Information security level judgment method and device, storage medium and electronic equipment
By obtaining data infringement paths and infringement probabilities, combined with the level determination matrix, the information security level is comprehensively determined, which solves the problem of the inability to comprehensively evaluate system security risks in existing technologies and improves the security of the data management system.
Patent Information
- Application Number
- CN202510798089.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-09-23
AI Technical Summary
Existing technologies are unable to comprehensively assess the security risks of the system, resulting in insufficient security of the data management system.
By obtaining the data infringement path, determining the impact level and infringement probability of the target node, and combining it with the preset level determination matrix, the system comprehensively determines the information security level.
It improves the security of transaction data, makes it easier for transaction personnel to manage data according to information security levels, and enhances data protection capabilities.
Smart Images

Figure CN120688061A_ABST
Abstract
Description
Technical Field
[0001] The present specification relates to the field of computer technology, and more specifically, to an information security level determination method, device, storage medium, and electronic device in the field of computer technology. Background Art
[0002] Nowadays, with the continuous development of science and technology, in order to manage data more conveniently, a systematic approach is adopted to count and manage corporate data. However, due to the infringement of the system used to manage data, the data in the system is leaked. Summary of the Invention
[0003] This specification provides a method, device, storage medium and electronic device for determining an information security level. This method can systematically and comprehensively determine the information security level of transaction data based on the data intrusion path of the transaction data, thereby facilitating transaction personnel to manage transaction data based on the information security level of the transaction data, thereby improving the security of the transaction data.
[0004] In a first aspect, a method for determining an information security level is provided, the method comprising:
[0005] Obtaining a data infringement path for transaction data, and determining an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data;
[0006] Determining a target infringement mode for the target node, and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode;
[0007] Obtaining a predetermined second infringement probability, and determining a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of occurrence of infringement of a preceding node in the data infringement path, the preceding node being a data node located before the target node in the data infringement path;
[0008] Based on the impact level and the target infringement probability, the information security level of the target node is determined in a preset level determination matrix.
[0009] Through the above technical solution, the impact of the transaction data being infringed and the probability of the transaction data being infringed are determined according to the data infringement path, and the information security level of the transaction data is determined by comprehensively considering the impact and probability of the transaction data being infringed. Therefore, according to the data infringement path of the transaction data, the information security level of the transaction data is systematically and comprehensively determined, which makes it easier for transaction personnel to manage the transaction data according to the information security level of the transaction data, thereby improving the security of the transaction data.
[0010] In conjunction with the first aspect, in certain possible implementations, obtaining a data infringement path for transaction data and determining an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data include:
[0011] Obtaining a data infringement path for transaction data, wherein the data infringement path is generated based on a data infringement condition and a read condition for the transaction data;
[0012] Obtaining the node importance of the target node, and determining the intrusion path and impact degree of the target node, wherein the impact degree represents the impact caused by the intrusion of the target node;
[0013] Based on the node importance, the infringement path and the impact degree, the impact level of the target node being infringed is determined.
[0014] Through the above technical solution, the data infringement path of the transaction data is obtained according to the data infringement conditions and reading conditions of the data transaction data, and then the impact level of the transaction data infringement is determined according to the node importance, infringement path and impact degree. Then, the information security level of the transaction data can be judged based on the accurate impact level obtained, which is convenient for transaction personnel to protect the transaction data and improve the security of the transaction data.
[0015] In combination with the first aspect and the above implementations, in some possible implementations, determining a target infringement mode for the target node and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode includes:
[0016] Identifying a first infringement behavior received by the target node, and obtaining at least one data infringement mode of the first infringement behavior;
[0017] A target infringement mode is determined among the data infringement modes, and a first infringement probability of the target node is determined based on mode parameters of the target infringement mode.
[0018] Through the above technical solution, the data infringement mode of the target node's infringement behavior is obtained, the target infringement mode is determined in the data infringement data, and the first infringement probability of the target node is obtained by calculation based on the mode parameters of the target infringement mode, so as to determine the possibility of the target node being infringed, so as to determine the information security level of the target node according to the first infringement probability.
[0019] In combination with the first aspect and the above implementations, in some possible implementations, identifying the first infringement behavior received by the target node and obtaining at least one data infringement mode of the first infringement behavior includes:
[0020] Identifying a first infringement behavior of the target node, and matching the first infringement behavior with a second infringement behavior in an infringement database;
[0021] If the infringement behavior library includes a second infringement behavior that matches the first infringement behavior, obtaining at least one data infringement method corresponding to the second infringement behavior recorded in the infringement behavior library;
[0022] If the infringement library does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed to determine at least one data infringement method of the first infringement behavior, and the first infringement behavior and the data infringement method are stored in the infringement behavior library.
[0023] Through the above technical solution, when the infringement database includes a second infringement behavior that matches a first infringement behavior, the data infringement mode of the second infringement behavior is directly obtained, improving the accuracy and efficiency of determining the first infringement probability of the target node. If the infringement database does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed and the first infringement behavior and the corresponding data infringement mode are stored in the infringement database, thereby enriching the content of the infringement database.
[0024] In combination with the first aspect and the above implementations, in certain possible implementations, determining a target infringement mode from the data infringement mode, and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode, includes:
[0025] Obtaining a first mode parameter of each of the data infringement modes, and selecting a target infringement mode from the data infringement modes based on the first mode parameter;
[0026] Based on the execution difficulty and required cost in the second mode parameters corresponding to the target infringement mode, the first infringement probability of the target infringement mode is determined.
[0027] In combination with the first aspect and the above implementations, in certain possible implementations, determining a target infringement mode from the data infringement mode, and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode, includes:
[0028] Determine each of the data infringement modes as a target infringement mode, and then determine a third infringement probability of each of the data infringement modes based on the second mode parameter of each of the data infringement modes;
[0029] The method weight of each of the data infringement methods is obtained, and the first infringement probability of the target node is obtained based on each of the third infringement probabilities and the method weight corresponding to the third infringement probability.
