interval is pre-set, wherein the correspondence relationship between the correction coefficient and the actual protection coefficient interval is associated with a corresponding correction coefficient for each actual protection coefficient interval; Obtaining an actual protection factor of the protective device, and based on a mapping relationship between an actual protection factor interval to which the actual protection factor belongs and a correction factor-actual protection factor interval correspondence relationship, selecting a correction factor corresponding to the actual protection factor interval as the correction factor of the protective device; Multiply the correction coefficient by the initial protection capability assessment value to obtain the protection capability assessment value of the protective equipment, and complete the correction of the initial protection capability assessment value.
10. A network security protection capability evaluation system, characterized in that: include: A first determination module is used to pre-set multi-dimensional evaluation indicators that directly affect the network security protection capability evaluation of the protection device, and determine the correlation information of the multi-dimensional evaluation indicators from the protection device; An evaluation module is used to analyze the correlation information of the multi-dimensional evaluation indicators, determine the information data characteristics, and determine the initial protection capability evaluation value of the protective equipment based on the information data characteristics of the correlation information; The second determination module is used to obtain the performance data of the protection equipment under different simulated attack scenarios, and analyze the performance data to determine the key factors affecting the network security protection capability; The correction module is used to determine the actual protection coefficient of the protective equipment based on the key factors, and to correct the initial protection capability evaluation value based on the actual protection coefficient to obtain the protection capability evaluation value of the protective equipment.