[0030] Through the above technical solution, the occurrence probability of all data infringement methods included in the infringement behavior is taken into account, and the possibility of infringing the target node according to each data infringement method is comprehensively considered in combination with the method weight, thereby improving the accuracy of the obtained first infringement probability.
[0031] In combination with the first aspect and the above implementations, in some possible implementations, before obtaining the predetermined second infringement probability, the method further includes:
[0032] Determine a first node adjacent to the target node in the data infringement path, and a second node in the data infringement path, where the second node is a data node in the data infringement path between the start node and the first node;
[0033] Based on each of the second nodes, obtaining at least one infringement path from the starting node to the first node, and simulating infringement for each of the infringement paths;
[0034] Obtaining a fourth infringement probability of each second node in the infringement path corresponding to the simulated infringement, and obtaining a fifth infringement probability of each infringement path based on the fourth infringement probability;
[0035] A second infringement probability of the preceding node being violated is obtained based on each of the fifth infringement probabilities.
[0036] In a second aspect, an information security level determination device is provided, the device comprising:
[0037] an impact determination unit, configured to obtain a data infringement path for transaction data and determine an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data;
[0038] A first probability determination unit is configured to determine a target infringement mode for the target node, and determine a first infringement probability of the target node based on a mode parameter of the target infringement mode;
[0039] a target probability determination unit, configured to obtain a predetermined second infringement probability, and determine a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of infringement of a preceding node in the data infringement path, the preceding node being a data node located before the target node in the data infringement path;
[0040] A level determination unit is used to determine the information security level of the target node in a preset level determination matrix based on the impact level and the target infringement probability.
[0041] In a third aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in the first aspect or any possible implementation of the first aspect.
[0042] In a fourth aspect, a computer-readable storage medium is provided, which stores a computer program code. When the computer program code runs on a computer, the computer executes the method in the above-mentioned first aspect or any possible implementation of the first aspect.
[0043] In a fifth aspect, an electronic device is provided, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the above method. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 This is a system architecture diagram of an information security level determination method provided by an embodiment of this specification;
[0045] Figure 2 This is a flowchart of a method for determining an information security level provided in an embodiment of this specification;
[0046] Figure 3 This is a flowchart of a method for determining an information security level provided in an embodiment of this specification;
[0047] Figure 4 This is a schematic diagram of an example of a data infringement path provided in an embodiment of this specification;
[0048] Figure 5 This is a schematic diagram of an example of an infringement path provided in the embodiments of this specification;
[0049] Figure 6 This is a schematic diagram of the structure of an information security level determination device provided in an embodiment of this specification;
[0050] Figure 7 This is a schematic diagram of the structure of an information security level determination device provided in an embodiment of this specification;
[0051] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0052] The following will clearly and thoroughly describe the technical solutions in this specification with reference to the accompanying drawings. In the description of the embodiments of this specification, unless otherwise specified, " / " means or. For example, A / B can mean A or B. "And / or" in the text is only a description of the association relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of this specification, "multiple" means two or more than two.
[0053] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.
[0054] Figure 1 This is a system architecture diagram of an information security level determination method provided by an embodiment of this specification. Figure 1 As shown, the information security level determination method provided in the embodiments of this specification can be applied to electronic devices to implement the process of determining the information security level of transaction data. The system structure provided in the embodiments of this specification mainly includes an electronic device 10 and a data infringement path 20. Among them, the electronic device 10 can be a device with data processing functions, such as a personal computer, a smart phone, a tablet computer, etc. The data infringement path 20 can be generated by transaction personnel based on transaction data, representing a path that can infringe on the transaction data.
[0055] In related technologies, in order to ensure the security of data in the system, it is necessary to detect security risks in the system. During the detection process, the method adopted is to detect vulnerabilities in the system and only perform security level assessment on the vulnerabilities. It is impossible to comprehensively determine the security risks existing in the system, resulting in insufficient security of the system.
[0056] Through the embodiments of this specification, the electronic device 10 obtains a data infringement path 20 for transaction data, and determines the impact level of the target node being infringed in the data infringement path 20 based on the infringement path and impact level corresponding to the transaction data. The target node is the data node corresponding to the transaction data, and a target infringement method for the target node is determined. The first infringement probability of the target node is determined based on the method parameters of the target infringement method, and a predetermined second infringement probability is obtained. The target infringement probability of the target node is determined based on the first infringement probability and the second infringement probability. Based on the impact level and the target infringement probability, the information security level of the target node is determined in a preset level determination matrix. Therefore, according to the data infringement path of the transaction data, the information security level of the transaction data is systematically and comprehensively determined, thereby facilitating transaction personnel to manage the transaction data according to the information security level of the transaction data, thereby improving the security of the transaction data.
[0057] based on Figure 1 The system architecture shown below will be combined with Figure 2-Figure 5 , a detailed introduction to the information security level determination method provided in the embodiments of this specification is given.
[0058] See Figure 2 , provides a flow chart of a method for determining an information security level according to an embodiment of this specification. Figure 2 As shown, the method of the embodiment of this specification may include the following steps S102 to S108.
[0059] S102, obtaining a data infringement path for the transaction data, and determining the impact level of the infringement of the target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data;
[0060] In one embodiment, transaction data that requires security assessment is determined. Transaction data can be data that needs to be protected by the transaction party, such as financial data, transaction data, and other data used by the transaction party for transactions, or data used by the transaction party for managing internal personnel, etc., and can be specifically set according to actual conditions. A data infringement path for the transaction data is obtained. The data infringement path can be generated by the transaction personnel for the transaction data, representing the path that can infringe upon the transaction data. The data infringement path includes at least two data nodes, and the data nodes can be data access paths involved in representing the transaction data and reading the transaction data, wherein the target node in the data infringement path can be the data node corresponding to the transaction data. Based on the infringement path and impact level corresponding to the transaction data, the impact level of the infringement of the target node in the data infringement path is determined. The infringement path can be a path that represents the path taken to infringe upon the transaction data, such as a path from network security aspects such as a network interface, or a path from information security aspects such as a path that infringes upon the data based on system vulnerabilities, etc., and can be specifically set according to actual conditions. The impact level can be a situation that represents the impact that may be caused by the infringement of the target node, such as maintenance costs, economic losses, etc. The impact level may be used to indicate the severity of the target node being infringed. For example, it may be set to different levels such as "serious," "high," "medium," and "low," and may be set specifically based on actual conditions.
[0061] S104, determining a target infringement mode for the target node, and determining a first infringement probability of the target node based on mode parameters of the target infringement mode;
[0062] In one embodiment, a target infringement method for a target node is determined, and the determined target infringement method includes corresponding method parameters. The target infringement method can be a means for infringing data on the target node, and the method parameters can be parameters such as the execution difficulty and cost corresponding to the target infringement method. Based on the method parameters of the target infringement method, a first infringement probability of the target node being infringed is determined. The first infringement probability indicates the probability value of the target node being infringed by the node preceding the target node in the data infringement path.
[0063] S106, obtaining a predetermined second infringement probability, and determining a target infringement probability of the target node based on the first infringement probability and the second infringement probability;
[0064] In one embodiment, a second infringement probability determined in advance based on the data infringement path is obtained, and a target infringement probability of the target node is obtained based on the first infringement probability and the second infringement probability. The second infringement probability can be a probability that the preceding node in the data infringement path is infringed. It should be noted that since the data infringement path can be generated in advance, the path and probability of the preceding node being infringed can be calculated in advance, so the second infringement probability can be predetermined. The preceding node is the data node that is located before the target node in the data infringement path. The target infringement probability can be a probability that indicates that the target node is infringed. It can be understood that since the first infringement probability is the probability value of the preceding node of the target node in the data infringement path infringing the target node, and the second infringement probability is the probability value of the preceding node being infringed, the probability value of the target node being infringed can be obtained by combining the first infringement probability and the second infringement probability.
[0065] Specifically, the target infringement probability can be obtained by multiplying the first infringement probability by the second infringement probability, and determining the resulting value as the target infringement probability. It is understood that probability is a percentage of an event occurring, and the probability of multiple events occurring is calculated by multiplying the probability values at each time. Therefore, the target infringement probability is obtained by combining the first infringement probability of the target node being infringed with the second infringement probability of the predecessor node being infringed.
[0066] For example, the first infringement probability is 0.6, the second infringement probability is 0.5, and the target infringement probability is 06*0.5=0.3.
[0067] S108, determining the information security level of the target node in a preset level determination matrix based on the impact level and the target infringement probability;
[0068] In one embodiment, based on the impact level of the target node being compromised and the target compromise probability, a search is performed in a preset level determination matrix to determine the information security level corresponding to the target node that meets the impact level and target compromise probability. The level determination matrix can be a comprehensive impact level and target compromise probability, and judge the possibility of the transaction data indicated by the target node being compromised, as well as the corresponding impact, to obtain the information security level of the target node. The information security level can be used to characterize the importance of data protection for the transaction data indicated by the target node, so that the transaction personnel of the transaction party can perform targeted data protection management on the transaction data indicated by the target node based on the information security level of the target node, and correct the vulnerabilities or system defects discovered during the determination of the information security level.
[0069] For example, if the impact level of a target node is "Critical" and the target compromise probability is "0.3," the corresponding level in the level determination matrix is "High Risk." It can be understood that since the impact level of the target node is "Critical," if the transaction data indicated by the target node is compromised, significant losses will result. However, since the probability of compromise is 0.3, the probability of the target node being compromised is low, and therefore the information security level of the transaction data indicated by the target node is determined to be "High Risk."
[0070] In the embodiments of this specification, the impact of the transaction data being infringed and the probability of the transaction data being infringed are determined based on the data infringement path, and the information security level of the transaction data is determined by comprehensively considering the impact and probability of the transaction data being infringed. Therefore, based on the data infringement path of the transaction data, the information security level of the transaction data is systematically and comprehensively determined, thereby facilitating transaction personnel to manage the transaction data based on the information security level of the transaction data, thereby improving the security of the transaction data.
[0071] See Figure 3 , provides a flow chart of a transaction processing method according to the embodiment of this specification. Figure 3 As shown, the method of the embodiment of this specification may include the following steps S202 to S222.
[0072] S202, obtaining a data infringement path for transaction data;
[0073] In one embodiment, transaction data requiring security assessment is determined. Transaction data may be data requiring protection on the transaction side, such as financial data, transaction data, and other data used by the transaction side for transactions, or data used by the transaction side for managing internal personnel, etc., and may be specifically configured based on actual circumstances. A data infringement path for transaction data is obtained. The data infringement path may be a path generated by transaction personnel for transaction data, representing a path that can infringe upon the transaction data. The data infringement path includes at least two data nodes, which may be data access paths involved in representing transaction data and reading transaction data, wherein the target node in the data infringement path may be a data node corresponding to the transaction data.
[0074] Specifically, a data violation path can be generated based on data violation conditions and read conditions for transaction data. Based on the data violation conditions and read conditions, the steps or interfaces involved in violating the transaction data are identified as nodes, and the nodes are connected based on their relationships to obtain the data violation path corresponding to the transaction data. The data violation conditions can be the means used to violate the transaction data, such as malware attacks or man-in-the-middle attacks. The read conditions can be the method for reading the transaction data from the transaction party's data management system, specifically the data interface used to read the data.
[0075] For example, Figure 4 As shown, Figure 4 It includes the target node H corresponding to the transaction data, as well as the preceding data nodes S, C, D, E and F. The data nodes are connected according to the relationship between them to obtain the data infringement path.
[0076] S204, obtaining the node importance of the target node and determining the target node's invasion path and impact degree;
[0077] In one embodiment, the node importance of the target node is obtained. The node importance may be an indication of the importance of the transaction data to the transaction parties. If the transaction data is financial data, it may be determined based on the amount of the transaction data, the transaction objects involved, etc. If the transaction data is the information data of the transaction personnel, the importance may be determined based on the level of detail of the transaction data, the job type of the transaction personnel, etc., and may be set specifically according to the actual situation. Then determine the infringement path and the degree of impact that may infringe on the target node. The infringement path may be a characterization of the path taken to infringe on the transaction data, such as a network security path from the network interface, or an information security path to infringe on the data based on system vulnerabilities, etc., and may be set specifically according to the actual situation. The degree of impact may be a characterization of the impact that may be caused by the infringement of the target node, such as maintenance costs, economic losses, etc.
[0078] S206, based on the node importance, the invasion path and the impact degree, determining the impact level of the target node being invaded;
[0079] In one embodiment, based on the node importance, infringement path, and impact level of the target node, the impact that may be caused by the infringement of the target node is determined to determine the impact level of the target node infringement. The impact level can be used to indicate the severity of the target node infringement. For example, it can be set to different levels such as "serious," "high," "medium," and "low," and the specific setting can be based on actual conditions. The impact level represents the impact caused by the infringement of the target node.
[0080] S208, identifying the first infringement behavior received by the target node, and obtaining at least one data infringement method of the first infringement behavior;
[0081] In one embodiment, a first infringement behavior received by a target node is identified and matched against a second infringement behavior in an infringement database. If the infringement database includes a second infringement behavior that matches the first infringement behavior, at least one data infringement method corresponding to the second infringement behavior recorded in the infringement database is obtained. The first infringement behavior can be an act of data infringement against the target node, specifically an instruction, an attack, etc. The infringement database can be a database created in advance for data infringement behaviors, and the infringement database includes at least one second infringement behavior, namely, the behavior identifier of each infringement behavior, the infringement method used, etc.
[0082] Specifically, matching the first infringement behavior in the infringement library can be performed by matching the behavior identifier of the first infringement behavior with the behavior identifier of the second infringement behavior in the infringement library. If there is a matching behavior identifier, the data infringement method corresponding to the matched second infringement behavior is determined as the data infringement method corresponding to the first infringement behavior.
[0083] Furthermore, if the infringement database does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed to determine at least one data infringement method of the first infringement behavior, and the first infringement behavior and the data infringement method are stored in the infringement behavior database. The method for analyzing the first infringement behavior can be set according to actual circumstances.
[0084] S210, determining a target infringement mode among the data infringement modes, and determining a first infringement probability of a target node based on mode parameters of the target infringement mode;
[0085] In one embodiment, after determining the data infringement mode of the first infringement behavior, the first mode parameters of each of the data infringement modes are obtained, and based on the first mode parameters, a target infringement mode is selected from the data infringement modes, and the first infringement probability of the target infringement mode is determined based on the execution difficulty and required cost in the second mode parameters corresponding to the target infringement mode. The first mode parameters can be parameters such as the execution difficulty and cost corresponding to the data infringement mode. The second mode parameters can be parameters such as the execution difficulty and cost corresponding to the target infringement mode. The first infringement probability indicates the probability value that the target node is infringed from the node before the target node in the data infringement path. Among them, the algorithm for calculating the first infringement probability can be a Monte Carlo algorithm, etc., which can be specifically set according to actual conditions.
[0086] Optionally, in addition to selecting a target infringement method from the data infringement methods of the first infringement behavior to calculate the first infringement probability, the various data infringement methods of the first infringement behavior can also be comprehensively analyzed to obtain the first infringement probability. The specific calculation method can be: determine each data infringement method as the target infringement method, then determine the third infringement probability of each data infringement method based on the second method parameter of each data infringement method, obtain the method weight of each data infringement method, and obtain the first infringement probability of the target node based on each third infringement probability and the method weight corresponding to the third infringement probability. The third infringement probability can be the probability of data infringement on the target node using each data infringement method. The method weight can be a weight set based on the second method parameter of each data infringement method, taking into account the feasibility and cost of data infringement according to the data infringement method. The larger the method weight, the greater the possibility that the data infringement method will infringe the target node.
[0087] For example, the first infringement behavior includes three data infringement methods, and the method weights of each data infringement method are 0.5, 03 and 0.2 respectively. The corresponding third infringement probabilities are 0.6, 0.2 and 0.2, then the calculated first infringement probability is 0.5*0.6+0.3*0.2+0.2*0.2=0.4.
[0088] S212, determining a first node adjacent to the target node in the data infringement path, and a second node in the data infringement path;
[0089] In one embodiment, after obtaining the first violation probability, since the first violation probability is the probability of the target node being violated by the node preceding the target node in the data violation path, the probability of the target node being violated also needs to be considered in order to determine the probability of the target node being violated. Therefore, the first node adjacent to the target node in the data violation path is determined, and the first node is the node preceding the target node in the data violation path. The second node in the data violation path is also obtained, and the second node can be a data node that passes through the data violation path from the starting node to the first node.
[0090] S214, based on each second node, obtaining at least one infringement path from the starting node to the first node, and simulating infringement for each infringement path;
[0091] In one embodiment, based on each second node and the node relationship between each second node in the data infringement path, at least one infringement path from the starting node to the first node is obtained, and infringement simulation is performed on each infringement path. The node relationship can be an execution logic that represents data access or data infringement between each second node. The starting node can be the first node in the data infringement path, for example, Figure 4The simulated infringement may be a simulated infringement behavior of infringing data on the first node according to the infringement path.
[0092] The infringement path can be a path formed from the starting node to the first node. For example, Figure 5 As shown, according to Figure 5 The starting node, the first node and the second node in the , can obtain the infringement paths S→E→C, S→F→C, S→D→C and S→D→E→C.
[0093] S216, obtaining a fourth infringement probability of each second node in the infringement path corresponding to the simulated infringement, and obtaining a fifth infringement probability of each infringement path based on the fourth infringement probability;
[0094] In one embodiment, each second node in the infringement path corresponding to the simulated infringement is determined, a fourth infringement probability of each second node in each infringement path is obtained, and a fifth infringement probability of each infringement path is calculated based on the fourth infringement probability of each second node. The fourth infringement probability can be the probability of the second node being violated, and can be specifically calculated using a Monte Carlo algorithm. The fifth infringement probability can be the probability of the infringement starting from the starting node along the infringement path and continuing to the first node.
[0095] Exemplarily, the infringement path includes a starting node, a first node and a second node. The fourth infringement probability of the starting node is 0.5, the fourth infringement probability of the first node is 0.5, and the fourth infringement probability of the second node is 0.4. Then the fifth infringement probability can be 0.5*0.5*0.4=0.1.
[0096] S218, obtaining a second infringement probability of the preceding node being infringed based on each fifth infringement probability;
[0097] In one embodiment, after obtaining the fifth infringement probability corresponding to each infringement path, each fifth infringement probability is added together to obtain the second infringement probability of the preceding node being violated. The preceding node can be a general term for the starting node, the first node, and each second node.
[0098] Exemplarily, the data infringement path includes four infringement paths, and the fifth infringement probabilities corresponding to the infringement paths are 0.1, 0.125, 0.15 and 0.06 respectively. The second infringement probability can be calculated as 0.1+0.125+0.15+0.06=0.435.
[0099] It should be noted that since the process of determining the second infringement probability can be to judge the target node by simulating the infringement, the possibility of the predecessor node being invaded can be judged in advance by using simulated infringement to obtain the second infringement probability corresponding to the predecessor node. In order to improve the accuracy of the obtained second infringement probability, a feasible way is to simulate the infringement of the predecessor node multiple times to obtain multiple second infringement probabilities, and determine the value obtained by averaging each second infringement probability as the second infringement probability.
[0100] S220, obtaining a predetermined second infringement probability, and determining a target infringement probability of the target node based on the first infringement probability and the second infringement probability;
[0101] In one embodiment, a second infringement probability determined in advance based on the data infringement path is obtained, and a target infringement probability of the target node is obtained based on the first infringement probability and the second infringement probability. The second infringement probability can be a probability that the preceding node in the data infringement path is infringed. It should be noted that since the data infringement path can be generated in advance, the path and probability of the preceding node being infringed can be calculated in advance, so the second infringement probability can be predetermined. The preceding node is the data node that is located before the target node in the data infringement path. The target infringement probability can be a probability that indicates that the target node is infringed. It can be understood that since the first infringement probability is the probability value of the preceding node of the target node in the data infringement path infringing the target node, and the second infringement probability is the probability value of the preceding node being infringed, the probability value of the target node being infringed can be obtained by combining the first infringement probability and the second infringement probability.
[0102] Specifically, the target infringement probability can be obtained by multiplying the first infringement probability by the second infringement probability, and determining the resulting value as the target infringement probability. It is understood that probability is a percentage of an event occurring, and the probability of multiple events occurring is calculated by multiplying the probability values at each time. Therefore, the target infringement probability is obtained by combining the first infringement probability of the target node being infringed with the second infringement probability of the predecessor node being infringed.
[0103] For example, the first infringement probability is 0.6, the second infringement probability is 0.5, and the target infringement probability is 06*0.5=0.3.
[0104] S222, based on the impact level and the target infringement probability, determining the information security level of the target node in a preset level determination matrix;
[0105] In one embodiment, based on the impact level of the target node being compromised and the target compromise probability, a search is performed in a preset level determination matrix to determine the information security level corresponding to the target node that meets the impact level and target compromise probability. The level determination matrix can be a comprehensive impact level and target compromise probability to determine the possibility of the transaction data indicated by the target node being compromised, as well as the corresponding impact, to obtain the information security level of the target node. The information security level can be used to characterize the importance of data protection for the transaction data indicated by the target node, so that the transaction personnel of the transaction party can perform data protection management on the transaction data indicated by the target node according to the information security level of the target node, and correct any vulnerabilities or system defects discovered during the determination of the information security level. System defects can be defects in the system used by the transaction party to manage data. It is understandable that even if there are no vulnerabilities in the system, if the data is easily accessed by external requests, data leakage may also occur. Therefore, by determining the information security level of the transaction data, it is convenient for the transaction personnel to conduct system monitoring and improvement on the system storing the transaction data, thereby improving data protection capabilities and improving the security of the transaction data.
[0106] Furthermore, in order to facilitate the determination of the information security level of the target node based on the impact level and the target infringement probability, a feasible approach is to divide the target infringement probability into different probability domains according to the threshold, for example, setting the target infringement probability greater than or equal to 0 and less than 0.25 to "low", setting the target infringement probability greater than or equal to 0.25 and less than 0.5 to "medium", setting the target infringement probability greater than or equal to 0.5 and less than 0.75 to "high", and setting the target infringement probability greater than or equal to 0.75 and less than or equal to 1 to "extremely high".
[0107] For example, if the impact level of a target node is "Critical" and the target compromise probability is "0.3," the corresponding level in the level determination matrix is "High Risk." It can be understood that since the impact level of the target node is "Critical," if the transaction data indicated by the target node is compromised, significant losses will result. However, since the probability of compromise is 0.3, the probability of the target node being compromised is low, and therefore the information security level of the transaction data indicated by the target node is determined to be "High Risk."
[0108] Exemplarily, the level determination matrix can be as shown in Table 1. The level determination matrix shown in Table 1 includes information security levels set according to the impact level and the target infringement probability. If the impact level is "serious" and the target infringement probability is "0.3", that is, the probability domain of the target infringement probability is "medium", then the level determination matrix is searched according to the impact level and the target infringement probability to determine that the information security level of the target node is "high-risk level".
[0109] Table 1:
[0110]
[0111]
[0112] In the embodiment of the present specification, by determining the impact of the transaction data being infringed and the probability of the transaction data being infringed according to the data infringement path, the information security level of the transaction data is determined by comprehensively considering the impact and probability of the transaction data being infringed, thereby systematically and comprehensively determining the information security level of the transaction data according to the data infringement path of the transaction data, thereby facilitating the transaction personnel to manage the transaction data according to the information security level of the transaction data, thereby improving the security of the transaction data. In addition, the data infringement method of the data infringement behavior is obtained according to the infringement library, thereby improving the accuracy and efficiency of determining the first infringement probability of the target node. Further, multiple methods are provided to determine the first infringement probability of the target node being infringed, so that the first infringement probability can be calculated according to the corresponding method according to actual needs, thereby improving the accuracy of the obtained first infringement probability. Further, the second infringement probability is obtained in advance by simulating the infringement of the first node, so that the target infringement probability of the target node being infringed can be determined based on the first infringement probability and the second infringement probability, thereby improving the efficiency of determining the target infringement probability while ensuring the accuracy of determining the target infringement probability.
[0113] based on Figure 1 The system architecture will be combined with Figure 6 and Figure 7 , the information security level determination device provided in the embodiment of this specification is introduced in detail. It should be noted that, Figure 6 The information security level determination device 1 is used to execute the information security level determination device 1 of this specification. Figure 2-Figure 5 For the convenience of explanation, only the part related to the embodiment of this specification is shown. For the specific technical details not disclosed, please refer to this specification. Figure 2-Figure 5 The embodiment shown.
[0114] See Figure 6 , is a structural diagram of a transaction processing device provided in the embodiment of this specification. Figure 6 As shown, the transaction processing device 1 of the embodiment of this specification may include: an impact determination unit 11, a first probability determination unit 12, a target probability determination unit 13 and a level determination unit 14.
[0115] An impact determination unit 11 is configured to obtain a data infringement path for transaction data and determine an impact level of an infringement on a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data.
[0116] A first probability determination unit 12 is configured to determine a target infringement mode for the target node, and determine a first infringement probability of the target node based on a mode parameter of the target infringement mode;
[0117] a target probability determination unit 13 configured to obtain a predetermined second infringement probability and determine a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of infringement of a preceding node in the data infringement path, the preceding node being a data node preceding the target node in the data infringement path;
[0118] The level determination unit 14 is configured to determine the information security level of the target node in a preset level determination matrix based on the impact level and the target infringement probability.
[0119] Optionally, the impact determination unit 11 is further configured to:
[0120] Obtaining a data infringement path for transaction data, wherein the data infringement path is generated based on a data infringement condition and a read condition for the transaction data;
[0121] Obtaining the node importance of the target node, and determining the intrusion path and impact degree of the target node, wherein the impact degree represents the impact caused by the intrusion of the target node;
[0122] Based on the node importance, the infringement path and the impact degree, the impact level of the target node being infringed is determined.
[0123] Optionally, the first probability determination unit 12 is further configured to:
[0124] Identifying a first infringement behavior received by the target node, and obtaining at least one data infringement mode of the first infringement behavior;
[0125] A target infringement mode is determined among the data infringement modes, and a first infringement probability of the target node is determined based on mode parameters of the target infringement mode.
[0126] Optionally, the first probability determination unit 12 is further configured to:
[0127] Identifying a first infringement behavior of the target node, and matching the first infringement behavior with a second infringement behavior in an infringement database;
[0128] If the infringement behavior library includes a second infringement behavior that matches the first infringement behavior, obtaining at least one data infringement method corresponding to the second infringement behavior recorded in the infringement behavior library;
[0129] If the infringement library does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed to determine at least one data infringement method of the first infringement behavior, and the first infringement behavior and the data infringement method are stored in the infringement behavior library.
[0130] Optionally, the first probability determination unit 12 is further configured to:
[0131] Obtaining a first mode parameter of each of the data infringement modes, and selecting a target infringement mode from the data infringement modes based on the first mode parameter;
[0132] Based on the execution difficulty and required cost in the second mode parameters corresponding to the target infringement mode, the first infringement probability of the target infringement mode is determined.
[0133] Optionally, the first probability determination unit 12 is further configured to:
[0134] Determine each of the data infringement modes as a target infringement mode, and then determine a third infringement probability of each of the data infringement modes based on the second mode parameter of each of the data infringement modes;
[0135] The method weight of each of the data infringement methods is obtained, and the first infringement probability of the target node is obtained based on each of the third infringement probabilities and the method weight corresponding to the third infringement probability.
[0136] Optional, such as Figure 7 As shown, the information security level determination device 1 further includes a second probability determination unit 15, which is used to:
[0137] Determine a first node adjacent to the target node in the data infringement path, and a second node in the data infringement path, where the second node is a data node in the data infringement path between the start node and the first node;
[0138] Based on each of the second nodes, obtaining at least one infringement path from the starting node to the first node, and simulating infringement for each of the infringement paths;
[0139] Obtaining a fourth infringement probability of each second node in the infringement path corresponding to the simulated infringement, and obtaining a fifth infringement probability of each infringement path based on the fourth infringement probability;
[0140] A second infringement probability of the preceding node being violated is obtained based on each of the fifth infringement probabilities.
[0141] In the embodiment of the present specification, by determining the impact of the transaction data being infringed and the probability of the transaction data being infringed according to the data infringement path, the information security level of the transaction data is determined by comprehensively considering the impact and probability of the transaction data being infringed, thereby systematically and comprehensively determining the information security level of the transaction data according to the data infringement path of the transaction data, thereby facilitating the transaction personnel to manage the transaction data according to the information security level of the transaction data, thereby improving the security of the transaction data. In addition, the data infringement method of the data infringement behavior is obtained according to the infringement library, thereby improving the accuracy and efficiency of determining the first infringement probability of the target node. Further, multiple methods are provided to determine the first infringement probability of the target node being infringed, so that the first infringement probability can be calculated according to the corresponding method according to actual needs, thereby improving the accuracy of the obtained first infringement probability. Further, the second infringement probability is obtained in advance by simulating the infringement of the first node, so that the target infringement probability of the target node being infringed can be determined based on the first infringement probability and the second infringement probability, thereby improving the efficiency of determining the target infringement probability while ensuring the accuracy of determining the target infringement probability.
[0142] The embodiment of this specification also provides a computer storage medium that can store multiple program instructions, which are suitable for being loaded and executed by a processor as described above. Figure 1-Figure 5 The method steps of the embodiment shown, the specific execution process can be found in Figure 1-Figure 5 The detailed description of the illustrated embodiment will not be repeated here.
[0143] The embodiment of this specification also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor as described above. Figure 1-Figure 5 The item recommendation model training method of the embodiment shown in the figure can be found in the specific execution process. Figure 1-Figure 5 The detailed description of the illustrated embodiment will not be repeated here.
[0144] See Figure 8 , is a schematic diagram of the structure of an electronic device provided in the embodiment of this specification. Figure 8As shown, the electronic device 1000 may include: at least one processor 1001, such as a CPU, at least one network interface 1004, an input / output interface 1003, a memory 1005, and at least one communication bus 1002. The communication bus 1002 is used to realize the connection and communication between these components. The network interface 1004 may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as at least one disk memory. The memory 1005 may optionally also be at least one storage device located away from the aforementioned processor 1001. As Figure 8 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, an input and output interface module, and an information security level determination application program.
[0145] exist Figure 8 In the electronic device 1000 shown, the input / output interface 1003 is mainly used to provide an input interface for the user and obtain data input by the user.
[0146] In one embodiment, the processor 1001 may be configured to call the information security level determination application stored in the memory 1005 and specifically perform the following operations:
[0147] Obtaining a data infringement path for transaction data, and determining an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data;
[0148] Determining a target infringement mode for the target node, and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode;
[0149] Obtaining a predetermined second infringement probability, and determining a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of occurrence of infringement of a preceding node in the data infringement path, the preceding node being a data node located before the target node in the data infringement path;
[0150] Based on the impact level and the target infringement probability, the information security level of the target node is determined in a preset level determination matrix.
[0151] Optionally, when executing the process of obtaining a data infringement path for transaction data and determining the impact level of the infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, the processor 1001 specifically performs the following operations:
[0152] Obtaining a data infringement path for transaction data, wherein the data infringement path is generated based on a data infringement condition and a read condition for the transaction data;
[0153] Obtaining the node importance of the target node, and determining the intrusion path and impact degree of the target node, wherein the impact degree represents the impact caused by the intrusion of the target node;
[0154] Based on the node importance, the infringement path and the impact degree, the impact level of the target node being infringed is determined.
[0155] Optionally, when determining a target infringement mode for the target node and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode, the processor 1001 specifically performs the following operations:
[0156] Identifying a first infringement behavior received by the target node, and obtaining at least one data infringement mode of the first infringement behavior;
[0157] A target infringement mode is determined among the data infringement modes, and a first infringement probability of the target node is determined based on mode parameters of the target infringement mode.
[0158] Optionally, when the processor 1001 identifies the first infringement behavior received by the target node and obtains at least one data infringement mode of the first infringement behavior, it specifically performs the following operations:
[0159] Identifying a first infringement behavior of the target node, and matching the first infringement behavior with a second infringement behavior in an infringement database;
[0160] If the infringement behavior library includes a second infringement behavior that matches the first infringement behavior, obtaining at least one data infringement method corresponding to the second infringement behavior recorded in the infringement behavior library;
[0161] If the infringement library does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed to determine at least one data infringement method of the first infringement behavior, and the first infringement behavior and the data infringement method are stored in the infringement behavior library.
[0162] Optionally, when determining a target infringement mode in the data infringement mode and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode, the processor 1001 specifically performs the following operations:
[0163] Obtaining a first mode parameter of each of the data infringement modes, and selecting a target infringement mode from the data infringement modes based on the first mode parameter;
[0164] Based on the execution difficulty and required cost in the second mode parameters corresponding to the target infringement mode, the first infringement probability of the target infringement mode is determined.
[0165] Optionally, when determining a target infringement mode in the data infringement mode and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode, the processor 1001 specifically performs the following operations:
[0166] Determine each of the data infringement modes as a target infringement mode, and then determine a third infringement probability of each of the data infringement modes based on the second mode parameter of each of the data infringement modes;
[0167] The method weight of each of the data infringement methods is obtained, and the first infringement probability of the target node is obtained based on each of the third infringement probabilities and the method weight corresponding to the third infringement probability.
[0168] Optionally, before obtaining the predetermined second infringement probability, the processor 1001 further performs the following operations:
[0169] Determine a first node adjacent to the target node in the data infringement path, and a second node in the data infringement path, where the second node is a data node in the data infringement path between the start node and the first node;
[0170] Based on each of the second nodes, obtaining at least one infringement path from the starting node to the first node, and simulating infringement for each of the infringement paths;
[0171] Obtaining a fourth infringement probability of each second node in the infringement path corresponding to the simulated infringement, and obtaining a fifth infringement probability of each infringement path based on the fourth infringement probability;
[0172] A second infringement probability of the preceding node being violated is obtained based on each of the fifth infringement probabilities.
[0173] In the embodiment of the present specification, by determining the impact of the transaction data being infringed and the probability of the transaction data being infringed according to the data infringement path, the information security level of the transaction data is determined by comprehensively considering the impact and probability of the transaction data being infringed, thereby systematically and comprehensively determining the information security level of the transaction data according to the data infringement path of the transaction data, thereby facilitating the transaction personnel to manage the transaction data according to the information security level of the transaction data, thereby improving the security of the transaction data. In addition, the data infringement method of the data infringement behavior is obtained according to the infringement library, thereby improving the accuracy and efficiency of determining the first infringement probability of the target node. Further, multiple methods are provided to determine the first infringement probability of the target node being infringed, so that the first infringement probability can be calculated according to the corresponding method according to actual needs, thereby improving the accuracy of the obtained first infringement probability. Further, the second infringement probability is obtained in advance by simulating the infringement of the first node, so that the target infringement probability of the target node being infringed can be determined based on the first infringement probability and the second infringement probability, thereby improving the efficiency of determining the target infringement probability while ensuring the accuracy of determining the target infringement probability.
[0174] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0175] The above disclosure is only a preferred embodiment of this specification, and certainly cannot be used to limit the scope of rights of this specification. Therefore, equivalent changes made according to the claims of this specification are still within the scope covered by this specification.
Claims
1. A method for determining an information security level, the method comprising: Obtaining a data infringement path for transaction data, and determining an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data; Determining a target infringement mode for the target node, and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode; Obtaining a predetermined second infringement probability, and determining a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of occurrence of infringement of a preceding node in the data infringement path, the preceding node being a data node located before the target node in the data infringement path; Based on the impact level and the target infringement probability, the information security level of the target node is determined in a preset level determination matrix.
2. The method according to claim 1, wherein obtaining a data infringement path for transaction data and determining an impact level of the infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data comprises: Obtaining a data infringement path for transaction data, wherein the data infringement path is generated based on a data infringement condition and a read condition for the transaction data; Obtaining the node importance of the target node, and determining the intrusion path and impact degree of the target node, wherein the impact degree represents the impact caused by the intrusion of the target node; Based on the node importance, the infringement path and the impact degree, the impact level of the target node being infringed is determined.
3. The method according to claim 1, wherein determining a target infringement mode for the target node and determining a first infringement probability of the target node based on a mode parameter of the target infringement mode comprises: Identifying a first infringement behavior received by the target node, and obtaining at least one data infringement mode of the first infringement behavior; A target infringement mode is determined among the data infringement modes, and a first infringement probability of the target node is determined based on mode parameters of the target infringement mode.
4. The method according to claim 3, wherein identifying the first infringement behavior received by the target node and obtaining at least one data infringement mode of the first infringement behavior comprises: Identifying a first infringement behavior of the target node, and matching the first infringement behavior with a second infringement behavior in an infringement database; If the infringement behavior library includes a second infringement behavior that matches the first infringement behavior, obtaining at least one data infringement method corresponding to the second infringement behavior recorded in the infringement behavior library; If the infringement library does not include a second infringement behavior that matches the first infringement behavior, the first infringement behavior is analyzed to determine at least one data infringement method of the first infringement behavior, and the first infringement behavior and the data infringement method are stored in the infringement behavior library.
5. The method according to claim 3, wherein determining a target infringement mode from the data infringement mode and determining a first infringement probability of the target node based on mode parameters of the target infringement mode comprises: Obtaining a first mode parameter of each of the data infringement modes, and selecting a target infringement mode from the data infringement modes based on the first mode parameter; Based on the execution difficulty and required cost in the second mode parameters corresponding to the target infringement mode, the first infringement probability of the target infringement mode is determined.
6. The method according to claim 3, wherein determining a target infringement mode from the data infringement mode and determining a first infringement probability of the target node based on mode parameters of the target infringement mode comprises: Determine each of the data infringement modes as a target infringement mode, and then determine a third infringement probability of each of the data infringement modes based on the second mode parameter of each of the data infringement modes; The method weight of each of the data infringement methods is obtained, and the first infringement probability of the target node is obtained based on each of the third infringement probabilities and the method weight corresponding to the third infringement probability.
7. The method according to claim 1, before obtaining the predetermined second infringement probability, further comprising: Determine a first node adjacent to the target node in the data infringement path, and a second node in the data infringement path, where the second node is a data node in the data infringement path between the start node and the first node; Based on each of the second nodes, obtaining at least one infringement path from the starting node to the first node, and simulating infringement for each of the infringement paths; Obtaining a fourth infringement probability of each second node in the infringement path corresponding to the simulated infringement, and obtaining a fifth infringement probability of each infringement path based on the fourth infringement probability; A second infringement probability of the preceding node being violated is obtained based on each of the fifth infringement probabilities.
8. An information security level determination device, comprising: an impact determination unit, configured to obtain a data infringement path for transaction data and determine an impact level of infringement of a target node in the data infringement path based on the infringement path and impact level corresponding to the transaction data, where the target node is a data node corresponding to the transaction data; A first probability determination unit is configured to determine a target infringement mode for the target node, and determine a first infringement probability of the target node based on a mode parameter of the target infringement mode; a target probability determination unit, configured to obtain a predetermined second infringement probability, and determine a target infringement probability of the target node based on the first infringement probability and the second infringement probability, wherein the second infringement probability represents a probability of infringement of a preceding node in the data infringement path, the preceding node being a data node located before the target node in the data infringement path; A level determination unit is used to determine the information security level of the target node in a preset level determination matrix based on the impact level and the target infringement probability.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program code, and when the computer program code is executed, the method according to any one of claims 1 to 7 is implemented.
10. An electronic device comprising: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method according to any one of claims 1 to 7.
11. A computer program product having at least one instruction stored thereon, wherein when the at least one instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.